Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

241–250 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#241

Earlier quoted context omitted.

> several pillars are missing from their “Zero Trust” marketing materials. TBH several pillars are missing from their entire security posture.

why bother when not a single vulnerability has resulted in any appreciable fines or loss of market share? it's absurd how untouchable their ubiquity has become.

They’re the Boeing of software. They go down with the ship, but, critically, it means they also can’t go down until and unless the ship also does.

It’s a symbiotic relationship that allows them to stop having to spend resources to compete in the market on merit.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#242
post #239

Earlier quoted context omitted.

It almost seems like the goal is to hurt people

[flagged]

There's some truth to this in that all organizations ultimately have their own perpetuation as a goal...but this is also a little like saying "well, there are a lot of complicated macroeconomic drivers of theft" while you're stealing somebody's purse.

The harms here are not the result of some broad faceless force so distributed and ethereal as to avoid accountability. The people performing them know exactly what they are doing. They're choosing to do it, when no systemic factor forces them to. If they wanted to not harm people, they could do so at zero or even negative harm to themselves.

Systems-level thinking is a useful tool, but it can make you miss the trees for the forest when a single concrete human being in front of you is just a bad person.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#243

With the chaos of the current administration has there ever been a better time? (other than maybe tomorrow)

I tell you in good faith: the chaotic response would have been to not notice, not disclose, not fix, and then go to the press claiming everything is fine, and accusing anyone saying otherwise of having a nefarious agenda.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#246

> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.

Oh CISA... What a pity that CISA has been purged down of effective useful people and turned into another sad selected-for-political-compliance-only force. Arizona recently got attacked from Iranian hackers & didn't even bother trying to get help from CISA. https://archive.is/2025.07.19-143305/https://www.azcentral.c... CISA is so so vital. Investigating incredibly wide ranging attacks like this, or the Salt Typhoon a…

So true, they make bullshit that affect security also on some security tools analyser … do not worry NSA everything is fine, you are not at risk against worms xD

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#247

It is instructive that we are seeing the results of DOGE's work: "The process took six hours Saturday night — much longer than it otherwise would have, because the threat-intelligence and incident-response teams have been cut by 65 percent as CISA slashed funding, Rose said."

Why isn't this under a branch of the military? Get lots of funding then. Protects national security

Because the losers and deadbeats who run the government have not figured out the right approach to making "pay 20x the current budget to military contractors to do half of what CISA does" sound like a good deal for taxpayers.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#249
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Most enterprise PCs are Windows machines and integrate with Microsoft services easily. The only way Microsoft is going to lose the enterprise market is if enterprise PCs move away from Windows. But, for enterprises, the only reasonable migration away from Windows is Mac. JAMF Pro for Mac can be hosted on-premise on Linux. The majority of enterprise software runs on Mac. However, Macs are expensive so it's unlikely to…

"Hardware support for Linux PCs is poor and lacks the manageable of Windows PCs with Active Directory and GPO, or JAMF for Macs. Enterprise software usually doesn't support Linux. Linux PCs are uncommon for personal use and corporations don't want to train users how to use Linux."

I would dispute the "hardware support" comment. Linux has pretty good hardware support nowadays. And "enterprise" software is a vague term here. For desktop Windows, of course Microsoft will have that covered every which way, but for things such as authentication, authorization and security, Linux has a place. A comment about adding "Redhat" to the mix is not talking about desktops (necessarily) but servers and security.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#250
post #145

Earlier quoted context omitted.

that's cool, do you support an RSS feed?

Not yet, but I’m planning to roll one out later this week! Are you in cybersecurity or just tracking vulnerabilities for fun/work?

I work both cybersec + fun/research, LOVE this resource and lucky to have come across it here. Subscribed via email & looking forward to RSS. Thanks for sharing it here!
Post reply on HN