[Security Information] Microsoft Completes Investigation of SolarWinds Security Incident


According to foreign media, the Microsoft security team said that it has officially completed the investigation of the SolarWinds security incident. Judging from the results of the investigation, there is no evidence that its internal systems or official products have been abused by hackers, or that fraud or network attacks have been launched against end users and corporate users.

Insert picture description here

It is reported that since December last year, the Microsoft security team has been investigating the incident. They discovered that hackers invaded the software manufacturer SolarWinds and inserted malicious software into the Orion IT monitoring platform. This product was also deployed within Microsoft. Microsoft stated in a blog post that hackers used the access rights obtained through the SolarWinds Orion application to jump to Microsoft's internal network, where they accessed the source code of multiple internal projects.

Microsoft confirmed that all repositories related to any single product or service have not been accessed, and most of the source code has not been accessed by hackers. In addition to viewing files, hackers have also successfully downloaded some codes. However, Microsoft said that the data is not extensive, and the intruder only downloaded the source code of a few components related to some of its cloud products.


Insert picture description here

Guess you like

Origin blog.csdn.net/YiAnSociety/article/details/114395479