Thursday, 16 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Microsoft could have prevented Chinese cloud email hack, US cyber report says
Security

Microsoft could have prevented Chinese cloud email hack, US cyber report says

Last updated: April 3, 2024 1:28 pm
Published April 3, 2024
Share
Microsoft could have prevented Chinese cloud email hack, US cyber report says
SHARE

A brand new report from the US Cyber Security Overview Board has discovered that Microsoft might have prevented Chinese language hackers from breaching US authorities emails via its Microsoft Change On-line software program final yr. The incident, described as a “cascade of safety failures” at Microsoft, allowed Chinese language state-sponsored hackers to entry on-line e mail inboxes of twenty-two organizations, affecting greater than 500 folks together with US authorities staff engaged on nationwide safety.

The US Division of Homeland Safety (DHS) has launched a scathing report that discovered that the hack was “preventable” and that various choices inside Microsoft contributed to “a company tradition that deprioritized enterprise safety investments and rigorous threat administration.”

The hackers used an acquired Microsoft account (MSA) shopper key to forge tokens to entry Outlook on the internet (OWA) and Outlook.com. The report makes it clear that Microsoft nonetheless isn’t certain precisely how the important thing was stolen, however the main idea is that the important thing was a part of a crash dump. Microsoft printed that idea in September, and not too long ago up to date its weblog publish to confess “we’ve got not discovered a crash dump containing the impacted key materials.”

With out entry to that crash dump, Microsoft can’t make certain precisely how the important thing was stolen. “Our main speculation stays that operational errors resulted in key materials leaving the safe token signing atmosphere that was subsequently accessed in a debugging atmosphere through a compromised engineering account,” says Microsoft in its up to date weblog publish.

The timeline of the Microsoft Change On-line hack.
Picture: Microsoft

Microsoft acknowledged to the Cyber Security Overview Board in November that its September weblog publish was inaccurate, but it surely was solely corrected months in a while March twelfth “after the Board’s repeated questioning about Microsoft’s plans to problem a correction.” Whereas Microsoft absolutely cooperated with the board’s investigation, the conclusion is that Microsoft’s safety tradition wants an overhaul.

See also  What’s going on with cloud finops?

“The Board finds that this intrusion was preventable and will by no means have occurred,” says the Cyber Security Overview Board. “The Board additionally concludes that Microsoft’s safety tradition was insufficient and requires an overhaul, significantly in gentle of the corporate’s centrality within the know-how ecosystem and the extent of belief prospects place within the firm to guard their knowledge and operations.”

The findings from the board are available in the identical week that Microsoft has launched its Copilot for Safety, an AI-powered chatbot designed for cybersecurity professionals. Microsoft is charging companies $4 per hour of utilization as a part of a consumption mannequin to entry this newest AI instrument, simply as the corporate struggles with an ongoing assault from Russian state-sponsored hackers.

Nobelium, the identical group behind the SolarWinds assault, managed to spy on some Microsoft government e mail inboxes for months. That preliminary intrusion additionally led to a few of Microsoft’s supply code being stolen, with Microsoft admitting not too long ago that the group accessed the corporate’s supply code repositories and inner techniques.

Microsoft is now making an attempt to overtake its software program safety following the breach of US authorities emails final yr and related cybersecurity assaults in recent times. Microsoft’s new Safe Future Initiative (SFI) is designed to overtake the way it designs, builds, exams, and operates its software program and companies. It’s the most important change to Microsoft’s safety efforts because the firm launched its Safety Growth Lifecycle (SDL) in 2004 after the devastating Blaster worm that hit Home windows XP machines offline in 2003.

See also  AuditBoard's Risk Intelligence Report exposes crucial disconnect in AI implementation

Source link

TAGGED: Chinese, cloud, Cyber, email, hack, Microsoft, prevented, report
Share This Article
Twitter Email Copy Link Print
Previous Article U.S. Tightens Chip Export Rules to China U.S. Tightens Chip Export Rules to China
Next Article NobleAI NobleAI Raises Over $10M in Series A Extension Funding
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

OnLogic and Scale Computing lead the charge in 2024 edge computing innovations

CRN’s 2024 Edge Computing 100 highlights main corporations in edge computing, together with prime cybersecurity,…

November 7, 2024

IFS launches Emissions Management module in collaboration with Climatiq

IFS, famend for its enterprise cloud and Industrial AI software program, has strategically partnered with…

August 1, 2025

How AI helped refine Hungarian accents in The Brutalist

With regards to films buzzing with Oscar potential, Brady Corbet’s The Brutalist is a standout…

January 24, 2025

Aetina introduces edge AI for transport and public safety at smart city event

Aetina, a supplier of AI options, will showcase its edge AI options on the Smart…

October 28, 2024

An active optical intensity interferometry scheme enables synthetic aperture imaging from over a kilometer away

Picture exhibiting the 1.36 km experimental surroundings. The distant imaging system (left) shoots eight near-infrared…

June 7, 2025

You Might Also Like

5 top cloud migration software for Infrastructure as Code (IaC)
AI

5 top cloud migration software for Infrastructure as Code (IaC)

By saad
OpenNebula releases version 7.2 with updates for AI and cloud infrastructure
Infrastructure

OpenNebula releases version 7.2 with updates for AI and cloud infrastructure

By saad
AI data centre power demand is reshaping cloud growth
Cloud Computing

AI data centre power demand shapes cloud growth

By saad
Leaseweb builds out European sovereign cloud with programmable networking and AI compute
Edge Computing

Leaseweb builds out European sovereign cloud with programmable networking and AI compute

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.