[HN Gopher] Global hack on Microsoft Sharepoint hits U.S., state...
       ___________________________________________________________________
        
       Global hack on Microsoft Sharepoint hits U.S., state agencies,
       researchers say
        
       https://archive.ph/Ym2jZ,
       https://web.archive.org/web/20250721135933/https://www.washi...
       https://research.eye.security/sharepoint-under-siege/
       https://krebsonsecurity.com/2025/07/microsoft-fix-targets-at...
       https://www.bleepingcomputer.com/news/microsoft/microsoft-re...
        
       Author : spenvo
       Score  : 268 points
       Date   : 2025-07-20 21:58 UTC (1 days ago)
        
 (HTM) web link (www.washingtonpost.com)
 (TXT) w3m dump (www.washingtonpost.com)
        
       | aspenmayer wrote:
       | https://archive.is/LVrQQ
       | 
       | Related:
       | 
       |  _ToolShell Mass Exploitation (CVE-2025-53770)_ -
       | https://research.eye.security/sharepoint-under-siege/ |
       | https://news.ycombinator.com/item?id=44629133
        
       | jmclnx wrote:
       | Another day another vulnerability with Microsoft. I wonder if
       | this will incentivize the countries to move faster with Linux.
       | 
       | Probably not since there are so many of these breaches people
       | just ignore them.
       | 
       | I miss the old days when a breach involved someone breaking into
       | the computer room and grabbing as many mag tapes as they can
       | carry and run :)
        
         | SketchySeaBeast wrote:
         | Genuinely asking - is there a Linux alternative to Sharepoint?
         | I couldn't care less if it was lit on metaphorical fire and
         | dumped into the sea, but a lot of orgs using it extensively.
        
           | bangaladore wrote:
           | O365 is a poor amalgamation of like 18 different things.
           | Quite frankly I hope there isn't a true "alternative" to it.
           | 
           | The reason orgs use Sharepoint is they are forced to if they
           | use Microsoft. One drive is sharepoint, teams is sharepoint,
           | sharepoint sites is sharepoint, etc...
           | 
           | I'm sure all those things have better alternatives, but
           | Microsoft shoves them down your throat when you license with
           | them.
        
             | SketchySeaBeast wrote:
             | But it's understandable why an org would prefer that to
             | having to maintain and manage the 18 things, right? It's a
             | hard sell.
             | 
             | I'm not saying that wouldn't be better, but it makes sense
             | why an org would be reluctant. Again, not a fan of
             | Sharepoint myself, but from an org's viewpoint, moving to
             | Linux raises more problems than it solves.
        
               | bangaladore wrote:
               | It's understandable, but it doesn't excuse how poorly
               | everything actually works and how confusing it is to use
               | and administrate.
               | 
               | To some extent I think Microsoft is largely in the
               | business of building solutions for problems that don't
               | exist.
               | 
               | Most orgs are probably perfectly fine with a document
               | management system + desktop word application and then a
               | commercial NAS for bulk storage / backups.
        
             | kuhsaft wrote:
             | > Sharepoint is a poor amalgamation of like 18 different
             | things.
             | 
             | You've got it backwards. Everything M365 is an amalgamation
             | of Entra, SharePoint, and Exchange.
        
               | bangaladore wrote:
               | Yes, thanks for the correction.
        
           | ray_v wrote:
           | git repo hosted on a secure server behind several layers of
           | VPN? I'm sure I could probably come up with something more
           | secure than freaking sharepoint
        
           | jonathanlydall wrote:
           | Sorry, I don't know the answer to your question, but I can
           | offer some possible insight into why it's used so much.
           | 
           | We're on Microsoft 365 and technically fall into the camp of
           | "uses SharePoint", but only for "shared network folder" usage
           | which OneDrive seamlessly synchronizes should you dislike the
           | web interface. We don't actively use any other features of
           | it.
           | 
           | Also worth mentioning that realtime collaboration and
           | automatic versioning of Office documents is seamless for
           | files on SharePoint, even if opened on a desktop on a
           | OneDrive synchronized folder.
           | 
           | Files shared over Teams as well as meeting recordings are
           | also stored on SharePoint.
           | 
           | My point is that SharePoint is used a lot but possibly not in
           | the way one might have assumed.
           | 
           | I don't know if self hosted SharePoint can do all this.
        
             | hulitu wrote:
             | > seamlessly
             | 
             | In 50 % of the time.
        
