{"id":6835,"date":"2025-09-11T10:03:27","date_gmt":"2025-09-11T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/11\/senator-calls-for-ftc-investigation-into-microsofts-use-of-outdated-rc4-encryption-and-kerberoasting-vulnerabilities\/"},"modified":"2025-09-11T10:03:27","modified_gmt":"2025-09-11T10:03:27","slug":"senator-calls-for-ftc-investigation-into-microsofts-use-of-outdated-rc4-encryption-and-kerberoasting-vulnerabilities","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/11\/senator-calls-for-ftc-investigation-into-microsofts-use-of-outdated-rc4-encryption-and-kerberoasting-vulnerabilities\/","title":{"rendered":"Senator Calls for FTC Investigation into Microsoft\u2019s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities"},"content":{"rendered":"<p>    Senator Calls for FTC Investigation into Microsoft\u2019s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms \u201cgross cybersecurity negligence,\u201d accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption that has enabled devastating ransomware attacks on U.S. critical infrastructure, including major healthcare systems.<\/p>\n<p>In a letter addressed to FTC Chair Andrew N. Ferguson on September 10, 2025, Senator Wyden argued that Microsoft\u2019s insecure default settings have created a fertile ground for cybercriminals, directly threatening U.S. national security. <\/p>\n<p>The letter highlights a hacking technique known as \u201c<a href=\"https:\/\/cybersecuritynews.com\/badsuccessor-post-patch\/\" target=\"_blank\" rel=\"noreferrer noopener\">Kerberoasting<\/a>,\u201d which exploits Microsoft\u2019s continued support for RC4, an obsolete encryption technology developed in the 1980s.<\/p>\n<p>While modern and secure encryption standards like the Advanced Encryption Standard (AES) are available, Microsoft has not made them the default requirement in its widely used <a href=\"https:\/\/cybersecuritynews.com\/active-directory-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> software.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-ascension-ransomware-attack\"><strong>The Ascension Ransomware Attack<\/strong><\/h2>\n<p>The letter details a 2024 ransomware attack on Ascension, one of the largest non-profit health systems in the United States, as a prime example of Microsoft\u2019s alleged failures. <\/p>\n<p>The incident began when a contractor clicked on a malicious link from a Microsoft Bing search result, inadvertently downloading malware. <\/p>\n<p>From this single entry point, hackers moved across Ascension\u2019s network and used the Kerberoasting technique to exploit the weak RC4 encryption in the organization\u2019s Microsoft Active Directory server. <\/p>\n<p>This allowed them to gain administrative privileges, deploy <a href=\"https:\/\/cybersecuritynews.com\/dragonforce-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> across thousands of computers, and steal the sensitive data of 5.6 million patients.<\/p>\n<p>The attack severely disrupted Ascension\u2019s ability to provide patient care.<\/p>\n<p>Senator Wyden\u2019s office <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/wyden_letter_to_ftc_on_microsoft_kerberoasting_ransomwarepdf.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">stated<\/a> it had urged senior Microsoft officials in July 2024 to issue clear warnings about the threat posed by Kerberoasting.<\/p>\n<p>In response, Microsoft published a highly technical blog post in October 2024, recommending mitigation steps and promising a future software update to disable the vulnerable RC4 encryption. <\/p>\n<p>However, Wyden criticized the company\u2019s disclosure as inadequate, noting it was posted on an obscure part of its website without meaningful publicity. <\/p>\n<p>Furthermore, eleven months later, the promised security update has yet to be released, leaving countless organizations vulnerable.<\/p>\n<p>The Senator pointed out the hypocrisy of Microsoft\u2019s inaction, as U.S. cybersecurity agencies, including CISA, the FBI, and the NSA, have all issued public guidance specifically warning against Kerberoasting and advising the disabling of RC4 encryption. <\/p>\n<p>A comprehensive guide from CISA and the NSA, authored by Australian national security agencies in September 2024, identified Kerberoasting as the top threat against Microsoft\u2019s Active Directory software. <\/p>\n<p>Wyden also referenced a Cyber Safety Review Board report that found Microsoft\u2019s security culture \u201cinadequate and requires an overhaul,\u201d a finding that followed a major hack of U.S. government agencies by China in July 2023. <\/p>\n<p>The Senator concluded by accusing Microsoft of profiting from its own insecure products by selling add-on cybersecurity services, comparing the company to \u201can arsonist selling firefighting services to their victims.\u201d <\/p>\n<p>He urged the FTC to take immediate action to hold Microsoft accountable for its monopolistic and negligent practices.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsofts-use-of-outdated-rc4-encryption\/\">Senator Calls for FTC Investigation into Microsoft\u2019s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsofts-use-of-outdated-rc4-encryption\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Senator Calls for FTC Investigation into Microsoft\u2019s Use of Outdated RC4 Encryption and Kerberoasting Vulnerabilities U.S. Senator Ron Wyden has called on the Federal Trade Commission (FTC) to investigate Microsoft for what he terms \u201cgross cybersecurity negligence,\u201d accusing the tech giant of knowingly shipping its Windows operating system with a dangerously outdated form of encryption [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-6835","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6835"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6835"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6835\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}