[HN Gopher] Global hack on Microsoft Sharepoint hits U.S., state...
___________________________________________________________________
Global hack on Microsoft Sharepoint hits U.S., state agencies,
researchers say
https://archive.ph/Ym2jZ,
https://web.archive.org/web/20250721135933/https://www.washi...
https://research.eye.security/sharepoint-under-siege/
https://krebsonsecurity.com/2025/07/microsoft-fix-targets-at...
https://www.bleepingcomputer.com/news/microsoft/microsoft-re...
Author : spenvo
Score : 268 points
Date : 2025-07-20 21:58 UTC (1 days ago)
(HTM) web link (www.washingtonpost.com)
(TXT) w3m dump (www.washingtonpost.com)
| aspenmayer wrote:
| https://archive.is/LVrQQ
|
| Related:
|
| _ToolShell Mass Exploitation (CVE-2025-53770)_ -
| https://research.eye.security/sharepoint-under-siege/ |
| https://news.ycombinator.com/item?id=44629133
| jmclnx wrote:
| Another day another vulnerability with Microsoft. I wonder if
| this will incentivize the countries to move faster with Linux.
|
| Probably not since there are so many of these breaches people
| just ignore them.
|
| I miss the old days when a breach involved someone breaking into
| the computer room and grabbing as many mag tapes as they can
| carry and run :)
| SketchySeaBeast wrote:
| Genuinely asking - is there a Linux alternative to Sharepoint?
| I couldn't care less if it was lit on metaphorical fire and
| dumped into the sea, but a lot of orgs using it extensively.
| bangaladore wrote:
| O365 is a poor amalgamation of like 18 different things.
| Quite frankly I hope there isn't a true "alternative" to it.
|
| The reason orgs use Sharepoint is they are forced to if they
| use Microsoft. One drive is sharepoint, teams is sharepoint,
| sharepoint sites is sharepoint, etc...
|
| I'm sure all those things have better alternatives, but
| Microsoft shoves them down your throat when you license with
| them.
| SketchySeaBeast wrote:
| But it's understandable why an org would prefer that to
| having to maintain and manage the 18 things, right? It's a
| hard sell.
|
| I'm not saying that wouldn't be better, but it makes sense
| why an org would be reluctant. Again, not a fan of
| Sharepoint myself, but from an org's viewpoint, moving to
| Linux raises more problems than it solves.
| bangaladore wrote:
| It's understandable, but it doesn't excuse how poorly
| everything actually works and how confusing it is to use
| and administrate.
|
| To some extent I think Microsoft is largely in the
| business of building solutions for problems that don't
| exist.
|
| Most orgs are probably perfectly fine with a document
| management system + desktop word application and then a
| commercial NAS for bulk storage / backups.
| kuhsaft wrote:
| > Sharepoint is a poor amalgamation of like 18 different
| things.
|
| You've got it backwards. Everything M365 is an amalgamation
| of Entra, SharePoint, and Exchange.
| bangaladore wrote:
| Yes, thanks for the correction.
| ray_v wrote:
| git repo hosted on a secure server behind several layers of
| VPN? I'm sure I could probably come up with something more
| secure than freaking sharepoint
| jonathanlydall wrote:
| Sorry, I don't know the answer to your question, but I can
| offer some possible insight into why it's used so much.
|
| We're on Microsoft 365 and technically fall into the camp of
| "uses SharePoint", but only for "shared network folder" usage
| which OneDrive seamlessly synchronizes should you dislike the
| web interface. We don't actively use any other features of
| it.
|
| Also worth mentioning that realtime collaboration and
| automatic versioning of Office documents is seamless for
| files on SharePoint, even if opened on a desktop on a
| OneDrive synchronized folder.
|
| Files shared over Teams as well as meeting recordings are
| also stored on SharePoint.
|
| My point is that SharePoint is used a lot but possibly not in
| the way one might have assumed.
|
| I don't know if self hosted SharePoint can do all this.
| hulitu wrote:
| > seamlessly
|
| In 50 % of the time.
