Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the accelerated-mobile-pages domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $options declared before required parameter $ad is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/advanced-ads/classes/display-conditions.php on line 208

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the easy-digital-downloads domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd_cfm domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edds domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $params declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutReturn.php on line 6

Deprecated: Optional parameter $insMessage declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutNotification.php on line 6

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the Newsmag domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-content/themes/Newsmag/functions.php on line 616

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-includes/feed-rss2.php on line 8
Microsoft source code viewed Archives - CISO MAG | Cyber Security Magazine Beyond Cyber Security Tue, 05 Jan 2021 06:59:49 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.1 SolarWinds Hackers Accessed Source Code: Microsoft https://staging-cisomagcom.kinsta.cloud/microsoft-source-code-viewed-in-solarwinds-hack/ Mon, 04 Jan 2021 14:13:35 +0000 https://staging-cisomagcom.kinsta.cloud/?p=8801 Microsoft has issued an update about its ongoing internal investigation of the SolarWinds hack that had reportedly compromised a few of its internal systems. The tech giant has now confirmed that it traced a compromised account used to “view source code” of its internal code structure. Earlier in December 2020, the entire world shook to […]

The post SolarWinds Hackers Accessed Source Code: Microsoft appeared first on CISO MAG | Cyber Security Magazine.

]]>
Microsoft has issued an update about its ongoing internal investigation of the SolarWinds hack that had reportedly compromised a few of its internal systems. The tech giant has now confirmed that it traced a compromised account used to “view source code” of its internal code structure.

Earlier in December 2020, the entire world shook to the tremors of the SolarWinds supply chain attack. The White House issued a press release stating multiple that government agencies and departments, including the U.S. Department of Treasury, a section of the U.S. Department of Commerce, and the National Nuclear Security Administration (NNSA), among others, were compromised during the widespread attack.

Mayday for Tech Giants

This hack was not just limited to the government institutions, but tech giants like Microsoft, Boeing, FireEye, etc., were also affected. In mid-December 2020, Microsoft, in an official notification, accepted that they “were hacked.” As a precautionary measure, they successfully created a Killswitch in collaboration with other industry heavyweights like FireEye and GoDaddy. The killswitch was devised to stop the spread of Sunburst malware. Microsoft further informed its partners and customers that the investigation of their compromise was ongoing and that they would issue regular updates about it.

Microsoft Issues Update

Staying true to its word, Microsoft issued an update of its internal investigation on New Year’s Eve. The update noted the following observations:

  • No evidence of the attackers accessing production services or customer data of Microsoft.
  • No indications of Microsoft’s systems being used to attack others.
  • No evidence of the common TTPs (tools, techniques, and procedures) related to the abuse of forged SAML tokens found being used against Microsoft’s corporate domains.
  • Detected unusual activity with a small number of internal accounts. Upon review, it was found that one of the compromised accounts was used to view source code in several source code repositories.
  • This unauthorized access has however not put Microsoft under any security risk as the compromised account had only viewing rights and no modification rights.
  • The affected accounts have now been remediated.
  • Evidence of multiple attempts to penetrate the systems has been recorded by Microsoft. However, its usage of Privileged Access Workstations (PAW) along with a host of other industry proposed standard protection practices made it possible to thwart these attacks.

Viewing the Source Code, No Big Deal!

Generally, when attackers gain access to the source code of any structure, software, application, and so on, it makes the developers break into a sweat simply because they can then find the vulnerabilities and attack them again in the future. However, Microsoft in its update suggested otherwise.

At Microsoft, we have an inner source approach – the use of open-source software development best practices and an open source-like culture – to making source code viewable within Microsoft. This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So, viewing source code is not tied to elevation of risk.

 

As with many companies, we plan our security with an ‘assume breach’ philosophy and layer in defense-in-depth protections and controls to stop attackers sooner when they do gain access.

The post SolarWinds Hackers Accessed Source Code: Microsoft appeared first on CISO MAG | Cyber Security Magazine.

]]>