The previous week’s articles are featured below.
Huntress Labs/Bleeping Computer
Most of us in IT spend our energy trying to keep attackers out. But a recent incident investigated by Huntress tells us a lot about what happens after an attacker gets in (and why it matters just as much).
Once an attacker has gained initial access, they don’t rush straight to the smash-and-grab, doing things like stealing data, encrypting files, or dropping ransomware. Instead, they take time to dwell and settle in—creating backdoors, covering their tracks, and disabling the tools meant to catch them…
Read moreIonut Arghire, Security Week
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of traveling corporate employees, ReliaQuest reports…
Read more
David Strom, CSO Online
Use of multifactor authentication is on the rise, but must be done right to be an effective security tool. Here’s how to protect your org against common MFA attacks and threat modalities.
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while often saddling users with an extra workflow burden — one of many obstacles to MFA’s success.
Read moreLawrence Abrams, Bleeping Computer
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
The guidance, titled “CI Fortify – Advice for isolating vital systems,” was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners…
Read more