this post was submitted on 01 Feb 2025
680 points (98.4% liked)

News

24300 readers
5524 users here now

Welcome to the News community!

Rules:

1. Be civil


Attack the argument, not the person. No racism/sexism/bigotry. Good faith argumentation only. This includes accusing another user of being a bot or paid actor. Trolling is uncivil and is grounds for removal and/or a community ban. Do not respond to rule-breaking content; report it and move on.


2. All posts should contain a source (url) that is as reliable and unbiased as possible and must only contain one link.


Obvious right or left wing sources will be removed at the mods discretion. We have an actively updated blocklist, which you can see here: https://lemmy.world/post/2246130 if you feel like any website is missing, contact the mods. Supporting links can be added in comments or posted seperately but not to the post body.


3. No bots, spam or self-promotion.


Only approved bots, which follow the guidelines for bots set by the instance, are allowed.


4. Post titles should be the same as the article used as source.


Posts which titles don’t match the source won’t be removed, but the autoMod will notify you, and if your title misrepresents the original article, the post will be deleted. If the site changed their headline, the bot might still contact you, just ignore it, we won’t delete your post.


5. Only recent news is allowed.


Posts must be news from the most recent 30 days.


6. All posts must be news articles.


No opinion pieces, Listicles, editorials or celebrity gossip is allowed. All posts will be judged on a case-by-case basis.


7. No duplicate posts.


If a source you used was already posted by someone else, the autoMod will leave a message. Please remove your post if the autoMod is correct. If the post that matches your post is very old, we refer you to rule 5.


8. Misinformation is prohibited.


Misinformation / propaganda is strictly prohibited. Any comment or post containing or linking to misinformation will be removed. If you feel that your post has been removed in error, credible sources must be provided.


9. No link shorteners.


The auto mod will contact you if a link shortener is detected, please delete your post if they are right.


10. Don't copy entire article in your post body


For copyright reasons, you are not allowed to copy an entire article into your post body. This is an instance wide rule, that is strictly enforced in this community.

founded 2 years ago
MODERATORS
 

Summary

A vulnerability in the new OPM email server allowed anyone to send mass messages to federal employees, exposing poor cybersecurity.

Over 13,000 NOAA staff received spam and vulgar messages, including crude jokes about Trump and bizarre newsletters, causing widespread outrage.

The breach resulted from an overhaul led by Elon Musk that installed underqualified personnel and an insecure in-house system, sparking a class-action lawsuit for cybersecurity failures.

The unsecured system also inadvertently revealed ties to Project 2025 and a plan to gather government employee data as Trump’s loyalists reshape federal operations.

(page 2) 40 comments
sorted by: hot top controversial new old
[–] forrgott@piefed.social 32 points 1 day ago (1 children)

But her emails!?

Just to clarify, i'm talking about Musk. :)

[–] dhork@lemmy.world 12 points 1 day ago* (last edited 1 day ago) (1 children)

Stop misgendering Elon!

The correct exclamation in this case is Butt Tizzy Males, not Buttery Males

[–] MrSpArkle@lemmy.ca 7 points 1 day ago

The Eo about gender made everyone a female.

[–] towerful@programming.dev 19 points 1 day ago (1 children)

It's been 4 days.
How did people get these email addresses?
I mean, the domain is known.
But was the system that president musk broke really holding back this torrent of abuse and garbage?
Feels like actual email addresses were leaked.
Unless it was a mailing list that was suddenly exposed.

Still seems strange that an email that simply says "yo" suddenly came through as part of the spam.
Feels like email addresses were posted somewhere, and someone jumped on for the lulz. Along with the wall of trolls and abusers jumping on.

I mean, as soon as I link a domain to an IP, I see all sorts of "security" scans turn up. Till then, firewall is pretty quiet.
And if I wildcard direct a domain to an ip, the root gets scanned but any sub domains don't.
I feel email addresses would follow a similar pattern.

[–] MrEff@lemmy.world 61 points 1 day ago (2 children)

It's worse than you think. Last week we got an email that looked like strait up fishing spam demanding that we were to email back "yes" confirming that we got the email. So many people even reported it as spam that we had supervisors have to directly tell us that it was legit. Then they sent out a second email with a warning that is was in fact legit and to respond to that email with "yes" if we got that one.

On the back end at OPM: Musk forced his way in and demanded to redo the email servers. The IT told him it wasn't possible for what he was asking. So he brought in his own goons to install a non government server with unknown software and unknown security configurations and they plugged it into the OPM network to spoof it as an official OPM server, then sent out those emails.

And sure enough, the idiot didn't didn't configure the security correctly or let official government IT people touch it, it ended up backdooring into the entire government HR system, and it had every active government email that responded "yes" to his stupid email that we were required to. And now we know it was compromised. There is no telling what foreign governments now have all of that info as well as what other backdoors they have installed.

[–] towerful@programming.dev 40 points 1 day ago (4 children)

Holy shit.
That's some shit that contravenes every security briefing, every security best practice.
Then they go and spoof a legit government installation with their own bullshit?!
Fucking Hilary and her email servers. But like times 10. Legitimately compromising the US government communications.
Why is this lawsuits, why isn't this treason?!

[–] dhork@lemmy.world 21 points 1 day ago

why isn't this treason?!

Because Musk bought the election for Trump, and now Musk do whatever he wants.

load more comments (3 replies)
load more comments (1 replies)
[–] Rhoeri@lemmy.world 13 points 1 day ago (1 children)

I wonder how much of the intended damage he wants us to suffer is going to be mitigated as a result of their incompetence, and then I wonder how long can we count on them to continue making these mistakes before people begin to get seriously hurt…

People have already died from their actions. 2 plane crashes and counting.

But her emails...

load more comments
view more: ‹ prev next ›