Arab Press

بالشعب و للشعب
Saturday, Feb 22, 2025

SolarWinds hackers accessed Microsoft source code, the company says

SolarWinds hackers accessed Microsoft source code, the company says

The hacking group behind the SolarWinds compromise was able to break into Microsoft Corp and access some of its source code, Microsoft said on Thursday, something experts said sent a worrying signal about the spies' ambition.
Source code - the underlying set of instructions that run a piece of software or operating system - is typically among a technology company's most closely guarded secrets and Microsoft has historically been particularly careful about protecting it.

It is not clear how much or what parts of Microsoft's source code repositories the hackers were able to access, but the disclosure suggests that the hackers who used software company SolarWinds as a springboard to break into sensitive U.S. government networks also had an interest in discovering the inner workings of Microsoft products as well.

Microsoft had already disclosed that like other firms it found malicious versions of SolarWinds' software inside its network, but the source code disclosure - made in a blog post - is new. After Reuters reported it was breached two weeks ago, Microsoft said it had not "found any evidence of access to production services."

Three people briefed on the matter said Microsoft had known for days that the source code had been accessed. A Microsoft spokesman said security employees had been working "around the clock" and that "when there is actionable information to share, they have published and shared it."

The SolarWinds hack is among the most ambitious cyber operations ever disclosed, compromising at least half-a-dozen federal agencies and potentially thousands of companies and other institutions. U.S. and private sector investigators have spent the holidays combing through logs to try to understand whether their data has been stolen or modified.

Modifying source code - which Microsoft said the hackers did not do - could have potentially disastrous consequences given the ubiquity of Microsoft products, which include the Office productivity suite and the Windows operating system. But experts said that even just being able to review the code could offer hackers insight that might help them subvert Microsoft products or services.

"The source code is the architectural blueprint of how the software is built," said Andrew Fife of Israel-based Cycode, a source code protection company.

"If you have the blueprint, it's far easier to engineer attacks."

Matt Tait, an independent cybersecurity researcher, agreed that the source code could be used as a roadmap to help hack Microsoft products, but he also cautioned that elements of the company's source code were already widely shared - for example with foreign governments. He said he doubted that Microsoft had made the common mistake of leaving cryptographic keys or passwords in the code.

"It's not going to affect the security of their customers, at least not substantially," Tait said.

Microsoft noted that it allows broad internal access to its code, and former employees agreed that it is more open than other companies.

In its blog post, Microsoft said it had found no evidence of access "to production services or customer data."

"The investigation, which is ongoing, has also found no indications that our systems were used to attack others," it said.

Reuters reported a week ago that Microsoft-authorized resellers were hacked and their access to productivity programs inside targets leveraged in attempts to read email. Microsoft acknowledged some vendor access was misused but has not said how many resellers or customers may have been breached.

There was no response to requests for comment from the FBI, which is investigating the hacking campaign, or from the Department of Homeland Security's Cybsersecurity and Infrastructure Security Agency.

U.S. officials have attributed the SolarWinds hacking campaign to Russia, an allegation the Kremlin denies.

Both Tait and Ronen Slavin, Cycode's chief technology officer, said a key unanswered question was which source code repositories were accessed. Microsoft has a huge range of products, from widely used Windows to lesser known software such as social networking app Yammer and the design app Sway.

Slavin said he was worried by the possibility that the SolarWinds hackers were poring over Microsoft's source code as prelude to a much more ambitious offensive.

"To me the biggest question is, 'Was this recon for the next big operation?'" he said.
Comments

Oh ya 4 year ago
What will be really funnyvis the day you go to use your bitcoin and find its all gone. Poof, no more , chit out of luck, a fool and his money...........

