ZeroHour
Ars Technica · Securitypublished ()ingested

Microsoft finally explains cause of Azure breach: An engineer’s account was hacked

mediumData breachimportance 45
Tagsbreach
Full article376 words · extracted from arstechnica.com · click to collapse

As noted earlier, Microsoft has steadfastly resisted using the word vulnerability in describing the flaws Storm-0558 exploited to pull off the breach. Instead, the company used the word “issue.” Asked to explain what Microsoft’s definition of “issue” is and how it differs from the company’s definition of “vulnerability,” the representative said: “Vulnerability is a specific term, and we would use the term vulnerability if it was appropriate. “Issue” in the blog refers to things such as misconfiguration, operator errors, or unintended byproducts of other actions.”

Will Dorman, senior principal analyst at security intelligence firm Analygence said in an online interview:

There were a few aspects that could be considered vulnerabilities:

—Race condition led to key material in a crash dump—Sounds like a vulnerability

—“mail system would accept a request for enterprise email using a security token signed with the consumer key”—definitely a vulnerability

—“able to successfully compromise a Microsoft engineer’s corporate account”—Just part of living in this world, I suppose.

Microsoft has said that roughly 25 organizations had one or more of their accounts breached in the campaign, which began on May 15 and lasted until June 16. Microsoft wasn’t aware of the mass hack until a customer tipped it off.

Microsoft has described Storm-0558 as a China-based threat actor with activities and methods consistent with espionage objectives.” The group targets a wide range of entities. They include: US and European diplomatic, economic, and legislative governing bodies, individuals connected to Taiwan and Uyghur geopolitical interests, media companies, think tanks, and telecommunications equipment and service providers.

“Storm-0558 operates with a high degree of technical tradecraft and operational security,” Microsoft wrote in July. “The actors are keenly aware of the target’s environment, logging policies, authentication requirements, policies, and procedures. Storm-0558’s tooling and reconnaissance activity suggests the actor is technically adept, well resourced, and has an in-depth understanding of many authentication techniques and applications.”

Critics calling out Microsoft for what they say is negligence connected to the breach have included a US senator and an industry CEO. They have criticized both the practices leading up to the hack and what they have said is a lack of transparency following it. Wednesday’s update goes a step in the right direction, but the company still has more work to do.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/09/hack-of-a-microsoft-corporate-account-led-to-azure-breach-by-chinese-hackers/