Microsoft called out for ‘blatantly negligent’ cybersecurity practices


Microsoft is facing mounting criticism in the wake of last month’s attack on Azure. In a post on LinkedIn, Amit Yoran, the CEO of the cybersecurity company Tenable, says Microsoft’s cybersecurity track record is “even worse than you think” — and he has an example to back it up.
On July 12th, Microsoft disclosed a major breach targeting its Azure platform, which it traced to a Chinese hacking group known as Storm-0558. The attack affected around 25 different organizations and resulted in the theft of sensitive emails from US government officials. Last week, Senator Ron Wyden (D-OR) sent a letter to the US Department of Justice, asking it hold Microsoft accountable for “negligent cybersecurity practices.”
Yoran has more to add to the senator’s arguments, writing in his post that Microsoft has demonstrated a “repeated pattern of negligent cybersecurity practices,” enabling Chinese hackers to spy on the US government. He also revealed Tenable’s discovery of an additional cybersecurity flaw in Microsoft Azure and says the company took too long to address it.
Tenable initially discovered the flaw in March and found that it could give bad actors access to a company’s sensitive data, including a bank. Yoran claims Microsoft took “more than 90 days to implement a partial fix” after Tenable notified the company, adding that the fix only applies to “new applications loaded in the service.” According to Yoran, the bank and all the other organizations “that had launched the service prior to the fix” are still affected by the flaw — and are likely unaware of that risk.
Yoran says Microsoft plans to fix the issue by the end of September but calls the delayed response “grossly irresponsible, if not blatantly negligent.” He also points to data from Google’s Project Zero, which indicates that Microsoft products have made up 42.5 percent of all discovered zero-day vulnerabilities since 2014.
“What you hear from Microsoft is ‘just trust us,’ but what you get back is very little transparency and a culture of toxic obfuscation,” Yoran writes. “How can a CISO, board of directors or executive team believe that Microsoft will do the right thing given the fact patterns and current behaviors?”
Microsoft senior director Jeff Jones responded to Yoran’s criticism in an emailed statement to The Verge:
We appreciate the collaboration with the security community to responsibly disclose product issues. We follow an extensive process involving a thorough investigation, update development for all versions of affected products, and compatibility testing among other operating systems and applications. Ultimately, developing a security update is a delicate balance between timeliness and quality, while ensuring maximized customer protection with minimized customer disruption.
Microsoft is facing mounting criticism in the wake of last month’s attack on Azure. In a post on LinkedIn, Amit Yoran, the CEO of the cybersecurity company Tenable, says Microsoft’s cybersecurity track record is “even worse than you think” — and he has an example to back it up. On…
Recent Posts
- Die in the Dungeon will keep you busy until Slay the Spire 2
- Sana Grain Mill Review: Makes Specialty Flours a Piece of Cake
- I tested an ultra-cheap Dolby Atmos soundbar against a premium alternative, here’s why it’s worth spending the extra cash
- ‘Revolutionary’ Wi-Fi router which can send data up to 10 miles away goes on sale for less than $100 – just make sure you’re happy with the 32Mbps speed
- The Humane Ai Pin Will Become E-Waste Next Week
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010