Recent Security News
-
Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication
October 14, 2023 at 02:48AM Microsoft plans to eliminate NT LAN Manager (NTLM) in Windows 11, focusing instead on strengthening the Kerberos authentication protocol. New features in Windows 11 include Initial and Pass Through Authentication Using Kerberos (IAKerb) and a local Key Distribution Center (KDC) for Kerberos. NTLM has vulnerabilities that make it susceptible to…
-
The Week in Ransomware – October 13th 2023 – Increasing Attacks
October 13, 2023 at 06:31PM Ransomware attacks on enterprises are causing disruption and data breaches. Recent attacks include Air Canada being targeted by BianLian, and state courts in Northwest Florida being attacked by ALPHV. Simpson Manufacturing experienced a cybersecurity incident, and a threat actor leaked the source code for the Hello Kitty ransomware. Ransomware trends…
-
How MOVEit Is Likely to Shift Cyber Insurance Calculus
October 13, 2023 at 04:59PM Progress Software plans to collect on its $15 million cyber insurance policy in light of the recent class action lawsuits and fines it faces due to security breaches caused by its MOVEit file transfer software. This large payout is likely to impact how insurers approach their businesses as premiums increase…
-
Feds: Beware AvosLocker Ransomware Attacks on Critical Infrastructure
October 13, 2023 at 04:59PM US authorities, including the Cybersecurity Infrastructure and Security Agency (CISA) and FBI, have issued a warning about the AvosLocker ransomware-as-a-service (RaaS) operation that poses a threat to critical infrastructure. AvosLocker has targeted multiple industries in the US, using various tactics such as double extortion and trusted software. Ransomware attacks have…
-
Passkeys Are Cool, But They Aren’t Enterprise-Ready
October 13, 2023 at 04:38PM Passkeys, a passwordless authentication technology supported by major internet firms like Apple, Google, and Microsoft, offer a user-friendly solution for accessing websites and cloud applications. However, their usability does not meet the control and attestation requirements of large corporations. Passkeys are expected to be integrated into the existing public key…