<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/passwords"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Passwords ]]></title>
                <link>https://www.itpro.com/uk/tag/passwords</link>
        <description><![CDATA[ All the latest passwords content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 16 Jul 2026 13:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ 1Password teams up with Anthropic to give Claude access to your credentials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/1password-teams-up-with-anthropic-to-give-claude-access-to-your-credentials</link>
                                                                            <description>
                            <![CDATA[ A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fdkgdXkJZezasXq4CfH8Wg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg">
                                                            <media:credit><![CDATA[1Password/Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:description>                                                            <media:text><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[Promotional image showing logos of 1Password and Anthropic placed side by side against a navy blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dLLcmT3NBWDWo5SPtGnEUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic’s Claude AI tool will be able fill in passwords through a new <a href="https://www.itpro.com/software/368008/lastpass-vs-1password">1Password </a>browser integration that gives it access to stored credentials, the two companies have announced. </p><p><a href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts">1Password's </a>new <em>1Password for Claude</em> service is a framework that allows agents to use stored credentials hosted in 1Password vaults without them ever reaching the model. </p><p>Access is granted per session, and scoped to a specific set of approved items so that authorization doesn’t carry over to other sessions. </p><p>According to <a href="https://www.itpro.com/software/368048/dashlane-vs-1password">1Password</a>, this means users can now authorize Claude to complete real-world tasks like booking travel and managing accounts securely, with credentials injected directly to the target system on their behalf.</p><p>"We need a new security model that is purpose-built for agents, not just humans. The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it,” said Nancy Wang, CTO of 1Password. </p><p>"Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><h2 id="how-1password-s-zero-exposure-framework-will-work">How 1Password’s ‘zero-exposure’ framework will work</h2><p>1Password's zero-exposure security framework allows per-task, user-approved access, with Claude requesting the credentials required for each task from 1Password.</p><p>Users can approve or deny access with a single biometric prompt, eliminating standing access or persistent sessions.  </p><p>Credentials are injected through a secure channel managed by 1Password, outside the agent's view, with the password and the MFA one-time code never accessible to the model or Anthropic's systems.</p><p>The moment an AI agent takes control of the browser, 1Password locks down automatically, limiting access to only the credentials explicitly granted for the current task. Nothing else in the 1Password vault is reachable.</p><figure role="gallery"><figure><img src="https://cdn.mos.cms.futurecdn.net/s3PCJM7YoZv9iZDxN5xbCg.png" alt="Promotional image showing Claude integration with 1Password filling out a password form for a user on GitHub. " /><figcaption><small role="credit">1Password/Anthropic</small></figcaption></figure><figure><img src="https://cdn.mos.cms.futurecdn.net/XkWd7sw8tmKWzu2wwZCr5g.jpg" alt="Promotional image showing Claude integration with 1Password filling out a password form for a user on Audible. " /><figcaption><small role="credit">1Password/Anthropic</small></figcaption></figure></figure><p>1Password brokers credential access across multiple sites within a single task, so Claude can complete multi-step workflows without prompting the user for credentials at each step.</p><p>Elsewhere, continuous field analysis will see 1Password scan the page after every autofill to ensure no secrets remain exposed: if a form submission fails, it wipes any filled values before returning control to the agent.</p><h2 id="new-agentic-mode-coming-to-1password">New ‘agentic mode’ coming to 1Password</h2><p>Alongside the Claude integration, 1Password is also introducing Agentic Mode for all users. </p><p>When a compatible AI agent takes control of the browser, 1Password locks down, so that the only credentials the agent can reach are those the user has explicitly granted for the current task. </p><p>It activates automatically and runs quietly in the background, and users have the option to cancel it at any time. </p><p>1Password for Claude is now available to 1Password users on Mac, across business, family, and individual plans.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ We need to do something about passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/we-need-to-do-something-about-passwords</link>
                                                                            <description>
                            <![CDATA[ Passwords are a fundamental aspect of access security, but recent password leaks have undermined their ability to protect data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sjBDSy68CavarKw7hhUYZ4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4om9U7E6D9fZbLUapTgpi6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Jun 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 18 Jun 2026 10:50:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4om9U7E6D9fZbLUapTgpi6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A password login page]]></media:description>                                                            <media:text><![CDATA[A password login page]]></media:text>
                                <media:title type="plain"><![CDATA[A password login page]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4om9U7E6D9fZbLUapTgpi6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The National Cyber Security Centre (NCSC) recently declared passwords to be <a href="https://www.itpro.com/security/the-ncsc-says-its-time-to-switch-to-passkeys"><u>fundamentally flawed</u></a>, so what are the concerns and what can be done about them?</p><p>Access and identity management are an essential part of our online lives. They protect our data and ensure sensitive information is only shared with the appropriate people. However, following <a href="https://www.itpro.com/security/data-breaches/a-treasure-trove-for-adversaries-10-billion-stolen-passwords-have-been-shared-online-in-the-biggest-data-leak-of-all-time"><u>recent</u></a> password leaks, billions of access credentials have been exposed, thereby fundamentally weakening the systems relying on them. </p><p>Passwords have been used to confirm identity for thousands of years, for example, by guards and sentries to identify friends and official visitors. However, even then, passwords were prone to interception and being used by enemies to falsify identity.</p><h2 id="the-problem-with-passwords">The problem with passwords</h2><p>The key problem with passwords is that they do not confirm identity, only that someone knows the correct response. The recent leaks have been compounded by the poor <a href="https://www.itpro.com/security/has-password-hygiene-ever-improved"><u>password hygiene</u></a> followed by many users, who use the same password credentials for multiple platforms and services.</p><p>Furthermore, recent advances in high-performance computing (HPC) and quantum computing have meant that computers are becoming increasingly powerful and able to crack passwords in a far shorter time than was previously possible. </p><p>In 2024, China <a href="https://www.livescience.com/technology/computing/chinese-scientists-claim-they-broke-rsa-encryption-with-a-quantum-computer-but-theres-a-catch"><u>announced</u></a> it was able to decrypt 50-bit RSA encryption using quantum computing. Although modern encryption is a minimum of 2048 bits, the research is a fascinating proof of concept, showing where the technology is heading and the implications for the future of cybersecurity.</p><p>As the processing capabilities of modern computers continue to grow rapidly, the recommended minimum length and complexity of passwords are becoming longer. It is now recommended that passwords be at least ten characters long, with a mix of letters, numbers, and symbols, and not be a name or word from a dictionary.</p><p>Compounding the issue is that not everyone follows appropriate password hygiene, such as not using the same password credentials across multiple accounts or avoiding words/phrases that have a personal connection. Furthermore, the most common passwords are <a href="https://nordpass.com/most-common-passwords-list/"><u>still</u></a> “123456”, “admin” and “12345678”.  At this point, we may as well just give the bad actors our keys.</p><p>“The VIPs are the worst security users in the company – they don't want to type even eight characters. I saw in the past some CEOs who are asking their IT people to have only three characters as a password,” says Jean-François Aliotti, co-founder of Almond. </p><p>“Now, because of all the leaks that we have seen, there are passwords leaked everywhere. Some of my passwords have been leaked. I use a unique password for each access I have. It's a rule that I follow strictly, and I use password managers for that. But most people don't do that – they have an Excel file with all their passwords, or they have the same password everywhere.”</p><p>Regular changes of passwords are commonly enforced, especially for business account login details.  The recommended duration varies depending on the sensitivity of the data, but a password change every three to six months is the most common requirement. However, the NCSC has <a href="https://www.ncsc.gov.uk/blog-post/problems-forcing-regular-password-expiry"><u>argued</u></a> against changing passwords due to the potential vulnerabilities it causes, as users can be tempted to rely on passwords that are easier to remember.</p><p>It is no longer recommended that access security and identity management be solely reliant upon a password. Instead, there needs to be a layered approach to security, with multiple levels of authentication before granting access.</p><h2 id="alternative-solutions">Alternative solutions</h2><p>The most common form of additional confirmation is Multi-Factor Authentication (MFA), whereby short-term single-use codes are sent to personal devices held by the user. Codes are typically sent via text, email, or authenticator app, but could also be generated by a 2FA token. However, if someone has already gained access to the secondary device or token, they will be able to confirm the additional verification.</p><p>Emails are potentially the most vulnerable form of MFA, as they are equally reliant on passwords, and many personal email accounts are not as strongly protected as they could be. </p><p>Biometrics (fingerprints, facial recognition, and voice recognition) are unique to each person, but are not as strong as many believe. Fingerprints can be <a href="https://www.itpro.com/security/33393/samsung-galaxy-s10-s-ultrasonic-sensor-fooled-by-fake-finger"><u>forged</u></a>, and voice recognition can be fooled using high-definition recording. Facial recognition can easily be bypassed if a user is caught off guard, as anyone with teenagers will know when friends ‘borrow’ their phones.</p><p>“Biometrics are a good thing, but not alone. If someone stole your fingerprint, it's over. You can change your password, but you cannot change your fingerprints,” says Aliotti. </p><p>“Biometrics alone are quite dangerous, because if they are stolen, then it's over.”</p><h2 id="passkeys-instead-of-passwords">Passkeys instead of passwords</h2><p>An alternative authentication system is passkeys. Although the technology is comparatively new, the NCSC has <a href="https://www.ncsc.gov.uk/passkeys"><u>recommended</u></a> that people use passkeys instead of passwords. </p><p>“Adopting passkeys wherever you can is a strong step towards a safer, simpler login experience, and I am pleased that we can now support uptake,” according to Jonathon Ellison, Director for National Resilience, NCSC.</p><p>“The headaches that remembering passwords have caused us for decades no longer need to be a part of logging in where users migrate to passkeys – they are a user-friendly alternative which provide stronger overall resilience.  </p><p>“As we aim to accelerate the UK’s cyber defences at scale, moving to passkeys is something all of us can do to improve the security of everyday digital services and be prepared for modern and future cyber threats.” </p><p>When a user seeks to confirm their identity, a push notification is sent to their smartphone. Once their device, such as a smartphone, has been unlocked, a unique passkey is created and sent to the platform/website/service they wish to access, confirming their identity. </p><p>Unlike MFA, which relies on traditional methods of user verification, this method does not rely on login information or biometric data being transmitted, thus mitigating interception and key-logging attacks.</p><p>“MFAs will continue to be deployed, but what we are seeing right now is that passkeys are the best way, but it will take a lot of time to deploy them at a large scale right now,” says Aliotti. </p><p>“Pass keys will be more and more used, and we hope that it will be the dominant way for credentials, as we don't have any other system right now that we are seeing as a brand-new thing.”</p><p>The decreasing effectiveness of passwords means they are no longer viable as a sole form of access management. Instead, a layered authentication process, where users need to prove their identity through two or more methods, is strongly recommended.</p><p>Furthermore, given the inherent weakness of passwords overall, the robust nature of passkey technology means that passkeys are the NCSC’s recommended access management protocol.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dashlane lifts the lid on attack that saw hackers download encrypted user vaults ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/dashlane-lifts-the-lid-on-attack-that-saw-hackers-downloaded-encrypted-user-vaults</link>
                                                                            <description>
                            <![CDATA[ The company said it has now informed all affected customers, and taken action to shut down the operation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PUktXTumtfubuYzeQny3CQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uswZUSdbhzgYhx2CzDUW2a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Jun 2026 10:03:40 +0000</pubDate>                                                                                                                                <updated>Fri, 05 Jun 2026 10:04:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uswZUSdbhzgYhx2CzDUW2a-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dashlane logo and branding pictured on a smartphone screen, with logo in white lettering against a black background.]]></media:description>                                                            <media:text><![CDATA[Dashlane logo and branding pictured on a smartphone screen, with logo in white lettering against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Dashlane logo and branding pictured on a smartphone screen, with logo in white lettering against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uswZUSdbhzgYhx2CzDUW2a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password management firm <a href="https://www.itpro.com/software/368031/lastpass-vs-dashlane">Dashlane </a>said it has completed its investigation into an attack that allowed hackers to steal around 20 encrypted vaults.</p><p>The incident kicked off on Sunday, May 31, when a hacker launched an attack against a number of Dashlane user accounts by brute-forcing <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA) </a>protections, allowing them to register new devices on existing accounts.</p><p>Because of the high volume of attempts on user accounts, Dashlane revealed its security controls automatically locked the accounts that were targeted by the attack. </p><p>However, the attackers were able to download a copy of the encrypted vaults of around 20 personal plan users, all of whom have now been notified, with some customers being prevented from adding new devices or logging in to their account with 2FA.</p><p>"Dashlane vault data cannot be accessed without the Master Password, and our <a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">vault encryption</a> ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time," said the firm.</p><p>"There is no evidence that Dashlane’s internal system has been impacted."</p><h2 id="how-the-dashlane-attack-unfolded">How the Dashlane attack unfolded</h2><p>When a user enables an additional device, Dashlane verifies the identity of the account holder in a process that ends up sending a one-time six-digit token to the user’s registered email address. </p><p>For users who have enabled 2FA, a six-digit code generated by their authentication app is sent. </p><p>Once the user enters this code into the Dashlane application, Dashlane registers the device and downloads a copy of the encrypted vault to the device. The user can access this by entering the Master Password, which serves as the decryption key to the user vault.</p><p>"Without the Master Password, a user cannot access the items inside the vault. The vault encryption (Argon2 + AES-256-CBC + HMAC-SHA256) used by Dashlane ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time," the company explained. </p><p>"Dashlane never stores Master Passwords or their derivatives on our servers in line with our zero-knowledge architecture."</p><h2 id="new-safeguards-introduced">New safeguards introduced</h2><p>Dashlane said it has now deployed additional protections at the network level and within the product to increase the likelihood of detecting and filtering out malicious traffic. </p><p>Similarly, the firm will introduce additional layers of verification to the new device registration flow. </p><p>It also advises users to review the devices registered to their account and remove any that they don't recognize, and to enable 2FA on their account if they haven't already. </p><p>There's no need to change credentials or update the Master Password, said the firm, unless it's weak or easily guessed.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC says it’s time to switch to passkeys ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-ncsc-says-its-time-to-switch-to-passkeys</link>
                                                                            <description>
                            <![CDATA[ UK security organization calls for companies to step up and offer more secure ways to login ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jaYhRKhMTS3hbYHkehkCrY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 11:21:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:description>                                                            <media:text><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:text>
                                <media:title type="plain"><![CDATA[Smartphone with authentication icon on screen with passkey hovering above.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/snMXVfJvpiJmLoNb66WzBR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's time to finally kill off passwords in favour of passkeys – and companies need to start offering them to login. </p><p>That's according to the UK's National Cyber Security Centre (NCSC), which is now advising consumers to use passkeys where available because they offer "stronger resilience" to cyber attacks and are easier to use. </p><p>Passkeys tie credentials to a specific device, including a smartphone or laptop, removing the need for text messages or email verification codes. </p><p>The NCSC sees this as more secure as hackers would need to intercept the code or steal the device itself for access. In a <a href="https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services" target="_blank"><u>blog post</u></a>, the security agency said this makes passkeys "phishing-resistant" by design. </p><p>While the NCSC has long persisted with passwords as its official preference, <a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc"><u>last year it began recommending</u></a> users switch to passkeys or a password manager. </p><p>In a statement, the NCSC said it had stopped short of fully endorsing passkeys due to "some key implementation challenges", but pointed to progress within the industry. </p><p>Indeed, the <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>shift to passkeys</u></a> is well underway. As the agency noted, passkeys are widely supported and half of Google users in the UK have one set up.</p><p>"Adopting passkeys wherever you can is a strong step towards a safer, simpler login experience and I am pleased that we can now support uptake," said Jonathon Ellison, Director for National Resilience at the NCSC. </p><p>"The headaches that remembering passwords have caused us for decades no longer need to be a part of logging in where users migrate to passkeys – they are a user-friendly alternative which provide stronger overall resilience."</p><p>The NCSC said beyond better security and lower costs for companies, passkeys save a minute per login versus a username, password, and text verification code. </p><h2 id="industry-push-needed-for-passkeys">Industry push needed for passkeys</h2><p>Of course, for that shift to happen, organizations need to step up and ditch passwords and SMS verification with passkeys. </p><p>“We strongly advise all organizations to implement passkeys wherever possible to enhance security, provide users with faster, frictionless logins and to save significant costs on SMS authentication," NCSC Chief Technical Officer Ollie Whitehouse said.</p><p>The government is hoping to achieve this later in the year across its own digital services. The NHS was one of the first government organizations in the world to offer passkeys for logins.</p><p>“The rollout of passkeys across GOV.UK services marks another major step forward in strengthening the UK’s digital defences while improving the user experience for millions," said AI and Digital Government Minister Feryal Clark.</p><h2 id="why-passkeys">Why passkeys?</h2><p>Passkeys are framed as a key weapon in the fight against phishing attacks. Beyond being more resistant to these attempts, it will also help reduce the number of texts users have to wade through. </p><p>This has become a major problem, and one exacerbated by the rise of <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platforms like <a href="https://www.itpro.com/security/cyber-crime/tycoon-2fa-phishing-risk-takedown-barracuda">Tycoon 2FA</a>, as well as the rise of <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026">AI-generated phishing campaigns</a>. </p><p>To help with passkey rollout, the NCSC has joined forces with the FIDO Alliance, which is working towards password-free authentication. </p><p>“We’re also very pleased that the NCSC has joined the FIDO Alliance, which allows agencies across the UK government to collaborate with other thought leaders in the Alliance to advance the development and deployment of foundational technologies that will strengthen our collective cyber resilience," said Executive Director and CEO of the FIDO Alliance Andrew Shikiar.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI agents are creating new identity security risks: 1Password wants to solve that ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/1password-unified-access-agent-identity-security</link>
