-
Iran, US trade blows as Hormuz impasse deepens
-
'Our year': Kane and Bayern primed for Champions League tilt
-
The round-the-clock monitors protecting Bhutan from glacier risk
-
Australian World Cup star Volpato fined over positive cocaine test
-
'Hell': Father of surfers killed in Mexico testifies at trial
-
Sabalenka edges Noskova to keep US Open treble bid alive
-
Travellers in UK face more chaos after air traffic control glitch
-
Pegula outlasts Navarro to set US Open semi with Sabalenka
-
Crude pushes towards $100 on Mideast flare-up, fanning inflation fears
-
From trenches to catwalk: Ukraine's amputee soldiers hit the runway
-
Record rain forces Asian Games athletes to evacuate accommodation
-
UK airports face more disruption after air traffic control glitch
-
Amusing or addictive? The algorithms powering our social feeds
-
ECB meets, weighing a tricky balance between savers and spenders
-
Norway bids farewell to King Harald V, 'grandfather' of the nation
-
Pakistan police counter drone attacks with Ukraine-style nets
-
NFL breaks new ground as 100,000 set to pack MCG in Australia
-
Russia torments Kyiv with new 'horror' jet drones
-
EU faces revolt over social media ban for children
-
Iran attacks US base in Jordan as Hormuz impasse deepens
-
Canada eyes researchers looking to leave 'hostile' US
-
New Apple CEO to face first test with foldable iPhone launch
-
Tiafoe escapes Michelsen to reach US Open semi-finals
-
BrYet Announces AIFA Approval of First-In-Kind cGMP Manufacturing Line for ML-016, Enabling Imminent Clinical Supply to Australia
-
Sabalenka edges Noskova, keeps US Open treble bid alive
-
Carney touts Canada 'pivot' away from US as Trump levels new threat
-
Real Madrid win Champions League opener as Haaland stars for Man City
-
Pounding waves open up sinkhole in swanky Malibu
-
Gambian leader vows power boost after violent blackout protests
-
LIV Golf files for bankruptcy protection
-
Newcastle battle past Millwall to reach League Cup fourth round
-
Argentina launches legal action against oil firms for Falklands drilling
-
Mourinho's Real Madrid make winning start against Inter Milan
-
Haaland double powers Man City to victory over Porto
-
Villa take 'big step forward' with win over Brugge
-
Sabalenka survives Noskova to return to US Open semi-finals
-
Yaya Toure hails 'new era' for African coaches ahead of Champions League bow
-
'South Park' changes name in dig at Trump
-
Lawes and Marchant told to prove themselves in quest for England recalls
-
OpenAI says AI solved one of math's hardest problems in days
-
Smithsonian secretary to retire as Trump exerts control over institution
-
Nearly 1,100 flights cancelled after UK air traffic control glitch
-
Atletico have work to do to reach home Champions League final: Simeone
-
Sabalenka holds off Noskova to keep US Open three-peat bid alive
-
Villa end goal drought to beat Brugge in Champions League opener
-
Rein in social media not children, say over 130 groups, experts
-
McIlroy says 'we'll keep our heads down and play' in event of Trump golf visit
-
Hong Kong's first post-colonial leader Tung Chee-hwa dies aged 89
-
Sabalenka holds of Noskova to reach US Open semi-finals
-
Rangers captain Shankland sidelined for up to four months
Microsoft faces heat from US Congress over cybersecurity
Members of US Congress on Thursday pressed Microsoft to explain a "cascade of avoidable errors" that allowed a Chinese hacking group to breach emails of senior US officials.
Microsoft President Brad Smith spent more than three hours answering questions from members of the House Committee on Homeland Security in Washington, assuring them cybersecurity is being woven more deeply into the technology company's culture.
"Microsoft accepts responsibility for each and every one of the issues cited" in a scathing US government report about the breach "without equivocation or hesitation," Smith told the committee.
The Cyber Safety Review Board (CSRB), led by the US Department of Homeland Security, conducted a seven-month investigation into the incident last year that involved the China-affiliated cyberespionage actor Storm-0558.
"Microsoft has an enormous footprint in both government and critical infrastructure networks," US congressman and committee member Bennie Thompson said to Smith as the hearing opened.
"It is our shared interest that the security issues raised by the (report) be addressed quickly."
The operation, which was first discovered by the US State Department in June 2023, included hacks on the official and personal mailboxes of Commerce Secretary Gina Raimondo and US Ambassador to China Nicholas Burns.
Microsoft's core business is to provide cloud computing services, such as Azure or Office360, that host sensitive data and power business and government operations across major sectors of the economy.
The report criticized a Microsoft corporate culture that was "at odds with... the level of trust customers place in the company."
The review identified a series of operational and strategic decisions by Microsoft that opened the door to the breach, including the failure to identify a new employee's compromised laptop following a corporate acquisition in 2021.
It also found that Microsoft fell short of safety standards seen at competing cloud companies, including Google, Amazon and Oracle.
"The Board finds that this intrusion was preventable and should never have occurred," the review said, pinpointing "the cascade of Microsoft's avoidable errors that allowed this intrusion to succeed."
- 'Lasting change' -
The report also recommended that Microsoft develop and publicly release a plan with timelines to enact wide-ranging security reforms across its products and practices.
"The real challenge is how you achieve effective lasting cultural change," Smith said, noting Microsoft has nearly 226,000 employees.
Smith said Microsoft has the equivalent of 34,000 engineers working full time on answering the security shortcomings in "the largest engineering project focused on cybersecurity in the history of digital technology."
Microsoft's board on Wednesday approved a change that will tie cybersecurity accomplishments with annual bonuses for senior executives and make it part of every employee's annual review, according to Smith.
Microsoft detects some 300 million cyberattacks on its customers daily, with most of those coming from China, Iran, Korea, Russia, or ransomware operations, Smith told the committee.
"We're dealing with four formidable foes in China, Russia, North Korea and Iran, and they are getting better," Smith said.
"We should expect them to work together; they're waging attacks at an extraordinary rate."
While it is inevitable that adversaries will use artificial intelligence for increasingly sophisticated attacks, the technology is already being used to strengthen cyber defenses, Smith added.
H.Gonzales--AT