> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.
Oh CISA... What a pity that CISA has been purged down of effective useful people and turned into another sad selected-for-political-compliance-only force. Arizona recently got attacked from Iranian hackers & didn't even bother trying to get help from CISA. https://archive.is/2025.07.19-143305/https://www.azcentral.c... CISA is so so vital. Investigating incredibly wide ranging attacks like this, or the Salt Typhoon a…
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
191–200 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#192Earlier quoted context omitted.
> Isn't security the number one priority in those spaces? Money changing hands between suitable people who pop up together at the right social occasions is the priority.
This though is also true in the private sector.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#193It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."
I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.
The problem is that while common sense would dictate those nonsensical expenses as such, they were part of the official process, so it was all legalized, so they avoid the FWA labels because the rule writers have made it so.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#194Earlier quoted context omitted.
> Private Teams messages are stored in individual Exchange mailboxes. Good lord. It truly is a layer of dung layered upon more layers of dung.
Throwaway account so keep this comment separate from my main account. I used to work within the Office group. The way that data is organized in Exchange is mind-boggling -- and not in a good way, IMO. Its design is from decades ago, and trying to understand how to find something really takes a lot of experience. Without going into any gruesome details of how it works, I'll just say that it is a HUGE hurdle to being p…
I assume you're talking about MAPI, which owes some of its baroque nature to X.400. It definitely comes from another time. It always struck me as over-engineered.
On the other hand, it has also been ridiculously successful.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#195Earlier quoted context omitted.
SharePoint is primarily written in C# [.NET Framework 4.8] and leverages ASP.NET; there would be no reason to rewrite the majority in another language. There is some C++ in SharePoint Search (and a few other components here and there). IIS which SharePoint runs atop of is written in presumably primarily C. You can decompile most of SharePoint if you ever need to peek at the code. That's a huge advantage to figure out…
[flagged]
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#196Earlier quoted context omitted.
Link: https://www.reuters.com/world/us/microsoft-stop-using-engine...
That is... crazy. Would the CCP allow their cloud infra to be administrated by US staff in the US? Never.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#197Earlier quoted context omitted.
Microsoft’s version of “Zero Trust” doesn’t care if things are reachable from the public internet. They have been preaching “identity is the new perimeter” [1] for years, and it doesn’t wash. The NIST Zero Trust Architecture (ZTA) implementation guides (SP 1800-35) [2] cut through the nonsense and AI generated marketing smoke. In ZTA, ALL network locations are untrusted. Network connections are created by a Policy En…
> several pillars are missing from their “Zero Trust” marketing materials. TBH several pillars are missing from their entire security posture.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#198> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.
I never remember thinking years ago how nice it would be to have all of our private docs that we only need to access on our private network accessible to the public. I just wasn’t thinking outside the box enough.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#199Earlier quoted context omitted.
I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.
There is waste. A God awful amount of waste, fraud, and abuse. You don't rack up a 1.8 trillion deficit and a debt per capita that is 7x the income per capita without waste, fraud, and abuse. The problem is that while common sense would dictate those nonsensical expenses as such, they were part of the official process, so it was all legalized, so they avoid the FWA labels because the rule writers have made it so.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#200> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.