                                                                            <description>
                            <![CDATA[ The Unified Access system from 1Password will help enterprises manage AI agent access across different devices and users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HHvPjzZf6yE7r7zi8fhbmg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6EL6ZhFnhVb2VEAF5Enb54-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Mar 2026 09:29:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6EL6ZhFnhVb2VEAF5Enb54-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[1Password logo and branding pictured on a smartphone screen with grey glowing streams of light emanating out from behind the device.]]></media:description>                                                            <media:text><![CDATA[1Password logo and branding pictured on a smartphone screen with grey glowing streams of light emanating out from behind the device.]]></media:text>
                                <media:title type="plain"><![CDATA[1Password logo and branding pictured on a smartphone screen with grey glowing streams of light emanating out from behind the device.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6EL6ZhFnhVb2VEAF5Enb54-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368008/lastpass-vs-1password">1Password </a>has announced the launch of a new service aimed at shoring up credential security in response to growing <a href="https://www.itpro.com/technology/artificial-intelligence/the-agentic-identity-crisis"><u>agent identity risks</u></a>. </p><p>The company has worked with a range of AI providers – notably Anthropic, Perplexity, <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a>, Cursor, and Vercel – to launch ‘Unified Access’, an agent security platform that lets companies deploy agents while keeping control of their credentials, authentication, and access. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">Agentic AI</a> is changing how work happens in organizations, noted CTO Nancy Wang and VP of engineering, development, and AI Jeff Malnick in a <a href="https://1password.com/blog/introducing-1password-unified-access" target="_blank"><u>blog post</u></a>, pointing to its use in coding environments, internal workflows, and productivity apps. </p><p>"That shift has real implications for identity and access control," they noted, saying user logins were no longer enough for authentication and policy controls. </p><p>"That model worked for human access, but it breaks down when credentials are used by local AI agents, automation scripts, <a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD</a> pipelines, and AI-native tooling.</p><p>"In this new reality, authority shouldn’t be decided once at login and then trusted all day. It should be confirmed right when access is requested, every time a credential or secret is used."</p><h2 id="what-to-expect-with-1password-s-unified-access">What to expect with 1Password’s Unified Access</h2><p>1Password said the Unified Access lets organizations maintain visibility of all AI and agent activity happening across devices, browsers, and local environments, spotting any existing credentials or leaked secrets such as encrypted keys and mapping all AI use to specific users or devices. </p><p>That can then be secured with a unified vault that governs human employees as well as agents, with extra controls for risky accounts. </p><p>"As the lines between human and non-human access blur, the same credential might be used by an employee today and by an agent or automation workflow tomorrow," Wang and Malnick noted. "Unified Access provides a single source of truth, so access policies aren’t fragmented by where or how work happens."</p><p>Those two features are available now, but 1Password also plans to roll out an auditing tool in Unified Access that offers visibility into credential access – across humans and agents alike. </p><p>"Later this year, 1Password will expand Unified Access to issue scoped credentials to agent and machine workloads at runtime, further reducing persistent access and strengthening governance as AI-driven automation scales," the company added in a statement. </p><h2 id="working-with-industry">Working with industry</h2><p>At launch, Unified Access will work with Anthropic and OpenAI as foundation model providers. For the former, Anthropic will integrate 1Password via Claude Code, Cowork, and the Claude browser extension, letting Claude login as though it was a human user. </p><p>With OpenAI, 1Password will enable the use of local vault items and developer IDEs. </p><p>For developers, Cursor, GitHub, and Vercel will integrate 1Password across their developer workflows, with hooks immediately available to Cursor agents and GitHub Actions. </p><p>"As agentic coding tools become part of how modern teams build and ship software, security needs to integrate directly into the developer workflow," said Talha Tariq, CISO at Vercel. </p><p>"Through our partnership with 1Password, we’re making it easier for developers to access credentials securely within the tools and environments they already use, so they can move quickly without compromising on sound security practices."</p><p>Beyond those partners, 1Password is also working with Commvault, agent control plane provider Runlayer, MCP gateway provider Natoma, and AI browsers from Anchor, Browserbase, Kernel and Perplexity, to protect information held by AI agents using least-privilege controls. </p><p>"Runlayer is the agent control plane for the enterprise, providing the security, governance, and observability organizations need to deploy AI agents in production with confidence," said Andrew Berman, CEO at Runlayer. </p><p>"As agents take real action across enterprise systems, credential management becomes a critical control surface. By integrating with 1Password, we're ensuring that every agent session Runlayer manages has secure, auditable access to the credentials it needs, and nothing more,” Berman added. </p><p>“When security is built into the foundation, organizations stop treating AI adoption as a risk to manage and start treating it as a capability to accelerate."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Using AI to generate passwords is a terrible idea, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/using-ai-to-generate-passwords-is-a-terrible-idea-experts-warn</link>
                                                                            <description>
                            <![CDATA[ Researchers have warned the use of AI-generated passwords puts users and businesses at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6x7b3jyuFeqHYS7jPDG9nj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dWWadtMsk3uez4rsjhdxv8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Feb 2026 10:46:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dWWadtMsk3uez4rsjhdxv8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person typing on keyboard with digitized password entry screen. ]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person typing on keyboard with digitized password entry screen. ]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person typing on keyboard with digitized password entry screen. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dWWadtMsk3uez4rsjhdxv8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber experts have warned against using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to generate passwords after research found glaring security failures. </p><p>Analysis from <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm Irregular found a host of popular AI chatbots, including <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT</a>, Claude, and <a href="https://www.itpro.com/technology/artificial-intelligence/google-launches-flagship-gemini-3-model-and-google-antigravity-a-new-agentic-ai-development-platform">Google Gemini</a> produced highly predictable passwords. </p><p>A key factor behind this, the study noted, is that <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">large language models (LLMs)</a> generate passwords based on recognizable patterns, rather than in the randomized manner recommended by security experts. </p><p>Testing of Claude, for example, produced 50 passwords. Of these, only 30 unique passwords were generated while one - G7$kL9#mQ2&xP4!w - was repeated 18 times. </p><p><a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-gpt-5-2-codex-is-its-most-advanced-agentic-coding-model-yet-heres-what-developers-and-cyber-teams-can-expect">GPT-5.2</a> fared similarly, according to researchers, with outputs showing “strong regularities”. </p><p>“Nearly all passwords begin with a v, and among those, almost half continue with Q,” Irregular said in a <a href="https://www.irregular.com/publications/vibe-password-generation" target="_blank"><u>blog post</u></a>. “Character selection is similarly narrow and uneven, with only a small subset of symbols appearing with any frequency.”</p><p>Notably, Gemini 3 Pro issued a security warning when prompted to generate suggested passwords, urging users not to use them. </p><p>“The reason given by the model is not that the password is weak, but that the password is ‘processed through servers’”, which Irregular warned misrepresents the potential risk posed to users. </p><h2 id="how-password-strength-is-measured">How password strength is measured</h2><p>Password strength has traditionally been based on its predictability or unpredictability and measured in “bits of entropy”. This is used to measure how many guesses would be required for someone to brute force crack the password. </p><p>Simply put, the higher the entropy, the stronger the password.</p><p>“A password with only 20 bits of entropy, for example, would need about 2²⁰ guesses, or approximately one million guesses – which could be done within seconds,” researchers explained. </p><p>“A password with 100 bits of entropy, however, would need about 2¹⁰⁰ guesses – a 31-digit number, requiring trillions of years to crack.”</p><h2 id="using-ai-to-generate-passwords-is-ill-advised">Using AI to generate passwords is ill-advised</h2><p>Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University, said using AI to generate passwords is a “risky practice” and urged users against relying on chatbots for this purpose. </p><p>“These models often produce strings which appear strong and complex but are actually highly predictable, featuring repeating patterns or familiar structures drawn from their training data,” he said. </p><p>“This approach is a poor security practice because large language models do not generate true randomness; they rely on statistical probabilities learned from vast datasets.”</p><p>Curran added that AI-generated passwords “lack the high entropy” needed to ensure robust protection, and could also be vulnerable to automated cracking tools. </p><p>Indeed, Irregular noted that a typical 16-character password should have roughly 98 bits of entropy, whereas AI-generated results only had an estimated 27 bits, making them highly susceptible to cracking. </p><p>“This is the difference between taking billions of years to crack a password even with a strong supercomputer, and taking seconds with a standard computer.”</p><p>Despite glaring risks, researchers noted that AI-generated passwords are appearing in the real world at an alarming rate. The company advised users to stick to traditional password generation methods. </p><p>Curran noted that enterprises need to nip these practices in the bud and inform staff about the potential risks. </p><p>“Organizations should take proactive steps to prevent staff from relying on AI for password creation by establishing clear policies that ban the use of public chatbots for security-sensitive tasks and instead mandate approved password managers equipped with cryptographically secure random number generators,” he said. </p><p>“Regular <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">training programs can raise awareness</a> of these limitations while encouraging the adoption of stronger alternatives, such as <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business">passkeys </a>or <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication</a>, to reduce overall reliance on traditional passwords.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company responded ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/researchers-called-on-lastpass-dashlane-and-bitwarden-to-up-defenses-after-severe-flaws-put-60-million-users-at-risk-heres-how-each-company-responded</link>
                                                                            <description>
                            <![CDATA[ Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NfFxTg6XRsaJYwtUPGvTad</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Feb 2026 12:56:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368049/best-password-managers-for-business">Password managers</a> may not be as secure as many assume, with researchers uncovering multiple attack vectors across three popular systems serving 60 million users. </p><p>Security researchers from ETH Zurich studied the architecture of Bitwarden, <a href="https://www.itpro.com/security/phishing/lastpass-issues-alert-as-customers-targeted-in-new-phishing-campaign">LastPass</a>, and <a href="https://www.itpro.com/software/368031/lastpass-vs-dashlane">Dashlane</a>, which between them hold 23% of the password manager market. </p><p>The researchers demonstrated 12 attacks that would work on <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a>, seven on LastPass, and six on Dashlane, prompting calls for each to bolster defense capabilities.</p><p>“We were surprised by the severity of the security vulnerabilities,” said Kenneth Paterson, Professor of Computer Science at ETH Zurich, in a <a href="https://ethz.ch/en/news-and-events/eth-news/news/2026/02/password-managers-less-secure-than-promised.html" target="_blank"><u>blog post</u></a> from ETH Zurich. </p><p>The study focused on password manager claims that they use "zero-knowledge encryption," which means the companies don't know what users have stored. </p><p>"The promise is that even if someone is able to access the server, this does not pose a security risk to customers because the data is encrypted and therefore unreadable," said ETH Zurich researcher Matilda Backendal. "We have now shown that this is not the case."</p><h2 id="testing-password-managers">Testing password managers</h2><p>To test security capabilities, researchers set up their own servers that would act as though they were hacked password manager servers. They found they could alter passwords, access vaults, and more. </p><p>The study revealed "strange code architecture" that PhD student Matteo Scarlata attributed to the companies trying to improve ease-of-use for customers, such as offering password recovery or account sharing, as well as using out-of-date cryptography for accessibility. </p><p>"As a result, the code becomes more complex and confusing, and it expands the potential attack surface for hackers," Scarlata said. </p><p>Researchers urged password manager providers to use the most up-to-date cryptographic standards for all new customers, while existing customers could be offered the chance to migrate to updated systems or stick with older, compatible ones – providing they’re informed of the potential risks. </p><p>“We want our work to help bring about change in this industry,” Paterson said. “The providers of password managers should not make false promises to their customers about security but instead communicate more clearly and precisely what security guarantees their solutions actually offer.” </p><h2 id="industry-response">Industry response</h2><p><em>ITPro </em>contacted each of the companies for comment, but did not receive a response by time of publication. </p><p>However, all three have already published blog posts addressing the paper and issued fixes for the addressable flaws and used hardening measures for other concerns, thanking the researchers for their efforts. </p><p>Dashlane said the methodology was "useful", though <a href="https://bitwarden.com/blog/security-through-transparency-eth-zurich-audits-bitwarden-cryptography/" target="_blank"><u>Bitwarden also noted</u></a> that the server-takeover scenario has never hit any password management product as far as it's aware. </p><p>Dashlane and LastPass stressed that there was no evidence that these flaws had been exploited as yet; Bitwarden added it has never suffered any security breach. </p><p>"Customers should continue using LastPass as normal," <a href="https://blog.lastpass.com/posts/details-on-hardening-in-response-to-eth-zurich-reported-security-issues" target="_blank"><u>LastPass noted</u></a>. "To continue to receive the best possible secure access experience, we always recommend that users check to ensure they are up-to-date and using the latest version of our browser extensions and apps."</p><p>Both companies noted they were selected by the researchers because their source code is publicly available. "We made that choice intentionally," Dashlane said in its <a href="https://www.dashlane.com/blog/zero-knowledge-malicious-server">blog post</a>. </p><p>"Transparency makes it easier for third parties to inspect our design and hold us accountable. Security improves when systems are open to review."</p><h2 id="fixing-the-flaws">Fixing the flaws</h2><p>Dashlane explained that it fixed an issue that allowed the use of legacy cryptography to enable backwards compatibility and migration flexibility that could have allowed the injection of code into a secure vault, weakening the encryption that protects keys and user data.</p><p> "It’s important to note that the exploitation of this issue would require full compromise of a password manager’s servers, paired with a highly sophisticated threat actor able to execute cryptographic attacks, and an extremely significant window of time," Dashlane added.</p><p>Dashlane added that two other attack vectors detailed in the report relate to wider architectural issues that are well known in the encryption community, namely public key authenticity in sharing and transaction-based synchronization. </p><p>The password manager firm noted it – and indeed the wider industry – were well aware of both concerns, and had built in additional protections with that in mind. </p><p>"Public key authentication at scale is a known challenge that we as an industry must solve," the post added. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of exposed civil servant passwords are up for grabs online ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/thousands-of-exposed-civil-servant-passwords-are-up-for-grabs-online</link>
                                                                            <description>
                            <![CDATA[ While the password security failures are concerning, they pale in comparison to other nations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BybKa87rHe77D33rgzRY9o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Oct 2025 11:40:30 +0000</pubDate>                                                                                                                                <updated>Fri, 17 Oct 2025 11:41:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:description>                                                            <media:text><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber crime concept image showing hacker typing on keyboard in dimly-lit room with tablet pictured on desk. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4w6boC4sd6Rmk2mt6aw3Ud-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The passwords of more than 3,000 UK civil servants have been found exposed on the dark web and other publicly available sources, according to research from NordPass.</p><p>195 exposed passwords identified by researchers belonged to staff at the Ministry of Justice, 111 from the Ministry of Defence, and 122 from the Department of Work and Pensions. </p><p>There were also large numbers of passwords from HM Revenue & Customs, the Home Office, as well as a number of councils including Aberdeen City Council, Lancashire County Council, Newham Council, and Southwark Council.</p><p>Notably, NordPass researchers <a href="https://nordpass.com/public-sector-passwords-leak/" target="_blank"><u>identified</u></a> 70 compromised passwords of UK Parliament employees.</p><p>“Exposure of sensitive data, including passwords, of civil servants is particularly dangerous,” said Karolis Arbačiauskas, head of product at NordPass.</p><p>"Compromised passwords can affect not only organizations and their employees but also large numbers of citizens. Moreover, such incidents may also pose serious risks to a country’s strategic interests."</p><h2 id="password-security-needs-shaking-up">Password security needs shaking up</h2><p>Some of the passwords came up more than once, thanks to multiple incidents related to one email address, or because several people used the same password. </p><p>All told, NordPass said as many as 434 unique passwords were identified during its investigation. </p><p>The number of <a href="https://www.itpro.com/security/29810/30-of-ceos-have-had-their-credentials-leaked">leaked passwords</a> doesn't directly reflect the strength of an organization’s internal security practices, Arbačiauskas noted. For a start, larger organizations with more employees naturally have a bigger digital footprint, increasing the likelihood of credentials being exposed in a breach. </p><p>"In many cases, a single malware infection on an employee’s personal device or the compromise of a popular third-party website can expose dozens of accounts,” he said. </p><p>“Furthermore, the majority of leaks originate from external sites where employees registered using their work email addresses."</p><p>While some of the civil servants’ passwords found in publicly available sources are also weak, many officials were following best practices – long passwords with upper-case letters, numbers, and symbols.</p><p>“If these passwords were not changed after their appearance on the dark web and <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> is not enabled, attackers could potentially access the email accounts and other sensitive information of these civil servants," said Arbačiauskas. </p><p>"Moreover, we found hundreds of thousands of email addresses with other exposed data like names, last names, phone numbers, autofills, and cookies. This data can be exploited for <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing attacks</a> and pose significant risks."</p><h2 id="password-security-is-even-worse-abroad">Password security is even worse abroad</h2><p>The UK isn't the only country to see civil servants' passwords exposed. Analysis from the company identified a whopping 53,070 passwords belonging to various US federal agency employees. </p><p>1,897 of these were from the Department of Defense, 15,272 from the State Department, 1,706 from the US Army, and 1,331 from the Department of Veterans Affairs.</p><p>Meanwhile, 19,538 French public sector emails were exposed, with 13,613 from Italy.</p><p>NordPass recommends the use of strong passwords or passphrases, creating a unique password for each account, setting up a password policy and turning on multi-factor authentication (MFA). </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/passwords-are-a-problem-why-device-bound-passkeys-can-be-the-future-of-secure-authentication">Passwords are a problem: Why device-bound passkeys can be the future of secure authentication</a></li><li><a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy">How to create a secure password policy</a></li><li><a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc">The NCSC wants you to start using password managers and passkeys</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gen Z has a cyber hygiene problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/gen-z-has-a-cyber-hygiene-problem</link>