| kuhsaft wrote:
| For collaborative documentation, there's probably a bunch of
| alternatives.
|
| But SharePoint is the linchpin for Microsoft 365. Well
| technically SharePoint and Exchange. You can't use any
| Microsoft 365 products without SharePoint.
|
| OneDrive uses SharePoint. Outlook Groups and Teams Channels
| create Microsoft 365 Groups. Every Microsoft 365 Group
| creates a SharePoint site. Microsoft Loop uses Microsoft
| SharePoint Embedded.
|
| SharePoint is now a "file and document management system
| suitable for use in any application".
|
| So, if you want an alternative to SharePoint you would need
| an alternative to any M365 Product, including Outlook and
| OneDrive.
|
| Fun Fact: Teams messages are actually stored via Exchange
| Mailboxes.
|
| https://learn.microsoft.com/en-
| us/sharepoint/dev/embedded/ov...
| SketchySeaBeast wrote:
| Yeah, that's what I'm thinking. Is it great? Well, no, but
| it's incredibly integrated and that has a great appeal to
| orgs.
| jongjong wrote:
| Google Docs and Libre Office both produce compatible
| documents. There's really no reason to force one or the
| other.
|
| It's just conflating needs. Document editing and file
| storage are two different tasks. It's weird that people
| want everything integrated. It's not much effort to just
| drag and drop a file into G-Drive, OneDrive, Dropbox,
| box.com...
| kuhsaft wrote:
| > It's not much effort to just drag and drop a file into
| ... OneDrive ...
|
| See, there's the problem. Once you touch anything M365,
| you're using SharePoint.
|
| People see SharePoint as a document collaboration tool.
| But, in reality, it's real use is as a data storage
| platform.
| Jtsummers wrote:
| What people want are systems that compose and work well
| together. That's what MS provides, or at least attempts
| to provide, with SharePoint. When you start trying to
| tack on collaborative document editors, workflow
| management systems, shared storage, and other
| capabilities from different providers or systems you run
| into more and more complications (especially because most
| of these don't offer any kind of standards compliance
| that lets them be used interchangeably). That's also why
| G-Suite works as a competitor to MS, it covers at least
| the more critical integrations that people want to work
| smoothly without needing to combine multiple maybe
| compatible things together.
| vel0city wrote:
| > Document editing and file storage are two different
| tasks.
|
| Not if you want to enable multiple users to be live
| editing the document at the same time.
| anonfordays wrote:
| It's not just SharePoint, it's the entire Microsoft suite of
| "productivity" products that the government uses. Is there a
| Linux alternative to that?
| whynotmaybe wrote:
| nextcloud ?
| justsomehnguy wrote:
| NextCloud is actively tries to be AIO replacement for
| SharePoint.
|
| Of course it's quite a poor replacement but it does exists.
| Sanzig wrote:
| Nextcloud, particularly with the Collabora Office integration
| for real-time collaborative document editing. It's got some
| rough edges but I'd say it suits the majority of use cases
| now. I suggest spinning up a copy of the community edition in
| a VM to give it a spin, I was pleasantly surprised. There is
| a lot of money getting poured in right now as entities
| outside the US are exploring ways to ditch American software.
| thewebguyd wrote:
| For the file storage/sharing/collaboration part, yeah -
| there's plenty, and sharepoint arguably sucks even for that.
|
| What trapped a lot of orgs is making use of the whole
| PowerPlatform around sharepoint. There's a lot of crusty old
| LoB apps built with MS's no code tools (PowerAutomate,
| PowerApps) which run on SharePoint as the delivery platform.
| Some of these even hook into Excel files stored in the
| various document libraries, etc. There are entire, large
| business processes being handled by this platform, and so
| migrating will require actual dev time, which automatically
| makes it a non-starter for most, unfortunately. Doubly so
| when you consider that a lot of these "solutions" were built
| by non-devs, long since gone from the company and no one
| knows how deep the tentacles go.
| sugarpimpdorsey wrote:
| The same people will tell you GIMP is a serious competitor to
| Photoshop.
| fsflover wrote:
| And it will be true for 99% of use cases.
