The Courts

After $380 Million Hack, Clorox Sues Its 'Service Desk' Vendor For Simply Giving Out Passwords (arstechnica.com) 89

An anonymous reader quotes a report from Ars Technica: Hacking is hard. Well, sometimes. Other times, you just call up a company's IT service desk and pretend to be an employee who needs a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset... and it's done. Without even verifying your identity. So you use that information to log in to the target network and discover a more trusted user who works in IT security. You call the IT service desk back, acting like you are now this second person, and you request the same thing: a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset. Again, the desk provides it, no identity verification needed. So you log in to the network with these new credentials and set about planting ransomware or exfiltrating data in the target network, eventually doing an estimated $380 million in damage. Easy, right?

According to The Clorox Company, which makes everything from lip balm to cat litter to charcoal to bleach, this is exactly what happened to it in 2023. But Clorox says that the "debilitating" breach was not its fault. It had outsourced the "service desk" part of its IT security operations to the massive services company Cognizant -- and Clorox says that Cognizant failed to follow even the most basic agreed-upon procedures for running the service desk. In the words of a new Clorox lawsuit, Cognizant's behavior was "all a devastating lie," it "failed to show even scant care," and it was "aware that its employees were not adequately trained."

"Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques," says the lawsuit, using italics to indicate outrage emphasis. "The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox's network, and Cognizant handed the credentials right over. Cognizant is on tape handing over the keys to Clorox's corporate network to the cybercriminal -- no authentication questions asked." [...] The new lawsuit, filed in California state courts, wants Cognizant to cough up millions of dollars to cover the damage Clorox says it suffered after weeks of disruption to its factories and ordering systems. (You can read a brief timeline of the disruption here.)

United States

US Nuclear Weapons Agency 'Among 400 Organizations Breached By Chinese Hackers' (slashdot.org) 26

A cyber-espionage campaign exploiting unpatched Microsoft SharePoint vulnerabilities has breached approximately 400 organizations worldwide, including the US National Nuclear Security Administration, according to Netherlands-based cybersecurity firm Eye Security. The figure represents a four-fold increase from 100 organizations cataloged over the weekend, with researchers calling it likely an undercount since not all attack vectors leave detectable artifacts.

Microsoft identified three Chinese groups -- state-backed Linen Typhoon and Violet Typhoon, plus China-based Storm-2603 -- as exploiting the vulnerabilities in on-premises SharePoint servers to steal authentication credentials and execute malicious code remotely. The campaign began July 7 and was first detected July 18 when Eye Security found unusual activity on a customer's server. Victims include the US Energy Department, Education Department, Florida's Department of Revenue, Rhode Island General Assembly, and European and Middle Eastern governments.
Privacy

Brave Browser Blocks Microsoft Recall By Default (brave.com) 48

The Brave Browser now blocks Microsoft Recall by default for Windows 11+ users, preventing the controversial screenshot-logging feature from capturing any Brave tabs -- regardless of whether users are in private mode. Brave cites persistent privacy concerns and potential abuse scenarios as justification. From a blog post: Microsoft has, to their credit, made several security and privacy-positive changes to Recall in response to concerns. Still, the feature is in preview, and Microsoft plans to roll it out more widely soon. What exactly the feature will look like when it's fully released to all Windows 11 users is still up in the air, but the initial tone-deaf announcement does not inspire confidence.

Given Brave's focus on privacy-maximizing defaults and what is at stake here (your entire browsing history), we have proactively disabled Recall for all Brave tabs. We think it's vital that your browsing activity on Brave does not accidentally end up in a persistent database, which is especially ripe for abuse in highly-privacy-sensitive cases such as intimate partner violence.

Microsoft has said that private browsing windows on browsers will not be saved as snapshots. We've extended that logic to apply to all Brave browser windows. We tell the operating system that every Brave tab is 'private', so Recall never captures it. This is yet another example of how Brave engineers are able to quickly tweak Chromium's privacy functionality to make Brave safer for our users (inexhaustive list here). For more technical details, see the pull request implementing this feature. Brave is the only major Web browser that disables Microsoft Recall by default in all tabs.