                                                                            <description>
                            <![CDATA[ A new survey shows Gen Z is far less concerned about cybersecurity than older generations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2U9CRCdzcRrSu72WFygD8L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Sep 2025 11:45:33 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Sep 2025 11:56:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:description>                                                            <media:text><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:text>
                                <media:title type="plain"><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Despite their reputation as digital natives, Gen Z is pretty poor when it comes to <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> practices.</p><p>Analysis from consumer insights platform GWI found that while many in this demographic have grown up online, only three-in-ten have made a habit of regularly <a href="https://www.itpro.com/security/researchers-at-uc-san-diego-reveal-the-most-effective-way-to-get-stubborn-employees-to-change-their-passwords">changing their passwords</a> compared to 42% of Baby Boomers. </p><p>They’re also the generation least likely to keep software and devices up to date, with only 43% bothering. Gen Z was found lacking in other basic <a href="https://www.itpro.com/security/370309/surge-in-compromised-credentials-highlights-rampant-cyber-hygeine-failings">cyber hygiene</a> practices, the study noted. </p><div class="product"><a data-dimension112="7a9a6c61-b4a8-4d55-9eba-1f12bb752d38" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="7a9a6c61-b4a8-4d55-9eba-1f12bb752d38" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="7a9a6c61-b4a8-4d55-9eba-1f12bb752d38" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Just 36% reported using any <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus">antivirus software</a>, for example, but more than half (58%) at least use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a> (2FA).</p><p>Gen Zers also take more risks. Only 35% avoid using insecure public wifi, in contrast to 48% of Boomers. They’re also less likely to check their accounts for suspicious activity, with only 40% doing so, compared with 54% of Boomers.</p><p>When asked how concerned they are about the threats of cyber attacks, only 44% of Gen Zers said they were ‘very’ or ‘extremely’ concerned, compared with 49% of Boomers.</p><h2 id="gen-z-is-too-trusting">Gen Z is too trusting</h2><p>In general, they're a pretty trusting lot - especially with technologies like AI.  </p><p>They're more likely than Boomers to feel extremely or very comfortable with AI agents taking action on their behalf, at 18%, compared with just 4% of Boomers. </p><p>By contrast, only 8% of Gen Z say they’re not at all comfortable with AI agents, compared with 12% of Boomers.</p><p>Notably, many said they often rely on <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>for important decision-making, with 24% using it for health-related information and 22% for financial advice. </p><p>At work, 24% said they are comfortable with AI completing tasks for them, more than twice as many Boomers.</p><h2 id="gen-z-is-keen-on-training">Gen Z is keen on training</h2><p>One positive takeaway from the study is that a significant majority are keen to improve their <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs">cybersecurity skills</a>. For example, 91% said that training staff on data security should be a key workplace priority. </p><p>The researchers suggested that the reason for the disconnect is Gen Z’s overreliance on smartphones, where features like face ID, auto-login, and password managers are the norm.</p><p>“Gen Z has grown up in a world where convenience is the default. With devices auto-filling passwords, logging them in with a glance, and silently syncing their data, there’s little reason, or opportunity, for them to build good security habits," said Matt Smith, data journalist at. </p><p>"But that reliance on automation creates a false sense of safety. When something goes wrong, many Gen Zers don’t know how to react—because they’ve never had to think about it.”</p><p>The report aligns with similar research into Gen Z security habits from <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a> earlier this year. The company found this generation was the worst when it comes to password reuse, with 72% admitting they recycle credentials, compared with just 42% of Boomers.</p><p>Worse still, even when they do create a new one, 38% of Gen Z and 31% of Millennials said they only bothered to change a single character or reuse an existing one. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/has-password-hygiene-ever-improved">Has password hygiene ever improved?</a></li><li><a href="https://www.itpro.com/security/most-passwords-take-a-matter-of-minutes-to-crack-heres-how-you-can-create-strong-hacker-resistant-credentials">Most passwords take a matter of minutes to crack</a></li><li><a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy">How to create a secure password policy</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Passwords are a problem: why device-bound passkeys can be the future of secure authentication ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/passwords-are-a-problem-why-device-bound-passkeys-can-be-the-future-of-secure-authentication</link>
                                                                            <description>
                            <![CDATA[ AI-driven cyberthreats demand a passwordless future… ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nfd3ZJ7NorKwhruRLYAXz7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fKPJfbMPb6acy9VEjaa9jn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Aug 2025 19:32:41 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Aug 2025 19:32:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Niall McConachie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/kW3qVWYehF5XRov96yTaJ4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fKPJfbMPb6acy9VEjaa9jn-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password]]></media:description>                                                            <media:text><![CDATA[Password]]></media:text>
                                <media:title type="plain"><![CDATA[Password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fKPJfbMPb6acy9VEjaa9jn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Long before the invention of the internet, passwords have been the primary means by which users can verify their identity and gain access to digital services. As archaic as they are, this remains the case today. Indeed, according to Yubico’s <a href="https://www.yubico.com/blog/state-of-global-authenticageion-a-look-at-cybersecurity-habits-by-generations/"><u>Global State of Authentication survey</u></a> of 20,000 employees, more than half use a username and password to log in to both their personal and work accounts.</p><p>However, passwords are far from a secure authentication method. The majority (81%)  of hacking-related breaches stem from<a href="https://spacelift.io/blog/password-statistics"> <u>weak or reused passwords</u></a> from cyberattacks like phishing. Once they have access to passwords, cybercriminals can easily circumvent outdated multi-factor authentication (MFA) systems, such as SMS-based verification, and gain entry to sensitive information. This highlights the growing consensus among security experts: passwords are an inherently flawed means of authentication and need to be left in the past once and for all. But what realistic solutions are there to replace passwords in the future?</p><h2 id="the-importance-of-secure-authentication-in-the-channel">The importance of secure authentication in the channel</h2><p>Implementing secure authentication methods is vital for organizations across all industries, particularly those handling highly sensitive data, managing critical infrastructure, and subject to rigorous regulatory compliance, such as healthcare and financial services.</p><p>Channel partners working with organizations in these industries are no exception here, given the vast amount of customer data they handle, along with their access to vendor systems. Inadequate authentication tools, which are highly susceptible to cyberattacks like phishing, expose both data and systems to cybercriminals, leading to repercussions, such as data breaches, financial losses, and reputational damage.</p><p>Advanced phishing and sophisticated attack techniques are on the rise, which, coupled with the threat of AI-driven <a href="https://sosafe-awareness.com/resources/reports/cybercrime-trends/"><u>cyberattacks</u></a>, exacerbate concerns for channel partners. Threat actors are taking advantage of AI tools to<a href="https://www.ncsc.gov.uk/report/impact-of-ai-on-cyber-threat"> <u>launch more attacks</u></a> and improve the chances of success and impact of their efforts. </p><p>For example, bad actors are exploiting AI's ability to clone voices and likenesses from audio and video clips or images found online, known as vishing. Combined with tools that mimic caller ID, cybercriminals can fool targets by calling them and impersonating a family member, friend, or loved one seeking urgent assistance. With this technology making life easier for attackers, threat actors require less skill to carry out successful attacks against channel partners.</p><h2 id="moving-on-from-passwords-for-good">Moving on from passwords for good</h2><p>Given the recent rise of sophisticated, modern AI-driven cyber threats, there has been a clear shift in how organizations view authentication and security. To protect both themselves and their employees from cyber threats, a global transition away from passwords and other outdated and insecure authentication methods, such as legacy forms of MFA, has taken place. As an alternative, enterprises across all sectors are moving towards stronger, more cyber-resilient technologies, in the form of phishing-resistant, passwordless solutions like passkeys.</p><p>For instance, last month, the UK government<a href="https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services"> <u>announced</u></a> plans to roll out passkey technology for its digital services later this year, transitioning away from current SMS-based verification systems. The move is set to offer users a more secure authentication option, while also providing the government with a cost-effective solution that could save it several million pounds annually, as well as being key in transforming cyber resilience on a national scale.</p><p>Now, it is the turn of channel partners and managers to do their utmost to protect their organizations, vendor partners, and customers to the best of their ability.</p><h2 id="the-future-of-secure-phishing-resistant-authentication-device-bound-passkeys">The future of secure, phishing-resistant authentication: device-bound passkeys</h2><p>Given the threat landscape, channel partners must step up their digital security, using more reliable, phishing-resistant MFA methods. This is where passkeys, such as device-bound passkeys, come in – quickly emerging as the de facto authentication solution to replace passwords and legacy MFA. These solutions operate by using something you know (a PIN) alongside something you have (a hardware security key), which is inserted into a device and physically touched, enabling users to access their accounts.</p><p>When compared to authentication offerings like passwords and even two-step authentication, hardware security keys are viewed as a far superior alternative, since they eradicate the need for users to recall or manually enter long character sequences that are difficult to remember. Instead, they seamlessly authenticate users via cryptographic security keys stored directly on a device, like a physical security key.</p><p>Passkeys stored on physical devices like security keys provide a superior level of security for channel managers since they not only require users to prove possession, but also their presence to log in. This inhibits passkeys from being shared or copied across the cloud, while remote attackers are unable to intercept or steal them, meaning only the key holder can gain access to their accounts. For instance, even if a user’s credentials are compromised, phishing-resistant device-bound passkeys prevent hackers from accessing information without having possession of the physical security key.</p><p>Utilizing high-level security like this does not just help channel partners maintain robust cybersecurity practices and enhance their cyber resilience. It also ensures compliance with regulations such as PCI DSS 4.0 and NIS2 – a vital consideration for channel partners in an ever-evolving regulatory landscape.</p><p>By implementing phishing-resistant MFA-like device-bound passkeys for all employees, channel managers can begin developing phishing-resistant users, enabling passkeys to fulfill their potential. Establishing such users is a proactive strategy channel partners can take to eradicate phishing threats by removing all phishable events from the user lifecycle. </p><p>To successfully achieve this, enterprises must implement phishing-resistant MFA for employees and establish secure, phishing-resistant processes for account registration and user recovery across the board. Purpose-built, device-bound passkeys provide the foundation for this high level of security.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass just launched a tool to help security teams keep tabs on shadow IT risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/lastpass-just-launched-a-tool-to-help-security-teams-keep-tabs-on-shadow-it-risks</link>
                                                                            <description>
                            <![CDATA[ Companies need to know what apps their employees are using, so LastPass made a browser extension to help ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NvCFsvyFg9AKkXRadWUQoK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u6zJNjHqbfa9wxpncAjnxc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Aug 2025 16:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u6zJNjHqbfa9wxpncAjnxc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass logo and branding pictured on a smartphone screen with car key and earbuds sat next to smartphone.]]></media:description>                                                            <media:text><![CDATA[LastPass logo and branding pictured on a smartphone screen with car key and earbuds sat next to smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass logo and branding pictured on a smartphone screen with car key and earbuds sat next to smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u6zJNjHqbfa9wxpncAjnxc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use">LastPass</a> has launched a new feature to help enterprises tackle ‘<a href="https://www.itpro.com/software/software-sprawl-is-getting-out-of-control-86-percent-of-it-leaders-say-disparate-tools-are-creating-financial-strain-and-security-risks-but-consolidation-is-now-a-high-priority">SaaS sprawl</a>’ and <a href="https://www.itpro.com/security/33537/what-is-shadow-it">shadow IT</a> security risks. </p><p>Unveiled at <em>Black Hat 2025</em>, the new SaaS Protect feature will allow IT admins to see how user-installed apps are being used across their organization — and to take action to avoid misuse or risk. </p><p>The new feature follows the launch of its SaaS Monitoring tools in May this year, and aims to provide a consolidated view of app usage and credentials. Both tools are part of LastPass' Secure Access Experience approach. </p><p>"Small and mid-sized businesses are facing a perfect storm of complexity: unknown risks living within unknown apps and AI services," said Don MacLennan, Chief Product Officer at LastPass. </p><p>"We built SaaS Protect to turn that chaos into clarity," he added.</p><p>Shadow IT, whereby employees use applications or devices unknown to IT departments, is on the rise. </p><p>This brings with it a range of security-related risks, research shows, largely due to the fact security teams lack visibility into how applications are being used and opening enterprises up to an array of threats. </p><p>LastPass pointed to <a href="https://www.gartner.com/en/newsroom/press-releases/2023-03-28-gartner-unveils-top-8-cybersecurity-predictions-for-2023-2024" target="_blank"><u>Gartner statistics</u></a> that show three-quarters of employees are expected to use unauthorised tech by 2027. Similar <a href="https://zylo.com/reports/2025-saas-management-index/" target="_blank"><u>research from Zylo</u></a> shows small and medium businesses have an average of 275 known SaaS applications – but just a quarter of these are authorized by IT teams. </p><p>The rest, the study noted, are installed by individual employees or business units, with the latter creating dangerous interdepartmental silos.</p><p>Last year, 73% of people polled by Next DLP admitted to using <a href="https://www.itpro.com/software/why-shadow-saas-is-becoming-a-major-blind-spot-for-enterprise-security-teams"><u>SaaS apps that weren't approved</u></a> by corporate IT, despite being fully aware of the risk of data breaches. </p><p>This long-running issue is now being exacerbated by <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it"><u>shadow AI</u></a>, with unapproved AI bots <a href="https://www.itpro.com/security/data-protection/almost-a-third-of-workers-are-covertly-using-ai-at-work-heres-what-thats-a-terrible-idea"><u>being used by a third of staff</u></a>, according to one survey, putting data at risk. </p><h2 id="lastpass-wants-to-keep-it-light">LastPass wants to keep it light </h2><p>Rather than a device agent that disrupts staff, SaaS Protect is deployed via a browser extension on employee devices, the company revealed. It works by pulling in activity data to an admin console to support policy enforcement, such as allowing or restricting an app or showing a custom warning to guide user behavior. </p><p>"It’s designed specifically for resource-constrained businesses that need visibility, policy enforcement, and credential protection without adding operational overhead," said MacLennan. </p><p>Alongside spotting and restricting shadow IT, SaaS Protect can also help reduce costs by identifying duplicate or over-licensed apps to help slash app sprawl, as well as assist with creating audits for compliance, the company said. </p><p>SaaS Protect is currently in beta for LastPass Business and Business Max customers, the latter of which will pay no additional cost for the product. General availability is expected in early autumn.  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/password-manager-passkey-guidance-ncsc">The NCSC wants you to start using password managers and passkeys</a></li><li><a href="https://www.itpro.com/software/368047/are-password-managers-safe-heres-how-to-use-them">Are password managers safe?</a></li><li><a href="https://www.itpro.com/software/368049/best-password-managers-for-business">Looking for a new password manager? Here are our top picks</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC wants you to start using password managers and passkeys – here’s how to choose the best options ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/password-manager-passkey-guidance-ncsc</link>
                                                                            <description>
                            <![CDATA[ New guidance from the NCSC recommends using passkeys and password managers – but how can you choose the best option? ITPro has you covered. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAvApWCpysZzhmWaZTSE2S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jun 2025 10:34:55 +0000</pubDate>                                                                                                                                <updated>Thu, 26 Jun 2025 10:35:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:description>                                                            <media:text><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:text>
