Happy week 10!
In this week's cybersecurity roundup, I cover a range of critical incidents and developments, from a Google engineer's theft of AI trade secrets to the discovery of multiple vulnerabilities in QNAP's NAS software.
🌐 This Week in Cybersecurity
Google Engineer Steals AI Trade Secrets for Chinese Companies
- Theft of Proprietary Information: Linwei Ding, a Google software engineer, is accused of stealing trade secrets related to Google's AI supercomputing systems, data center management software, and AI models from May 2022 to May 2023. He siphoned the data to a personal Google Cloud account while secretly affiliating with two Chinese tech companies.
- Concealment Techniques: To conceal the theft, Ding allegedly copied data from Google source files into Apple Notes on his company MacBook, converted them to PDFs, and uploaded them to his Google account. He also allowed another employee to use his access badge to give the impression he was working from the U.S. while in China.
- Competitive Advantage for Chinese Firms: Ding's startup company in China aimed to replicate and upgrade Google's computational power platform, giving them an unfair competitive advantage. The stolen trade secrets could potentially accelerate the development of AI capabilities in China.
- Legal Consequences: Ding has been charged with four counts of theft of trade secrets, each carrying a maximum penalty of 10 years in prison and a $250,000 fine. The case highlights the ongoing threat of intellectual property theft and the need for robust cybersecurity measures to protect sensitive data.
Microsoft Confirms Russian Cyberspies Stole Source Code and Accessed Internal Systems
- Ongoing Intrusion: Microsoft has confirmed that the Russian cyberspies known as Midnight Blizzard (aka Cozy Bear, APT29) have stolen source code and gained access to internal systems. The intrusion, which began in November, is characterized as "ongoing" with a significant commitment of resources by the threat actor.
- Unauthorized Access Attempts: Midnight Blizzard is using information initially exfiltrated from Microsoft's corporate email systems to attempt to gain unauthorized access to source code repositories and internal systems. While there is no evidence of compromised customer-facing systems, the volume of password spray attacks increased ten-fold in February compared to January.
- Potential Misuse of Sensitive Data: Concerns have been raised about how the potential access to Microsoft's sensitive data and AI models may be misused by hostile nation states, especially with 42 percent of the world's population electing new leadership in 2024. The threat actor may be accumulating information to enhance their ability to attack targeted areas.
- Ongoing Investigation and Mitigation: Microsoft's investigation is ongoing, and they are reaching out to affected customers to assist them in taking mitigating measures. The security breach has not had any financial impact on Microsoft's operations yet. However, the incident raises questions about Azure's authentication and security mechanisms, and reinforces the need for robust cybersecurity measures in the face of sophisticated nation-state attacks.