Microsoft’s post-mortem into how China-linked attackers accessed cloud email accounts for US gov’t organisations is an incredible read, and it shows how a chain of mistakes and vulnerabilities in the cloud can lead to a real mess. The attackers probably couldn’t believe their luck. In cloud email security poker, it's a royal flush.
A Microsoft engineer account gets hacked. Engineer has access to a sensitive crash dump, which due to a race condition vulnerability still contained a consumer signing key. That expired consumer signing key works for – boom! – enterprise email due to some validation errors. After forging some Azure Active Directory (AD) access tokens, the attackers crack open the email accounts of the State and Commerce departments. #infosec
Story by @dangoodin https://arstechnica.com/security/2023/09/hack-of-a-microsoft-corporate-account-led-to-azure-breach-by-chinese-hackers/


