SolarWinds Hackers Accessed Microsoft Source Code, the Company Says

The Microsoft logo is pictured ahead of the Mobile World Congress in Barcelona, Spain February 24, 2019. (Reuters)
The Microsoft logo is pictured ahead of the Mobile World Congress in Barcelona, Spain February 24, 2019. (Reuters)
TT

SolarWinds Hackers Accessed Microsoft Source Code, the Company Says

The Microsoft logo is pictured ahead of the Mobile World Congress in Barcelona, Spain February 24, 2019. (Reuters)
The Microsoft logo is pictured ahead of the Mobile World Congress in Barcelona, Spain February 24, 2019. (Reuters)

The hacking group behind the SolarWinds compromise was able to break into Microsoft Corp and access some of its source code, Microsoft said on Thursday, something experts said sent a worrying signal about the spies’ ambition.

Source code - the underlying set of instructions that run a piece of software or operating system - is typically among a technology company’s most closely guarded secrets and Microsoft has historically been particularly careful about protecting it.

It is not clear how much or what parts of Microsoft’s source code repositories the hackers were able to access, but the disclosure suggests that the hackers who used software company SolarWinds as a springboard to break into sensitive US government networks also had an interest in discovering the inner workings of Microsoft products as well.

Microsoft had already disclosed that like other firms it found malicious versions of SolarWinds’ software inside its network, but the source code disclosure - made in a blog post - is new. After Reuters reported it was breached two weeks ago, Microsoft said it had not “found any evidence of access to production services.”

Three people briefed on the matter said Microsoft had known for days that the source code had been accessed. A Microsoft spokesman said security employees had been working “around the clock” and that “when there is actionable information to share, they have published and shared it.”

The SolarWinds hack is among the most ambitious cyber operations ever disclosed, compromising at least half-a-dozen federal agencies and potentially thousands of companies and other institutions. US and private sector investigators have spent the holidays combing through logs to try to understand whether their data has been stolen or modified.

Modifying source code - which Microsoft said the hackers did not do - could have potentially disastrous consequences given the ubiquity of Microsoft products, which include the Office productivity suite and the Windows operating system. But experts said that even just being able to review the code could offer hackers insight that might help them subvert Microsoft products or services.

“The source code is the architectural blueprint of how the software is built,” said Andrew Fife of Israel-based Cycode, a source code protection company.

“If you have the blueprint, it’s far easier to engineer attacks.”

Matt Tait, an independent cybersecurity researcher, agreed that the source code could be used as a roadmap to help hack Microsoft products, but he also cautioned that elements of the company’s source code were already widely shared - for example with foreign governments. He said he doubted that Microsoft had made the common mistake of leaving cryptographic keys or passwords in the code.

“It’s not going to affect the security of their customers, at least not substantially,” Tait said.

Microsoft noted that it allows broad internal access to its code, and former employees agreed that it is more open than other companies.

In its blog post, Microsoft said it had found no evidence of access “to production services or customer data.”

“The investigation, which is ongoing, has also found no indications that our systems were used to attack others,” it said.

Reuters reported a week ago that Microsoft-authorized resellers were hacked and their access to productivity programs inside targets leveraged in attempts to read email. Microsoft acknowledged some vendor access was misused but has not said how many resellers or customers may have been breached.

There was no response to requests for comment from the FBI, which is investigating the hacking campaign, or from the Department of Homeland Security’s Cybsersecurity and Infrastructure Security Agency.

US officials have attributed the SolarWinds hacking campaign to Russia, an allegation the Kremlin denies.

Both Tait and Ronen Slavin, Cycode’s chief technology officer, said a key unanswered question was which source code repositories were accessed. Microsoft has a huge range of products, from widely used Windows to lesser known software such as social networking app Yammer and the design app Sway.

Slavin said he was worried by the possibility that the SolarWinds hackers were poring over Microsoft’s source code as prelude to a much more ambitious offensive.

“To me the biggest question is, ‘Was this recon for the next big operation?’” he said.



Report: France Aims to Ban Under-15s from Social Media from September 2026

French President Emmanuel Macron holds a press conference during a European Union leaders' summit, in Brussels, Belgium December 19, 2025. (Reuters)
French President Emmanuel Macron holds a press conference during a European Union leaders' summit, in Brussels, Belgium December 19, 2025. (Reuters)
TT

Report: France Aims to Ban Under-15s from Social Media from September 2026

French President Emmanuel Macron holds a press conference during a European Union leaders' summit, in Brussels, Belgium December 19, 2025. (Reuters)
French President Emmanuel Macron holds a press conference during a European Union leaders' summit, in Brussels, Belgium December 19, 2025. (Reuters)

France plans to ban children under 15 from social media sites and to prohibit mobile phones in high schools from September 2026, local media reported on Wednesday, moves that underscore rising public angst over the impact of online harms on minors.

President Emmanuel Macron has often pointed to social media as one of the factors to blame for violence among young people and has signaled he wants France to follow Australia, whose world-first ‌ban for under-16s ‌on social media platforms including Facebook, Snapchat, TikTok ‌and ⁠YouTube came into force ‌in December.

Le Monde newspaper said Macron could announce the measures in his New Year's Eve national address, due to be broadcast at 1900 GMT. His government will submit draft legislation for legal checks in early January, Le Monde and France Info reported.

The Elysee and the prime minister's office did not immediately respond to a request for comment on the reports.

Mobile phones have been banned ⁠in French primary and middle schools since 2018 and the reported new changes would extend that ban ‌to high schools. Pupils aged 11 to ‍15 attend middle schools in the French ‍educational system.

France also passed a law in 2023 requiring social platforms to ‍obtain parental consent for under-15s to create accounts, though technical challenges have impeded its enforcement.

Macron said in June he would push for regulation at the level of the European Union to ban access to social media for all under-15s after a fatal stabbing at a school in eastern France shocked the nation.

The European Parliament in ⁠November urged the EU to set minimum ages for children to access social media to combat a rise in mental health problems among adolescents from excessive exposure, although it is member states which impose age limits. Various other countries have also taken steps to regulate children's access to social media.

Macron heads into the New Year with his domestic legacy in tatters after his gamble on parliamentary elections in 2024 led to a hung parliament, triggering France's worst political crisis in decades that has seen a succession of weak governments.

However, cracking down further on minors' access to social media could prove popular, according to opinion ‌polls. A Harris Interactive survey in 2024 showed 73% of those canvassed supporting a ban on social media access for under-15s.


Poland Urges Brussels to Probe TikTok Over AI-Generated Content

The TikTok logo is pictured outside the company's US head office in Culver City, California, US, September 15, 2020. (Reuters)
The TikTok logo is pictured outside the company's US head office in Culver City, California, US, September 15, 2020. (Reuters)
TT

Poland Urges Brussels to Probe TikTok Over AI-Generated Content

The TikTok logo is pictured outside the company's US head office in Culver City, California, US, September 15, 2020. (Reuters)
The TikTok logo is pictured outside the company's US head office in Culver City, California, US, September 15, 2020. (Reuters)

Poland has asked the European Commission to investigate TikTok after the social media platform hosted AI-generated content including calls for Poland to withdraw from the EU, it said on Tuesday, adding that the content was almost certainly Russian disinformation.

"The disclosed content poses a threat to public order, information security, and the integrity of democratic processes in Poland and across the European Union," Deputy Digitalization Minister Dariusz Standerski said in a letter sent to the Commission.

"The nature of ‌the narratives, ‌the manner in which they ‌are distributed, ⁠and the ‌use of synthetic audiovisual materials indicate that the platform is failing to comply with the obligations imposed on it as a Very Large Online Platform (VLOP)," he added.

A Polish government spokesperson said on Tuesday the content was undoubtedly Russian disinformation as the recordings contained Russian syntax.

TikTok, representatives ⁠of the Commission and of the Russian embassy in Warsaw did not ‌immediately respond to Reuters' requests for ‍comment.

EU countries are taking ‍measures to head off any foreign state attempts to ‍influence elections and local politics after warning of Russian-sponsored espionage and sabotage. Russia has repeatedly denied interfering in foreign elections.

Last year, the Commission opened formal proceedings against social media firm TikTok, owned by China's ByteDance, over its suspected failure to limit election interference, notably in ⁠the Romanian presidential vote in November 2024.

Poland called on the Commission to initiate proceedings in connection with suspected breaches of the bloc's sweeping Digital Services Act, which regulates how the world's biggest social media companies operate in Europe.

Under the Act, large internet platforms like X, Facebook, TikTok and others must moderate and remove harmful content like hate speech, racism or xenophobia. If they do not, the Commission can impose fines of up to 6% ‌of their worldwide annual turnover.


Saudi National Cybersecurity Authority Launches Service to Verify Suspicious Links

Saudi National Cybersecurity Authority Launches Service to Verify Suspicious Links
TT

Saudi National Cybersecurity Authority Launches Service to Verify Suspicious Links

Saudi National Cybersecurity Authority Launches Service to Verify Suspicious Links

The National Cybersecurity Authority has launched the “Tahqaq” service, aimed at enabling members of the public to proactively and safely deal with circulated links and instantly verify their reliability before visiting them.

This initiative comes within the authority’s strategic programs designed to empower individuals to enhance their cybersecurity, SPA reported.

The authority noted that the “Tahqaq” service allows users to scan circulated links and helps reduce the risks associated with using and visiting suspicious links that may lead to unauthorized access to data. The service also provides cybersecurity guidance to users, mitigating emerging cyber risks and boosting cybersecurity awareness across all segments of society.

The “Tahqaq” service is offered as part of the National Portal for Cybersecurity Services (Haseen) in partnership with the authority’s technical arm, the Saudi Information Technology Company (SITE). The service is available through the unified number on WhatsApp (+966118136644), as well as via the Haseen portal website at tahqaq.haseen.gov.sa.