TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft says it found malicious software in its systems

219 点作者 0xedb超过 4 年前

23 条评论

AareyBaba超过 4 年前
Statement from Microsoft President here on security<p><a href="https:&#x2F;&#x2F;blogs.microsoft.com&#x2F;on-the-issues&#x2F;2020&#x2F;12&#x2F;17&#x2F;cyberattacks-cybersecurity-solarwinds-fireeye&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blogs.microsoft.com&#x2F;on-the-issues&#x2F;2020&#x2F;12&#x2F;17&#x2F;cyberat...</a><p>&quot;One of the more chilling developments this year has been what appears to be new steps to use AI to weaponize large stolen datasets about individuals and spread targeted disinformation using text messages and encrypted messaging apps.&quot;<p>&quot;a second evolving threat, namely the growing privatization of cybersecurity attacks through a new generation of private companies, akin to 21st-century mercenaries.&quot;<p>&quot;As humanity raced to develop vaccines, Microsoft security teams detected three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19.&quot;<p>&quot;One indicator of the current situation is reflected in the federal government’s insistence on restricting through its contracts our ability to let even one part of the federal government know what other part has been attacked. Instead of encouraging a “need to share,” this turns information sharing into a breach of contract. It literally has turned the 9&#x2F;11 Commission’s recommendations upside down.&quot;
评论 #25465833 未加载
评论 #25466767 未加载
blhack超过 4 年前
How will this even begin to be remediated (the broader hack that is coming to light right now)?<p>It seems like malicious actors had unrestricted access to almost every major computer system in the US Government, and now possibly <i>microsoft itself</i> as well?<p>How are these people ever going to be able to trust any of this equipment ever again? This just seems unbelievably catastrophic.
评论 #25463197 未加载
评论 #25462664 未加载
评论 #25463057 未加载
评论 #25464247 未加载
评论 #25463260 未加载
评论 #25468036 未加载
评论 #25463202 未加载
评论 #25463216 未加载
评论 #25463176 未加载
yborg超过 4 年前
Microsoft has now categorically denied it.<p>&quot;We have no indication of this,&quot; company President Brad Smith told New York Times reporter Nicole Perlroth. Perlroth said the company stood by a statement it issued on Sunday saying it had no indication of a vulnerability in any Microsoft product or cloud service in its investigations of the hacking campaign.&quot;
评论 #25462358 未加载
评论 #25464269 未加载
评论 #25463529 未加载
dgudkov超过 4 年前
&gt;The U.S. National Security Agency issued a rare “cybersecurity advisory” Thursday detailing how certain Microsoft Azure cloud services may have been compromised by hackers<p>I believe there is common overestimation of security of cloud providers. Microsoft Azure was just breached and that&#x27;s only what we know. There might be breaches at other cloud providers we&#x27;re not aware of.<p>Centralization creates an exponentially growing incentive for bad actors. Decentralization has been given up too soon.
chrononaut超过 4 年前
It is always events like these that make me ponder if the Internet will devolve into regional Internets, which still wouldn&#x27;t necessarily prevent or stop any determined attacker from performing these types of attacks. So perhaps it&#x27;s never.
评论 #25463133 未加载
评论 #25463444 未加载
评论 #25463019 未加载
shiado超过 4 年前
Does anybody have any details on the Russia attribution? Not looking to start political flame bait here just curious what details are out there.
评论 #25463039 未加载
评论 #25463074 未加载
评论 #25463167 未加载
评论 #25463452 未加载
markus_zhang超过 4 年前
I wonder when we will hear the news that all major clouds have been breached and data has been leaking for months&#x2F;years...would be interesting to see. My wet dream is that people ditch the cloud to hold their own infrastructures.
评论 #25463364 未加载
marcosdumay超过 4 年前
And, of course, unrestricted access to Microsoft leads to unrestricted access to nearly any company on the world.<p>I need some popcorn.
评论 #25464181 未加载
nethunters超过 4 年前
The most scariest part from this is Homeland Security saying that Solarwinds wasn&#x27;t the only vector used by the APT.
评论 #25462883 未加载
CyanLite4超过 4 年前
I’m hesitant to blame anyone before we understand the full scope. “Breached into Microsoft” could mean they hacked into a guest public WiFi access point.
seibelj超过 4 年前
And backdoors in everything is a good idea? This is beyond hilarious. The silver lining is that argument is 100% dead in the water going forwards.
评论 #25464031 未加载
评论 #25463034 未加载
评论 #25462987 未加载
评论 #25462800 未加载
评论 #25465358 未加载
HenryKissinger超过 4 年前
If you&#x27;re a cybersecurity consultant, you can practically dictate your salary at this point. What&#x27;s $3,000&#x2F;hour to the government or a Fortune 500 to recover from a cyberattack like this?<p>There must be a lot of all nighters behind the scenes.
评论 #25463076 未加载
coldcode超过 4 年前
Goes to show that you are only as secure as your weakest dependency. Allow and trust software into your organization built by a system protected by an obvious single factor password (which you didn&#x27;t know about or ask) and no matter what else you did you are screwed.<p>I worked at a healthcare company that stored its production credentials (with no login auditing) in a plain text file accessible by half the employees and contractors and when I complained that this was dumb (and violated HIPAA) was told &quot;we passed our audits and we trust our employees&quot;.
sjg007超过 4 年前
I am not surprised, it&#x27;s a dirty little secret in the software industry that we employ a lot of Russian and other potentially vulnerable Eastern European software contractors. Not to blame anyone specifically, I mean the threat could equally come from India or China. Or even a direct hack. It could also be an insider threat from an American as well. Since software development is a complicated profession, it takes a lot of intelligent oversight to ensure that critical paths are secure; especially as we migrate to cloud and site wide solutions.
评论 #25463469 未加载
maest超过 4 年前
What is the actual evidence that the hack was done by Cozy Bear&#x2F;APT29&#x2F;Russia?<p>I keep seeing this information repeated all over the place, but no mention of how that is actually known.
评论 #25467960 未加载
ohuf超过 4 年前
Here&#x27;s the link to the NSA Cyber Advisory mentioned in the article: <a href="https:&#x2F;&#x2F;www.nsa.gov&#x2F;News-Features&#x2F;Feature-Stories&#x2F;Article-View&#x2F;Article&#x2F;2434988&#x2F;russian-state-sponsored-malicious-cyber-actors-exploit-known-vulnerability-in-v&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.nsa.gov&#x2F;News-Features&#x2F;Feature-Stories&#x2F;Article-Vi...</a>
hellodang超过 4 年前
Microsoft is working on the big government cloud solution defense contract, JEDI. Certainly a prime target for state actors.
foxhop超过 4 年前
I&#x27;m buying FEYE stock.
评论 #25465036 未加载
评论 #25471606 未加载
yters超过 4 年前
The more lockdown the more lucrative big hacks become.
moocowtruck超过 4 年前
hopefully private repos on github are safe
评论 #25462982 未加载
评论 #25462748 未加载
Shared404超过 4 年前
&gt; Still, another person familiar with the matter said the Department of Homeland Security (DHS) does not believe Microsoft was a key avenue of fresh infection.<p>Thoughts on this? It seems unlikely to me that someone who compromises literally <i>the</i> enterprise desktop OS manufacturer isn&#x27;t going to take advantage of the situation.
评论 #25465345 未加载
desktopninja超过 4 年前
I wonder how much social engineering played a part in this?
seanwilson超过 4 年前
[Edit: Question was answered in article]
评论 #25462823 未加载