| amelius wrote:
| GIMP is falling behind because GenAI doesn't work out of
| the box.
| ok123456 wrote:
| For the self-hosted version: a Synology NAS.
| sivm wrote:
| I operate under the assumption that open source projects are
| compromised by states. If you espouse unpopular ideas or are
| yourself a state don't rely on it.
| jmclnx wrote:
| Lets pretend what you are saying is true, which it is not.
| Who would you want to access your data ? The State or the
| "underworld". Many countries have laws on how to access your
| data. The underworld, you may wake up dead.
|
| Granted there are countries that act like a Criminal Org.,
| but if you live there you have more issues than your data.
|
| With proprietary software, it is a much larger chance that
| backdoors exist than in Open Source. Many of us heard of 1
| issue where it was claimed a project had a Gov sponsored BH
| in it. They did a long audit and found that was false.
|
| Eventually Open Source backdoors will found in Open Systems.
| Proprietary you are SOL unless you do very expensive and very
| hard testing. Even then it is doubtful you will find a
| backdoor.
| pessimizer wrote:
| It is true. Denying trivial truths with the purpose of not
| giving an inch does not add to one's argument, it weakens
| it.
|
| Plenty of closed source products will happily backdoor
| their products on request, without a warrant, if they are
| confident they will never be found out. That's the point.
| Not that FOSS source is somehow inviolable to nation-states
| with virtually infinite resources, many of which sponsor or
| contribute to the finance of a huge percentage of the
| development of FOSS themselves.
|
| It's easier to find backdoors in FOSS if you're looking,
| because you're allowed to look. But somebody has to be
| looking.
| temp0826 wrote:
| Interesting, I'd more likely assume the same for closed
| source projects as there is less transparency into the supply
| chain
| fsflover wrote:
| https://news.ycombinator.com/item?id=27897975
| lenerdenator wrote:
| Oh, don't worry, there's plenty of known, unpatched
| vulnerabilities in FOSS, too.
| ho_schi wrote:
| I wonder what drives people using Microsoft and then using more
| from this company. We didn't knew it better,
| back then. We knew it better, now. But migrating is work. So we
| prefer to suffer! And harm others! This Linux and BSD people
| are so annoying with their desire for compatibility. They shall
| suffer, too! And when we buy everything from a Monopoly, we
| don't need to think.
|
| Somehow. Part of the game is that you've always an excuse with
| Microsoft. You cannot made responsible? There is this quote
| about IBM: Nobody Ever Got Fired for Buying
| IBM.
|
| But I cannot remember stories about suffering from IBM forever.
| dizlexic wrote:
| From what I've seen in my industry? To pass all the liability
| to Microsoft.
|
| "If something happens, we used enterprise grade industry
| standard software. We did our due diligence."
|
| This outlook is basically why we can't innovate anymore.
|
| I had to recently sit through a meeting where our CTO quoted
| all the "blogs" he's been reading as a way to slap down my
| suggestion for an in-house project.
|
| It's all about CYA.
| hulitu wrote:
| > I wonder if this will incentivize the countries to move
| faster with Linux.
|
| Countries are run by politicians. The ability of a politician
| to remember something is inverse proportional to the sum of
| money landed in its account.
| formerly_proven wrote:
| As far as I can tell there's two vulnerabilities bundled up
| here. One is an unauthenticated command injection (!)
| vulnerability to steal some keys and the other is of course yet
| another serialization-based RCE in a safe language, mediated by
| signed cookies (signed with the keys stolen in step 1).
|
| I don't understand how often this design has to blow up in
| people's faces until they stop doing this and use something
| dumb and safe instead.
| shrubble wrote:
| Wasn't Microsoft just recently using Chinese people living in
| China to administer DOD servers? I would guess they use
| Sharepoint inside the DOD?
| computegabe wrote:
| Link: https://www.reuters.com/world/us/microsoft-stop-using-
| engine...
