Microsoft says SolarWinds hackers were able to view some of its source code by hacking into an employee account but were unable to modify code or access emails
The hackers gained more access than the company previously revealed, though the attackers were unable to modify code or access emails.
New York TimesNicole Perlroth
Context & Ripple Effects
Microsoft’s disclosure initially bounded the breach: attackers could inspect some source code through an employee account, but Microsoft said they could not alter code or read email. Its subsequent investigation similarly reported stolen source code but no evidence of abuse of internal systems, reinforcing the distinction between exposure and tampering.
Later related reports broadened the access-control picture. Suspected SolarWinds attackers used a compromised customer-service agent account to target customers, while the campaign was also tied to malicious messages sent through a State Department aid-agency email system to 150 organizations.
First-order effects
Microsoft must assess what the viewed source code revealed about its internal systems while treating code integrity and employee email as unaffected within the scope it reported.
The disclosure gives Microsoft customers and developers a more precise incident boundary: source-code visibility occurred, but Microsoft reported no ability to modify that code or access email.
Second-order effects
The later customer-service-agent breach puts privileged support access alongside developer access as a critical control point for Microsoft, because either can create a route to downstream customer targeting.
Organizations receiving malicious aid-agency emails face a more immediate operational threat than Microsoft’s source-code exposure alone, showing how compromised administrative access can be converted into outbound attacks.
Third-order effects
If this access pattern persists, software suppliers will be judged less only on whether code was changed and more on whether identity-linked administrative accounts can expose customers, code, or communications.
The SolarWinds episode points toward security programs that prioritize containment of privileged accounts across development, support, and messaging systems rather than treating source-code repositories as the sole high-value target.
The trend: The broader trend is a shift from code-integrity-focused breach response toward securing the privileged identities that connect software vendors to customer and communications systems.
After initially issuing a statement that dismissed reports that it had been hacked, Microsoft now admits that hackers breached its network and viewed (but didn't modify) its products' source code as part of the SolarWinds affair. https://msrc-blog.microsoft.com/ ...
Our story, with a focus on some of the unanswered questions: - What repositories were accessed? - How long did the hackers have access? - And, as @ronen_sl puts it: “Was this recon for the next big operation?” https://www.reuters.com/...
Microsoft says its investigation into malicious SolarWinds code in its systems found no evidence attackers used that to forge single sign-on tokens for its corporate domains. But it did find the intruders viewed (but didn't alter) Microsoft source code. https://msrc-blog.microsof…
As grim as it sounds, MSFT (*unlike Apple and other cos) doesn't rely on the secrecy of source code for security, so employees can readily view source code and its threat model assumes attackers have access to it. But it does expand the scope of the attack.
This story is getting a lot of attention. Let me quickly break down for followers not in offensive security what it means. This is not great, but *the sky isn't falling*. Anyone who says this will immediately result in {thing} is uninformed (or worse) 1/ https://www.reuters.com/.…
NEW: Microsoft says SolarWinds hackers successfully viewed source code, accessed network, did not breach products/cloud or use its systems to attack other targets. https://www.nytimes.com/...
Microsoft said the suspected Russian hackers behind the stunning breach of numerous U.S. government agencies also accessed the company's internal source code https://www.bloomberg.com/... via @technology
Microsoft updates on its SolarWinds-related investigation (Solorigate/SUNBURST) saying, more or less, coast is clear on its end. https://msrc-blog.microsoft.com/ ...
The hacking group behind the SolarWinds compromise was able to break into Microsoft and access some of the company's source code, the software giant said Thursday. https://www.reuters.com/...
New: Microsoft says #SolarWinds hackers were able to access “a number of source code repositories.” However, the company adds that it “found no indications that our systems were used to attack others.” https://msrc-blog.microsoft.com/ ... https://twitter.com/...
As MSFT notes in their blog post, they have embraced an open source threat modeling approach - assume the code will become open and don't tie security to secrecy. With some companies, you might hear that and call BS. Don't do that here. 3/ https://msrc-blog.microsoft.com/ ... htt…
New Microsoft alert on SolarWinds breach: “we discovered 1 account had been used to view source code in a number of source code repositories. The account did not have permissions to modify any code” — MSFT says its services & customer data aren't at risk. https://msrc-blog.micros…
Microsoft Says Russian Hackers Viewed Some of Its Source Code. The hackers gained more access than the company previously revealed, though the attackers were unable to modify code or access emails. https://www.nytimes.com/...
Microsoft new info on its SW infection. “We detected unusual activity with a small number of internal accounts...one...had been used to view source code in...source code repositories. The account did not have permissions to modify any code or... systems... https://msrc-blog.micro…