>

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email
>