TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft government email compromised (and quietly fixed)

21 点作者 deckiedan将近 2 年前

2 条评论

donmcronald将近 2 年前
&gt; They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key.<p>How does that work? Is the key part of some kind of complex auth flow where it&#x27;s only allowed to sign tokens that have Exchange access?<p>A compromised key that can sign authentication tokens seems like a pretty big deal.
评论 #36701159 未加载
nonfamous将近 2 年前
Actual title of linked article: &quot;Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email&quot;