As you have read ransomware has been in the news for because one of the major ransomware gangs, BlackCat/ALPHV updated and expanded its capability to carry out the double extortion tactic and because another major ransomware player LockBit suffered an insider attack of its own: The threat actors are also …
Microsoft Teams is keeping security tokens in plain text… and more UPDATED 23 September 2022
The original post was published on 16 September 2022 This is a real problem, no software or system should keep any security token in plain text, any time during operation. The user base for Microsoft Teams is in excess of 270 million users – we are part of that number …
More privacy issues for Twitter
Following the revelations by Peiter Zatko, the former head of security at Twitter: Is Twitter a decade behind in its security practices? – Smart Thinking Solutions It now emerges that one of the essential steps in a Twitter password reset – logging out of any and all devices already logged …
Another case of a false positive and why we must not let these incidents weaken our cybersecurity stance
The highly respected security software vendor Malwarebytes, slipped up this time, classifying Google and YouTube as malware for short time: Malwarebytes mistakenly blocks Google, YouTube for malware (bleepingcomputer.com) I recently wrote about false positives and their possible impact on the cyber security stance of an organisation – if you did …
Credential stuffing attacks
This research by Okta highlights the issue of users recycling passwords: Okta: Credential stuffing accounts for 34% of all login attempts (bleepingcomputer.com) There were more login attempts by threat actors than legitimate ones! They were just trying out passwords to see if someone was stupid, (sorry if you do not …