A tool new to MageCart bolsters the group’s ability to evade detection and steal data.
from Dark Reading: https://ift.tt/2YpVG0c
via IFTTT
A tool new to MageCart bolsters the group’s ability to evade detection and steal data.
from Dark Reading: https://ift.tt/2YpVG0c
via IFTTT
It might be difficult to fathom how this isn’t already mandatory, but Microsoft Corp. says it will soon force all Cloud Solution Providers (CSPs) that help companies manage their Office365 accounts to use multi-factor authentication. The move comes amid a noticeable uptick in phishing and malware attacks targeting CSP employees and contractors.

When an organization buys Office365 licenses from a reseller partner, the partner is granted administrative privileges in order to help the organization set up the tenant and establish the initial administrator account. Microsoft says customers can remove that administrative access if they don’t want or need the partner to have access after the initial setup.
But many companies partner with a CSP simply to gain more favorable pricing on software licenses — not necessarily to have someone help manage their Azure/O365 systems. And those entities are more likely to be unaware that just by virtue of that partnership they are giving someone at their CSP (or perhaps even outside contractors working for the CSP) full access to all of their organization’s email and files stored in the cloud.
This is exactly what happened with a company whose email systems were rifled through by intruders who broke into PCM Inc., the world’s sixth-largest CSP. The firm had partnered with PCM because doing so was far cheaper than simply purchasing licenses directly from Microsoft, but its security team was unaware that a PCM employee or contractor maintained full access to all of their employees’email and documents in Office365.
As it happened, the PCM employee was not using multi-factor authentication. And when that PCM employee’s account got hacked, so too did many other PCM customers.
KrebsOnSecurity pinged Microsoft this week to inquire whether there was anything the company could be doing to better explain this risk to customers and CSP partners. In response, Microsoft said while its guidance has always been for partners to enable and require multi-factor authentication for all administrators or agent users in the partner tenants, it would soon be making it mandatory.
“To help safeguard customers and partners, we are introducing new mandatory security requirements for the partners participating in the Cloud Solution Provider (CSP) program, Control Panel Vendors, and Advisor partners,” Microsoft said in a statement provided to KrebsOnSecurity.
“This includes enforcing multi-factor authentication for all users in the partner tenants and adopting secure application model for their API integration with Microsoft,” the statement continues. “We have notified partners of these changes and enforcement will roll out over the next several months.”
Microsoft said customers can check or remove a partner’s delegated administration privileges from their tenants at any time, and that guidance on how do do this is available here and here.
This is a welcome — if long overdue — change. Countless data breaches are tied to weak or default settings. Whether we’re talking about unnecessary software features turned on, hard-coded passwords, or key security settings that are optional, defaults matter tremendously because far too many people never change them — or they simply aren’t aware that they exist.
from Krebs on Security https://ift.tt/2JcXxPk
via IFTTT
Key Biscayne is the third Florida town to be hit by hackers in June.
from Dark Reading: https://ift.tt/2FFHt7K
via IFTTT
Attackers were reportedly able to compromise email and file-sharing systems for some of PCM’s customers.
from Dark Reading: https://ift.tt/2ZVNhlu
via IFTTT
Looking at underlying security needs means organizations are more likely to be in compliance with privacy regulations.
from Dark Reading: https://ift.tt/2XbLbkp
via IFTTT
This year Black Hat USA is introducing special half-day programs focused on important topics that combine subject matter expertise with networking opportunities.
from Dark Reading: https://ift.tt/2IVz81Q
via IFTTT
“I’m not a voyeur, I’m a technology enthusiast,” says the creator, who combined deepfake AI with a need for cash to get ka-CHING!
from Naked Security https://ift.tt/2XaAuhY
via IFTTT
With partner abuse increasingly going digital, we took an in-depth look this week at what needs to be done to stop the scourge of stalkerware
The post Week in security with Tony Anscombe appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/2KMmpk3
via IFTTT
In an effort to show you how advertisers snoop on your surfing activity, Mozilla is offering you the chance to pretend that you’re someone else.
from Naked Security https://ift.tt/31VB8i4
via IFTTT
Trying to save 20 minutes, 100 drivers took a Google Maps shortcut… into a field, where the mud-stuck cars then caused a 2-hour delay.
from Naked Security https://ift.tt/2X4vDdq
via IFTTT