article thumbnail

US Cyber Safety Review Board on the 2023 Microsoft Exchange Hack

Schneier on Security

US Cyber Safety Review Board released a report on the summer 2023 hack of Microsoft Exchange by China. It was a serious attack by the Chinese government that accessed the emails of senior U.S. government officials. From the executive summary: The Board finds that this intrusion was preventable and should never have occurred.

Hacking 258
article thumbnail

Kicking off NIST's Cybersecurity Awareness Month Celebration & Our Cybersecurity Awareness Month 2023 Blog Series

NSTIC

This year is a big one because 2023 marks the 20 th anniversary of this important initiative —and we will celebrate in various ways every day throughout the month. We’ll be using our NIST Cybersecurity Awareness Month website to share information about our events, resources, blogs, and how to stay involved.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Account takeover data, consumer insights, and emerging trends in 2023

Security Boulevard

See findings from Sift’s Q3 2023 Digital Trust & Safety Index on account takeover data, consumer insights, and emerging trends. The post Account takeover data, consumer insights, and emerging trends in 2023 appeared first on Sift Blog.

article thumbnail

Grip Security Blog 2023-05-22 15:44:00

Security Boulevard

When SaaS services are compromised, Grip enables security teams to take action by destroying existing credentials, identifying user accounts (past and present), and continuously rotating double-blind passwords to blunt identity attacks from compromised credentials. Get started with a SaaS-Identity Risk Assessment.

article thumbnail

Grip Security Blog 2023-05-22 15:54:43

Security Boulevard

Fortify The Identity Perimeter ‍The explosion of SaaS adoption has led to unprecedented identity sprawl with some employees creating hundreds of SaaS accounts over the time. Most of these accounts are created with just an email and password, and this has now become the new perimeter for the modern enterprise.

Risk 59
article thumbnail

All GitHub Users Will Need to Enable 2FA by the End of 2023

Heimadal Security

GitHub recently announced that it will require all users who contribute with code on the platform to enable two-factor authentification over the course of 2023. Two-factor authentication (2FA) makes accounts safer by adding an extra step that requires entering a one-time code during the login process.

article thumbnail

VMware addressed two zero-day flaws demonstrated at Pwn2Own Vancouver 2023

Security Affairs

VMware released security updates to address two zero-day vulnerabilities ( CVE-2023-20869, CVE-2023-20870 ) that were chained by the STAR Labs team during the Pwn2Own Vancouver 2023 hacking contest against Workstation and Fusion software hypervisors. They earned $80,000 and 8 Master of Pwn points.

Hacking 98