While I’m talking about CISA, the Agency has partnered with MITRE to develop a cyberattack emulation platform for operational technology (OT) networks. The platform extends MITRE Caldera, an open-source tool that helps cybersecurity officials reduce the time and resources needed for routine cybersecurity testing. Caldera for OT provides defenders of industrial control systems better options for conducting security assessments and red-, blue-, and purple-teaming.
There’s been an update to the Microsoft cloud breach. Microsoft has revealed that a China-based threat actor known as Storm-0558 acquired the inactive consumer signing key to forge tokens and access Outlook by compromising an engineer’s corporate account. The breach was made possible by a crash dump that contained sensitive information and a race condition that allowed the key to be present in the dump. The breach highlights a series of cascading security mishaps that culminated in the signing key ending up in the hands of a skilled actor with a “high degree of technical tradecraft and operational security.”
A global study by Traceable AI has revealed significant gaps in API security worldwide. The report found that 74% of respondents reported at least three API-related breaches in the past two years, with DDoS being the primary API breach method. Additionally, 58% agree that APIs substantially expand organizations’ attack surface, and only 38% of respondents can discern intricate context between API activity, user behaviors, and data flow.
A new tool for some and insights for the rest of us. That Microsoft breach was very targeted – VERY targeted. That should give most of us relief, as this isn’t the kind of attack that comes for most organizations…. Except via the shared infrastructure of the cloud. As both consumers and implementors of technology, we should push for more insight and accountability – and controls, as offered in that API data.

