- General strike in Greece against cost of living
- Magritte painting nets auction record of $121 million
- Markets fluctuate as traders weigh geopolitical tensions
- Japanese, Koreans bottom of global love life survey
- Japan ramps up tech ambitions with $65 bn for AI, chips
- Taliban govt clearing 'un-Islamic' books from Afghanistan shelves
- Asian markets struggle as traders weigh geopolitical tensions
- Iraq holds its first census in nearly 40 years
- SpaceX fails to repeat Starship booster catch, as Trump watches on
- European powers, US seek to censure Iran at UN nuclear watchdog board
- SpaceX fails to repeat Starship booster catch, as Trump looks on
- European stocks fall on Ukraine-Russia fears, US focused on earnings
- Trump names China hawk Howard Lutnick commerce secretary
- SpaceX set for Starship's next flight -- with Trump watching
- Top-selling daily French daily Ouest-France stops posting on X
- Russian invasion toll on environment $71 billion, Ukraine says
- New Botswana leader eyes cannabis, sunshine to lift economy
- China's Xi urges 'strategic' ties in talks with Germany's Scholz
- COP29 negotiators strive for deal after G20 'marching orders'
- Walmart lifts full-year forecast after strong Q3
- Son of Norwegian princess arrested on suspicion of rape
- US lawmaker accuses Azerbaijan in near 'assault' at COP29
- Spain royals to visit flood epicentre after chaotic trip: media
- French farmers step up protests against EU-Mercosur deal
- Burst dike leaves Filipino farmers under water
- Markets rally after US bounce as Nvidia comes into focus
- Crisis-hit Thyssenkrupp books another hefty annual loss
- Farmers descend on London to overturn inheritance tax change
- Floods strike thousands of houses in northern Philippines
- SpaceX set for Starship's next flight, Trump expected to attend
- Several children injured in car crash at central China school
- Urban mosquito sparks malaria surge in East Africa
- Many children injured after car crashes at central China school: state media
- Asian markets rally after US bounce as Nvidia comes into focus
- Tens of thousands march in New Zealand Maori rights protest
- Five takeaways from the G20 summit in Rio
- Parts of Great Barrier Reef suffer highest coral mortality on record
- Defiant Lebanese harvest olives in the shadow of war
- Divided G20 fails to agree on climate, Ukraine
- Can the Trump-Musk 'bromance' last?
- US to call for Google to sell Chrome browser: report
- Trump expected to attend next Starship rocket launch: reports
- Stocks, dollar hesitant as traders brace for Nvidia earnings
- Biden in 'historic' pledge for poor nations ahead of Trump return
- Tropical storm Sara kills four in Honduras and Nicaragua
- Spanish resort to ban new holiday flats in 43 neighbourhoods
- Phone documentary details Afghan women's struggle under Taliban govt
- G20 wrestles with wars, 'turbulence' in run-up to Trump
- Stocks, dollar hesitant as traders eye US rate outlook, Nvidia
- G20 wrestles with wars, climate in run-up to Trump
Microsoft faces heat from US Congress over cybersecurity
Members of US Congress on Thursday pressed Microsoft to explain a "cascade of avoidable errors" that allowed a Chinese hacking group to breach emails of senior US officials.
Microsoft President Brad Smith spent more than three hours answering questions from members of the House Committee on Homeland Security in Washington, assuring them cybersecurity is being woven more deeply into the technology company's culture.
"Microsoft accepts responsibility for each and every one of the issues cited" in a scathing US government report about the breach "without equivocation or hesitation," Smith told the committee.
The Cyber Safety Review Board (CSRB), led by the US Department of Homeland Security, conducted a seven-month investigation into the incident last year that involved the China-affiliated cyberespionage actor Storm-0558.
"Microsoft has an enormous footprint in both government and critical infrastructure networks," US congressman and committee member Bennie Thompson said to Smith as the hearing opened.
"It is our shared interest that the security issues raised by the (report) be addressed quickly."
The operation, which was first discovered by the US State Department in June 2023, included hacks on the official and personal mailboxes of Commerce Secretary Gina Raimondo and US Ambassador to China Nicholas Burns.
Microsoft's core business is to provide cloud computing services, such as Azure or Office360, that host sensitive data and power business and government operations across major sectors of the economy.
The report criticized a Microsoft corporate culture that was "at odds with... the level of trust customers place in the company."
The review identified a series of operational and strategic decisions by Microsoft that opened the door to the breach, including the failure to identify a new employee's compromised laptop following a corporate acquisition in 2021.
It also found that Microsoft fell short of safety standards seen at competing cloud companies, including Google, Amazon and Oracle.
"The Board finds that this intrusion was preventable and should never have occurred," the review said, pinpointing "the cascade of Microsoft's avoidable errors that allowed this intrusion to succeed."
- 'Lasting change' -
The report also recommended that Microsoft develop and publicly release a plan with timelines to enact wide-ranging security reforms across its products and practices.
"The real challenge is how you achieve effective lasting cultural change," Smith said, noting Microsoft has nearly 226,000 employees.
Smith said Microsoft has the equivalent of 34,000 engineers working full time on answering the security shortcomings in "the largest engineering project focused on cybersecurity in the history of digital technology."
Microsoft's board on Wednesday approved a change that will tie cybersecurity accomplishments with annual bonuses for senior executives and make it part of every employee's annual review, according to Smith.
Microsoft detects some 300 million cyberattacks on its customers daily, with most of those coming from China, Iran, Korea, Russia, or ransomware operations, Smith told the committee.
"We're dealing with four formidable foes in China, Russia, North Korea and Iran, and they are getting better," Smith said.
"We should expect them to work together; they're waging attacks at an extraordinary rate."
While it is inevitable that adversaries will use artificial intelligence for increasingly sophisticated attacks, the technology is already being used to strengthen cyber defenses, Smith added.
M.P.Jacobs--CPN