235
top 50 comments
sorted by: hot top controversial new old
[-] Treczoks@lemmy.world 95 points 3 days ago

Oh wonderful. Replacing all IT because they were hacked? Let me guess, they will use Windows, Exchange, and MS Office again on the new system. The software triumvirate screaming "please hack me".

[-] derry@midwest.social 26 points 3 days ago

Project manager: at least I can blame the vendor

[-] sp3ctr4l@lemmy.dbzer0.com 14 points 3 days ago

Entirely seriously, yes.

Most project managers I've ever met or known or worked with are basically incompetent technically, and very insecure / in denial about that, and thus vastly prefer the 'safe' option of someone else being responsible over the 'risk' of... hiring actual quality people that can make/support their own quality product.

[-] Saleh@feddit.org 3 points 3 days ago

Did you consider that project managers often have to follow all sorts of company standards, have to figure out a way to get a dozen departments with conflicting standards together, on top of that have to catch the stupid ideas from the upper-management and marketing without telling the upper-management that they have no idea what they are talking about, on top of getting something actually done in the project?

Because often the level of tech competency has very little to do with the decision corridor that the project manager has, given everything else.

[-] sp3ctr4l@lemmy.dbzer0.com 7 points 3 days ago

Yep.

I've been one.

Thats how I know what I am saying.

Like you're not even challenging what I'm saying really, you admit that most PMs are technically incompetent, because their job is mainly playing office politics.

It didn't used to be this way.

And it still doesn't have to be.

A good PM is someone who actually knows their relevant field, and can also do some office politics, but much more importantly, is a responsible and helpful team leader.

A person with only an MBA just has a degree in how to play office politics and gaslight people.

load more comments (1 replies)
[-] CallMeAnAI@lemmy.world 13 points 3 days ago* (last edited 3 days ago)

🤣 should we get a list of foss projects that have had security issues? Or how about how someone slips some shit in upstream every few weeks it seems?

Stop this nonsense. You can hate Microsoft for legitimate reasons.

[-] toothpaste_ostrich@feddit.nl 23 points 3 days ago

I mean... For real, I've never heard of Linux systems being hacked this way. I'm sure it's possible, but it certainly seems rarer.

Slipping shit in upstream also certainly doesn't happen "that* often. It takes effort to become recognised enough as a developer to be allowed access to the upstream code, meaning you can't automate those kinds of attacks. (I imagine. Correct me if I'm wrong.)

[-] CallMeAnAI@lemmy.world 11 points 3 days ago

Absolute opposite. The majority of successful attacks you see today are identity management and supply chain attacks. If you walk into any OCIO office supply chain will be a top 3 concern.

[-] msage@programming.dev 6 points 3 days ago

I know of one successful supply chain attack in FOSS.

So still points for using it.

[-] SheeEttin@lemmy.zip 2 points 3 days ago

AUR has had multiple Trojans just this week

[-] msage@programming.dev 1 points 2 days ago

I'm sorry, Dave, but AUR does not count.

load more comments (1 replies)
[-] sp3ctr4l@lemmy.dbzer0.com 6 points 3 days ago* (last edited 3 days ago)

It does happen occasionally, from time to time, but, because everything is gasp open source, it tends to get caught, identified, blocked/quarantined and then fixed considerably more rapidly, with decent fallback instructions/procedures in that interim period.

Like apparently it actually just recently happened with some asshole uploading bs malware libs/sources to the AUR... even still, got caught pretty quickly.

Also, you can basically describe the entire CrowdStrike fiasco as exactly this kind of upstream oopsie doopsie.

Doesn't really matter in the big picture if it was intentionally malicious or not, when you Y2K 1/4 of the world's computer systems.

[-] disco@lemdro.id 13 points 3 days ago

Microsoft is getting hacked every other week.

[-] CallMeAnAI@lemmy.world 6 points 3 days ago

As well as FoSS projects.

[-] trolololol@lemmy.world 2 points 3 days ago

Mate have a look at the SharePoint vulnerability. It's embarrassingly bad. Like really really bad, and btw so bad that it's very easy to understand and exploit. And prevent too, if a jr in my team did this I'd get them in trouble.

[-] sp3ctr4l@lemmy.dbzer0.com 2 points 2 days ago* (last edited 2 days ago)

No no, you don't get it.

Random Windows 'Powerusers' obviously know more about programming and cybersecurity than people who actually do that for a living, as a professional line of work, duh!

See, I wrote a bash file once, so I basically know everything about software dev, especially on linux as well, which is basically just the whole OS is powershell, right?

/s/s/s

[-] dumples@midwest.social 45 points 3 days ago

The national guard here is looking around for men in black masks in front of computers throughout the city. Its crazy

[-] prole 28 points 3 days ago

Is this a joke or are you serious?

Goddamn it, I can't tell anymore

[-] dumples@midwest.social 15 points 3 days ago

They found him

Hackerman

It's a joke....

