3 ms·
Where can we fund more information about this?
by RyeCombinator 2y ago
Where can we fund more information about this?
- justinclift 2y agoThere are so many that it's just not funny. :( • https://www.nbcnews.com/tech/security/scathing-federal-report-rips-microsoft-shoddy-security-insincerity-res-rcna146177 https://www.nbcnews.com/tech/security/scathing-federal-repor... • https://www.wiz.io/blog/bingbang https://www.wiz.io/blog/bingbang • https://www.theverge.com/2023/7/12/23792371/security-breach-china-us-government-emails-microsoft-cloud-exploit https://www.theverge.com/2023/7/12/23792371/security-breach-... • https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-analysis-and-best-practices https://www.wiz.io/blog/midnight-blizzard-microsoft-breach-a... These are just the first few I've found for the last 12 months. There are more if you go back even 12 months further, and I'm pretty sure the above aren't the complete list for the last year anyway. Microsoft are actually really bad at this Cloud "security" thing. :( :( :(
- dingdong33 2y ago[dead]
- Bognar 2y ago3 of those are about Exchange and one is about Bing (involving AAD, but it was an AAD app that was misconfigured and not an AAD issue itself). The teams that run Azure are in entirely separate organizations with wildly different product stacks. Exchange has a bunch of decades old infrastructure and is a security nightmare afaik. Dunno much about Bing. The "org chart" graphic with MS orgs all pointing guns at each other is real shit. Different orgs have very different security postures, and Azure's is much stronger than others. Source: spent some time at MS