Microsoft Faces Scrutiny Over Security and Ransomware Threats

11 Sep 2025

In a detailed plea to the Federal Trade Commission, U.S. Senator Ron Wyden has called for an investigation into Microsoft's cybersecurity practices, highlighting what he perceives as serious lapses leading to ransomware attacks against critical U.S. infrastructure. This comes in light of fresh revelations from a security breach at the healthcare provider Ascension, which were recently uncovered by Wyden’s office. The breach, attributed to the ransomware group Black Basta, severely disrupted operations by compromising electronic health records.

The senator's concerns stem from the manner in which the breach occurred. It began with a contractor inadvertently clicking a malicious link while using Microsoft's Bing search engine. This action unleashed malware onto the system, which was subsequently exploited due to insecure default settings in Microsoft's software. The attackers leveraged a technique known as Kerberoasting, which took advantage of legacy encryption protocols like RC4 that were still enabled by default in some configurations.

Legacy Encryption Issues

Kerberoasting specifically exploited vulnerabilities in older encryption methods, notably RC4, a stream cipher known for its weaknesses. Despite awareness among security professionals of RC4's risks, it remained active in default configurations. While Microsoft has committed to removing DES for Kerberos and disabling RC4 by default in upcoming updates for its systems, the timeline for these updates raises concerns.

Microsoft has faced criticism for its handling of these vulnerabilities. Although it issued an alert in October 2024 about the forthcoming changes for Windows 11 24H2 and Windows Server 2025, Wyden argues that the company should have implemented these measures sooner. The senator's letter to the FTC pointedly criticizes Microsoft's decision to not enforcing longer, more secure passwords for privileged accounts, which leaves customers unnecessarily vulnerable to cyber threats.

Further recommendations from Microsoft included the use of Group Managed Service Accounts to manage passwords securely, configuring AES (128/256-bit) for Kerberos service ticket encryption, and conducting audits on accounts with Service Principal Names. Nevertheless, Wyden insists that Microsoft's continued allowance of insecure default settings represents a systemic risk that needs urgent addressing.

This call for investigation is not Microsoft's first brush with security-related criticisms. Past reports, including those from the U.S. Cyber Safety Review Board, have faulted the tech giant for security missteps, such as those leading to the Storm-0558 compromise. Security experts note that the lack of a secure-by-default design in such a widely used software vendor underscores a bigger issue within the industry.

As these debates unfold, Microsoft is now under increased scrutiny to demonstrate a commitment to security that matches its technological dominance. While the company promises improvements, the urgency of cybersecurity in safeguarding vital infrastructures cannot be overstated, making this a pressing issue for regulators and industry leaders alike.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5723254
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1029988
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
441129
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
372941
downloads

News and reviews for Desktop Windows

Strategic Tips for Conquering Beastfly in Pharloom

Learn effective strategies to tackle Beastfly in Pharloom with the right preparation and combat tactics for both the Hunter's March and Far Fields encounters.

Read more

Ghostrunner 2 Now Free on Epic Games Store for Limited Time

Ghostrunner 2, a fast-paced cyberpunk action game, is currently free on the Epic Games Store. Experience the enhanced combat, upgraded katana, and expansive new settings in this highly-rated sequel, available until September 18 alongside Monument Valley 2 and The Battle of Polytopia.

Read more

Microsoft Faces Scrutiny Over Security and Ransomware Threats

Sen. Wyden urges FTC probe into Microsoft's role in ransomware, citing inadequate cybersecurity. Wyden calls for stronger security measures for legacy encryptions like RC4.

Read more

Microsoft Releases Windows 11 25H2 ISOs for Testers

Microsoft has released ISO files for Windows 11 25H2, allowing testers a clean installation process before the update's full release. The update maintains core system components intact while offering significant internal improvements and is expected to be generally available in October.

Read more

Hell Let Loose Vietnam Offers Asymmetric Warfare Experience

Hell Let Loose Vietnam surprises with its setting shift. This sequel introduces asymmetric mechanics, offering unique strategies for players. Set during the Vietnam War, it promises an intense, immersive combat experience, expanding on the series' existing foundations ahead of its 2026 release.

Read more

Nano11 Launches: Minimizing Windows 11 Installation Size

NTDEV introduces Nano11, a PowerShell tool trimming Windows 11 ISOs, achieving up to 3.5 times size reduction. Designed for experimental use, it streamlines installations by removing non-essential components.

Read more

Helmets Now Available in Latest Space Marine 2 Update

Saber Interactive releases fan-favorite helmets in Space Marine 2, including the plain Mark 8, with patch 10.1, available in the store. The update also resolves gameplay bugs, enhancing the gaming experience.

Read more

Assassin's Creed Update Brings Key Enhancements for Gamers

Ubisoft's Assassin's Creed Shadows unveils major improvements including a new gear system, map enhancements, and a free story mission, enticing players to re-engage with the game.

Read more

Dragonwilds Update Delay Due to Technical Issues

Dragonwilds 0.9 update faces delay due to detected bugs. Originally set for September 9, release postponed for fixes. Features include new skill trees and controller overhaul. Expected this week, with 0.9.1 due late September.

Read more

Windows 10 Users Advised to Join Security Updates Program

As Windows 10 support winds down, users are urged to enroll in the Extended Security Updates program, providing critical security patches until October 2026.

Read more