{"id":29699,"date":"2023-08-03T22:19:02","date_gmt":"2023-08-03T22:19:02","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/08\/03\/microsoft-called-out-for-blatantly-negligent-cybersecurity-practices\/"},"modified":"2023-08-03T22:19:02","modified_gmt":"2023-08-03T22:19:02","slug":"microsoft-called-out-for-blatantly-negligent-cybersecurity-practices","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/08\/03\/microsoft-called-out-for-blatantly-negligent-cybersecurity-practices\/","title":{"rendered":"Microsoft called out for \u201cblatantly negligent\u201d cybersecurity practices"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft is facing mounting criticism in the wake of last month\u2019s attack on Azure. <a href=\"https:\/\/www.linkedin.com\/pulse\/microsoftthe-truth-even-worse-than-you-think-amit-yoran%3FtrackingId=hE4qd2mSSwmpSoVPqfWAAw%253D%253D\/?_l=en_US\" target=\"_blank\" rel=\"noopener\">In a post on LinkedIn<\/a>, Amit Yoran, the CEO of the cybersecurity company Tenable, says Microsoft\u2019s cybersecurity track record is \u201ceven worse than you think\u201d \u2014 and he has an example to back it up.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">On July 12th, <a href=\"https:\/\/www.theverge.com\/2023\/7\/12\/23792371\/security-breach-china-us-government-emails-microsoft-cloud-exploit\" target=\"_blank\" rel=\"noopener\">Microsoft disclosed a major breach<\/a> targeting its Azure platform, which it traced to a Chinese hacking group known as Storm-0558. The attack affected around 25 different organizations and resulted in the theft of sensitive emails from US government officials. Last week, Senator Ron Wyden (D-OR) <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/wyden_letter_to_cisa_doj_ftc_re_2023_microsoft_breach.pdf\" target=\"_blank\" rel=\"noopener\">sent a letter<\/a> to the US Department of Justice, asking it hold Microsoft accountable for \u201cnegligent cybersecurity practices.\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Yoran has more to add to the senator\u2019s arguments, writing in his post that Microsoft has demonstrated a \u201crepeated pattern of negligent cybersecurity practices,\u201d enabling Chinese hackers to spy on the US government. He also revealed Tenable\u2019s discovery of an <a href=\"https:\/\/www.tenable.com\/security\/research\/tra-2023-25?x-clickref=1011lxHkyXa3&amp;x-promotion-id=afffiliate\" target=\"_blank\" rel=\"noopener\">additional cybersecurity flaw<\/a> in Microsoft Azure and says the company took too long to address it.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Tenable initially discovered the flaw in March and found that it could give bad actors access to a company\u2019s sensitive data, including a bank. Yoran claims Microsoft took \u201cmore than 90 days to implement a partial fix\u201d after Tenable notified the company, adding that the fix only applies to \u201cnew applications loaded in the service.\u201d According to Yoran, the bank and all the other organizations \u201cthat had launched the service prior to the fix\u201d are still affected by the flaw \u2014 and are likely unaware of that risk.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Yoran says Microsoft plans to fix the issue by the end of September but calls the delayed response \u201cgrossly irresponsible, if not blatantly negligent.\u201d He also points to data from Google\u2019s Project Zero, which indicates that Microsoft products have made up 42.5 percent of all discovered zero-day vulnerabilities since 2014.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cWhat you hear from Microsoft is \u2018just trust us,\u2019 but what you get back is very little transparency and a culture of toxic obfuscation,\u201d Yoran writes. \u201cHow can a CISO, board of directors or executive team believe that Microsoft will do the right thing given the fact patterns and current behaviors?\u201d<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Microsoft senior director Jeff Jones responded to Yoran\u2019s criticism in an emailed statement to <em>The Verge<\/em>:<\/p>\n<\/div>\n<div>\n<blockquote class=\"duet--article--blockquote ewrhy30\">\n<p class=\"duet--article--dangerously-set-cms-markup ewrhy37 _1xwtict0\">We appreciate the collaboration with the security community to responsibly disclose product issues. We follow an extensive process involving a thorough investigation, update development for all versions of affected products, and compatibility testing among other operating systems and applications. Ultimately, developing a security update is a delicate balance between timeliness and quality, while ensuring maximized customer protection with minimized customer disruption.<\/p>\n<\/blockquote>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2023\/8\/3\/23819237\/microsoft-azure-breach-blatantly-negligent-cybersecurity-practices\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft is facing mounting criticism in the wake of last month\u2019s attack on Azure. In a post on LinkedIn, Amit Yoran, the CEO of the cybersecurity company Tenable, says Microsoft\u2019s cybersecurity track record is \u201ceven worse than you think\u201d \u2014 and he has an example to back it up. On July 12th, Microsoft disclosed a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29700,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-29699","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/29699","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=29699"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/29699\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/29700"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=29699"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=29699"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=29699"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}