🧔♂️ A friendly human may check it before it goes live. More news here
US senator urges FTC probe of Microsoft over cybersecurity
US Senator Ron Wyden has urged the Federal Trade Commission to investigate Microsoft over recent cybersecurity incidents, citing risks to national security.
Wyden, a Democrat, said in a letter to the FTC that Microsoft’s security practices contributed to ransomware attacks on US critical infrastructure, including healthcare providers.
He pointed to the May 2024 ransomware attack on Ascension, a hospital operator, which exposed the data of about 5.6 million people.
Wyden said the attack involved a contractor clicking a malicious Bing search link, which allowed hackers to access Ascension’s network and its Microsoft Active Directory server.
He criticized Microsoft’s support for outdated encryption and default settings, claiming they enabled the attack.
A Microsoft spokesperson said the referenced encryption standard, RC4, accounts for less than 0.1% of its traffic and is being phased out, with RC4 to be disabled by default in some Windows products in Q1 2026.
The FTC confirmed receipt of Wyden’s letter but did not comment.
🔗 Source: Reuters
🧠 Food for thought
Implications, context, and why it matters.
Microsoft’s breach frequency reveals systemic security challenges at scale
- Microsoft has experienced major cybersecurity incidents almost annually, with over 1,200 vulnerabilities reported between 2021 and 2025, including a record 1,360 vulnerabilities in 2024 alone2.
- The pattern includes high-profile breaches like the 2021 Exchange Server attack that affected over 250,000 organizations and the 2020 exposure of 250 million customer records due to misconfigured servers34.
- Recent incidents demonstrate ongoing vulnerabilities: Russian hackers breached executive email accounts in January 2024 through password spraying attacks, while Chinese hackers stole 60,000 State Department emails in September 20232.
- These repeated breaches suggest that Microsoft’s scale and complexity may be creating inherent security challenges that traditional cybersecurity approaches struggle to address effectively.
Market dominance amplifies national security risks from Microsoft’s security gaps
- Microsoft’s position as the dominant enterprise technology provider creates what Wyden called a “near-monopoly over enterprise IT,” where government agencies and companies have “no choice” but to use Microsoft products despite security concerns1.
- The company leads the cloud AI market with 45% of new implementations, significantly ahead of competitors like AWS and Google, while its partnership with OpenAI has further strengthened its market position5.
- This dominance means that Microsoft’s security failures have cascading national security implications—the Storm-0558 breach alone accessed email accounts across numerous government organizations because of compromised authentication keys that Microsoft had failed to rotate since 20166.
Recent Microsoft developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




