I could be wrong about that, though, and I’d be curious to learn and understand more.
I could be wrong about that, though, and I’d be curious to learn and understand more.
The "risk" mentioned in the quote a few comments up, and in the context of the post by MSRC, isn't about the risk of leaking Microsoft IP. It's about the risk that Microsoft customers might have been affected. Whether or not MSRC found evidence of a breach of customer accounts/data is a related but separate question.
The comment in the article speaks to #1. And of course, we have to take that with a grain of salt. I doubt any company impacted by this would be fully honest if there was a customer breach. Regardless, you also can't prove a negative. So all they can really say is what they did. Which doesn't mean services/data weren't compromised. Given the size of Microsoft, I find it hard to believe that every service running there has the logs/audit trail to know whether they were inappropriately accessed.
But I took the OPs comment to be focused on #2 as well. There is a very real possibility that having access to the source code could help the attackers attack customers. Having access to the source code can help in locating vulnerabilities that allow future attacks against customers/services.
And this doesn't look like something bored 15 year old would pull, So I doubt it was to access their source.
If I had to guess, they were either trying to find something specific, about one of MS's customers (some gov org) or the target was Azure. Lots of corps keep a lot of data there.
Or in charge of protecting them.