logo

Feds to Microsoft: Clean Up Your Cloud Security Act Now

ID: 664d53fa-1b11-557a-95a7-d078d1a67641

STIX ID: report--664d53fa-1b11-557a-95a7-d078d1a67641

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-04-03

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

The DHS Cyber Safety Review Board concluded that Microsoft’s security failures enabled China-based Storm-0558 to breach Microsoft 365 accounts by using a compromised Microsoft consumer signing key to forge Azure AD tokens, affecting email accounts across ~25 government agencies; the board calls for Microsoft to prioritize cloud security, remove paywalled logging, hold leadership accountable, and publish a timeline for security-focused reforms while Microsoft announces a "Secure Future Initiative."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.