"Major Security Breach: Hackers Steal Microsoft's Windows Signing Key from Crash Dump"

1 min read
Source: BleepingComputer
"Major Security Breach: Hackers Steal Microsoft's Windows Signing Key from Crash Dump"
Photo: BleepingComputer
TL;DR Summary

Chinese hackers known as Storm-0558 stole a Microsoft signing key from a Windows crash dump after compromising a Microsoft engineer's corporate account. The attackers used the key to breach the Exchange Online and Azure Active Directory accounts of several organizations, including US government agencies. The key was leaked into the crash dump due to a race condition, and the hackers found it after compromising the engineer's account. The compromised key provided widespread access to Microsoft cloud services, allowing the attackers to impersonate accounts within impacted customers' applications. Microsoft has revoked all valid signing keys and expanded access to cloud logging data to help detect similar breach attempts in the future.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

2 min

vs 3 min read

Condensed

81%

577110 words

Want the full story? Read the original article

Read on BleepingComputer