| theteapot wrote:
| Says this in the article:
|
| > A programming flaw in its cloud services also allowed China-
| backed hackers to steal email from federal officials. On
| Friday, Microsoft said it would stop using China-based
| engineers to support Defense Department cloud-computing
| programs after a report by investigative outlet ProPublica
| revealed the practice, prompting Defense Secretary Pete Hegseth
| to order a review of Pentagon cloud deals.
| p_ing wrote:
| There is a DoD version of M365 which has SPO, but that isn't
| what the article is discussing.
| timewizard wrote:
| Why didn't they just rewrite it in Rust?
| tialaramex wrote:
| IIRC Microsoft is rewriting some of these backend services in
| Rust, although not because it will increase security but
| because it lets them get better perf than existing solutions
| without the safety tradeoff they'd have suffered to go to C++
| which would have been their option 15-20 years ago. I don't
| know whether Sharepoint was on that list.
| mynameisash wrote:
| You also can get better velocity than with other languages
| due to the compile-time checks.
| theteapot wrote:
| They should've just Linux.
| tombert wrote:
| At the risk of massive downvotes, I have to admit that a small
| part of me wants this so that maybe corporations _stop_ using
| Sharepoint as soon as possible.
|
| Seriously, I haven't used it since 2017, but every time I used it
| then it was the worst part of my day. I used to have a shirt that
| said SHarepoIT Happens that I would wear to work, and it seemed
| like the one thing I could get my coworkers agree on was that
| Sharepoint is terrible and we'd rather use anything else.
| CommenterPerson wrote:
| I upvoted you .. share the same sentiment.
| neuroelectron wrote:
| My boss spent over a year trying to get me to setup Sharepoint.
| About 6 months into this, I finally looked into it and what it
| provided and said no. Eventually he hired a second tech and he
| set it up "in an afternoon." Good for him. Nobody ever used it.
| He also stole my high speed USB drive.
| threetonesun wrote:
| While Sharepoint might some day die, it will only be replaced
| by another piece of software that gets launched for nobody to
| ever use.
| dylan604 wrote:
| Clearly Sharepoint _is_ being used. Otherwise, this would
| not be a news story. So if every single Sharepoint user
| switched to another piece of software, it would be more
| than nobody using it.
| weinzierl wrote:
| Sorry to disappoint you, but Sharepoint isn't going to die.
|
| This is actually a great day for Microsoft. People will come to
| their cloud solutions in troves after this and everyone will be
| happy. Maybe not everyone, but Microsoft for sure.
| pvtmert wrote:
| to accommodate $MSFT shareholders downvotes, have my upvote :)
|
| nevertheless, even NFS is better than sharepoint. At least, NFS
| works...
| sureglymop wrote:
| SharePoint is garbage. Even nextcloud is way better and it
| doesn't exactly have the best reputation. It can't possibly be
| that hard can it...
| jdiez17 wrote:
| I have never used SharePoint but I honestly cannot imagine it
| being worse than Nextcloud + Collabora Office. Which I do use
| almost every day.
| jasonvorhe wrote:
| You have no idea how good you have it.
| delfinom wrote:
| Good news.
|
| Teams is actually SharePoint.
|
| It ain't going anywhere
| galangalalgol wrote:
| My company was using slack and mattermost and consolidated to
| teams... It is so bad.
| kuhsaft wrote:
| It's impossible to stop using M365 while stopping usage of
| SharePoint (cloud or on-premises). See
| https://news.ycombinator.com/item?id=44640219
|
| Here's just one example:
|
| Each M365 Teams Team creates an M365 Group which creates a
| SharePoint site and Exchange mailbox. Teams channel files are
| stored in that SharePoint site. Teams channel messages are
| stored in the Exchange mailbox.
|
| Private files dropped in Teams are stored in OneDrive
| (rebranded SharePoint). Private Teams messages are stored in
| the sender and recipients' Exchange mailboxes.
|
| M365 _is_ SharePoint and Exchange. _EVERYTHING_ is built on
| top.
|
| EDIT: changed 'individual' to 'sender and recipients'
| mschuster91 wrote:
| > Private Teams messages are stored in individual Exchange
| mailboxes.
