惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
GRAHAM CLULEY
www.infosecurity-magazine.com
www.infosecurity-magazine.com
V2EX - 技术
V2EX - 技术
The Last Watchdog
The Last Watchdog
S
Secure Thoughts
Webroot Blog
Webroot Blog
PCI Perspectives
PCI Perspectives
L
LINUX DO - 最新话题
Hacker News: Ask HN
Hacker News: Ask HN
N
News and Events Feed by Topic
H
Heimdal Security Blog
H
Help Net Security
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
Recent Commits to openclaw:main
Recent Commits to openclaw:main
F
Full Disclosure
小众软件
小众软件
S
Securelist
罗磊的独立博客
NISL@THU
NISL@THU
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cisco Blogs
云风的 BLOG
云风的 BLOG
C
CERT Recently Published Vulnerability Notes
Cisco Talos Blog
Cisco Talos Blog
Know Your Adversary
Know Your Adversary
S
Schneier on Security
D
DataBreaches.Net
M
MIT News - Artificial intelligence
V
Vulnerabilities – Threatpost
N
News and Events Feed by Topic
有赞技术团队
有赞技术团队
F
Fortinet All Blogs
T
Tenable Blog
The Register - Security
The Register - Security
C
Check Point Blog
AWS News Blog
AWS News Blog
Cloudbric
Cloudbric
C
CXSECURITY Database RSS Feed - CXSecurity.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google Online Security Blog
Google Online Security Blog
博客园 - 叶小钗
Hacker News - Newest:
Hacker News - Newest: "LLM"
博客园 - 司徒正美

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyber insurers paid out over twice as much for UK ransomware attacks last year Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ UK data watchdog fines 23andMe £2.3M over 2023 breach Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Snowflake CISO talks lessons learned from breaches, improv Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Ransomware crims targeting systems between IT and operations Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
Ex-White House cyber guru talks Microsoft security fails
Jessica Lyons Jessica Lyons · 2025-08-08 · via The Register - Security: CSO

COMMENT Roger Cressey served two US presidents as a senior cybersecurity and counter-terrorism advisor and currently worries he'll experience a "political aneurysm" due to Microsoft's many security messes.

In the last few weeks alone, Microsoft disclosed two major security vulnerabilities – along with news that attackers exploited one involving SharePoint as a zero-day. The second flaw, while not yet under exploitation, involves Exchange server – a favorite of both Russian and Chinese spies for years.

Chinese familiarity with Microsoft products makes them a door already open

The Windows giant disclosed the Exchange bug late Wednesday, hours after becoming a $4 trillion company.

Cressey, who served in the Clinton and Bush administrations, prefers to call it "A $4 trillion monster."

"And from a national security perspective, this really bothers me," Cressey, now a partner with Liberty Group Ventures, told The Register.

"The Chinese are so well prepared and positioned on Microsoft products that in the event of hostilities, we know for a fact that Chinese actors will target our critical infrastructure through Microsoft products for two reasons," he said. "One: [Microsoft products] are everywhere within our digital ecosystem. And two: they are so vulnerable that the Chinese familiarity of them makes it a door already open. So that's what gives me the political aneurysm here."

Prior to spending several years in the White House, Cressey served in the departments of Defense and State. He's worked in the private sector as a counterterrorism professor and cybersecurity consultant since 2001.

"This is the latest episode of a decades-long process of Microsoft not taking security seriously. Full stop," Cressey said, acknowledging that the government continues spending billions on Microsoft products. "Anytime there's a major announcement of a Microsoft procurement by the government, the happiest people in the world first are in Redmond and second in Beijing."

Microsoft declined to comment for this story, but did point out that Google Cloud is a client of Cressey's in his consulting work.

Groundhog Day … but with national security implications

Cressey isn't the first to point out Microsoft's poor security record has national security implications. They resurface after every major breach … and then nothing changes.

AJ Grotto, another former senior White House cyber policy director, called Redmond's security failures a national security issue and said they date at least back to the Solar Winds hack.

CrowdStrike Senior VP of Counter Adversary Operations Adam Meyers told The Register the same thing and likened Microsoft's stranglehold on government tech to the mafia shortly after Redmond's January 2024 admission that Russia's Cozy Bear had, once again, broken into its network.

In June 2024, US lawmakers questioned Microsoft President Brad Smith about his company's business in China during a Congressional hearing about a Homeland Security report that blasted Microsoft for a series of "avoidable errors."

