Microsoft admits it lost weeks of security logs due to operational bug

Microsoft admits it lost weeks of security logs due to operational bug

Microsoft has confirmed that more than two weeks' worth of security logs were missing from some of its cloud products. The company said the issue was caused by a malfunction in one of its internal monitoring agents, which occurred between September 2 and September 19, 2024.

According to Microsoft, a bug in one of its internal monitoring agents has lead to failed uploads of log data to the company’s logging platform. The issue primarily impacted logs from Microsoft Entra, Sentinel, Defender for Cloud, and Purview. These logs typically provide information about sign-ins, failed login attempts, and other activity that can help defenders spot possible security incidents.

Microsoft clarified that the bug was introduced during efforts to fix a separate problem with its log collection service. Although the company followed safe deployment practices, it failed to detect the new issue for several days. However, Microsoft said that the problem has since been resolved.

"We have mitigated the issue by rolling back a service change. We have communicated to all impacted customers and will provide support as needed," John Sheehan, Microsoft’s corporate vice president, told TechCrunch.

The incident follows a string of high-profile security issues for the tech giant. In May 2023, a Chinese hacker group tracked as Storm-0558 exploited a vulnerability in Microsoft’s services, stealing a signing key that allowed them to breach corporate and government Exchange and Microsoft 365 accounts. The threat actor breached an unidentified number of email accounts linked to around 25 organizations, including some related individual consumer accounts and government agencies in Western Europe and the US.

The attackers leveraged forged authentication tokens to access impacted email accounts via Outlook Web Access in Exchange Online (OWA) and Outlook.com.

A few months after the attack, the DHS Cyber Safety Review Board (CSRB) released a report on Microsoft's hack blaming the company for the intrusion, which officials said was “preventable” and that “Storm-0558 was able to succeed because of a cascade of security failures at Microsoft.”

Back to the list

Latest Posts

Hackers exploited zero-day flaw in Gladinet CentreStack software since March

Hackers exploited zero-day flaw in Gladinet CentreStack software since March

The issue stems from a hardcoded machineKey in the web application’s configuration file.
10 April 2025
Intelligence agencies warn of Chinese spyware targeting Taiwan, Tibetan rights advocates

Intelligence agencies warn of Chinese spyware targeting Taiwan, Tibetan rights advocates

The advisory focuses on two spyware families, dubbed ‘BadBazaar’ and ‘Moonshine’ masquerading as seemingly legitimate apps.
9 April 2025
One of largest bulletproof web hosting providers Media Land got its internal data leaked

One of largest bulletproof web hosting providers Media Land got its internal data leaked

Researchers believe the hacker behind the breach is likely the same group responsible for the previous BlackBasta leak.
9 April 2025