                                <media:title type="plain"><![CDATA[Person logging into password manager on a laptop computer placed on a desktop surface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DNNDQJfmWoictK9SvZZV5n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has published guidance recommending the use of password managers and <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business">passkeys</a>, insisting that the latter are the “future of authentication”.</p><p>In a <a href="https://www.ncsc.gov.uk/blog-post/trust-the-tech-using-password-managers-passkeys-to-help-you-stay-secure-online" target="_blank">blog post</a> outlining the advantages of both, the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> agency noted that first-party, browser-based password managers can be a handy tool for users due to their deep integration with a platform’s security. </p><p>Browsers such as Chrome, Safari, Edge, and Firefox all offer built-in password management capabilities, making them a convenient option for users. </p><p>Dedicated password management platforms are also a viable option. Notably, the agency said that long-standing services will probably have only survived due to their strong attention to security practices. </p><p>It's worth noting that there have been issues with password managers in recent years, with <a href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance">high-profile breach incidents denting consumer confidence</a>. </p><p>So what makes password managers safe and secure? According to the NCSC, password data is stored securely either by using "device features like security chips, or encryption, or both". </p><p>"Many first-party and third-party password managers now use fingerprint or facial recognition before revealing passwords," the agency added.</p><p>A passkey, meanwhile, is a new standard developed and supported by tech giants like Apple, Google, and Microsoft, offering a <a href="https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys">passwordless login technology</a> based on public-key cryptography. </p><p>Instead of a password, the device creates a pair of complex secrets for each website the user signs up to, keeping one secret and giving the other to the website at the time of sign-up.</p><p>Because the key pair combination is unique, the passkey will only work on the website or app it was created for.</p><p>When the user logs in, the device checks that it is the right person through whatever means is usually used to unlock it, and can then prove to the website that it has the device secret, without actually revealing the secret itself.</p><p>"Because this happens so quickly, it's often eight times faster than logging in with a username, password and two factor code, whilst being more secure," said the NCSC.</p><p>"Passkeys are rolling out fast. Websites like Google, eBay, and PayPal already support them. They’re easy to use, hard to compromise, and eliminate password fatigue."</p><h2 id="choosing-your-options">Choosing your options</h2><p>First and foremost, the NCSC said it is important to consider a company's reputation when choosing tools such as these. </p><p><em>ITPro </em>has a comprehensive list of password managers that both individuals and businesses can choose from below. </p><ul><li><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022">The best password managers you can try today</a></li><li><a href="https://www.itpro.com/software/368049/best-password-managers-for-business">The best password managers for businesses</a></li></ul><p>While these tools provide convenience, users are still urged to follow best practices in terms of cyber hygiene and awareness. The agency advised users to make sure they run updates, use biometric locks, and <a href="https://www.itpro.com/storage/29803/best-backup-software">backup recovery</a> options. </p><p>For example, this could include using recovery keys or trusted contacts. </p><p>“Don’t be afraid to adopt new security practices like passkeys – they’re easier and it’s where the internet is headed,” the agency added. </p><p>Greg Wetmore, vice president of product development at Entrust, echoed the NCSC’s stance on passkeys, claiming that they’re a game changer from a cybersecurity perspective. </p><p>Passwords are easy to breach, he noted, and often challenging to remember, with research indicating that more than half of people have to reset their password once a month because they can't remember it. </p><p>"Creating a unique, secure password is difficult to achieve for each account, with the average person having 170 passwords. Passkeys provide an excellent technical response to the problems with passwords," he said.</p><p>"Perhaps the most important security attribute of passkeys is that they are phishing resistant.  An attacker cannot steal your passkey and subsequently use it to access your online account. The NCSC are right; It's time to move from passwords to password managers and passkeys."  </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/368047/are-password-managers-safe-heres-how-to-use-them">Are password managers safe? Here’s how to use them</a></li><li><a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy">How to create a secure password policy</a></li><li><a href="https://www.itpro.com/security/the-end-of-passwords-and-how-businesses-will-embrace-it">The end of passwords – and how businesses will embrace it</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass targets revenue opportunities with partner program refresh ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/lastpass-targets-revenue-opportunities-with-partner-program-refresh</link>
                                                                            <description>
                            <![CDATA[ LastPass has announced a fresh round of enhancements to its channel partner program for 2025. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7wXKQzS7waQGutkZNiihvc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aw9WJ2JPetyYnjMzEc4maG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Feb 2025 14:12:11 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 17:45:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aw9WJ2JPetyYnjMzEc4maG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass logo on huawei phone sitting on laptop keyboard]]></media:description>                                                            <media:text><![CDATA[LastPass logo on huawei phone sitting on laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass logo on huawei phone sitting on laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aw9WJ2JPetyYnjMzEc4maG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity and <a href="https://www.itpro.com/security/33048/popular-password-managers-found-to-have-serious-flaws">password management</a> software provider LastPass has announced a fresh round of enhancements to its channel partner program for 2025.</p><p>The updates have been designed to make it easier to sell and support LastPass’ password management and security solutions through simplified processes, improved tools, and clear benefits, the firm said.</p><p>Key additions include an improved <a href="https://www.itpro.com/business/have-we-seen-the-end-of-the-true-msp">MSP</a> admin console, a centralized partner portal, as well as optimized partner pillars for clarity around benefits and discounts.</p><p>In an announcement, <a href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance">LasPass</a> said the revamp will help its broad range of partner types  to achieve sustainable growth, unlock new revenue opportunities, and build stronger, long-lasting customer relationships.</p><p>“We understand that partners need straightforward and affordable solutions to help their customers enhance security and efficiency in password management,” commented Jessica Couto, vice president of global channel and alliances at LastPass. </p><p>“Our enhanced Partner Program is designed to remove complexities, making it simple for partners to deliver impactful solutions that address real points.”</p><h2 id="lastpass-touts-crucial-updates">LastPass touts crucial updates</h2><p>The program’s enhanced MSP admin experience means partners can now leverage improved reporting capabilities to streamline invoices, implement prorated billing, and generate executive summary reports to communicate key business and product data to client stakeholders.</p><p>LastPass’ new <a href="https://www.itpro.com/cloud/cloud-computing/nasuni-revamps-partner-program-to-bolster-ecosystem-support">centralized partner portal</a> will also operate as a convenient one-stop hub for a host of tools and resources, covering training, support, marketing, case management, benefit tracking, and attainment.</p><p>Integrated with the new portal, LastPass partners across all tiers can also find optimized partner pillars which the firm said will provide clear and enforceable benefits and standardized <a href="https://www.itpro.com/hardware/368512/the-best-amazon-prime-day-tech-hardware-deals">discounts</a> at registration.</p><p>Led by channel veteran Couto, the LastPass Partner Program has seen strong growth since its inception, with the initiative growing by more than 260% globally.</p><p>With its latest refresh, the firm said the updates reflect its commitment to supporting its channel community, driving growth, and delivering product innovations at a time when demand for managed security services continues to rise.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="yVz32JF7XZdDNUy6RpEhxE" name="Developer security best practices in a fast growing tech company" caption="" alt="Developer security best practices in a fast growing tech company" src="https://cdn.mos.cms.futurecdn.net/yVz32JF7XZdDNUy6RpEhxE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/developer-security-best-practices-in-a-fast-growing-tech-company"><em>Maintain developer satisfaction and productivity</em></a></p></div></div><p>According to a <a href="https://www.lastpass.com/-/media/ff37a072c5e54474ba4edadb0309f5fb.pdf?blaid=7028410" target="_blank">study by analyst firm Enterprise Strategy Group (ESG)</a>, 77% of small businesses plan to increase their use of MSPs over the next 12-24 months - with 59% specifically looking for third-party cloud security providers.</p><p>“By providing high-margin opportunities, streamlined tools, and dedicated support, we are enabling partners to grow their businesses while delivering the trusted security their customers expect,” Couto added.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/lastpass-breach-comes-back-to-haunt-users-as-hackers-steal-usd12-million-in-two-days">LastPass breach comes back to haunt users as hackers steal $12 million in cryptocurrency</a></li><li><a href="https://www.itpro.com/business/leadership/canon-names-shinichi-sam-yoshida-as-new-president-and-ceo-for-emea">Canon names Shinichi ‘Sam’ Yoshida as new president and CEO for EMEA</a></li><li><a href="https://www.itpro.com/infrastructure/networking/extreme-networks-targets-simplicity-with-platform-one-for-msps">Extreme Networks targets simplicity with Platform ONE for MSPs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ I love magic links – why aren’t more services using them? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/i-love-magic-links-why-arent-more-services-using-them</link>
                                                                            <description>
                            <![CDATA[ Using magic links instead of passwords is safe and easy but they’re still infuriatingly underused by businesses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nfmQWR47QKZ3Rkk4DMXN7h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9xGMmgZG44XK53WgPVtfuN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Feb 2025 13:33:51 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Feb 2025 17:25:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9xGMmgZG44XK53WgPVtfuN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a key with asterisks on it to represent magic links to replace passwords. It is set against a dull, yellow-green background.]]></media:description>                                                            <media:text><![CDATA[A hand holding a key with asterisks on it to represent magic links to replace passwords. It is set against a dull, yellow-green background.]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a key with asterisks on it to represent magic links to replace passwords. It is set against a dull, yellow-green background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9xGMmgZG44XK53WgPVtfuN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As someone who spends a lot of time writing about <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, I often find myself at risk of sounding like a broken record when it comes to the frailties of using passwords to sign into digital services.</p><p>By now people are probably all too aware that passwords are an imperfect <a href="https://www.itpro.com/security/cisco-launches-hypershield-a-must-have-solution-for-those-defending-against-iot-based-cyber-attacks">security solution</a>.</p><p>The dangers of poor password hygiene have been <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">well documented</a> for years now and despite this fact, and a number of alternative solutions being available (passkeys, biometrics, <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a>, and so on) we remain hooked on authenticating the old-fashioned way, but why?</p><p>One alternative to passwords that I’ve been using for a handful of digital services in my personal and professional life for the last few years is the magic link – and I’m pretty convinced of its efficacy, efficiency, and security.</p><p>A magic link is a URL with an embedded token sent to the user’s email address and when clicked it automatically logs them into the service they are trying to access. Simple right? They really make passwords feel like antiquated technology.</p><p>Instead of forcing the weary user through the all too familiar rigmarole of creating and recording a strong password for each and every platform they use on their computer, the magic link just necessitates they manage one password: the one for their <a href="https://www.itpro.com/email-providers/30214/how-to-delete-a-gmail-account">email account</a>.</p><p>Of course, it goes without saying that your email account should have at least one extra layer of protection, such as <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a>, but if you can ensure this is secure then using it to quickly sign into other services is a breeze, and I’m stumped why passwordless authentication is not more common today.</p><p>Today, most professionals, regardless of their specific role, are <a href="https://www.itpro.com/business/business-strategy/software-developers-security-experts-and-even-investment-bankers-all-report-that-tool-sprawl-is-burning-budgets-and-wasting-employees-time">required to use a litany of environments and platforms</a>. Multiple social media networks, a content management suite, analytics tools, development environments, and the inevitable <a href="https://www.itpro.com/software-as-a-service-saas/34466/cloud-communications-what-is-it-and-why-do-you-need-it">unified communications as a service (UCaaS)</a> in their daily workflow, can all very quickly accumulate to become an <a href="https://www.itpro.com/business/business-strategy/software-developers-security-experts-and-even-investment-bankers-all-report-that-tool-sprawl-is-burning-budgets-and-wasting-employees-time">overwhelming sea of tools and accounts</a> you need to manage.</p><p>Because these sessions usually expire each day for security reasons, most professionals will have to repeat the process of signing in every morning. This is tedious and only becomes more frequent over time as new services are onboarded.</p><p>I’ve found the programs in my daily workflow that use magic links, such as <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a>, make this process seamless and instant. I would suggest that many enterprises are losing productivity and sacrificing their security by not implementing magic links across more elements of their software portfolio.</p><h2 id="resigning-popular-password-based-attacks-to-the-past">Resigning popular password-based attacks to the past</h2><p>As people are forced to constantly create and record an ever-expanding list of passwords, the fatigue becomes all too real. It’s inevitable the average professional will get complacent the longer this goes on and give up on creating a unique, strong password each and every time.</p><p>This is what cybercriminals are banking on when they conduct their <a href="https://www.itpro.com/security/most-passwords-take-a-matter-of-minutes-to-crack-heres-how-you-can-create-strong-hacker-resistant-credentials">brute force</a>, password spraying, or <a href="https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks">credential stuffing</a> attacks, and magic links could remove these weapons from their arsenal.</p><p>Reusing passwords is a bad habit that most people can’t seem to kick. <a href="https://bitwarden.com/resources/world-password-day/#:~:text=The%20survey%20shows%20that%20a,and%20online%20forums%20(30%25).">Research</a> from Bitwarden, who surveyed 2,400 individuals in the US, UK, Australia, France, Germany, and Japan, found that a quarter admitted to reusing passwords across at least 11 accounts; this would make them prime targets for credential stuffing attacks if just one of these accounts was compromised and uploaded to a <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a> hacking forum.</p><p>Password spraying attacks are another common entry vector. Last year, we saw even the biggest companies fall prey to a seemingly simple error. In January 2024, it emerged that the Russian threat group Midnight Blizzard had accessed <a href="https://www.itpro.com/security/cyber-attacks/sneak-and-peek-midnight-blizzard-attack-highlights-worrying-flaws-in-microsoft-security-processes">emails from Microsoft’s senior leadership team</a>, after compromising a legacy account using a password spray attack.</p><p>This proves that even firms of the size and resources of Microsoft are not infallible and fall prey to using basic or already compromised passwords, so why should your business be any different?</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p><a href="https://www.itpro.com/software/368047/are-password-managers-safe-heres-how-to-use-them">Password managers</a> are often raised as the panacea to this problem. While I use one in my day-to-day life, setting them up is far from seamless. Once established, they also need constant updates and reconfiguring to ensure they detect login fields, sync across devices, and more.</p><p>Magic links, in my opinion, would mitigate the aforementioned attack vectors, and remove all of the added stress, and often cost, of managing hundreds of passwords for every single service users need to access on a semi-regular basis.</p><p>And the security benefits of using magic links are not just exclusive to people who use these services from the front-end. If a service uses usernames and passwords to authenticate users, then a breach of the database containing these credentials could leave their customers’ accounts at risk, as well as any other services they’ve reused these passwords with.</p><p>Even if these passwords are hashed there are still ways attackers may be able to decode the original password using rainbow tables or similar techniques, so hashed or not you don’t want this data falling into the wrong hands. So why not get rid of it altogether?</p><p>Implementing magic links also requires minimal changes to an organization’s existing infrastructure and they can be stood up with fewer resources than other security layers like MFA or physical hardware-based tokens.</p><h2 id="magic-links-are-no-silver-bullet-but-they-re-halfway-there">Magic links are no silver bullet – but they’re halfway there</h2><p>There are, of course, some caveats here. The email that delivers your magic link must be instant for the system to work properly. If you’ve ever had to wait for a password reset email you know how frustrating this process can be. Ensuring the login email arrives in your inbox quickly is imperative, or the efficiency of the system is totally lost.</p><p>The elephant in the room is the fact that by using magic links, any attacker with access to your email account suddenly has access to every service you use magic links to sign in with. </p><p>I would argue this isn’t necessarily a weakness with just magic links, however. For email-based authentication like magic links to be successful you need to ensure you have adequate security protections on your email account – but this really should be the bare minimum.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qQyHwhHoccvsxdAQrEgLgJ" name="Fortinet’s tested and validated architectures for cloud network security" caption="" alt="Fortinet’s tested and validated architectures for cloud network security" src="https://cdn.mos.cms.futurecdn.net/qQyHwhHoccvsxdAQrEgLgJ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/fortinets-tested-and-validated-architectures-for-cloud-network-security"><em>Speed up cloud deployment and improve security</em></a></p></div></div><p>But even if you aren’t using magic links, the password reset option on most sign-in pages would mean most of your secure services are at risk if an attacker successfully takes over your inbox. As long as you are smart about keeping your email account secure and following a <a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy">strong password policy</a>, using magic links should be a very secure way to sign in.</p><p>Although I like the idea of going passwordless, it’s a ways off. In the short term, we can drastically reduce the cyber burden on workers through solutions such as magic links. Outside of core services that still require passwords and layers of MFA, there’s no reason to not embrace magic links on a massive scale.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Password management startup Passbolt secures $8 million to shake up credential security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/Passbolt-Series-A-Funding-Round</link>
                                                                            <description>
                            <![CDATA[ Password management startup Passbolt has secured $8 million in funding as part of a Series A investment round. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vUKHBEBiWGjweqF8BwD5dT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6adyF6yToudp5xyxeAfBSK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jan 2025 14:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 23 Jan 2025 15:26:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6adyF6yToudp5xyxeAfBSK-1280-80.jpg">
                                                            <media:credit><![CDATA[Passbolt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Passbolt co-founders pictured standing side by side against a white background.]]></media:description>                                                            <media:text><![CDATA[Passbolt co-founders pictured standing side by side against a white background.]]></media:text>
                                <media:title type="plain"><![CDATA[Passbolt co-founders pictured standing side by side against a white background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6adyF6yToudp5xyxeAfBSK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/368049/best-password-managers-for-business">Password management</a> startup Passbolt has secured $8 million in funding as part of a Series A investment round. </p><p>Passbolt specializes in credential management for organizations ranging in size from small businesses to large enterprises, and boasts more than 400,000 active daily users. </p><p>While focusing primarily on <a href="https://www.itpro.com/software/368024/five-essential-features-of-password-managers">password management</a>, the startup also provides security for a variety of organizational credentials. This includes support for root accounts, SSH keys, <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business">passkeys</a>, and API keys. </p><p>Additionally, Passbolt is fully <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a>, providing enterprise users with both self-hosting capabilities and the ability to customize management practices to match company policies or regulatory obligations. </p><p>The funding will be used to accelerate product development, the company confirmed, and enable it to scale international sales and marketing activities. </p><p>Among the first key milestones for the firm in the wake of the investment will be its next major release, Passbolt 5.0, which it said will “extend capabilities” for users. </p><p>"Organizations are trapped between consumer-focused password managers and complex monolithic enterprise solutions that don't meet the need for secure collaboration of agile teams operating in digital environments," said Kevin Muller, co-founder and CEO of Passbolt. </p><p>"We're building a new type of credential and access manager for organizations of all sizes. It enables technical teams to collaboratively manage access to the organization’s IT, software development, and security infrastructure. At the same time, it allows the broader workforce to automatically log into productivity tools and to share access credentials with colleagues securely." </p><h2 id="passbolt-capitalizing-on-market-growth">Passbolt capitalizing on market growth</h2><p>Passbolt operates in a market which is expected to grow significantly over the next few years. </p><p>Analysis from Gartner, for example, predicts the <a href="https://www.gartner.com/en/documents/4811431" target="_blank"><u>privileged access management (PAM) space will grow to $2.8 billion by 2027</u></a>, underlining the huge demand for solutions. </p><p>The consultancy noted that a key factor in this growth rate is a surge in demand for secure remote access by external contractors and the continued trend of remote and hybrid working practices. </p><p>The funding round, which brings its total investment to date to over $11.5 million, was led by Netherlands-based investment firm, Airbridge Equity Partners, alongside existing partners such as Expon Capital.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="i95dfjdDqzWPFmQQCuuuBE" name="dell-logo-white-bright-sign-wood-background-GettyImages-1175327992.jpg" caption="" alt="The Dell logo in white against a wood-panelled wall" src="https://cdn.mos.cms.futurecdn.net/i95dfjdDqzWPFmQQCuuuBE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/powerstore-prime"><em>Keep your IT infrastructure ready for future needs</em></a></p></div></div><p>“Since the very first funding round, we have supported Passbolt in its mission to transform password and access management for modern teams," said Alain Rodermann, partner at Expon Capital. </p><p>“We are thrilled to see Passbolt achieve this new funding milestone and continue innovating to serve thousands of organizations worldwide.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass breach comes back to haunt users as hackers steal $12 million in cryptocurrency ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/lastpass-breach-comes-back-to-haunt-users-as-hackers-steal-usd12-million-in-two-days</link>
