This
@wiz_io blog post on the compromised Microsoft signing key (used by Storm-0558), confirms what many were worried about, but had no confirmation of: The scope the key was trusted in is MUCH larger than we thought. Let's review why that's an issue
https://foxdeo.com/17Ie.tnk