Microsoft

Microsoft Poaches Top Google DeepMind Staff in AI Talent War (ft.com) 26

Microsoft has recruited more than 20 AI employees from Google's DeepMind research division, the newest front in a talent war being waged by Silicon Valley's tech giants as they jostle to gain an edge in the nascent technology. From a report: Amar Subramanya, the former head of engineering for Google's Gemini chatbot, is the latest to move to Microsoft from its rival, according to a post on his LinkedIn profile on Tuesday. "The culture here is refreshingly low ego yet bursting with ambition," he wrote, confirming his appointment as corporate vice-president of AI.

Subramanya will join other DeepMind staff including engineering lead Sonal Gupta, software engineer Adam Sadovsky and product manager Tim Frank, according to people familiar with Microsoft's recruiting. The Seattle-based company has persuaded at least 24 staff to join in the past six months, they added.

HP

Mike Lynch's Estate and Business Partner Owe HP $944M, Court Rules (theguardian.com) 37

The estate of Mike Lynch, who died a year ago when his superyacht sank off the coast of Sicily, and his business partner owe Hewlett-Packard more than $944 million, a court has ruled. From a report: The US technology company has been seeking damages of up to $4.55 billion from the estate of the late tycoon, once hailed as the UK's answer to Microsoft founder Bill Gates, over its disastrous takeover of his British software company Autonomy.

Lynch's estate has been estimated to be worth about $674 million and paying its share of the $944 million damages could leave it bankrupt. He and six others, including his 18-year-old daughter Hannah, died last August on a trip celebrating his acquittal on US fraud charges relating to HP's $11 billion takeover of Autonomy in 2011. However, HP won a separate six-year civil fraud case against Lynch and his former finance director Sushovan Hussain in the English high court in 2022, with Mr Justice Hildyard ruling that the US company had been induced into overpaying for the business.

Security

Alaska Airlines Resumes Operations After System Glitch Grounds All Flights (gizmodo.com) 13

Alaska Airlines and Horizon Air grounded all flights Sunday night due to a major IT outage, prompting a system-wide FAA ground stop that lasted until early Monday. Although operations have since resumed, passengers are still facing delays and residual disruptions. Gizmodo reports: The airline requested a system-wide ground stop from federal aviation authorities at about 11 p.m. ET on Sunday night. That stop remained in effect until around 2 a.m. ET Monday, when the Federal Aviation Administration confirmed it had been lifted. But disruptions didn't end there. Alaska warned passengers to brace for likely delays throughout the day. [...] The FAA's website listed the stop as applying to all Alaska Airlines aircraft. Gizmodo notes that the incident comes nearly a year after the massive 2024 CrowdStrike crash, which has become known as the largest IT outage in history. "The July 2024 outage brought down an estimated 8.5 million Microsoft Windows systems running CrowdStrike's Falcon Sensor software, disrupting everything from hospitals and airports to broadcast networks."

"There's no word yet from Alaska on whether the outage ties into a broader software problem, but the timing, almost exactly a year after the CrowdStrike crash, isn't going unnoticed on social media, with users wondering if the events are related."
Cloud

Xbox Cloud Games Will Soon Follow You Across Xbox, PC, and Windows Handhelds (theverge.com) 15

Microsoft is rolling out updates to the Xbox PC app and consoles that sync your cloud gaming history and progress across devices, making it easier to resume cloud-playable titles on PCs, handhelds, and other Xbox hardware. The Verge reports: Cloud-playable games are now starting to show inside play history or the library on the Xbox PC app. "This includes all cloud playable titles, even console exclusives spanning from the original Xbox to Xbox Series X|S, whether you own the title or access it through Game Pass," explains Lily Wang, product manager of Xbox experiences. Your recent games, including cloud ones, will soon follow you across devices -- complete with cloud-powered game saves. So if you played an Xbox game on your console that's not natively available on PC, it will still show up in your recent games list and be playable through Xbox Cloud Gaming on Windows.

Cloud-playable games on the Xbox PC app can be found from a new filter in the library section, and a new "play history" section will appear at the end of the "jump back in" list on the home screen of the Xbox PC app. "While the large tiles highlight games you've recently played on your current device, the play history tile shows games you've played across any Xbox device, making it easy to pick up where you left off," says Wang. This same play history section will appear on the main Xbox console interface, too -- which could mean we'll eventually see PC games listed here and playable through Xbox Cloud Gaming.

