• Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints

Nine takeaways from ProPublica’s investigation into Microsoft’s cybersecurity failures

Simon Osuji by Simon Osuji
June 21, 2024
in Military & Defense
0
Nine takeaways from ProPublica’s investigation into Microsoft’s cybersecurity failures
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter


After Russian hackers exploited a flaw in a widely used Microsoft product during one of the largest cyberattacks in U.S. history, the software giant downplayed its culpability. However, a recent ProPublica investigation revealed that a whistleblower within Microsoft’s ranks had repeatedly attempted to convince the company to address the weakness years before the hack — and that the company rebuffed his concerns at every step.

Here are the key things you need to know about that whistleblower’s efforts and Microsoft’s inaction.

Related posts

Madagascar Faces Uncertain Future Under Military Rule

Madagascar Faces Uncertain Future Under Military Rule

February 25, 2026
South Africans recruited for Russo/Ukrainian conflict coming home

South Africans recruited for Russo/Ukrainian conflict coming home

February 25, 2026

Years before the SolarWinds hack was discovered in 2020, a Microsoft engineer found a security flaw these hackers would eventually exploit.

In 2016, while researching an attack on a major tech company, Microsoft engineer Andrew Harris said he discovered a flaw in the company’s Active Directory Federation Services, a product that allowed users to sign on a single time for nearly everything they needed. As a result of the weakness, millions of users — including federal employees — were left exposed to hackers.

Harris said the Microsoft team responsible for handling reports of security weaknesses dismissed his concerns.

The Microsoft Security Response Center determines which reported security flaws need to be addressed. Harris said he told the MRSC about the flaw, but it decided to take no action. The MSRC argued that, because hackers would already need access to an organization’s on-premises servers before they could take advantage of the flaw, it didn’t cross a so-called “security boundary.” Former MSRC members told ProPublica that the center routinely rejected reports of weaknesses using this term, even though it had no formal definition at the time.

Microsoft product managers also refused to address the problem.

Following the MSRC’s decision, Harris escalated the issue to Microsoft product leaders who, he said, “violently agreed with me that this is a huge issue.” But, at the same time, they “violently disagreed with me that we should move quickly to fix it.”

Harris had proposed the temporary solution of suggesting that customers turn off the seamless single sign-on function. That move would eliminate the threat but result in users needing to log on twice instead of once. A product manager argued that it wasn’t a viable option because it risked alienating federal government customers and undermined Microsoft’s strategy to marginalize a top competitor.

Microsoft was also concerned that going public with the flaw could hurt its chances of winning future government contracts worth billions of dollars, Harris said.

At the time Harris was trying to convince Microsoft product leaders to address the flaw, the federal government was preparing to make a massive investment in cloud computing, and Microsoft wanted the business. Acknowledging this security flaw could jeopardize the company’s chances, Harris recalled one product leader telling him.

Harris eventually learned that the flaw was even more dire than he originally thought. Once again, Microsoft opted to not take action, he said.

In 2018, a colleague of Harris’ pointed out how hackers could also bypass a common security feature called multifactor authentication, which requires users to perform one or more additional steps to verify their identity, such as entering a code sent via text message.

Their discovery meant that, no matter how many additional security steps a company puts in place, a hacker could bypass them all.

When the colleagues brought this new information to the MSRC, “it was a nonstarter,” Harris said.

Researchers outside of Microsoft also warned the company about the flaw.

In November 2017, cybersecurity firm CyberArk published a blog post detailing the same flaw Harris had identified.

Microsoft would later claim this blog post was the first time it had learned of the issue, but researchers at CyberArk told ProPublica they had reached out to Microsoft staff at least twice before publication.

Later, in 2019, cybersecurity firm Mandiant would publicly demonstrate at a cybersecurity conference how hackers could exploit the flaw to gain access to victims’ cloud services. The firm said it had given Microsoft advance notice of its findings.

Russian hackers ultimately exploited the very flaw Harris and the others had raised.

Within months of Harris leaving Microsoft in 2020, his fears became reality. U.S. officials confirmed reports that a state-sponsored team of Russian hackers used the flaw in the SolarWinds hack. Exploiting the weakness, hackers vacuumed up sensitive data from a number of federal agencies, including, ProPublica learned, the National Nuclear Security Administration, which maintains the United States’ nuclear weapons stockpile. The Russians also used the weakness to compromise dozens of email accounts in the Treasury Department, including those of its highest-ranking officials.

In congressional hearings after the SolarWinds attack, Microsoft’s president insisted the company was blameless.

Microsoft President Brad Smith assured Congress in 2021 that “there was no vulnerability in any Microsoft product or service that was exploited” in SolarWinds, and he said customers could have taken more steps to secure their systems.

When asked what Microsoft had done to address the flaw in the years before the attack, Smith responded by listing a handful of steps that customers could have taken to protect themselves. His suggestions included purchasing an antivirus product like Microsoft Defender and securing devices with another Microsoft product called Intune.

After ProPublica published its investigation, lawmakers pressed Microsoft’s Smith if his prior testimony before Congress was incorrect.

Hours after the ProPublica investigation was published, Microsoft’s Smith appeared before the House Homeland Security Committee to discuss his company’s cybersecurity failures.

Rep. Seth Magaziner, D-R.I., asked Smith about his prior congressional testimony, in which he said that Microsoft had first learned about this weakness in November 2017 from the CyberArk blog post. ProPublica’s investigation, Magaziner noted, found that Harris had raised it even earlier, only to be ignored. The lawmaker asked Smith if his prior testimony was incorrect.

Smith demurred, saying he hadn’t read the story. “I was at the White House this morning,” he told the panel.

He also complained that ProPublica’s investigation was published the day of the hearing and said that he’d know more about it “a week from now.”

However, ProPublica had sent detailed questions to Microsoft nearly two weeks before the story was published and had requested an interview with Smith. The company declined to make him available. Instead, Microsoft had issued a statement in response. “Protecting customers is always our highest priority,” a spokesperson said. “Our security response team takes all security issues seriously and gives every case due diligence with a thorough manual assessment, as well as cross-confirming with engineering and security partners. Our assessment of this issue received multiple reviews and was aligned with the industry consensus.”

This story was originally published by ProPublica, a nonprofit newsroom that investigates abuses of power. Sign up to receive our biggest stories as soon as they’re published.





Source link

Previous Post

Worldcoin token surges 12% after Ecuador expansion and Kenya probe closure

Next Post

Boeing nearing deal with supplier Spirit Aero after months of talks, sources say

Next Post
Boeing nearing deal with supplier Spirit Aero after months of talks, sources say

Boeing nearing deal with supplier Spirit Aero after months of talks, sources say

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Russian Strikes Raise Concerns Over Ukraine’s Imminent F-16s

Russian Strikes Raise Concerns Over Ukraine’s Imminent F-16s

2 years ago
3.1 billion people remain offline despite mobile internet coverage

3.1 billion people remain offline despite mobile internet coverage

6 months ago
Lords call for ‘urgent’ action on long-term energy storage

Lords call for ‘urgent’ action on long-term energy storage

2 years ago
Top 50 Wallets That Own Trillions of SHIB Tokens Revealed

Top 50 Wallets That Own Trillions of SHIB Tokens Revealed

2 years ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • The world’s top 10 most valuable car brands in 2025

    0 shares
    Share 0 Tweet 0
  • Top 10 African countries with the highest GDP per capita in 2025

    0 shares
    Share 0 Tweet 0
  • Global ranking of Top 5 smartphone brands in Q3, 2024

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0

Get strategic intelligence you won’t find anywhere else. Subscribe to the Limitless Beliefs Newsletter for monthly insights on overlooked business opportunities across Africa.

Subscription Form

© 2026 LBNN – All rights reserved.

Privacy Policy | About Us | Contact

Tiktok Youtube Telegram Instagram Linkedin X-twitter
No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • LBNN Blueprints
  • Quizzes
    • Enneagram quiz
  • Fashion Intelligence

© 2023 LBNN - All rights reserved.