Microsoft says 365 outage was amplified by internal errors

From ComputerWorld: Microsoft’s latest outage on Tuesday might have been amplified by its own unforced errors, the company said in an incident report.

“While the initial trigger event was a distributed denial-of-service (DDoS) attack, which activated our DDoS protection mechanisms, initial investigations suggest that an error in the implementation of our defenses amplified the impact of the attack rather than mitigating it,” the report said.

The Microsoft 365 outage on Tuesday is the latest in a series of unforced errors by major IT vendors.

Failure to adequately test systems before roll-out was also a factor in the CrowdStrike incident on July 19, and behind DigiCert’s short-notice revocation of erroneously issued SSL certificates earlier this week.

The July 19 incident was caused by a flaw in CrowdStrike’s security sensor software that cost users millions of dollars in repairs and lost business opportunities, and that testing had failed to uncover.

View: Full Article