Cisco Duo provider breached, SMS MFA logs compromised

Hackers have managed to compromise a telephony provider for Duo, the Cisco-owned company providing secure access solutions, and steal MFA (multi-factor authentication) SMS message logs of Duo customers. About the attack The unnamed provider – one… Continue reading Cisco Duo provider breached, SMS MFA logs compromised

Microsoft: Enterprise MFA adoption still low

While two-factor authentication usage in the consumer space is climbing quickly, enterprises are still straggling when it comes to using multi-factor authentication (MFA) to protect crucial accounts, despite the fact that compromised credentials are th… Continue reading Microsoft: Enterprise MFA adoption still low

Noname Security appoints Matt Tesauro as API Security Evangelist

Noname Security announced the appointment of Matt Tesauro as its API Security Evangelist. Tesauro will engage with Noname customers and the security industry at large, contributing to standards bodies and sharing his experience, insights and strategies… Continue reading Noname Security appoints Matt Tesauro as API Security Evangelist

Multi-factor authentications soar as enterprises move away from passwords to secure hybrid workers

Enterprises are taking steps to move away from passwords and adopting low-friction authentication methods to protect the hybrid workforce, a Cisco’s Duo Security report reveals. Multi-factor authentications increased significantly While the total… Continue reading Multi-factor authentications soar as enterprises move away from passwords to secure hybrid workers

YubiKey Bio Series supports fingerprint recognition for passwordless and second factor logins

Yubico launched YubiKey Bio Series, the first YubiKey series that supports fingerprint recognition for secure passwordless and second factor logins. Built for biometric authentication on desktops, the YubiKey Bio Series supports modern FIDO2/WebAuthn a… Continue reading YubiKey Bio Series supports fingerprint recognition for passwordless and second factor logins

Cisco introduces infrastructure agnostic, passwordless authentication by Duo

Cisco Secure unveiled the future of simple and effective security with infrastructure agnostic, passwordless authentication by Duo. Integrated seamlessly into the existing Duo authentication experience used by more than 25,000 organizations globally, D… Continue reading Cisco introduces infrastructure agnostic, passwordless authentication by Duo

The security consequences of massive change in how we work

Organizations underwent an unprecedented IT change this year amid a massive shift to remote work, accelerating adoption of cloud technology, Duo Security reveals. The security implications of this transition will reverberate for years to come, as the h… Continue reading The security consequences of massive change in how we work

Government learns that authenticators are key part of modernization

Now that federal agencies have shifted to mass telework and sorted through many of the related hardware and software needs, they’re able to take a closer look all the pieces necessary to implement zero-trust security architecture, a cybersecurity expert says. In particular, agencies have greatly embraced the use of different kinds of authenticators to help identify users and control their network access, said Brian Rosensteel, Cybersecurity Architect at Duo Security, during an SNG Live virtual discussion panel hosted by Scoop News Group on Oct. 20. Federal IT leaders are seeing that for telework, old forms of proving identity don’t translate, and they’re looking for other solutions. “That’s where we’ve seen zero trust really starting to take place,” he said. The zero-trust model assumes that the network is penetrable, so it forces users to verify themselves for each set of data or applications they want to access once they’re on the […]

The post Government learns that authenticators are key part of modernization appeared first on CyberScoop.

Continue reading Government learns that authenticators are key part of modernization

Can we trust passwordless authentication?

We are beginning to shift away from what has long been our first and last line of defense: the password. It’s an exciting time. Since the beginning, passwords have aggravated people. Meanwhile, passwords have become the de facto first step in most atta… Continue reading Can we trust passwordless authentication?

Critical flaw opens Palo Alto Networks firewalls and VPN appliances to attack, patch ASAP!

Palo Alto Networks has patched a critical and easily exploitable vulnerability (CVE-2020-2021) affecting PAN-OS, the custom operating system running on its next generation firewalls and enterprise VPN appliances, and is urging users to update to a fixe… Continue reading Critical flaw opens Palo Alto Networks firewalls and VPN appliances to attack, patch ASAP!