Security News > 2024 > April > US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack

US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack
2024-04-09 13:56

US Cyber Safety Review Board released a report on the summer 2023 hack of Microsoft Exchange by China.

The Board finds that this intrusion was preventable and should never have occurred.

The Board also concludes that Microsoft's security culture was inadequate and requires an overhaul, particularly in light of the company's centrality in the technology ecosystem and the level of trust customers place in the company to protect their data and operations.

How Microsoft's ubiquitous and critical products, which underpin essential services that support national security, the foundations of our economy, and public health and safety, require the company to demonstrate the highest standards of security, accountability, and transparency.

The board was established in early 2022, modeled in spirit after the National Transportation Safety Board.


News URL

https://www.schneier.com/blog/archives/2024/04/us-cyber-safety-review-board-on-the-2023-microsoft-exchange-hack.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 678 806 4494 4179 3706 13185