A review of the June 2023 attack on Microsoft's Exchange Online hosted email service – which saw accounts used by senior US officials compromised by a China-linked group called "Storm-0558" – has found that the incident would have been preventable save for Microsoft's lax infosec culture and sub-par cloud security precautions. The review, conducted by the Cybersecurity and Infrastructure Security Agency's Cyber Safety Review Board, calls for "rapid cultural change" at Microsoft. Among the Board's recommendations: That strong language was offered in light of the attack, which it attributed to a "cascade of Microsoft's avoidable errors." The CSRB report [PDF] pins the attack on key rotation practices used to secure the Microsoft Services Account (MSA) – the identity management system underpinning the software giant's cloudy services for consumers. MSA was designed in the early 2000s, without a process for automated signing key rotation or deactivation. Microsoft therefore managed keys manually – but stopped doing so in 2021 after the practice caused a major cloud outage. Between 2021 and the breach in 2023, Microsoft did not employ any tool that would alert it to keys that should be retired. So when Storm-0558 obtained a key created in 2016, which should have been retired, it gained the ability to access the version of Outlook Web Access offered to consumers. Things escalated from there because a flaw in Microsoft's systems meant that the 2016 MSA key could create tokens that a...
Microsoft slammed for lax infosec that led to Exchange crack
The Register
·Simon Sharwood
·Published Apr 3, 2024
·Updated
Affected Software
3 affected components
Microsoft Exchange Online
Microsoft MSA
Microsoft Outlook Web Access
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a review of a security breach in Microsoft's Exchange Online service linked to a Chinese hacking group.
2
What security implications are discussed in the article?
The article discusses the vulnerabilities in Microsoft's information security practices that led to the compromise of senior US officials' accounts.
3
What group is responsible for the attack mentioned in the article?
The hacking group responsible for the attack is identified as "Storm-0558," which is linked to Chinese state-sponsored actors.
4
What products are specifically affected by the security incident?
The affected products include Microsoft Exchange Online, Microsoft MSA, and Microsoft Outlook Web Access.
5
What recommendations are suggested in the article to improve security?
The article suggests that Microsoft needs to enhance its security measures to prevent similar incidents in the future.