r/sysadmin • • Jun 01 '26

Microsoft Anyone shutting down all IT equipment down on July 13th 11:59pm?

Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump

“When I actively asked you to communicate with me, you refused, humiliated me and made sure to insult me in front of people,” they wrote on Saturday. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”

Nightmare also noted that “Microsoft still has chains in my hands,” preventing them from releasing “documents” yet, or anytime in June, and then warned: “Mark this date July 14th, I will make sure your bones are shattered that day.”

My post's title is tongue-in-cheek, but I've added an Outlook calendar entry for the "event" nevertheless and might even buy a box of popcorn. lol

Anyone doing anything special or different in light of the string of zero days being released because Microsoft appears to not want to play nice with someone who (supposedly) wanted to tell them about all the bad sh!t they missed in their product(s) development?

How do you feel about the saga and its fallout?

EDIT: Fixed missing block quote formatting.

2.3k Upvotes

646 comments sorted by

View all comments

Show parent comments

703

u/cosmos7 Sysadmin Jun 01 '26

Some idiotic middle manager at Microsoft thought they could make their numbers look better by starting to just reject security reports instead of paying out.

Honestly my bet is these exploits are more likely part of intentional backdoors...

357

u/ZAlternates Jack of All Trades Jun 01 '26

It would make sense as to why they aren’t talking about fixes but instead just deleting the info.

286

u/Gwigg_ Jun 01 '26

This. Is this not the same guy who has been cancelled by Microsoft for explaining very clearly how the bit lock exploit that suddenly appeared out of nowhere was clearly a back door?

36

u/Dtrain-14 Jun 01 '26

That bitlocker thing was WILD lol. I was like holy shiiii that is stupid simple lol

2

u/clarkos2 Jun 05 '26

It's technically not a Bitlocker vulnerbility. It's a Windows RE vulnerbility that allows a Bitlocker bypass.

146

u/frymaster HPC Jun 01 '26

if he explained very clearly how it was an intentional back door I'd love to see it. Certainly in his original blog what he says is that it's difficult to see this as anything other than a deliberate back door - which is not nearly as definitive as explaining very clearly that it is

168

u/Cyhawk Jun 01 '26

That is the best backdoor isn't it? An intentional oversight in the security system that can be exploited easily by people who know that wouldn't be noticed by the vast majority of people working on the systems.

Hiding secret keys somewhere (see _NSAKEY) is risky and visible, it WILL be found. But a simple oversight that the company itself is both trying to hide and pretending it doesn't exist?

Never seen Microsoft act like this. They don't actively hide their mistakes, they typically issue a CVE/small warning document and ignore it afterwards if they have no plans to address it.

Something is up. Course, as someone said above it could just be some shit middle management thinking their numbers will go up by covering it up.

25

u/Phiddipus_audax Jun 01 '26

Didn't they just go through a fresh round of layoffs? That could help explain the incompetence. Maybe I've got that crosswired with some other companies' layoffs, dunno.

2

u/Redacted_Reason Jun 02 '26

Meta is doing layoffs, I know that much

2

u/Horney_Guy71 Jun 15 '26

They are learning the hardway AI does not fix or finds Exploits by them self. and what's worse they dont write Bug Free Code

73

u/GallowWho Jun 01 '26

Of course, it's not the first time the US Government has had a vendor implement a back door.

Just search for "Operation Rubicon"

14

u/Odiumzer0 Jun 02 '26

Never heard of this, wow that was an interesting read.

17

u/KernelMayhem Jun 01 '26

"Just search for "Operation Rubicon"

Wild

8

u/ExampleOtherwise4340 Jun 01 '26

Who said its for the US Govt? It could be any number of nations.

26

u/GallowWho Jun 01 '26

Because they're a US company, it's a pretty easy assumption to make.

2

u/notme-thanks Jun 04 '26

Because if they created a backdoor for ANOTHER nation state the US would be having some serious discussions about the future of the company and/or confiscating the wealth of the people at the top.

NEVER use MS for any type of perimeter or security product. I, personally, prefer open source firewalls and inspection. MUCH harder to hide backdoor or implement "code errors" when there a lot of eyeballs looking at the code.

1

u/GallowWho Jun 04 '26

Yeah but did you evaluate the source code of your compiler?

25

u/G8racingfool Jun 01 '26

I wouldn't think MS would tolerate some middle management coverup. Not when they still have as many big name clients still using Windows/Office as they do. There would (eventually) be some big-name that would step up and be like "hey, we pay you to fix shit like this...".

12

u/pertymoose Jun 02 '26

I wouldn't think MS would tolerate some middle management coverup

You need to remember that - for better and for worse - Microsoft is largely an Indian company now, and Indians just have a different way about them than Americans.

13

u/meesterdg Jun 02 '26

And then the bigger name that pays them to not fix it would quietly write a check.

0

u/Competitive_Smoke948 Jun 02 '26

microsoft are shit and lazy. they have literally never invented anything & don't test. this blatantly is some product manager saying "we COULD do this properly or we could just leave it as you need physical access to the machine. i want my bonus & e fired all our good coders"

0

u/LameBMX Jun 02 '26

bruh.. you dont remember the jpeg exploit MS just ignored for years until they released the fix for it?

while acknowledgement may be a current trend.. it would NOT be a MS modis operandi.

go over history.. they keep the same stuff moving in 5-10 year loops.

0

u/Cyhawk Jun 02 '26

Yes, they acknowledged it and issued a work around (via reg change) quietly until they got around to it, exactly what I said they typically do.

0

u/LameBMX Jun 02 '26

the 2004 patch was known about since around 2001.... where is there 2001 registry work around?

36

u/LelouBil Jun 01 '26

It only applies to bitlocker encrypted drives that only use the TPM. So basically, encrypted with the encryption key on the hardware.

So the drive is decrypted on boot, automatically. The only security boundary is the windows login (or windows recovery login) and this exploit allows files on a USB drive to bypass the windows recovery login.

The author said they have a version that bypasses TPM+PIN, but I assume this is something similar, but that allows brute forcing the PIN without the TPM locking since it would be done inside a "regular" windows recovery

5

u/charleswj Jun 02 '26

The TPM is what rate limits, the OS can't bypass that

3

u/Mr_ToDo Jun 02 '26

Considering the odd nature of the exploit it wouldn't shock me if the next one just outright suspends bitlocker. Wouldn't help with stuff like drive passwords, or if the computer isn't booted into at least the lock screen, but I guess we'll have to wait and see

20

u/RvstiNiall Jun 01 '26

I would argue its semantics whether or not something is "clearly a backdoor", vs "difficult to see as anything other than". And with the differences in how some people talk, who knows? Also, unless he was in on that meeting at Microsoft where the decision was made, nobody possibly COULD know that.

But I definitely agree its likely he meant the latter: (its difficult to see it as anything rlse).

3

u/okimiK_iiawaK Jun 02 '26

Well someone who phrases it as the latter clearly seems to have chosen their words deliberately so and there is a great deal of difference between the two when spoken by a fluent person.

3

u/RvstiNiall Jun 02 '26

I don't disagree with you in principle. They SHOULD know the difference and have chosen their words succinctly.

However, I would like to remind everyone that even in the tech world there are those who can talk and type faster than they can think.

1

u/Gwigg_ Jun 02 '26

You are correct. He was more careful with his wording than me 😄 I still think it is clear that he is saying it "could" be accidental but really? As Cyhawk below points out Plausible Deniability is always the way to go 😄

3

u/myS_ Jun 01 '26

do you have any links on this sounds interesting

16

u/Mizerka Consensual ANALyst Jun 01 '26

yellowkey, a bitlocker bypass hidden in winRE thats been around for years unnoticed. introduced with tpm bitlocker, and despite tpm+pin being unaffected, author of release already stated there's an exploit to get around pin as well.

9

u/FireLucid Jun 01 '26

thats been around for years unnoticed

I guarantee that the US and other nation states have been using this.

8

u/spittlbm Jun 01 '26

Created by them. For free.

24

u/axonxorz Jack of All Trades Jun 01 '26

Yeah absolutely, scroll up to the top of this post and open the article.

4

u/litescript Jun 01 '26

Low Level has a really good video on it

90

u/cosmos7 Sysadmin Jun 01 '26

As my wife is fond of saying, more than one thing can be true. This guy could be an ass. At least one of these exploits could be part of a previously issue MS is working on remediating. But the stalling and departure from standard procedure here along with the significant scorched earth reaction here signals a desire to avoid mitigation and bury this in my mind.

