Vulnerabilities / Threats
7/14/2010
04:28 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Microsoft Employee From Russia Linked To Spy Ring

The company says the software tester didn't compromise any data or systems.

Microsoft has acknowledged that Alexey V. Karetnikov, alleged to have been the 12th member of a group of Russian spies arrested last month, worked for the company at its headquarters in Redmond, Washington.

A company spokesperson confirmed that Karetnikov was employed for nine months as an entry-level software tester.

Karetnikov's Facebook page indicates that he worked as a Software Development Engineer in Test (SDET), located in Redmond.

Microsoft, the spokesperson said, has reviewed his activities and is confident he did not compromise the company’s software or systems.

Karetnikov had been detained since June 28 on immigration violations, according to The Wall Street Journal, and was sent home on Tuesday without being charged with a crime.

Citing unnamed sources, The Wall Street Journal said that Karetnikov came to the attention of FBI agents last fall in connection with the agency's decade-long investigation into Russian "illegals," as the deep-cover spies have been called.

That investigation concluded last month when the U.S. Department of Justice charged 11 people with covertly gathering intelligence for Russia.

Ten of them pleaded guilty to acting as unregistered agents of a foreign government and were deported last week.

The 11th was detained in Cyprus and subsequently jumped bail.

Karetnikov reportedly acknowledged that he was in the U.S. illegally and agreed to leave voluntarily.

It appears that either the U.S. lacked enough evidence to charge him or that the nation interest was better served by dispensing with legal proceedings.

U.S. officials traded the agents they detained for four Russians imprisoned in Russia on intelligence-related charges last week.

The spy swap is widely seen as a way to defuse international tensions heightened by the arrests and to help strengthen relations between the U.S. and Russia, a goal favored by the leaders of both countries.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.