Feeds

Did Microsoft actually put 'get repeatedly pwned by Syrian hackers' on its 2014 todo list?

Now its Office blog is trashed

Internet Security Threat Report 2014

Another week, and yet another successful compromise of Microsoft's servers by the so-called Syrian Electronic Army. And this time it's Redmond's revamped Office blog that got vandalized.

Hacked Microsoft Office blog

All your blogs are belong to us

"A targeted cyberattack temporarily affected the Microsoft Office blog and the account was reset," a spokesperson told El Reg in a statement.

"We can confirm that no customer information was compromised. Microsoft continues to take a number of actions to protect our employees and accounts against this industry-wide issue."

Microsoft relaunched the Office blog on Monday, but in a series of Twitter postings the self-styled Syrian Electronic Army (SEA) mocked Redmond's attempts to keep the dastardly defacers at bay: "Changing the CMS [content management system] will not help if your employees are hacked and they don't know about it."

It's a highly embarrassing development for Microsoft. Last week the SEA successfully got into two official Microsoft Twitter accounts and one blog, and a few days later Redmond was forced to admit that some of its staff email accounts had also been taken over.

The SEA has made Microsoft a target because it claims Redmond is selling user data from Hotmail and Outlook to the US government for monitoring purposes. Microsoft has denied this, although it was named as a participant in the NSA's PRISM massive internet surveillance operation in leaked documents from whistleblower Edward Snowden.

This latest hack is another embarrassment for a company that has been making much of its advanced computer security capabilities. In November the Windows giant trumpeted its new Digital Crimes Unit facility, a CSI-style center designed to map cybercrooks around the world and stop them in realtime.

While Microsoft has had some success in tracking down and eliminating armies of hackered-controlled hijacked PCs (aka botnets), it might be an idea if Redmond spent a little more time putting its own house in order and allocated some resources to knocking back the SEA.

The hacking group started out going after media outlets and caused a brief stock-market rollback after broadcasting the report of an explosion at the White House on AP's Twitter feed. Rival hacktivist group Anonymous claimed to have targeted the SEA, but this latest attack suggests that the SEA is still out there cracking passwords. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.