Lawmakers will also look at how Microsoft âplans to strengthen security measuresâ following a 2023 cyber intrusion by âthreat actorsâ affiliated with China.
Microsoftâs vice chairman and president, Brad Smith, will testify before Congress next month on the tech giantâs alleged âsecurity shortcomingsâ following multiple cyberattacks, lawmakers announced on May 21.
Mr. Smith will testify before the House Homeland Security Committee on June 13, the committee said in a press release.
The hearing will also examine the âchallenges encountered in preventing significant cyber intrusions,â at Microsoft, House Committee on Homeland Security Chairman Mark E. Green (R-Tenn.) and Ranking Member Bennie G. Thompson (D-Miss.) announced.
Lawmakers will also look at how Microsoft âplans to strengthen security measuresâ in the wake of the Cyber Safety Review Boardâs (CSRB) report on the Microsoft Online Exchange 2023 cyber intrusion by âthreat actorsâ affiliated with China.
A Russian-based hacking group was suspected of being behind that incident, widely known as the SolarWinds hack.
Juneâs hearing also comes roughly one year after a hacking group linked to the Chinese communist regime, called Storm-0558, was implicated in the breach of thousands of emails from top U.S. officials, including those from several U.S. government agencies.
âAvoidable Errorsâ
According to Microsoft, the hacking group was able to access the emails after obtaining a private encryption key, known as an MSA key, and used it to forge access tokens for the Outlook Web Access (OWA) and Outlook.com services before Microsoft resolved the issue.
At the time, the tech giant said it had deployed âin-depth measures to harden all systems involved,â in the cyberattack and successfully blocked the hack.
âThe board finds that Microsoft had not sufficiently prioritized rearchitecting its legacy infrastructure to address the current threat landscape,â the report read.
âIntegrity of Government Dataâ
Reps. Green and Thompson said they are pleased Mr. Smith will appear before the committee to share information on how Microsoft is responding to the âgrave homeland security threats.â
âGiven the Microsoft Exchange Online incident and other recent major cyberattacks experienced by the company, the Committee is also deeply concerned about the continued integrity of U.S. government data, networks, and informationâespecially considering Microsoftâs role as a trusted vendor and dominant supplier of information technology for the federal government,â they said.
âWe look forward to Mr. Smithâs testimony and anticipate a productive discussion that advances our shared goal of strengthening cybersecurity practices for the cloud and addressing any vulnerabilities in the companyâs security culture,â they continued. âThis includes building confidence about a path forward to enhance the collective cyber defense of federal civilian networks and the private sector as threats rise from nefarious nation-state actors and opportunistic cybercriminals.â
âIt is our hope that Microsoft plays a leading role in accomplishing this mission,â the lawmakers added.
Juneâs hearing is entitled: âA Cascade of Security Failures: Assessing Microsoft Corporationâs Cybersecurity Shortfalls and the Implications for Homeland Security,â and will be livestreamed on YouTube, according to Reps. Green and Thompson.
Original News Source Link – Epoch Times
Running For Office? Conservative Campaign Consulting – Election Day Strategies!