Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Exclusive: This is Wiim’s first wireless speaker

14 May 2025

A VPN Company Canceled All Lifetime Subscriptions, Claiming It Didn’t Know About Them

14 May 2025

2025 Nintendo Switch 2 Game Release Schedule

14 May 2025
Facebook X (Twitter) Instagram
Just In
  • Exclusive: This is Wiim’s first wireless speaker
  • A VPN Company Canceled All Lifetime Subscriptions, Claiming It Didn’t Know About Them
  • 2025 Nintendo Switch 2 Game Release Schedule
  • Sony WH-1000XM6 are confirmed, so the XM5s are on sale
  • Airbnb Is in Midlife Crisis Mode
  • iPhone Could Get AI-Powered Battery Management Mode With iOS 19: Report
  • Bravely Default HD Remaster shows the party potential of Switch 2’s mouse controls
  • iQOO Neo 10 India Price Range, AnTuTu Score Revealed Ahead of May 26 Launch; Specifications Teased
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » The US Government Has a Microsoft Problem
News

The US Government Has a Microsoft Problem

News RoomBy News Room15 April 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

These incidents occurred as security experts were increasingly criticizing Microsoft for failing to promptly and adequately fix flaws in its products. As by far the biggest technology provider for the US government, Microsoft vulnerabilities account for the lion’s share of both newly discovered and most widely used software flaws. Many experts say Microsoft is refusing to make the necessary cybersecurity improvements to keep up with evolving challenges.

Microsoft hasn’t “adapted their level of security investment and their mindset to fit the threat,” says one prominent cyber policy expert. “It’s a huge fuckup by somebody that has the resources and the internal engineering capacity that Microsoft does.”

The Department of Homeland Security’s CSRB endorsed this view in its new report on the 2023 Chinese intrusion, saying Microsoft exhibited “a corporate culture that deprioritized both enterprise security investments and rigorous risk management.” The report also criticized Microsoft for publishing inaccurate information about the possible causes of the latest Chinese intrusion.

The recent breaches reveal Microsoft’s failure to implement basic security defenses, according to multiple experts.

Adam Meyers, senior vice president of intelligence at the security firm CrowdStrike, points to the Russians’ ability to jump from a testing environment to a production environment. “That should never happen,” he says. Another cyber expert who works at a Microsoft competitor highlighted China’s ability to snoop on multiple agencies’ communications through one intrusion, echoing the CSRB report, which criticized Microsoft’s authentication system for allowing broad access with a single sign-in key.

“You don’t hear about these types of breaches coming out of other cloud service providers,” Meyers says.

According to the CSRB report, Microsoft has “not sufficiently prioritized rearchitecting its legacy infrastructure to address the current threat landscape.”

In response to written questions, Microsoft tells WIRED that it’s aggressively improving its security to address recent incidents.

“We are committed to adapting to the evolving threat landscape and partnering across industry and government to defend against these growing and sophisticated global threats,” says Steve Faehl, chief technology officer for Microsoft’s federal security business.

As part of its Secure Future Initiative launched in November, Faehl says, Microsoft has improved its ability to automatically detect and block abuses of employee accounts, begun scanning for more types of sensitive information in network traffic, reduced the access granted by individual authentication keys, and created new authorization requirements for employees seeking to create company accounts.

Microsoft has also redeployed “thousands of engineers” to improve its products and has begun convening senior executives for status updates at least twice weekly, Faehl says.

The new initiative represents Microsoft’s “roadmap and commitments to answer much of what the CSRB report called out as priorities,” Faehl says. Still, Microsoft does not accept that its security culture is broken, as the CSRB report argues. “We very much disagree with this characterization,” Faehl says, “though we do agree that we haven’t been perfect and have work to do.”

A Security Revenue ‘Addiction’

Microsoft has earned special enmity from the cybersecurity community for charging its customers extra for better security protections like threat monitoring, antivirus, and user access management. In January 2023, the company touted that its security division had passed $20 billion in annual revenue.

“Microsoft has shifted to looking at cybersecurity as something that’s meant to generate revenue for them,” says Juan Andrés Guerrero-Saade, associate vice president of research at security firm SentinelOne. His colleague Alex Stamos recently wrote that Microsoft’s “addiction” to this revenue “has seriously warped their product design decisions.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleXiaomi 14T, Xiaomi 14T Pro Reference Spotted on HyperOS Code, Unlikely to Launch in India: Report
Next Article Smite 2 Founder’s Editions available now, closed alpha coming in May

Related Articles

News

Exclusive: This is Wiim’s first wireless speaker

14 May 2025
News

A VPN Company Canceled All Lifetime Subscriptions, Claiming It Didn’t Know About Them

14 May 2025
News

Sony WH-1000XM6 are confirmed, so the XM5s are on sale

13 May 2025
News

Airbnb Is in Midlife Crisis Mode

13 May 2025
News

Bravely Default HD Remaster shows the party potential of Switch 2’s mouse controls

13 May 2025
News

2026 BMW iX first drive: I expected BMW to tone things down, but thankfully it didn’t

13 May 2025
Demo
Top Articles

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202457 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Phones

iPhone Could Get AI-Powered Battery Management Mode With iOS 19: Report

News Room13 May 2025
News

Bravely Default HD Remaster shows the party potential of Switch 2’s mouse controls

News Room13 May 2025
Phones

iQOO Neo 10 India Price Range, AnTuTu Score Revealed Ahead of May 26 Launch; Specifications Teased

News Room13 May 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025120 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202493 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 202486 Views
Our Picks

Sony WH-1000XM6 are confirmed, so the XM5s are on sale

13 May 2025

Airbnb Is in Midlife Crisis Mode

13 May 2025

iPhone Could Get AI-Powered Battery Management Mode With iOS 19: Report

13 May 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.