Topic: conditional access
-
ConnectSecure automates M365 security fixes for MSPs
ConnectSecure launched M365 Auto Remediation and AI-powered Training Assessments, enabling MSPs to directly address Microsoft 365 security findings and create, assign, and track training assessments within a single console. M365 Auto Remediation allows MSPs to fix supported findings (e.g., missin...
Read More » -
Health-ISAC warns healthcare of rising ShinyHunters attacks
ShinyHunters is increasingly targeting healthcare organizations by breaching cloud SaaS and storage platforms through supply chain and identity attacks, using stolen OAuth tokens and compromised single-sign-on (SSO) accounts to access entire cloud data ecosystems for extortion. The attack chain b...
Read More » -
New OAuth Spoofing Attack Exploits Client IDs in Cloud Environments
Cyberattackers are using OAuth client ID spoofing to infiltrate cloud environments via Microsoft Entra ID, exploiting the Resource Owner Password Credentials (ROPC) flow to send POST requests and infer valid credentials and security controls like MFA. This technique evades detection in Entra sign...
Read More » -
Device Security Must Share the Load Beyond Identity
Identity verification alone is no longer sufficient for security, as AI-powered phishing, credential theft, and session hijacking allow attackers to bypass authentication and steal session tokens even after MFA succeeds. Zero Trust frameworks like NIST 800-207 warn against relying on implied trus...
Read More » -
Microsoft Entra passkeys for Windows arriving late April
Microsoft will launch passkey support for phishing-resistant passwordless authentication on Windows devices in late April 2026, with general availability by mid-June, enabling secure sign-in on unmanaged devices. The feature creates device-bound FIDO2 passkeys stored in the Windows Hello containe...
Read More » -
OAuth Redirects Exploited to Deliver Malware
A sophisticated phishing campaign exploits OAuth's error-handling to redirect users from legitimate login pages to attacker-controlled sites, bypassing standard security filters. The attacks use convincing business-themed email lures to trick users into clicking links that lead to credential thef...
Read More » -
Secure Access: The Persistent Vulnerability
The traditional security model of relying solely on identity verification is inadequate for today's distributed workforce, as it fails to assess the risk of the specific device and context used for access. Attackers exploit this flaw by using stolen credentials from untrusted devices, highlightin...
Read More » -
A Step-by-Step Guide to Implementing Zero Trust
Zero trust security shifts from assuming internal network trust to continuously verifying every user, device, and application attempting to access resources, starting with foundational actions like enforcing multi-factor authentication (MFA) and removing stale accounts. The model adds intelligent...
Read More » -
Microsoft's New AI Security Agents Outsmart Hackers
Microsoft has launched advanced AI security agents that proactively identify and neutralize cyber threats, available at no extra cost for Security Copilot users on Microsoft 365 E5 plans. These AI agents are integrated into platforms like Defender, Entra, and Intune to shift security from reactiv...
Read More » -
VPN Credentials Fuel 50% of Ransomware Attacks
Ransomware activity surged in Q3 2025, with compromised VPN credentials being the primary entry point for nearly half of all breaches, driven mainly by three groups: Akira, Qilin, and INC Ransomware. The Akira group specifically targeted SonicWall appliances using credential stuffing attacks, exp...
Read More » -
Ransomware Attackers Wipe Azure Data and Backups After Theft
A new wave of cloud-focused ransomware attacks by group Storm-0501 systematically wipes primary data and backups in Microsoft Azure, leaving organizations with no recovery options. The group exploits native cloud functionalities to exfiltrate large volumes of data without on-premises hardware, ma...
Read More »