sgt_zim
AH legend
- Joined
- Mar 26, 2017
- Messages
- 4,542
- Reaction score
- 17,422
- Location
- Richmond, Texas
- Media
- 33
- Articles
- 1
- Member of
- NRA, Houston Safari Club Foundation, NWTF
- Hunted
- South Africa, Idaho, Texas, Louisiana
Not sure how many of you might have caught this news in the last 4 or 5 days, but it seems at least part of Microsoft was compromised pretty badly by a Russian-supported hacking group that goes by a few different names - Midnight Blizzard and Cozy Bear are 2 of them. This is the same group responsible for the Solar Winds compromise back in 2022
MS has responsibly disclosed, but they still don't know the full extent of the penetration, nor even if the bad guys are still maintaining some sort of presence in their network.
So far, no MS source code (for operating systems, web servers, database engines, et al) have been reported as exfiltrated, but stay tuned for that.
That's to say nothing of what China has been busy doing for the last probably 10 years or so, embedding spyware (and God only knows what else) in low tech hardware like port cranes, among other things.
We're still trying to figure out the implications of all this. But,
MS has responsibly disclosed, but they still don't know the full extent of the penetration, nor even if the bad guys are still maintaining some sort of presence in their network.
Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center
Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard
msrc.microsoft.com
Microsoft admits Russian state hack still not contained. ‘This has tremendous national security implications’
A new SEC rule compels publicly traded companies to disclose breaches that could negatively impact their business.
fortune.com
So far, no MS source code (for operating systems, web servers, database engines, et al) have been reported as exfiltrated, but stay tuned for that.
That's to say nothing of what China has been busy doing for the last probably 10 years or so, embedding spyware (and God only knows what else) in low tech hardware like port cranes, among other things.
We're still trying to figure out the implications of all this. But,