Company
Date Published
Author
Mackenzie Jackson
Word count
998
Language
English
Hacker News points
None

Summary

Lapsus$, a hacking group, has leaked internal source code from 250 Microsoft projects, claiming it includes 90% of Bing's and 45% of Bing Maps and Cortana's code. This follows previous leaks from companies like Samsung and Nvidia. The group employs various methods to gain access, such as deploying malware, purchasing credentials, and exploiting personal accounts of employees with leaked corporate credentials. Despite Microsoft's assertion that these breaches have caused limited damage, an analysis by GitGuardian found 376 sensitive secrets within the leaked Microsoft source code, highlighting the ongoing challenge of managing exposed sensitive information even in security-focused organizations. GitGuardian's analysis also indicates that while Microsoft has implemented security measures to minimize such leaks, the presence of secrets remains a significant issue, showcasing the difficulty of maintaining complete secrecy in large code repositories.