Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Shadow AI’s Real Threat Is Access Control

June 26, 2026

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026
Facebook X (Twitter) Instagram
Saturday, June 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Wyden Urges FTC Investigation Over Ascension Ransomware Hack
News

Wyden Urges FTC Investigation Over Ascension Ransomware Hack

Team-CWDBy Team-CWDSeptember 11, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US Senator Ron Wyden of Oregon has called on the Federal Trade Commission to investigate Microsoft for cybersecurity lapses linked to ransomware attacks on critical US infrastructure. This includes the 2024 hack of Ascension, one of the nation’s largest hospital systems.

According to Wyden’s office, the breach began when a contractor clicked a malicious link in a Bing search result, which infected their laptop with malware.

Default settings in Microsoft software then allowed attackers to gain administrative access to the Ascension network, exposing the sensitive data of 5.6 million patients.

The hackers exploited a technique known as “Kerberoasting,” which leverages Microsoft’s continued support for the outdated RC4 encryption standard. A more secure encryption option exists but is not enabled by default.

Wyden staff reportedly warned Microsoft of the vulnerability in July 2024. Microsoft published a blog post about the threat in October 2024 and said it planned to issue a software update. Nearly a year later, no update has been released and the company has not conducted direct outreach to warn customers.

Read more on ransomware attack trends: Ransomware Payments Plummet in Education Amid Enhanced Resiliency

Microsoft’s dominant position in enterprise operating systems gives the company control over default security configurations.

Wyden criticized the company’s handling of cybersecurity.

“Without timely action, Microsoft’s culture of negligent cybersecurity, combined with its de facto monopolization of the enterprise operating system market, poses a serious national security threat and makes additional hacks inevitable,” he wrote in his FTC letter on Wednesday.

Calls for Accountability

Wyden has reportedly pressed federal agencies several times to hold Microsoft responsible for cybersecurity lapses.

Past reviews, including one by the Cyber Safety Review Board, concluded that Microsoft’s security culture “was inadequate and requires an overhaul.” 

Despite repeated breaches, Wyden said the company continues to secure lucrative federal contracts.

“What happened at Ascension isn’t just about one bad click or an old cipher,” said Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar.

“It’s about systemic risk inherited from default configurations and the architectural complexity of widely adopted software ecosystems like Microsoft’s.”

The Human Cost of Insecure Software

Ransomware incidents in the US increased sharply in 2024 with over 5000 attacks reported, representing a 15% rise from 2023. Half of these targeted US organizations, including hospitals, government agencies and private companies.

The Ascension case highlights the potential human cost of insecure default software, disrupting patient care and putting sensitive data at risk.

Wyden’s letter urges the FTC to act, citing the need to hold Microsoft accountable for systemic cybersecurity failures that could pose a threat to national security.

Image credit: Ahyan Stock Studios / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleIranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats
Next Article Google Patches 120 Flaws, Including Two Zero-Days Under Attack
Team-CWD
  • Website

Related Posts

News

Shadow AI’s Real Threat Is Access Control

June 26, 2026
News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why children’s data is a long-term identity risk

June 3, 2026

Look out for phony verification pages spreading malware

September 14, 2025

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.