Newsletter

Related Articles

Arab Press
0:00
0:00
Close
The negotiation teams of Trump and Putin meet directly, establishing the groundwork for a significant advance.
Israeli Minister Urges Hamas to Surrender and Depart from Gaza.
Iran Considers Moving Its Capital Due to Urban Difficulties
Israel and Hamas Finalize Sixth Exchange of Hostages and Prisoners During Continuing Gaza Ceasefire
Leaders of BRICS to Gather in Rio de Janeiro for July Summit
Muhsin Hendricks, a trailblazing openly gay imam, was killed in South Africa.
Trump's special envoy for hostage affairs cautions Hamas against challenging Trump before Saturday's deadline.
Two British citizens apprehended in Iran amid escalating tensions.
Israel Issues Threat of Military Action as Hostage Negotiations with Hamas Continue
Hamas Coordinates Worldwide Solidarity Marches in Reaction to U.S. and Israeli Initiative
Israel Warns of Ending Gaza Ceasefire Due to Hostage Situation
King Abdullah II Dismisses US Proposal to Relocate Palestinians, Commits to Welcoming Gaza Children.
Lebanon Installs New Government with Hezbollah's Impact on Key Ministries
Report: Iran Attempted to Assassinate Trump During Election Campaign
U.S. Authorizes $7.4 Billion Arms Sale to Israel
Iran's Supreme Leader Rejects Nuclear Negotiations with the U.S.
UN Chief Denounces Trump's Gaza Plan, Cautions Against Ethnic Cleansing
Pressure Intensifies for a Free Trade Agreement between the UK and GCC in Light of Economic Difficulties
Israel to Withdraw from UN Human Rights Council Due to Accusations of Anti-Semitism
EU Reaffirms Gaza's Essential Role in Future Palestinian State Following Trump's Proposal
Iranian Currency Reaches All-Time Low Amid US 'Maximum Pressure' Initiative.
UN Reaffirms Ban on Deportation from Occupied Territories Amid US Gaza Proposal
Palestinians Fear Repeat of 'Nakba' Amid Ongoing Crisis in Gaza
UAE Aids in the Exchange of 300 Prisoners Between Russia and Ukraine
Egypt Seeks Global Backing for Two-State Solution Following US Proposal for Gaza Plan
Trump's Suggestion to 'Seize Control' of Gaza Represents a Significant Shift in US Policy
French President is the first EU leader to extend congratulations to the new Syrian President.
Tunisian President Appoints New Finance Minister Amid Economic Crisis
Trump Suggests U.S. 'Takeover' of Gaza, Prompting Global Worries
Trump's Proposal for Gaza Provokes Global Debate
President Trump Suggests Moving Gaza's Palestinian Population
Aga Khan IV, Spiritual Leader and Philanthropist, Dies at 88
Erdogan and Syria's Sharaa Talk About Collaboration to Counter Kurdish Militants
Trump Suggests U.S. Control of Gaza Strip Amid Ongoing Conflict
Trump Resumes 'Maximum Pressure' Strategy to Limit Iran's Oil Exports.
Ex-British Soldier Sentenced for Espionage on Behalf of Iran and Fleeing from Prison
Gazans in Egypt Reject Displacement, Struggle with Return to War-Torn Home
Queen Rania Urges Protection of Children’s Rights at Vatican Summit
Hamas Officials Ready to Begin Negotiations for Phase Two of Gaza Truce
Trump Expresses Caution Over Gaza Ceasefire as Netanyahu Visits Washington
Oman to Host 18th Indian Ocean Conference on Maritime Security and Trade
Emir of Kuwait Meets BlackRock CEO for Talks on Investment Opportunities
Queen Rania of Jordan Calls for Global Action on Children’s Rights at Vatican Summit
Egyptian President El-Sisi Invited for White House Meeting Following Jordanian King’s Visit
Queen Rania Calls for Protection of Children’s Rights at Vatican Summit
Israeli Military Operations Continue on Lebanon Border Amid Ceasefire Tensions
Israeli Hostage's Release Highlights Uncertainty Over Family's Fate
Israeli Military Operations Escalate in Southern Lebanon Amid Hezbollah Tensions
Zayed Award for Human Fraternity Announces 2025 Honorees
Kuwait Anticipates a 12% Increase in Budget Deficit for the 2025-2026 Fiscal Year
×