Has Microsoft Been Hacked?
#1
Exclamation 
Quote:Microsoft is investigating claims that internal source code repositories have been accessed and data has been stolen.

[Image: azure-folder-listing-scaled.webp]

The alleged hack is linked to the hacking group Lapsus$, which attacked companies such as Nvidia, Samsung and Vodafone in the past successfully.

Evidence of the hack emerged on Sunday evening when Tom Malka published screenshots on Twitter showing a Telegram conversation and what appears to be an internal folder listing of Microsoft source code repositories.

The screenshot suggests that the hackers downloaded source codes of Cortana and several Bing services. The post has been deleted in the meantime. Microsoft told Bleeping Computer that it is investigating the reports.

Unlike most extortion groups, which try to install ransomware on systems that they attack successful, Lapsus$ tries to get a ransom for downloaded data from the companies that it attacked.

The main services that Lapsus$ may have downloaded the source code from appear to be Bing, Bing Maps and Cortana. It is unclear at this point whether the full source codes have been downloaded by the attackers, and whether other Microsoft applications or services are included in the dump.

Source codes may contain valuable information. The code may be analyzed for security vulnerabilities that hacking groups may exploit. There is also the chance that source codes include valuable items such as code signing certificates, access tokens or API keys. Microsoft has a development policy in place that prohibits the inclusion of such items, Microsoft calls them secrets, in its source codes
 
Quote:The search terms used by the actor indicate the expected focus on attempting to find secrets. Our development policy prohibits secrets in code and we run automated tools to verify compliance.

Lots of uncertainty is surrounding the hack at this moment. Did Lapsus$ manage to breach Microsoft's defenses? Did the group manage to download data, and if it did, what data was downloaded and how complete is it? Bing, Bing Maps and Cortana are not the most important Microsoft services.

Judging by Lapsus$'s track record, it is likely that the reported hack did indeed happen. The question of whether the downloaded data is valuable enough to get a ransom from Microsoft for not publishing it on the Internet is open for debate.

Now You: was Microsoft hacked? What is your take on this?
[-] The following 1 user says Thank You to harlan4096 for this post:
  • ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Tor Browser 15.0.12
 Tor Browser 15.0....harlan4096 — 12:26
Mozilla Firefox Browser 150.0.2
Mozilla Firefox Br...harlan4096 — 10:49
AMD Radeon Adrenalin Edition 26.5.1
AMD Radeon Adrenal...harlan4096 — 10:48
AdGuard for iOS v4.5.20
AdGuard for iOS v4...harlan4096 — 10:46
Google Chrome 148.0.7778.96/97
Google Chrome 148....harlan4096 — 10:45

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (41)iruqi
avatar (42)saitetib
avatar (36)ypasodiny
avatar (39)omapek
avatar (48)Geraldtuh
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>