Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Microsoft Admits That Hacker Lapsus$ Stole the Source Code

Learn about Cybercrime, including how Cybercrime works, key uses, practical steps, common issues, and answers to frequently asked questions.

Table of Contents

This guide provides a clear overview of cybercrime, including the main concepts, practical steps, and common questions. Use it to understand the topic, compare the available options, and make a more informed decision.

The company's security blog post said that Microsoft investigators have been tracking Lapsus$ for weeks now, as well as details of the method they used to penetrate the victim's system.

Cybercrime guide image 1

According to the Microsoft Threat Intelligence Center (MSTIC), "the goal of the DEV-0537 group is to gain high-level access through the theft of credentials to steal data and perform attacks." sabotage against the targeted organization, often leading to extortion. Tactics and targets indicate that this is a cybercrime fueled by theft and vandalism."

Microsoft also asserted that the leaked source code was not severe enough to pose a high risk and that the company's response team blocked the hacker's attack.

Lately, Lapsus$ has become a terror to major tech companies when the group claims to have collected data from companies including Okta, Samsung, Ubisoft, Nvidia and now Microsoft. While companies like Samsung and Nvidia acknowledged the data was stolen, Okta denied the group's claims, saying: "Okta's services were not compromised and remain fully functional."

This is not the first time Microsoft has suggested that attackers have gained access to their source code - something similar happened in the recent Solarwinds attack. Lapsus$ also admitted that it only had access to 45% of the Bing and Cortana source code and about 90% of the Bing Maps source code. Even so, the Bing Maps source code doesn't appear to be as valuable as the other two products even as Microsoft worries about the source code exposing their vulnerabilities.

In its blog post, Microsoft outlines several steps other organizations can take to improve their security, including multi-factor authentication, which doesn't use weak authentication methods. like SMS messages or secondary email addresses, train team members on the dangers of cyberattacks, and create a process to respond to attacks like Lapsus$'s.

Conclusion

Understanding Cybercrime makes it easier to compare options, avoid common mistakes, and apply the information in this guide more effectively. Review the relevant requirements before making changes or choosing a solution.

FAQ

What is Cybercrime?

According to the Microsoft Threat Intelligence Center (MSTIC), "the goal of the DEV-0537 group is to gain high-level access through the theft of credentials to steal data and perform attacks." sabotage against the targeted organization, often leading to extortion.

Why is Cybercrime important?

Understanding Cybercrime helps you evaluate features, compatibility, performance, and potential limitations before you choose a product or follow a procedure.

What should you consider when using or choosing Cybercrime?

Consider your specific goal, compatibility requirements, available features, cost, security, and the practical recommendations described in this guide.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.