Topic: active directory security

  • World Cup Password Trends Raise Active Directory Risk

    World Cup Password Trends Raise Active Directory Risk

    The 2026 FIFA World Cup is driving password trends where users create credentials based on football-related references, which can introduce security risks in Active Directory environments even when passwords technically meet complexity requirements. Specops Software's analysis of over 6.4 billion...

    Read More »
  • Enforce Strong Active Directory Passwords Without Frustrating Users

    Enforce Strong Active Directory Passwords Without Frustrating Users

    Effective AD password policies should prioritize length over complexity by encouraging passphrases of at least 15 characters, as recommended by NIST, to improve security and user recall. Organizations must actively block weak and compromised passwords using tools like banned word lists and breach...

    Read More »
  • Why Password Changes Fail to Stop Active Directory Breaches

    Why Password Changes Fail to Stop Active Directory Breaches

    A password reset in Active Directory or hybrid Entra ID environments does not instantly invalidate old credentials across all authentication paths, leaving a window for attackers to exploit. Attackers exploit this gap using techniques like pass-the-hash on cached credentials, active Kerberos tick...

    Read More »
  • $30,000 GPU Password Cracking Test: Results

    $30,000 GPU Password Cracking Test: Results

    A benchmark test found that high-end consumer GPUs, like the Nvidia RTX 5090, significantly outperform expensive AI accelerators (Nvidia H200, AMD MI300X) in password-cracking speed, making specialized AI hardware a poor investment for this purpose. The primary organizational risk is not advanced...

    Read More »
  • Blumira Boosts EDR & ITDR for Faster Threat Response

    Blumira Boosts EDR & ITDR for Faster Threat Response

    Blumira has upgraded its EDR and ITDR features to enable faster threat containment, allowing security teams to isolate endpoints, terminate processes, and lock out attackers directly from a unified dashboard. The enhancements address the rising threat of ransomware and identity-based attacks by i...

    Read More »
  • Master NIS2 Compliance: Secure Passwords & MFA

    Master NIS2 Compliance: Secure Passwords & MFA

    The NIS2 Directive is a critical EU regulation requiring medium and large organizations in key sectors to implement stringent security controls, with a major focus on robust identity and access management to combat credential-based attacks. Compliance is mandatory for qualifying organizations, an...

    Read More »
  • ManageEngine Boosts Identity Threat Protection

    ManageEngine Boosts Identity Threat Protection

    ManageEngine's AD360 platform has introduced new risk exposure management and multi-factor authentication (MFA) features to address critical vulnerabilities like privilege escalation and unsecured local accounts. Credential abuse remains a top attack vector, with 22% of breaches linked to poorly ...

    Read More »
  • 35 Must-Have Open-Source Security Tools for Red Teams & SOCs

    35 Must-Have Open-Source Security Tools for Red Teams & SOCs

    The article highlights 35 essential open-source security tools for various domains like cloud security, threat hunting, and vulnerability management, aiding red teams and SOC analysts. Key tools include Autorize for authorization testing, BadDNS for DNS security, and Beelzebub for...

    Read More »