5 ms·
Here are few big ones from the past 12 months. https://www.wiz.io/blog/bingbang https://www.wiz.io/blog/bingbang https://www.theverge.com/2023/7/12/23792371/s
by crimsontech 3y ago
Here are few big ones from the past 12 months.
https://www.wiz.io/blog/bingbang https://www.wiz.io/blog/bingbang
https://www.theverge.com/2023/7/12/23792371/security-breach-china-us-government-emails-microsoft-cloud-exploit https://www.theverge.com/2023/7/12/23792371/security-breach-...
https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-analysis-and-best-practices https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-a...
I would agree, the Windows OS has really matured since XP, from a security perspective at least.
I would definitely expect better than this from a tech giant like MS. When was the last time Google, Meta, or Apple got breached like this?
Edited to add, I think them open sourcing some security training is good, it benefits everyone whether or not MS themselves are a great example of a secure company.
- kimixa 3y agoAnother perspective is if you haven't failed and analyzed the failure, you don't really know why your current processes might be succeeding. Or if your processes are good at all, and it's not just luck, or being less of a target, that means the holes haven't been exploited yet.
- Veserv 3y agoThe slingshot penetrating your tank armor is not a helpful failure. Except for telling you that your processes are so wildly off base that you need to start over. People who claim this kind of failure is useful are clueless. Failures are interesting in exploratory processes and useful when occurring within a predicted failure regime (i.e testing to failure). Unexpected failures in predicted success regimes just indicate process weaknesses. Repeated and continuous failures in similar fashions do not indicate strength, they indicate structural process deficiencies despite what cybersecurity bozos would like you to believe.