SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
hector_titucius [he/him]@hexbear.net to chapotraphouse@hexbear.netEnglish · 2 years ago

🫡🫡🫡Link in description

hexbear.net

message-square
21
fedilink
62

🫡🫡🫡Link in description

hexbear.net

hector_titucius [he/him]@hexbear.net to chapotraphouse@hexbear.netEnglish · 2 years ago
message-square
21
fedilink

https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/

  • blobjim [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 years ago

    Pretend to be someone they aren’t

    An actor that can acquire a private signing key can then create falsified tokens with valid signatures that will be accepted by relying parties. This is called token forgery.

    • mustardman [none/use name]@hexbear.net
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 years ago

      Oh cool so they can distribute updates?

      • blobjim [he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 years ago

        The article just says they signed authentication tokens which gave them access to outlook emails. I don’t think it was code signing that would let them distribute software, and that’s not what they were after.

        • mustardman [none/use name]@hexbear.net
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 years ago

          Thanks for actually reading the article o7

chapotraphouse@hexbear.net

chapotraphouse@hexbear.net

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !chapotraphouse@hexbear.net

Banned? DM Wmill to appeal.

No anti-nautilism posts. See: Eco-fascism Primer

Slop posts go in c/slop. Don’t post low-hanging fruit here.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 776 users / day
  • 1.67K users / week
  • 2.65K users / month
  • 5.25K users / 6 months
  • 30 local subscribers
  • 13.8K subscribers
  • 20.5K Posts
  • 303K Comments
  • Modlog
  • mods:
  • LENINSGHOSTFACEKILLA [he/him]@hexbear.net
  • MiraculousMM [he/him, any]@hexbear.net
  • Nakoichi [they/them]@hexbear.net
  • corgiwithalaptop [any, love/loves]@hexbear.net
  • PorkrollPosadist [he/him, they/them]@hexbear.net
  • ZoomeristLeninist [they/them, she/her]@hexbear.net
  • EmmaGoldman [she/her, comrade/them]@hexbear.net
  • sweet_pecan [love/loves, they/them]@hexbear.net
  • a_little_red_rat [he/him, comrade/them]@hexbear.net
  • khizuo [ze/zir]@hexbear.net
  • gaystyleJoker [she/her]@hexbear.net
  • thelastaxolotl [he/him]@hexbear.net
  • context [fae/faer, fae/faer]@hexbear.net
  • Infamousblt [any]@hexbear.net
  • Sulvy [he/him, comrade/them]@hexbear.net
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org