           | kuhsaft wrote:
           | For collaborative documentation, there's probably a bunch of
           | alternatives.
           | 
           | But SharePoint is the linchpin for Microsoft 365. Well
           | technically SharePoint and Exchange. You can't use any
           | Microsoft 365 products without SharePoint.
           | 
           | OneDrive uses SharePoint. Outlook Groups and Teams Channels
           | create Microsoft 365 Groups. Every Microsoft 365 Group
           | creates a SharePoint site. Microsoft Loop uses Microsoft
           | SharePoint Embedded.
           | 
           | SharePoint is now a "file and document management system
           | suitable for use in any application".
           | 
           | So, if you want an alternative to SharePoint you would need
           | an alternative to any M365 Product, including Outlook and
           | OneDrive.
           | 
           | Fun Fact: Teams messages are actually stored via Exchange
           | Mailboxes.
           | 
           | https://learn.microsoft.com/en-
           | us/sharepoint/dev/embedded/ov...
        
             | SketchySeaBeast wrote:
             | Yeah, that's what I'm thinking. Is it great? Well, no, but
             | it's incredibly integrated and that has a great appeal to
             | orgs.
        
             | jongjong wrote:
             | Google Docs and Libre Office both produce compatible
             | documents. There's really no reason to force one or the
             | other.
             | 
             | It's just conflating needs. Document editing and file
             | storage are two different tasks. It's weird that people
             | want everything integrated. It's not much effort to just
             | drag and drop a file into G-Drive, OneDrive, Dropbox,
             | box.com...
        
               | kuhsaft wrote:
               | > It's not much effort to just drag and drop a file into
               | ... OneDrive ...
               | 
               | See, there's the problem. Once you touch anything M365,
               | you're using SharePoint.
               | 
               | People see SharePoint as a document collaboration tool.
               | But, in reality, it's real use is as a data storage
               | platform.
        
               | Jtsummers wrote:
               | What people want are systems that compose and work well
               | together. That's what MS provides, or at least attempts
               | to provide, with SharePoint. When you start trying to
               | tack on collaborative document editors, workflow
               | management systems, shared storage, and other
               | capabilities from different providers or systems you run
               | into more and more complications (especially because most
               | of these don't offer any kind of standards compliance
               | that lets them be used interchangeably). That's also why
               | G-Suite works as a competitor to MS, it covers at least
               | the more critical integrations that people want to work
               | smoothly without needing to combine multiple maybe
               | compatible things together.
        
               | vel0city wrote:
               | > Document editing and file storage are two different
               | tasks.
               | 
               | Not if you want to enable multiple users to be live
               | editing the document at the same time.
        
           | anonfordays wrote:
           | It's not just SharePoint, it's the entire Microsoft suite of
           | "productivity" products that the government uses. Is there a
           | Linux alternative to that?
        
           | whynotmaybe wrote:
           | nextcloud ?
        
           | justsomehnguy wrote:
           | NextCloud is actively tries to be AIO replacement for
           | SharePoint.
           | 
           | Of course it's quite a poor replacement but it does exists.
        
           | Sanzig wrote:
           | Nextcloud, particularly with the Collabora Office integration
           | for real-time collaborative document editing. It's got some
           | rough edges but I'd say it suits the majority of use cases
           | now. I suggest spinning up a copy of the community edition in
           | a VM to give it a spin, I was pleasantly surprised. There is
           | a lot of money getting poured in right now as entities
           | outside the US are exploring ways to ditch American software.
        
           | thewebguyd wrote:
           | For the file storage/sharing/collaboration part, yeah -
           | there's plenty, and sharepoint arguably sucks even for that.
           | 
           | What trapped a lot of orgs is making use of the whole
           | PowerPlatform around sharepoint. There's a lot of crusty old
           | LoB apps built with MS's no code tools (PowerAutomate,
           | PowerApps) which run on SharePoint as the delivery platform.
           | Some of these even hook into Excel files stored in the
           | various document libraries, etc. There are entire, large
           | business processes being handled by this platform, and so
           | migrating will require actual dev time, which automatically
           | makes it a non-starter for most, unfortunately. Doubly so
           | when you consider that a lot of these "solutions" were built
           | by non-devs, long since gone from the company and no one
           | knows how deep the tentacles go.
        
           | sugarpimpdorsey wrote:
           | The same people will tell you GIMP is a serious competitor to
           | Photoshop.
        