[-] sp3ctr4l@lemmy.dbzer0.com 49 points 3 days ago* (last edited 3 days ago)

https://techxplore.com/news/2025-07-fbi-national-st-paul-cyber.html

https://www.reuters.com/world/us/minnesota-calls-national-guard-after-st-paul-slammed-by-digital-attack-2025-07-29/

https://techcrunch.com/2025/07/30/minnesota-activates-national-guard-as-cyberattack-on-saint-paul-disrupts-public-services/

So, this actually was first detected on Friday July 25, escalated all the way up to the Emergency Operations Center on July 28 (Monday), state of emergency / near total intranet shut down (they are quarantineing the whole system) on July 29 (Tuesday).

It seems to me that some kind of rather sophisticated threat actor managed to get into the core ... this techxplore article calls it a 'VPN', but it isn't technically a VPN, its a secure access tunnel system that city-gov systems and employees use to talk to each other, it almost certainly is not intended to be geared toward broad internet access/usage, beyond accepting user input from public facing government web portals, such as say, people paying their utliity bills online or trying to submit a business liscense application online, things like that.

This system is sounding like it got fully compromised (as in, low level/high privilege level access was secured), and was either sending data out/in through improper IP addresses, and/or was possibly being hijacked to do some kind of DOS attack ... on itself?

I am having a really hard time finding any exact details on this, but this is my best guess.

Given that the EOC essentially immediately shutdown everything and called in a National Guard Cybersecurity team, it seems to me that there is a high chance this was done by basically a nation-state level threat actor.

It also at least seems like the systems, the data, the hardware, have at least not yet been locked down in a ransomware style move, which... could be largely due to their just quickly pulling the whole thing offline, or could be because that wasn't the goal of the attackers... or some combination of both.

[-] SlartyBartFast@sh.itjust.works 27 points 3 days ago

What's Saint Paul gonna do about it?

Complain to Jesus?

[-] JohnAnthony@lemmy.dbzer0.com 15 points 3 days ago

but at least Abilene was insured against such an attack

Oh, well that's great. I hope the people, whose identity, medical records, or whatever else was stolen will be compensated accordingly. Would be a shame if the money went into building a new, just as unsafe system.

Not that anyone gives a fuck. At this point the argument is "your data had probably already been stolen somewhere else"...

[-] justlemmyin@lemmy.world 16 points 3 days ago

Had to read the article to realise st Paul is a city name. 😅

Also, could it be a 'the call is coming from inside the house " situation?

I remember pedo party hating this mayor. It was all over lemmy during simpler times.

[-] Chulk@lemmy.ml 10 points 3 days ago

Also, could it be a 'the call is coming from inside the house " situation?

I think this is far more likely than China, North Korea, Iran or Russia having a sudden interest in St Paul Minnesota (a city that most people in the US don't even think about).

Who benefits more from the crippling of city-level liberal governments and stealing their data, Trump or China? If we see ICE conducting surgical raids within St Paul in the coming months, I think we'll have our answer.

[-] JaymesRS@piefed.world 7 points 3 days ago

Probably not the mayor, the governor of the state was the VP candidate for Kamala Harris.

[-] disco@lemdro.id 11 points 3 days ago

Isn't there an upcoming election in St. Paul?

[-] JaymesRS@piefed.world 17 points 3 days ago* (last edited 3 days ago)

Minneapolis and St Paul (Cross-River sister cities, St Paul is the State Capital) both have mayoral elections on November 4, 2025. The one you’ve been seeing mentioned more likely is the Minneapolis one where the DFL (State Democratic Party) endorsed a candidate for the first time in a bit and it was the challenger to the incumbent Democratic candidate, so it’s been in the news.

[-] Zombie@feddit.uk 10 points 3 days ago

Loving the completely unfounded speculation that it must be ~~Eurasia~~ Russia or ~~Eastasia~~ China in this thread.

Y'all are so deep in propaganda you don't even know it.

https://en.m.wikipedia.org/wiki/Political_geography_of_Nineteen_Eighty-Four

[-] Ilovethebomb@sh.itjust.works 27 points 3 days ago
[-] Zombie@feddit.uk 8 points 3 days ago

Oh honey, don't you see the irony of posting the BBC and the government's cyber security centre to refute claims of propaganda?

Do you believe the most technologically advanced country in the world, with the power of silicon valley, an unlimited budget for the military and CIA, currently being run by an outright fascist, is innocent?

https://en.wikipedia.org/wiki/Operation_Olympic_Games

https://www.independent.co.uk/news/world/americas/us-politics/donald-trump-us-hacking-china-b2779104.html

“We have stated our position many times regarding such groundless accusations that lack evidence,” ministry spokesperson Mao Ning was quoted as saying by the AFP news agency.

A spokesperson for the Chinese embassy in the US, Liu Pengyu, denied the department’s allegations. “We hope that relevant parties will adopt a professional and responsible attitude when characterising cyber-incidents, basing their conclusions on sufficient evidence rather than unfounded speculation and accusations,” he said, according to a BBC report.

“The US needs to stop using cybersecurity to smear and slander China and stop spreading all kinds of disinformation about the so-called Chinese hacking threats.”

https://www.aljazeera.com/news/2025/1/1/us-treasury-hacked-are-china-and-the-us-stepping-up-their-cyberwar

It's always China, Russia, North Korea, and Iran that is jumped to because that is the main adversaries of the west. Never India, or Brazil, or Israel, or Saudi Arabia, all capable countries. With not a shred of evidence it's always China, Russia, North Korea, and Iran that are speculated.

No speculation that perhaps Mexico and Canada, two countries currently having beef with the US could be to blame. No speculation that it's a false flag by the US federal government. No, straight to China.

When the Spanish power grid went down straight away the speculation was to Russian or Chinese hacking, investigations aren't finished yet but it appears to have been nothing of the sort, but instead frequency oscillations in the power lines.

https://en.wikipedia.org/wiki/2025_Iberian_Peninsula_blackout#Misinformation

It could very well be China etc but straight away with no evidence there's comments like "What are the chances this took place during working hours in China?".

At best it's bigoted, at worst it's U.S. sponsored Lemmy propaganda.

[-] Allero@lemmy.today 5 points 3 days ago* (last edited 3 days ago)

Yes. There are quite a few completely unfounded pieces stating it is Russia or China or North Korea behind thing X with no proofs whatsoever.

These do not go to prove your point.

Now, there were some proven cases, but attributing every attack to one of these now without judge and jury is nothing but blatant and bold propaganda.

[-] Ilovethebomb@sh.itjust.works 20 points 3 days ago

Did you get lost on the way to Lemmy.ml?

1.5 billion in crypto isn't something you can spend without attracting attention, of course it was them.

[-] Allero@lemmy.today 7 points 3 days ago* (last edited 3 days ago)

People got so deep into their allegiance games that they cannot comprehend anyone standing for the truth.

Fuck .ml China fappers, and fuck .world Russia-guilty-of-everything fans. You're equally terrible in enabling atrocities.

As I said, some cases are confirmed, some are wild speculations. And latter are commonly used in future arguments as confirmations, despite them being mere speculated assumptions.

You can have a barrage of "something-bad" confirmations like these out of thin air, and this is a common propaganda tactic.

[-] AwesomeLowlander@sh.itjust.works 20 points 3 days ago

Would you like to name other likely suspects? It's not standard criminals, there have been no ransom demands. And they're unlikely to piss off the govt to this extent. Which leaves state actors. Gee, wonder who it might be.

[-] Allero@lemmy.today 7 points 3 days ago

Literally anyone until proven guilty?

[-] Deceptichum@quokk.au 18 points 3 days ago

Checks out, it was probably New Zealand.

Fucking dumbarse.

[-] AwesomeLowlander@sh.itjust.works 17 points 3 days ago

Nobody's passing sentence, it's just speculation about guilty parties. Last I checked that was legal and in fact common discussion.

[-] shortwavesurfer@lemmy.zip 5 points 3 days ago

We're at war with East Asia. We've always been at war with East Asia. George Orwell, 1984.

[-] Ilovethebomb@sh.itjust.works 11 points 3 days ago

What are the chances this took place during working hours in China?

[-] setsubyou@lemmy.world 26 points 3 days ago

The article says it started on a Friday morning in Minnesota. It’s clear that that’s when the attack started and not a case of the first guy starting work that day discovering that it happened, because the article also says that they tried to contain it as it was going on, but ultimately failed.

Minnesota is at UTC-5 and China is at UTC+8, meaning when it’s morning in Minnesota, it’s already 13 hours later in China, i.e. middle of the night.

[-] Nimrod@lemmy.world 24 points 3 days ago

I don’t see anything in the article that states the attack started that morning. It says that i was “first noticed” early Friday morning:

According to remarks by St. Paul Mayor Melvin Carter, the attack was first noticed early in the morning of Friday, July 25.

I’m not arguing it’s China, just that I didn’t see anything indicating they know when the attack started

[-] outhouseperilous@lemmy.dbzer0.com 11 points 3 days ago

Or maryland. The feds are not friends right now. Arguably ever, but definitely not right now.

[-] Hegar@fedia.io 9 points 3 days ago

With no ransom demand it's gotta be a state actor probing defenses and testing responses, right? I think first guesses would be Russia, China, Iran or maybe North Korea.

first guesses

Not so sure. Arent they known for being a queer friendly town?

load more comments (2 replies)
[-] piecat@lemmy.world 2 points 3 days ago

Or some bored teenager somewhere

load more comments
view more: next ›
this post was submitted on 01 Aug 2025
235 points (100.0% liked)

Technology

73602 readers
3007 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS