Axios Codebook

January 30, 2024
Happy Tuesday! Welcome back to Codebook.
- 🏈 Congrats to my fellow Swifties on our first Super Bowl! Who said we can't have it all?
- 📬 Have thoughts, feedback or scoops to share? [email protected].
Today's newsletter is 1,228 words, a 4.5-minute read.
1 big thing: Microsoft's latest flaw hits open-source projects
Illustration: Aïda Amer/Axios
A team of security researchers has uncovered a flaw in Microsoft's code development and testing environment that could affect upward of 70,000 open-source projects, according to a report first shared with Axios.
Driving the news: Researchers at Legit Security said in a report today that they've found a flaw in popular testing tool Azure Pipelines that would allow hackers to inject malicious code into source code and other projects hosted in code testing environments.
Details: The vulnerability can be triggered when someone submits a contribution or edit to a build system project hosted on Azure Pipelines, Liav Caspi, co-founder and chief technology officer at Legit Security, told Axios.
- When Azure Pipelines runs a review of that code, it usually tests the new suggestion in a "sandbox" environment.
- However, Legit Security researchers found a way to trick a build system into running the test code in a live environment, Caspi said, "so it can find out sensitive secrets and sensitive data."
- The bug has a 7.3 out of 10 severity rating on the industry's widely used Common Vulnerability Scoring System and could give hackers elevated access to an organization's networks, but it would need to be combined with another vulnerability to execute an attack, per Microsoft.
Yes, but: The problem still affects only code that's hosted on the on-premise version of Azure Pipelines and those who haven't manually updated to the latest version.
- Microsoft released a patch in October, and all customers who have installed the latest software updates or have automatic updates are already protected, a spokesperson told Axios.
- Code repositories that have implemented a so-called trigger in Azure Pipelines are likely to be most vulnerable, Caspi said.
The big picture: The recent disclosure underscores the growing importance of both supply chain security and securing open-source code, especially in companies' source code.
- Ever since the 2020 hack of SolarWinds, Legit Security's clients have made scanning and securing their software supply chains a top priority, and Caspi's team found this new flaw while poking around Azure Pipelines for customers.
What they're saying: "If you're developing software, and this software is important, and it's driving the business, there's a lot of focus on, 'Can somebody change something in the build? Can somebody steal data?'" Caspi said.
Catch up quick: The news also comes as Microsoft continues to wrestle with a recent Russian hack of its senior executives' email inboxes.
- The company said last week that it had started notifying other companies that were targets of the same Russian hacking group.
Between the lines: Both the vulnerability that Legit Security found and the recent Russian hack take advantage of weaknesses in Microsoft's production environments.
- In the recent breach, the Midnight Blizzard group first gained access to Microsoft's systems via a password-spraying attack targeting a "legacy non-production test tenant account."
The intrigue: Microsoft was quick to respond to Legit Security's vulnerability, Caspi said, which isn't always a guarantee when security researchers submit their findings to large companies.
The bottom line: Caspi said his company finds all sorts of security flaws in testing environments and systems that host a company's source code — not just in Microsoft products.
- "This specific area of supply chain security — build security — is a bit of a new territory," he said. "The more people dig in, the more they find. It's a little bit uncharted."
2. Feds release plan for AI operators' info-sharing
Illustration: Annelise Capossela/Axios
AI developers whose models pose risks to national security are now starting to report "vital information," including safety test results, to the Department of Commerce before releasing their models to the public, the White House said Monday.
Why it matters: This marks the start of the first formalized safety and security information-sharing program between some of the most powerful AI model developers and the federal government.
Driving the news: The White House hosted the first meeting of its new AI Council on Monday.
- The council, which includes top officials from a range of federal offices, met to discuss the progress they've made in implementing President Joe Biden's AI executive order.
Details: Part of that progress has been implementing a new requirement for certain AI model developers to share key details about their models with the federal government.
- The Commerce Department is authorizing this power under the Defense Production Act, a 1950 law that was established to give the president the ability to implement certain domestic economic controls, such as the ability to require companies to prioritize national defense contracts.
The other side: Industry groups have pushed back against this new requirement, arguing that a government review process will slow down innovation.
Meanwhile, the Commerce Department also released a proposed rule that would require cloud providers to report information about non-U.S. customers who use their services to train AI models.
Yes, but: A Commerce Department spokesperson declined to share which companies are required to comply with these new rules.
3. Dwindling paydays for ransomware


Fewer ransomware victims are paying up when faced with a ransomware attack, according to a new report from ransomware negotiation firm Coveware.
Why it matters: Malicious hackers are opportunistic and follow the money.
- If the money dries up in ransomware, they're likely to turn to other schemes.
By the numbers: 29% of organizations paid a ransom in the last quarter of 2024 to get their stolen data back and unlock their systems during a cyberattack, according to Coveware's report, released Friday.
- That's a completely different story from the 85% who were paying in the first quarter of 2019.
- The average ransom payment in the fourth quarter of 2023 was roughly $568,000 — a 33% drop from the third quarter.
Between the lines: Coveware attributes the drop last quarter to a few factors.
- Enterprise networks have built up better cyber defenses and have more data backups to help them recover quickly.
- More companies don't trust hackers to keep their promises and delete any stolen data.
The big picture: Ransomware has become a top cyber threat for all organizations — from the world's largest companies to small mom-and-pop businesses — over the last five years.
- Government officials have spent years trying to make a dent in the number of ransomware attacks targeting businesses, governments and other entities.
Yes, but: Ransomware hackers are known to be adaptable and will likely change their tactics to get more payments.
- Cybersecurity officials and industry experts believe ransomware is already an endemic issue.
4. Catch up quick
@ D.C.
🗳️ Taiwan deployed a mix of fact-checking groups, social media influencers and official government press statements to debunk China-backed disinformation during its elections this month. (Associated Press)
🤷🏻♀️ Most government agencies did not have sufficient plans for securing smart devices as of early last year, according to a previously unreported internal government assessment. (Nextgov/FCW)
@ Industry
🤖 China has approved more than 40 AI models for public use in the last six months. (Reuters)
⚠️ Microsoft has added new protections to its AI text-to-image generation tool after reports that people had abused it to create nonconsensual sexual images of celebrities. (404 Media)
@ Hackers and hacks
⚡️ Energy giant Schneider Electric reportedly faced a ransomware attack earlier this month. (BleepingComputer)
👨🏻⚖️ Former Department of Homeland Security employees were sentenced to prison after pleading guilty to stealing databases with personal data belonging to 200,000 federal employees. (New York Post)
💸 A D.C. theater was able to get back $250,000 of funds stolen during a recent hack. (The Record)
☀️ See y'all Friday!
Thanks to Scott Rosenberg and Megan Morrone for editing and Khalid Adad for copy editing this newsletter.
If you like Axios Codebook, spread the word.


