AIRLINK 196.38 Increased By ▲ 4.54 (2.37%)
BOP 10.11 Increased By ▲ 0.24 (2.43%)
CNERGY 7.75 Increased By ▲ 0.08 (1.04%)
FCCL 38.10 Increased By ▲ 0.24 (0.63%)
FFL 15.74 Decreased By ▼ -0.02 (-0.13%)
FLYNG 24.54 Decreased By ▼ -0.77 (-3.04%)
HUBC 130.38 Increased By ▲ 0.21 (0.16%)
HUMNL 13.73 Increased By ▲ 0.14 (1.03%)
KEL 4.60 Decreased By ▼ -0.07 (-1.5%)
KOSM 6.19 Decreased By ▼ -0.02 (-0.32%)
MLCF 44.85 Increased By ▲ 0.56 (1.26%)
OGDC 206.51 Decreased By ▼ -0.36 (-0.17%)
PACE 6.58 Increased By ▲ 0.02 (0.3%)
PAEL 39.77 Decreased By ▼ -0.78 (-1.92%)
PIAHCLA 17.20 Decreased By ▼ -0.39 (-2.22%)
PIBTL 7.99 Decreased By ▼ -0.08 (-0.99%)
POWER 9.20 Decreased By ▼ -0.04 (-0.43%)
PPL 178.91 Increased By ▲ 0.35 (0.2%)
PRL 38.93 Decreased By ▼ -0.15 (-0.38%)
PTC 24.31 Increased By ▲ 0.17 (0.7%)
SEARL 109.27 Increased By ▲ 1.42 (1.32%)
SILK 1.00 Increased By ▲ 0.03 (3.09%)
SSGC 37.75 Decreased By ▼ -1.36 (-3.48%)
SYM 18.83 Decreased By ▼ -0.29 (-1.52%)
TELE 8.53 Decreased By ▼ -0.07 (-0.81%)
TPLP 12.14 Decreased By ▼ -0.23 (-1.86%)
TRG 64.76 Decreased By ▼ -1.25 (-1.89%)
WAVESAPP 12.11 Decreased By ▼ -0.67 (-5.24%)
WTL 1.64 Decreased By ▼ -0.06 (-3.53%)
YOUW 3.87 Decreased By ▼ -0.08 (-2.03%)
BR100 12,000 Increased By 69.2 (0.58%)
BR30 35,548 Decreased By -112 (-0.31%)
KSE100 114,256 Increased By 1049.3 (0.93%)
KSE30 35,870 Increased By 304.3 (0.86%)

WASHINGTON: The hacking group behind the SolarWinds compromise was able to break into Microsoft Corp and access some of its source code, Microsoft said on Thursday, something experts said sent a worrying signal about the spies’ ambition.

Source code - the underlying set of instructions that run a piece of software or operating system - is typically among a technology company’s most closely guarded secrets and Microsoft has historically been particularly careful about protecting it.

It is not clear how much or what parts of Microsoft’s source code repositories the hackers were able to access, but the disclosure suggests that the hackers who used software company SolarWinds as a springboard to break into sensitive US government networks also had an interest in discovering the inner workings of Microsoft products as well.

Microsoft had already disclosed that like other firms it found malicious versions of SolarWinds’ software inside its network, but the source code disclosure - made in a blog post - is new. After Reuters reported it was breached two weeks ago, Microsoft said it had not “found any evidence of access to production services.”

Three people briefed on the matter said Microsoft had known for days that the source code had been accessed. A Microsoft spokesman said security employees had been working “around the clock” and that “when there is actionable information to share, they have published and shared it.”

The SolarWinds hack is among the most ambitious cyber operations ever disclosed, compromising at least half-a-dozen federal agencies and potentially thousands of companies and other institutions. US and private sector investigators have spent the holidays combing through logs to try to understand whether their data has been stolen or modified.

Modifying source code - which Microsoft said the hackers did not do - could have potentially disastrous consequences given the ubiquity of Microsoft products, which include the Office productivity suite and the Windows operating system. But experts said that even just being able to review the code could offer hackers insight that might help them subvert Microsoft products or services.

“The source code is the architectural blueprint of how the software is built,” said Andrew Fife of Israel-based Cycode, a source code protection company.

“If you have the blueprint, it’s far easier to engineer attacks.”

Matt Tait, an independent cybersecurity researcher, agreed that the source code could be used as a roadmap to help hack Microsoft products, but he also cautioned that elements of the company’s source code were already widely shared - for example with foreign governments. He said he doubted that Microsoft had made the common mistake of leaving cryptographic keys or passwords in the code.

“It’s not going to affect the security of their customers, at least not substantially,” Tait said.

Microsoft noted that it allows broad internal access to its code, and former employees agreed that it is more open than other companies.

In its blog post, Microsoft said it had found no evidence of access “to production services or customer data.”

“The investigation, which is ongoing, has also found no indications that our systems were used to attack others,” it said.

Comments

Comments are closed.