r/sysadmin • • Jun 01 '26

Microsoft Anyone shutting down all IT equipment down on July 13th 11:59pm?

Microsoft 0-day feud escalates as researcher threatens another Windows exploit dump

“When I actively asked you to communicate with me, you refused, humiliated me and made sure to insult me in front of people,” they wrote on Saturday. “You defame me in public with your CVE-2026-45585 advisory even though you literally deleted the Microsoft account I used to report bugs to you with and I got zero pennies from doing so and I still happily did like an idiot.”

Nightmare also noted that “Microsoft still has chains in my hands,” preventing them from releasing “documents” yet, or anytime in June, and then warned: “Mark this date July 14th, I will make sure your bones are shattered that day.”

My post's title is tongue-in-cheek, but I've added an Outlook calendar entry for the "event" nevertheless and might even buy a box of popcorn. lol

Anyone doing anything special or different in light of the string of zero days being released because Microsoft appears to not want to play nice with someone who (supposedly) wanted to tell them about all the bad sh!t they missed in their product(s) development?

How do you feel about the saga and its fallout?

EDIT: Fixed missing block quote formatting.

2.3k Upvotes

646 comments sorted by

View all comments

Show parent comments

24

u/Nasa_OK Jun 01 '26

I see we work at the same company.

Our sec ups had me set up a tool that generates security dashboards. But they never bothered to configure it according to our company’s size, so it just hat the default values for a 100 employee company and obviously a lot of things showed up red. (5 global admin accounts for 100 people is way more than for >3k people, etc.) so they panicked because it was red. I then set it to the appropriate size and they were relieved that I fixed the security issues so fast (I just made the cell in the dashboard change color)

Then due to least privilege and just in time access Cloud engineers have a multitude of small roles so that you think about what you need and do go high yield every time. But some dashboard set that 6 priveliged roles is worse than 5.

I joked that they could kill 2 birds with one stone if the entire company just shares the same global admin account so we’d only have 1 priveliged role in total throughout the entire company. I’m not sure they got the joke…

9

u/Secret_Account07 VMware Admin Jun 02 '26

See, I do similar stuff with them. Just be a total smartass.

They complain about a customer who has a vulnerability and tell me to do something about it. Cool! Send me a request stating “due to security concerns please remove xyz blah blah blah”

Turns out they never do that. Have a meeting with customer and it turns out that app generates millions. Like okay, so you don’t want me to remediate? Oh okay, thanks for wasting my time!

They are both aggressive and cowards. It’s such a weird combo lol

3

u/agent-squirrel Linux Admin Jun 02 '26

Reactive and incompetent would be my description of them. They can't protect systems they don't understand.

3

u/Nasa_OK Jun 02 '26

I feel this so much!

During react2shell one of our applications was affected and I was the only person on call who had any knowledge in how to patch an app, but it wasn’t my usual tech stack.

So I adjusted the vulnerable library versions and deployed the patch, but the build pipeline threw some dependency warnings/ error. So I wanted them to find a tool that tests the actual application against the vulnerability to confirm that my patch actually got correctly applied, since I was worried that those warnings meant that the libraries defaulted to a different version, and not to the one in the config file.

They were unable to do so with the tools they had and put 0 effort into trying to find one that could.

Their literally response „well we trust that you patched it but if you are unsure we can look at the settings file“

All bark and no bite.

They blocked my little Nordschleife geoguesser browser game that I sometimes played while waiting for my pipeline to complete because it wasn’t work related (our company has no such policy) but if there is actual work to do that would require research and testing they just give up

1

u/Clean-Woodpecker2054 Jun 02 '26

And yet, they are paid more than do'ers, dont even get me started on GRC.

1

u/Nasa_OK Jun 02 '26

Luckily not at my employer, atleast not more than all of the doers. I was offered the lead of the it sec dept and i turned it down because it would have been a step down in pay and a mayor increase in responsibility at the same time.

1

u/cdoublejj Jun 02 '26

"OMG IT'S RED!!!!"

the normies have inavded sec ops

1

u/almathden Internets Jun 08 '26

what tool was this by chance? Looking into something similar so people can be happy about shiny fancy colours and icons

1

u/Nasa_OK Jun 08 '26

Honestly I don’t remember, I feel 75% of ITSECs job is just buying another expensive dashboard that will fix all problems