Wiz researchers: the compromised MSA signing key could have given Chinese hackers access beyond Outlook.com and Exchange Online; Microsoft disputes the report
Microsoft is disputing a new report that claims hackers may have had access to more parts of victims' systems than previously known … Source: Wiz Blog .
The RecordJonathan Greig
Context & Ripple Effects
Microsoft had already disclosed that Chinese hackers accessed some US government email accounts for at least a month before detection, establishing an incident whose scope was still being defined the initial account of the email intrusion.
Wiz’s analysis shifts the focus from the affected mailboxes to the trust boundary around the signing key. Microsoft’s dispute makes the technical scope—not merely attribution—the central unresolved issue.
First-order effects
Microsoft must counter or clarify the asserted service scope of the compromised MSA key, while affected organizations are left with uncertainty over whether the incident was confined to the previously identified email services.
The report puts renewed scrutiny on the authentication relationship between MSA-issued tokens and Microsoft-hosted services, even though Microsoft rejects Wiz’s conclusion.
Second-order effects
Enterprise and government customers may reassess incident-response assumptions that treat a cloud-email breach as isolated from other services when a shared signing credential is implicated.
Competitors and cloud-security providers gain a concrete case for emphasizing key isolation, token validation boundaries, and independently verifiable incident-scope disclosures.
Third-order effects
If disputes over signing-key blast radius recur, cloud providers will face stronger pressure to design identity systems with narrower, more auditable trust domains rather than relying on customers to accept provider scope assessments.
The broader shift is toward treating cloud identity infrastructure as critical shared infrastructure: failures in a single credential can become governance and transparency issues as much as technical ones.
The trend: This is one data point in the growing focus on how shared cloud identity keys can turn a limited account intrusion into a potentially wider service-boundary incident.
This @wiz_io blog post on the compromised Microsoft signing key (used by Storm-0558), confirms what many were worried about, but had no confirmation of: The scope the key was trusted in is MUCH larger than we thought. Let's review why that's an issue. 1/ https://www.wiz.io/...
This is a great and important blog post on some aspects of the Microsoft cloud breach that have been ascertained by open source analysis of info about the abused signing key and MS's auth systems. The implications for what is affected are worth thought. https://www.wiz.io/... [im…
😲 While Microsoft reported that the threat actors compromised Exchange Online and https://outlook.com/, the actual scope of at-risk applications was much broader!
@SwiftOnSecurity The Wiz's analysis is excellent. They got more detail than I would have superficially thought possible just by focusing on the what specific signing key was used and looking at the accompanying public info + information available about how Microsoft's cloud auth …
🔑 The compromised Microsoft signing key potentially allows the threat actors to forge access tokens for ALL Microsoft's personal account services and any Azure Active Directory (AAD) applications supporting both multi-tenancy and Microsoft's OpenID v2.0 implementation. [image]
The @wiz_io research team dug into Microsoft's recently disclosed compromise of an MSA key and discovered that the potential impact was much broader than many initially understood. Our new blog shares details & recommendations for Azure app owners: https://www.wiz.io/...
This is pretty high praise of the Wiz write up on the Microsoft compromise, which I found impressively detailed but could not judge technically. https://www.wiz.io/...
Vendors will jump on big events and sometimes not really contribute more than what's in the original blog post plus some commentary, this adds to the discussion.