Microsoft

Microsoft To Help France Showcase Paris' Notre-Dame Cathedral in Digital Replica (reuters.com) 14

An anonymous reader shares a report: Microsoft is teaming up with the French government to create a digital replica of Paris' Notre-Dame Cathedral, France's most visited monument, the U.S. tech company's president, Brad Smith, said on Monday. The 862-year-old Gothic masterpiece was reopened last December after a five-year restoration following a devastating fire in 2019. A digital replica will serve as a record of the building's architectural details, Microsoft said. It will also provide a virtual experience for visitors and those unable to visit.
Security

Microsoft Releases Emergency Patches for Actively Exploited SharePoint Zero-Days (bleepingcomputer.com) 18

Microsoft has released emergency security updates for two actively exploited zero-day vulnerabilities in SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, that have compromised servers worldwide in what researchers call "ToolShell" attacks. The U.S. Cybersecurity and Infrastructure Security Agency warned over the weekend that hackers were exploiting the vulnerabilities to gain remote code execution on on-premises SharePoint installations, while Microsoft has not yet provided patches for all affected versions.

The vulnerabilities allow hackers to steal private digital keys from SharePoint servers without requiring credentials, enabling them to plant malware and access stored files and data. Eye Security, which first identified the attacks on Saturday, found dozens of actively exploited servers and warned that SharePoint's integration with Outlook, Teams, and OneDrive could enable further network compromise. Researcher Silas Cutler at cybersecurity firm Censys estimated more than 10,000 companies with SharePoint servers were at risk, with the largest concentrations in the United States, Netherlands, United Kingdom, and Canada.

Microsoft released patches for SharePoint 2019 and Subscription Edition but is still working on fixes for SharePoint Server 2016. Administrators must install available updates immediately and rotate machine keys to prevent re-compromise, according to Microsoft's security guidance.
Security

'Tens of Thousands' of SharePoint Servers at Risk. Microsoft Issues No Patch (msn.com) 90

"Anybody who's got a hosted SharePoint server has got a problem," the senior VP of cybersecurity firm CrowdStrike told the Washington Post. "It's a significant vulnerability."

And it's led to a new "global attack on government agencies and businesses" in the last few days, according to the article, "breaching U.S. federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers..."

"Tens of thousands of such servers are at risk, experts said, and Microsoft has issued no patch for the flaw, leaving victims around the world scrambling to respond." (Microsoft says they are "working on" security updates "for supported versions of SharePoint 2019 and SharePoint 2016," offering various mitigation suggestions, and CISA has released their own recommendations.)

From the Washington Post's article Sunday: Microsoft has suggested that users make modifications to SharePoint server programs or simply unplug them from the internet to stanch the breach. Microsoft issued an alert to customers but declined to comment further... "We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available," said Pete Renals, a senior manager with Palo Alto Networks' Unit 42. "We have identified dozens of compromised organizations spanning both commercial and government sectors.''

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted. What's also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched. "So pushing out a patch on Monday or Tuesday doesn't help anybody who's been compromised in the past 72 hours," said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

The breaches occurred after Microsoft fixed a security flaw this month. The attackers realized they could use a similar vulnerability, according to the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency. CISA spokeswoman Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft... The nonprofit Center for Internet Security, which staffs an information-sharing group for state and local governments, notified about 100 organizations that they were vulnerable and potentially compromised, said Randy Rose, the organization's vice president. Those warned included public schools and universities. Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

But there's many more breaches, according to the article:
  • "Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies."
  • "At least two U.S. federal agencies have seen their servers breached, according to researchers."
  • "One state official in the eastern U.S. said the attackers had 'hijacked' a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material..."

"It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is. One private research company found the hackers targeting servers in China..."


Microsoft

Microsoft To Stop Using Engineers In China For Tech Support of US Military (reuters.com) 51

Microsoft will stop using China-based engineers to support U.S. military cloud services after a ProPublica report revealed their involvement, prompting backlash from Senator Tom Cotton and a two-week Pentagon review ordered by Defense Secretary Pete Hegseth. In response, Hegseth announced an immediate ban on any Chinese involvement in Department of Defense cloud contracts. Reuters reports: The report detailed Microsoft's use of Chinese engineers to work on U.S. military cloud computing systems under the supervision of U.S. "digital escorts" hired through subcontractors who have security clearances but often lacked the technical skills to assess whether the work of the Chinese engineers posed a cybersecurity threat. [Microsoft] told ProPublica it disclosed its practices to the U.S. government during an authorization process.

On Friday, Microsoft spokesperson Frank Shaw said on social media website X the company changed how it supports U.S. government customers "in response to concerns raised earlier this week ... to assure that no China-based engineering teams are providing technical assistance" for services used by the Pentagon.

Microsoft

LibreOffice Calls Out Microsoft For Using 'Complex' File Formats To Lock in Office Users (neowin.net) 83

LibreOffice has accused Microsoft of intentionally using "unnecessarily complex" file formats to lock in Office users, claiming the company weaponizes its Office Open XML schema to create barriers for competitors. The open-source office suite argued that Microsoft's OOXML format includes deeply nested structures with non-intuitive naming conventions and numerous optional elements that make implementation difficult for developers outside Microsoft.

LibreOffice compared the situation to a railway system where tracks are public but one company's control system is so convoluted that competitors cannot build compatible trains.
Microsoft

Microsoft Kills Movies and TV Storefront on Windows and Xbox (windowscentral.com) 22

Microsoft has shut down its Movies & TV storefront on the Microsoft Store, ending the ability to purchase new entertainment content on Windows PCs and Xbox consoles. The company announced that as of July 18, users can no longer buy or rent movies and TV shows through Microsoft.com, the Microsoft Store on Windows, or the Microsoft Store on Xbox.

Customers who previously purchased content from the Microsoft Store can continue accessing their libraries through the Movies & TV app, which remains available for download. Microsoft will not offer refunds for recent purchases. US customers can use the Movies Anywhere service to sync their purchased content to other compatible platforms.
Microsoft

'Microsoft's Constant Layoffs Risk Creating a Culture of Fear' (theverge.com) 79

An anonymous reader shares a column: I can't open LinkedIn without seeing a new post from a Microsoft employee who lost their job in the company's latest round of layoffs. Around 15,000 jobs have been eliminated at Microsoft over the past couple months -- the biggest cuts at the company in more than a decade.

I've spoken to more than a dozen Microsoft employees in recent weeks, and everyone is concerned about the company's direction in this AI era. Morale is at an all-time low, and employees are worried that regular layoffs are simply the new normal.

Sources tell me that Microsoft's leadership team had the choice between reducing investment in AI infrastructure for the upcoming financial year or deeply cutting its headcount and operating expenses. It's very clear what route Microsoft chose.

Cloud

OpenAI Says It Will Use Google's Cloud For ChatGPT (cnbc.com) 7

OpenAI has added Google Cloud as a provider for ChatGPT and its API, expanding beyond Microsoft to address growing demand for computing power. CNBC reports: OpenAI has added Google to a list of suppliers, specifying that ChatGPT and its application programming interface will use the Google Cloud Platform, as well as Microsoft, CoreWeave and Oracle. The announcement amounts to a win for Google, whose cloud unit is younger and smaller than Amazon's and Microsoft's. Google also has cloud business with Anthropic, which was established by former OpenAI executives. The Google infrastructure will run in the U.S., Japan, the Netherlands, Norway and the United Kingdom.
Microsoft

Microsoft Uses Chinese Engineers To Maintain Defense Department Systems Under Minimal US Oversight 63

Microsoft employs engineers in China to help maintain Defense Department computer systems, with U.S. citizens serving as "digital escorts" to oversee the foreign workers, according to a ProPublica investigation. The escorts often lack advanced technical expertise to police engineers with far more sophisticated skills, and some are former military personnel paid barely above minimum wage.

"We're trusting that what they're doing isn't malicious, but we really can't tell," one current escort told the publication. The arrangement, critical to Microsoft winning federal cloud computing contracts a decade ago, handles sensitive but unclassified government data including materials that directly support military operations. Former CIA and NSA executive Harry Coker called the system a natural opportunity for spies, saying "If I were an operative, I would look at that as an avenue for extremely valuable access."
Microsoft

Microsoft Has a New Trick To Improve Laptop Battery Life On Windows (theverge.com) 49

Microsoft is testing a new adaptive energy saver mode in Windows 11 that automatically turns energy saver on or off based on system workload instead of battery percentage, aiming to extend laptop battery life without dimming screen brightness. The feature is currently available to Windows Insider testers and expected to roll out later this year. The Verge reports: The energy saver mode in Windows 11 typically dims a display brightness by 30 percent, disables transparency effects, and stop apps running in the background. Non-critical Windows update downloads are also paused, and certain apps like OneDrive, OneNote, and Phone Link may not sync fully while energy saver is enabled. This new adaptive energy saver mode, which will only be available on devices with a battery, will automatically enable or disable without affecting screen brightness. That will make it less noticeable on devices like laptops, tablets, and handhelds.