             | fsflover wrote:
             | And it will be true for 99% of use cases.
        
               | amelius wrote:
               | GIMP is falling behind because GenAI doesn't work out of
               | the box.
        
           | ok123456 wrote:
           | For the self-hosted version: a Synology NAS.
        
         | sivm wrote:
         | I operate under the assumption that open source projects are
         | compromised by states. If you espouse unpopular ideas or are
         | yourself a state don't rely on it.
        
           | jmclnx wrote:
           | Lets pretend what you are saying is true, which it is not.
           | Who would you want to access your data ? The State or the
           | "underworld". Many countries have laws on how to access your
           | data. The underworld, you may wake up dead.
           | 
           | Granted there are countries that act like a Criminal Org.,
           | but if you live there you have more issues than your data.
           | 
           | With proprietary software, it is a much larger chance that
           | backdoors exist than in Open Source. Many of us heard of 1
           | issue where it was claimed a project had a Gov sponsored BH
           | in it. They did a long audit and found that was false.
           | 
           | Eventually Open Source backdoors will found in Open Systems.
           | Proprietary you are SOL unless you do very expensive and very
           | hard testing. Even then it is doubtful you will find a
           | backdoor.
        
             | pessimizer wrote:
             | It is true. Denying trivial truths with the purpose of not
             | giving an inch does not add to one's argument, it weakens
             | it.
             | 
             | Plenty of closed source products will happily backdoor
             | their products on request, without a warrant, if they are
             | confident they will never be found out. That's the point.
             | Not that FOSS source is somehow inviolable to nation-states
             | with virtually infinite resources, many of which sponsor or
             | contribute to the finance of a huge percentage of the
             | development of FOSS themselves.
             | 
             | It's easier to find backdoors in FOSS if you're looking,
             | because you're allowed to look. But somebody has to be
             | looking.
        
           | temp0826 wrote:
           | Interesting, I'd more likely assume the same for closed
           | source projects as there is less transparency into the supply
           | chain
        
           | fsflover wrote:
           | https://news.ycombinator.com/item?id=27897975
        
         | lenerdenator wrote:
         | Oh, don't worry, there's plenty of known, unpatched
         | vulnerabilities in FOSS, too.
        
         | ho_schi wrote:
         | I wonder what drives people using Microsoft and then using more
         | from this company.                  We didn't knew it better,
         | back then. We knew it better, now. But migrating is work. So we
         | prefer to suffer! And harm others! This Linux and BSD people
         | are so annoying with their desire for compatibility. They shall
         | suffer, too! And when we buy everything from a Monopoly, we
         | don't need to think.
         | 
         | Somehow. Part of the game is that you've always an excuse with
         | Microsoft. You cannot made responsible? There is this quote
         | about IBM:                   Nobody Ever Got Fired for Buying
         | IBM.
         | 
         | But I cannot remember stories about suffering from IBM forever.
        
           | dizlexic wrote:
           | From what I've seen in my industry? To pass all the liability
           | to Microsoft.
           | 
           | "If something happens, we used enterprise grade industry
           | standard software. We did our due diligence."
           | 
           | This outlook is basically why we can't innovate anymore.
           | 
           | I had to recently sit through a meeting where our CTO quoted
           | all the "blogs" he's been reading as a way to slap down my
           | suggestion for an in-house project.
           | 
           | It's all about CYA.
        
         | hulitu wrote:
         | > I wonder if this will incentivize the countries to move
         | faster with Linux.
         | 
         | Countries are run by politicians. The ability of a politician
         | to remember something is inverse proportional to the sum of
         | money landed in its account.
        
         | formerly_proven wrote:
         | As far as I can tell there's two vulnerabilities bundled up
         | here. One is an unauthenticated command injection (!)
         | vulnerability to steal some keys and the other is of course yet
         | another serialization-based RCE in a safe language, mediated by
         | signed cookies (signed with the keys stolen in step 1).
         | 
         | I don't understand how often this design has to blow up in
         | people's faces until they stop doing this and use something
         | dumb and safe instead.
        
       | shrubble wrote:
       | Wasn't Microsoft just recently using Chinese people living in
       | China to administer DOD servers? I would guess they use
       | Sharepoint inside the DOD?
        
         | computegabe wrote:
         | Link: https://www.reuters.com/world/us/microsoft-stop-using-
         | engine...
        
