#Microsoft walks back its threat to pursue those who don't disclose responsibly as criminals. They don't apologize, but merely "clarify" their position in a post on X.com today. Since their statement doesn't seem to be on their blog, I am linking to x.com:
This is the type of threat to researchers that @zackwhittaker and I had been looking at in our survey on threats to journalists and researchers. It was impressive to see all of the experts like @GossiTheDog speaking up to slam Microsoft for their blog post of May 27.
Confronted with overwhelming criticism by the security community, Microsoft stepped back.
I seem to be making even more enemies than usual for my refusal to simply parrot or repeat what is being claimed by experts who aren't willing to back up their assertions or claims with any actual data, when asked.
I hope even more journalists do what we are supposed to do -- dig in, investigate, and report, noting critical gaps in evidence when experts aren't citing evidence in making claims.
We do not have a well-informed public when journalists just repeat what experts say. They may give us good quotes or "exclusives," about criminal gangs or cybercrime, but where is the data to support their claims?
Smearing me -- or trying to -- because I keep asking for evidence is its own attempt at censoring a free press.
Someone commented on my Instructure post with a comment as "Sysadmin." They wrote:
"Are you effin kidding me! We got an Email from Instructure saying we were impacted and now we have to inform all the students and families in our district.
Why do these ShinyHunters keep attacking the edtech sector?? PowerSchool, infinite campus and now this.
It’s only a Sunday night and law enforcement has still done nothing about these hackers. Regulators really need to hold these companies accountable for poor security practices."
NEW: My post on the student/k-12 tips exposed in "BlueLeaks 2.0" is now up.
P3 Campus and its partner programs like Safe2Say Something PA, Safe2Tell, and Sandy Hook Promise were supposed to provide secure and anonymous ability to report tips.
Promises of security and anonymity do not appear to have been kept. A hacker claims it was easy to gain access and repeatedly access the database to acquire more than 8 million tips.
There is not much anonymous about what I reviewed in the dataset.
Many of the school-related tips I reviewed reported concerns over named students with suicidal ideation or cutting, students being bullied or bullying others, and drugs (mostly vaping) in school. Some students reported cybercriminal activity.
Navigate360, the parent company of P3, still hasn't publicly acknowledged that it was breached and that sensitive information was involved. Their lack of transparency was noted by @douglevin
My focus in this post was on the student/school -related tips, but the 93.51 GB dataset has millions of tips that include adult issues and crimes, including drugs, homicide, assaults, etc. I provide one or two examples from the non-student tips to illustrate how sensitive the tips are in this dataset.
This may be the worst breach I've ever seen involving sensitive student information, and I've seen many student-related data breaches over the past two decades.
When I get mad at #USPol stuff, I try to remind myself of all the good people in this country.
A woman who is a dog-sitter mentioned to her clients that she was collecting donations for the local shelter. Within days, here's what her living room looked like.
Alleged Scattered Spider members Thalha Jubair and Owen Flowers who are both charged with the TransportForLondon cyberattack, pleaded not guilty in Southwark Crown Court in London today. The judge has set a trial date of June 8, 2026 for them, and they continue to be detained on remand.
Flowers is also charged with conspiring to damage the network of SSM Health Care Corporation and attempting to do the same to Sutter Health, both U.S. healthcare entities. He pleaded not guilty to those charges, too.
Jubair also faces an additional charge of not providing his password to investigators when they seized his devices.
Remember that frustrating situation where some of us couldn't get a vendor to respond to notifications that court-sealed records and sensitive files were exposed? One entity eventually reached the vendor by phone and was so angry at their response that they wound up canceling their account with them.
Yesterday, I finally reached the second court entity. They, too, wound up telling the vendor to take the share down.
How many other clients may still have exposed data because the vendor tells clients that everything's fine when it isn't? I don't know. If you know any entity using Software Unlimited Corp software (not Software Unlimited Inc, but Software Unlimited CORP), you may want to point them to my coverage:
It's #Halloween, so it's time for my annual tradition of posting the picture of my front porch after my daughter surprised me by decorating it for me while I was away.
I don't usually ask for boosts, but if you are in a position to help spread the word about this vendor and that its clients need to check their security, that would be great.
Two teens have been arrested by Dutch authorities on espionage-related charges. They were allegedly recruited --and paid -- by pro-Russian hackers on Telegram to carry a wi-fi sniffer near areas that included embassies near the Hague, Europol, and Eurojust.
As part of their coverage of the story, the NL Times reports:
The father (of one of the boys) said his son is a diligent student, plays hockey, and works part-time in a supermarket. “He doesn’t go out, and shows no inclination to explore the world. We raise our children to handle everyday risks, but nothing like this. Who could have anticipated it?”
NEW: When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on
Others seem to have interpreted their "goodbye" message differently than I had. Were they lying or did people just not understand a significant statement in their message?
And while headlines focus on them hitting a bank, I think we need to take a closer look at their attacks on the aviation sector.
@GossiTheDog Was he ever in a juvie facility or did they just send him home each time because he was a minor?
IntelBroker got into a diversion program at one point. It didn't stick, obviously, but do you know if either of these teens was ever in any kind of diversion program or getting any supervision?
Blogger/journalist at databreaches.net and pogowasright.org. As a retired healthcare professional, breaches in the healthcare sector are my priority.The header pic is Indy, a Siberian husky we rescued in 2016 after I read how nobody wanted her because she was so difficult. She is now living her best life and is a mushball with me.