ZeroHour
Ars Technica · Securitypublished ()ingested

Microsoft takes pains to obscure role in 0

mediumData breachimportance 45
Tagsbreach
Full article336 words · extracted from arstechnica.com · click to collapse

“I don’t think Microsoft ever acknowledges vulnerabilities in their cloud services (also there’s no CVEs for cloud), and you don’t say breach at Microsoft,” independent researcher Kevin Beaumont said on Mastodon. “They did say ‘exploit’ in the original MSRC blog in relation to Microsoft’s cloud services, and you exploit a vulnerability. So I think it’s fair to say that, yes, they had vuln(s).”

Microsoft issued the following comment: “We don’t have any evidence that the actor exploited a 0day.” Microsoft didn’t elaborate. In one of the two posts published on Tuesday, Microsoft said: “The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail.” Ars has asked for clarification of exactly what was exploited by the threat actor.

Pay-to-play security

Besides being opaque about the root cause of the breach and its own role in it, Microsoft is under fire for withholding details that some of the victims could have used to detect the intrusion, something critics have called “pay-to-play security.” According to the US Cybersecurity and Information Security Agency, one federal agency that was breached by Storm-0558, it discovered the intrusion through audit logs that track logins and other important events affecting customers’ Microsoft cloud accounts.

Microsoft, however, requires customers to pay an additional fee to access these records. The cost for an “E5” enterprise license allowing such access is $57 per month per user, compared to an E3 license cost of $36 per month per customer.

“The fact that Microsoft only allows those who pay the extra money for E5 licensing to see the relevant log files is, well, something…” Will Dorman, senior principal analyst at Analygence, said in an interview. “If you’re not an E5-paying customer, you lose the ability to see that you were compromised.”

While Microsoft’s disclosures have been less than forthcoming in the role its vulnerabilities played in breaching the accounts of organizations, Friday’s disclosure provides helpful indicators that people can use to determine if they’ve been targeted or compromised by Storm-0558.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/07/microsoft-takes-pains-to-obscure-role-in-0-days-that-caused-email-breach/