         | theteapot wrote:
         | Says this in the article:
         | 
         | > A programming flaw in its cloud services also allowed China-
         | backed hackers to steal email from federal officials. On
         | Friday, Microsoft said it would stop using China-based
         | engineers to support Defense Department cloud-computing
         | programs after a report by investigative outlet ProPublica
         | revealed the practice, prompting Defense Secretary Pete Hegseth
         | to order a review of Pentagon cloud deals.
        
         | p_ing wrote:
         | There is a DoD version of M365 which has SPO, but that isn't
         | what the article is discussing.
        
       | timewizard wrote:
       | Why didn't they just rewrite it in Rust?
        
         | tialaramex wrote:
         | IIRC Microsoft is rewriting some of these backend services in
         | Rust, although not because it will increase security but
         | because it lets them get better perf than existing solutions
         | without the safety tradeoff they'd have suffered to go to C++
         | which would have been their option 15-20 years ago. I don't
         | know whether Sharepoint was on that list.
        
           | mynameisash wrote:
           | You also can get better velocity than with other languages
           | due to the compile-time checks.
        
         | theteapot wrote:
         | They should've just Linux.
        
       | tombert wrote:
       | At the risk of massive downvotes, I have to admit that a small
       | part of me wants this so that maybe corporations _stop_ using
       | Sharepoint as soon as possible.
       | 
       | Seriously, I haven't used it since 2017, but every time I used it
       | then it was the worst part of my day. I used to have a shirt that
       | said SHarepoIT Happens that I would wear to work, and it seemed
       | like the one thing I could get my coworkers agree on was that
       | Sharepoint is terrible and we'd rather use anything else.
        
         | CommenterPerson wrote:
         | I upvoted you .. share the same sentiment.
        
         | neuroelectron wrote:
         | My boss spent over a year trying to get me to setup Sharepoint.
         | About 6 months into this, I finally looked into it and what it
         | provided and said no. Eventually he hired a second tech and he
         | set it up "in an afternoon." Good for him. Nobody ever used it.
         | He also stole my high speed USB drive.
        
           | threetonesun wrote:
           | While Sharepoint might some day die, it will only be replaced
           | by another piece of software that gets launched for nobody to
           | ever use.
        
             | dylan604 wrote:
             | Clearly Sharepoint _is_ being used. Otherwise, this would
             | not be a news story. So if every single Sharepoint user
             | switched to another piece of software, it would be more
             | than nobody using it.
        
         | weinzierl wrote:
         | Sorry to disappoint you, but Sharepoint isn't going to die.
         | 
         | This is actually a great day for Microsoft. People will come to
         | their cloud solutions in troves after this and everyone will be
         | happy. Maybe not everyone, but Microsoft for sure.
        
         | pvtmert wrote:
         | to accommodate $MSFT shareholders downvotes, have my upvote :)
         | 
         | nevertheless, even NFS is better than sharepoint. At least, NFS
         | works...
        
         | sureglymop wrote:
         | SharePoint is garbage. Even nextcloud is way better and it
         | doesn't exactly have the best reputation. It can't possibly be
         | that hard can it...
        
           | jdiez17 wrote:
           | I have never used SharePoint but I honestly cannot imagine it
           | being worse than Nextcloud + Collabora Office. Which I do use
           | almost every day.
        
             | jasonvorhe wrote:
             | You have no idea how good you have it.
        
         | delfinom wrote:
         | Good news.
         | 
         | Teams is actually SharePoint.
         | 
         | It ain't going anywhere
        
           | galangalalgol wrote:
           | My company was using slack and mattermost and consolidated to
           | teams... It is so bad.
        
         | kuhsaft wrote:
         | It's impossible to stop using M365 while stopping usage of
         | SharePoint (cloud or on-premises). See
         | https://news.ycombinator.com/item?id=44640219
         | 
         | Here's just one example:
         | 
         | Each M365 Teams Team creates an M365 Group which creates a
         | SharePoint site and Exchange mailbox. Teams channel files are
         | stored in that SharePoint site. Teams channel messages are
         | stored in the Exchange mailbox.
         | 
         | Private files dropped in Teams are stored in OneDrive
         | (rebranded SharePoint). Private Teams messages are stored in
         | the sender and recipients' Exchange mailboxes.
         | 
         | M365 _is_ SharePoint and Exchange. _EVERYTHING_ is built on
         | top.
         | 
         | EDIT: changed 'individual' to 'sender and recipients'
        
           | mschuster91 wrote:
           | > Private Teams messages are stored in individual Exchange
           | mailboxes.
           | 
           | Good lord. It truly is a layer of dung layered upon more
           | layers of dung.
        
