Beautiful Virgin Islands

Sunday, Nov 09, 2025

SolarWinds hackers accessed Microsoft source code, the company says

SolarWinds hackers accessed Microsoft source code, the company says

The hacking group behind the SolarWinds compromise was able to break into Microsoft Corp and access some of its source code, Microsoft said on Thursday, something experts said sent a worrying signal about the spies' ambition.
Source code - the underlying set of instructions that run a piece of software or operating system - is typically among a technology company's most closely guarded secrets and Microsoft has historically been particularly careful about protecting it.

It is not clear how much or what parts of Microsoft's source code repositories the hackers were able to access, but the disclosure suggests that the hackers who used software company SolarWinds as a springboard to break into sensitive U.S. government networks also had an interest in discovering the inner workings of Microsoft products as well.

Microsoft had already disclosed that like other firms it found malicious versions of SolarWinds' software inside its network, but the source code disclosure - made in a blog post - is new. After Reuters reported it was breached two weeks ago, Microsoft said it had not "found any evidence of access to production services."

Three people briefed on the matter said Microsoft had known for days that the source code had been accessed. A Microsoft spokesman said security employees had been working "around the clock" and that "when there is actionable information to share, they have published and shared it."

The SolarWinds hack is among the most ambitious cyber operations ever disclosed, compromising at least half-a-dozen federal agencies and potentially thousands of companies and other institutions. U.S. and private sector investigators have spent the holidays combing through logs to try to understand whether their data has been stolen or modified.

Modifying source code - which Microsoft said the hackers did not do - could have potentially disastrous consequences given the ubiquity of Microsoft products, which include the Office productivity suite and the Windows operating system. But experts said that even just being able to review the code could offer hackers insight that might help them subvert Microsoft products or services.

"The source code is the architectural blueprint of how the software is built," said Andrew Fife of Israel-based Cycode, a source code protection company.

"If you have the blueprint, it's far easier to engineer attacks."

Matt Tait, an independent cybersecurity researcher, agreed that the source code could be used as a roadmap to help hack Microsoft products, but he also cautioned that elements of the company's source code were already widely shared - for example with foreign governments. He said he doubted that Microsoft had made the common mistake of leaving cryptographic keys or passwords in the code.

"It's not going to affect the security of their customers, at least not substantially," Tait said.

Microsoft noted that it allows broad internal access to its code, and former employees agreed that it is more open than other companies.

In its blog post, Microsoft said it had found no evidence of access "to production services or customer data."

"The investigation, which is ongoing, has also found no indications that our systems were used to attack others," it said.

Reuters reported a week ago that Microsoft-authorized resellers were hacked and their access to productivity programs inside targets leveraged in attempts to read email. Microsoft acknowledged some vendor access was misused but has not said how many resellers or customers may have been breached.

There was no response to requests for comment from the FBI, which is investigating the hacking campaign, or from the Department of Homeland Security's Cybsersecurity and Infrastructure Security Agency.

U.S. officials have attributed the SolarWinds hacking campaign to Russia, an allegation the Kremlin denies.

Both Tait and Ronen Slavin, Cycode's chief technology officer, said a key unanswered question was which source code repositories were accessed. Microsoft has a huge range of products, from widely used Windows to lesser known software such as social networking app Yammer and the design app Sway.

Slavin said he was worried by the possibility that the SolarWinds hackers were poring over Microsoft's source code as prelude to a much more ambitious offensive.

