I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
Yeah, at least they make a very small percentage of all Microsoft employees I guess"To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."
So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment.
From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.
In the current context, this language is part of a pattern to carefully choose words in such a way as to downplay what has happened.
As I said, the work of the CEO, the cybersecurity team and the legal team is part of the overall production process at a software company.
But in general I would say routine janitorial maintenance issues don't have quite the same potential to affect production as Russian criminals reading the email of Microsoft's cybersecurity team.
Microsoft produces software and services. The communications of their CEO as well as their cybersecurity and legal teams is part of that overall production process.
It doesn’t matter to customers if Microsoft teams is down and we are talking to each other internally using iMessage and signal but anything that is in the data path is production.
In this instance, a system used by the cybersecurity team to do its actual job was breached - not some development or testing server.
We don't know what it was exactly that these attackers were looking for or what they found. But it is absolutely possible that the information they gained enables them to protect an ongoing or future attack against Microsoft's customers.
I’m going to take a wild guess here and say you don’t really run any kind of system. “Internal is not production” is the weirdest statement I have heard in a long time.
Of course these systems are production. Not only production, but _P1_ level production.
A system used by the cybersecurity team for its day to day work was breached by attackers constantly trying to break into customer systems.
1% of 238,000 employees is a "very small percentage" and still 2,380 employees. Insight into certain operational information and potentially undisclosed/unpatched zero days could be monumentally valuable to a nation state actor.
"We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes"
In other words: Microsoft will adopt their own security standards. Curious whether their SOC reports mention these are optional?
Microsoft is pretty learning resistant lately. Always prioritize the spamming customers, I guess?
Azure was owned pretty hard a while back, very little was ever heard of it again.
Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
Users are more than just things you milk for cash, they're people that trusted you and your product.
GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy?
This is vice-signaling.
It says nothing about users being compromised.
This is why they won’t do anything about it though ? Do you understand how it works ?
They’re not going to do anything about the consequences for the users until it impacts their profits.
Name one person who is done with Microsoft after this?
Making my point. It doesn't mean users weren't compromised. And even if it did, that doesn't make it so for every security breach.
From what I recall, it was a Chinese APT (designated as Storm-0558, which I think means they could not reliably attribute it to any group: https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0558), that was sitting on developers’ workstations long enough to get access to master signing key from a memory dump that ended up on one of the workstations. They then used it to access US government officials’ emails (Department of State if I recall correctly), which supposedly gave China a strategic advantage and a better understanding of inner workings of US foreign policy.
You will not see it in news that China got favourable terms in some negotiations with a country in Africa (are of Chinese interests) and US got least favourable terms than they could’ve gotten because the Chinese negotiators knew something.