             | anonymars wrote:
             | I don't think this is nearly as crazy as you may think at
             | first glance
             | 
             | Imagine if it was just a hidden (special) folder in an
             | Exchange mailbox.
             | 
             | Voila, you already have a well-known and widely implemented
             | and tested message syncing solution both for content and
             | status (read/unread)
             | 
             | I assume Windows Phone worked the same way with its text
             | message backup. When you'd set up a new phone it would take
             | a while for your Microsoft account to finish syncing during
             | which new messages would trickle into the Messaging app in
             | real time. In fact if your old phone was still on WiFi new
             | messages would show up on both. Still more advanced 15(?!)
             | years ago than my Android today
        
               | blibble wrote:
               | explains why scrolling up in teams loads 3 messages at a
               | time too
               | 
               | very slowly
               | 
               | and why the search doesn't work
        
         | rs186 wrote:
         | My company has SharePoint and another internal site for
         | documents/notes (think about Notion/Quip/Confluence). The other
         | site works quite well, and most developers write all their
         | notes/docs on it. But _some_ people just insist on uploading
         | Word documents to SharePoint. So now everybody else has to use
         | SharePoint as well, plus search twice whenever they need to
         | find something.
        
         | cm2187 wrote:
         | And sharepoint in large organisations I have been at recently
         | is now using oauth which breaks Microsoft's own sharepoint
         | client API. That whole software is one massive waste of time
         | and buget.
        
         | persolb wrote:
         | As a mid size company that does work with government agencies,
         | it's near impossible to use anything 'better' solution.
         | Cybersecurity requirements are getting so onerous that
         | Sharepoint is too commercially feasible of an option to use
         | anything else for a shared file store between organizations.
         | 
         | The fact that Sharepoint sucks* doesn't matter... because
         | anything else is seen as a risk.
         | 
         | * folders with lots of files are hard to scroll through because
         | each page is lazy loaded, the automation functions are buggy,
         | logins between different M365 tenants breaks and is not
         | correctable by a normal site admin, human readable URL paths
         | aren't standard, search is shit, tables/filters are buggy, the
         | new interface hides a bunch of the permissions logic, some
         | things like permission groups need to be managed via outlook,
         | etc etc. I'm sure a bunch of my gripes are technically fixable,
         | but these aren't things that should need a web search in order
         | to use/fix.
        
           | kuhsaft wrote:
           | It's not cybersecurity. It's legal, trust me. For large
           | corporations, eDiscovery is huge. Failing eDiscovery can cost
           | a company millions. Having a bunch of different data sources
           | makes it impossible, so companies stick with M365 as
           | corporate policy and call it a day.
        
         | eitland wrote:
         | At some point Microsoft tried to sell some automatic DRM system
         | based on SharePoint to some company that I worked for.
         | 
         | The sales pitch was that they could upload documents to
         | SharePoint and when people downloaded the documents SharePoint
         | would automatically apply DRM so the documents could only be
         | opened by that person on authorised machines for a specified
         | number of days.
         | 
         | Well, it turned out depending on how you logged in (using the
         | same account, just different login forms) on the SharePoint
         | server it would either give you the files with DRM applied - or
         | the completely unrestricted files.
         | 
         | We got some senior Microsoft consultant working directly for
         | Microsoft to look at it but in the end they were just as
         | confused as us.
        
         | xxs wrote:
         | >At the risk of massive downvotes,
         | 
         | The only reason to get downvotes is nonsense of prefacing the
         | post with the 'worry'. Sharepoint would be far from a first
         | choice under normal circumstances (e.g. not bundled with excel
         | and friends)
        
       | sega_sai wrote:
       | It is instructive that we are seeing the results of DOGE's work:
       | 
       | "The process took six hours Saturday night -- much longer than it
       | otherwise would have, because the threat-intelligence and
       | incident-response teams have been cut by 65 percent as CISA
       | slashed funding, Rose said."
        
         | ToucanLoucan wrote:
         | I'm not sure which part pisses me off more: that tons of
         | professionals lost their jobs and will likely not work in
         | public service again because of it, or that through all that,
         | they barely found any actual waste at all. A fucking farce.
        
           | azemetre wrote:
           | You're assuming their purpose was to find waste, it was not.
           | Their purpose was to be the Chicago boys in DC.
        
