WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Threat Awareness – Impacts of Stolen Microsoft Encryption Key Potentially Extend to Other Microsoft Platforms
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Impacts of Stolen Microsoft Encryption Key Potentially Extend to Other Microsoft Platforms

Author: April Zupan

Created: Tuesday, July 25, 2023 - 18:47

Categories: Cybersecurity

Wiz has posted a blog discussing the implications of the recently announced security incident affecting Microsoft where a Chinese-attributed threat actor stole a private encryption key to forge access tokens for various Outlook products. After conducting further technical analysis, researchers believe that this stolen key could also impact users of Azure Active Directory, SharePoint, Teams, and OneDrive.

Specifically, the stolen key was used for signing OpenID v2.0 access tokens for personal accounts and mixed-audience Azure Active Directory applications, which means the incident is believed to have a much wider impact than initially reported. Wiz provides recommended steps for organizations who use potentially compromised applications in their environment. While Microsoft advised customers it believed were impacted, members are encouraged to review the joint cybersecurity advisory on Enhanced Monitoring to Detect APT Activity Targeting Outlook Online from CISA and the FBI and address accordingly. Read more at Wiz.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Zero-Day Vulnerability in Microsoft Exchange Under Active Exploitation, CVE-2026-42897

May 19, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability Affecting Cisco Catalyst SD-WAN, CVE-2026-20182

May 19, 2026 in Cybersecurity, Security Preparedness

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar