Stolen Microsoft Key Gave Chinese Hackers Widespread Access to Cloud Services
As it turns out, the Wiz security team found that the Chinese hackers could have used the private key to access several other Microsoft products. The attack potentially affected all Microsoft apps that utilize OpenID v2.0 access tokens for account authentication.
"Our researchers concluded that the compromised MSA key could have allowed the threat actor to forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive, customers' ...
Publisher: Petri IT Knowledgebase
Date: 2023-07-24T10:43:06-05:00
Reference: (Read more) Visit Source
Comments
Post a Comment