             | caconym_ wrote:
             | Seems like generally it ended up being a surveillance play,
             | in practice if not original intent. For example, Dog coin
             | has been reported to be passing data taken from other
             | agencies directly to ICE^[1] for law enforcement
             | applications, and there was that other matter of logins
             | apparently from Russia using accounts the Dog coin
             | personnel demanded agencies create on their internal
             | systems with (auditable) logging disabled^[2]. And probably
             | more that I'm forgetting.
             | 
             | One does wonder whether this was all part of Musk's vision,
             | or more thanks to the scum he hired to staff Dog coin
             | and/or other lawless opportunists in the Trump
             | administration.
             | 
             | [1] https://www.washingtonpost.com/immigration/2025/04/16/m
             | edica...
             | 
             | [2] https://www.reuters.com/technology/cybersecurity/whistl
             | eblow...
        
               | dylan604 wrote:
               | The idea that Musk's intent was to gut all of the
               | agencies that were in a position to regulate any of his
               | companies does seem to suggest that DOGE was an
               | outstanding success.
        
               | caconym_ wrote:
               | Good point!
        
           | to11mtm wrote:
           | This is what happens when Chesterton's fence is ignored...
        
             | tough wrote:
             | not just ignored but purposefully burnt down
        
           | nine_zeros wrote:
           | I'll tell you what pisses me off: Having to be subjected to
           | low security services because one political party wants to
           | run a reality TV show instead of caring for people. The
           | consequences are all for us to bear.
        
           | righthand wrote:
           | The first obvious sign was that the people not holding office
           | or having any access to government data were making unfounded
           | claims about how the government was operating.
        
             | vkou wrote:
             | The move obvious sign is that people making that claim have
             | a proven track record of being compulsive liars.
             | 
             | That anyone gives a word they say the time of day is
             | actually crazy.
        
           | tempnew wrote:
           | How about the fact that Elon and most of his cronies weren't
           | even born here and seem to feel that the people who were born
           | here are stupid and/or lazy. Maybe only Vivek said that quiet
           | part out loud, but they very much agreed on the solution.
        
       | CommenterPerson wrote:
       | Wondering if this was a self goal to, you know, get people to use
       | this enshittified product on the cloud?
        
         | Jtsummers wrote:
         | There are basically two things at play here:
         | 
         | MS's hosted version of SharePoint. It's apparently unimpacted
         | by this current round of attacks. DOD (since it's been brought
         | up by other commenters) makes significant use of this.
         | 
         | People hosting SharePoint instances themselves. Some on-prem,
         | some with rented computers. These are the impacted ones. It's
         | not about "the cloud", it's about hosted SharePoint having
         | weaknesses that were exploited and many organizations
         | apparently leaving their SharePoint instances accessible over
         | the open internet. These hosted instances are also probably old
         | and unpatched which doesn't help things. Some (many?) units
         | within DOD make use of this, but definitely not all.
        
           | fakedang wrote:
           | Tinfoil theory, but what if Microsoft secretly sponsored the
           | attack so that users ditch onprem in favour of the hosted
           | cloud version? Microsoft is in the best position to know of
           | their own software's shortcomings and would have just needed
           | to pay the right folks to do the dirty job.
        
             | Jtsummers wrote:
             | "Our product is remarkably insecure, let's convince
             | everyone of this by sponsoring an attack so they go and buy
             | our other product."
             | 
             | I mean, there are definitely stupid people everywhere, but
             | I'd hope MS leadership isn't _that_ stupid.
        
               | dylan604 wrote:
               | I mean, dumber things have happened. Governments have
               | destroyed their own government buildings to blame on the
               | opposition and gain sympathy for their causes.
        
               | Jtsummers wrote:
               | Yes, false flags. That's usually used to motivate people
               | to go attack someone or to garner sympathy or support for
               | a cause. MS's products being subject to attacks because
               | they have numerous vulnerabilities does not encourage
               | anyone to go out and buy other MS products.
               | 
               | You sink one of your own naval vessels (or it sinks due
               | to an accident and you take advantage of the situation)
               | and blame it on an enemy. That enemy is now the target of
               | your military and your population approves.
               | 
               | A shipbuilder hires someone to poke a hole in 1000 of
               | their ships that are so badly designed and manufactured
               | that it only takes a rubber ducky bouncing off the hull
               | to sink them does not encourage anyone to go back to that
               | shipbuilder.
               | 
               | False flags (particularly of the "let's kill or maim
               | hundreds of our own people and other innocent people"
               | variety) push into evil territory. They aren't _dumb_ on
               | their own, they 're calculated risks predicated on the
               | willingness of the masses to fall in line after a
               | catastrophe.
               | 
               | Deliberately hurting your own customers by using
               | weaknesses in your own systems in order to motivate them
               | to go buy your other products or services is dumb.
        
       | 1970-01-01 wrote:
       | It's not right to victim blame but it's also not wrong. Akin to
       | investing lots of money in a stock. If you took the risks of
       | maintaining a public SharePoint server in 2025, here's your very
       | bad day.
        
         | jasonvorhe wrote:
         | It's perfectly fine to victim blame corporations that keep
         | kneecapping themselves. That's a hill I'm willing to day on.
        
       | exabrial wrote:
       | Yet another Microsoft hack. Didn't we learn from Crowdstrike? All
       | Microsoft products are security hazards.
        
         | zanecodes wrote:
         | CrowdStrike is not made or owned by Microsoft.
        
           | alephnerd wrote:
           | Giving OP the benefit of the doubt, there were issues with
           | how the Windows kernel had little guardrails and
           | restrictions.
           | 
           | That said, that was the EU's fault, as the EU in 2009 forced
           | Microsoft to fully expose their OS internals to outside
           | vendors during an anti-trust settlement, and with little
           | ability to enforce vendor standards:
           | 
           | ""Microsoft shall make available to interested undertakings
           | Interoperability Information that enables non-Microsoft
           | server Software Products to interoperate with Windows Server
           | Operating System on an equal footing with other Microsoft
           | Server Software Products.
           | 
           | "Microsoft shall ensure on an ongoing basis and in a Timely
           | Manner that the APIs in the Windows Client PC Operating
           | System and the Windows Server Operating System that are
           | called on by Microsoft Security Software Products are
           | documented and available for use by third-party security
           | software products that run on the Windows Client PC Operating
           | System and/or the Windows Server Operating System.
           | 
           | These APIs will be documented on the Microsoft Developer
           | Network, unless open publication would create security risks.
           | In such circumstances, Microsoft will provide third-party
           | security vendors with access to such APIs pursuant to a
           | royalty-free license and on fair, reasonable and non-
           | discriminatory terms." [0]
           | 
           | This meant that by offering Microsoft Defender for Endpoint,
           | Microsoft needs to give similar access to the underlying
           | kernel to competing vendors like CRWD and S1.
           | 
           | [0] -
           | https://news.microsoft.com/download/archived/presskits/eu-
           | ms...
        
             | zanecodes wrote:
             | Well, I hate Microsoft as much as the next person, but I'm
             | not sure "writing a buggy kernel module can crash the
             | kernel" is much of an indictment of Windows in
             | particular...
        
               | alephnerd wrote:
               | I agree with ya. Just playing devil's advocate.
        
             | zelphirkalt wrote:
             | Security by obscurity is a bad security concept. If
             | anything making that information available prevented things
             | from lurking in there and doing even more damage.
        
               | alephnerd wrote:
               | I agree with your position on security via obscurity
               | being uslesss, but the issue was the settlement didn't
               | allow Microsoft to add limits such as additional
               | validation checks on vendors offerings, as those actions
               | could be construed as violating the "non-discriminatory
               | terms".
               | 
               | Any vendor's legal team worth their mettle could then
               | argue that any additional validation on vendors is unfair
               | given that MS would always have significant internal
               | knowledge about how the Windows Kernel operated.
               | 
               | It's yet another example of the EU getting in the way of
               | itself.
        
             | acdha wrote:
             | The EU defense is something they claim to shirk
             | responsibility, best left to their PR team. Nothing
             | prevented Microsoft from following Apple's lead in having
             | safer APIs to perform filtering. Note how it refers to
             | "equal footing"? That means that they have to let other
             | people do what Defender does, not that they can't secure
             | Windows at all.
        
             | bilekas wrote:
             | > Giving OP the benefit of the doubt, there were issues
             | with how the Windows kernel had little guardrails and
             | restrictions.
             | 
             | This also wasn't Microsofts fault. It was bad kernel code,
             | and don't say you would like microsoft to audit everyone
             | else's code before it can be deployed somewhere.
        
           | exabrial wrote:
           | So yes or no were a bunch of Microsoft products hacked?
        