|
| Good lord. It truly is a layer of dung layered upon more
| layers of dung.
| anonymars wrote:
| I don't think this is nearly as crazy as you may think at
| first glance
|
| Imagine if it was just a hidden (special) folder in an
| Exchange mailbox.
|
| Voila, you already have a well-known and widely implemented
| and tested message syncing solution both for content and
| status (read/unread)
|
| I assume Windows Phone worked the same way with its text
| message backup. When you'd set up a new phone it would take
| a while for your Microsoft account to finish syncing during
| which new messages would trickle into the Messaging app in
| real time. In fact if your old phone was still on WiFi new
| messages would show up on both. Still more advanced 15(?!)
| years ago than my Android today
| blibble wrote:
| explains why scrolling up in teams loads 3 messages at a
| time too
|
| very slowly
|
| and why the search doesn't work
| rs186 wrote:
| My company has SharePoint and another internal site for
| documents/notes (think about Notion/Quip/Confluence). The other
| site works quite well, and most developers write all their
| notes/docs on it. But _some_ people just insist on uploading
| Word documents to SharePoint. So now everybody else has to use
| SharePoint as well, plus search twice whenever they need to
| find something.
| cm2187 wrote:
| And sharepoint in large organisations I have been at recently
| is now using oauth which breaks Microsoft's own sharepoint
| client API. That whole software is one massive waste of time
| and buget.
| persolb wrote:
| As a mid size company that does work with government agencies,
| it's near impossible to use anything 'better' solution.
| Cybersecurity requirements are getting so onerous that
| Sharepoint is too commercially feasible of an option to use
| anything else for a shared file store between organizations.
|
| The fact that Sharepoint sucks* doesn't matter... because
| anything else is seen as a risk.
|
| * folders with lots of files are hard to scroll through because
| each page is lazy loaded, the automation functions are buggy,
| logins between different M365 tenants breaks and is not
| correctable by a normal site admin, human readable URL paths
| aren't standard, search is shit, tables/filters are buggy, the
| new interface hides a bunch of the permissions logic, some
| things like permission groups need to be managed via outlook,
| etc etc. I'm sure a bunch of my gripes are technically fixable,
| but these aren't things that should need a web search in order
| to use/fix.
| kuhsaft wrote:
| It's not cybersecurity. It's legal, trust me. For large
| corporations, eDiscovery is huge. Failing eDiscovery can cost
| a company millions. Having a bunch of different data sources
| makes it impossible, so companies stick with M365 as
| corporate policy and call it a day.
| eitland wrote:
| At some point Microsoft tried to sell some automatic DRM system
| based on SharePoint to some company that I worked for.
|
| The sales pitch was that they could upload documents to
| SharePoint and when people downloaded the documents SharePoint
| would automatically apply DRM so the documents could only be
| opened by that person on authorised machines for a specified
| number of days.
|
| Well, it turned out depending on how you logged in (using the
| same account, just different login forms) on the SharePoint
| server it would either give you the files with DRM applied - or
| the completely unrestricted files.
|
| We got some senior Microsoft consultant working directly for
| Microsoft to look at it but in the end they were just as
| confused as us.
| xxs wrote:
| >At the risk of massive downvotes,
|
| The only reason to get downvotes is nonsense of prefacing the
| post with the 'worry'. Sharepoint would be far from a first
| choice under normal circumstances (e.g. not bundled with excel
| and friends)
| sega_sai wrote:
| It is instructive that we are seeing the results of DOGE's work:
|
| "The process took six hours Saturday night -- much longer than it
| otherwise would have, because the threat-intelligence and
| incident-response teams have been cut by 65 percent as CISA
| slashed funding, Rose said."
| ToucanLoucan wrote:
| I'm not sure which part pisses me off more: that tons of
| professionals lost their jobs and will likely not work in
| public service again because of it, or that through all that,
| they barely found any actual waste at all. A fucking farce.
| azemetre wrote:
| You're assuming their purpose was to find waste, it was not.
| Their purpose was to be the Chicago boys in DC.
