Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

Microsoft responds to hack of Cortana and Bing source code

A hacking group has hit Microsoft, getting into Azure DevOps source code repositories and leaking source code for Cortana and several other Microsoft projects. It is the latest round of attacks by the group going by the name of “LAPSUS$,” which also successfully targeted Nvidia, Ubisoft, and other large technology giants.

The latest update from the group, coming on March 22, includes the sharing of a 9GB archive, which has source code for 250 Microsoft projects. Of those, the group claims to have 90% of the source code for Bing, and 45% of the source code for Bing Maps and Cortana. This is only some of the hacked data, with the full archive having 37GB of Microsoft source code.

Alexa says hello on a windows PC that's next to a smart speaker with Alexa.
Image used with permission by copyright holder

The source code for Windows and Office are not included in the leak, according to Bleeping Computer, which believes the leaked files are genuine. The files instead are tied to mobile apps or websites and contain emails and other documents used internally by Microsoft engineers who worked on the projects.

Recommended Videos

Microsoft confirmed the hack in a blog post, which details the actions of the LAPSUS$ group that it tracks as DEV-0537. In the post, Microsoft said that the hackers had “limited access” to source code since a single account had been compromised. Microsoft went on to explain that no customer code or data was involved in the activities.

Please enable Javascript to view this content

“Our investigation has found a single account had been compromised, granting limited access. Our cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity,” said Microsoft.

The company also mentioned that it does not rely on the secrecy of code as a security measure and that viewing the source code does not lead to elevation of risk. This is similar to what Microsoft explained during the Solarigate investigation, where a compromised account had been used to view source code, though it didn’t have permission to modify engineering systems.

“Our team was already investigating the compromised account based on threat intelligence when the actor publicly disclosed their intrusion. This public disclosure escalated our action, allowing our team to intervene and interrupt the actor mid-operation, limiting broader impact,” explained Microsoft.

As dangerous as this sounds, the hacking group LAPSUS$, isn’t typical. The group is more interested in holding the source code ransom for tech giants in order to make a profit. That’s because source code repositories could also have API keys and code signing certificates. LAPSUS$ did this with Nvidia when it stole DLSS code and demanded that the GPU maker “completely open-source (and distribute under a FOSS license) [its] GPU drivers.”

Article updated on March 23 with Microsoft response to LAPSUS$ hack.

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
This Bing flaw let hackers change search results and steal your files
The new Bing preview screen appears on a Surface Laptop Studio.

A security researcher was recently able to change the top results in Microsoft’s Bing search engine and access any user’s private files, potentially putting millions of users at risk -- and all it took was logging into an unsecured web page.

The exploit was discovered by researcher Hillai Ben-Sasson at their team at Wiz, a cloud security firm. According to Ben-Sasson, it would not only allow an attacker to change Bing search results but would also grant them access to millions of users’ private files and data.

Read more
Microsoft’s Bing Chat waitlist is gone — how to sign up now
Microsoft Edge browser showing Bing Chat on an iPhone.

It appears Microsoft is doing away with the long Bing Chat waitlist. As originally reported by Windows Central, new users who sign up for the waitlist are immediately given access to the AI chatbot, without having to wait, and Digital Trends has confirmed this to be the case.

Microsoft hasn't officially killed the waitlist, but it should go away in short order. On Tuesday, Microsoft bolstered OpenAI's launch of the GPT-4 model by confirming that it was the model behind Bing Chat. Microsoft is also set to host an AI-focused event on Thursday, where we expect to hear about AI integrations in Microsoft's Office apps like Word and PowerPoint. It's possible Microsoft could remove the waitlist during the presentation.

Read more
Edge Copilot finally delivers on Microsoft’s Bing Chat promises
Here's Microsoft's example of how Bing chat will work in the future.

Microsoft is finally making the version of Bing Chat we heard about in February a reality. The latest version of Microsoft Edge (111.0.1661.41) includes the Bing Copoilot sidebar, which allows you to chat, generate AI content, and get insights into topics powered by AI.

This is the form of Bing Chat Microsoft originally pitched. Since its launch, the chat portion of Bing Chat has been available through a waitlist that, according to Microsoft, has amassed millions of sign-ups. However, Microsoft also talked about Bing Copilot, which would live in the Edge sidebar and open up the possibility of generating emails, blog posts, and more, as well as provide context for whatever web page you were on.

Read more