1Password for Teams and Business1password.com
As always I'm extremely grateful to 1Password for supporting the newsletter. If you have passwords or secure notes to share with your colleagues, I highly recommend you give them a try.
Supported by 1Password.
As always I'm extremely grateful to 1Password for supporting the newsletter. If you have passwords or secure notes to share with your colleagues, I highly recommend you give them a try.
Even though I've been very short on time this week, I seem to have written longer summaries than usual. Consider yourself warned. And I'll try to keep them shorter next time ;-)
This does warrant its own item. Hackers hijacked the credentials of a helpdesk employee, which gave them access to any non-corporate Outlook.com and Hotmail accounts. It boggles the mind that that level of access exists, and apparently doesn't even require 2fa or proper auditing on its usage. Seriously uncool Microsoft. Hackernews discussion here.
The campaign has been going on for a while and seems very successful, even hijacking multiple country-code top-level domains. The targets seem to be mostly governmental.
Please make sure your DNS accounts are as secure as you can make them. Remember, once you have control over someones DNS you can do pretty much everything, including hijacking every visit to their website without anyone knowing, or redirecting e-mail.
Some insight in this year's NATO cybersecurity wargame, where blue teams of various countries have to defend both the critical infrastructure and the elections of the fictitious country of Berylia.
Most ransomware infects a computer and then starts encrypting the files on the machine itself. This one tries to brute-force its way into an online exposed Samba server and then encrypts everything remotely. It doesn't change much to the root cause of the problem but I found it interesting, I never realised the nuance between local and remote ransomware.
NoScript is a much loved Firefox extension that allows you to block Javascript, Flash and other content from domains you don't trust. You can now also get it for Chrome here.
Pretty cool move from Google. Whatever lowers the bar to proper 2fa sure has my vote. Any Android 7 phone can now be used as a two-factor device, where you validate a login by pressing a button. As with all 2fa, remember to set a backup device or securely store backup codes in case you lose your phone.
It's always fascinating to get a glimpse in the inner workings of cybercrime. I found this to be a great read, detailing how three Romanians went from small-time eBay scamming to operating a 400.000-strong botnet and hijacking bank accounts. All three will be sentenced later this year.