| caconym_ wrote:
| Seems like generally it ended up being a surveillance play,
| in practice if not original intent. For example, Dog coin
| has been reported to be passing data taken from other
| agencies directly to ICE^[1] for law enforcement
| applications, and there was that other matter of logins
| apparently from Russia using accounts the Dog coin
| personnel demanded agencies create on their internal
| systems with (auditable) logging disabled^[2]. And probably
| more that I'm forgetting.
|
| One does wonder whether this was all part of Musk's vision,
| or more thanks to the scum he hired to staff Dog coin
| and/or other lawless opportunists in the Trump
| administration.
|
| [1] https://www.washingtonpost.com/immigration/2025/04/16/m
| edica...
|
| [2] https://www.reuters.com/technology/cybersecurity/whistl
| eblow...
| dylan604 wrote:
| The idea that Musk's intent was to gut all of the
| agencies that were in a position to regulate any of his
| companies does seem to suggest that DOGE was an
| outstanding success.
| caconym_ wrote:
| Good point!
| to11mtm wrote:
| This is what happens when Chesterton's fence is ignored...
| tough wrote:
| not just ignored but purposefully burnt down
| nine_zeros wrote:
| I'll tell you what pisses me off: Having to be subjected to
| low security services because one political party wants to
| run a reality TV show instead of caring for people. The
| consequences are all for us to bear.
| righthand wrote:
| The first obvious sign was that the people not holding office
| or having any access to government data were making unfounded
| claims about how the government was operating.
| vkou wrote:
| The move obvious sign is that people making that claim have
| a proven track record of being compulsive liars.
|
| That anyone gives a word they say the time of day is
| actually crazy.
| tempnew wrote:
| How about the fact that Elon and most of his cronies weren't
| even born here and seem to feel that the people who were born
| here are stupid and/or lazy. Maybe only Vivek said that quiet
| part out loud, but they very much agreed on the solution.
| CommenterPerson wrote:
| Wondering if this was a self goal to, you know, get people to use
| this enshittified product on the cloud?
| Jtsummers wrote:
| There are basically two things at play here:
|
| MS's hosted version of SharePoint. It's apparently unimpacted
| by this current round of attacks. DOD (since it's been brought
| up by other commenters) makes significant use of this.
|
| People hosting SharePoint instances themselves. Some on-prem,
| some with rented computers. These are the impacted ones. It's
| not about "the cloud", it's about hosted SharePoint having
| weaknesses that were exploited and many organizations
| apparently leaving their SharePoint instances accessible over
| the open internet. These hosted instances are also probably old
| and unpatched which doesn't help things. Some (many?) units
| within DOD make use of this, but definitely not all.
| fakedang wrote:
| Tinfoil theory, but what if Microsoft secretly sponsored the
| attack so that users ditch onprem in favour of the hosted
| cloud version? Microsoft is in the best position to know of
| their own software's shortcomings and would have just needed
| to pay the right folks to do the dirty job.
| Jtsummers wrote:
| "Our product is remarkably insecure, let's convince
| everyone of this by sponsoring an attack so they go and buy
| our other product."
|
| I mean, there are definitely stupid people everywhere, but
| I'd hope MS leadership isn't _that_ stupid.
| dylan604 wrote:
| I mean, dumber things have happened. Governments have
| destroyed their own government buildings to blame on the
| opposition and gain sympathy for their causes.
| Jtsummers wrote:
| Yes, false flags. That's usually used to motivate people
| to go attack someone or to garner sympathy or support for
| a cause. MS's products being subject to attacks because
| they have numerous vulnerabilities does not encourage
| anyone to go out and buy other MS products.
|
| You sink one of your own naval vessels (or it sinks due
| to an accident and you take advantage of the situation)
| and blame it on an enemy. That enemy is now the target of
| your military and your population approves.
|
| A shipbuilder hires someone to poke a hole in 1000 of
| their ships that are so badly designed and manufactured
| that it only takes a rubber ducky bouncing off the hull
| to sink them does not encourage anyone to go back to that
| shipbuilder.
