Posts

Showing posts from April 28, 2024

Weak passwords continue to exist in 2024

Image
Concept artwork of handwritten passwords on sticky notes, generated by Blue Willow . World Password Day , the first Thursday in May, has come round again — highlighting one of the vulnerabilities in our cyberdefences. Darren Guccione, CEO and co-founder, Keeper Security, noted that weak and compromised credentials remain the leading cause of breaches. "In a new study by Keeper Security, 92% of IT security leader respondents revealed that cyberattacks are more frequent now than one year ago — and are growing more sophisticated," he said.  "While no one likes updating their passwords, World Password Day is a great time to recognise and enforce this critical best practice. Passwords act as the first line of defence — protecting access to applications, systems, secrets and IT resources."  Keeper Security  found that  only 25% of people are using strong, unique passwords for all their accounts, which leaves 75% of individuals with dangerously weak password ...

Microsoft vulnerabilities cluster around privileges, denial of service in 2023

BeyondTrust , the intelligent identity and access security provider, has released the 2024 Microsoft Vulnerabilities Report . Produced annually, this report analyses data from security bulletins* publicly issued by Microsoft throughout the previous year and helps organisations understand, identify, and address the risks within their Microsoft ecosystems.  Total and critical vulnerabilities demonstrated some of the most consistent data, year over year, since this report’s debut, a strong indicator that overall long-term security efforts are paying off. This may also reflect that attackers are increasingly refocusing their efforts on exploiting identities, rather than Microsoft software vulnerabilities. After hitting an all-time high in 2022, total vulnerabilities continue their four-year holding pattern near their highest-ever numbers in 2023, remaining between 1,200 and 1,300 (since 2020). - The Elevation of Privilege vulnerability category continues to dominate, accounting for 4...