Burn Some Time with this Arduino Reddit Browser

If you’re like us, you probably spend more time browsing Reddit than you’d like to admit to your friends/family/boss/therapist. A seemingly endless supply of knowledge, wisdom, and memes; getting stuck on Reddit is not unlike looking something up on Wikipedia and somehow managing to spend the next couple hours just clicking through to new pages. But we’re willing to bet that none of us love browsing Reddit quite as much as [Saad] does.

He writes in to tell us about the handheld device he constructed which lets him view random posts from the popular /r/showerthoughts sub. Each press of the …read more

Continue reading Burn Some Time with this Arduino Reddit Browser

New vuln in Microsoft Active Directory lets attackers bypass multi-factor authentication

A vulnerability in Microsoft’s popular identity management directory could let an attacker breach multiple employee accounts in an organization by circumventing multi-factor authentication, according to new research from identity security company Okta. The directory in question is Microsoft’s Active Directory Federation Services (ADFS), which allows business partners from different organizations to sign in to shared web applications. A weakness in the multi-factor authentication protocol for ADFS means that a hacker equipped with a user’s password and second “factor,” such as an SMS message, could use that factor in place of any other employee’s in the organization, according to Okta. To breach another user in the organization, the hacker would need access to his or her user name and password on the same ADFS service. “Simply put, if just one employee in a global company wanted to – or if a bad actor compromised the account of one employee – they […]

The post New vuln in Microsoft Active Directory lets attackers bypass multi-factor authentication appeared first on Cyberscoop.

Continue reading New vuln in Microsoft Active Directory lets attackers bypass multi-factor authentication

Reddit Breach Takeaways: MFA and Access Management

Reddit has been hacked! Their SMS based authentication was not strong enough to prevent a breach, so they will be moving towards token-based two-factor authentication (2FA)—will that be enough? Discover how a strong cloud access management soluti… Continue reading Reddit Breach Takeaways: MFA and Access Management

Yale University, Spam’s Revival, and SDR – Paul’s Security Weekly #570

Reddit breached after hackers bypass 2FA, Yale University discloses old school data breach, and 5 steps to fight unauthorized cryptomining. All that and more, here on security weekly! Full Show Notes Subscribe to YouTube Channel
The post Yale Universit… Continue reading Yale University, Spam’s Revival, and SDR – Paul’s Security Weekly #570

A week in security (July 30 – August 5)

A roundup of the security news from July 30 – August 5, including cryptomining, big data, social engineering, and more.
Categories:

Security world
Week in security

Tags: big databreachcryptominingfacebookmalwarerecapredditSocial Engineeri… Continue reading A week in security (July 30 – August 5)