"US Cyber Safety Board Condemns Microsoft for Allowing Chinese Hackers to Breach Government Emails"

TL;DR Summary
The U.S. Cyber Safety Review Board has criticized Microsoft for security lapses that allowed a China-based hacker group to breach nearly two dozen companies, faulting the tech giant for deprioritizing enterprise security investments and failing to detect the compromise on its own. Microsoft acknowledged errors in its source code and a compromised engineer's account, leading to unauthorized access and exfiltration of emails. The CSRB recommended cloud service providers to implement modern control mechanisms, adopt incident and vulnerability disclosure practices, and update federal authorization frameworks to safeguard against state-sponsored cyber threats.
- U.S. Cyber Safety Board Slams Microsoft Over Breach by China-Based Hackers The Hacker News
- US government review faults Microsoft for ‘cascade’ of errors that allowed Chinese hackers to breach senior US officials’ emails CNN
- Microsoft could have prevented Chinese cloud email hack, US cyber report says The Verge
- Scathing federal report rips Microsoft for shoddy security, insincerity in response to Chinese hack NBC News
- Microsoft could have stopped Chinese cloud email hack: Review panel The Hill
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
3 min
vs 4 min read
Condensed
87%
668 → 90 words
Want the full story? Read the original article
Read on The Hacker News