Microsoft admits that hacker Lapsus$ stole the source code
After investigation, Microsoft itself now has to admit that a group of hackers known by the company as DEV-0537 compromised "a single account" and stole part of the source code of some of its products.
The company's security blog post said that Microsoft investigators have been tracking Lapsus$ for weeks now, as well as details of the method they used to penetrate the victim's system.
According to the Microsoft Threat Intelligence Center (MSTIC), "the goal of the DEV-0537 group is to gain high-level access through the theft of credentials to steal data and perform attacks." sabotage against the targeted organization, often leading to extortion. Tactics and targets indicate that this is a cybercrime fueled by theft and vandalism."
Microsoft also asserted that the leaked source code was not severe enough to pose a high risk and that the company's response team blocked the hacker's attack.
Lately, Lapsus$ has become a terror to major tech companies when the group claims to have collected data from companies including Okta, Samsung, Ubisoft, Nvidia and now Microsoft. While companies like Samsung and Nvidia acknowledged the data was stolen, Okta denied the group's claims, saying: "Okta's services were not compromised and remain fully functional."
This is not the first time Microsoft has suggested that attackers have gained access to their source code - something similar happened in the recent Solarwinds attack. Lapsus$ also admitted that it only had access to 45% of the Bing and Cortana source code and about 90% of the Bing Maps source code. Even so, the Bing Maps source code doesn't appear to be as valuable as the other two products even as Microsoft worries about the source code exposing their vulnerabilities.
In its blog post, Microsoft outlines several steps other organizations can take to improve their security, including multi-factor authentication, which doesn't use weak authentication methods. like SMS messages or secondary email addresses, train team members on the dangers of cyberattacks, and create a process to respond to attacks like Lapsus$'s.
You should read it
- The world lost $ 400 billion every year for cybercrime
- Be cautious when accessing the Internet the last days of the year
- Americans are more afraid of being hacked than afraid of being killed
- Lapsus$ hacker group claims to be in possession of Microsoft's source code
- Public service security: Increase investment
- Decode FBI spyware
- Spyware is the biggest threat on the web
- 5 tips to help you stay safer when investing in cryptocurrencies
May be interested
- If there is not enough ransom for the file, send an email to complain to the hacker, maybe you will get a surprise giftdue to the low income and inability to pay ransom, a victim sent an email to the hacker and received unexpected results.
- Hackers Use Malicious Google Ads to Steal Users' Microsoft Accountsthere is a dangerous trend being deployed by the global hacker community, which is abusing the google ads platform to spread malicious code.
- The source code for iOS is revealed on GitHub as 'real goods', this is the time to reveal the biggest information in historywith this source code, hackers, every security researcher can find the weakness of ios, the system that is supposed to be extremely secure. in the short term, this big hole will make jailbreak easier.
- In turn, Microsoft admitted being hacked because of the SolarWinds vulnerabilitymicrosoft has admitted that they were attacked by hackers through a vulnerability of solarwinds' software update system. however, the software giant denied that hackers used their software to infect users as well as customers.
- Has OpenAI had data about AI technology stolen by hackers in 2023?the new york times just had a shocking revelation: in early 2023, a hacker gained access to openai's internal messaging system and stole information about the company's ai technology.
- Official news: Microsoft acquired GitHub for $ 7.5 billionmicrosoft recently announced the price they spent to buy the $ 7.5 billion github source store page at microsoft 's stock price.
- 17 skills needed to become a hackerto become a professional hacker you need a lot of knowledge in both engineering and information technology. here are 17 skills you will need to have if you want to be a good hacker.
- Microsoft admits a new zero-day vulnerability threatens millions of Windows usersaccording to microsoft, this new zero-day vulnerability affects all versions of windows from windows 7 to windows 10 and corresponding versions of windows server.
- 10 professional code sample websites for programmersmost programmers have to do a lot of different tasks. knowing where to find free code samples online will help you learn and create applications.
- 6 best code editor apps for Macwhether you are a script writer or a black hat hacker, a programmer or professional code writer, you need a code editor application. if you choose to program on a mac instead of windows, here is a list of the best code editing tools you should use.