Bonum Certa Men Certa

Unwarranted Media Hysteria Over (Allegedly) China Almost Sneaking Compromised xz Into Stable, Production Operating Systems (It Failed) While the US Government Blames Microsoft for Allowing China to Break Into Vital Government Systems Via Windows

posted by Roy Schestowitz on Apr 03, 2024

Shifting attention much, Microsoft-funded media? Microsoft: my dog ate my homework. So what if our whole internal infrastructure and all of Azure got compromised? "LOOK OVA' THAR!"

Beautiful white and brown dog lying under the table

THIS morning we wrote about how nearly 2 decades ago rms (Richard Stallman), who had given public talks about GNU since the mid-80s, warned that proprietary operating systems like Windows were a "back door" threat and, to make matters worse, you would not even know, no matter if that got detected or not (this already happened to Microsoft) [1, 2].

The "mainstream" (corporate, advertisers-funded and typically oligarch-owned) media won't mention any of this and instead it has helped distract from severe Microsoft Exchange issues. There is now a follow-up (see [1-4] below), but the media is shifting attention to "Linux" and it blames "Open Source" because some random user on Microsoft's GitHub (proprietary) pulled off a social engineering attack, aided by Microsoft systemd (also GitHub) and made "famous" by a Microsoft employee.

"Not only is there the 17k Microsoft Exchange server problem," an associate notes this morning, "but there is also the recent report excoriating Microsoft over its mishandling of the China-origin breach of its infrastructure."

See the links below.

"Allegedly" in the title of this post is because (while China is confirmed for the Microsoft breach) we don't even know what happened to xz. GitHub (Microsoft) makes it harder by hiding the evidence. The issue here or the culprit remains unattributed, an associate has said. "Red China is as likely as Israel, Russia, Netherlands, or US."

"However, in the other break-in [Microsoft], it is directly attributable to Red China."

Funnily enough, the corruptible media portrays the source of the FUD, Microsoft, as the saviour here. As if a campaign of misinformation or strategically-timed drama is something to be commended/praised for.

We're collectively paying the price for having very bad media/press. Media standards in the West have fallen closer to Red China's levels.

  1. Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack

    In a scathing indictment of Microsoft corporate security and transparency, a Biden administration-appointed review board issued a report Tuesday saying “a cascade of errors” by the tech giant let state-backed Chinese cyber operators break into email accounts of senior U.S. officials including Commerce Secretary Gina Raimondo.

    The Cyber Safety Review Board, created in 2021 by executive order, describes shoddy cybersecurity practices, a lax corporate culture and a lack of sincerity about the company's knowledge of the targeted breach, which affected multiple U.S. agencies that deal with China.

  2. Cyber review board blames cascading Microsoft failures for Chinese hack

    The CSRB lays the blame for the incident squarely on Microsoft: “The Board concludes that this intrusion should never have happened. Storm-0558 was able to succeed because of a cascade of security failures at Microsoft.”

    The report represents the conclusion of a seven-month review and comes against the backdrop of growing concern in Washington that a series of severe breaches at Microsoft has made the company a national-security liability at a time when the federal government is increasingly relying on that company for a raft of cloud computing services. In January, Microsoft disclosed the latest such incident, in which Russian hackers were able to access emails belonging to senior company officials and company source code.

  3. Microsoft slammed for lax infosec that led to Exchange crack

    A review of the June 2023 attack on Microsoft's Exchange Online hosted email service – which saw accounts used by senior US officials compromised by a China-linked group called "Storm-0558" – has found that the incident would have been preventable save for Microsoft's lax infosec culture and sub-par cloud security precautions.

    The review, conducted by the US government's Cybersecurity and Infrastructure Security Agency's Cyber Safety Review Board (CSRB), calls for "rapid cultural change" at Microsoft. Among the Board's recommendations: [...]

  4. Review of the Summer 2023 Microsoft Exchange Online Intrusion [PDF]

    In May and June 2023, a threat actor compromised the Microsoft Exchange Online mailboxes of 22 organizations and over 500 individuals around the world. The actor—known as Storm-0558 and assessed to be affiliated with the People’s Republic of China in pursuit of espionage objectives—accessed the accounts using authentication tokens that were signed by a key Microsoft had created in 2016. This intrusion compromised senior United States government representatives working on national security matters, including the email accounts of Commerce Secretary Gina Raimondo, United States Ambassador to the People’s Republic of China R. Nicholas Burns, and Congressman Don Bacon.

    Signing keys, used for secure authentication into remote systems, are the cryptographic equivalent of crown jewels for any cloud service provider. As occurred in the course of this incident, an adversary in possession of a valid signing key can grant itself permission to access any information or systems within that key’s domain. A single key’s reach can be enormous, and in this case the stolen key had extraordinary power. In fact, when combined with another flaw in Microsoft’s authentication system, the key permitted Storm-0558 to gain full access to essentially any Exchange Online account anywhere in the world. As of the date of this report, Microsoft does not know how or when Storm-0558 obtained the signing key.

    This was not the first intrusion perpetrated by Storm-0558, nor is it the first time Storm-0558 displayed interest in compromising cloud providers or stealing authentication keys. Industry links Storm-0558 to the 2009 Operation Aurora campaign that targeted over two dozen companies, including Google, and the 2011 RSA SecurID incident, in which the actor stole secret keys used to generate authentication codes for SecurID tokens, which were used by tens of millions of users at that time. Indeed, security researchers have tracked Storm-0558’s activities for over 20 years.