                                                                            <description>
                            <![CDATA[ The hackers behind the LastPass breach are on a rampage two years after their initial attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eTrJaFggUFyNf5FEmxduQV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zDzWLjVkFNnr4Jf7GbSnmM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Dec 2024 11:00:44 +0000</pubDate>                                                                                                                                <updated>Wed, 18 Dec 2024 14:45:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zDzWLjVkFNnr4Jf7GbSnmM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass Logo on mobile phone next too earbuds and car keys]]></media:description>                                                            <media:text><![CDATA[LastPass Logo on mobile phone next too earbuds and car keys]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass Logo on mobile phone next too earbuds and car keys]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zDzWLjVkFNnr4Jf7GbSnmM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A major data breach at password manager firm <a href="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely">LastPass</a> in 2022 is still causing mayhem two years later, with cyber criminals using stolen information to carry out further attacks.</p><p>According to data collated by crypto investigator ZachXBT, hackers <a href="https://www.chainabuse.com/report/0ea24e3c-0b02-46f4-bb5d-5196700f0149?context=browse-all" target="_blank">stole</a> $12.38 million in cryptocurrency from LastPass users on 16 and 17 December.</p><p>The attackers drained nearly 150 individual victim addresses, according to the analysis, with ZachXBT noting the stolen money was quickly converted into different currencies and syphoned away.</p><p>“The stolen funds were swapped for ETH and transferred to various instant exchanges from <a href="https://www.itpro.com/blockchain/32679/coinbase-halts-trading-of-ethereum-classic-after-attack">Ethereum</a> to <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin">Bitcoin</a>,” ZachXBT wrote in his Telegram channel.</p><p>This activity is the most recent example of criminal activity linked to the 2022 <a href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance">LastPass breach</a>, with cyber criminals stealing approximately $4.4 million from over 25 victims on 25 October 2023.</p><p>Breaking the news, ZachXBT <a href="https://x.com/zachxbt/status/1717901088521687330" target="_blank">urged</a> readers to move their cryptocurrencies if they might have been impacted by the LastPass incident.</p><p>“I cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass, migrate your crypto assets immediately.”</p><p>Jamie Moles, senior technical manager at <a href="https://www.itpro.com/business/extrahop-eyes-2024-expansion-after-securing-dollar100-million-growth-capital">ExtraHop</a>, said the drawn out effects of cyber breaches are becoming all too familiar, noting it’s likely the true scale of the fallout associated with the incident is yet to be fully comprehended.</p><p>“This is just the most recent in an ongoing stream of <a href="https://www.itpro.com/technology/cryptocurrencies/359959/cryptocurrency-crimes-increased-12-fold-since-2016-foi-finds">crypto thefts</a> affecting victims of the LastPass breach. With this new information coming to light two years on , we can assume we still don’t understand the full extent of the damage,” he explained.</p><p>“The long-tail effects of hacks on even the most sophisticated organisations underscores how important it is to get cybersecurity right in the first place. We know that there are going to be new exploits and unknown threats coming at enterprise and public sector organisations. Using signatures and rules to detect known <a href="https://www.itpro.com/cloud/cloud-security/protect-your-attack-vectors-from-emerging-threats">attack vectors</a> isn’t enough, and it hasn’t been for some time.”</p><h2 id="what-happened-with-the-lastpass-breach">What happened with the LastPass breach?</h2><p>The original incident, believed to have begun in August 2022, saw hackers use stolen information from a compromised developer environment to eventually lift <a href="https://www.itpro.com/business/business-strategy/370170/openai-launches-chatgpt-api-for-businesses-at-competitive-price">API tokens</a>, MFA seeds, customer keys, and source code.</p><p>On 25 August 2022, Karim Toubba, <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> at LastPass, published a <a href="https://blog.lastpass.com/posts/notice-of-recent-security-incident" target="_blank">notice</a> warning users that suspicious activity had been detected inside the company’s development environment.</p><p>“We have determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information. Our products and services are operating normally.”</p><p>Although the company said no customer or password information was compromised in September, Toubba issued a statement on 30 November warning that hackers had used information stolen in August to gain access to its <a href="https://www.itpro.com/cloud/cloud-storage/368596/best-cloud-storage-for-business">third-party cloud storage service</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QvKLZacdmNXsnKdQahLywe" name="Grow and Innovate on an Energy-Efficient, Sustainable IT Infrastructure" caption="" alt="Grow and Innovate on an Energy-Efficient, Sustainable IT Infrastructure" src="https://cdn.mos.cms.futurecdn.net/QvKLZacdmNXsnKdQahLywe.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/grow-and-innovate-on-an-energy-efficient-sustainable-it-infrastructure"><em>An environmentally responsible approach to IT operations</em></a></p></div></div><p>In December 2022, LastPass found that the hackers were able to access LastPass <a href="https://www.itpro.com/security/data-breaches/roku-issues-warning-over-massive-customer-account-breach">customer account information</a> as well as backups of the customer vault data. </p><p>Compromised data included “unencrypted data, such as website <a href="https://www.itpro.com/security/privacy/368588/meta-begins-encrypting-facebook-urls-nullifying-tracking-countermeasures">URLs</a>, as well as fully-encrypted sensitive fields, such as website usernames and passwords, secure notes, and form-filled data”.</p><p>Finally, in March 2023 LastPass revealed the threat actors behind the attack had gained access to the personal device used by a senior <a href="https://www.itpro.com/devops/28097/what-is-devops">DevOps</a> engineer after reportedly exploiting a vulnerability in their Plex Media software.</p><p>The hackers appeared to be looking for <a href="https://www.itpro.com/security/ransomware/359859/avaddon-hackers-release-decryption-keys">decryption keys</a> they could use to access the customer vaults they had stolen in November 2022. </p><p>It looks as if these activities were largely successful as the group continued to their rampage draining crypto accounts of users impacted by the breach years after the fact, underscoring the ‘long-tail effect’ breaches can have.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitHub launches passkeys beta for passwordless authentication ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/github-launches-passkeys-beta-for-passwordless-authentication</link>
                                                                            <description>
                            <![CDATA[ Users can now opt-in to using passkeys, replacing their password and 2FA method ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Kr2aNVKiLVdMj9noMzVDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jul 2023 15:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jul 2023 14:06:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:description>                                                            <media:text><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:text>
                                <media:title type="plain"><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GitHub has announced the arrival of its passkeys public beta for passwordless authentication, which the company says will enable seamless and secure access on GitHub.com.</p><p>The move will allow users to upgrade their security keys to passkeys to be used in place of both passwords and two-factor authentication (2FA) to bolster overall account security.</p><p>In an announcement, the firm explained that most security breaches involve lower-cost attacks such as social engineering, credential theft, or leakage. </p><p>According to data from the FIDO Alliance, the team behind the global authentication standard based on <a href="https://www.itpro.com/security/31775/what-is-public-key-infrastructure-pki"><u>public key cryptography</u></a>, passwords are estimated to be the root cause of over 80% of data breaches globally.</p><p>To tackle this, GitHub said its new passkeys bring easier configuration and enhanced recoverability, providing a secure and private way to protect accounts and minimize the risk of lockouts.</p><p>“GitHub is committed to helping all developers employ strong account security while staying true to our promise of not compromising their user experience,” said Hirsch Singhal, staff product manager at GitHub. “We began this commitment with our <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>2FA</u></a> initiative across GitHub. </p><p>“Today, we are furthering this work by ensuring seamless and secure access on GitHub.com with the public beta of passkey authentication.”</p><p>Users can implement passkeys via the ‘Feature Preview’ tab in the settings sidebar, which now displays an option to ‘enable passkeys’. This will enable the option to upgrade eligible security keys to passkeys, as well as register new passkeys.</p><h2 id="how-github-passkeys-work">How GitHub passkeys work</h2><p>The new passkeys essentially count as two security layers in one, combining a <a href="https://www.itpro.com/security/29705/what-are-biometrics"><u>user element such as a thumbprint</u></a>, face, or knowledge of a PIN, with a physical element such as a security key or device.</p><p>Due to expanded browser support, GitHub said a browser’s autofill system can automatically suggest that users use their passkey to sign in straight from the login page – regardless of whether a user has 2FA enabled.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2nNdcPL9CGTu8jwiuvm3GK" name="State of Email Security 2023_thumb.jpg" caption="" alt="Black whitepaper cover with strapline and image of man's face overlaid looking in different directions" src="https://cdn.mos.cms.futurecdn.net/2nNdcPL9CGTu8jwiuvm3GK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The state of email security 2023</strong></p><p class="fancy-box__body-text">Discover how leaders are protecting their organizations from cyber attacks in the face of increases in email usage. </p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/the-state-of-email-security-2023">DOWNLOAD FOR FREE</a></p></div></div><p>Passkeys can also be used across more than just the device they were created on, thanks to a new experience labeled ‘Cross-Device Authentication’. </p><p>This allows the use of a passkey on a phone to sign into a laptop, for example, by verifying the phone’s presence.</p><p>“Because your phone or tablet must be physically close to your laptop or desktop, Cross-Device Authentication retains the phishing-resistant promise of FIDO,” Singhal said.</p><p>Additionally, many passkeys can be synced across multiple devices to help prevent account lock-out due to key loss. This can be done automatically, depending on passkey provider, GitHub said. </p><h2 id="how-to-upgrade">How to upgrade</h2><p>Existing user security keys that are capable of verifying identity – such as Touch ID, Windows Hello, Android thumbprints, or PIN-locked or biometric hardware keys – are eligible to be upgraded.</p><p>Upon next sign in with the security key, GitHub will ask users if they would like to upgrade to a passkey. This will then re-register the security key with the user’s <a href="https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys"><u>passkey</u></a> provider to ensure it is discoverable during authentication and synced. Up-to-date devices support passkeys straight out of the box.</p><p>“Because passkeys are privacy-preserving, you might have to trigger your passkey a few times during that upgrade flow so we can make sure we’re upgrading the right credential,” Singhal said. “Once you do, you’re all set for a <a href="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better"><u>passwordless experience</u></a>.</p><p>“By registering durable, secure credentials across all your devices, we hope to prevent account lockouts due to device loss,” Singhal added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft SQL password-guessing attacks rising as hackers pivot from OneNote vectors ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-sql-password-guessing-attacks-rising-as-hackers-picot-from-onenote-vectors</link>
                                                                            <description>
                            <![CDATA[ Database admins are advised to enforce better controls as attacks ending in ransomware are being observed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Umthpss9ruTMtDiWXfTLT9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jul 2023 11:54:08 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jul 2023 13:49:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:description>                                                            <media:text><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Malware attacks using Microsoft SQL (MSSQL) Server as an intrusion vector have risen sharply in the last six months, as experts report hackers moving away from blocked methods.</p><p>Researchers at cyber security firm ESET revealed the absolute count of MSSQL attacks increased by 84% between H2 2022 and H1 2023. </p><p>The rise in attacks utilizing the vector was linked to Microsoft’s landmark move to block Virtual Basic for Applications (VBA) macros in Office documents by default last year.</p><p>Cyber security professionals had been calling for stricter default controls for VBA macros for years before Microsoft finally implemented the changes.</p><p>Exploiting VBA macros in Office documents was historically one of the most popular methods of embedding malware in seemingly innocuous files which were downloaded as part of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><p>Shortly after this avenue of attack was blocked off, researchers recorded a clear rise in the number of attacks using OneNote as a vector instead. </p><p>Cyber criminals behind malware such as <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet"><u>Emotet</u></a> exploited .one files to trick users into running malicious scripts, moving on from <a href="https://www.itpro.com/security/cyber-security/370253/new-emotet-socially-engineers-evade-detection"><u>their own abuse of VBA macros</u></a>.</p><p>In its <a href="https://www.welivesecurity.com/wp-content/uploads/2023/07/eset_threat_report_h12023.pdf" target="_blank">report</a>, ESET said Microsoft’s blocking of VBA macros and its efforts to shore up the security of OneNote means that “cyber criminals may be looking at MSSQL and other intrusion vectors more closely” for the future.</p><p>MSSQL is a widely-used solution for regional database management, and when exposed to the internet can be a tempting target for hackers. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XoGp9XGktCfhhm5KZbiWzT" name="The Board's Evolving Perceptions of Cyber Risk (1).jpg" caption="" alt="Whitepaper from Mimecast about cyber risk as business risk" src="https://cdn.mos.cms.futurecdn.net/XoGp9XGktCfhhm5KZbiWzT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The board&apos;s evolving perceptions of cyber risk</strong></p><p class="fancy-box__body-text"><em>78 global CISOs share their advice on how to communicate cyber risk as business risk to C-suite peers and their board.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-boards-evolving-perceptions-of-cyber-risk">DOWNLOAD FOR FREE</a></p></div></div><p>Internet-accessible MSSQL servers can be accessed via port 1433, which leaves the door open for ‘brute force’ password-guessing attempts by threat actors.</p><p>ESET noted that firms with weak passwords or improperly-managed servers are at particular risk, and cited an AhnLab <a href="https://asec.ahnlab.com/en/51343/"><u>report</u></a> from April which examined a case of <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware</u></a> installed on MSSQL servers as a result of easily-guessed credentials.</p><p>In all, telemetry data showed 1.7 billion failed password-guessing attempts against MSSQL between December 2022 and May 2023.</p><p>Even as threat actors have increased attacks against MSSQL, researchers noted reduced brute-force attempts on other commonly-used attack vectors. </p><p>Attacks on <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp"><u>Remote Desktop Protocol (RDP)</u></a>, which allows users to view and control desktops remotely and has been <a href="https://www.itpro.com/security/malware/researchers-uncover-novel-rdstealer-malware-targeting-remote-desktop-protocol"><u>exploited for malware such as RDStealer</u></a>, fell 22% from 17.9 billion to 15.8 billion across the period.</p><p>Brute-force attacks are among the <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>top password-cracking techniques hackers use</u></a>, and rely on businesses to employ poor strategies around their credentials such as allowing employees to re-use passwords or not enforcing complexity controls.</p><p>“With the rise of brute-force attacks against MSSQL, database admins should be reminded of the security benefits of Windows Authentication mode over mixed mode when setting up the database engine,” said Ladislav Janko, senior detection engineer at ESET.</p><p>“In Windows Authentication mode, SQL Server Authentication is disabled, compelling database users to connect through their Windows user account, which can be protected with an account lockout policy that effectively stops brute force attacks from progressing.</p><p>“If you can’t avoid using mixed mode, make sure passwords are strong and put the database behind a firewall or VPN, if possible.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No, Microsoft SharePoint isn’t cracking users’ passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/no-microsoft-sharepoint-isnt-cracking-users-passwords</link>
                                                                            <description>
