RSS Amplifier

Pithy Security | InfoSec Made Simple · Jul 25, 2025

Microsoft Security Debacle 🔥 | Clorox Sues IT Staff 💸 | UK Ransomware Ban 🚫

0
Sign in to vote or save

MrComputerScience · Pithy Security | InfoSec Made Simple

You don't need to be paranoid.

But you do need to be intentional.

Your inbox is a warzone. Phishing isn't a maybe, it's a when.

Treat every unexpected email as if it were a loaded trap.

Because one click can rewrite your whole story.

#Security #Privacy #Phishing

Welcome to the July 25, 2025, issue of Pithy Security. Here are this week's three most significant cybersecurity developments.

Microsoft knew of a critical SharePoint security flaw but failed to address it promptly. Their slow response allowed hackers to breach 400 organizations and counting. Internal timelines indicate that the tech giant was aware of the vulnerability yet was unable to prevent (allegedly) China-backed attackers from exploiting it across corporate networks worldwide.

Key Insights:

The breach exposes an uncomfortable truth about enterprise software. Companies trust Microsoft with their most sensitive data, assuming the software giant has bulletproof security practices. However, this incident highlights that knowing about a problem and solving it are two distinctly different things, especially when dealing with sophisticated (potentially nation-state) hackers who adapt faster than patches launch.

Why This Matters For You:

This security breach could mark a turning point for corporate accountability in cybersecurity. Expect more high-profile clients to demand transparency about known vulnerabilities and faster response times from their software providers. Microsoft's reputation for enterprise security just took a significant hit, and competitors are likely already pitching "more secure alternatives" to concerned IT departments.

Read More on CNBC.

* While the precise identity of the attackers remains undetermined, both Microsoft and Google have attributed the SharePoint intrusions to China-linked hacking groups, according to Reuters and other reports. Beijing has denied these accusations.

Here's a shocking number for your coffee break. In August of 2023, a cyberattack cost Clorox $380 million, all because hackers asked the IT help desk for passwords and got them. The hacking group behind it, called Scattered Spider, didn't deploy fancy code or tech wizardry. They just picked up the phone and, more than once, convinced the Clorox IT staff (provided by Cognizant) to hand over credentials, according to a new lawsuit.

Key Insights:

The lawsuit includes transcripts showing conversations where hackers say, "I don't have a password, so I can't connect," and support staff cheerfully replying, "Oh, OK. So let me provide the password to you, OK?" Cognizant defended itself and pushed back against these claims, arguing that it was only offering basic help desk services, not cybersecurity.

Why This Matters For You:

This case could fundamentally change how companies structure their IT outsourcing contracts. Expect stricter liability terms, mandatory verification protocols, and much higher costs as vendors price in cybersecurity risks. The days of cheap, cheerful help desk support may be coming to an end quickly.

Read More on Reuters.

The UK government is proposing to make paying ransomware demands illegal for public organizations and critical infrastructure. No more quiet Bitcoin transfers to unlock hospital systems or power grids. Instead of negotiating with cybercriminals, British agencies will have to rely purely on backups, security teams, and sheer determination to recover from attacks.

Key Insights:

This bold move upends the traditional ransomware business model. Criminals have thrived because victims often find it cheaper and faster to pay up than rebuild their systems from scratch. But if primary targets can't legally pay, hackers may lose their most significant revenue stream. This policy could either squash ransomware operations or drive them toward more destructive attacks aimed at causing maximum chaos.

Why This Matters For You:

Other countries are watching closely to see if Britain's gamble pays off. If ransomware attacks decrease without resulting in catastrophic system failures, expect similar bans to roll out worldwide. If critical services collapse under pressure, the experiment could backfire spectacularly and discourage other nations from following suit.

Read More on Bleeping Computer.

In 1998, seven hackers walked into Congress in black T-shirts. They didn't give real names. Only handles. Known collectively as L0pht Heavy Industries, they told lawmakers they could shut down the internet in 30 minutes. Most in the room chuckled. But the hackers weren't joking. Nor were they bluffing.

L0pht wasn't a crew of vandals. It was a hacker think tank. From a loft in Boston, they reverse-engineered software, exposed flaws in Windows, and created early disclosure protocols. That day in D.C. marked a turning point. The U.S. government had to reckon with a new kind of whistleblower who understood the systems better than their creators.

Some L0pht members went on to shape cybersecurity policy, launch startups, and develop tools still in use today. However, their legacy is even greater. They proved that hackers weren't just a threat. They were the alarm system that no one else knew they needed.

These are my go-to privacy + security tools. Some links are affiliate links. (They support this newsletter at no extra cost to you!)

  • Proton Mail - One of the more private and secure email services. Basic accounts are free.

  • Proton VPN – Keep your internet, browsing history, and connection secure with servers in over 120 countries.

  • Proton Pass - Protect passwords with an elite encrypted password manager. Supports 2FA codes, device sync, multiple vaults, notes, and more.

  • Proton Drive - Store your data safely. Get 5GB for free and enjoy peace of mind, knowing your files are safe.

Please read my two newsletters:

# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.

# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security so you can spot scams and stay safe without needing to become an expert.

Follow for extra insights:

Bluesky | X (Twitter) | LinkedIn | YouTube

PS: Do you have questions? Reply to this email!

Thanks for reading. More cutting-edge cybersecurity insights coming soon.

You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Read the original on pithysecurity.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.