154

Microsoft reported a breach by Russian group 'Midnight Blizzard,' which accessed internal systems and source code using stolen authentication secrets from a January cyberattack. The unauthorized access was facilitated by a compromised non-production test account lacking multi-factor authentication and linked to an OAuth app with elevated privileges. Microsoft is contacting affected customers and has ramped up security measures to counter the persistent threat.

you are viewing a single comment's thread
view the rest of the comments
[-] ptz@dubvee.org 45 points 8 months ago* (last edited 8 months ago)

Oh, no. Imagine all the havoc that could be wrought if the source code for an operating system was released onto the internet /s

That's why you should never rely on security through obscurity.

-- Sent from my Linux desktop

[-] assembly@lemmy.world 10 points 8 months ago

I hope these hackers didn’t also get the source code to RockyLinux or I’m screwed man. If all you need is source code access, I won’t be safe after that. :-)

[-] atzanteol@sh.itjust.works 7 points 8 months ago

I don't think that is the concern here.

Microsoft is a huge cloud provider now.

[-] msage@programming.dev 2 points 8 months ago

What OS does that cloud utilize?

[-] atzanteol@sh.itjust.works 2 points 8 months ago
[-] msage@programming.dev 1 points 8 months ago

Source code is available for most of their infrastructure is what I'm saying.

[-] homesweethomeMrL@lemmy.world 2 points 8 months ago

Inconcievably.

[-] rutellthesinful@kbin.social 3 points 8 months ago

wouldn't the counterpoint to that be all the vulnerabilities that have sat out in the open for years before finally being reported?

[-] rdri@lemmy.world 0 points 8 months ago

Chances are it didn't involve the OS source code. If you read the article, previously Microsoft reported about source code for service components like Exchange, Azure etc.

this post was submitted on 08 Mar 2024
154 points (97.5% liked)

Cybersecurity

5728 readers
134 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS