TechCrunch News 2024年10月18日
Microsoft said it lost weeks of security logs for its customers’ cloud products
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

微软通知客户,其云产品在9月的两周内未持续存储安全日志,可能导致网络防御出现盲点。原因是内部监测代理的一个漏洞,该问题并非安全事件引起,仅影响日志事件收集。受影响产品包括多种,缺失日志可能影响客户分析数据、检测威胁等能力。微软已采取措施缓解问题,并向受影响客户沟通提供支持。

🥔微软云产品在9月的两周内安全日志存储出现问题,原因是内部监测代理的一个漏洞,导致部分代理在向内部日志平台上传数据时出现故障,此问题并非安全事件导致,仅影响日志收集。

🎯受影响的产品包括Microsoft Entra、Sentinel、Defender for Cloud和Purview等,受影响客户可能在安全相关日志或事件方面出现潜在缺口,可能影响其分析数据、检测威胁或生成安全警报的能力。

💪微软已通过回滚服务变更来缓解该问题,并已与所有受影响客户进行沟通,表示将根据需要提供支持。但此前微软曾因未向某些美国联邦政府部门提供安全日志而受到指责。

Microsoft has notified its customers that it wasn’t consistently storing security logs for its cloud products during a two-week window in September, leaving network defenders with a potential blind spot for detecting possible intrusions.

According to a notification sent to affected customers, Microsoft said that “a bug in one of Microsoft’s internal monitoring agents resulted in a malfunction in some of the agents when uploading log data to our internal logging platform.” 

The notification said that the logging outage was not caused by a security incident, and “only affected the collection of log events.” 

Business Insider first reported the loss of log data earlier in October. Details of the notification have not been widely reported. As noted by security researcher Kevin Beaumont, the notifications that Microsoft sent to affected companies are likely accessible only to a handful of users with tenant admin rights.

Logging helps to keep track of events within a product, such as information about users signing in and failed attempts, which can help network defenders identify suspected intrusions. Missing logs could make it more difficult to identify unauthorized access to the customers’ networks during that two-week window. 

The affected products include Microsoft Entra, Sentinel, Defender for Cloud, and Purview, according to the Business Insider report. Affected customers “may have experienced potential gaps in security related logs or events, possibly affecting customers’ ability to analyze data, detect threats, or generate security alerts,” the notification said.

Microsoft would not answer specific questions about the logging outage, but a Microsoft executive confirmed to TechCrunch that the incident was caused by an “operational bug within our internal monitoring agent.”

“We have mitigated the issue by rolling back a service change. We have communicated to all impacted customers and will provide support as needed,” said John Sheehan, a Microsoft corporate vice president.

The logging outage comes a year after Microsoft came under fire from federal investigators for withholding security logs from certain U.S. federal government departments that host their emails on the company’s hardened, government-only cloud, which investigators said having access to those logs could have identified a series of China-backed intrusions far sooner.

The China-backed intruders, referred to as Storm-0558, broke into Microsoft’s network and stole a digital skeleton key that allowed the hackers unfettered access to U.S. government emails stored in Microsoft’s cloud. According to a government-issued post-mortem of the cyberattack, the State Department identified the intrusions because the it paid for a higher-tier Microsoft license that granted access to security logs for its cloud products, which many other hacked U.S. government agencies did not have.

Following the China-backed hacks, Microsoft said it would start providing logs to its lower-paid cloud accounts from September 2023.

Carly Page contributed reporting.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

微软 安全日志 云产品 数据安全
相关文章