>

Windows Recall: The Privacy Architecture Debate Before a Single Line Shipped

Announced May 20, 2024 as a Copilot+ flagship, Windows Recall promised searchable memory of everything on screen — and researchers found the archive in a plaintext SQLite database any user-context malware could read, with a runtime API to match. This account covers Kevin Beaumont's teardown, the TotalRecall extraction tool, the threat-model fallacies in each Microsoft defense, the June climb-down to opt-in plus Windows Hello and encryption, and the rare process win of an architecture changed before deployment.

Continue ReadingWindows Recall: The Privacy Architecture Debate Before a Single Line Shipped

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia's Midnight Blizzard a foothold inside Microsoft's own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email
>