Apple DEP vulnerability lets attackers access orgs’ resources, info

An authentication weakness in Apple’s ​Device Enrollment Program​ (DEP) may allow attackers to enroll any device into an organization’s Mobile Device Management server and, consequently, to obtain privileged access to the private resources … Continue reading Apple DEP vulnerability lets attackers access orgs’ resources, info

Phished credentials caused twice as many breaches than malware in the past year

Personal device use for remote work poses the biggest security risk to organisations safeguarding their increasingly mobile and cloud-based IT environment, according to a new survey of 100 UK-based senior IT security professionals. Conducted from March… Continue reading Phished credentials caused twice as many breaches than malware in the past year

Researchers to release open source tools to identify Twitter bots at scale

Duo Security published technical research and methodology detailing how to identify automated Twitter accounts, known as bots, at a mass scale. Using machine learning algorithms to identify bot accounts across their dataset, Duo Labs researchers also u… Continue reading Researchers to release open source tools to identify Twitter bots at scale

Cisco Outlines Strategy Post $2.35B Duo Security Deal

Cisco Systems is gearing up to extend its cybersecurity reach all the way out to the endpoint, in the wake of plopping down $2.35 billion to acquire Duo Security, a provider of identity management software delivered as cloud service. The deal, which i… Continue reading Cisco Outlines Strategy Post $2.35B Duo Security Deal

Cisco to acquire Duo Security for $2.35 billion

Cisco is planning to buy Duo Security, a company that provides enterprises with secure multi-factor authentication services, for $2.35 billion, the two companies announced on Thursday. Duo Security is largely seen as a leader in the multi-factor authentication space and is best known for its “zero-trust” security platform, which helps companies verify the identity and trust of the various user endpoints on their networks. Based in Ann Arbor, Michigan with other offices in the U.S. and London, the company has raised more than $121 million in venture capital funding since it was founded in 2010. “Cisco created the modern IT infrastructure, and together we will rapidly accelerate our mission of securing access for all users, with any device, connecting to any application, on any network,” said Duo CEO Dug Song in a statement. “By joining forces with the world’s largest networking and enterprise security company, we have a unique opportunity […]

The post Cisco to acquire Duo Security for $2.35 billion appeared first on Cyberscoop.

Continue reading Cisco to acquire Duo Security for $2.35 billion

Cisco to Acquire Duo Security for $2.35 Billion in Cash

Cisco just announced a big acquisition, in the size of $2.35 billion in cash. The company is acquiring cloud-based identity and access management solutions provider Duo Security. “Cisco (NASDAQ: CSCO) today announced its intent to acquire private… Continue reading Cisco to Acquire Duo Security for $2.35 Billion in Cash

Google: Security Keys Neutralized Employee Phishing

Google has not had any of its 85,000+ employees successfully phished on their work-related accounts since early 2017, when it began requiring all employees to use physical Security Keys in place of passwords and one-time codes, the company told KrebsOnSecurity. Continue reading Google: Security Keys Neutralized Employee Phishing

No one is updating their Android devices, new data shows

It’s typically good advice to patch early and often. What’s said less often is that most of the time it just isn’t happening. Duo Security has new data to back that up: The company released a study Wednesday finding 90 percent of over 10.7 million Android devices across the U.S. and Western Europe are running outdated versions of the operating system. Additionally, only 8 percent of Android phones ran the latest security patch, according to the report. It’s a significant gap that’s due in large part to Android’s enormous, fractured ecosystem. Users often receive updates haphazardly through their carriers or phone manufacturers, and that’s if they get them at all. Attackers often take advantage of this, with new malware frequently popping up that preys on old Android models. Even as Android’s competitor Apple is doling out patches through its App Store, there is an significant gap in users updating to […]

The post No one is updating their Android devices, new data shows appeared first on Cyberscoop.

Continue reading No one is updating their Android devices, new data shows