Device Security

Today I have published the first part of a two-part article on device security over on CyberAwake. This is something many organisations skip over, if they have implemented a password policy and MFA! Device Security (Pt. 1) – CyberAwake Often the reluctance to take action is because they are concerned …

“View Document”

Credentials and AAA

Sometimes a cyber-attack is something as easy as adding a button saying “view document” when whale phishing senior people in an organisation. Ongoing Microsoft Azure account hijacking campaign targets executives (bleepingcomputer.com) Your takeaway When was the last time you audited the credentials and associated authorisations of those credentials? If you …

You may not have $25m in your bank account but here is the state of play of deep fake hacking

phishing email threat

That is a long title, but for this well financed, hi-tech cyber-attack it is appropriate. A worked at a multi-national company in Hong Kong was persuaded to transfer $200 million Hong Kong dollars to a variety of accounts, having been reassured by a group video call with the company’s CFO …