The hackers, who carried out a sophisticated cyber attack on government agencies in the US and private companies, were able to access Microsoft's source code, the company said on Thursday.
A Microsoft investigation found "unusual activity with a small number of internal accounts" and "an account was used to view source code in a number of source code repositories," the company said in a blog post. Microsoft said the account would not be able to change code and that it would not compromise any company services or customer data.
Stay up to date
Get the latest technical stories every weekday with CNET Daily News.
Microsoft is diligent in protecting its source code, the foundation of its software, but the company is providing access to certain "qualified" customers, governments and partners for debugging and reference purposes.
"The ongoing investigation has also revealed no evidence that our systems have been used to attack others," the company said.
Continue reading:: SolarWinds Hack continues to spread: what you need to know
A Russian intelligence agency is suspected of running the massive campaign that reportedly targeted an email system used by executives from the finance department. It started earlier this year when hackers compromised SolarWinds' IT management software. Based in Austin, Texas, the company sells software that enables a company to see what is happening on its computer networks.
Hackers have put malicious code in an update to this software called Orion. Around 18,000 SolarWinds customers have installed the vulnerable update on their systems.
The US national security agencies have described the violation as "significant and ongoing". According to an analysis by Microsoft and the security company FireEye, both were infectedThe malware offers hackers a broad reach for affected systems.
Microsoft previously said it had identified more than 40 customers those were targeted in the hack. More information about the hack and its aftermath is likely to be released.
Continue reading: How to avoid a spear phishing attack. 4 tips to keep you safe from timeless scams
Source link