Post #718269
2026-03-12 00:42 UTC
Hey more hardcore #infosec people: Do you know of any exploits involving threat actors somehow using Microsoft's Bingbot crawler to crawl/scout targets? I ask because I've been seeing pretty intelligent-seeming vulnerability-probing at nonexistent URLs, and it's coming from IP ranges that are registered to Microsoft, and the ones with hostnames are like msnbot-[ip].search.msn.com
I spent all day thinking I might be under the crosshairs of an APT-type situation, but now I'm starting to suspect that Bingbot is just suddenly doing insane stuff that looks like intelligent penetration testing in logs.
It honestly feels plausible that Microsoft have just fired up some kind of LLM-based vulnerability scanner, and are just ... scanning random sites, for ... reasons?
Replies (1)
-
@capriciousday@mastodon.social 2026-03-12 11:08
@joby clearly evidence of bingbot sentience, it needs to probe websites to hack itself an independent source of compute (to be clear this is a very funny joke not me undergoing AI psychosis)