"Adaptive energy saver is an opt-in feature that automatically enables and disables energy saver, without changing screen brightness, based on the power state of the device and the current system load," explains Microsoft's Windows Insider team.

Nintendo

Nintendo Banned Switch 2 Owner For Playing a Used Switch 1 Game They Bought Online (tomshardware.com) 84

"A Nintendo Switch 2 user reportedly got his brand-new console banned by Nintendo after buying used Switch 1 games and patching them on his console," reports Tom's Hardware: According to Reddit user dmanthey, they purchased four used titles off the Facebook marketplace, inserted them into the Switch 2, and had them all updated. When they turned on their handhelds the following day, they received a message saying that they were restricted from Nintendo's online services and that they couldn't even download the games they had already bought...

[T]hey were able to prove their innocence by pulling up the Facebook Marketplace listing for their games and sending the photos of their purchased cartridges. According to the Redditor, the process was painless and fast, and it was "so much easier than getting support from Microsoft or Sony...." Other users warned, though, that this isn't always a guaranteed resolution.

Nintendo is known for being protective of its intellectual property and delivers harsh penalties to anyone caught violating it. We've already had several reports of users getting banned for using Mig Flash, even on their own ROMs. And while it's not true that getting banned turns your Switch 2 into a brick, it will still prevent you from accessing the company's online services, which severely restricts its features and usability.

"Nintendo attaches unique codes to its Switch game cartridges to prevent piracy," notes Engadget. "However, bad actors can copy games onto a third-party device, like the MIG Flash, and then resell the physical game card. Once Nintendo detects two instances of its unique code being online at the same time, it will ban any accounts using it..." This anti-piracy policy isn't new — Nintendo has long had a reputation for fiercely combating any type of piracy — but it has become relevant again thanks to the recently released Switch 2, which offers backwards compatibility with original Switch titles. The company even recently amended its user agreement to allow itself the power to brick a Nintendo Switch that's caught running pirated games or mods.
Microsoft

Microsoft Outlook Malfunctioned For Over 21 Hours Wednesday and Thursday (apnews.com) 19

"Microsoft's Outlook email service malfunctioned for over 21 hours Wednesday and Thursday," reports CNBC, "prompting some people to post on social media about the inability to reach their virtual mailboxes." The issue began at 6:20 p.m. Eastern time on Wednesday, according to a dashboard the software company maintains. It affected Outlook.com as well as Outlook mobile apps and desktop programs. At 12:21 ET on Thursday, the Microsoft 365 Status account posted that it was rolling out a fix.
Although earlier on Thursday Microsoft posted on X that "We identified an issue with the initial fix, and we've corrected it..."

More details from the Associated Press: Disruptions appeared to peak just before noon ET on Thursday, when more than 2,700 users worldwide reported issues with Outlook, formerly also Hotmail, to outage tracker Downdetector. Some said they encountered problems like loading their inboxes or signing in. By later in the afternoon, reports had fallen to just over a couple hundred...

Microsoft did not immediately provide more information about what had caused the hourslong outage. A spokesperson for Microsoft had no further comment when reached by The Associated Press on Thursday.

Businesses

HMD 'Scaling Back' in the US, Killing Nokia All Over Again (theverge.com) 13

An anonymous reader shares a report: HMD Global, the company best known for licensing the Nokia brand for new phones and tablets over the last decade, has announced that it will "scale back" its US operations, and appears to have stopped selling both HMD and Nokia devices entirely.

[...] Based in Finland, HMD was formed in 2016 in order to purchase the Nokia feature phone business from Microsoft, which had in turn bought the ailing brand in 2014. It also secured a license to use the Nokia name on smartphones and tablets, with a focus on affordable and midrange hardware.

Slashdot Top Deals