       | charles_f wrote:
       | > CISA advises vulnerable organizations [...] to disconnect
       | affected products from the public-facing Internet until an
       | official patch is available.
       | 
       | It's interesting to me that you'd go the hassle of hosting your
       | own SharePoint on prem, but leave it internet facing. I would
       | have assumed a the Venn diagram of these organizations to be
       | entirely contained in orgs forcing you to use a VPN.
        
         | jauntywundrkind wrote:
         | Oh CISA...
         | 
         | What a pity that CISA has been purged down of effective useful
         | people and turned into another sad selected-for-political-
         | compliance-only force.
         | 
         | Arizona recently got attacked from Iranian hackers & didn't
         | even bother trying to get help from CISA.
         | https://archive.is/2025.07.19-143305/https://www.azcentral.c...
         | 
         | CISA is so so vital. Investigating incredibly wide ranging
         | attacks like this, or the Salt Typhoon attack are vital for
         | this nation. But the show is being run by a bunch of people who
         | value political dogma far above anything else.
         | https://www.techdirt.com/tag/cisa/
        
         | Arainach wrote:
         | Best practice is to assume the network is compromised - a VPN
         | doesn't provide as much guarantee as people would like. In
         | large fleets, devices are regularly lost, damaged, retired,
         | etc. In organizations with high target value, physical
         | penetration through any number of means should be assumed.
         | 
         | So you don't do that. You use zero trust and don't care that
         | things are exposed to the internet.
         | 
         | Working from anywhere (remote sites, home, your phone) is a
         | huge benefit. Organizations want to control their data entirely
         | while still wanting their organization to be able to access it.
        
           | anonymars wrote:
           | Maybe I'm missing something but doesn't this very story cut
           | your assertion off at the knees?
           | 
           | With a VPN the attack surface of this vulnerability would
           | have been miniscule compared to a _publicly accessible zero-
           | day RCE_
           | 
           | (And it's not like you have to allow carte-blanche access
           | behind the wall)
           | 
           | Defense in depth!
        
             | zamadatix wrote:
             | In zero trust "exposed to the internet" is a bit of a
             | misnomer compared to how traditional security would use the
             | term. A better description might be "you're allowed to form
             | a session to it from over the internet but only after your
             | identity and set of rights have been verified". From this
             | view: "zero trust" < "vpn" < "wide open" (in terms of
             | exposure).
        
         | cptskippy wrote:
         | > It's interesting to me that you'd go the hassle of hosting
         | your own SharePoint on prem, but leave it internet facing.
         | 
         | Once upon a time Microsoft marketed it as, and a lot of Orgs
         | adopted SharePoint as their Intranet. With SharePoint 2019
         | being sunset, a lot of Orgs are scrambling to implement
         | replacements.
        
         | p_ing wrote:
         | Hosting internal services be they SharePoint or Exchange behind
         | a [pre-auth] reverse proxy isn't that unusual.
        
       | ThinkBeat wrote:
       | I have spent far too much of my life on SharePoint. Having it
       | internet facing has never been a good idea. Not really what it is
       | meant for, though the promo verbiage on that has changed over
       | different versions.
       | 
       | Some folks wanted SharePoint as their "web server", I would set
       | that installation up entirely separted from all other instances
       | they may have on the network.
        
         | miffy900 wrote:
         | Actually it wasn't too long ago, in the early-2010's, that
         | Microsoft was promoting SharePoint for internet sites; I think
         | at one point some Europoean car manufacturer (BMW? Ferrari?)
         | had their global marketing site on SharePoint. Of course that
         | didn't last long, as Microsoft licensed it at a crazy price
         | ($40k per site or something like that).
        
       | vultour wrote:
       | How did Principal Engineer Copilot not prevent this?!
        
         | dylan604 wrote:
         | This vuln might have existed before Copilot received that title
         | bump. It could have been introduced while Copilot was just an
         | intern
        
         | amelius wrote:
         | Because the hackers used Copilot too, and one side has to win
         | ... (?)
        
       | pyuser583 wrote:
       | I've heard many Pentagon employees claim that if someone wanted
       | to take out the US military, all they'd have to do is kill
       | Sharepoint.
       | 
       | It's the go-to warm-up joke whenever someone in the military
       | gives a speech.
        
       | Arubis wrote:
       | Part of me hopes to see ICE's personnel files leaked.
        
       ___________________________________________________________________
       (page generated 2025-07-21 23:00 UTC)