Microsoft faces heat from US Congress over cybersecurity

Microsoft President Brad Smith testifies before a U.S. House Homeland Security Committee hearing. (Reuters)
Short Url
Updated 14 June 2024
Follow

Microsoft faces heat from US Congress over cybersecurity

  • A report criticized a Microsoft corporate culture that was “at odds with... the level of trust customers place in the company.”

WASHINGTON: Members of US Congress on Thursday pressed Microsoft to explain a “cascade of avoidable errors” that allowed a Chinese hacking group to breach emails of senior US officials.
Microsoft President Brad Smith spent more than three hours answering questions from members of the House Committee on Homeland Security in Washington, assuring them cybersecurity is being woven more deeply into the technology company’s culture.
“Microsoft accepts responsibility for each and every one of the issues cited” in a scathing US government report about the breach “without equivocation or hesitation,” Smith told the committee.
The Cyber Safety Review Board (CSRB), led by the US Department of Homeland Security, conducted a seven-month investigation into the incident last year that involved the China-affiliated cyberespionage actor Storm-0558.
“Microsoft has an enormous footprint in both government and critical infrastructure networks,” US congressman and committee member Bennie Thompson said to Smith as the hearing opened.
“It is our shared interest that the security issues raised by the (report) be addressed quickly.”
The operation, which was first discovered by the US State Department in June 2023, included hacks on the official and personal mailboxes of Commerce Secretary Gina Raimondo and US Ambassador to China Nicholas Burns.
Microsoft’s core business is to provide cloud computing services, such as Azure or Office360, that host sensitive data and power business and government operations across major sectors of the economy.
The report criticized a Microsoft corporate culture that was “at odds with... the level of trust customers place in the company.”
The review identified a series of operational and strategic decisions by Microsoft that opened the door to the breach, including the failure to identify a new employee’s compromised laptop following a corporate acquisition in 2021.
It also found that Microsoft fell short of safety standards seen at competing cloud companies, including Google, Amazon and Oracle.
“The Board finds that this intrusion was preventable and should never have occurred,” the review said, pinpointing “the cascade of Microsoft’s avoidable errors that allowed this intrusion to succeed.”
The report also recommended that Microsoft develop and publicly release a plan with timelines to enact wide-ranging security reforms across its products and practices.
“The real challenge is how you achieve effective lasting cultural change,” Smith said, noting Microsoft has nearly 226,000 employees.
Smith said Microsoft has the equivalent of 34,000 engineers working full time on answering the security shortcomings in “the largest engineering project focused on cybersecurity in the history of digital technology.”
Microsoft’s board on Wednesday approved a change that will tie cybersecurity accomplishments with annual bonuses for senior executives and make it part of every employee’s annual review, according to Smith.
Microsoft detects some 300 million cyberattacks on its customers daily, with most of those coming from China, Iran, Korea, Russia, or ransomware operations, Smith told the committee.
“We’re dealing with four formidable foes in China, Russia, North Korea and Iran, and they are getting better,” Smith said.
“We should expect them to work together; they’re waging attacks at an extraordinary rate.”
While it is inevitable that adversaries will use artificial intelligence for increasingly sophisticated attacks, the technology is already being used to strengthen cyber defenses, Smith added.


Bangladesh’s religio-political party open to unity govt

Updated 01 January 2026
Follow

Bangladesh’s religio-political party open to unity govt

  • Opinion polls suggest that Jamaat-e-Islami will finish a close second to the Bangladesh Nationalist Party in the first election it has contested in nearly 17 years

DHAKA: A once-banned Bangladeshi religio-political party, poised for its strongest electoral showing in February’s parliamentary vote, is open to joining a unity government and has held talks with several parties, its chief said.

Opinion polls suggest that Jamaat-e-Islami will finish a close second to the Bangladesh Nationalist Party in the first election it has contested in nearly 17 years as it marks a return to mainstream politics in the predominantly Muslim nation of 175 million.

Jamaat last held power between 2001 and 2006 as a junior coalition partner with the BNP and is open to working with it again.

“We want to see a stable nation for at least five years. If the parties come together, we’ll run the government together,” Jamaat chief Shafiqur Rahman said in an interview at his office in a residential area in Dhaka, ‌days after the ‌party created a buzz by securing a tie-up with a Gen-Z party.

Rahman said anti-corruption must be a shared agenda for any unity government.

The prime minister will come from the party winning the most seats in the Feb. 12 election, he added. If Jamaat wins the most seats, the party will decide whether he himself would be a candidate, Rahman said.

The party’s resurgence follows the ousting of long-time Prime Minister Sheikh Hasina in a youth-led uprising in August 2024. 

Rahman said Hasina’s continued stay in India after fleeing Dhaka was a concern, as ties between the two countries have hit their lowest point in decades since her downfall.

Asked about Jamaat’s historical closeness to Pakistan, Rahman said: “We maintain relations in a balanced way with all.”

He said any government that includes Jamaat would “not feel comfortable” with President Mohammed Shahabuddin, who was elected unopposed with the Awami League’s backing in 2023.