CISA Expands ‘Bad Practices’ List With Single-Factor Authentication

CISA Expands ‘Bad Practices’ List With Single-Factor Authentication

The United States Cybersecurity and Infrastructure Security Agency (CISA) this week added single-factor authentication to its list of bad practices. “Single-factor authentication is a common low-security method of authentication. It only requires matching one factor—such as a password—to a username to gain access to a system,” CISA says. While the agency mainly refers to “the…

‘ProxyToken’ Exchange Server Vulnerability Leads to Email Compromise

‘ProxyToken’ Exchange Server Vulnerability Leads to Email Compromise

A vulnerability that Microsoft patched in Exchange Server earlier this year can allow attackers to set forwarding rules on target accounts and gain access to incoming emails. Tracked as CVE-2021-33766 and referred to as ProxyToken, the vulnerability has a severity rating of medium (CVSS score of 6.5). The security hole was identified by Le Xuan…

Get Lifetime Access to 24 Professional Cybersecurity Certification Prep Courses

Get Lifetime Access to 24 Professional Cybersecurity Certification Prep Courses

Get Lifetime Access to 24 Professional Cybersecurity Certification Prep Courses | IT Security News 29. August 2021 This article has been indexed from The Hacker News Not all heroes wear capes. Cybersecurity professionals are digital warriors who use their knowledge and skill to battle malicious hackers. Sounds like an exciting career, right? If the comic-book comparisons aren’t…

Don’t use single-factor auth on Internet-exposed systems

Don’t use single-factor auth on Internet-exposed systems

Single-factor authentication (SFA) has been added today by the US Cybersecurity and Infrastructure Security Agency (CISA) to a very short list of cybersecurity bad practices it advises against. CISA’s Bad Practices catalog includes practices the federal agency has deemed “exceptionally risky” and not to be used by organizations in the government and the private sector as…

CISA Adds Single-Factor Authentication to the List of Bad Practices

CISA Adds Single-Factor Authentication to the List of Bad Practices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added single-factor authentication to the short list of “exceptionally risky” cybersecurity practices that could expose critical infrastructure as well as government and the private sector entities to devastating cyberattacks. Single-factor authentication is a method of signing in users to websites and remote systems by using…

Check Point Software acquires cloud email security company Avanan, IT News, ET CIO

Check Point Software acquires cloud email security company Avanan, IT News, ET CIO

JERUSALEM: Check Point Software Technologies said on Monday it acquired U.S.-Israeli cyber security company Avanan, which specialises in protecting email, where most cyber attacks begin. Check Point, which is based in Israel, did not disclose financial details. “More and more businesses are moving to cloud-email platforms and with email becoming a major channel to launch…