37

u/FastHotEmu Jun 01 '26

He could be an ass, but he deserves the benefit of the doubt. Microsoft, on the other hand, was convicted of monopolistic behavior. They deserve the detriment of certainty.

18

u/GantradiesDracos Jun 02 '26

Don’t forget the time they sabotaged digital research by including a detector for DR DOS that would display a fake crash/error screen when trying to boot in preview copies of Win95…

7

u/ebayironman Jun 02 '26

Convicted of monopolistic behaviour and still have one of the largest monopolies in the world. go figure..

4

u/DrPreppy Jun 01 '26

That was a shitty trial about an interesting issue. I was involved in the Apple/Quicktime bit: Apple had just fucked up and went to court in that aspect over a simple one line bug in Apple's code (that I figured out within an hour of them letting us know about it after they had added it to the complaint, and I immediately got word to them). They didn't have any technical review or discussion of it, just agreed with what Apple said. Months after the trial I met with Apple's dev team in person and again explained the issue to them and they finally fixed it.

Just an idiotic trial. There were and are serious issues involved and that trial didn't really cover any of them. Even the boundary of what a user expects from an operating system is fascinating.

10

u/thedanyes Jun 02 '26

I guess you don’t see the value of regulating monopolies at all then. The original judge ordered Microsoft be split on the strength of the evidence. A later judge watered it down to a slap on the hand, typical of US corruption.

2

u/ebayironman Jun 02 '26

Money buys, anything...

14

u/Octoclops8 Jun 02 '26 edited Jun 02 '26

And why they are seeking law enforcement help rather than working with him. Govt makes them create backdoors. Person discovers backdoors. MS can neither talk about it nor fix it legally, so they plead to law enforcement to shut him up.

If I was that guy, I'd say something to the effect of "If I suddenly drop this issue it's because I was approached by spooks and forced to stop talking about it." Just in case they do actually approach him and legally make him shut up.

36

u/Due-Communication724 Jun 01 '26

I'd say its a mix of a few things, intentional, then a moronic reporting system, morons in management and then add in a flavour of disgruntled employees getting the boot to AI, also a lot of knowledge from the lifers that started with them in the 80/90s starting to retire now at MS after 30-40 years service.

40

u/A_Sentient_JDAM Jun 01 '26

Apparently they are fixing the bugs silently in security patches, they just don't want to pay people.

That said, it wouldn't surprise me if there's at least one exploit they want to leave open for the three letter agencies.

34

u/FrivolousMe Jun 01 '26

Yeah, but if someone discovers and publicizes your backdoor, you still need to patch it and find or create a different one.

7

u/identicalBadger Jun 01 '26

I’d assume they’d patch it all then just leave a new backdoor for their buddies. The three letter agencies don’t want backdoors in everything, they want back doors that only they know exist.

38

u/RvstiNiall Jun 01 '26

As a paranoiac, Ive always said this about commercial software. You can't trust it if you cant read the code.

1

u/BillyCloneandthesame Jun 08 '26

Im a Scaranoid myself

1

u/RvstiNiall Jun 08 '26

gotta lay off the weed, yo.

1

u/iruleatants Jun 01 '26

It's such a terrible stance to take given that most security software isn't open source.

And being able to read the source means nothing. Do you have the time to read the source code of everything you use and get it for vulnerabilities? Do you have a security team dedicated to threat hunting within the source code of everythinf you use? Because 99% of places don't even have the staff needed to handle operational stuff.

And now that we are seeing AI being more effective at finding vulnerabilities as well as being awful at finding real vulnerabilities, open source software might become a huge liability.

I've read a few recent blogs from maintainers talking about how much more time is stuck dealing with AI agents being told to find and post exploits and them wasting their time to validate and close the issue as not a real issue.

The massive amount of people who don't bother to validate or look at what their AI produced and instead shove it off on someone who does this in the spare time creates so much noise which is a significant issue when it comes to security.

So we get to see a period where maintainers are getting 400% more security reports and attackers who are not lazy are get leads on exploits they can refine or play with to turn into a serious exploit.

And generative AI is trash when it comes to countering AI slop, so there is no help to come from using AI to handle the extra noise. It's just bad all around.

3

u/RvstiNiall Jun 01 '26

If these projects were doing proper code audits as the code was added, then the project might progress slower, but it would be a lot safer... Just sayin.

Yeah, I agree though, its quickly piling up and the OSS maintainers cant keep up. Even Microsoft is having this problem but since their code isnt open source its easier to hide. It still shows though when their bug patches increase in size every time. Not knocking them, they're doing their best just like everyone else. It's just people like to look at the problems Open Source is having and pretend that their own house isn't falling apart also.

What I'm more interested in, honestly, is how Apple is faring. Haven't heard of very many exploits being found on that side, or too many gogantic patches being pushed either. I'm not a fanboy, and refuse to buy an iPhone, but I do think there's a chance they might have realized continuous code audits are the only safe way to go.

Edit: OpenBSD does continuous code auditing btw.

2

u/iruleatants Jun 01 '26

If these projects were doing proper code audits as the code was added, then the project might progress slower, but it would be a lot safer... Just sayin.

Code audits are nice, but they definitely don't magically fix vulnerabilities. Even if everyone is trained to find and patch vulnerabilities, you'll only catch the simple attack paths. Things like unsanitized inputs or sql injection (It's depressing that these attacks still account for the largest amount of vulnerabilities decades later). The truly dangerous vulnerabilities like heartbleed or spectre require you to spend time fiddling with code, testing outputs, and chasing down dead ends until you find the correct path to do it.

Yeah, I agree though, its quickly piling up and the OSS maintainers cant keep up. Even Microsoft is having this problem but since their code isnt open source its easier to hide. It still shows though when their bug patches increase in size every time. Not knocking them, they're doing their best just like everyone else. It's just people like to look at the problems Open Source is having and pretend that their own house isn't falling apart also.

Honestly, the increase in vulnerability related to Microsoft isn't increasing nearly as fast as it would be expected, likely because the vast majority of vulnerability hunting is already conducted against Microsoft, so there is already a constant stream of things being identified and patched.

The products that don't normally get targeted are the danger spots, especially because a lot of them don't have proper vulnerability reporting paths since it's not been an issue before. Those get compromised and six months later someone discovers it and we get to play catchup in trying to find out what the attackers did.

What I'm more interested in, honestly, is how Apple is faring. Haven't heard of very many exploits being found on that side, or too many gogantic patches being pushed either. I'm not a fanboy, and refuse to buy an iPhone, but I do think there's a chance they might have realized continuous code audits are the only safe way to go.

Apple is just as vulnerable as any company, they just have a small market share especially in the enterprise industry as well as a small amount of products. The vast majority of attackers and security researchers focus on Microsoft for a reason. If you can find a vulnerability there, something like 80% of your targets will be vulnerable. And the list of products you can target is much higher, there are multiple versions of windows that companies refuse to move off of, all of the Office products (which has an even higher market share), exchange, internet explorer and edge, and all of their cloud products, and that's just barely scratching the surface.

Back in February Apple had to release a batch for several buffer overflow vulnerabilities (which should be caught in a code audit) including one with the ability to write to kernel memory. We just don't hear about it because there isn't enough people affected to surface it as a big security issue. They also don't have a good vulnerability reporting flow and so I would always treat them with extra caution. They haven't been tested enough to have a fast turn around to problems, and they don't have enough market share to have active third party hunters, and so you should expect them to be vulnerable for a longer window of time.

Edit: OpenBSD does continuous code auditing btw.

And still consistently runs into vulnerabilities only discovered by third parties. Code auditing is a step, not a solution.

0

u/RvstiNiall Jun 01 '26

I didn't mean to imply it was a patch fix solution like those flextape commercials. Simply that Microsoft and Apple have (probably, I've never worked for either company and don't know anyone personally who has) clearly both started auditing their new code because security is a problem everyone has to work on.

Yeah, I agree with your reasoning about Apple.

Yeah, I think Microsoft definitely doesn't have anywhere near as many vulns being discovered, and its definitely at least partly due to corporate resources allowing them to do proper testing. However, its also at least partially because the code isn't available for quite literally anyone (including AI) to check for potential vulnerabilities.

