#

microsoft

(7 articles)

Leaks, database leaks from 07/17/2026 15:02

| Database Name | Data | Tags | |---|---|---| | ⊞ Microsoft Employee Database 2024 (Worldwide). | The database includes FirstName, LastName, JobTitle, Email, Phone, Employees, Industry, Linkedin URL, Website, City, Country.<br>👉 More details: https://t.me/simpledb 👈 | #сотрудник,#контакты,#microsoft | | ✅ Database of b2b platform APOLLO #1 (WORLDWIDE) 2024. | The database includes Name, Title, Functions, Phone, Email, Linkedin_url, Organization, City, Country, Address, Geolocation.<br>👉 More details: https://t.me/simpledb 👈 | #apollo,#контакты,#email | | 👥 Database of the service PEOPLEDATALABS #11 (WORLDWIDE) 2024. | The database includes First Name, Last Name, Phone, Email, Address, Linkedin link.<br>👉 More details: https://t.me/simpledb 👈 | #база,#контакты,#email | | 🚗 Customer base of the Asian food delivery platform SAYWEEE #2 (USA) 2023. | The database includes Phone, Email, FullName, Country, Address, Registration date.<br>👉 More details: https://t.me/simpledb 👈 | #доставка,#платформа,#продукты | | 👥 Consumer Database (USA, Alaska) 2024. | The database includes EMail, Fname, Lname, Address, City, State, Zip, Phone, Gender, DOB.<br>👉 More details: https://t.me/simpledb 👈 | #потребитель,#leads,#сша | More details: https://t.me/simpledb

El gusano Miasma afecta a 73 repositorios de Microsoft GitHub en un importante ataque a la cadena de suministro

**Autor:** Ravie Lakshmanan | **Fecha:** 6 de junio de 2026 Los repositorios de GitHub de Microsoft se han convertido en las últimas víctimas de la continua campaña de ataques a la cadena de suministro protagonizada por el gusano autorreplicante Miasma. El incidente afectó a 73 repositorios de Microsoft distribuidos en cuatro de sus organizaciones de GitHub (Azure, Azure-Samples, Microsoft y MicrosoftDocs), lo que obligó a GitHub a deshabilitar el acceso a dichos repositorios para contener la amenaza. El ataque aprovechó credenciales previamente comprometidas. El mes pasado, el grupo de amenazas TeamPCP infectó el paquete de PyPI "*durabletask*", alojado en la organización Azure de Microsoft, para distribuir un software de robo de información. El investigador de seguridad Paul McCarty señaló que este mismo repositorio se encuentra en el centro de la retirada de este mes. *"Cuando el repositorio en la raíz del compromiso del mes pasado es el epicentro de la retirada de este mes, no es una coincidencia, es la misma herida que se reabre"*, afirmó McCarty. *"Quienquiera que tuviera esas credenciales en mayo, plausible y definitivamente nunca las perdió por completo"*. Lo que hace que esta campaña sea particularmente peligrosa es la forma en que detona la carga útil. El atacante insertó un ejecutor de carga útil de 4,3 MB configurado para ejecutarse automáticamente a través de cinco herramientas de desarrollo: Claude Code, Gemini CLI, Cursor, VS Code y el script de prueba de npm. Un desarrollador solo necesita clonar un repositorio afectado y abrirlo en un agente de codificación con inteligencia artificial para que el malware se ejecute. Una vez activado, el gusano, basado en Bun, recolecta credenciales para AWS, Azure, GCP, Kubernetes, npm y GitHub. Posteriormente, utiliza estos tokens robados para inyectarse en cualquier repositorio al que la víctima tenga permisos de escritura, propagándose de manera autónoma a través del ecosistema. Entre los repositorios deshabilitados se encuentran proyectos críticos de infraestructura de Azure, como *azure-search-openai-demo*, *durabletask* (y sus implementaciones en .NET, Go, JS y MSSQL), *functions-container-action*, *llm-fine-tuning* y *windows-driver-docs*. Según OpenSourceMalware, GitHub logró contener el ataque en solo 105 segundos, aunque el alcance de los usuarios posteriores afectados sigue sin estar claro. Miasma es una variante del gusano Mini Shai-Hulud que TeamPCP publicó a mediados de mayo de 2026. El Shai-Hulud original apareció en septiembre de 2025 como el primer malware autorreplicante observado en el ecosistema npm. Desde entonces, ha mutado a través de npm y PyPI, comprometiendo previamente 32 paquetes de Red Hat y afectando a paquetes de TanStack, Mistral AI y UiPath. El gusano también ha comenzado a omitir por completo el registro de npm. La empresa SafeDep descubrió que estaba insertando código malicioso directamente en los repositorios de origen. A la fecha de esta publicación, más de 80 repositorios públicos en GitHub presentan el patrón de nomenclatura de la campaña Miasma. El problema fundamental no es una vulnerabilidad en npm o GitHub. *"Explota el modelo de confianza en el que se construyen esas plataformas"*, señaló la firma de seguridad FalconFeeds.io en su análisis. *"La suposición de que si un paquete está firmado con una clave válida y publicado por un mantenedor autenticado, es seguro"*. El gusano compromete la clave y al mantenedor, y luego actúa exactamente como un publicador legítimo. Desde la perspectiva del registro, cada evento de publicación maliciosa parece una actualización rutinaria. La orientación hacia los agentes de codificación con inteligencia artificial representa una evolución notable. Los desarrolladores dependen cada vez más de herramientas como Claude Code y Cursor para trabajar con repositorios desconocidos. Un gusano que se activa cuando un agente de IA abre un proyecto explota un nuevo patrón de comportamiento que no existía hace un año. Se trata, en definitiva, de un malware de cadena de suministro diseñado para la era del desarrollo asistido por inteligencia artificial. **Fuente:** https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html?m=1

All The News That's Fit To Print On Ken's Blogspot Serving The Internet Since 2006

4/22/2026

muskspacexipoirishnewstennesseehonoluluindonesiaislamabadnasaluxembourgtexas100senate2chinese13samsung4usnepal3utahparispodcast1ukfleetrihanna75adisneyworld9amarketslisbonlocallywalesonlineukrainerussianoklahomacity27a11pakistanfreemanjamaicaeuathensmothergazaisraeli52ottawanewdelhioxfordshiresaintpaulnetflixkathmanduhealth6iowahouse50pcb24congoapple48usubelfast_livetaiwaneseafricantaiwansingaporenewkualalumpursaskatoonrussiaconstructionirelandportlandstarmertallinnnazithejournallondon94chinabeijinggermanymoldovansarabiaindianseoulunitedstatesmanilajapanuniversity43kilkennykazakhstanenvironmentalberlinepamarylanddcjoneslebronjamesbaku18horoscope41ai21atvuae1aedmontontrump16denmarkxbox51a105aoxfordinternationalperuvianbishkekgooglehome12cbsnews39denverbitcoin17greecetodayindiaidfwallstreetnewsletterfoxirishmirrorthiruvananthapurambagdadspainsouthwalesargusfloridaunfi11amacbooklinuxhungarykyivmediatechicc64apopenewbuses49europeirandonaldtrumpfamily42skoreapopescatholic15hartfordmalawiansnationalrigasupremecourthousestanzanianorthernnigeriaadhdafricajapanese22manufacturingmicrosoft53dublinpatriotskuwaitcitydubairiyadhresearcherscanadiansportsnewengland25windows36americansouthkorean81bbcwalessudanbelgrade7stock55policeaustraliaprovidenceearthcraftsscottishkuwaitghanalearnovateevoke35toykonevadaargentinathesunrelationshipchatgptcharity39a28awyoming119ajacksonyemendna29fitnesswisconsinnflcomusmcaconsumerromania20northropgrummanfinancialhongkongsuriname21lucknownewprince384764news2413a10grandrapidsdemocratsnorthkorealebanonrtbristol22aestonianderrynicosiaandroidauto31capetownretail55a54political5ohio28austinukrainianpanamacitymusicceo77global35amovie145labostonsyriachristians75unitedcanadaethiopianprimeministerlimaseychellesdesmoinespalestinianeuropeanpakistanicalifornia26aungovernmentvideodeifashioniphonemalaysiafmjerusalemsouthafricaasiansbritishvirginislandsnapshotghanaiangoldmansachs9maputo10aatlantaputinmadisonrepublic87amiami14munichisrg46romaniandonegaldowndaily_recordapramazon37icewellingtonbuildingenvironmentmichiganromemetabhamliveedinburghtechnologyalabamaarizonabrusselsrwandausbcolomboscotsmanmetalsderryjournalsouthkoreacristianoronaldo41aarchitecturemaltalearnedhawaiiphilippinesrsvp1313074achicagosecurityalbanianfbitransgendermachinestradefood58turkeynovakittnlawmanchesterresearchermagastv_newsnepaliforeignmlahistoryegyptirishrepublicansarmeniacharlestoncancertrentoniranian45glasgowattorneygeneraljakarta118abbcscotlandmorocco104macronrabatasiapierregeorgia8missoulanewalbumgpuscpusrepublicanhawaiianairlineslimerickleaderlyonsinvestmentkosovocopenhagentrinitycollegewomenhorrorbangladeshludhianaholidaylaosamericans32ankarawebtoonssciencewindsorgopscotusnewsonygandhibookamsterdamitalynbawsjoklahomacitycheyennefinancespurslatviagdpmexicounite63akievnflmotorcyclist140openaifaafccnewlookspotifyjubaalaskalatvianwhocongressnewwarjordanvilniustlibyaairbnbamericazelenskydelhinationwideautonomyharrisburginternetnewrazrchristiane991bernabeuevmstiruchirappalli83espncyprustownpackersbasseterremotherwellmilanlearninglimericknewplaycnnnewzealand40travel110amontgomeryevsbarbadosususarichmondagrilandgas197freezechilesuclasantodomingokigaliodesamamdaninewsupportbanjulwilliamsonstarbucksabudhabialdihanoitehranparliament25acvspharmacylilongweoregonmilitarybuenosairesdhsmadridnovascotiahomebuildertollbrothersarkansasmonacoconnorstorrieresearchfuturenewsodasscotlandnatonewfedlpool_echomacaocongressional26slovakianvidia57acryptosaints1989yankeesgodbulgariamoscowrfkportvilavirginianewyorkbuffalocairohomeownerskabulrnaljubljanacoloradomiddleeastasian93sonyazerbaijanundpdarwinaustralianspanamaartistickanolawmakerslasvegas33maduraikingcharlesnewnaturepropertykansaslouisiana23walmartnewabortion16amassachusettsyerevanaustriagermanmyanmarintelligencehomelessfrancedefenselittlerockbooksbookingshelenatownsenddominicansailakyliejennerhousekeepervaticancitymortgagesdemocratgambiathe42culturalgasperini27minnesotaartemisinsurancemlasmilwaukeehumanrightsugandabestbuy44charlottesvilleconcordjeffersoncityequatorialguineaindustryscientificsalonemobilemilanoastanatesla33adowngrade51engineeringtorontopodcastsnewrulesindianabatonrougekyrgyzstan102adobemobilealgerianwichitademocraticjerseyarturoamericasmalawivarietyeducationcubsbreakingnewshelsinkifmsmalinovkavrambeiruttourismapplesmalaysianabujacbp88aharvardtraderzelenskyyvolvoswedencostaricacuencadominicanhaitibelfastscientistsstockholmnihweatheraviationcarsoncitynewpregnancymoviesmoneyartistgodmotherhathawaytvkvermontbeveragemedicalraleighsomaliatopekaetfsnewark69latviansisraelmontpelier101vietnamkevinwarshdojagrawalperthlansing

Understanding Artificially Complex XML Schemas and Vendor Lock-In

A few days ago, I stumbled across a fascinating article by Italo Vignoli on The Document Foundation blog, titled “An artificially complex XML schema as a lock-in tool.” It caught my eye because it tackles an issue I've seen play out repeatedly throughout my career—vendor lock-in disguised within technical standards. We've all encountered XML (Extensible Markup Language), the backbone of cross-platform data interchange, praised for its clarity, simplicity, and universality. I've worked on numerous projects, from healthcare to government contracts, and XML was always there, quietly ensuring compatibility and seamless data exchange. But as Vignoli points out, XML’s openness doesn't always translate into freedom—especially when it comes to document formats. The crux of his argument revolves around Microsoft's Office Open XML (OOXML), the underlying format for the familiar DOCX, XLSX, and PPTX files. On paper, OOXML seems open enough: it's XML-based, standardized, and widely adopted. Yet, beneath its open facade lies an intentionally convoluted schema—bloated with deeply nested tags, obscure naming conventions, and thousands of optional or abstract elements. And here’s the kicker: the official specification runs to over 8,000 pages! Let me share a vivid analogy from Vignoli's article that really clarified this issue for me. Imagine a public railway: the tracks are open to everyone, but the leading train manufacturer imposes an insanely complicated control system. Yes, anyone could theoretically build a compatible train, but the complexity ensures only the original manufacturer can feasibly do it. Passengers remain unaware until fares rise or service quality drops—and by then, they're trapped. This is precisely what's happening with OOXML. Documents may look identical onscreen, but their hidden complexity makes third-party implementations prohibitively difficult. Vignoli demonstrates this starkly by comparing OOXML to the vendor-neutral OpenDocument Format (ODF), used by LibreOffice. To illustrate: writing a simple sentence like “To be, or not to be” generates a concise 32-line XML file in ODF. In OOXML, it expands to 41 lines—breaking words into numerous tags and embedding multiple proprietary namespaces. Scaling this up, the full text of Hamlet balloons from roughly 5,600 lines in ODF to an astonishing 93,000+ lines in OOXML. That complexity isn't accidental; it's strategic. I've seen this first-hand. Years ago, I worked on a document migration project for a government client. We started with thousands of DOCX files, and converting them reliably into another format felt like defusing a bomb. Every subtle update from Microsoft risked breaking our carefully reverse-engineered code, costing countless hours and frustration. Many colleagues echoed a sentiment of resignation: "We're stuck; what else can we do?" Microsoft argues that OOXML’s complexity stems from needing to support extensive legacy features and compatibility. There's truth in that; backward compatibility is challenging. But does it really justify an 87,000-line markup overhead for Hamlet? Not likely. Instead, this complexity functions as a "soft" lock-in, quietly discouraging migration to other tools and subtly reinforcing dependency on Microsoft's ecosystem. Journalists and academics have noted similar trends. A Reuters report from way back in 2007 already highlighted concerns about OOXML’s complexity, calling it "artificially complicated." XDA Developers recently echoed these concerns, reinforcing that complexity prevents interoperability and fosters dependency. What's encouraging, however, is how governments are waking up to this issue. Denmark recently announced it’s shifting public infrastructure from Microsoft 365 to LibreOffice, specifically citing the need to reduce vulnerability and foster innovation. Schleswig-Holstein in Germany is doing the same, migrating 30,000 public-sector PCs to open standards. They understand something crucial: digital sovereignty requires open, transparent, and genuinely interoperable document formats. When formats remain genuinely open and manageable—like ODF—they empower users, developers, and governments alike. They ensure you retain control over your data. They promote competition, innovation, and accessibility. I’ve learned that embracing open standards isn’t just a technical decision; it’s about preserving autonomy in an increasingly monopolized digital landscape. So, the next time you're choosing software or a document format for a project, look beyond mere compatibility. Question the complexity beneath the surface. Ask yourself: "Am I inadvertently locking myself (or my organization) into an ecosystem where my data could someday become inaccessible?" Remember, complexity should serve content, not vendors.