Most successful compromises of an organisation these days occur from a #Phishing email compromising an end user, and using the end user's workstation to attack the rest of the network.
If you compromise one endpoint, and you get the local admin password, nine times out of 10 it's game over, and you reuse those credentials in the environment to go and find what you're after. You don't need the main admin access. #CyberAware
In case you thought #2fa was added security. Iranian phishers bypass 2fa protections offered by Yahoo Mail and Gmail | Ars Technica https://t.co/seHVNWGzok
Laugh and blame the user all you want, but this lools like the PIN had to be entered after FaceID failed to recognize him. We have several security and usability failures at work here.
Talking about passwords on a technical level to people is hard because in their simplified threat model it sounds like you shouldn’t save your passwords anywhere to be safe. But you really should. In a password manager.
Indeed. @sonikpass already beating out everyone else with quantum tech to eliminate usernames, eliminate passwords and provide 100% verification for identity and proximity.
#advisor https://t.co/tbP1yMjJX1
A recent survey found that a one-fourth of the workers reuse a similar #password for all the online records, putting #corporate#cybersecurity in danger and asking for better training. What about your organization? > Via @juliasowells https://t.co/8CzSou0rZT