{"id":12569,"date":"2024-04-03T11:04:21","date_gmt":"2024-04-03T11:04:21","guid":{"rendered":"https:\/\/demo4.dedicatedhost247.com\/newstime\/microsoft-could-have-prevented-chinese-cloud-email-hack-us-cyber-report-says\/"},"modified":"2024-04-03T11:04:21","modified_gmt":"2024-04-03T11:04:21","slug":"microsoft-could-have-prevented-chinese-cloud-email-hack-us-cyber-report-says","status":"publish","type":"post","link":"https:\/\/demo4.dedicatedhost247.com\/newstime\/microsoft-could-have-prevented-chinese-cloud-email-hack-us-cyber-report-says\/","title":{"rendered":"Microsoft could have prevented Chinese cloud email hack, US cyber report says"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">A new report from the US Cyber Safety Review Board has found that Microsoft <a href=\"https:\/\/www.dhs.gov\/news\/2024\/04\/02\/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer\">could have prevented<\/a> Chinese hackers from breaching US government emails through its Microsoft Exchange Online software last year. <a href=\"https:\/\/www.theverge.com\/2023\/7\/12\/23792371\/security-breach-china-us-government-emails-microsoft-cloud-exploit\">The incident<\/a>, described as a \u201ccascade of security failures\u201d at Microsoft, allowed Chinese state-sponsored hackers to access online email inboxes of 22 organizations, affecting more than 500 people including US government employees working on national security.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The US Department of Homeland Security (DHS) has released a <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2024-04\/CSRB_Review_of_the_Summer_2023_MEO_Intrusion_Final_508c.pdf\">scathing report<\/a> that found that the hack was \u201cpreventable\u201d and that a number of decisions inside Microsoft contributed to \u201ca corporate culture that deprioritized enterprise security investments and rigorous risk management.\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The hackers used an acquired Microsoft account (MSA) consumer key to forge tokens to access Outlook on the web (OWA) and Outlook.com. The report makes it clear that Microsoft still isn\u2019t sure <em>exactly <\/em>how the key was stolen, but the leading theory is that the key was part of a crash dump. Microsoft published that theory in September, and recently <a href=\"https:\/\/msrc.microsoft.com\/blog\/2023\/09\/results-of-major-technical-investigations-for-storm-0558-key-acquisition\/\">updated its blog post<\/a> to admit \u201cwe have not found a crash dump containing the impacted key material.\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Without access to that crash dump, Microsoft can\u2019t be sure exactly how the key was stolen. \u201cOur leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account,\u201d says Microsoft in its updated blog post.<\/p>\n<\/div>\n<div>\n<div class=\"my-9\">\n<p><figcaption class=\"duet--article--dangerously-set-cms-markup inline text-gray-13 dark:text-gray-e9 [&amp;&gt;a:hover]:text-black [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-e9 dark:[&amp;&gt;a:hover]:shadow-underline-gray-63 [&amp;&gt;a]:shadow-underline-gray-13 dark:[&amp;&gt;a]:shadow-underline-gray-63\"><em>The timeline of the Microsoft Exchange Online hack.<\/em><\/figcaption><cite class=\"duet--article--dangerously-set-cms-markup inline not-italic text-gray-63 dark:text-gray-bd [&amp;&gt;a:hover]:text-gray-63 [&amp;&gt;a:hover]:shadow-underline-black dark:[&amp;&gt;a:hover]:text-gray-bd dark:[&amp;&gt;a:hover]:shadow-underline-gray [&amp;&gt;a]:shadow-underline-gray-63 dark:[&amp;&gt;a]:text-gray-bd dark:[&amp;&gt;a]:shadow-underline-gray\">Image: Microsoft<\/cite><\/p>\n<\/div>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft acknowledged to the Cyber Safety Review Board in November that its September blog post was inaccurate, but it was only corrected months later on March 12th \u201cafter the Board\u2019s repeated questioning about Microsoft\u2019s plans to issue a correction.\u201d While Microsoft fully cooperated with the board\u2019s investigation, the conclusion is that Microsoft\u2019s security culture needs an overhaul.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cThe Board finds that this intrusion was preventable and should never have occurred,\u201d says the Cyber Safety Review Board. \u201cThe Board also concludes that Microsoft\u2019s security culture was inadequate and requires an overhaul, particularly in light of the company\u2019s centrality in the technology ecosystem and the level of trust customers place in the company to protect their data and operations.\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The findings from the board come in the same week that Microsoft has <a href=\"https:\/\/www.theverge.com\/2024\/3\/13\/24099670\/microsoft-copilot-for-security-pricing-launch-date-features\">launched its Copilot for Security<\/a>, an AI-powered chatbot designed for cybersecurity professionals. Microsoft is charging businesses $4 per hour of usage as part of a consumption model to access this latest AI tool, just as the company struggles with an ongoing attack from Russian state-sponsored hackers. <\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Nobelium, the same group behind the\u00a0<a href=\"https:\/\/www.theverge.com\/2020\/12\/13\/22173035\/hackers-russia-breached-us-government-agencies-email-cozy-bear\">SolarWinds attack<\/a>, managed to <a href=\"https:\/\/www.theverge.com\/2024\/1\/19\/24044561\/microsoft-senior-leadership-emails-hack-russian-security-attack\">spy on some<\/a> Microsoft executive email inboxes for months. That initial intrusion also led to some of Microsoft\u2019s source code being stolen, with Microsoft admitting recently that the group <a href=\"https:\/\/www.theverge.com\/2024\/3\/8\/24094287\/microsoft-hack-russian-security-attack-stolen-source-code\">accessed the company\u2019s source code<\/a> repositories and internal systems.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft is now attempting to <a href=\"https:\/\/www.theverge.com\/2023\/11\/2\/23943178\/microsoft-security-secure-future-initiative-cybersecurity\">overhaul its software security<\/a>\u00a0following the breach of US government emails last year and <a href=\"https:\/\/www.theverge.com\/2021\/3\/5\/22316189\/microsoft-exchange-server-security-exploit-china-attack-30000-organizations\">similar cybersecurity attacks<\/a> in recent years. Microsoft\u2019s new Secure Future Initiative (SFI) is designed to overhaul how it designs, builds, tests, and operates its software and services. It\u2019s the biggest change to Microsoft\u2019s security efforts since the company introduced its Security Development Lifecycle (SDL) in 2004 after the devastating Blaster worm that hit Windows XP machines offline in 2003.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2024\/4\/3\/24119787\/microsoft-cloud-email-hack-china-us-cyber-report\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new report from the US Cyber Safety Review Board has found that Microsoft could have prevented Chinese hackers from<\/p>\n","protected":false},"author":1,"featured_media":12570,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[],"_links":{"self":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts\/12569"}],"collection":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/comments?post=12569"}],"version-history":[{"count":0,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/posts\/12569\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/media\/12570"}],"wp:attachment":[{"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/media?parent=12569"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/categories?post=12569"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/demo4.dedicatedhost247.com\/newstime\/wp-json\/wp\/v2\/tags?post=12569"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}