
"US Cyber Safety Board Condemns Microsoft for Allowing Chinese Hackers to Breach Government Emails"
The U.S. Cyber Safety Review Board has criticized Microsoft for security lapses that allowed a China-based hacker group to breach nearly two dozen companies, faulting the tech giant for deprioritizing enterprise security investments and failing to detect the compromise on its own. Microsoft acknowledged errors in its source code and a compromised engineer's account, leading to unauthorized access and exfiltration of emails. The CSRB recommended cloud service providers to implement modern control mechanisms, adopt incident and vulnerability disclosure practices, and update federal authorization frameworks to safeguard against state-sponsored cyber threats.