Microsoft's lax security blasted by investigators after serious breach

Cascade of failings allowed Chinese hackers to access government emails, says US review board

John Leonard
clock • 3 min read
Microsoft's lax security blasted by investigators after serious breach

A damning report by the US Cyber Safety Review Board (CSRB), has revealed a "cascade of errors and security failures" at Microsoft which allowed a major breach of its systems last year.

The attack, which took place in summer 2023, saw China-linked threat actor Storm-0558 access the Microsoft Exchange Online mailboxes of 22 organisations and more than 500 individuals, including sev...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Microsoft May Patch Tuesday fixes two actively exploited zero days

Threats and Risks

Microsoft has fixed 60 Windows CVEs in its May Patch Tuesday update, two of which are actively exploited zero days. One is a critical vulnerability, earning an 8.8 CVSS rating.

clock 15 May 2024 • 3 min read
Chancellor wants to build $1tn 'British Microsoft'

Leadership

Aims to challenge US giants with looser regulations

clock 14 May 2024 • 3 min read
Microsoft faces renewed antitrust charges in EU over Teams dominance

Compliance

Global unbundling of Teams insufficient concession

clock 14 May 2024 • 2 min read

More on Security

Maritime security: 'Hacking a ship is just like hacking a Tesla but bigger'

Maritime security: 'Hacking a ship is just like hacking a Tesla but bigger'

Cyber attacks on shipping up 400-500% in five years, Lloyds List Intelligence

John Leonard
clock 16 May 2024 • 4 min read
Tories self-refer to ICO over data breach

Tories self-refer to ICO over data breach

Revealed hundreds of personal email addresses by forgetting to BCC

Tom Allen
clock 15 May 2024 • 2 min read
Why cybersecurity staff burn out, and what to do about it

Why cybersecurity staff burn out, and what to do about it

The 'cyber skills gap' results from lack of support, career path and understanding risk

John Leonard
clock 14 May 2024 • 13 min read