{"id":3509,"date":"2020-12-31T13:01:00","date_gmt":"2020-12-31T18:01:00","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=3509"},"modified":"2021-01-05T13:09:14","modified_gmt":"2021-01-05T18:09:14","slug":"russian-hacking-exposes-microsoft-source-code","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2020\/12\/russian-hacking-exposes-microsoft-source-code\/","title":{"rendered":"Russian hacking exposes Microsoft source code"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-12-31\/microsoft-says-suspected-russian-hackers-viewed-source-code\">Bloomberg<\/a> reports Microsoft Corp. said that the alleged hackers behind the impressive attacks on numerous U.S. government agencies also accessed the company&#8217;s internal source code. The company stressed that the hackers did not manage to make any changes to their source code, but acknowledged that they had access to it, without clarifying for how long or which programs the impacted files corresponded to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We detected unusual activity with a small number of internal accounts and upon review, we discovered one account had been used to view source code in a number of source code repositories,&#8221; Microsoft said Thursday in a blog post that it is continually updating with data on the attack investigation. &#8220;The account did not have permissions to modify any code or engineering systems and our investigation further confirmed no changes were made.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A Microsoft spokesperson did not want to say what source code the hackers had access to. The source code shows how computer programs work and are used to create products. Accessing this code could have given hackers valuable information about how to exploit vulnerabilities within programs or avoid detection. Microsoft said that its security philosophy, or &#8220;threat model,&#8221; anticipates that its source code could be compromised and that defense tools are created with that in mind.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Previously Microsoft said it had received a malicious software update from the information technology provider SolarWinds Corp, which could have been used in the attack on government bodies and companies around the world. For the most part, the details are still unknown, such as the number of organizations that were victims and what type of information the hackers obtained. In December, Bloomberg News reported that investigators determined that at least 200 organizations had been compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cyber-attack could have begun in October 2019 and could still be active, according to US authorities, who consider it &#8216;enormously difficult&#8217; to completely restore security to the affected systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft said that the hackers did not use the SolarWinds update to access the internal account, but refused to give details about how they gained access. The company also did not specify in its publication which code repositories they had access to, or how long the hackers had been on the company&#8217;s network, but reiterated that there is no indication that their systems had been used to attack others.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u00e2\u20ac\u0153This activity has not put at risk the security of our services or any customer data, but we want to be transparent and share what we\u00e2\u20ac\u2122re learning as we combat what we believe is a very sophisticated nation-state actor,\u00e2\u20ac\u009d the company said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bloomberg reports Microsoft Corp. said that the alleged hackers behind the impressive attacks on numerous U.S. government agencies also accessed the company&#8217;s internal source code. The company stressed that the hackers did not manage to make any changes to their source code, but acknowledged that they had access to it, without clarifying for how long<\/p>\n","protected":false},"author":11,"featured_media":3510,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-3509","post","type-post","status-publish","format-standard","has-post-thumbnail","category-dedicated-server-best-practices"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/3509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=3509"}],"version-history":[{"count":1,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/3509\/revisions"}],"predecessor-version":[{"id":3511,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/3509\/revisions\/3511"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/3510"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=3509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=3509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=3509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}