logo

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

ID: 39b9a3b0-c008-5276-886b-2c1a7966f703

STIX ID: report--39b9a3b0-c008-5276-886b-2c1a7966f703

Feed Name: The Register (Security)

Date Published: 2024-04-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

This article analyzes the CSRB’s harsh critique of Microsoft’s security failures—highlighting incidents tied to China’s Storm-0558 and Russia’s Cozy Bear—and argues that despite repeated breaches, the U.S. government remains heavily dependent on Microsoft. It amplifies Senator Ron Wyden’s calls for strict, auditable cybersecurity standards and accountability for vendors and executives, while noting that federal procurement dynamics and Microsoft’s market position make replacement unlikely. The piece references a pattern of past compromises (SolarWinds, Lapsus$, Storm-0558, Cozy Bear) and contends that Microsoft’s continued federal revenue faces little risk absent stronger enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.