"Major Security Breach: Hackers Steal Microsoft's Windows Signing Key from Crash Dump"

Chinese hackers known as Storm-0558 stole a Microsoft signing key from a Windows crash dump after compromising a Microsoft engineer's corporate account. The attackers used the key to breach the Exchange Online and Azure Active Directory accounts of several organizations, including US government agencies. The key was leaked into the crash dump due to a race condition, and the hackers found it after compromising the engineer's account. The compromised key provided widespread access to Microsoft cloud services, allowing the attackers to impersonate accounts within impacted customers' applications. Microsoft has revoked all valid signing keys and expanded access to cloud logging data to help detect similar breach attempts in the future.
Reading Insights
0
7
2 min
vs 3 min read
81%
577 → 110 words
Want the full story? Read the original article
Read on BleepingComputer