#WizResearch

🔘 G◍M◍◍T 🔘gomoot@mastodon.uno
2025-01-31
2023-08-02

Feudalismus als GeschÀftsprinzip

Einen Schwelbrand zu löschen ist fast unmöglich, immer wieder flackern kleine oder grĂ¶ĂŸere Glutnester auf. Eine Meldung in den Nachrichten ist das kaum wert, wenn die eine oder andere Katastrophe heimlich ausgetreten werden kann. Und obwohl hinten schon Flammen ĂŒberall krĂ€ftig auflodern, steht Microsoft da und sagt: „Das ist nix, wirklich gar nix – das [
]

https://extradienst.net/2023/08/03/feudalismus-als-geschaeftsprinzip/

deltatux :donor:deltatux@infosec.town
2023-07-22

#Microsoft apparently denies the report from #WizResearch that the impact of the stolen keys from the #Microsoft365 #hack was more severe than what Microsoft initially reported in their #blog, calling it "speculative and not evidence-based".

When asked for comments, Wiz Research was surprised at Microsoft's response because they said that their blog post was "reviewed and validated" by the Microsoft Security Research Team.

#infosec #cybersecurity #cloudsecurity #Azure

https://therecord.media/microsoft-disputes-report-on-chinese-hacking

deltatux :donor:deltatux@infosec.town
2023-07-21

The implication of the #Microsoft365 #hack goes deeper than just affecting #ExchangeOnline. Researchers from #WizResearch notes that the implication of the stolen #MSA keys could have allowed the attacker to:

forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive, customers’ applications that support the “login with Microsoft” functionality, and multi-tenant applications in certain conditions.
#infosec #cybersecurity #databreach #dataloss #cloudsecurity

https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst