• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Microsoft Reveals Cyberattack & Theft of Internal Source Code

Status
Not open for further replies.

T0@st

News Editor
Staff member
Joined
Mar 7, 2023
Messages
2,077 (4.96/day)
Location
South East, UK
We have provided an update on the nation-state attack that was detected by the Microsoft Security Team on January 12, 2024. As we shared, on January 19, the security team detected this attack on our corporate email systems and immediately activated our response process. The Microsoft Threat Intelligence investigation identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as NOBELIUM. As we said at that time, our investigation was ongoing, and we would provide additional details as appropriate.

In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our corporate email systems to gain, or attempt to gain, unauthorized access. This has included access to some of the company's source code repositories and internal systems. To date we have found no evidence that Microsoft-hosted customer-facing systems have been compromised. It is apparent that Midnight Blizzard is attempting to use secrets of different types it has found. Some of these secrets were shared between customers and Microsoft in email, and as we discover them in our exfiltrated email, we have been and are reaching out to these customers to assist them in taking mitigating measures. Midnight Blizzard has increased the volume of some aspects of the attack, such as password sprays, by as much as 10-fold in February, compared to the already large volume we saw in January 2024.




Midnight Blizzard's ongoing attack is characterized by a sustained, significant commitment of the threat actor's resources, coordination, and focus. It may be using the information it has obtained to accumulate a picture of areas to attack and enhance its ability to do so. This reflects what has become more broadly an unprecedented global threat landscape, especially in terms of sophisticated nation-state attacks.

Across Microsoft, we have increased our security investments, cross-enterprise coordination and mobilization, and have enhanced our ability to defend ourselves and secure and harden our environment against this advanced persistent threat. We have and will continue to put in place additional enhanced security controls, detections, and monitoring.

Our active investigations of Midnight Blizzard activities are ongoing, and findings of our investigations will continue to evolve. We remain committed to sharing what we learn.

View at TechPowerUp Main Site | Source
 
Joined
Feb 20, 2020
Messages
9,340 (6.10/day)
Location
Louisiana
System Name Ghetto Rigs z490|x99|Acer 17 Nitro 7840hs/ 5600c40-2x16/ 4060/ 1tb acer stock m.2/ 4tb sn850x
Processor 10900k w/Optimus Foundation | 5930k w/Black Noctua D15
Motherboard z490 Maximus XII Apex | x99 Sabertooth
Cooling oCool D5 res-combo/280 GTX/ Optimus Foundation/ gpu water block | Blk D15
Memory Trident-Z Royal 4000c16 2x16gb | Trident-Z 3200c14 4x8gb
Video Card(s) Titan Xp-water | evga 980ti gaming-w/ air
Storage 970evo+500gb & sn850x 4tb | 860 pro 256gb | Acer m.2 1tb/ sn850x 4tb| Many2.5" sata's ssd 3.5hdd's
Display(s) 1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24"/ 3rd LG 43" series
Case D450 | Cherry Entertainment center on Test bench
Audio Device(s) Built in Realtek x2 with 2-Insignia 2.0 sound bars & 1-LG sound bar
Power Supply EVGA 1000P2 with APC AX1500 | 850P2 with CyberPower-GX1325U
Mouse Redragon 901 Perdition x3
Keyboard G710+x3
Software Win-7 pro x3 and win-10 & 11pro x3
Benchmark Scores Are in the benchmark section
Hi,
Internal passwordless world hehe
 
Joined
Dec 12, 2016
Messages
1,250 (0.46/day)
It weird here in the US. The Russian government is actively attacking our technology companies and cyber infrastructure while half of US government is trying to fund Ukraine and the other half of US government is using Russia to undermine our election system.

It like some kind of modern day version of Game of Thrones. Kinda cool in a demented way.
 

AsRock

TPU addict
Joined
Jun 23, 2007
Messages
18,876 (3.07/day)
Location
UK\USA
Processor AMD 3900X \ AMD 7700X
Motherboard ASRock AM4 X570 Pro 4 \ ASUS X670Xe TUF
Cooling D15
Memory Patriot 2x16GB PVS432G320C6K \ G.Skill Flare X5 F5-6000J3238F 2x16GB
Video Card(s) eVga GTX1060 SSC \ XFX RX 6950XT RX-695XATBD9
Storage Sammy 860, MX500, Sabrent Rocket 4 Sammy Evo 980 \ 1xSabrent Rocket 4+, Sammy 2x990 Pro
Display(s) Samsung 1080P \ LG 43UN700
Case Fractal Design Pop Air 2x140mm fans from Torrent \ Fractal Design Torrent 2 SilverStone FHP141x2
Audio Device(s) Yamaha RX-V677 \ Yamaha CX-830+Yamaha MX-630 \Paradigm 7se MKII, Paradigm 5SE MK1 , Blue Yeti
Power Supply Seasonic Prime TX-750 \ Corsair RM1000X Shift
Mouse Steelseries Sensei wireless \ Steelseries Sensei wireless
Keyboard Logitech K120 \ Wooting Two HE
Benchmark Scores Meh benchmarks.
It weird here in the US. The Russian government is actively attacking our technology companies and cyber infrastructure while half of US government is trying to fund Ukraine and the other half of US government is using Russia to undermine our election system.

It like some kind of modern day version of Game of Thrones. Kinda cool in a demented way.

Russia is ?, more chance it being China.
 
Joined
Aug 20, 2007
Messages
20,789 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Joined
Nov 18, 2010
Messages
7,129 (1.45/day)
Location
Rīga, Latvia
System Name HELLSTAR
Processor AMD RYZEN 9 5950X
Motherboard ASUS Strix X570-E
Cooling 2x 360 + 280 rads. 3x Gentle Typhoons, 3x Phanteks T30, 2x TT T140 . EK-Quantum Momentum Monoblock.
Memory 4x8GB G.SKILL Trident Z RGB F4-4133C19D-16GTZR 14-16-12-30-44
Video Card(s) Sapphire Pulse RX 7900XTX + under waterblock.
Storage Optane 900P[W11] + WD BLACK SN850X 4TB + 750 EVO 500GB + 1TB 980PRO[FEDORA]
Display(s) Philips PHL BDM3270 + Acer XV242Y
Case Lian Li O11 Dynamic EVO
Audio Device(s) Sound Blaster ZxR
Power Supply Fractal Design Newton R3 1000W
Mouse Razer Basilisk
Keyboard Razer BlackWidow V3 - Yellow Switch
Software FEDORA 39 / Windows 11 insider
And at the end of the day it still will be a rouge ex-employee(maybe Russian) or an idiot left his laptop in a pub again.

But yeah... Russian attack sounds more plausible. The truth usually lies somewhere in between.
 

dgianstefani

TPU Proofreader
Staff member
Joined
Dec 29, 2017
Messages
4,312 (1.86/day)
Location
Swansea, Wales
System Name Silent
Processor Ryzen 7800X3D @ 5.15ghz BCLK OC, TG AM5 High Performance Heatspreader
Motherboard ASUS ROG Strix X670E-I, chipset fans removed
Cooling Optimus AMD Raw Copper/Plexi, HWLABS Copper 240/40+240/30, D5, 4x Noctua A12x25, Mayhems Ultra Pure
Memory 32 GB Dominator Platinum 6150 MHz 26-36-36-48, 56.6ns AIDA, 2050 FLCK, 160 ns TRFC
Video Card(s) RTX 3080 Ti Founders Edition, Conductonaut Extreme, 18 W/mK MinusPad Extreme, Corsair XG7 Waterblock
Storage Intel Optane DC P1600X 118 GB, Samsung 990 Pro 2 TB
Display(s) 32" 240 Hz 1440p Samsung G7, 31.5" 165 Hz 1440p LG NanoIPS Ultragear
Case Sliger SM570 CNC Aluminium 13-Litre, 3D printed feet, custom front panel with pump/res combo
Audio Device(s) Audeze Maxwell Ultraviolet, Razer Nommo Pro
Power Supply SF750 Plat, transparent full custom cables, Sentinel Pro 1500 Online Double Conversion UPS w/Noctua
Mouse Razer Viper Pro V2 Mercury White w/Tiger Ice Skates & Pulsar Supergrip tape
Keyboard Wooting 60HE+ module, TOFU Redux Burgundy w/brass weight, Prismcaps White & Jellykey, lubed/modded
Software Windows 10 IoT Enterprise LTSC 19053.3803
Benchmark Scores Legendary
It weird here in the US. The Russian government is actively attacking our technology companies and cyber infrastructure while half of US government is trying to fund Ukraine and the other half of US government is using Russia to undermine our election system.

It like some kind of modern day version of Game of Thrones. Kinda cool in a demented way.
Really? "Russian interference" boogeyman aside I think you guys are undermining the election system well enough on your own considering voter ID isn't even required. Besides, coming from the country that founded the CIA, it's a bit rich talking about supposed Russian meddling in sovereign nation's politics and elections, what did they do again? Some promoted political posts on Facebook or something, total budget in the low thousands $.

But regarding the hacks, every powerful nation state is actively doing this to each other. USA, China and Russia are just big enough and good enough that it's noticeable.

Even my university IT staff talk about the constant attempted hacks 24/7 from China and other sources.
 
Joined
Jun 18, 2021
Messages
2,287 (2.19/day)
Really? "Russian interference" boogeyman aside I think you guys are undermining the election system well enough on your own considering voter ID isn't even required. Besides, coming from the country that founded the CIA, it's a bit rich talking about supposed Russian meddling in sovereign nation's politics and elections, what did they do again? Some promoted political posts on Facebook or something, total budget in the low thousands $.

But regarding the hacks, every powerful nation state is actively doing this to each other. USA, China and Russia are just big enough and good enough that it's noticeable.

Even my university IT staff talk about the constant attempted hacks 24/7 from China and other sources.

That's some weird both siding it when China and Russia don't have elections to begin with. But I'll see myself out as this already went on a very unnecessary political tangent
 

dgianstefani

TPU Proofreader
Staff member
Joined
Dec 29, 2017
Messages
4,312 (1.86/day)
Location
Swansea, Wales
System Name Silent
Processor Ryzen 7800X3D @ 5.15ghz BCLK OC, TG AM5 High Performance Heatspreader
Motherboard ASUS ROG Strix X670E-I, chipset fans removed
Cooling Optimus AMD Raw Copper/Plexi, HWLABS Copper 240/40+240/30, D5, 4x Noctua A12x25, Mayhems Ultra Pure
Memory 32 GB Dominator Platinum 6150 MHz 26-36-36-48, 56.6ns AIDA, 2050 FLCK, 160 ns TRFC
Video Card(s) RTX 3080 Ti Founders Edition, Conductonaut Extreme, 18 W/mK MinusPad Extreme, Corsair XG7 Waterblock
Storage Intel Optane DC P1600X 118 GB, Samsung 990 Pro 2 TB
Display(s) 32" 240 Hz 1440p Samsung G7, 31.5" 165 Hz 1440p LG NanoIPS Ultragear
Case Sliger SM570 CNC Aluminium 13-Litre, 3D printed feet, custom front panel with pump/res combo
Audio Device(s) Audeze Maxwell Ultraviolet, Razer Nommo Pro
Power Supply SF750 Plat, transparent full custom cables, Sentinel Pro 1500 Online Double Conversion UPS w/Noctua
Mouse Razer Viper Pro V2 Mercury White w/Tiger Ice Skates & Pulsar Supergrip tape
Keyboard Wooting 60HE+ module, TOFU Redux Burgundy w/brass weight, Prismcaps White & Jellykey, lubed/modded
Software Windows 10 IoT Enterprise LTSC 19053.3803
Benchmark Scores Legendary
That's some weird both siding it when China and Russia don't have elections to begin with. But I'll see myself out as this already went on a very unnecessary political tangent
The 24/7 cyberwarfare between these three and others isn't related to the elections content being discussed separately. But hacking is just the reality of 2024, and is an observation related to how this time MS were aware of a specific hack that was successful.
 
Joined
Nov 6, 2014
Messages
106 (0.03/day)
Processor Intel i7 13700K
Motherboard ASUS PROArt Z690 Creator WiFi
Cooling Liquid Freezer II - 280
Memory Kingston 32GB DDR5 @ 6200 MT/s
Video Card(s) Palit RTX3070 GamingPRO
Storage TrueNAS CORE
Case Phanteks ECLIPSE P600S
Audio Device(s) Creative Sound Blaster AE-5
Power Supply SEASONIC CONNECT 750W
if MS can't keep their own shit safe, how can we trust them to keep our shit safe?
 
Joined
Aug 22, 2007
Messages
3,457 (0.57/day)
Location
CA, US
System Name :)
Processor Intel 13700k
Motherboard Gigabyte z790 UD AC
Cooling Noctua NH-D15
Memory 64GB GSKILL DDR5
Video Card(s) Gigabyte RTX 4090 Gaming OC
Storage 960GB Optane 905P U.2 SSD + 4TB PCIe4 U.2 SSD
Display(s) Alienware AW3423DW 175Hz QD-OLED + Nixeus 27" IPS 1440p 144Hz
Case Fractal Design Torrent
Audio Device(s) MOTU M4 - JBL 305P MKII w/2x JL Audio 10 Sealed --- X-Fi Titanium HD - Presonus Eris E5 - JBL 4412
Power Supply Silverstone 1000W
Mouse Roccat Kain 122 AIMO
Keyboard KBD67 Lite / Mammoth75
VR HMD Reverb G2 V2
Software Win 11 Pro
if MS can't keep their own shit safe, how can we trust them to keep our shit safe?
The thing is... security is a lie, and nothing is safe. As soon as you accept that, you'll be fine. :toast:
 

Space Lynx

Astronaut
Joined
Oct 17, 2014
Messages
16,020 (4.60/day)
Location
Kepler-186f
Processor i5-12600kf @ 5.3 P and 3.9 E (1.28v)
Motherboard MSi Z790 Pro Wifi
Cooling Frost Commander 140
Memory 32gb (4x8gb) 3200
Video Card(s) XFX MERC310 7900 XT (oc'd)
Display(s) NZXT Canvas 1440p 165hz 27"
Case NZXT H710 (Red/Black)
Audio Device(s) Jade Audio JT1, Asgard 2, Modi 3
Power Supply Corsair RM850W Gold
Mouse Naga X
Keyboard Akko Fairy Switch
Why would you even keep super important source code online accessible. It's funny to me how secure our rare libraries are vs modern tech. Like if I want to read a book from Ancient Rome, I have to go sit in a room while being supervised as I read it, then they put the book away for me. lol just makes me laugh
 
Joined
Jan 18, 2020
Messages
677 (0.43/day)
No surprises here. Mentioned something similar in the thread about Meta and got low quality post hidden.

Maybe they should focus more on security than AI pumping?
 
Joined
Mar 15, 2023
Messages
868 (2.11/day)
System Name Stugots V
Processor Ryzen 7 5800X3D
Motherboard MSI MAG B550 Tomahawk
Cooling Thermalright PA-120 Black
Memory 2 x 16GB G.Skill 3600Mhz CL16
Video Card(s) ASUS Dual RTX 4070
Storage 500GB WD SN750 | 2TB WD SN750 | 6TB WD Red +
Display(s) Dell S2716DG (1440p / 144Hz)
Case Fractal Meshify 2 Compact
Audio Device(s) JDS Labs Element | Audioengine HD3 + A8 | Beyerdynamic DT-990 Pro (250)
Power Supply Seasonic Focus Plus 850W
Mouse Logitech G502 Lightspeed
Keyboard Leopold FC750R
Software Win 10 Pro x64
Sighs. At least it's not Equifax (again)...
 
Joined
Jul 16, 2014
Messages
8,122 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
The Nigerian Prince strikes again. Some gullible person clicked a link...
 
Joined
Nov 15, 2020
Messages
874 (0.69/day)
System Name 1. Glasshouse 2. Odin OneEye
Processor 1. Ryzen 9 5900X (manual PBO) 2. Ryzen 9 7900X
Motherboard 1. MSI x570 Tomahawk wifi 2. Gigabyte Aorus Extreme 670E
Cooling 1. Noctua NH D15 Chromax Black 2. Custom Loop 3x360mm (60mm) rads & T30 fans/Aquacomputer NEXT w/b
Memory 1. G Skill Neo 16GBx4 (3600MHz 16/16/16/36) 2. Kingston Fury 16GBx2 DDR5 CL36
Video Card(s) 1. Asus Strix Vega 64 2. Powercolor Liquid Devil 7900XTX
Storage 1. Corsair Force MP600 (1TB) & Sabrent Rocket 4 (2TB) 2. Kingston 3000 (1TB) and Hynix p41 (2TB)
Display(s) 1. Samsung U28E590 10bit 4K@60Hz 2. LG C2 42 inch 10bit 4K@120Hz
Case 1. Corsair Crystal 570X White 2. Cooler Master HAF 700 EVO
Audio Device(s) 1. Creative Speakers 2. Built in LG monitor speakers
Power Supply 1. Corsair RM850x 2. Superflower Titanium 1600W
Mouse 1. Microsoft IntelliMouse Pro (grey) 2. Microsoft IntelliMouse Pro (black)
Keyboard Leopold High End Mechanical
Software Windows 11
The Nigerian Prince strikes again. Some gullible person clicked a link...
Yep, that's what happened! No point fretting about Microsoft and their security - it's out of our control. Just control the things you can.
 
Joined
Jun 21, 2021
Messages
2,745 (2.63/day)
System Name daily driver Mac mini M2 Pro
Processor Apple Silicon M2 Pro (6 p-cores, 4 e-cores)
Motherboard Apple proprietary
Cooling Apple proprietary
Memory Apple proprietary 16GB LPDDR5 unified memory
Video Card(s) Apple Silicon M2 Pro (16-core GPU)
Storage Apple proprietary 512GB SSD + various external HDDs
Display(s) LG 27UL850W (4K@60Hz IPS)
Case Apple proprietary
Audio Device(s) Apple proprietary
Power Supply Apple proprietary
Mouse Apple Magic Trackpad 2
Keyboard Keychron K1 tenkeyless (Gateron Reds)
Software macOS Ventura 13.6 (including latest patches)
Benchmark Scores (My Windows daily driver is a Beelink Mini S12. I'm not interested in benchmarking.)
Why would you even keep super important source code online accessible. It's funny to me how secure our rare libraries are vs modern tech. Like if I want to read a book from Ancient Rome, I have to go sit in a room while being supervised as I read it, then they put the book away for me. lol just makes me laugh
That's because that ancient Roman book is physical, likely very rare (or unique), and subject to wear & tear. Their strict reading room measures are to preserve the physical book, not the data it holds.

The same procedures are used for other old items like Greek pottery, jewelry, paintings, drawings, textiles, etc. They are more worried about damage to the physical object by careless or poor handling from your greasy hands or you spilling a soda all over a priceless manuscript.

In fact, many of these priceless artifacts get digitally archived as a precaution against further damage to the original object. This is particularly important for books because a museum can't put a book on display and show all of its pages.

For something like precious source code, there are multiple copies. That's what backups are for. You can make a copy of the Magna Carta but the copy doesn't have the same value as the original. For digital data, it's all pretty much equivalent.

Let's say you have your grandfather's wristwatch and it gets destroyed in an accident. You find the same exact model on FleaBay. Would you buy it as a replacement? It's no longer the item that your grandfather actually used. It just looks the same.

Anyhow, it goes well beyond the loss of source code. It's about losing trust. Even if they can identify and eventually nail the perpetrators, they have lost trust and goodwill from customers. And not just Joe Consumer or Xbox Gamer Guy, it also includes corporate customers of Azure.

Even if you don't use OneDrive, you probably use some service that is running on Azure. Can't get away from the cloud anymore even if you disconnect your PC from the Internet and throw away your smartphone. Your bank, hospital, insurance company, airline, public transit system, etc. are all online.

Yeah, until you run out of money or public support.

The latter happened to the USA in Vietnam.

Yes, you can defeat anything. But at what cost? Is it always worth it?

With cyberattacks, a very small organization can topple a massive one. It's a little different than the physical warfare that Patton was commenting about. Look at Kevin Mitnick.

I can't buy a DJI drone and defeat the British Navy. However a hacker could by a $500 laptop and infiltrate Microsoft.
 
Last edited:
Status
Not open for further replies.
Top