Feds to Microsoft: Clean Up Your Cloud Security Act Now
ID: 664d53fa-1b11-557a-95a7-d078d1a67641
STIX ID: report--664d53fa-1b11-557a-95a7-d078d1a67641
Feed Name: Dark Reading
Date Published: 2024-04-03
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
The DHS Cyber Safety Review Board concluded that Microsoft’s security failures enabled China-based Storm-0558 to breach Microsoft 365 accounts by using a compromised Microsoft consumer signing key to forge Azure AD tokens, affecting email accounts across ~25 government agencies; the board calls for Microsoft to prioritize cloud security, remove paywalled logging, hold leadership accountable, and publish a timeline for security-focused reforms while Microsoft announces a "Secure Future Initiative."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
