Posts

Showing posts with the label FIDO Alliance

Microsoft: Phishing bypassed MFA in attacks against 10,000 orgs

Image
By Sergiu Gatlan,  Bleeping Computer Microsoft says a massive series of phishing attacks has targeted more than 10,000 organizations starting with September 2021, using the gained access to victims' mailboxes in follow-on business email compromise (BEC) attacks. The threat actors used landing pages designed to hijack the Office 365 authentication process (even on accounts protected by multifactor authentication (MFA) by spoofing the Office online authentication page. In some of the observed attacks, the potential victims were redirected to the landing pages from phishing emails using HTML attachments that acted as gatekeepers ensuring the targets were being sent via the HTML redirectors. After stealing the targets' credentials and their session cookies, the threat actors behind these attacks logged into the victims' email accounts. They subsequently used their access in business email compromise (BRC) campaigns targeting other organizations. "A large-scale phishing cam...

How Google passwordless sign-in will work

Image
By Chris Smith, BGR The first Thursday of May each year is World Password Day, which explains all the password-related announcements we saw this week. First, 1Password 8 for Mac launched with a few big new features. Then, Google started rolling out its Google Assistant password-changing feature. More importantly, Apple, Google, and Microsoft have announced plans to support passwordless sign-in . That last one is a massive cross-platform initiative that will bring us closer to killing passwords. In turn, this could significantly boost the security of online accounts, making them a lot harder to hack. It’ll take some time for websites and apps to support passwordless sign-in. But Google already gave us an idea of how it’ll all work. Proper password practices can help prevent hacks right now. You don’t need passwordless sign-in options if you’re already using unique, long passwords in connection with a password manager like 1Password or LastPass. These passwords are much harder to hack, e...

Apple, Google, Microsoft announce plans to drop passwords

Image
By Katie Smith, Paul Gerke, News Nation Now Apple, Google and Microsoft announced plans on Thursday to eliminate passwords and replace them with other secure sign-in methods. The announcement came just before World Password Day, which is recognized annually on the first Thursday of May. It highlights the use of safe password habits, but some major tech companies say password-only authentication is of the biggest security problems on the web. “Fundamentally, what we’re doing is letting you use your everyday device — the same thing that you do multiple times a day — to unlock your device now to log in, in a way that is just leaps and bounds more secure than anything that you’re doing today,” said Megan Shamas, a spokesperson for FIDO, the authentication company leading the charge. Together, Apple, Google and Microsoft plan to follow a standard created by the FIDO Alliance and the World Wide Web Consortium . That means that websites and apps could offer an “end-to-end passwordless op...