Elektrine lite

← Feed

@wdormann@infosec.exchange

Post #4070286

2026-07-24 19:05 UTC

MSRC is starting well with their "piss off the reporter" strategy. I reported in full detail a two-vulnerability exploit chain, since on their own either vulnerability is somewhat shrug-worthy. I got a request that I submit a separate report for the second vulnerability. I dunno, maybe do it yourself? You already have everything. MSRC is a perfect example of an organization where nobody wants to do their job.

Replies (1)

  • @buherator@infosec.place 2026-07-24 19:17

    @wdormann@infosec.exchange What *is* their job though? Incentives are pervese and blurring risk is in many cases the most cost-effective for everyone. If shits hit the fan, they can blame $country or AI (or both). Somewhat related: who would've predicted that ClickFix will become an actual ItW vector that needs to be mitigated?!

    Open ##4070533