Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”

Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”

A leading U.S. Senator has urged the Federal Trade Commission to launch an investigation into Microsoft, accusing the tech giant of severe cybersecurity oversights. Senator Ron Wyden (D–Ore.) highlighted concerns over Microsoft's reliance on outdated encryption methods in Windows, particularly in light of a significant ransomware attack in 2024 that compromised the healthcare provider Ascension, resulting in the leakage of medical records for 5.6 million individuals. In a letter addressed to FTC Chairman Andrew Ferguson, Wyden emphasized that the default use of the RC4 encryption cipher was a critical factor in the breach. This marks the second occasion in recent years that Wyden has criticized Microsoft's cybersecurity approach as negligent. He stated, "Due to perilous software engineering decisions by Microsoft, which have largely remained obscured from both corporate and governmental clients, a single click by an employee can lead to a widespread ransomware incident within an organization." Wyden's letter underscored the urgency of the matter, asserting that Microsoft has failed to mitigate the ransomware threat exacerbated by its software vulnerabilities. The RC4 cipher, originally created by cryptographer Ron Rivest in 1987, has been recognized as insecure since its vulnerabilities became publicly known in the mid-1990s. Despite attempts to phase it out, Microsoft still utilizes RC4 as the default encryption method for Active Directory, a key Windows feature for managing user accounts in larger organizations. While alternatives exist, many users do not activate them, resulting in a fallback to the compromised Kerberos authentication method. In a recent blog post, cryptography expert Matt Green from Johns Hopkins University pointed out that the continued use of Kerberos in conjunction with RC4, along with frequent misconfigurations, leaves networks vulnerable to “kerberoasting.” This attack technique, which has been recognized since 2014, involves offline password-cracking methods aimed at Kerberos accounts lacking stronger encryption safeguards.

Sources : Ars Technica

Published On : Sep 10, 2025, 19:45

Computing
The New Era of Browsers: Exploring Innovative Alternatives to Chrome and Safari

The landscape of web browsers is evolving dramatically this year, shifting the focus from traditional search capabilitie...

TechCrunch | Jul 03, 2026, 19:00
The New Era of Browsers: Exploring Innovative Alternatives to Chrome and Safari
Startups
Congressional Members Reveal SpaceX Stock Purchases Following Record IPO

Two congressional representatives have recently disclosed purchases of SpaceX stock shortly after the company's groundbr...

CNBC | Jul 03, 2026, 18:25
Congressional Members Reveal SpaceX Stock Purchases Following Record IPO
Gadgets
Unmissable Smartphone Deals Under ₹30,000 During Amazon and Flipkart Sales!

Amazon and Flipkart have launched two major shopping festivals that smartphone enthusiasts won't want to miss. The Amazo...

Business Today | Jul 04, 2026, 02:55
Unmissable Smartphone Deals Under ₹30,000 During Amazon and Flipkart Sales!
AI
What If the Founding Fathers Had AI? Google's New Ad Sparks Debate

In a creative twist, Google has released a commercial that envisions how the Founding Fathers might have utilized modern...

TechCrunch | Jul 04, 2026, 21:15
What If the Founding Fathers Had AI? Google's New Ad Sparks Debate
AI
Midjourney Demands Transparency from Hollywood Studios in AI Legal Battle

In an escalating legal conflict with major Hollywood studios, AI company Midjourney is pushing for transparency regardin...

TechCrunch | Jul 04, 2026, 18:40
Midjourney Demands Transparency from Hollywood Studios in AI Legal Battle
View All News