Why Nostr? What is Njump?
2024-04-03 13:08:25
in reply to

Taggart :donor: on Nostr: Savage. Basically Microsoft has no evidence to verify its theory of the attack. > ...

Savage. Basically Microsoft has no evidence to verify its theory of the attack.

> Microsoft learned that, in 2021, Storm-0558 had accessed a variety of documents stored in SharePoint and assessed that the threat actor was specifically looking for information on Azure service management and identity-related information. Despite Microsoft’s pursuit of the 46 key-theft hypotheses, the Board assesses that Microsoft does not know how Storm-0558 obtained the 2016 MSA key. Microsoft stated in a September 6, 2023 blog post that the most probable way Storm-0558 had obtained the key was from a crash dump to which it had access during the 2021 compromise of Microsoft’s systems. However, Microsoft had only theorized that such a scenario was technically feasible in the 2016 timeframe. While Microsoft updated this blog on March 12, 2024 to correct its assessment of these theories, it has not determined that this is how Storm-0558 obtained the key.
Author Public Key
npub14xx8pgqrkzr5wg8afzflp2724gjyvyxurhrfyk9739fu892p2evqhwcfzw