Other Recent Techrights' Posts

SLAPP Censorship - Part 136 Out of 200: Lawyers That Get Paid to Mess About
They were already outnumbered and understaffed
 
The Cyber Show on the Slop Bubble
new article about the implosion of the slop bubble
Links 01/08/2026: New York Times Trying to Inflate the Slop Pyramid Scheme (at Cost to Its Own Reputation) and "Iran Appears to Be Blasting Amazon Data Centers Off the Map"
Links for the day
Positive Political Momentum
Daniel Pocock is taken seriously by many people who contact us privately
Google "AI" is Plagiarism, the Case of Richard Stallman (RMS)
Why would anyone choose LLM slop over the originals, curated and fact-checked by domain experts?
Explaining That Software Patents Are Neither Legal Nor Desirable
Many of our readers work in the legal sector
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 31, 2026
IRC logs for Friday, July 31, 2026
Gemini Links 01/08/2026: Retirement, Bike Trips, Quake Stuff, Usenet Reborn
Links for the day
Links 31/07/2026: Microsoft Now Says Slop is Bad (LinkedIn Cracks Down on It), LinkedIn Narrows Down Size (No Expansion)
Links for the day
European Patent Office (EPO) Series: From Alicante to Munich: Another Smooth Ride
Campinos is intent on transforming what was originally envisaged as a temporary public office into his own permanent personal feather-bed
Daniel Pocock and the Important Observation About Threats of Cult-Like Behaviours (No Rationality, No Reason, Just "Mob Rule")
It's a threat to Europe's sovereignty
The "PIP Parade" of IBM's Lousy Management, Which Said "Blockchain" Was the Future
In a healthy company such a CEO would be punished for utterly wrong visions and predictions. Not at IBM...
SLAPP Censorship - Part 135 Out of 200: Limited Liability Partnership (LLP) That Does Not Disclose Financial Activities Before August
It certainly looks like they keep losing the remaining women that still exist in the firm
Links 31/07/2026: "Climate Cover-Up Continues" and Pesticides "Cook the Planet"
Links for the day
Datacentre 'Boom' Sceptics Aren't Luddites, They Recognise a Threat to Human Survival (Not Limited to Climate Change)
Archaeologists very well know that no species will survive forever
Microsoft's Claims Are Based on a Big Lie
the bubble is coming to its hard limits
Don't Lose Sight of the Impact of "End of 10" (Vista 10)
GNU/Linux has taken off fast
Microsoft's Debt Continues to Steadily Increase, Not Counting Hundreds of Billions in Secret/Hidden Debt
The mass layoffs will carry on, maybe labelled LITE
IBM is Circling Down the Drain, the 'Growth' Comes From Beancounting Tricks and Salary Cuts
IBM was down 2.17% yesterday
Microsoft's "Headcount" Distracts From How Big a Cull It Had This Month
It also speaks of numbers "[a]s of June 30" though the "buyouts" were effective July 1 and since then well over 10,000 workers have vanished
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 30, 2026
IRC logs for Thursday, July 30, 2026
Gemini Links 31/07/2026: Music, Journaling, and Longing
Links for the day
More Fake News From (and for) IBM, Nobody Ever Held Accountable for Fraud
Companies that turn a blind eye to their own corruption end up recruiting more corrupt people and sacking those who object to the corruption
Links 30/07/2026: Smol Document Server and More PalmOS-ing
Links for the day
Links 30/07/2026: Microsoft Refuting Its Own Slop Hype and "Amazon Is Gutting Its Hey Hi (AI) Division" (GAFAM Bubble)
Links for the day
Today The Register MS Published "AI" Spam and Fake Article by "Senior Technical Marketing Engineer"
unethical practices
Cult inquiry parliament leak fallout
Reprinted with permission from Daniel Pocock
Techrights Will Always Protect Sources
Our #1 priority is sources
European Patent Office (EPO) Series: Legal Concerns and Suspicions of Irregularities
complaints submitted to OLAF
The Era of Silence
So stay silent, remain hidden
GAFAM and IBM Dying in Massive Debt, Hence the Mass Layoffs (Increasingly Silent Layoffs That the Media Fails to Mention)
the integrity of this economy is only as good as its leaders or those who govern the market
TheLayoff.com Deletes Comment That Called IBM's Previous CEO, Ginni Rometty, "Gin 'n Tonic"
It is hard to believe the comment was deleted for being a duplicate (in another thread)
The Mainstream Media Continues to Overlook or Intentionally Ignore Hundreds of Billions in Hidden/Secret Microsoft Debt
the issue is that Microsoft's crisis is a lot greater and broader than this
SLAPP Censorship - Part 134 Out of 200: What "Majority Rules" Tell Us About the Litigant
we press on with this series
Overshoot Day Sites That Contribute to the Problem
Some of these are not even accessible (at all) without JavaScript
Microsoft May Have Gotten Rid of 8% of Its Workforce This Month
It's hard to know what's really going on because there's no transparency due to NDAs
Links 30/07/2026: "Age of Irrationality", Google Losing Money, and "House of Ellison is on the Brink"
Links for the day
Gemini Links 30/07/2026: Homeworlds Notes and Manuscript Submitted
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, July 29, 2026
IRC logs for Wednesday, July 29, 2026