Serge Borso

210 posts

Serge Borso banner
Serge Borso

Serge Borso

@SergeBorso

Founder of SpyderSec SANS Course Author & Certified Instructor President of Denver OWASP chapter

Denver, CO Katılım Ekim 2013
2 Takip Edilen298 Takipçiler
Serge Borso retweetledi
Rob T. Lee
Rob T. Lee@robtlee·
We finally have more info about how exactly Microsoft was hacked by Chinese threat actors. It’s a doozy, so strap in. Back in June, hacking group Storm-0558 accessed the cloud-based Outlook email systems for 25 organizations, including at least two US government agencies. We finally know how they managed to pull it off. The hackers got their hands on a Microsoft account consumer signing key, all the way back in 2021. This cryptographic key is used to generate authentication ‘tokens’ that prove a user’s identity before they’re allowed to access data and services. This is usually stored in a highly isolated and restricted ‘production environment.’ However, during an April 2021 consumer signing system crash, the signing key made its way out of this secure environment and into a crash dump, which should not happen under normal circumstances. A race condition allowed the key to be present in the crash dump, which Microsoft did not know at the time, and this mass of data was subsequently moved from the isolated production network into the company’s debugging environment on the internet-connected corporate network. At some point after this, Storm-0558 successfully compromised a Microsoft engineer’s corporate account, which had access to the debugging environment containing the crash dump, and subsequently the signing key. @Microsoft’s explanation covers this whole controversy, and the company has since patched the accumulation of errors and issues that led to this, but the one missing link is how the threat actors got their hands on this engineer’s account. As my good friend Jacob Williams put it in the article below, “All the best hacks are deaths by 1,000 paper cuts, not something where you exploit a single vulnerability and then get all the goods.” Indeed, the best threat actors are cunning, patient and perseverent - so much so that they can infiltrate global corporations. Here’s the news story: wired.com/story/china-ba… Microsoft’s post-mortem report on the attack: msrc.microsoft.com/blog/2023/09/r…
English
5
139
435
76.4K
Serge Borso retweetledi
SANS Cloud Security
SANS Cloud Security@SANSCloudSec·
Join us for SANS Cloud Defender Dallas on Feb. 20 - 25 in Dallas, TX to experience hands-on training from top industry experts. Now is the time to become a #SANSCloudAce! 🤔 Do you know the benefits of attending in-person sans.org/u/1oqt #SANSCloudDevOps
SANS Cloud Security tweet media
English
0
3
6
663
Serge Borso
Serge Borso@SergeBorso·
@ManieshNeupane Interesting list. Definitely some good tidbits. Curious if anyone has ever done #15 or has even heard of some doing #15 in a real world scenario. I would be surprised.
English
0
0
0
0
Serge Borso retweetledi
SANS Cloud Security
SANS Cloud Security@SANSCloudSec·
Ready, set & deploy! ☁️ 🖥️ On Thursday, 13 Oct, learn how to deploy & configure a #VirtualMachine in the #Cloud with @SergeBorso, SANS Certified Instructor at our FREE 2-hour, hands-on workshop. Limited space 🔥 - only 500 spots available. Register: sans.org/u/1mP7
SANS Cloud Security tweet media
English
0
1
1
0
Serge Borso retweetledi
SANS Cloud Security
SANS Cloud Security@SANSCloudSec·
Want to learn how experts solve for the #Security concerns surrounding virtual machines in a cloud ☁️ environment? Now's your chance. Join us Live Online, Oct 13 for a FREE 2-hour workshop led by @SergeBorso, SANS Certified Instructor. Register: sans.org/u/1mP2
SANS Cloud Security tweet media
English
0
3
4
0
Serge Borso retweetledi
SANS Cloud Security
SANS Cloud Security@SANSCloudSec·
Decided to make a career change to take advantage of the job opportunities in cloud security? #SEC388 from @sergeborso is the perfect starting point for your journey into #cloudsecurity No time like the present! Reg now for inaugural run Aug 29-31! sans.org/u/1lmt
SANS Cloud Security tweet media
English
0
2
2
0
Serge Borso retweetledi
SANS Cloud Security
SANS Cloud Security@SANSCloudSec·
LAST CALL #SEC388 Inaugural run Aug 29-31 Ground School for Cloud Security @sergeborso provides the knowledge needed to confidently speak to modern #cybersecurity issues brought on by cloud, & become well versed with applicable terminology. Reg Now! sans.org/u/1lmt
SANS Cloud Security tweet media
English
0
2
2
0