Archive for Microsoft

US Senator Calls for FTC Investigation of Microsoft for Ascension Hospital Ransomware Hack 

Posted in Commentary with tags , on September 11, 2025 by itnerd

In a letter to FTC Chairman Andrew Ferguson, U.S. Senator Ron Wyden urged the FTC to launch an investigation of Microsoft and “hold the company responsible for the serious harm it has caused by delivering dangerous, insecure software to the U.S. government and to critical infrastructure entities, such as those in the U.S. health care sector.” This includes the hack of millions of patient records from Ascension, the major hospital system, in 2024 

You can read the letter here: https://www.wyden.senate.gov/news/press-releases/wyden-calls-for-ftc-investigation-of-microsoft-for-enabling-ascension-hospital-ransomware-hack-with-insecure-software

Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar, commented:

“The letter underscores a long-standing tension in enterprise cybersecurity, the balance between legacy system support and secure-by-default design. What happened at Ascension isn’t just about one bad click or an old cipher. It’s about systemic risk inherited from default configurations and the architectural complexity of widely adopted software ecosystems like Microsoft’s. When a single vendor becomes foundational to national infrastructure, their security design decisions, or lack thereof, can have cascading consequences.

“From a technical standpoint, allowing deprecated encryption like RC4 to remain enabled by default, even at 0.1% usage, introduces avoidable exposure. The challenge is that many organizations still rely on legacy applications that can break when more secure defaults are enforced. Vendors are often reluctant to force those changes out of fear of business disruption, but in security, inertia can be dangerous.

“This incident also reinforces the importance of zero trust segmentation and endpoint detection. A single compromised contractor laptop should never have been able to reach Active Directory in the first place. That speaks to deeper gaps in lateral movement defenses, privilege boundaries, and user behavior monitoring, not just a software flaw.

“Ultimately, this isn’t about blaming one company. It’s about recognizing that national security is now tightly coupled with the configuration defaults of dominant IT platforms. Enterprises and public sector agencies alike need to demand more secure-by-design defaults and be ready to adapt when they’re offered.”

The EU has proven via strict enforcement and high fines that if you give organizations a reason to care about cybersecurity, they will care because it will get expensive if they don’t. It’s time that this sort of thing comes to North America.

Over 29,000 Unpatched Exchange Servers Could Be The Targets Of Threat Actors

Posted in Commentary with tags , on August 11, 2025 by itnerd

Over 29,000 Exchange servers exposed online remain unpatched against a high-severity vulnerability that can let attackers move laterally in Microsoft cloud environments, potentially leading to complete domain compromise.

We added Microsoft Exchange CVE-2025-53786 detection to our daily scans (version based). See US CISA Emergency Directive 25-02: http://www.cisa.gov/news-events/…Over 28K IPs unpatched (2025-08-07). Top affected: US, Germany, RussiaDashboard world map: dashboard.shadowserver.org/statistics/c…

— The Shadowserver Foundation (@shadowserver.bsky.social) 2025-08-08T14:21:30.322Z

Commenting on this is Martin Jartelius, CTO at Outpost24:

“The scale of unpatched Exchange servers is concerning, but not surprising. Initial guidance on this flaw included isolating end-of-life and end-of-support systems, and many organizations were already running far older, unmaintainable infrastructure before April’s patch was released.

This vulnerability affects hybrid environments. Many cloud-first businesses have already moved to Microsoft 365, and without deeper analysis it’s unclear how many of these identified servers are truly at risk. Some may determine the conditions for exploitation don’t exist in their setup and choose not to prioritize mitigation.

However, even if the exploitation risk is low, leaving a known vulnerability unpatched is an open invitation to attackers. We advise organizations to continuously assess and remediate such issues to reduce their attack surface and strengthen resilience.”

The CISA has a directive about this issue that you can find here. There’s also an interactive map here. And if you run a Microsoft Exchange hybrid-joined environment, you should follow the guidance in the CISA directive ASAP.

Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems

Posted in Commentary with tags on July 24, 2025 by itnerd

Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws, Storm-2603, is deploying Warlock ransomware on targeted systems.

As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers. In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware. Investigations into other actors also using these exploits are still ongoing. With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems. This blog shares details of observed exploitation of CVE-2025-49706 and CVE-2025-49704 and the follow-on tactics, techniques, and procedures (TTPs) by threat actors. We will update this blog with more information as our investigation continues.

