Security


FIDO Authenticate Keynote Talk Calls for 'Radical' Industry Transparency on Multifactor Authentication Use

The Authenticate 2022 keynote talk highlighted passwordless efforts by the FIDO Alliance and called for increased multifactor authentication transparency by industry sectors.

Microsoft Server Misconfiguration Led to Exposed Customer Data

Microsoft on Wednesday confirmed that a misconfiguration with a Microsoft server endpoint has potentially exposed some customer data, including personal information and emails.

On the Floor of Microsoft Ignite: Day 1 Announcement Thoughts

Despite a smaller floor presence, Microsoft jumped out of the gate with some big announcements for IT and database managers.

Freeeway Tunnel Graphic

Microsoft 365 and Security Products Reaching General Availability at Microsoft Ignite

A lot of products were announced at the "general availability" (GA) commercial-release stage during this week's Microsoft Ignite event, which kicked off on Wednesday.

Microsoft's October Security Patch Missing Zero-Day Exchange Fix

This month's Microsoft monthly security update, which comes packed with 85 flaw fixes, is notable for what's not included – a fix for last month's publicly disclosed Exchange vulnerabilities, known as "NotProxyShell."

Microsoft Endpoint Manager Enables AOSP Android Device Management via Premium Add-On

Microsoft this week announced the ability to manage Android Open Source Project (AOSP) devices via Microsoft Intune, which is available as a "premium" add-on to Microsoft Endpoint Manager (MEM) subscribers.

Identity Theft Monitoring Offered to Microsoft 365 Consumer Users

Microsoft this week announced that a new Identity Theft Monitoring service is available to U.S. subscribers to the Microsoft 365 Personal or Microsoft 365 Family editions.

Microsoft Confirms Two Zero Day Exploits of Exchange Server

Exchange Server products are potential subject two newly disclosed "zero-day" vulnerabilities that are under exploit, Microsoft acknowledged, in a Thursday announcement.

Microsoft Authenticator Features Can Address 'MFA Fatigue Attacks'

Microsoft is urging organizations using the Microsoft Authenticator app to activate additional security functionality to protect against possible "multifactor authentication fatigue attacks," according to a Wednesday announcement.

Microsoft Enhances Phishing Protections for Windows 11, but Not Windows 10

Microsoft offered more details this week about its enhanced phishing protection technology that kicked off with the newly released Windows 11 version 22H2.

Microsoft September Patch Bundle Addresses 64 Vulnerabilities

Microsoft has released its September bundle of security patches, addressing about 64 common vulnerabilities and exposures (CVEs).

Why Immutable Backup Storage Isn't Enough Protection Against Ransomware

To truly protect your data from attackers, take some time to follow these additional safeguards.

Google Cloud Now Bolstered by Mandiant Security Services

Google announced on Monday that it has completed its acquisition of security solutions company Mandiant.

Los Angeles Unified School District Hit by Ransomware Attack

The Los Angeles Unified School District reported on Monday that a ransomware attack had occurred.

Microsoft Adds Azure AD Security and Compliance Perks

Microsoft this week announced Azure Active Directory enhancements for organizations that likely will better address some security and compliance issues.

Microsoft Permits 3-Month Reprieve Before Ending Basic Authentication for Exchange Online Users

Microsoft still intends to turn off Basic Authentication for Exchange Online users on Oct. 1, but it is offering a possible grace period of about three months before ending it altogether.

Microsoft Describes 'MagicWeb' Attacks Using Active Directory Federation Services

Microsoft on Wednesday described "MagicWeb" attacks by an advanced persistent threat group called "Nobelium," advising organizations using Active Directory Federation Services (ADFS) to take hardening steps.

Network and Web Protections in Microsoft Defender for Endpoint Now Available at Preview for Linux and macOS Devices

Microsoft this week announced public previews of Network Protection and Web Protection capabilities for Linux and macOS devices in its Microsoft Defender for Endpoint solution.

Microsoft Disrupts Major Russian Phishing Group

Microsoft this week announced it had taken actions to cripple the Russia-based SEABORGIUM cybercriminal group.

Examining Microsoft 365 Privacy Options

You might not be able to stay hidden from your employer's watchful eye, but you do have some control on the amount of visibility.

Subscribe on YouTube