"To me the biggest question is, 'Was this recon for the next big operation?'" he said.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Tom Cruise Arrives by Helicopter at UK Scientology Fundraiser Amid Local Protests
Prince Andrew and Sarah Ferguson Face Fresh UK Probes Amid Royal Fallout
Mothers Link Teen Suicides to AI Chatbots in Growing Legal Battle
UK Government to Mirror Denmark’s Tough Immigration Framework in Major Policy Shift
UK Government Turns to Denmark-Style Immigration Reforms to Overhaul Border Rules
UK Chancellor Warned Against Cutting Insulation Funding as Budget Looms
UK Tenant Complaints Hit Record Levels as Rental Sector Faces Mounting Pressure
Apple to Pay Google About One Billion Dollars Annually for Gemini AI to Power Next-Generation Siri
UK Signals Major Shift as Nuclear Arms Race Looms
BBC’s « Celebrity Traitors UK » Finale Breaks Records with 11.1 Million Viewers
UK Spy Case Collapse Highlights Implications for UK-Taiwan Strategic Alignment
On the Road to the Oscars? Meghan Markle to Star in a New Film
A Vote Worth a Trillion Dollars: Elon Musk’s Defining Day
AI Researchers Claim Human-Level General Intelligence Is Already Here
President Donald Trump Challenges Nigeria with Military Options Over Alleged Christian Killings
Nancy Pelosi Finally Announces She Will Not Seek Re-Election, Signalling End of Long Congressional Career
UK Pre-Budget Blues and Rate-Cut Concerns Pile Pressure on Pound
ITV Warns of Nine-Per-Cent Drop in Q4 Advertising Revenue Amid Budget Uncertainty
National Grid Posts Slightly Stronger-Than-Expected Half-Year Profit as Regulatory Investments Drive Growth
UK Business Lobby Urges Reeves to Break Tax Pledges and Build Fiscal Headroom
UK to Launch Consultation on Stablecoin Regulation on November 10
UK Savers Rush to Withdraw Pension Cash Ahead of Budget Amid Tax-Change Fears
Massive Spoilers Emerge from MAFS UK 2025: Couple Swaps, Dating App Leaks and Reunion Bombshells
Kurdish-led Crime Network Operates UK Mini-Marts to Exploit Migrants and Sell Illicit Goods
UK Income Tax Hike Could Trigger £1 Billion Cut to Scotland’s Budget, Warns Finance Secretary
Tommy Robinson Acquitted of Terror-related Charge After Phone PIN Dispute
Boris Johnson Condemns Western Support for Hamas at Jewish Community Conference
HII Welcomes UK’s Westley Group to Strengthen AUKUS Submarine Supply Chain
Tragedy in Serbia: Coach Mladen Žižović Collapses During Match and Dies at 44
Diplo Says He Dated Katy Perry — and Justin Trudeau
Dick Cheney, Former U.S. Vice President, Dies at 84
Trump Calls Title Removal of Andrew ‘Tragic Situation’ Amid Royal Fallout
UK Bonds Rally as Chancellor Reeves Briefs Markets Ahead of November Budget
UK Report Backs Generational Smoking Ban Ahead of Tobacco & Vapes Bill Review
UK’s Domino’s Pizza Group Reports Modest Like-for-Like Sales Growth in Q3
UK Supplies Additional Storm Shadow Missiles to Ukraine as Trump Alleges Russian Underground Nuclear Tests
High-Profile Broodmare Puca Sells for Five Million Dollars at Fasig-Tipton ‘Night of the Stars’
Wilt Chamberlain’s One-of-a-Kind ‘Searcher 1’ Supercar Heads to Auction
Erling Haaland’s Remarkable Run: 13 Premier League Goals in 10 Matches and Eyes on History
UK Labour Peer Warns of Emerging ‘Constituency for Hating Jews’ in Britain
UK Home Secretary Admits Loss of Border Control, Warns Public Trust at Risk
President Trump Expresses Sympathy for UK Royal Family After Title Stripping of Prince Andrew
Former Prince Andrew to Lose His Last Military Title as King Charles Moves to End His Public Role
King Charles Relocates Andrew to Sandringham Estate and Strips Titles Amid Epstein Fallout
Two Arrested After Mass Stabbing on UK Train Leaves Ten Hospitalised
Glamour UK Says ‘Stay Mad Jo x’ After Really Big Rowling Backlash
Former Prince Prince Andrew Faces Possible U.S. Congressional Appearance Over Jeffrey Epstein Inquiry
UK Faces £20 Billion Productivity Shortfall as Brexit’s Impact Deepens
UK Chancellor Rachel Reeves Eyes New Council-Tax Bands for High-Value Homes
UK Braces for Major Storm with Snow, Heavy Rain and Winds as High as 769 Miles Wide
×