Key takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]
Read MoreAttackers have been taking administrative control of the Wi-Fi gateways that hotels and conference centres use to run their guest networks, then quietly rewriting DNS so that travelling employees who try to reach Microsoft 365 land on a page the attacker controls instead. The activity was documented by ReliaQuest Threat Research and has been running […]
Read MoreKey takeaways MFA is the single highest-value security control most businesses can deploy, and it is usually low-cost or free. Microsoft reports it blocks more than 99% of automated account-compromise attacks, the kind that make up the vast majority of what hits your business daily. Not all MFA is equal. SMS codes are the weakest […]
Read MoreKey takeaways: Your password is the first line of defence for almost everything you do online, more important than any software. The biggest risk is reuse. If one site is breached, attackers try that same password everywhere else you use it. Length beats complexity. A long passphrase made of several random, unrelated words is both […]
Read More