Brutkey

Kevin Beaumont
@GossiTheDog@cyberplace.social
Kevin Beaumont
@GossiTheDog@cyberplace.social

A Microsoft employee has bypassed the filtering of the words Palestine, Gaza or genocide to email thousands of employees https://www.theverge.com/microsoft/673568/microsoft-palestine-email-block-defeated-employee

The full email
https://archive.ph/6SZ6A

Kevin Beaumont
@GossiTheDog@cyberplace.social

TCS has a security incident running around the M&S breach.

Interestingly the source claims TCS aren't involved in Co-op's IT - which is categorically false, they took over most of it while I worked there, including the helpdesk, and my team (SecOps) after I left.

https://www.ft.com/content/c658645d-289d-49ee-bc1d-241c651516b0

Kevin Beaumont
@GossiTheDog@cyberplace.social

Co-op Group announces it's getting rid of paper prices in stores, going to electric displays. Good luck during a ransomware incident πŸ˜’πŸ˜’

Kevin Beaumont
@GossiTheDog@cyberplace.social

Let’s see if I get booted off LinkedIn for a third time.

Kevin Beaumont
@GossiTheDog@cyberplace.social

Microsoft has used its security controls to block messages which contain the words Palestine and Gaza.

https://www.theverge.com/tech/672312/microsoft-block-palestine-gaza-email

Kevin Beaumont
@GossiTheDog@cyberplace.social

Tabletop scenario for you:

Employee gets into a dispute with employer, leaves, had sensitive role. Employer revokes access, devices etc. Employee had logged in via BYOD to email, IM etc.

Due to Recall, employee walks away with 6 months of screenshots of everything she's ever worked on in a text indexed form - every email, chat, document, Teams call with video snapshots, transcripts of verbal calls etc - even if they set M365 to not store documents locally.

What does the employer do now?

Kevin Beaumont
@GossiTheDog@cyberplace.social

Signal have rolled out an update to all users that stops Microsoft Recall from capturing Signal conversations.

I’ve tested this and it works. Brilliant work by the
@signalapp@mastodon.world team. πŸ’ͺπŸ’ͺ

They call on Microsoft to build better, as there was no standardised way as an app developer to do this. Because Signal is open source, now app developers have a template to protect their users from Windows.

https://signal.org/blog/signal-doesnt-recall/

Kevin Beaumont
@GossiTheDog@cyberplace.social

The CEO of M&S has declined to comment if they have paid a ransom. For the record: I’ve heard they have, in secret, via their insurance. https://www.reuters.com/business/retail-consumer/ms-says-cyber-attack-was-result-human-error-declines-comment-ransom-2025-05-21/

Kevin Beaumont
@GossiTheDog@cyberplace.social

The NCA has confirmed on the record that the investigation into the M&S and Co-op hack is focused on English teenagers. I could toot the names of the people I think they’ll pick up, but won’t.

https://www.bbc.co.uk/news/articles/ckgnndrgxv3o

Kevin Beaumont
@GossiTheDog@cyberplace.social

Their CEO has commented they’ve drawn a line under the hack, without recovering, which has a bit of this energy honestly

Kevin Beaumont
@GossiTheDog@cyberplace.social

M&S say online ordering will be stopped until sometime in July, and it has taken a Β£300m hit, far higher than analysts had predicted. https://www.bbc.co.uk/news/articles/c93llkg4n51o