Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

Microsoft Exchange Successfully Hacked Due to Weak Security Culture, Cyber Safety Review Board Says

by Jerry Petersen
April 3, 2024
in Cybersecurity, DHS, News
Hacker

Hacker

The intrusion by a hacking group affiliated with the People’s Republic of China called Storm-0558 into the Microsoft Exchange Online service during the summer of 2023 could have been prevented, according to a report released by the Cyber Safety Review Board in late March.

Table of Contents

  • You might also like
  • Proposed NRC Rule Seeks to Accelerate Nuclear Energy Tech Deployment
  • Rear Adm. Michael Baker: NGA Requires AI Skills Across Workforce
  • NRO Sends Third 2026 Architecture Mission Into Orbit With NROL-179 Launch

You might also like

Proposed NRC Rule Seeks to Accelerate Nuclear Energy Tech Deployment

Rear Adm. Michael Baker: NGA Requires AI Skills Across Workforce

NRO Sends Third 2026 Architecture Mission Into Orbit With NROL-179 Launch

The findings and recommendations within the report are based on a seven-month independent review conducted by the CSRB, which saw participation and cooperation from various stakeholders, including law enforcement organizations, cybersecurity companies, organizations that were impacted by the attack and Microsoft itself, the Department of Homeland Security said Tuesday.

The report attributes the success of Storm-0558’s hacking campaign to the inadequacy of the security culture within Microsoft as illustrated by a number of failures, including the company’s inability to detect the compromised status of an employee’s laptop, through which, it is believed, Storm-0558 managed to obtain Microsoft cryptographic signing keys.

With these keys, the hackers gained access to and exfiltrated information from Microsoft’s email service, compromising the accounts of numerous U.S. government officials, including that of Commerce Secretary Gina Raimondo, Rep. Don Bacon and U.S. Ambassador to the People’s Republic of China R. Nicholas Baum.

Illegal access to the email accounts is believed to have begun in May 15 but Microsoft would not initiate response efforts until June 16, after the Department of State notified the company of anomalous service activity.

To bring about change in Microsoft’s security culture, the report recommends that the company formulate and publicly disclose a plan on how it would reform its security practices, an effort to which senior officers would be held accountable. The report also recommends that, in the meantime, the company divert personnel to focus on product security improvements rather than feature development.

As for the broader industry, the report recommends, among other things, that cloud service providers implement modern control mechanisms as well as emerging digital identity standards. The report also calls for the adoption of a minimum standard for cloud service audit logging to facilitate the detection and investigation of intrusions.

Microsoft Exchange Successfully Hacked Due to Weak Security Culture, Cyber Safety Review Board Says

Cyber experts, government leaders and industry visionaries will speak about the dynamic and evolving role of cyber in the public sector at the Potomac Officers Club’s 2024 Cyber Summit, which will take place in June. Register now to attend this important event!

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

Proposed NRC Rule Seeks to Accelerate Nuclear Energy Tech Deployment

by Jane Edwards
June 22, 2026
Ho Nieh. The NRC chairman commented on the proposed rule to modernize the agency’s nuclear materials licensing requirements.

NRC has proposed updated licensing rules to support advanced nuclear fuel developmentThe proposal includes revised requirements for nuclear materials production, use and securityThe agency plans to hold a...

Read moreDetails

Rear Adm. Michael Baker: NGA Requires AI Skills Across Workforce

by Jane Edwards
June 22, 2026
Rear Adm. Michael Baker. The NGA associate director for operations discussed the agency’s need for employees with AI skills.

NGA has required AI proficiency and expanded training across its workforceRear Adm. Michael Baker has outlined AI agent applications in training and intelligence workflowsThe 2026 Intel Summit will...

Read moreDetails

NRO Sends Third 2026 Architecture Mission Into Orbit With NROL-179 Launch

by Miles Jamison
June 22, 2026
National Reconnaissance Office logo. The NRO has launched NROL-179 in support of its proliferated architecture initiative.

NRO has launched the NROL-179 mission aboard a SpaceX Falcon 9 rocketThe mission is the agency's 14th deployment under its proliferated satellite architecture and third launch of 2026The...

Read moreDetails

NASA Seeks Industry Input for Spaceport Maintenance & Operations at Kennedy Space Center

by Miles Jamison
June 22, 2026
Maintenance and repair. NASA is seeking industry input for the Spaceport Infrastructure Maintenance and Operations contract.

NASA is seeking industry input on a new contract supporting operations and maintenance at key Florida launch facilitiesThe planned SIMO contract vehicle will provide maintenance, logistics and technical...

Read moreDetails

Bipartisan Senate Bill Would Reform Bureau of Industry & Security

by Jamie Bennet
June 22, 2026
Bureau of Industry and Security. The BIS would undergo reform under new a new bipartisan Senate bill.

Sens. Kevin Cramer, R-N.D., and Andy Kim, D-N.J., proposed legislation to reform the Bureau of Industry and SecurityThe bipartisan bill is designed to strengthen export control of military...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!