Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why
    • You can now buy the OnePlus 15 in the US and score free earbuds if you hurry
    • Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455
    • Android might finally stop making you tap twice for Wi-Fi
    • Today’s NYT Mini Crossword Answers for Dec. 22
    • Waymo’s robotaxis didn’t know what to do when a city’s traffic lights failed
    • Today’s NYT Wordle Hints, Answer and Help for Dec. 22 #1647
    • You Asked: OLED Sunlight, VHS on 4K TVs, and HDMI Control Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Gaming»‘Microsoft has become like an arsonist selling firefighting services to their victims’ says US senator, referring it to the FTC for a cybersecurity flaw, though Microsoft says it has a plan
    Gaming

    ‘Microsoft has become like an arsonist selling firefighting services to their victims’ says US senator, referring it to the FTC for a cybersecurity flaw, though Microsoft says it has a plan

    techupdateadminBy techupdateadminSeptember 12, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A logo marking the edge of the Microsoft corporate campus in Redmond, Washington.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    US senator Ron Wyden has written a letter to the FTC requesting that the organisation investigate Microsoft for what he calls “gross cybersecurity negligence.” His complaint is primarily related to a form of encryption still supported by the company’s Windows operating system, which the senator’s office believes is vulnerable to ransomware attacks.

    In the letter [PDF warning], Senator Wyden reveals that an investigation his office conducted into a ransomware breach of healthcare provide Ascension last year found that support of the RC4 encryption cipher was a direct contributor to the attack (via Ars Technica).

    “Because of dangerous software engineering decisions by Microsoft, which the company has largely hidden from its corporate and government customers, a single individual at a hospital or other organization clicking on the wrong link can quickly result in an organization-wide ransomware infection,” said Wyden.


    Related Articles

    “Microsoft has utterly failed to stop or even slow down the scourge of ransomware enabled by its dangerous software.”

    RC4, or Rivest Cipher 4, was developed in 1987 by mathematician and cryptographer Ron Rivest, and was considered a protected method of encryption until 1994, when it was compromised as a result of a leaked technical description. Despite this, RC4 was widely used in common encryption protocols until around a decade ago, and is still used by Microsoft to secure Active Directory, a Windows component used by system administrators to configure user accounts.

    (Image credit: Witthaya Prasongsin via Getty Images)

    While Windows will use AES encryption by default, the senator’s office discovered that Windows servers will still respond to RC4-based authentication requests, which potentially opens them up to “Kerberoasting.” This is a technique in which administrative privileges are gained via exploiting encryption on one affected machine in order to install ransomware on others.

    In the case of Ascension, the senator claims that a contractor clicking on a malicious link led to hackers “moving laterally” within its server network, exploiting the weak encryption in order to push ransomware to thousands of other other computers in the organisation and ultimately stealing the sensitive data of 5.6 million patients.

    Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.

    While the senator says that his office contacted Microsoft about the vulnerability, and that the company eventually posted a blog post with actions that organisations could take to protect against it, a promised security update to fix the issue is yet to arrive.

    A photo of the Windows update menu, showing that I'm all up to date

    (Image credit: Future)

    “The Ascension hack illustrates how it is Microsoft’s customers, and, ultimately, the public, who bear the cost of Microsoft’s dangerous software engineering practices and the company’s refusal to inform its customers about the pressing need to adopt important cybersecurity safeguards,” the senator continues.

    “There is one company benefiting from this status quo: Microsoft itself. Instead of delivering secure software to its customers, Microsoft has built a multibillion dollar secondary business selling cybersecurity add-on services to those organizations that can afford it. At this point, Microsoft has become like an arsonist selling firefighting services to their victims”


    Related Articles

    The senator ends his letter by urging the FTC to investigate Microsoft, and hold the company responsible for what the senator claims is the “serious harm it has caused by delivering dangerous, insecure software to the U.S. government and to critical infrastructure entities, such as those in the U.S. health care sector.”

    Image manipulated symbolic alegory pointing into the mystery of being.

    (Image credit: Maciej Toporowicz, NYC via Getty Images)

    Microsoft has since released a statement to multiple outlets, including Ars Technica, directly addressing the senator’s claims:

    “RC4 is an old standard, and we discourage its use both in how we engineer our software and in our documentation to customers – which is why it makes up less than .1% of our traffic. However, disabling its use completely would break many customer systems,” the company said.

    “For this reason, we’re on a path to gradually reduce the extent to which customers can use it, while providing strong warnings against it and advice for using it in the safest ways possible. We have it on our roadmap to ultimately disable its use. We’ve engaged with The Senator’s office on this issue and will continue to listen and answer questions from them or others in government.”

    Microsoft also says that in the first quarter of 2026, “Any new installations of Active Directory Domains using Windows Server 2025 will have RC4 disabled by default, meaning any new domain will inherently be protected against attacks relying on RC4 weaknesses. We plan to include additional mitigations for existing in-market deployments with considerations for compatibility and continuity of critical customer services.”

    HP OMEN 35L

    Best gaming PC 2025

    All our current recommendations
    arsonist cybersecurity firefighting Flaw FTC Microsoft Plan referring selling Senator Services victims
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI Tested Acer’s Nitro V Gaming Laptop, and It Serves Up a Big Screen and Big Value
    Next Article PC security will never be perfect. But that shouldn’t stop progress
    techupdateadmin
    • Website

    Related Posts

    Gadgets

    How to Quickly Find Out What’s Streaming on Multiple Services at Once

    December 21, 2025
    Mobile

    Santa isn’t the only one watching: Save 50% on Webroot cybersecurity

    December 18, 2025
    Mobile

    Your iPhone choices could grow, but Apple’s Air plan is getting rewritten

    December 17, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    NYT Strands hints and answers for Monday, August 11 (game #526)

    August 11, 202545 Views

    These 2 Cities Are Pushing Back on Data Centers. Here’s What They’re Worried About

    September 13, 202542 Views

    Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 4 #346

    September 4, 202540 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.