Ensar Seker, CISO at SOCRadar had this comment:

“The exploitation of unpatched SharePoint servers by Storm-2603 represents a serious escalation in threat actor behavior. What began as an espionage campaign has now evolved into a destructive ransomware operation using Warlock malware. This is significant not only because of the rapid weaponization of recent vulnerabilities, but because the group has adopted enterprise-level tactics; stealing credentials, disabling defenses, and deploying ransomware across entire networks using Active Directory tools.”

“Warlock ransomware in this context is particularly dangerous. Once Storm-2603 gains access to a vulnerable SharePoint server, they quickly move laterally, extract domain credentials, and push ransomware across systems often encrypting data en masse before defenders can respond. This is not a hit-and-run campaign. It reflects a strategic shift where attackers burrow deep, create persistence mechanisms, and time their ransomware deployment for maximum disruption.”

“The takeaway for enterprises is clear: if you run on-premises SharePoint, you must patch immediately. Beyond that, organizations should rotate keys and credentials, hunt for web shells or suspicious DLLs, and harden against lateral movement. Defenses like EDR in block mode, AMSI integration, and proper backup strategies are critical now, not optional. This campaign isn’t just a wake-up call for patch management, but for a broader rethink of how we defend internal collaboration platforms.”

James McQuiggan, Security Awareness Advocate at KnowBe4 adds this:

“Cybercriminals don’t need to be sophisticated, they just need organizations to be slow. Attackers don’t target the most vulnerable point, they go for what’s exposed, unpatched, and easiest to monetize. Essentially, a front door left wide open.”

“Enterprise environments are especially vulnerable because change takes time. There are processes, reviews, testing, and approvals that are needed to roll out mitigations and patches. However, if an organization’s SharePoint server is exposed on the internet with a known zero-day vulnerability and no compensating controls, it’s making their job easier.”

“If it’s internet-facing, treat it like a crown jewel. Anything exposed should be hardened, monitored, and patched rapidly, or segmented entirely. Limit attack surfaces by design. Many of these exposures exist simply because someone left default configurations or expanded access for convenience.”

“Cybersecurity isn’t about being perfect, it’s about not being predictable. The more visible and unpatched your environment, the easier it is for an organization to find and exploit. Organizations don’t need to outsmart every attacker, they just need to stop making it easy for them.”

If you have an on premise SharePoint server, now would be a really good time to update it. As in drop everything you are doing and apply updates right now. Because if it wasn’t clear that this was a today problem, it should be now.

Microsoft Pushed Out An Emergency Fix On Sunday For An Actively Exploited SharePoint Vulnerability

Posted in Commentary with tags on July 21, 2025 by itnerd

Microsoft on Sunday issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. To be clear, this is applicable to those with SharePoint on premise. In an advisory, Microsoft said this:

We are working on security updates for supported versions of SharePoint 2019 and SharePoint 2016. Please check this blog for updates.

To mitigate potential attacks customers should:

  • Rotate SharePoint Server ASP.NET machine keys
  • Use supported versions of on-premises SharePoint Server
  • Apply the latest security updates, including the July 2025 Security Update
  • Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an appropriate antivirus solution such as Defender Antivirus
  • Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions

The Washington Post is reporting that the U.S. government and partners in Canada and Australia are investigating this situation.

Andrew Obadiaru, CISO, Cobalt, an offensive security company, had this to say:

     “Zero-day vulnerabilities in widely deployed platforms like SharePoint are a goldmine for attackers because they provide immediate, scalable access to high-value environments. The challenge isn’t just patching—it’s that attackers typically implant persistence mechanisms within hours, ensuring long-term footholds. Defense strategies need to assume breach and validate controls through proactive testing, including red teaming and continuous pentesting, to uncover weaknesses before adversaries do. In today’s threat landscape, reactive security alone is a losing game.”

If you’re a SharePoint on premise user, drop what you are doing and patch your SharePoint instance to make sure that you don’t get pwned or you have not already been pwned seeing as this is an actively exploited exploit. Because this is a today problem to say the least.

UPDATE: Adrian Culley, Senior Sales Engineer, SafeBreach had this to say:

“This CVE represents a critical security incident: it was exploited as a zero-day vulnerability in active attacks against production systems before any patches were available—the most severe type of threat organizations face. The absence of a single remediation patch further complicates the situation. Microsoft has taken the unusual step of advising organizations to assume compromise and conduct thorough investigations to verify their security posture—language that underscores the severity of this vulnerability.

SharePoint Server 2016 environments face particular challenges, as no immediate technical remediation is available. Organizations must rely on breach and attack simulation exercises alongside their existing security controls to assess exposure. Proactive defense requires targeted hardening measures and resilience improvements to prevent falling victim to this sophisticated attack vector.”

2,300 Domains Seized in Lumma Infostealer Disruption

Posted in Commentary with tags on May 21, 2025 by itnerd

Microsoft’s Digital Crimes Unit facilitated the takedown, suspension, and blocking of about 2,300 malicious domains that formed the infrastructure backbone of Lumma Stealer, an info-stealing malware used by hundreds of cyber threat actors to steal passwords, credit cards, bank accounts, and cryptocurrency wallets. Lumma Stealer has also enabled criminals to hold schools for ransom, empty bank accounts, and disrupt critical services.

Microsoft has a blog post on this here: https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/

Ensar Seker, CISO at SOCRadar, commented:

“The coordinated takedown of Lumma Stealer’s infrastructure marks a pivotal moment in combating the proliferation of Malware-as-a-Service (MaaS) platforms. Lumma Stealer, also known as LummaC2, has been a formidable tool in the cybercriminal arsenal, facilitating the theft of sensitive data including credentials, financial information, and cryptocurrency wallets from nearly 400,000 Windows systems globally between March and May 2025.

“This operation, led by Microsoft’s Digital Crimes Unit in collaboration with international law enforcement agencies, successfully seized over 2,300 domains integral to Lumma’s operations and dismantled its command-and-control infrastructure . Such actions not only disrupt the immediate threat but also send a clear message to cybercriminals about the increasing capabilities and resolve of global cybersecurity alliances. However, the resilience of such malware underscores the necessity for continuous vigilance. Lumma’s ability to adapt employing phishing, malvertising, and exploiting trusted platforms highlights the evolving tactics of threat actors.

“While this takedown is a commendable achievement, it also serves as a reminder of the persistent and evolving nature of cyber threats. Ongoing collaboration between private sector entities and international law enforcement is essential to stay ahead.”

Takedowns are nice. But sometimes they’re a game of “whack a mole” where the threat actors pop up someplace else. Which is why these sorts of efforts need to be ongoing and not a one time thing.

Microsoft making all new accounts passwordless by default

Posted in Commentary with tags on May 2, 2025 by itnerd

From the “this should have happened a long time ago” department comes this  announcement from Microsoft that all new Microsoft accounts will become “passwordless by default” to secure them against password attacks such as phishing, brute force, and credential stuffing.

Although passwords have been around for centuries, we hope their reign over our online world is ending. Billions of times a day, people all over the world sign into their accounts. According to the FIDO Alliance, more than 15 billion user accounts can now sign in using passkeys instead of passwords. But we need billions more to make every sign-in passwordless. So, to observe World Passkey Day, take the leap. Start by securing at least one of your accounts—ideally as many as you can—with a passkey. Protect your digital life from unauthorized access and make signing in faster, easier, and most importantly, more secure.

Darren James, a Senior Product Manager at Specops Software had this comment:

“This is a good first step to help consumers become more familiar with passkeys and their usage. Passwords as we all know are still a key attack vector, but sadly we can’t just forget about passwords. Users still need to provide an email address when they sign up for their Microsoft account (Windows, Xbox and Microsoft 365 accounts), that can be used for account recovery should your passkey get lost, for example if you lose your smartphone. But what protects your email account? You guessed it — most likely a password!

“So although Microsoft won’t need to worry about your passwords being stolen from them, you will still need to make sure that any recovery methods you put in place still have a strong, unbreached password, or even better a passphrase and hopefully with a 2nd factor of authentication that isn’t something you can lose. Let’s not forget all the other accounts you have that aren’t controlled by Microsoft, work and personal. Even in this statement Microsoft themselves have said password use because of this has reduced by 20%, meaning that passwords are still in use by 80% elsewhere.”

“Right now, this is just for consumers, what about business or other professional users? Again, it’s better to take a layered approach, switching to passkeys may not suit the way your business operates, so passwords will still be part of the authentication story for some time to come. As mentioned above, making sure that passwords are unbreached, not just when you set them, but constantly checked to make sure they don’t become breached, and adding an additional, low friction MFA layer wherever they are used will be the best approach.”

Chris Hauk, Consumer Privacy Champion at Pixel Privacy offers this comment:

“I applaud any effort to make this a passwordless online society. However, while biometric authentication from fingerprints or face scanners definitely make logins more secure, I am concerned that users who choose to use a PIN will reuse the PIN across multiple sites (as other sites move to passwordless login) making PIN reuse as bad as password reuse.”

Roger Grimes, Data-Driven Defense Evangelist at KnowBe4 adds this:

“I think this is an encouraging decision by Microsoft, long overdue. My personal O365 account is under heavy password guessing attacks by hackers and bots around the world. It’s scary to see how many times hackers are trying to guess my password…and to be honest, I’m more than a little shocked that Microsoft was not proactively warning me about it. I got a warning about “unusual activity” on my O365 account when I was logging in from Calgary, Canada, where I was visiting for a business conference. Microsoft asked me to review that activity, and when I went to my admin console to review that legitimate login, I saw hundreds of other recent password guesses against my account from all over the world. It was shocking. I wondered why Microsoft was not warning me about it, even though I use strong passwords. It must be because what’s going on to my account is so normal and routine that it doesn’t meet the criteria of warning me. I updated my O365 password to an even stronger one even though I was not breached. Microsoft did automatically offer me a passkey version as well, and that’s good, but FIDO passkeys, as great as they are (compared to passwords) are still not well-managed at the enterprise level.” 

“FIDO needs to get enterprise and cross-platform management figured out better…which they are working on. But if it isn’t done soon and well, managing your FIDO passkeys could be as big as a problem as managing your passwords. But still, I applaud what FIDO created and passkeys are more secure than passwords. I would also like to see Microsoft (and Google and every other vendor) more strongly push phishing-resistant forms of MFA and authentication. FIDO passkeys are phishing-resistant, which is exactly why I love them and FIDO. But Microsoft (and Google, and Duo, and most other vendors) still push very phishable forms of authentication that are barely any better than the passwords they were designed to replace. Microsoft allows admins to require phishing-resistant forms of MFA, but doesn’t require them to. And I get it, 90% of the world uses phishable forms of MFA and moving them to phishing-resistant forms of MFA and authentication isn’t easy. Customers are resistant. Still, a customer using or going to a phishable form of MFA or authentication is not ideal. It’s a lot of work for a false sense of security. I wish Microsoft (and Google, and Duo, and other vendors) more strongly advocated for and pushed phishing-resistant forms of authentication. We are years past when we should have already done so. The MFA industry, in general, has let customers down by allowing them to select and use phishable forms of MFA and authentication, especially when there are many phishing-resistant forms.”

Now I have been a major advocate of passwordless all the things for some time now because you can’t phish, sniff or steal what doesn’t exist. I am in the midst of converting all of my passwords to some form of passwordless authentication where possible. The key words here are “where possible” because not everyone supports this yet. Thus I would urge banks, eCommerce, anyone to jump onto this train as soon as possible. And I would say that organizations should do the same as well. Because this is one of those things that will make the world a safer place.

New Microsoft Email Sender Requirements Go Into Effect On May 5th

Posted in Commentary with tags on May 1, 2025 by itnerd

Microsoft recently announced updated email sender requirements, raising the bar to help better protect email inboxes by making email authentication a prerequisite for successful email delivery to Outlook.com.

On May 5, Microsoft will start rejecting non-compliant emails and you can read more about it here. Which is something that anyone who runs an email server should do. But here’s the TL:DR:

  • Sending domains must have a published DMARC policy, with a policy setting of p=none or better, and there must be proper alignment with either SPF or DKIM authentication settings (Microsoft’s guidelines recommend both be aligned whenever possible).
  • If your domains do not meet these requirements, your non-compliant emails will be rejected as of May 5.

Please note: If your domains are at enforcement (p=reject or p=quarantine), congratulations your domain is protected. However, if your DMARC policy is at p=none, your domain is not protected and is open to phishing and spoofing.

I’ll be checking my email servers over the weekend to ensure that they are compliant. You should do the same so that you have no issues on May 5th.

Microsoft Entra Account Lockouts Caused by User Token Logging Mistake

Posted in Commentary with tags on April 22, 2025 by itnerd

From the “Oops” department comes this story. Microsoft has reported that the Entra accounts that were locked out over the weekend were caused by the invalidation of user refresh tokens that were mistakenly logged into internal systems.

More details here:  https://www.reddit.com/r/sysadmin/comments/1k2pmkz/comment/mo33q3f/

On Friday 4/18/25, Microsoft identified that it was internally logging a subset of short-lived user refresh tokens for a small percentage of users, whereas our standard logging process is to only log metadata about such tokens. The internal logging issue was immediately corrected, and the team performed a procedure to invalidate these tokens to protect customers.  As part of the invalidation process, we inadvertently generated alerts in Entra ID Protection indicating the user’s credentials may have been compromised. These alerts were sent between 4/20/25 4AM UTC and 4/20/25 9AM UTC. We have no indication of unauthorized access to these tokens – and if we determine there were any unauthorized access, we will invoke our standard security incident response and communication processes.  

Jim Routh, Chief Trust Officer at Saviynt, commented:

“It is not often that the identification of security vulnerabilities within a commonly used platform, which caused business disruption for some Microsoft enterprise customers, has some positive attributes for enterprises. The positive news is that the disruption occurred over the weekend, and today (Monday), customers have the facts along with the fix (corrective actions) necessary for recovery. The vulnerability and the action taken (token invalidation) were ultimately shared by Microsoft in an advisory relatively quickly. This is a sign of health or resilience despite the inconvenience to some enterprise customers over the weekend.”

I’ll give Microsoft credit for discovering this, fixing this, and admitting to it quickly. Hopefully something like this never happens again as this had the possibility of not ending well on multiple fronts.

Microsoft To Windows 10 Users…. Buy A New PC With Windows 11

Posted in Commentary with tags on March 22, 2025 by itnerd

Later this year, Windows 10 is going to go into end of support status in a few months. But the problem is that there’s a lot of Windows 10 PCs out there. No problem says Microsoft. Because you can just trade in your PC to get a brand new Windows 11 one:

Windows Latest spotted a new email from the Redmond giant related to Windows 10 in our ProtonMail account. We use this email for the Microsoft account of the test PC running Windows 10, which is sadly not capable of running the latest and greatest OS from Microsoft.

The email begins with a bold “End of support for Windows 10 is approaching” heading, followed by direct links to check the upgrade eligibility or purchase a new computer.

Next up is a FAQ section that tries to answer all the important questions related to Windows 10’s retirement. The first question clarifies the things that’ll happen after October 14, 2025, which includes the end of all kinds of support from Microsoft. It clarifies that all the free support will halt from that day onwards but doesn’t offer any paid alternatives.

After that, there is a brief answer about trading or recycling your old PC if you want to upgrade, followed by an assurance that your PC will work but won’t get updates. However, with time it’ll support fewer apps and will become a hunting ground for malicious actors.

Here’s the problem with this approach. People aren’t going to get much when trading in a laptop or a desktop that’s too old to run Windows 11. The market for those machines is already falling fast. On top of that with inflation, tariffs and the like squeezing the bank accounts of people, I really don’t think that this is a winning approach as you have to have the disposable income to buy a new PC. But I guess that their thought process is YOLO.

StilachiRAT Targeting Credentials and Crypto Wallets Warns Microsoft

Posted in Commentary with tags on March 19, 2025 by itnerd

News of a novel remote access trojan named StilachiRAT, which Microsoft has warned employs advanced techniques to sidestep detection and persist within target environments.

In November 2024, Microsoft Incident Response researchers uncovered a novel remote access trojan (RAT) we named StilachiRAT that demonstrates sophisticated techniques to evade detection, persist in the target environment, and exfiltrate sensitive data. Analysis of the StilachiRAT’s WWStartupCtrl64.dll module that contains the RAT capabilities revealed the use of various methods to steal information from the target system, such as credentials stored in the browser, digital wallet information, data stored in the clipboard, as well as system information.

Microsoft has not yet attributed StilachiRAT to a specific threat actor or geolocation. Based on Microsoft’s current visibility, the malware does not exhibit widespread distribution at this time. However, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape.

Erich Kron, Security Awareness Advocate at KnowBe4, has the following comments:

“People who work or play in the cryptocurrency world are significant targets for bad actors due to the unregulated nature of the funds, the possibility for anonymity, and the fact that once a transaction is complete, unlike with wire transfers or other more traditional methods, there is no way to undo it.”

“As cryptocurrency continues to become more mainstream, attackers will adjust their tactics as they refine their efficiency and speed. Many people just getting started with cryptocurrency are not familiar with its pitfalls, and are sometimes excited to make a profit, so they take foolish risks.”

“For those people dealing with cryptocurrency, it is important that accounts use extremely strong passwords that are unique and impossible to guess. In addition, accounts should be protected by MFA, and the individuals should educate themselves about common cryptocurrency scams and cyberattack methods.”

This is all good advice not just for anyone in the crypto space, but in general. Things like MFA and strong passwords are going to mitigate threat actors like this one from carrying out attacks of any sort. Crypto related or not.