The information that is emerging about Russia’s extensive cyberintelligence operation against the United States and other countries systems should be increasingly alarming to the public. The magnitude of the hacking, now believed to have affected more than 250 federal agencies and businesses such as Microsoft — primarily through a malicious update of the SolarWinds network management software — may have slipped under most people’s radar during the holiday season, but its implications are stunning.
Microsoft said Thursday in a blog post that hackers tied to a massive intrusion of dozens of US government agencies and private companies sneaked further into its systems than previously thought, although the intrusion doesn’t appear to have caused any additional harm. The company said the hackers were able to view some of the code underlying Microsoft software, but weren’t able to make any changes to it.
Microsoft played down any risk associated with the additional intrusion, noting that its software development relies on code sharing within the company, a practice called “inner source,” the AP reports. Likewise, Microsoft said it doesn’t rely on keeping program code secret as a security measure and instead assumes that adversaries have seen its code and uses other defensive measures to frustrate attacks.
The company said it found no evidence of hacker access to customer data and no indication that its systems were used to attack others. The hack began as early as March when malicious code was snuck into updates to SolarWinds software that monitors computer networks.
Microsoft helped respond to the breach with cybersecurity firm FireEye, which discovered the hack when the security firm itself was targeted. Cybersecurity experts and US officials suspect Russia was behind the hack. Microsoft said earlier this month that it identified more than 40 government agencies, think tanks, nongovernmental organizations, and IT companies infiltrated by the hackers. Russia has denied that it is to blame.
2 Comments
Pingback: SolarWinds Hack: The More we Learn, The Worse it Looks - Innovation Village
Pingback: US Intelligence Confirms SolarWinds Hack Culprits 'Likely Russian' - Innovation Village