/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says SolarWinds hackers were able to view some of its source code by hacking into an employee account but were unable to modify code or access emails

The hackers gained more access than the company previously revealed, though the attackers were unable to modify code or access emails.

New York Times Nicole Perlroth

Discussion

  • @ericgeller Eric Geller on x
    After initially issuing a statement that dismissed reports that it had been hacked, Microsoft now admits that hackers breached its network and viewed (but didn't modify) its products' source code as part of the SolarWinds affair. https://msrc-blog.microsoft.com/ ...
  • @razhael Raphael Satter on x
    Our story, with a focus on some of the unanswered questions: - What repositories were accessed? - How long did the hackers have access? - And, as @ronen_sl puts it: “Was this recon for the next big operation?” https://www.reuters.com/...
  • @fxshaw Frank X. Shaw on x
    Providing transparency about the Solarigate incident: https://msrc-blog.microsoft.com/ ...
  • @malwarejake Jake Williams on x
    Grab your popcorn folks, 2021 is going to be lit. https://www.reuters.com/...
  • @gregotto Greg Otto on x
    Hmm wow i remember some people getting on this website and saying that this was not the case, hmm how about that https://twitter.com/...
  • @briankrebs @briankrebs on x
    Microsoft says its investigation into malicious SolarWinds code in its systems found no evidence attackers used that to forge single sign-on tokens for its corporate domains. But it did find the intruders viewed (but didn't alter) Microsoft source code. https://msrc-blog.microsof…
  • @nicoleperlroth Nicole Perlroth on x
    As grim as it sounds, MSFT (*unlike Apple and other cos) doesn't rely on the secrecy of source code for security, so employees can readily view source code and its threat model assumes attackers have access to it. But it does expand the scope of the attack.
  • @mrphs Nima Fatemi on x
    What a better chance for Microsoft to go fully open source 🙃 https://twitter.com/...
  • @malwarejake Jake Williams on x
    This story is getting a lot of attention. Let me quickly break down for followers not in offensive security what it means. This is not great, but *the sky isn't falling*. Anyone who says this will immediately result in {thing} is uninformed (or worse) 1/ https://www.reuters.com/.…
  • @nicoleperlroth Nicole Perlroth on x
    NEW: Microsoft says SolarWinds hackers successfully viewed source code, accessed network, did not breach products/cloud or use its systems to attack other targets. https://www.nytimes.com/...
  • @williamturton William Turton on x
    Microsoft said the suspected Russian hackers behind the stunning breach of numerous U.S. government agencies also accessed the company's internal source code https://www.bloomberg.com/... via @technology
  • @timstarks Tim Starks on x
    Microsoft updates on its SolarWinds-related investigation (Solorigate/SUNBURST) saying, more or less, coast is clear on its end. https://msrc-blog.microsoft.com/ ...
  • @dalperovitch Dmitri Alperovitch on x
    More shoes keep dropping from the #SolarWindsHack fallout. Many more to come yet https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    The hacking group behind the SolarWinds compromise was able to break into Microsoft and access some of the company's source code, the software giant said Thursday. https://www.reuters.com/...
  • @razhael Raphael Satter on x
    New: Microsoft says #SolarWinds hackers were able to access “a number of source code repositories.” However, the company adds that it “found no indications that our systems were used to attack others.” https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @malwarejake Jake Williams on x
    As MSFT notes in their blog post, they have embraced an open source threat modeling approach - assume the code will become open and don't tie security to secrecy. With some companies, you might hear that and call BS. Don't do that here. 3/ https://msrc-blog.microsoft.com/ ... htt…
  • @stevesi Steven Sinofsky on x
    Microsoft Says Russian Hackers Viewed Some of Its Source Code - The New York Times // HNY https://www.nytimes.com/...
  • @shanvav Shannon Vavra on x
    New Microsoft alert on SolarWinds breach: “we discovered 1 account had been used to view source code in a number of source code repositories. The account did not have permissions to modify any code” — MSFT says its services & customer data aren't at risk. https://msrc-blog.micros…
  • @jessedamiani Jesse Damiani on x
    Microsoft Says Russian Hackers Viewed Some of Its Source Code. The hackers gained more access than the company previously revealed, though the attackers were unable to modify code or access emails. https://www.nytimes.com/...
  • @kimzetter Kim Zetter on x
    Microsoft new info on its SW infection. “We detected unusual activity with a small number of internal accounts...one...had been used to view source code in...source code repositories. The account did not have permissions to modify any code or... systems... https://msrc-blog.micro…
  • @780thc @780thc on x
    Microsoft Internal Solorigate Investigation Update: “We detected unusual activity with a small number of internal accounts and upon review, we discovered one account had been used to view source code in a number of source code repositories.” https://msrc-blog.microsoft.com/ ...
  • @bespokeinvest Bespoke on x
    “Microsoft, unlike many technology companies, does not rely on the secrecy of its source code” https://www.nytimes.com/...