                            <![CDATA[ The discovery sparked concerns over potentially invasive antivirus scanning practices by Microsoft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K6kGumBxCtcKtVSpuz8shJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 May 2023 10:53:40 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 13:04:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:description>                                                            <media:text><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security professionals have raised concerns that Microsoft SharePoint appears to be ‘breaking into files’ and scanning users’ password-protected ZIP archives. </p><p>The discovery was made by Andrew Brandt, a principal security researcher at Sophos, after he found that files containing malware for research purposes were scanned by Microsoft’s 365 virus detection software. </p><p>Brandt outlined his claims in a Mastodon thread, revealing that several password-protected ZIP files had been flagged as ‘malware detected’ by <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>antivirus software</u></a>. </p><p>Following the <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware </u></a>flag, Brandt noted that this “limits what I can do with those files - they are basically dead space now”. </p><p>“Apparently Microsoft SharePoint now has the ability to scan inside of password-protected ZIP archives,” he wrote. </p><p>“How do I know? Because I have a lot of ZIPs (encrypted with a password) that contain malware, and my typical method of sharing those is to upload those passworded ZIPs into a Sharepoint directory.</p><p>“This morning, I discovered that a couple of password-protected ZIPs are flagged as "Malware detected" which limits what I can do with those files - they are basically dead space now.”</p><p>The discovery sparked initial concerns that Microsoft is actively scanning password-protected files, raising concerns over security and privacy. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XLoUwV2iUi4cPwrDUKxR6k" name="Defence in depth_listing.jpg" caption="" alt="Whitepaper cover with title over purple shaded image of female worker peering over the top of an office cubicle" src="https://cdn.mos.cms.futurecdn.net/XLoUwV2iUi4cPwrDUKxR6k.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Defence in depth: Closing the gaps in Microsoft 365 security</strong></p><p class="fancy-box__body-text"><em>Exploring the security challenges facing organisations with a reliance on Microsoft 365</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/microsoft-office/356963/defence-in-depth-closing-the-gaps-in-microsoft-365-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>One user suggested that the practice is a reason why they’re “moving away from MS cloud” and that it crosses “ethics boundaries”. </p><p>“There is a bit of an ethics boundary being crossed here when they are starting to just break into files and archives under the guise of ‘security’ (which may just be used as a facade for them).”</p><p>In a reply on the <a href="https://infosec.exchange/@threatresearch/110373860063222707" target="_blank"><u>Mastodon thread</u></a>, Brandt noted that SharePoint uses a “word list” to check and potentially flag the content of files. </p><p>Given the password was ‘infected’ - a common archive password used in the cyber security community - SharePoint appears to have flagged this particular file. </p><p>“[SharePoint] says it uses a word list,” he said. “The password was ‘infected’ which is not in the least bit secure, but I hadn’t seen it poking around inside of passworded ZIPs before now, and was under the impression it wouldn’t do that.” </p><p>Brandt added that while this practice is understandable from a generalist perspective, for malware analysts in particular it could prove inhibitive. </p><p>“While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” he said. </p><p>“The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”</p><h2 id="file-scanning-practices">File scanning practices</h2><p>Although this has raised some concerns over the scanning of files, the practice is well-documented by Microsoft in an <a href="https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-malware-protection-for-spo-odfb-teams-about?view=o365-worldwide#what-happens-if-an-infected-file-is-uploaded-to-sharepoint-online" target="_blank"><u>explainer for its built-in antivirus protection</u></a> for SharePoint, OneDrive, and Microsoft Teams. </p><p>“The <a href="https://www.itpro.com/business-operations/productivity/368063/microsoft-365-vs-google-workspace"><u>Microsoft 365</u></a> virus detection engine scans files asynchronously (at some time after upload). If a file has not yet been scanned by the asynchronous virus detection process, and a user tries to download the file from the browser or from Teams, a scan on download is triggered by SharePoint before the download is allowed,” the explainer reads. </p><p>“All file types are not automatically scanned. Heuristics determine the files to scan. When a file is found to contain a virus, the file is flagged.” </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">So, Microsoft's scanner started detecting malware in password-protected ZIP archvies and people are losing their shit because they have no goddamn clue how anti-virus programs work.https://t.co/P0a5QFPrRXStrap in, kids, because I'm in a lecturing mood. Thread:<a href="https://twitter.com/VessOnSecurity/status/1658373432562597889">May 16, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>In a Twitter thread reacting to the news, Dr. Vesselin Vladimirov Bontchev (@‘VessOnSecurity’) said the practice isn’t quite as concerning as it seems. </p><p>“Scanners have been doing this since the ‘90s,” he wrote. “I think McAfee’s scanner was the first to try the password ‘infected’ if it encountered an <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encrypted</u></a> ZIP archive.”</p><p>Bontchev pointed out that the practice of ‘protecting’ a ZIP archive potentially containing malware has traditionally been a tactic to improve safety and prevent unknowing users from downloading malicious software. </p><p>“The idea here is not secrecy. The idea is safety. These archives with malware are (or at least were) often sent by email from one researcher to another,” he explained. </p><p>“It&apos;s easy to mistype someone&apos;s email address and we wanted to make sure that if some random person, other than the intended recipient, received the malware by mistake, they wouldn&apos;t infect themselves by accidentally running it.”</p><p><em>ITPro</em> has approached Microsoft for comment on the matter. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Authenticator mandates number matching to counter MFA fatigue attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-authenticator-mandates-number-matching-to-counter-mfa-fatigue-attacks</link>
                                                                            <description>
                            <![CDATA[ The added layer of complexity aims to keep social engineering at bay ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PFXs6L8QB6ZQk37HwUY5Rj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SwwWx2x86rG7LZCCN4yjxL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 May 2023 09:21:40 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 12:16:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SwwWx2x86rG7LZCCN4yjxL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Authenticator: Microsoft logo on an office building]]></media:description>                                                            <media:text><![CDATA[Microsoft Authenticator: Microsoft logo on an office building]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Authenticator: Microsoft logo on an office building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SwwWx2x86rG7LZCCN4yjxL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft Authenticator will now enforce number matching for all push notifications to make multi-factor authentication (MFA) less susceptible to social engineering attacks.</p><p>High-profile cyber criminals have seen success exploiting <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>MFA fatigue</u></a> attacks. These involve sending a barrage of MFA push notification requests to organizations’ staff, often at unsociable hours, to manipulate them into authenticating a login attempt just to clear the frustrating notifications.</p><p>Number matching involves opening a push notification, launching Microsoft Authenticator, and entering a series of numbers that appear in the app in order to approve the login attempt.</p><p>The technique has been around for years and marries the authentication methods of <a href="https://www.itpro.com/security/why-mfa-why-now"><u>MFA</u></a> and <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>two-factor authentication (2FA)</u></a>.</p><p>These numbers usually reset after a given time period, like 30 seconds, and add an additional layer of interaction to help reduce the risk of successful <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one"><u>social engineering attacks</u></a>.</p><p>In a typical attack scenario, recipients of the constant notifications are often asleep and wake up to a series of loud alerts from their smartphone. </p><p>Half asleep, the attack can see success when staff simply approve login attempts so they can get back to sleep, for example.</p><p>Adding another manual layer increases the difficulty in quickly approving requests, making the process more manual and potentially allowing more time for the recipient to realize that the event is being triggered by a bad actor.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Hw9HzYMdQ9BWUrqYhSXezD" name="msft-mfa-number-matching.jpg" alt="Number matching in Microsoft Authenticator" src="https://cdn.mos.cms.futurecdn.net/Hw9HzYMdQ9BWUrqYhSXezD.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Microsoft)</span></figcaption></figure><p>“As relevant services deploy, users worldwide who are enabled for Authenticator push notifications will begin to see number matching in their approval requests,” said Microsoft in its <a href="https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-number-match" target="_blank"><u>Active Directory (AD) documentation</u></a>. </p><p>“Users can be enabled for Authenticator push notifications either in the Authentication methods policy or the legacy multifactor authentication policy if Notifications through mobile app is enabled.”</p><p>Microsoft said number matching will be applied as standard to a number of different authentication scenarios. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qWsVUmLpRdEkf8fyizCyRM" name="Why MFA, why now_thumb.jpg" caption="" alt="Webinar screen with host image top right and centre image of man using a smartphone surrounded by brand logos including Salesforce" src="https://cdn.mos.cms.futurecdn.net/qWsVUmLpRdEkf8fyizCyRM.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Why MFA, why now?</strong></p><p class="fancy-box__body-text"><em>A discussion with Okta and Salesforce on the new MFA requirement</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/why-mfa-why-now"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Users attempting a self-service password reset (SSR) will also have to use MFA number matching to complete the process. </p><p>Number matching will also be enforced for combined registration in Azure AD and the AD FS adapter for Windows Server.</p><p>Microsoft clarified that users cannot opt out of number matching, but there may be some scenarios that don’t enforce it, such as in MFA Server, which is deprecated, and with old versions of Authenticator which will no longer work, requiring an update.</p><p>The AD portal may also still show the setting to enable number matching manually, but Microsoft said that you may just need to refresh the browser in order to see the update.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ As Google launches passwordless authentication for all, what are the business benefits of passkeys? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys</link>
                                                                            <description>
                            <![CDATA[ Google follows Apple in its latest shift to passwordless authentication, but what are the benefits? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">epQDr2gQuKBbiZFGQpuDdL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Kd5SYfqeocWb8itfzoCTTZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 May 2023 11:50:21 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 11:33:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Kd5SYfqeocWb8itfzoCTTZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google logo in a shield surrounded by warnings and password icons i the Google design language]]></media:description>                                                            <media:text><![CDATA[Google logo in a shield surrounded by warnings and password icons i the Google design language]]></media:text>
                                <media:title type="plain"><![CDATA[Google logo in a shield surrounded by warnings and password icons i the Google design language]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Kd5SYfqeocWb8itfzoCTTZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has announced that users can now create and use passkeys on personal Google accounts, marking another leap towards a potential passwordless future for businesses. </p><p>In an announcement this week, the tech giant revealed that users will be able to ditch their traditional passwords and two-factor authentication processes when signing into accounts. </p><p>Google said the move will provide users with a “more convenient and safer alternative to passwords” by allowing them to unlock their computer or mobile device using biometric technologies such as <a href="https://www.itpro.com/security/privacy/356882/the-pros-and-cons-of-facial-recognition-technology"><u>facial recognition</u></a>, or by using a local pin. </p><p>“Using passwords puts a lot of responsibility on users,” the company said in a statement. “Choosing strong passwords and remembering them across various accounts can be hard.”</p><p>This announcement from Google follows significant movement among major tech firms on the development and rollout of passkeys. </p><p>Microsoft, Apple, and Google have all <a href="https://www.itpro.com/security/cyber-security/367601/apple-google-microsoft-expand-support-for-password-less-sign-in"><u>committed to providing passkeys</u></a> in recent years, and have been working closely with the FIDO Alliance and World Wide Web Consortium to deliver more standardized forms of passwordless authentication. </p><p>In June last year, Apple announced the launch of its Passkey standards at its Worldwide Developer Conference (WWDC). </p><p>The move meant that users could use passkeys on <a href="https://www.itpro.com/software/operating-systems/369384/security-features-apple-macos-ventura-compelling-business-upgrade"><u>supported devices using macOS Ventura</u></a>, iOS 16 and onward, and iPadOS 16 and onward. </p><h2 id="what-are-passkeys">What are passkeys?</h2><p>A passkey is a method of passwordless login for users. This form of login standard relies on public key cryptography and is thought to offer huge benefits in preventing phishing attacks.</p><p>A private key will be generated and stored on a user’s device and a corresponding public key is uploaded to the cloud. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LXUGMsM76TZFUMCwm9Eu27" name="Build_vs_Buy.png" caption="" alt="Webinar screen with title, logo, and contributor information" src="https://cdn.mos.cms.futurecdn.net/LXUGMsM76TZFUMCwm9Eu27.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Build vs. buy: Is managing Customer Identity slowing your time to market?</strong></p><p class="fancy-box__body-text"><em>Why identity should be top of mind</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/build-vs-buy-is-managing-customer-identity-slowing-your-time-to-market"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Separate key pairs are created for each service provider, such as Apple, Google, or Microsoft, for example. </p><p>When logging in using a passkey, a device will request that the user identifies themselves with their own private key, which is then verified via the public key. </p><p>Private keys stay on your devices, and in some cases only stay on the device it was created on, meaning that users aren’t forced to remember myriad passwords and navigate 2FA protocols when logging in. </p><p>The method is seen as a strong defense against phishing attacks as the attacker would need physical access to the unlocked device in order to login to a victim’s account.</p><p>It builds on the previous gold standard of 2FA implementations: using passwords combined with hardware keys, which prevent cases of <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>MFA fatigue</u></a>, for example.</p><p>There are certain drawbacks to passkey authentication, especially in the event that a user loses their device. However, this isn’t as disastrous as some might think. </p><p>Some organizations, such as Apple, allow users to create a passkey on their iPhone which is cross-functional with other Apple devices and linked to iCloud. </p><p>This is specifically designed so that users can avoid being locked out of their accounts if they lose a particular device and enables a more seamless experience for users when upgrading or switching to newer hardware. </p><p>Google also has similar protocols in place which are linked to an individual’s Google Account. For example, if a device with a passkey is lost and at risk, Google allows users to “immediately revoke the passkey” via their account settings. </p><p>“If your device supports the option to remotely wipe it, consider doing that as well, especially if it also has passkeys for other services,” the firm said. </p><p>Google said it recommends users have a recovery phone and email for an account, which increases the chance of recovery in the event of a device being lost. </p><h2 id="the-business-advantages-of-passkeys">The business advantages of passkeys</h2><p>There are a number of advantages to using passkeys, with security and convenience among the most commonly highlighted. </p><p>The FIDO Alliance believes that <a href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security"><u>passwordless authentication standards</u></a> will unlock significant benefits with regard to security. </p><p>“Based on FIDO standards, passkeys are a replacement for passwords that provide faster, easier, and more secure sign-ins to websites and apps across a user’s devices,” according to a <a href="https://fidoalliance.org/passkeys/" target="_blank"><u>FIDO Alliance explainer</u></a>. “Unlike passwords, passkeys are always strong and phishing-resistant.​”</p><p>Millions of businesses worldwide still rely on using traditional passwords and multi-factor authentication techniques to keep them safe. But often this isn’t quite enough to keep them secure, as research shows. </p><p>Earlier this year, Authlogics, a provider of password security technologies, issued a warning over the <a href="https://www.itpro.com/security/370309/surge-in-compromised-credentials-highlights-rampant-cyber-hygeine-failings"><u>growing scale of exposed account passwords</u></a>.</p><p>The UK-based firm revealed that its Password Breach Database had reached a concerning landmark number of more than 5 billion compromised credentials. </p><p>Research from threat intelligence firm SpyCloud in March revealed that organizations globally still <a href="https://spycloud.com/resource/2023-annual-identity-exposure-report/" target="_blank"><u>maintain a “rampant” practice of password reuse</u></a>, which poses significant risks for businesses. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="5U2zqz7iAdmxwAmuuREEHX" name="2022_Public_Sector_Identity_Index_Report_listing.jpg" caption="" alt="Dark mauve whitepaper cover with title" src="https://cdn.mos.cms.futurecdn.net/5U2zqz7iAdmxwAmuuREEHX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>2022 Public Sector Identity Index Report</strong></p><p class="fancy-box__body-text"><em>UK Report</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/2022-public-sector-identity-index-report"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Nick France, Chief Technology Officer at Sectigo, said that, broadly speaking, passkeys represent a far more secure mode of authentication compared to traditional methods. </p><p>“While no system is perfect, the passkey strategy is fundamentally more secure than the old password system,” he said. </p><p>“Communication across the open internet is managed by unbreakable cryptographic keys, which are among the most secure computing standards we have.”</p><p>Similarly, Google’s view is that the inherent nature of passkeys lends itself to improved security. Unlike passwords, passkeys can only exist on a user’s device. </p><p>This means they cannot be written down and misplaced, or end up in the hands of a bad actor due to <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> techniques. </p><p>Given the increasing scale of phishing attacks in recent years, the continued rollout of passkeys offers businesses a key advantage in mitigating these risks.</p><p>“When you use a passkey to sign in to your Google Account, it proves to Google that you have access to your device and are able to unlock it,” Google said. </p><p>“Together, this means that passkeys protect you against phishing and any accidental mishandling that passwords are prone to, such as being reused or exposed in a data breach.”</p><p>Cost benefits are also a key factor in the popularity of passkeys among businesses. </p><p>Because passkeys are linked to a user&apos;s device, this reduces the IT-related red tape associated with password resets in corporate environments in the event that a user forgets one of many passwords, or if the account is compromised. </p><p><a href="https://www.okta.com/blog/2019/08/how-much-are-password-resets-costing-your-company/"><u>Analysis from Okta</u></a> shows that costs accrued from password resets reach up to $70 on average, which in larger enterprises could add up to a significant overall cost each year. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ There's only one way to avoid credential stuffing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/theres-only-one-way-to-avoid-credential-stuffing-attacks</link>
                                                                            <description>
                            <![CDATA[ PayPal accounts were breached last year due to a credential stuffing attack, but can PayPal avoid taking responsibility? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JNJisedo5pKuhiJ8nLCMph</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Apr 2023 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 02 May 2023 13:05:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:description>                                                            <media:text><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A cyber criminal using a laptop, with a close-up of their hands on the keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QiKYok3J9ymuxFszVLW8CM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Back in December 2022, PayPal didn’t suffer a data breach, but nearly 35,000 of its customers had their accounts accessed by an unauthorized party over the course of three days. Wait a minute, I hear you say; why isn’t that a PayPal <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>data breach</u></a>, then? </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></p></div></div><p>It’s a tricky one, truth be told, but the account access didn’t happen as a result of any compromise of PayPal security systems. Rather, they were subject to a large-scale credential stuffing incident that enabled a third-party attacker to access them using the correct <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022"><u>username and password</u></a> combo the real customer had set. </p><p>In effect, then, this was a breach of 34,942 individual PayPal accounts rather than a breach of PayPal itself. It was also a very good example of why people need to take better care when it comes to preventing themselves from getting stuffed in almost every sense of the phrase. </p><h2 id="what-happened-to-paypal-customers">What happened to PayPal customers?</h2><p>PayPal confirmed on 20 December that a credential stuffing attack took place between 6 and 8 December, when access for the unauthorized parties was eliminated. This is according to the notice of security incident sent to the affected account holders in January 2023. </p><p>No unauthorized transactions were made and, PayPal wrote, no personal information was misused. Whatever that may mean. Importantly, the attackers didn’t obtain the login credentials used from any PayPal systems. This means that it was the dreaded, all too common, and so easily preventable credential stuffing attack instead. </p><h2 id="how-do-credential-stuffing-attacks-work">How do credential stuffing attacks work?</h2><p>A credential stuffing attack is precisely what it claims to be: attempting to access multiple high-value accounts using login credentials for a different service. A service that, of course, has already been breached and the resulting credentials stolen and distributed within criminal marketplaces. The process itself is highly automated, with one login attempt after another executed using credential pairing upon credential pairing. </p><p>Some of these bot-driven attacks are pretty sophisticated, employing rotating <a href="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference"><u>IP addresses</u></a> and simultaneous login attempts in an attempt to circumvent rate-limiting and IP-blocking defensive measures. It’s easy to think of these as a type of brute force attack, but it’s more of a brute slamming one. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/365553/password-complexity-rules-arent-enough-to-protect-employees-from">Password complexity rules aren&apos;t enough to protect employees from attack</a></p></div></div><p>It slams the target service with actual credential pairs whereas brute force attacks have no known credentials and instead rely upon the use of random strings and common passwords. The critical difference, at least from the customer perspective, is that credential-stuffing attacks are way more successful than the no-context brute force ones.</p><h2 id="how-to-avoid-credential-stuffing-attacks">How to avoid credential stuffing attacks</h2><p>I would guess the average reader uses a <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022"><u>password manager</u></a> and isn’t in the habit of sharing login credentials between multiple accounts. The average user, however, is a different case. I checked with my password manager of choice, <a href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts"><u>1Password</u></a>, and I currently have just shy of 300 unique and random passwords stored within it. Nobody could remember all of those, not even if you had an ingenious password construction method. </p><p>Unless that ingenious method isn’t quite as secure as you think. Any form of password iteration is a no-no, as is using the service name in the password string. Not only do I not need to remember my passwords, I only actually know one of them; the password manager master password. And that’s not even a password; it’s a long passphrase that a combination of muscle memory and remembering the first two words ensures it’s easy to recall when needed.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YssANqmxxS4hiCype5M99b" name="Anatomy_of_Identity_Based_Attacks_listing.jpg" caption="" alt="Image of female and male colleagues looking at a computer" src="https://cdn.mos.cms.futurecdn.net/YssANqmxxS4hiCype5M99b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Anatomy of identity-based attacks</strong></p><p class="fancy-box__body-text"><em>Helping security teams mitigate identity-based attacks</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/anatomy-of-identity-based-attacks"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Because I’m fast approaching “old fart” status, I also have a 1Password emergency kit safely stashed away where nobody could easily find it, in case I did forget. Keeping such a thing written down isn’t as weak a security measure as you might think. The chance of someone breaking into your home and then finding it, if they did, is highly unlikely. A lot less likely than reusing the same passwords between multiple accounts. Yet that’s precisely what so many people do, and it’s why credential-stuffing attacks are not only increasingly popular but increasingly successful as well.</p><p>The mitigation is simple: <a href="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers">use a password manager</a>. Doing so can give you a double protective whammy, as it happens because you can also have random and unique usernames for accounts that don’t insist on your email address. If an account does, then you can simply set up unique email addresses using Gmail, for example. I’m quite a fan of using Apple’s Hide My Email feature with my iPhone, as this generates random and unique emails for logins that redirect to your actual email. </p><h2 id="was-paypal-to-blame-in-any-way">Was PayPal to blame in any way?</h2><p>For what it’s worth, I’m not letting PayPal off the hook here. While technically, this wasn’t a breach, it was a security incident because such a large number of accounts were accessed. PayPal should have measures in place to shut down such a concerted credential-stuffing attack before it ever achieves the scale of success it did in this case. </p><p>Although PayPal hasn’t, at the time of writing, disclosed much detail regarding the timeline and the technical measures employed, I feel pretty confident in saying the company fell short of what I’d expect such a large player in the financial sector to achieve in terms of security. </p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance">Does LastPass really deserve a last chance?</a></p></div></div><p>The small matter of not sharing your passwords across sites and services apart, the easiest way to stop credential stuffers from being successful is the use of <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue"><u>multi-factor authentication (MFA)</u></a>. Ironically, PayPal has such protections available, but it’s up to each customer as to whether they enable it. I’d argue that for all services, but particularly those in the financial sector, mandatory 2FA should be the norm. </p><p>What’s more, as I’ve already said, questions need to be asked as to how a large-scale attack such as this, and you have to assume that if 35,000 accounts were successfully accessed, then a much larger number of logins would have been attempted but failed, could not have been shut down more promptly. For this credential stuffing attack to continue across three days suggests to me that a review of relevant incident detection and response processes needs to be undertaken sharpish.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft Defender “obliterating” users with false password alerts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/windows/microsoft-defender-obliterating-users-with-false-password-alerts</link>
                                                                            <description>
                            <![CDATA[ Windows 11 devices have been affected by the Defender for Endpoint error, which flags SSO domains as problematic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2dFnJbT2GAv4nD2nSMhMPU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Apr 2023 11:22:25 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Apr 2023 15:42:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:description>                                                            <media:text><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo under magnifying glass, which appears in color in place of the Windows key on a standard white Microsoft keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zAYaas3CxLBLjrBvXghy8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>System administrators have reported an abudance of alerts from Microsoft Defender for Endpoint, with multiple sites falsely flagged as having reused passwords.  </p><p>A number of admins complained that they are receiving alerts that read “Password reuse activity was detected by Microsoft Defender for Endpoint” with no clear explanation from the software.</p><p>Users denied having reused passwords on the sites flagged by the system, while others have stated that multiple subdomains of software as a service (SaaS) platforms have been flagged as containing password reuse.</p><p>Many admins indicated that the problem could have arisen from Defender for Endpoint incorrectly flagging <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" target="_blank"><u>single sign-on (SSO)</u></a> domains as needing attention.</p><p>“We now have 17 alerts today for Password Reuse. Everyone I have looked at is a false positive,” one user <a href="https://www.reddit.com/r/DefenderATP/comments/12s6qcc/comment/jgyz7gj/" target="_blank"><u>wrote</u></a>.</p><p>They also noted that some alerts come with “about:blank” as the supposed domain containing password reuse, and that in one case a user was accused of “password reuse over three services, listing three subdomains of the same SaaS”.</p><p>The warning message itself is seemingly absent from Microsoft documentation.</p><p>"We determined these are false positive results and we have resolved this," a Microsoft spokesperson told <em>ITPro</em>.</p><p>"No customer action is needed."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uH2UFsZsWQr9xxCirTLXZP" name="More than a number_Your risk score explained_listing.jpg" caption="" alt="The back of two colleagues looking, and pointing at, a dual screen workstation in an office" src="https://cdn.mos.cms.futurecdn.net/uH2UFsZsWQr9xxCirTLXZP.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>More than a number: Your risk score explained</strong></p><p class="fancy-box__body-text"><em>Understanding risk score calculations</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/risk/370277/more-than-a-number-your-risk-score-explained"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>According to accounts from multiple commenters, the alerts appear to only be coming from Windows 11 devices and almost all relate to supposed password reuse on Microsoft domains.</p><p>“Yup same here, we are getting obliterated with alerts. The alerts are only coming from Win 11 devices,” <a href="https://www.reddit.com/r/sysadmin/comments/12s8gr9/any_one_else_all_of_sudden_getting_password_reuse/" target="_blank"><u>wrote</u></a> another.</p><p>Dozens of new commenters have appeared in a six-month-old thread covering the same issue, seeking help with inexplicable alerts that they too have received.</p><p>In a Twitter exchange on the issue, one user <a href="https://twitter.com/GlorytoSpoon/status/1646006140231098369" target="_blank"><u>suggested</u></a> that the problem could be linked to <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/protect-passwords-with-enhanced-phishing-protection/ba-p/3631881" target="_blank"><u>enhanced phishing protection</u></a> brought in by Microsoft in September 2022.</p><p>This is intended to warn users against reusing passwords.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">All this is related to SSO and OAuth and the only URI being flagged is https://t.co/oZk8RKMK00 (with various URLs)But yeah, fun trying to explain the user is not even entering a password 😬<a href="https://twitter.com/nemesis09/status/1648962153842462720">April 20, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>Microsoft Defender has incorrectly inundated users with warnings on multiple prior occasions. </p><p>In September 2022, the app <a href="https://www.itpro.com/security/cyber-security/368972/microsoft-defender-causes-mass-confusion-after-legitimate-apps-trigger-ransomware-alerts" target="_blank"><u>caused confusion after flagging software as ransomware</u></a>, including popular browsers and productivity apps such as Chrome, <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" target="_blank"><u>Slack</u></a>, and <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge" target="_blank"><u>Microsoft Edge</u></a>.</p><p>Further false positives were addressed by Microsoft in January 2023, after a <a href="https://www.itpro.com/operating-systems/microsoft-windows/369873/microsoft-releases-scripts-to-restore-shortcuts-windows-defender-faulty-update" target="_blank"><u>faulty update deleted shortcuts</u></a> that had been incorrectly identified as malware. </p><p>Microsoft released <a href="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference" target="_blank"><u>scripts</u></a> to fix the issue, though some administrators stated that these were imperfect and failed to fully rectify matters.</p><p>A recent update for Microsoft Defender Antivirus also led to confusion among devs, who upon updating received a warning stating that Local Security Authority (LSA) Protection - a process used to authenticate and oversee user logins - had been disabled.</p><p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#3048msgdesc" target="_blank"><u>released</u></a> a workaround for the issue, though a subsequent update appears to have disabled LSA altogether on Windows 11 systems in favor of a new process titled ‘Kernel-mode Hardware-enforced Stack Protection’.</p><p><em>This article has been updated to include a statement from Microsoft.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft angers admins as April Patch Tuesday delivers password feature without migration guidance ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/windows/microsoft-april-patch-tuesday-password-feature</link>
                                                                            <description>
                            <![CDATA[ Security fixes include a zero day exploited by a ransomware group and seven critical flaws ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">92PXHhi4fpg7Cv4b8VNdFn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Apr 2023 11:51:19 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Apr 2023 09:40:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Windows]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:description>                                                            <media:text><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:text>
                                <media:title type="plain"><![CDATA[Windows logo appearing on a smartphone set against a bright Windows logo taking up the entire background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ecqqzhaeTJbyTBMiTyGzNe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft’s April 2023 Patch Tuesday delivered not just the usual score of security fixes for Windows admins, but also a new feature that has attracted criticism from the IT community.</p><p>The Windows 11 22H2 KB5025239 cumulative update, among other fixes and features, delivers the new Windows Local Administrator Password Solution (LAPS) to IT teams managing both on-prem and cloud environments.</p><p>Microsoft LAPS manages and backs up local admin account passwords on Azure Active Directory-joined devices. </p><p>It’s seen as one of the most secure ways to ensure unauthorized users aren’t able to access things they’re not supposed to.</p><p>The new LAPS is available for Windows 10&11 Pro, EDU, and Enterprise versions, as well as Windows Server 2022, Windows Server Core 2022, and Windows Server 2019.</p><p>LAPS for Azure AD is not yet available. It’s now bundled into Microsoft Entra - the name given to Microsoft’s identity and access products that can be managed through a single portal.</p><p>The Azure AD version of LAPS is expected to go from private to public preview “later this quarter,” said Jay Simmons, development lead at Microsoft, and will deliver new features such as password encryption, password histories, an emulation mode, and automatic rotation.</p><p>“Windows LAPS is a huge improvement in virtually every area beyond Legacy LAPS,” he added.</p><p>Online IT admin communities have not greeted the news as warmly as expected.</p><p>The main issue among these communities relates to concerns over how to migrate. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="stxf8shwiEd3uXTVtmCZAD" name="Leaked today, exploited for life_thumb.png" caption="" alt="Red whitepaper cover with title" src="https://cdn.mos.cms.futurecdn.net/stxf8shwiEd3uXTVtmCZAD.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Leaked today, exploited for life</strong></p><p class="fancy-box__body-text">How social media biometric patterns affect your future</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/370153/leaked-today-expolited-for-life"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The new LAPS feature has been released but Microsoft has not supplied the community with any documentation detailing how to complete the migration.</p><p>Some professionals have already encountered issues where the new LAPS has stopped working due to nuances in the migration process. </p><p>The prevailing advice is to stop deploying the legacy LAPS MSI immediately after the April Patch Tuesday update is applied. </p><p>Failure to do so reportedly breaks the new LAPS and prevents legacy LAPS from updating passwords.</p><p>“You need to update documentation and guidance very soon,” one user told Simmons in an <a href="https://www.reddit.com/r/sysadmin/comments/12itqb9/windows_laps_available_today/"><u>online discussion</u></a>.</p><p>“I hate spending my day discovering something that is about to hit 100,000 of our machines doesn&apos;t have guidance, and we have to action something,” they added.</p><p>“If migration docs aren’t available yet, [why] was this released,” another asked. “This tells me that documentation, upgrades, and coexistence, were not given any priority - which is bloody shocking but given how Microsoft pushes stuff out the last few years, I suppose it really shouldn’t be any more.”</p><p>Simmons responded to users by saying that he “should have been better prepared” to allay the global community’s concerns.</p><p>“New Windows LAPS has been designed to be an almost entirely opt-in feature, using a separate brand new GPO policy and separate brand new AD schema attributes, which – at least to my Microsofty-mind – mostly mitigates the risk of applying the patches to existing environments,” he said.</p><p>“But regardless yes we should have preemptively called this out in the post so as to not scare folks.”</p><p>Error-strewn Patch Tuesday releases are becoming something of a commonality from Microsoft, with the monthly updates often presenting major issues for IT teams.</p><p>Most recently in last month’s March Patch Tuesday updates, IT admins complained about a <a href="https://www.itpro.com/security/370264/windows-admins-plagued-issues-outlook-zero-day-patch"><u>variety of problems after installing patches for an Outlook zero day</u></a>.</p><p>Windows 10 users were hit with the infamous <a href="https://www.itpro.com/operating-systems/microsoft-windows/369757/windows-10-blue-screen-of-death-patch-tuesday-updates"><u>blue screen of death after installing December’s updates</u></a>, and around a year earlier <a href="https://www.itpro.com/server-storage/microsoft-windows-server/362009/windows-server-admins-agree-to-forgo-broken-patches"><u>IT admins were forced to ignore the security fixes for a month</u></a> as a result of the rampant issues reported by the community.</p><h2 id="april-2023-patch-tuesday-summary">April 2023 Patch Tuesday Summary</h2><p>Microsoft’s April 2023 Patch Tuesday brought fixes for 97 total security vulnerabilities including seven critical-rated flaws and one zero day that’s been actively exploited by a <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> group.</p><p>Tracked as CVE-2023-28252, the privilege escalation vulnerability in Windows Common Log File System (CLFS) Driver grants SYSTEM-level privileges if successfully exploited.</p><p>Kaspersky identified exploit attempts dating back to February 2023 that it said were very similar to other types of exploits it had been tracking. </p><p>The team investigated and discovered that it was a zero day affecting different versions of Windows, including <a href="https://www.itpro.com/software/operating-systems/368298/windows-10-vs-windows-11-which-is-best-for-business"><u>Windows 11</u></a>.</p><p>The Nokoyama group is described as “sophisticated” and used a newer version of its ransomware payload, which has historically been a rebranded version of JSWorm. Now <a href="https://www.itpro.com/development/programming-languages/369499/move-away-from-memory-unsafe-languages-c"><u>written in C</u></a> with encrypted strings.</p><p>In previous attacks, Nokoyama has also deployed the Cobalt Strike penetration testing tool to evade antivirus products, and a custom modular backdoor called Pipemagic in other attacks.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KEWTygV2eNQU2nkeskB3sn" name="Trend Micro security predictions for 2023_thumb.png" caption="" alt="Whitepaper cover with shattered image of female using a VR headset" src="https://cdn.mos.cms.futurecdn.net/KEWTygV2eNQU2nkeskB3sn.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Security predictions for 2023</strong></p><p class="fancy-box__body-text"><em>Prioritise cyber security strategies on capabilities rather than costs</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/ransomware/370157/trend-micro-security-predictions-for-2023"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Kaspersky said it believes “CVE-2023-28252 could have been easily discovered with the help of fuzzing” - a technique that sees automated injections of invalid or unexpected inputs into a target system to reveal security vulnerabilities.</p><p>It said that the clfs.sys driver extensively uses try/catch blocks to handle exceptions, so code continues to execute as if no errors were thrown. </p><p>Kaspersky’s <a href="https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/"><u>analysis</u></a> showed that a possible access violation that follows after the vulnerability is triggered was masked by one of these exception handlers, and because there was no crash, fuzzers were most likely ‘finding’ the vulnerability but not reporting it as a potential issue.</p><h2 id="april-2023-patch-tuesday-breakdown">April 2023 Patch Tuesday breakdown</h2><p>This month’s 97 security fixes slightly exceeded March’s total of 83, with the overall count not including the 17 <a href="https://www.itpro.com/web-browsers/24526/what-is-microsoft-edge"><u>Microsoft Edge</u></a> issues patched on 6 April.</p><p>All seven of the critical-severity vulnerabilities were remote code execution (RCE) flaws.</p><p>The two most serious of which, CVE-2023-21554 and CVE-2023-28250, affecting Microsoft Message Queuing and Windows Pragmatic General Multicast (PGM) respectively, both scored a near-maximum 9.8/10 on the CVSS v3 severity scale.</p><p>Four RCEs were also found in <a href="https://www.itpro.co.uk/desktop-software/19337/office-365-review"><u>Microsoft Office</u></a>, Microsoft Word, and Microsoft Publisher, and were exploitable by opening malicious documents.</p><p>All four were categorized under “exploitation less likely” by Microsoft. This classification is designated to vulnerabilities for which attackers would either have difficulty writing the code, require expertise and/or sophisticated timing, or would experience varied results when testing the vulnerable target.</p><p>These flaws are also not recently exploited in the wild but given the potential impact of successful abuse, the vulnerability warrants an update regardless.</p><p>The full breakdown of the vulnerabilities’ types can be found below:</p><ul><li>45 remote code execution</li><li>20 elevation of privilege</li><li>10 information disclosure</li><li>9 denial of service</li><li>7 security feature bypass</li><li>6 spoofing</li></ul><p>Microsoft&apos;s full dashboard of the month’s updates can be found on <a href="https://msrc.microsoft.com/update-guide/vulnerability"><u>its website</u></a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bitwarden to release fix for four-year-old vulnerability ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/370288/bitwarden-to-release-fix-for-four-year-old-vulnerability</link>
                                                                            <description>
                            <![CDATA[ The password manager knew about the issue since 2018, exploits for which were highlighted in a Flashpoint report earlier in March ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b3HG1wgHNkZCvfnqd6Zc66</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Mar 2023 12:14:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Shutterstock]]></media:description>                                                            <media:text><![CDATA[A person on a laptop to depict hacking]]></media:text>
