TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tenable CEO says Microsoft security is blatantly negligent

122 pointsby jollofricepeasalmost 2 years ago

9 comments

jonmoorealmost 2 years ago
Coincidentally, today I noticed a surprisingly high number of file accesses from Tenable&#x27;s Nessus software, caused by it reading a megabyte-sized config file one character at a time without buffering, each going through Win32&#x27;s ReadFile.<p>It seems that negligence is not in short supply.
评论 #37124129 未加载
pluto_modadicalmost 2 years ago
This is generally my impression of anything Microsoft. O365, Azure, AAD, Teams, logging needing extra support levels, patching on Windows, how CVEs aren&#x27;t CVEs, how they won&#x27;t implement secure defaults, etc.<p>Mind you my opinion is easily permanently soured on far cooler engineering things (like Cloudflare) for them hosting doxxing things... as much as I like the engineering... if you refuse to keep people safe why would I take the risk to use your infrastructure?
评论 #37118125 未加载
badrabbitalmost 2 years ago
Well, I am glad someone is doing research in this area. Powerapps are one of those things I hope I never have to deal with in a security incident. The logging and access control is messy but the underlying implementation uses normal azuread authentiation&#x2F;access control.<p>Let&#x27;s say a random user creates an app to measure something for their team, store it in sharepoint and update the avatar or some other property of users stored in azuread. Because of that latter part, the powerapp might (!) have requested and been granted directory.readwrite.all which means it can do anything at all including making itself or whoever can somehow control it and abuse it global admin, controlling the whole tenant.<p>A lot of this stuff is for business customers only, I suspect that&#x27;s why you see little research or random threat actors abusing these types of features (until they&#x27;re not random anymore).
TheHumanistalmost 2 years ago
This was brought to Microsoft&#x27;s attention by Tenable well before the Tenable CEO decided to make a public statement about it.<p>I have a relative that works for them doingnthe CyberSec thing who had talked about this a few weeks ago.
JoBradalmost 2 years ago
Actual title: Microsoft fixes flaw after being called irresponsible by Tenable CEO<p>Maybe they need an Azure SP3 moment?
gundmcalmost 2 years ago
It&#x27;s bizarre how the author refers to Microsoft as &quot;Redmond&quot; repeatedly.<p>&gt; Redmond has since notified all impacted customers through the Microsoft 365 Admin Center starting August 4th.<p>&gt; initial fix deployed by Redmond on June 7th was tagged by Tenable as incomplete<p>&gt; To make matters even worse, Redmond&#x27;s initial commitment to fixing the issue...
评论 #37119005 未加载
评论 #37117514 未加载
评论 #37119035 未加载
评论 #37118118 未加载
评论 #37119705 未加载
bravetraveleralmost 2 years ago
Careful, Tenable, lest we throw stones at your bucket of regex called Nessus
villgaxalmost 2 years ago
Do people just forget that the three letter organisations of the USA are always able to obtain MSFT touching data??
exabrialalmost 2 years ago
Also, water has been discovered in vast quantities near the ocean.