Earlier quoted context omitted.
Best practice is to assume the network is compromised - a VPN doesn't provide as much guarantee as people would like. In large fleets, devices are regularly lost, damaged, retired, etc. In organizations with high target value, physical penetration through any number of means should be assumed. So you don't do that. You use zero trust and don't care that things are exposed to the internet. Working from anywhere (remot…
Maybe I'm missing something but doesn't this very story cut your assertion off at the knees? With a VPN the attack surface of this vulnerability would have been miniscule compared to a publicly accessible zero-day RCE (And it's not like you have to allow carte-blanche access behind the wall) Defense in depth!
Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
111–120 of 456 posts
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#112At the risk of massive downvotes, I have to admit that a small part of me wants this so that maybe corporations stop using Sharepoint as soon as possible. Seriously, I haven't used it since 2017, but every time I used it then it was the worst part of my day. I used to have a shirt that said SHarepoIT Happens that I would wear to work, and it seemed like the one thing I could get my coworkers agree on was that Sharepo…
The only reason to get downvotes is nonsense of prefacing the post with the 'worry'. Sharepoint would be far from a first choice under normal circumstances (e.g. not bundled with excel and friends)
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#113It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."
I'm not sure which part pisses me off more: that tons of professionals lost their jobs and will likely not work in public service again because of it, or that through all that, they barely found any actual waste at all. A fucking farce.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#114Earlier quoted context omitted.
Seems like generally it ended up being a surveillance play, in practice if not original intent. For example, Dog coin has been reported to be passing data taken from other agencies directly to ICE^[1] for law enforcement applications, and there was that other matter of logins apparently from Russia using accounts the Dog coin personnel demanded agencies create on their internal systems with (auditable) logging disabl…
The idea that Musk's intent was to gut all of the agencies that were in a position to regulate any of his companies does seem to suggest that DOGE was an outstanding success.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#115How did Principal Engineer Copilot not prevent this?!
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#116Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#117Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#118Earlier quoted context omitted.
CrowdStrike is not made or owned by Microsoft.
Giving OP the benefit of the doubt, there were issues with how the Windows kernel had little guardrails and restrictions. That said, that was the EU's fault, as the EU in 2009 forced Microsoft to fully expose their OS internals to outside vendors during an anti-trust settlement, and with little ability to enforce vendor standards: ""Microsoft shall make available to interested undertakings Interoperability Informatio…
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#119I have spent far too much of my life on SharePoint. Having it internet facing has never been a good idea. Not really what it is meant for, though the promo verbiage on that has changed over different versions. Some folks wanted SharePoint as their "web server", I would set that installation up entirely separted from all other instances they may have on the network.
Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
#120> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.
Once upon a time Microsoft marketed it as, and a lot of Orgs adopted SharePoint as their Intranet. With SharePoint 2019 being sunset, a lot of Orgs are scrambling to implement replacements.