Stolen Microsoft Key Gave Chinese Hackers Widespread Access to Cloud Services

As it turns out, the Wiz security team found that the Chinese hackers could have used the private key to access several other Microsoft products. The attack potentially affected all Microsoft apps that utilize OpenID v2.0 access tokens for account authentication.

"Our researchers concluded that the compromised MSA key could have allowed the threat actor to forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive, customers' ...

logo
Publisher: Petri IT Knowledgebase
Date: 2023-07-24T10:43:06-05:00
Reference: (Read more) Visit Source



Comments

Popular posts from this blog

Why alien hunters have spent 60 years finding new solutions for the Drake Equation

UFO Hunting, With Harvard Data: Astrophysicist Advocates For Scientific Investigation

Top UFO hotspots in the UK: Find the best spot to celebrate World UFO Day 2021 | Weird | News |