|
| False flags (particularly of the "let's kill or maim
| hundreds of our own people and other innocent people"
| variety) push into evil territory. They aren't _dumb_ on
| their own, they 're calculated risks predicated on the
| willingness of the masses to fall in line after a
| catastrophe.
|
| Deliberately hurting your own customers by using
| weaknesses in your own systems in order to motivate them
| to go buy your other products or services is dumb.
| 1970-01-01 wrote:
| It's not right to victim blame but it's also not wrong. Akin to
| investing lots of money in a stock. If you took the risks of
| maintaining a public SharePoint server in 2025, here's your very
| bad day.
| jasonvorhe wrote:
| It's perfectly fine to victim blame corporations that keep
| kneecapping themselves. That's a hill I'm willing to day on.
| exabrial wrote:
| Yet another Microsoft hack. Didn't we learn from Crowdstrike? All
| Microsoft products are security hazards.
| zanecodes wrote:
| CrowdStrike is not made or owned by Microsoft.
| alephnerd wrote:
| Giving OP the benefit of the doubt, there were issues with
| how the Windows kernel had little guardrails and
| restrictions.
|
| That said, that was the EU's fault, as the EU in 2009 forced
| Microsoft to fully expose their OS internals to outside
| vendors during an anti-trust settlement, and with little
| ability to enforce vendor standards:
|
| ""Microsoft shall make available to interested undertakings
| Interoperability Information that enables non-Microsoft
| server Software Products to interoperate with Windows Server
| Operating System on an equal footing with other Microsoft
| Server Software Products.
|
| "Microsoft shall ensure on an ongoing basis and in a Timely
| Manner that the APIs in the Windows Client PC Operating
| System and the Windows Server Operating System that are
| called on by Microsoft Security Software Products are
| documented and available for use by third-party security
| software products that run on the Windows Client PC Operating
| System and/or the Windows Server Operating System.
|
| These APIs will be documented on the Microsoft Developer
| Network, unless open publication would create security risks.
| In such circumstances, Microsoft will provide third-party
| security vendors with access to such APIs pursuant to a
| royalty-free license and on fair, reasonable and non-
| discriminatory terms." [0]
|
| This meant that by offering Microsoft Defender for Endpoint,
| Microsoft needs to give similar access to the underlying
| kernel to competing vendors like CRWD and S1.
|
| [0] -
| https://news.microsoft.com/download/archived/presskits/eu-
| ms...
| zanecodes wrote:
| Well, I hate Microsoft as much as the next person, but I'm
| not sure "writing a buggy kernel module can crash the
| kernel" is much of an indictment of Windows in
| particular...
| alephnerd wrote:
| I agree with ya. Just playing devil's advocate.
| zelphirkalt wrote:
| Security by obscurity is a bad security concept. If
| anything making that information available prevented things
| from lurking in there and doing even more damage.
| alephnerd wrote:
| I agree with your position on security via obscurity
| being uslesss, but the issue was the settlement didn't
| allow Microsoft to add limits such as additional
| validation checks on vendors offerings, as those actions
| could be construed as violating the "non-discriminatory
| terms".
|
| Any vendor's legal team worth their mettle could then
| argue that any additional validation on vendors is unfair
| given that MS would always have significant internal
| knowledge about how the Windows Kernel operated.
|
| It's yet another example of the EU getting in the way of
| itself.
| acdha wrote:
| The EU defense is something they claim to shirk
| responsibility, best left to their PR team. Nothing
| prevented Microsoft from following Apple's lead in having
| safer APIs to perform filtering. Note how it refers to
| "equal footing"? That means that they have to let other
| people do what Defender does, not that they can't secure
| Windows at all.
| bilekas wrote:
| > Giving OP the benefit of the doubt, there were issues
| with how the Windows kernel had little guardrails and
| restrictions.
|
| This also wasn't Microsofts fault. It was bad kernel code,
| and don't say you would like microsoft to audit everyone
| else's code before it can be deployed somewhere.
| exabrial wrote:
| So yes or no were a bunch of Microsoft products hacked?
