frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

How to report suspected Microsoft service compromise?

1•dboreham•5h ago
Investigating a report from someone in the office today I found their browser displaying one of those full screen "Your computer has been hacked, call this phone number" pages. Not too surprising: I clicked the exit full screen button. But when I looked at the URL it appeared to be a legit Microsoft host name (and had obviously evaded the browser blacklisting filter). After some digging in the DNS and traceroute to the host I still can't exclude the possibility that an MS service has been compromised. It had a valid cert issued by MS Azure CA.

Question is what should someone do with this information? I'm 99.9% sure if I fill out Microsoft's "report hacking" form nobody will read it. otoh a compromised MS service seems like a thing I should try to report to someone. Perhaps I'm confused somehow about the evidence and it's running on a throwaway VPS with a unicode character in the DNS zone. Doesn't seem so however.

On the theory that the attacker hasn't actually compromised the MS DNS, I suspect that they've figured out a way to get an auto-generated DNS A record that points to an Azure-hosted VM from which they deliver the payload. They're also somehow able to use a cert with CN: *.web.core.windows.net but should that be valid also for foo.z13.web.code.windows.net? Apparently yes. TIL

I did find this site, with a report of a very similar URL: https://urlquery.net/ . When I submitted mine it ran a check, displayed the same malware screen I had seen, but declared the site to be problem free.

For obvious reasons I don't want to post the URL but you can construct it from this hostname: errorzxx9120x6er in this zone: z13.web.core.windows.net

The zones all the way down to z13 seem to be owned by MS, as is the netblock where the server resides.

Comments

pvg•5h ago
https://www.reddit.com/r/sysadmin/comments/1b0m7nj/legit_win...

Looks like it's Azure stuff, not an actual compromise of Microsoft services.

dboreham•4h ago
Oh wow thanks. That's unbelievably stupid on MS part. I thought it was a general rule you never allow customer content to be served on any branded DNS zone (since inevitably it'll be a cesspit of malware). But wait...why the doesn't Google blacklist .windows.net like they would if I ran a customer hosting service under .mycompany.com ?
stop50•5h ago
It was Microsofts dumb idea to use the windows.net domain for azure stuff.

The Fordow Enrichment Plant, a.k.a. Al Ghadir (2019)

https://isis-online.org/isis-reports/detail/the-fordow-enrichment-plant-aka-al-ghadir/
1•pinewurst•17s ago•0 comments

How to negotiate your salary package

https://www.complexsystemspodcast.com/episodes/how-to-negotiate-your-salary-package/
1•surprisetalk•2m ago•0 comments

When Humans Learned to Live Everywhere

https://www.nytimes.com/2025/06/18/science/ancient-human-adaptation-environments.html
1•pepys•5m ago•0 comments

Ask HN: Has Google Weather forecasting changed?

1•windyshrimp•11m ago•0 comments

Address bar shows hp.com. Browser displays scammers' malicious text anyway

https://arstechnica.com/security/2025/06/tech-support-scammers-inject-malicious-phone-numbers-into-big-name-websites/
2•LorenDB•11m ago•0 comments

Amazon Orders Employees to Relocate to Seattle and Other Hubs

https://www.bloomberg.com/news/articles/2025-06-18/amazon-orders-employees-to-relocate-to-seattle-and-other-hubs
2•petethomas•12m ago•0 comments

GEO Is the new SEO

https://driftspear.com/blog/what-is-geo
1•woktalk•13m ago•0 comments

Pushing the Envelope: The Effects of Salary Negotiation

https://www.hks.harvard.edu/centers/mrcbg/programs/growthpolicy/pushing-envelope-effects-salary-negotiation
1•zuhayeer•15m ago•0 comments

A deep-dive explainer on Ink and Switch's BeeKEM protocol

https://meri.garden/a-deep-dive-explainer-on-beekem-protocol/
2•erlend_sh•16m ago•0 comments

NIST and Partners Use Quantum Mechanics to Make a Factory for Random Numbers

https://www.icfo.eu/news/2521/nist-and-partners-use-quantum-mechanics-to-make-a-factory-for-random-numbers/
1•libpcap•20m ago•0 comments

Become More Social as an Engineer – By Gregor Ojstersek

https://newsletter.eng-leadership.com/p/become-more-social-as-an-engineer
1•rbanffy•25m ago•0 comments

Update to GitHub Copilot consumptive billing experience

https://github.blog/changelog/2025-06-18-update-to-github-copilot-consumptive-billing-experience/
1•denysvitali•26m ago•0 comments

Remote MCP Support in Claude Code

https://www.anthropic.com/news/claude-code-remote-mcp?campaignId=13929719&source=i_email&medium=email&content=Oct2024AnalysisTool&messageTypeId=140367
2•handfuloflight•27m ago•0 comments

Accelerating Collaboration with AI, chat => personal knowledge => train

https://www.loom.com/share/0d19f01ec0b24f23b81ea3a8a51469c8?sid=aab77205-4c63-4180-a9c6-dcb2489ac2b4
1•IXCoach•27m ago•1 comments

Core Components of a Profitable AI Billing System

https://www.getlago.com/blog/ai-billing-infrastructure
1•AnhTho_FR•28m ago•0 comments

The Missing 11th of the Month

https://drhagen.com/blog/the-missing-11th-of-the-month/
2•xk3•33m ago•0 comments

Microsoft planning thousands more job cuts aimed at salespeople

https://www.seattletimes.com/business/microsoft/microsoft-planning-thousands-more-job-cuts-aimed-at-salespeople/
2•petethomas•39m ago•1 comments

The Python Language Summit 2025: State of Free-Threaded Python

https://pyfound.blogspot.com/2025/06/python-language-summit-2025-state-of-free-threaded-python.html
1•rbanffy•40m ago•0 comments

A Python dict that can report which keys you did not use

https://www.peterbe.com/plog/a-python-dict-that-can-report-which-keys-you-did-not-use
2•rbanffy•41m ago•0 comments

Understanding and managing requests in Copilot

https://docs.github.com/en/copilot/managing-copilot/understanding-and-managing-copilot-usage/understanding-and-managing-requests-in-copilot
2•benbristow•41m ago•0 comments

The Impossible Man: Roger Penrose and the Cost of Genius

https://www.lrb.co.uk/the-paper/v47/n11/steven-shapin/through-the-trapdoor
1•mitchbob•41m ago•1 comments

Preview app adds Dark Mode toggle for PDFs on macOS Tahoe, iOS and iPadOS 26

https://blog.sangeeth.dev/notes/preview-app-adds-dark-mode-toggle-for-pdfs-on-macos-tahoe-ios-and-ipados-26/
2•sangeeth96•44m ago•0 comments

Use this free tool if you are not able to be productive

https://chromewebstore.google.com/detail/todays-task/ghmmlbbhellogdiejchbppddlfmfdepj
1•ngninja•45m ago•0 comments

Lego improves maths and spatial ability in the classroom

https://www.surrey.ac.uk/news/lego-improves-maths-and-spatial-ability-classroom
1•giuliomagnifico•45m ago•0 comments

Claude Code can use AST-grep to improve search efficiency and accuracy

https://twitter.com/OnlyXuanwo/status/1935291824106795450
1•handfuloflight•46m ago•0 comments

Show HN: universal application where LLM does all computation directly

https://universal.oroborus.org/
1•snickell•47m ago•0 comments

OpenDeepWiki – the open-source multi-repo AI chat Copilot wishes it were

https://github.com/Flopsky/OpenDeepWiki
1•flopsy2•48m ago•1 comments

Addictive Screen Use Trajectories and Suicidal Behaviors in US Youths

https://jamanetwork.com/journals/jama/fullarticle/2835481
1•cmsefton•48m ago•0 comments

Chord: Multiplayer LLM Chats

https://www.chord.chat/hn
1•handfuloflight•49m ago•0 comments

Ancestra says a lot about the current state of AI-generated videos

https://www.theverge.com/ai-artificial-intelligence/688448/ancestra-primordial-soup-google-deepmind
1•ajuhasz•49m ago•0 comments