Security


Microsoft Expanding Cybersecurity Worker Shortage Initiative

In three years there will be 3.5 million vacant cybersecurity jobs across the globe. And that's going to lead to real problems in addressing the growing threat landscape, according to Microsoft.

Okta Confirms Lapsus$ Attack, While Microsoft Investigates Breach Claim

Identity services provider Okta on Tuesday stated that its service wasn't breached by Lapsus$ attackers, although the account of a third-party support engineer working with Okta did get hacked back in January.

U.S. Infrastructure Operators Urged To Harden Security Immediately

The Biden White House this week warned that U.S. "critical infrastructure" operators should "harden their cyberdefenses immediately" against possible Russian attacks.

Microsoft Previews Delaying Brute-Force NTLM Logon Guesses in Windows Server

Microsoft this week announced a preview of its next Windows Server ("VNext") enhancements, which includes a new approach for deterring brute-force attempts to guess system passwords and gain network access.

Misconfigured Multifactor Authentication Subject to Russian Attackers

Organizations should not only use multifactor authentication (MFA), but they should also ensure that it's not misconfigured to ward off possible Russian state-sponsored attacks.

Microsoft's Commitment To Addressing the Gender Gap in Cybersecurity

Women accounted for just 25 percent of the global cybersecurity force in 2021, according to Microsoft.

Microsoft 365 Services Getting Root Certificate Authority Switch in 2025

Microsoft gave notice this week that currently used Transport Layer Security (TLS) certificates associated with Microsoft 365 services and Azure Communication Services "will expire in May 2025."

Microsoft Packs 71 Flaw Fixes in March Patch Tuesday

Microsoft on Tuesday released its monthly patch rollout, addressing 71 vulnerabilities and exposures (CVEs), three of those tackling "critical" flaws.

Google To Acquire Security Firm Mandiant for $5.4 Billion

Google announced on Tuesday it's going big on security with the purchase of Virginia-based security firm Mandiant.

Defender for Azure Cosmos DB Preview Announced by Microsoft

Microsoft Defender for Cloud users are getting a preview of Microsoft Defender for Azure Cosmos DB, per a Tuesday Microsoft announcement.

Microsoft IDs FoxBlade Malware Attack Hours Before Russia's Invasion of Ukraine

Microsoft is not only voicing support for the Ukrainian people, it's also supplying what aid it can to the European country.

New Defender for Business Product Now Getting Released to Some Microsoft 365 Subscribers

Microsoft Defender for Business, a new security solution for small-to-medium organizations, is now at the "general availability" commercial-release stage for Microsoft 365 Business Premium subscribers, per a Tuesday Microsoft announcement.

Report Suggests Every Organization Has Exploitable Identity Risks

Identity security company Illusive this week announced a new identity risk management platform and an annual report on the state of identity-based security risks for organizations.

Microsoft Defender for IoT Version 22.1 Commercially Released

Microsoft this week announced Microsoft Defender for IoT version 22.1 at the "general availability" (GA) commercial-release stage.

Microsoft Defender for Cloud adds Google Cloud Protection

Microsoft on Wednesday announced a bunch of security product enhancements at the preview stage.

Report: 76% of Orgs Faced Ransomware Attacks in 2021

More than two thirds of enterprises experienced at least one ransomware incident last year, according to security vender Veeam.

Motherboard Image

Microsoft Cautions of Growing 'Ice Phishing' Threat on the Blockchain

This week Microsoft released a warning that it's seeing an increased number of phishing attempts aimed at web3 -- a term used to describe the decentralized environment created on the blockchain.

Microsoft Eliminates Need for ADFS with Azure Active Directory Certificate-Based Authentication Preview

Microsoft on Monday announced the availability of Azure Active Directory certificate-based authentication at the public preview stage.

The FIDO Impetus to Passwordless Authentications

The time is ripe for organizations to implement "phishing-resistant multifactor authentication" via FIDO standards, says advocate Andrew Shikiar.

Defender Portal Gets Microsoft Defender for Identity Capabilities

The Microsoft 365 Defender portal now supports some lagging Microsoft Defender for Identity capabilities that have reached the "general availability" (GA) commercial-release stage, Microsoft announced this week.

Subscribe on YouTube