Attackers Target Check Point VPNs to Access Corporate Networks

May 28, 2024 at 03:37PM Researchers have seen a rise in attackers using remote access VPNs for unauthorized network access. Check Point’s leadership noted three such attempts and advised organizations to strengthen VPN security by requiring more than just passwords. Industry experts recommend modern authentication methods and transitioning to Zero Trust Network Access for better … Read more

Check Point VPN Targeted for Initial Access in Enterprise Attacks

May 28, 2024 at 05:33AM Check Point advises customers to review VPN configurations to prevent abuse by threat actors, citing attempts to gain access through old VPN local accounts with password-only authentication. The company recommends using additional authentication measures, deploying products on security gateways, and disabling unnecessary local accounts. It also provides a script and … Read more

New Flaws in Fingerprint Sensors Let Attackers Bypass Windows Hello Login

November 22, 2023 at 10:30AM Multiple vulnerabilities have been discovered in fingerprint sensors on Dell Inspiron 15, Lenovo ThinkPad T14, and Microsoft Surface Pro X laptops. The flaws allow bypassing Windows Hello authentication. Researchers found weaknesses in the fingerprint sensors from Goodix, Synaptics, and ELAN. Exploiting these vulnerabilities requires users to have fingerprint authentication set … Read more

Amazon adds passkey support as new passwordless login option

October 17, 2023 at 03:09PM Amazon has introduced passkey support as a passwordless login option to enhance security for customers. Passkeys are digital credentials that use biometric controls or PINs linked to devices for logging into websites. They mitigate the risk of data breaches, compromised accounts, phishing attacks, and information-stealing malware. Passkeys also simplify the … Read more