this post was submitted on 27 Jan 2024
47 points (96.1% liked)

Security

647 readers
5 users here now

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don't be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

founded 1 year ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] [email protected] 4 points 9 months ago

Microsoft is one of the companies that wants us to all be forced to use digital IDs. Google, Apple, Microsoft and Amazon are all constantly getting hacked and they think they're trustworthy to have all our identity information when stories like this come out every day.

[–] [email protected] 3 points 9 months ago

someone forgor

[–] [email protected] 2 points 9 months ago

This is the best summary I could come up with:


The hackers who recently broke into Microsoft’s network and monitored top executives’ email for two months did so by gaining access to an aging test account with administrative privileges, a major gaffe on the company's part, a researcher said.

In Thursday’s post updating customers on findings from its ongoing investigation, Microsoft provided more details on how the hackers achieved this monumental escalation of access.

In Thursday’s update, Microsoft officials said as much, although in language that largely obscured the extent of the major blunder.

Threat actors like Midnight Blizzard compromise user accounts to create, modify, and grant high permissions to OAuth applications that they can misuse to hide malicious activity.

They created a new user account to grant consent in the Microsoft corporate environment to the actor controlled malicious OAuth applications.

The threat actor then used the legacy test OAuth application to grant them the Office 365 Exchange Online full_access_as_app role, which allows access to mailboxes.


The original article contains 339 words, the summary contains 156 words. Saved 54%. I'm a bot and I'm open source!