Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
66 Indlæg 46 Posters 67 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • anomr@mastodon.socialA anomr@mastodon.social

    @mrmasterkeyboard @kkarhan @GossiTheDog you also included the .git, amazing!

    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
    mrmasterkeyboard@mastodon.social
    wrote sidst redigeret af
    #23

    @anomr @kkarhan @GossiTheDog yup, i believe that the history is important too!

    mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

      It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

      https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

      goingforbrooke@hachyderm.ioG This user is from outside of this forum
      goingforbrooke@hachyderm.ioG This user is from outside of this forum
      goingforbrooke@hachyderm.io
      wrote sidst redigeret af
      #24

      @GossiTheDog 9 out of 10 doctore agree that sell-to-APT incentives are going up

      drwho@masto.hackers.townD 1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        GitHub has long been a source for zero days exploits in competitor products - it still is. While I worked there GitHub had a policy saying they wouldn’t remove them.

        By continually removing just exploits for their own products from Github and declaring “criminal activity”, it’s a rubicon.

        zaicurity@infosec.exchangeZ This user is from outside of this forum
        zaicurity@infosec.exchangeZ This user is from outside of this forum
        zaicurity@infosec.exchange
        wrote sidst redigeret af
        #25

        @GossiTheDog I was actually surprised that the repos weren’t taken down sooner given Microsoft’s track record with similar cases affecting their products.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

          rairii@labyrinth.zoneR This user is from outside of this forum
          rairii@labyrinth.zoneR This user is from outside of this forum
          rairii@labyrinth.zone
          wrote sidst redigeret af
          #26
          @GossiTheDog i mean, i can totally understand why it was done

          if the coordinated disclosure process breaks down, full disclosure seems to be the obvious result. this isn't the first time this has happened and won't be the last.

          MS seems to be acting more irrationally than the researcher here, banning them from MSRC seems to guarantee any future discoveries from them will be fully disclosed, and there are enough git forges that MS don't lean on.

          and if MS's leaning on law enforcement does end up with something happening on that front, it seems that would increase the streisand effect exponentially?
          1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

            It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

            https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

            ralph@hear-me.socialR This user is from outside of this forum
            ralph@hear-me.socialR This user is from outside of this forum
            ralph@hear-me.social
            wrote sidst redigeret af
            #27

            @GossiTheDog

            #alttext

            The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed. In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.
            We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity -coordinating as needed with law enforcement around the world.

            rndanger@infosec.exchangeR theothersimo@mastodon.socialT 2 Replies Last reply
            0
            • rndanger@infosec.exchangeR rndanger@infosec.exchange

              @lykso @GossiTheDog
              Microsoft attained market dominance in the eighties by scaring people with fake error messages, so yeah. People should remember better

              resister@infosec.exchangeR This user is from outside of this forum
              resister@infosec.exchangeR This user is from outside of this forum
              resister@infosec.exchange
              wrote sidst redigeret af
              #28

              @RnDanger @lykso @GossiTheDog remember "different"

              1 Reply Last reply
              0
              • notavi10@critter.cafeN notavi10@critter.cafe

                @GossiTheDog nah the finder was acting rationally cause ms didn't fucking pay them for the zero days like they was supposed to

                resister@infosec.exchangeR This user is from outside of this forum
                resister@infosec.exchangeR This user is from outside of this forum
                resister@infosec.exchange
                wrote sidst redigeret af
                #29

                @notavi10 @GossiTheDog
                Is this for real? They submitted for bug bounty and got rejected?

                notavi10@critter.cafeN 1 Reply Last reply
                0
                • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                  @anomr @kkarhan @GossiTheDog yup, i believe that the history is important too!

                  mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                  mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                  mrmasterkeyboard@mastodon.social
                  wrote sidst redigeret af
                  #30

                  @anomr @kkarhan @GossiTheDog well I dunno where to rereupload it now.

                  mrmasterkeyboard@mastodon.socialM 1 Reply Last reply
                  0
                  • mrmasterkeyboard@mastodon.socialM mrmasterkeyboard@mastodon.social

                    @anomr @kkarhan @GossiTheDog well I dunno where to rereupload it now.

                    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                    mrmasterkeyboard@mastodon.socialM This user is from outside of this forum
                    mrmasterkeyboard@mastodon.social
                    wrote sidst redigeret af
                    #31

                    @anomr @kkarhan @GossiTheDog fuck it, I give up.

                    I'm not uploading my copy again elsewhere, turns out it's here anyway.

                    https://archive.softwareheritage.org/browse/search/?q=nightmare-eclipse&with_visit=true&with_content=true

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                      It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                      https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                      briankrebs@infosec.exchangeB This user is from outside of this forum
                      briankrebs@infosec.exchangeB This user is from outside of this forum
                      briankrebs@infosec.exchange
                      wrote sidst redigeret af
                      #32

                      @GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.

                      johncc@corteximplant.comJ sly_vi@lgbtqia.spaceS 2 Replies Last reply
                      0
                      • notavi10@critter.cafeN notavi10@critter.cafe

                        @GossiTheDog nah the finder was acting rationally cause ms didn't fucking pay them for the zero days like they was supposed to

                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchangeB This user is from outside of this forum
                        briankrebs@infosec.exchange
                        wrote sidst redigeret af
                        #33

                        @notavi10 @GossiTheDog is there anything to support this claim? thanks.

