Our investigation of the security incident disclosed by Microsoft and CISA and attributed to Chinese threat actor Storm-0558, found that this incident seems to have a broader scope than originally assumed. Organizations using Microsoft and Azure services should take steps to assess potential impact.
As usual provocative thoughts from Rob Graham
https://open.substack.com/pub/cybersect/p/why-bidens-cyber-trust-mark-is-nonsense