Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Breaching Microsoft via DeepSpeed GitHub Repository (johnstawinski.com)
6 points by cyberbender on April 17, 2024 | hide | past | favorite | 3 comments


How crazy is it that Microsoft is not even monitoring/alerting on commands like, "whoami" being issued on their managed systems? Wow.


I wonder if alerts did come in, but Microsoft didn't respond quickly enough. That's giving them the benefit of the doubt, though; very possible they weren't monitoring this system. If they were, they probably would have identified the fact that it was exposed to the internet via a public GitHub repository....


Agreed. That was a great read and cautionary tale about not following best practices!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: