Elektrine lite

← Feed

@wdormann@infosec.exchange

Post #4049980

2026-07-24 00:26 UTC

Fun fact: If you go to report a vulnerability to MSRC that is a missed-fix or a variant of something that Microsoft has already released an update for, you must provide the existing VULN- identifier. Meaning, only the person who reports a vulnerability to Microsoft is allowed to tell them that the fix wasn't good enough. (The VULN- ID is what you get when you submit a case to MSRC) Great job, folks.

Replies (4)

  • @ferrix@mastodon.online 2026-07-24 00:38

    @wdormann@infosec.exchange I bet there's a support for this form that will clear it up, by having copilot alter and regurgitate whatever doc page is the closest to your query

    Open ##4050194

  • @kaaswe@swecyb.com 2026-07-24 08:59

    @wdormann@infosec.exchange That behavior my friend is called CMA (Cover My Ass). They try to delay as much as they can because if there is a breach with their code included they can always say “Hey, we didn’t know as nobody has yet reported this vulnerability.” #microslop #cma #microsoft

    Open ##4058756

  • @wdormann@infosec.exchange 2026-07-24 19:05

    MSRC is starting well with their "piss off the reporter" strategy. I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability. I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.

    Open ##4070286

  • @avuko@infosec.exchange 2026-07-24 19:09

    @wdormann@infosec.exchange Microsoft: putting the Computer in “Computer Says No”.

    Open ##4216144