So, it seems that the attack vector was that Microsoft was running RHUI Log Collector open to the public internet for some reason.<p>Considering that's from Redhat, and not Microsoft, I do wonder if this is a non sensible default setup issue and there may be many enterprises running this out in the open.