| charles_f wrote:
| > CISA advises vulnerable organizations [...] to disconnect
| affected products from the public-facing Internet until an
| official patch is available.
|
| It's interesting to me that you'd go the hassle of hosting your
| own SharePoint on prem, but leave it internet facing. I would
| have assumed a the Venn diagram of these organizations to be
| entirely contained in orgs forcing you to use a VPN.
| jauntywundrkind wrote:
| Oh CISA...
|
| What a pity that CISA has been purged down of effective useful
| people and turned into another sad selected-for-political-
| compliance-only force.
|
| Arizona recently got attacked from Iranian hackers & didn't
| even bother trying to get help from CISA.
| https://archive.is/2025.07.19-143305/https://www.azcentral.c...
|
| CISA is so so vital. Investigating incredibly wide ranging
| attacks like this, or the Salt Typhoon attack are vital for
| this nation. But the show is being run by a bunch of people who
| value political dogma far above anything else.
| https://www.techdirt.com/tag/cisa/
| Arainach wrote:
| Best practice is to assume the network is compromised - a VPN
| doesn't provide as much guarantee as people would like. In
| large fleets, devices are regularly lost, damaged, retired,
| etc. In organizations with high target value, physical
| penetration through any number of means should be assumed.
|
| So you don't do that. You use zero trust and don't care that
| things are exposed to the internet.
|
| Working from anywhere (remote sites, home, your phone) is a
| huge benefit. Organizations want to control their data entirely
| while still wanting their organization to be able to access it.
| anonymars wrote:
| Maybe I'm missing something but doesn't this very story cut
| your assertion off at the knees?
|
| With a VPN the attack surface of this vulnerability would
| have been miniscule compared to a _publicly accessible zero-
| day RCE_
|
| (And it's not like you have to allow carte-blanche access
| behind the wall)
|
| Defense in depth!
| zamadatix wrote:
| In zero trust "exposed to the internet" is a bit of a
| misnomer compared to how traditional security would use the
| term. A better description might be "you're allowed to form
| a session to it from over the internet but only after your
| identity and set of rights have been verified". From this
| view: "zero trust" < "vpn" < "wide open" (in terms of
| exposure).
| cptskippy wrote:
| > It's interesting to me that you'd go the hassle of hosting
| your own SharePoint on prem, but leave it internet facing.
|
| Once upon a time Microsoft marketed it as, and a lot of Orgs
| adopted SharePoint as their Intranet. With SharePoint 2019
| being sunset, a lot of Orgs are scrambling to implement
| replacements.
| p_ing wrote:
| Hosting internal services be they SharePoint or Exchange behind
| a [pre-auth] reverse proxy isn't that unusual.
| ThinkBeat wrote:
| I have spent far too much of my life on SharePoint. Having it
| internet facing has never been a good idea. Not really what it is
| meant for, though the promo verbiage on that has changed over
| different versions.
|
| Some folks wanted SharePoint as their "web server", I would set
| that installation up entirely separted from all other instances
| they may have on the network.
| miffy900 wrote:
| Actually it wasn't too long ago, in the early-2010's, that
| Microsoft was promoting SharePoint for internet sites; I think
| at one point some Europoean car manufacturer (BMW? Ferrari?)
| had their global marketing site on SharePoint. Of course that
| didn't last long, as Microsoft licensed it at a crazy price
| ($40k per site or something like that).
| vultour wrote:
| How did Principal Engineer Copilot not prevent this?!
| dylan604 wrote:
| This vuln might have existed before Copilot received that title
| bump. It could have been introduced while Copilot was just an
| intern
| amelius wrote:
| Because the hackers used Copilot too, and one side has to win
| ... (?)
| pyuser583 wrote:
| I've heard many Pentagon employees claim that if someone wanted
| to take out the US military, all they'd have to do is kill
| Sharepoint.
|
| It's the go-to warm-up joke whenever someone in the military
| gives a speech.
| Arubis wrote:
| Part of me hopes to see ICE's personnel files leaked.
___________________________________________________________________
(page generated 2025-07-21 23:00 UTC)