Passkey Redaction Attacks Subvert GitHub, Microsoft Authentication

July 2, 2024 at 06:08PM Many online accounts using passkey technology are still vulnerable to adversary-in-the-middle (AitM) attacks, allowing attackers to manipulate the login screen and remove passkey authentication. This discovery by security researcher Joe Stewart highlights the need for more secure authentication methods and account recovery options. Enterprises can mitigate this risk by implementing … Read more

FCC Enforces Stronger Rules to Protect Customers Against SIM Swapping Attacks

November 17, 2023 at 07:48AM The FCC is implementing new rules to protect consumers from SIM-swapping attacks and port-out fraud. These scams involve malicious actors gaining control of a consumer’s phone number without physical access to the device. The rules require wireless providers to use secure authentication methods and notify customers of any SIM changes … Read more

Make API Management Less Scary for Your Organization

October 24, 2023 at 08:09AM API modernization is crucial for organizations to enhance security and protect against threats like data breaches and unauthorized access. To achieve this, organizations should use strong authentication methods, encryption for data transfer, access control policies, real-time monitoring, security audits, and employee education. Gloo Gateway is a cloud-native API management solution … Read more