These errors, the investigation found, allowed Beijing-backed cyberspies to steal tens of thousands of sensitive emails from the Microsoft-hosted Exchange Online inboxes of high-ranking US government officials.

At the time, however, Smith defended Microsoft, which he claimed to be above the rule of law – in China, at least.

National intelligence laws in China can be used to force companies operating there to provide snooping services for the government, or hand over proprietary code if pressured to do so. But Smith claimed Microsoft doesn't have to comply with that.

More recently, following the SharePoint attacks, frequent Microsoft critic and US Senator Ron Wyden (D-OR) told us that "government agencies have become dependent on a company that not only doesn't care about security, but is making billions of dollars selling premium cybersecurity services to address the flaws in its products."

The government will never escape this cycle unless it stops rewarding Microsoft for its negligence with bigger and bigger contracts

The US Energy Department, including its National Nuclear Security Administration (NNSA), which maintains America's nuclear weapons, was among the 400-plus victims in this most recent mass exploitation of a Microsoft product.

"Each hack caused by Microsoft's negligence results in increased government spending on Microsoft cybersecurity services," Wyden continued. "The government will never escape this cycle unless it stops rewarding Microsoft for its negligence with bigger and bigger contracts."

There is no indication that Washington, or Microsoft, is changing.

Why are we allowing this company to have such major touch points within our national security infrastructure?

"We are living the definition of insanity when it comes to our expectations of Microsoft," Cressey said, a reference to the aphorism "Insanity is doing the same thing over and over again and expecting different results."

China's deep familiarity with Microsoft products

According to Cressey, security holes in Microsoft products aren't the only risk Redmond poses: its presence in China hurts, too.

"In what universe does any member of Microsoft security think it makes sense to have Chinese engineers touch anything related to our government and cloud infrastructure," he said, referring to recent ProPublica reports that revealed Microsoft for years used a China-based engineering team to support SharePoint.

Last month, a similar ProPublica story said Microsoft has for a decade relied on Chinese workers to maintain the Defense Department's cloud systems with oversight from US-based "digital escorts."

"When I was doing counter terrorism for a living, we had this major issue with Pakistan as a sanctuary for al Qaeda," Cressey said. "We used to say the Pakistanis were either incapable or unwilling to do something significant against their al Qaeda presence."

"I feel like Microsoft is this equivalent of Pakistan right now in cybersecurity: they're either incapable or unwilling to take the actions that truly could make a difference," he continued.

"Because, rest assured, if this was another company that was conducting these same types of practices, the furor would be off the charts, and people would be demanding to know why are we allowing this product and this company to have such major touch points within our national security infrastructure?"

The reasons for this, according to Cressey and others, include Microsoft being really good at sales and the government being cost-conscious, making it difficult to pass up the offer of "free" security products and services (for a limited time), despite this deal locking in federal customers.

Microsoft is this equivalent of Pakistan right now in cybersecurity

"When you're giving away Microsoft Defender for free, that is the gateway drug to becoming chemically dependent on Microsoft infrastructure," he said.

Will Trump hold Microsoft accountable?

Cressey is hopeful that the Trump administration, with its "unconventional" approach to government contracts, will "hold companies like Microsoft accountable for their security failures."

On Wednesday, Senate Intelligence Committee Chair Tom Cotton (R-AR) sent a letter [PDF] to Defense Secretary Pete Hegseth urging him to ban non-US citizens from accessing Department of Defense systems.

Cotton also praised Hegseth's "ongoing actions" to eliminate Chinese engineers' access to DOD systems and requested a briefing about any security vulnerabilities in the DOD's contracts and software related to "Microsoft's business dealings in China."

"I'm not saying we should just get rid of Microsoft, I'm saying Microsoft has got to be better at what it does," Cressey said. "At the end of the day, we as a nation are suffering because the number one software company we rely upon continues to treat security as an annoyance and not a necessity."

"Sure as the Sun rises in the east, there will be another story soon of Microsoft falling short on security," he told The Register during a Wednesday interview – before Microsoft and CISA sounded the alarm on another high-severity bug in Exchange Server hybrid deployments.

So we reached out again to Cressey on Thursday morning to see what he had to say on the new CVE.

"It just never ends," he said. "Eighty-five percent of the federal government uses Microsoft 365, and this is the latest example of why Microsoft deficiencies present such a high risk to national security. This should be the tipping point for the Administration to pause any new awards to Microsoft and demand that Microsoft does a comprehensive security audit before they are eligible for future procurement."

Maybe it's the tipping point. But we're not holding our breath. ®