                        notavi10@critter.cafeN 1 Reply Last reply
                        0
                        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                          @GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.

                          johncc@corteximplant.comJ This user is from outside of this forum
                          johncc@corteximplant.comJ This user is from outside of this forum
                          johncc@corteximplant.com
                          wrote sidst redigeret af
                          #34

                          @briankrebs @GossiTheDog I often hear UK politicians use "working around the clock", "working tirelessly", or "striving relentlessly" when defending themselves. It has become meaningless (which is the point) but to me it serves as a bullshit flag. I'm impressed they managed to get two in one press release!

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                            It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                            https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                            cxj@phpc.socialC This user is from outside of this forum
                            cxj@phpc.socialC This user is from outside of this forum
                            cxj@phpc.social
                            wrote sidst redigeret af
                            #35

                            @GossiTheDog Well that’s rather horrifying.

                            1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                              It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                              https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                              snickerbockers@freeradical.zoneS This user is from outside of this forum
                              snickerbockers@freeradical.zoneS This user is from outside of this forum
                              snickerbockers@freeradical.zone
                              wrote sidst redigeret af
                              #36

                              @GossiTheDog bold threats coming from a company founded by a frequent visitor to epstein island.

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                                It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                                https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                                interpipes@thx.ggI This user is from outside of this forum
                                interpipes@thx.ggI This user is from outside of this forum
                                interpipes@thx.gg
                                wrote sidst redigeret af
                                #37

                                @GossiTheDog Microsoft continuing to work hard to prove to everyone else that they are the bad faith actor in infosec I have been criticising them for

                                1 Reply Last reply
                                0
                                • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                                  @GossiTheDog yeah that reads as pretty hostile to researchers in general and labels as "threat actors" those who don't choose to play by Microsoft's rules.

                                  sly_vi@lgbtqia.spaceS This user is from outside of this forum
                                  sly_vi@lgbtqia.spaceS This user is from outside of this forum
                                  sly_vi@lgbtqia.space
                                  wrote sidst redigeret af
                                  #38

                                  @briankrebs @GossiTheDog not to defend M$, but isn't the responsible disclosure stuff an etiquette in the whole infosec domain? My friends working in a SOC told me so, and I can understand the point of "please think about the workers"
                                  Still, M$ wanting people to think about the workers leaves a bitter taste int mouth, and nothing justifies sending legal threats against individuals like that

                                  bertdriehuis@infosec.exchangeB 1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    Do I think the finder was acting rationally? No. Do I think Microsoft gets to decide what is criminal activity around proof of concept exploits? No.

                                    cdubbs@infosec.exchangeC This user is from outside of this forum
                                    cdubbs@infosec.exchangeC This user is from outside of this forum
                                    cdubbs@infosec.exchange
                                    wrote sidst redigeret af
                                    #39

                                    @GossiTheDog That response playbook looks like a villain arc generator.

                                    1 Reply Last reply
                                    0
                                    • ralph@hear-me.socialR ralph@hear-me.social

                                      @GossiTheDog

                                      #alttext

                                      The vulnerabilities known as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma were not responsibly disclosed. In response to the unnecessary risk created by these disclosures, our security teams have been working around the clock to understand the impact, protect our customers, and develop security updates.
                                      We remain firmly opposed to these actions, and any disclosure outside proper coordination that could harm our customers and the digital ecosystem. Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences. Our security teams across the company work tirelessly tracking threat actors who look for weaknesses just like these to attack Microsoft and our customers. Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity -coordinating as needed with law enforcement around the world.

                                      rndanger@infosec.exchangeR This user is from outside of this forum
                                      rndanger@infosec.exchangeR This user is from outside of this forum
                                      rndanger@infosec.exchange
                                      wrote sidst redigeret af
                                      #40

                                      @Ralph @GossiTheDog
                                      Thank you, i really didn't want to look at the picture of text

                                      ralph@hear-me.socialR 1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        I’m deeply uncomfortable with Microsoft attempting to weaponise their extensive law enforcement contacts to arrest people who post zero days in the products.

                                        It comes after the researcher was kicked off GitHub (owned by Microsoft), Gitlab (a Microsoft partner), after they were doxxed on Twitter and had their MSRC - Microsoft vulnerability reporting portal - account disabled.

                                        https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure

                                        kitsunevixi@sakurajima.socialK This user is from outside of this forum
                                        kitsunevixi@sakurajima.socialK This user is from outside of this forum
                                        kitsunevixi@sakurajima.social
                                        wrote sidst redigeret af
                                        #41

                                        @GossiTheDog@cyberplace.social So they complain about irresponsible disclosure but kick them off the MSRC so they can't disclose responsibly?

                                        1 Reply Last reply
                                        0
                                        • will@www.librepunk.clubW This user is from outside of this forum
                                          will@www.librepunk.clubW This user is from outside of this forum
                                          will@www.librepunk.club
                                          wrote sidst redigeret af
                                          #42

                                          @GossiTheDog I really hope that somebody at Microsoft acknowledges that this screenshot looks like it could be lifted straight from Cyberpunk 2077.

                                          ciclistarubio@norden.socialC 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper