Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"approximately 25 organizations" using "an acquired Microsoft account (MSA) consumer signing key"

How did an acquired consumer signing key allow them to penetrate 25 organizations?

> token validation issue

wish we knew exactly what that was so we could gauge long-range impact, because the probability is 1 that there are more victims.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: