Energy News
CYBER WARS
Microsoft faces heat from US Congress over cybersecurity
Microsoft faces heat from US Congress over cybersecurity
by AFP Staff Writers
Washington (AFP) June 13, 2024

Members of US Congress on Thursday pressed Microsoft to explain a "cascade of avoidable errors" that allowed a Chinese hacking group to breach emails of senior US officials.

Microsoft President Brad Smith spent more than three hours answering questions from members of the House Committee on Homeland Security in Washington, assuring them cybersecurity is being woven more deeply into the technology company's culture.

"Microsoft accepts responsibility for each and every one of the issues cited" in a scathing US government report about the breach "without equivocation or hesitation," Smith told the committee.

The Cyber Safety Review Board (CSRB), led by the US Department of Homeland Security, conducted a seven-month investigation into the incident last year that involved the China-affiliated cyberespionage actor Storm-0558.

"Microsoft has an enormous footprint in both government and critical infrastructure networks," US congressman and committee member Bennie Thompson said to Smith as the hearing opened.

"It is our shared interest that the security issues raised by the (report) be addressed quickly."

The operation, which was first discovered by the US State Department in June 2023, included hacks on the official and personal mailboxes of Commerce Secretary Gina Raimondo and US Ambassador to China Nicholas Burns.

Microsoft's core business is to provide cloud computing services, such as Azure or Office360, that host sensitive data and power business and government operations across major sectors of the economy.

The report criticized a Microsoft corporate culture that was "at odds with... the level of trust customers place in the company."

The review identified a series of operational and strategic decisions by Microsoft that opened the door to the breach, including the failure to identify a new employee's compromised laptop following a corporate acquisition in 2021.

It also found that Microsoft fell short of safety standards seen at competing cloud companies, including Google, Amazon and Oracle.

"The Board finds that this intrusion was preventable and should never have occurred," the review said, pinpointing "the cascade of Microsoft's avoidable errors that allowed this intrusion to succeed."

- 'Lasting change' -

The report also recommended that Microsoft develop and publicly release a plan with timelines to enact wide-ranging security reforms across its products and practices.

"The real challenge is how you achieve effective lasting cultural change," Smith said, noting Microsoft has nearly 226,000 employees.

Smith said Microsoft has the equivalent of 34,000 engineers working full time on answering the security shortcomings in "the largest engineering project focused on cybersecurity in the history of digital technology."

Microsoft's board on Wednesday approved a change that will tie cybersecurity accomplishments with annual bonuses for senior executives and make it part of every employee's annual review, according to Smith.

Microsoft detects some 300 million cyberattacks on its customers daily, with most of those coming from China, Iran, Korea, Russia, or ransomware operations, Smith told the committee.

"We're dealing with four formidable foes in China, Russia, North Korea and Iran, and they are getting better," Smith said.

"We should expect them to work together; they're waging attacks at an extraordinary rate."

While it is inevitable that adversaries will use artificial intelligence for increasingly sophisticated attacks, the technology is already being used to strengthen cyber defenses, Smith added.

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
CYBER WARS
Phony 'news' portals surpass US newspaper sites, researchers say
Washington (AFP) June 11, 2024
Partisan websites masquerading as media outlets now outnumber American newspaper sites, a research group that tracks misinformation said Tuesday, highlighting a local news crisis in a year of high-stakes elections. Hundreds of sites mimicking news outlets - many of them powered by artificial intelligence - have cropped up in recent months, fueling an explosion of polarizing or false narratives that are stoking alarm as the race for the White House intensifies. At least 1,265 "pink slime" outl ... read more

CYBER WARS
Ozone-harming gas declining faster than expected: study

Diagnosing damaged infrastructure from space

Nitrous oxide emissions surge in climate threat: study

A milestone in digital Earth modelling

CYBER WARS
Europe's Largest Ground Segment Upgraded Without User Disruption

Magic Lane secures 3 million euro to enhance location intelligence capabilities

China Encourages BeiDou System Integration in Electric Bicycles

Estonia summons Russian envoy over GPS jamming

CYBER WARS
Carbon credits protecting forests use flawed calculations: study

'All Eyes on Papua' campaign generates interest in deforestation cases

Indian Islamic centre warns Muslims against felling trees

DR Congo capital hosts forest forum

CYBER WARS
Sky's the limit for biofuels

Sustainable Aviation Fuel Reduces Non-CO2 Emissions

Vast Gets Approval for Solar Methanol Plant in Port Augusta

Singapore shipper claims milestone with bio-methanol refuelling

CYBER WARS
Sweeping review reveals impact of integrating AI into photovoltaics

Redwire to Develop Solar Arrays for Thales Alenia Space's New GEO Satellites

Flexible perovskite/silicon tandem solar cell achieves new efficiency record

Solar investment outstrips all other power forms: IEA

CYBER WARS
Why US offshore wind power is struggling - the good, the bad and the opportunity

Robots enhance wind turbine blade production at NREL

Offshore wind turbines may reduce nearby power output

Wind Energy Expansion Planned for China's Rural Areas

CYBER WARS
Australia gives largest coal power plant two-year lifeline

US plans to end leasing in its largest coal-producing region

In coal country Bulgaria, a losing battle against EU Green Deal

Banks slow to limit coal financing: NGO

CYBER WARS
Four Americans stabbed in northeastern China

Hong Kong arrests three for 'insulting' anthem at World Cup qualifier

Millions of Chinese students start exams in biggest 'gaokao' ever

China accuses US of interfering after Tiananmen comments

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.