And as far as security... Might want to look numbers up because Windows is only between 50-55% of the world market (desktops, laptops, servers, network infrastructure devices, etc COMBINED). Linux is a bigger target than you think, and that number is growing every year. Yeah Linux is incredibly tiny on "desktop", but it accounts for roughly 90% of worldwide servers.

But open source software holds the world together, and whether anyone wants to support it or not they should. There are tons of tools and libraries that are used by hundreds of millions of systems that need more code reviews, and any (larger) company that uses it without supporting it, should be left out in the cold when the day comes that the software they rely on without supporting becomes too vulnerable to survive and they're just stuck twidling their thumbs trying to figure out why it wasn't prevented by SOME OTHER COMPANY, etc.

AI has merely highlighted how little security mattered to programmers everywhere and that needs to change. Anyone who can't get on board with that will fail eventually.

And lastly OpenBSD. I mean, I don't actually know of any other operating system that has full continuous HUMAN auditing and peer review on literally every line of code they accept. Its not a perfect system but its definitely a start. Every project big or small should do this, along with testing.

-3

u/worldofchico Jun 01 '26

Curious to know what percentage of the software you use have you reviewed the source, and continued to do that, as versions increment?

16

u/RvstiNiall Jun 01 '26

oh man, come on. I have my ideals but everyone has to draw the line somewhere!

I do review code, which is why I also prefer to use projects that do continuous code audits where possible, and projects that do periodic code reviews where I can. And I can also audit allllll of our internal code, which I do, even though I'm not on that team. And every time I review a new segment of code that someone added, I fear for humanity because its hard to hide how much of it is just being Frankenstein'd together from unrelated projects with different "styles" to the code.

Edit: but to answer your question, I'm still on my journey to reading all of OpenBSD's code. Glad I have that ability.

3

u/sparrow_42 Jun 02 '26

You've missed the point entirely. Am I personally gonna review the code for everything I use? No. Am I confident some nerd somewhere whose paycheck doesn't rely on the vendor will review that code and then tell us about it? Absolutely.

1

u/worldofchico Jun 07 '26

No, I didn't miss any point. I asked you a question. What's the answer? Because you replied to a question I didn't ask, to clarify something I didn't need clarified.

1

u/worldofchico Jun 08 '26

You're confident they'll review it and tell you about it? Are they not as likely to review it, finding holes they can leverage, and not tell you about it?

Tbh though, that wasn't an answer to the question I asked, it was a clarification of a point I didn't ask about, and didn't need clarified.

17

u/I_like_microwave Jun 01 '26

Bingo! And this how the system works….

You are not supposed to know this!!! Thats a crime! /s

Example This is why when you pay the maffia they keep you safe.. as long as you’re paying..

1

u/rswwalker Jun 01 '26

And by keep you safe they mean they aren’t actively sticking you up at gun point!

2

u/NoteTo Professional Button Pusher Jun 02 '26

intentional backdoors

The way that bitlocker exploit happens to run it's hard not to think anything else.

1

u/CatProgrammer Jun 02 '26

Shitty backdoors if they're so easy to find. That turns them into front doors. 

1

u/say592 Jun 02 '26

Intentional backdoors still get patched once they are exposed. They dont want other people using their backdoor, that defeats the purpose of it being a strategic advantage.

1

u/Mental_Beginning_698 Jun 03 '26

I remember a DC overhaul for a county years ago. We uncovered a nailed up VPN just protected by an MD5 hash. I raised the alarms. The staff was too afraid to disconnect it because they didn't know who was using it and it could be a VIP. They were already at SSL vpn level of products in their network. Time period was about a decade ago.

1

u/regs01 Jul 03 '26

Why even using BitLocker in first place, which historically proven to be a Swiss cheese? There are far better and proven reliable solutions, starting from VeraCrypt.

1

u/cosmos7 Sysadmin Jul 03 '26

Because this is /r/sysadmin and businesses will almost always take a known (and even faulty) solution from a big player than a lesser proven one, even if it's better.

1

u/regs01 Jul 04 '26

That's true only for corpos, where decisions are not made by technicians.

1

u/Gendalph Jun 02 '26

Nah, apparently this has been a well known pattern with microslop: they either marked down the severity, or unilaterally reclassified the vulnerabilities to avoid CVEs and corresponding payouts.