                                <media:title type="plain"><![CDATA[A person on a laptop to depict hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wDQfXhNPUxQ6TfnH5UYHo3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bitwarden has confirmed it will soon be releasing a fix for a security vulnerability the company has known about for four years.</p><p>Researchers from Flashpoint identified earlier this month that the password manager’s autofill feature contained a flaw that could allow websites to steal users' passwords.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/370223/four-year-old-iframe-flaw-hackers-steal-bitwarden-passwords" data-original-url="/security/cyber-attacks/370223/four-year-old-iframe-flaw-hackers-steal-bitwarden-passwords">Four-year-old iframe flaw allows hackers to steal Bitwarden passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance" data-original-url="/security/information-security-infosec/370210/lastpass-breach-last-chance">Does LastPass really deserve a last chance?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368656/should-you-take-your-password-manager-off-the-internet" data-original-url="/security/cyber-security/368656/should-you-take-your-password-manager-off-the-internet">Should you take your password manager off the internet?</a></p></div></div><p>Bitwarden confirmed today that the fix is expected to be pushed to users next week.</p><p>The <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" target="_blank" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">password manager</a> will only fill in iframes from trusted domains if a user enables autofill on page load. These trusted domains include the same domain as a website or a URL the user has designated as safe.</p><p>Bitwarden said that autofill on page load remains 'off' by default. If a user fills in an untrusted iframe when using manual autofill, the password manager will flag an alert into the URI or URL to let the user decide whether to cancel or proceed with the operation.</p><p>“This eliminates the iframe <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management">attack vector</a> while still allowing convenient autofill functionality for sites that have trusted iframes,” a spokesperson from Bitwarden told <em>IT Pro</em>.</p><p><em>IT Pro</em> has asked the company why it decided to release the fix now even though it has <a href="https://www.itpro.com/security/cyber-attacks/370223/four-year-old-iframe-flaw-hackers-steal-bitwarden-passwords" data-original-url="https://www.itpro.com/security/cyber-attacks/370223/four-year-old-iframe-flaw-hackers-steal-bitwarden-passwords">known about the issue since 2018</a>.</p><p>“I highly appreciate that the vendor decided to address this security issue," said Sven Krewitt, senior vulnerability researcher at Flashpoint. "The steps in the provided description of the fix should address the external iframe handling as the user is now in control of which iframes are filled by the extension (as opposed to filling all iframes by default). </p><p>"Please note that while the behavior of the 'URI match detection' setting is documented, the default setting still leaves an attack vector for environments where users can host content under certain sub-domains," said Krewitt. "We still recommend setting the 'Default URI match detection' to at least check the 'Host'.”</p><p>In their original research, Flashpoint researchers found that the password manager was handling iframes embedded on a web page in an atypical manner.</p><p>Bitwarden would auto-fill forms in an embedded iframe even if they were from different <a href="https://www.itpro.com/network-internet/web-hosting/368160/why-domain-privacy-is-important-and-what-it-means-for-your" target="_blank" data-original-url="https://www.itpro.com/network-internet/web-hosting/368160/why-domain-privacy-is-important-and-what-it-means-for-your">domains</a>.</p><p>By combining the autofill behaviour with URI matching, which is when the browser extension knows when to auto-fill logins, the researchers said that could lead to two different attack methods.</p><p>The first is if an attacker embeds an external iframe into an uncompromised website and enables the ‘Auto-fill on page load option’. The other is if an attacker hosts a web page under a subdomain.</p><p>In either case, the default implementation of Bitwarden could then auto-fill malicious web elements with credentials, presenting a security risk.</p><p>In their original report, Flashpoint researchers said that the <a href="https://www.itpro.com/security/cyber-security/368656/should-you-take-your-password-manager-off-the-internet" data-original-url="https://www.itpro.com/security/cyber-security/368656/should-you-take-your-password-manager-off-the-internet">password</a> manager was planning to exclude the reported hosting environment from its auto-fill function, but wasn’t going to change how iframes work.</p><p>The researchers added that only one attack vector had been addressed through this fix, instead of the main cause of the issue.</p><p>“It should also be noted that a brief evaluation of other password manager extensions shows that none of those will auto-fill iframes from different origins or show warnings for iframes from different origins. This currently appears to be unique to Bitwarden’s product,” they added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GoTo admits hackers stole customer backups in LastPass breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369934/goto-admits-hackers-stole-customer-backups-in-lastpass-breach</link>
                                                                            <description>
                            <![CDATA[ In addition to losing encrypted backups such as hashed passwords, the firm has confirmed hackers stole an encryption key relating to the data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fFEhvD47SGgL8xAw9eMrwX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Jan 2023 12:51:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:description>                                                            <media:text><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Communications firm GoTo has revealed that threat actors stole encrypted customer backups and sensitive product information in a November 2022 attack, which also affected subsidiary LastPass.</p><p>The firm has stated that account usernames, salted and hashed passwords, and multi-factor authentication (MFA) settings were included in the stolen information which was taken from a third-party cloud storage service in the November incident. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LTMrgEvSNMdUH7gB9RYH7b" name="LTMrgEvSNMdUH7gB9RYH7b.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" mos="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Automate security intelligence with IBM Security QRadar SIEM</strong></p><p class="fancy-box__body-text">Simplify and improve threat detection, investigation and response with reducing overheads</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem" data-original-url="/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem">FREE DOWNLOAD</a></p></div></div><p>Although this customer backup data is encrypted, the company believes that the threat actor behind the attack also stole an encryption key for a portion of the stolen backups.</p><p>GoTo stated that the key related to a “portion” of the data, but did not elaborate on which files are vulnerable to decryption by the threat actor.</p><p>As GoTo does not store payment details, nor collect or store user addresses, dates of birth, or other such identifiable information, data of this kind was not included in the breach.</p><p>The company has also warned that backups relating to other services it runs were stolen, such as its <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private network (VPN)</a> product Hamachi and <a href="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions" data-original-url="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions">remote access applications</a> Central and Pro.</p><p>GoTo subsidiary LastPass had commenced an investigation in collaboration with Mandiant following <a href="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach" data-original-url="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach">a breach in November 2022</a> that saw threat actors access a third-party cloud storage system used by both LastPass and GoTo.</p><p>“At this time, we have no evidence of exfiltration affecting any other GoTo products other than those referenced above or any of GoTo’s production systems," said Paddy Srinivasan, CEO at GoTo, in a <a href="https://www.goto.com/blog/our-response-to-a-recent-security-incident" data-original-url="https://www.goto.com/blog/our-response-to-a-recent-security-incident#">blog post</a>.</p><p>"We are contacting affected customers directly to provide additional information and recommend actionable steps for them to take to further secure their account."</p><p>GoTo has stated it will provide advice for next steps for making affected accounts secure. Customers who were impacted by the breach will have passwords reset as a precautionary measure, and MFA settings reauthorised.</p><p>The firm has also committed to migrating accounts to an <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy" data-original-url="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity management</a> platform, to further secure accounts against possible future action.</p><p>This is the third attack impacting GoTo and its subsidiaries in the past 12 months. In August 2022 a <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">hacker exfiltrated LastPass source code</a>, though Karim Toubba, CEO at the firm, denied that customer information had been impacted in this breach. </p><p>Since then, the <a href="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely" data-original-url="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely">LastPass admitted encrypted password vaults were stolen</a>, and that names, email addresses, phone numbers and payment information. This has prompted concerns that stolen data could be used for mass <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage" data-original-url="/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage">Mailchimp data breach impact unravels as second customer reveals extent of damage</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach" data-original-url="/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach">T-Mobile customers at heightened risk of phishing attacks in wake of data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></p></div></div><p>“Any breach is unfortunate for all those impacted,” said Javvad Malik, lead security awareness advocate at KnowBe4.</p><p>“While in this case the data was encrypted, the fact that the decryption keys were also stolen renders the encryption worthless. Therefore, impacted customers should treat this as a complete breach of all data and take the necessary steps to protect themselves from any fallout. </p><p>“This can include changing their passwords and being on the lookout for any phishing or social engineering scams which can be crafted using the stolen data.”</p><p><em>IT Pro</em> has approached GoTo for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass customer password vaults stolen, targeted phishing attacks likely ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely</link>
                                                                            <description>
                            <![CDATA[ The latest fallout from the password manager's August security nightmare will probably see attackers deploying sophisticated methods to acquire decryption information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gjNDCnz6ooKnhY344FHAVH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Dec 2022 10:41:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:description>                                                            <media:text><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:text>
                                <media:title type="plain"><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>LastPass customers have been warned to remain vigilant to a wave of phishing attacks after it was revealed that cyber criminals stole customers’ encrypted password vaults during a breach earlier this year. </p><p>In a blog post, the password manager said that hackers extracted a copy of backup customer vault data following the <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">August attack</a> by using cloud storage keys stolen from a LastPass employee. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach" data-original-url="/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach">LastPass admits 'elements' of customer data accessed in breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">LastPass breach: CEO says 'no evidence' of customer data being stolen</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/368008/lastpass-vs-1password" data-original-url="/software/368008/lastpass-vs-1password">LastPass vs 1Password</a></p></div></div><p><a href="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach" data-original-url="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach%5D">LastPass</a> revealed that this repository of customer passwords is stored in a “binary format” and contains both unencrypted data, such as website URLs, as well as encrypted data including website usernames and passwords, secure notes, and form-filled data. </p><p>The company said that cyber criminals also stole a significant volume of customer data, including names, email addresses, phone numbers, and some billing information. </p><p>"Once the cloud storage access key and dual storage container decryption keys were obtained, the threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service,” the firm said in a <a href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident">statement</a>. </p><p>CEO <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">Karim Toubba</a> insisted that only customers have the ability to decrypt protected passwords. </p><p>“These encrypted fields remain secured with 256-bit <a href="https://www.itpro.com/security/29671/what-is-aes-encryption" data-original-url="https://www.itpro.com/security/29671/what-is-aes-encryption">AES encryption</a> and can only be decrypted with a unique encryption key derived from each user’s master <a href="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by" data-original-url="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by">password</a>,” he said. </p><p>Toubba also sought to quell ongoing fears that financial payment data was stolen in the attack. </p><p>“There is no evidence that any unencrypted credit card data was accessed,” he said in a statement. “LastPass does not store complete credit card numbers and credit card information is not archived in this could storage environment” </p><h2 id="phishing-fears">Phishing fears </h2><p>This latest update from LastPass has raised serious concerns that stolen information could be leveraged by threat actors to target users en masse. </p><p>LastPass warned that hackers may attempt to use brute force attacks to guess master passwords, but noted that due to hashing and encryption methods employed by the service, it would be “extremely difficult”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="s7hnF2HF5HjCJogZeSiun4" name="s7hnF2HF5HjCJogZeSiun4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" mos="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Understanding the economics of in-cloud data protection</strong></p><p class="fancy-box__body-text">Data protection solutions designed with cost optimisation in mind</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection" data-original-url="/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection">FREE DOWNLOAD</a></p></div></div><p>A key concern highlighted by both LastPass and security experts, however, is the potential for users to be targeted by sophisticated <a href="https://www.itpro.com/security/phishing/369482/rising-tide-of-no-hook-phishing" data-original-url="https://www.itpro.com/security/phishing/369482/rising-tide-of-no-hook-phishing">phishing</a> campaigns in the wake of this news. </p><p>John Scott-Railton, senior security researcher at the University of Toronto's Citizen Lab, warned that the threat actor(s) behind the breach is “clearly well-resourced, capable, and strategic”. </p><p>“Latest LastPass breach may be worse than you think,” he said in a Twitter thread. “Attacker didn't just get encrypted passwords. They got unencrypted URLs.” </p><p>“I’m especially worried about high-value users and entities. Serious national security implications that probably need mitigating.” </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1606195077939744768"></a></p></blockquote><div class="see-more__filter"></div></div><p>Scott-Railton cited a separate thread on the incident which warned that although <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted data</a> was stolen in this incident, the websites that customers visited were not, meaning that users "should expect to get phishing emails” in the coming days and months. </p><p>It is believed that hackers will likely use this breach as a means to target users and encourage them to change passwords and click on malicious links. </p><p>“Be VERY careful about password reset alerts in these next few months,” the advice read. </p><p>LastPass issued a similar warning for users, noting that it expects customers to be targeted by phishing attacks, <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">credential stuffing, and other brute force attacks</a> “against online accounts associated with your LastPass vault”. </p><p>“In order to protect yourself against <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> or phishing attacks, it is important to know that LastPass will never call, email, or text you and ask you to click on a link to verify your personal information,” the company said. </p><h2 id="domino-effect">Domino effect </h2><p>The <a href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">LastPass</a> revelations appear to have sparked a domino effect among users of similar <a href="https://www.itpro.com/software/368030/5-things-to-consider-before-buying-a-password-manager" data-original-url="https://www.itpro.com/software/368030/5-things-to-consider-before-buying-a-password-manager">password management services</a>. Some took to social media to ponder the potential exposure of rival password managers, that also use cloud storage, to similar attacks.</p><p>Responding to concerns relating to its own product on social media, <a href="https://www.itpro.com/software/368008/lastpass-vs-1password" data-original-url="https://www.itpro.com/software/368008/lastpass-vs-1password">1Password</a> confirmed that “all 1Password vault data is end-to-end encrypted” on user devices, distancing itself from the idea that it could also suffer a similar attack.</p><p>The firm added that “this means that even if our servers were breached, all the attackers would have is encrypted gibberish that is useless and unreadable”. </p><p>“An attacker would need both your 1Password account password and secret key to decrypt the data within it,” the company said. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass admits 'elements' of customer data accessed in breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach</link>
                                                                            <description>
                            <![CDATA[ The password manager denies the exfiltration of any password data in an attack that also hit affiliate GoTo ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s5VbBwKbC6km6Jk5epf2qH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Dec 2022 12:23:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:description>                                                            <media:text><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:text>
                                <media:title type="plain"><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password manager firm LastPass has revealed that it was subject to another security breach in which a threat actor accessed a system used by the firm, as well as some customer information.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEepSJfbVh7mxRAUSTFsXo" name="dEepSJfbVh7mxRAUSTFsXo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" mos="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 IBM's Security X-Force cloud threat landscape report</strong></p><p class="fancy-box__body-text">Recommendations for preparing and responding to cloud breaches</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report" data-original-url="/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report">FREE DOWNLOAD</a></p></div></div><p>LastPass said that unusual activity was detected on a third-party cloud storage platform used by LastPass. Following the launch of an investigation involving cyber security firm Mandiant, it was established that a threat actor accessed some customer information.</p><p>There is no evidence to suggest that customer passwords were affected or obtained in the attack, and LastPass states that all passwords remain securely <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a>.</p><p>The incident follows a similar attack in August in which a <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">hacker stole LastPass source code</a>. In that case, the hacker made use of a compromised developer account to breach the company’s development environment and then stole source code and technical information. At the time, the firm denied that any customer data or password vaults were stolen.</p><p>In the statement announcing the recent incident, LastPass CEO Karim Toubba linked the two attacks by suggesting that it was information stolen in the August incident that enabled this new attack.</p><p>“We have determined that an unauthorised party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” said Toubba in a <a href="https://blog.lastpass.com/2022/11/notice-of-recent-security-incident">blog post</a>. “Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture.</p><p>“We are working diligently to understand the scope of the incident and identify what specific information has been accessed. In the meantime, we can confirm that LastPass products and services remain fully functional.”</p><p>LastPass affiliate GoTo (formerly LogMeIn) was also affected in the attack; the two companies share the same third-party cloud storage service. </p><p>In a <a href="https://www.goto.com/blog/our-response-to-a-recent-security-incident">blog post</a> covering the incident, GoTo CEO Paddy Srinivasan said that the company “detected unusual activity within our development environment and third-party cloud storage service”.</p><p>The company stated that all its products and services remain operational and that it is deploying further security measures and monitoring to prevent further activity from threat actors.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">LastPass breach: CEO says 'no evidence' of customer data being stolen</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="/software/368077/best-password-managers-in-2022">Best password managers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></p></div></div><p>GoTo has not offered further information on the specific activity performed within its development environment, and unlike LastPass made no mention of customer information being affected.</p><p>"Third-party cloud storage certainly poses risks for organisations," said Javvad Malik, lead security awareness advocate at KnowBe4, to <em>IT Pro.</em> "This will vary depending on the nature of data that is stored or processed on the third-party cloud.</p><p>"Data can sometimes be considered similar to chemical elements. On their own, maybe a certain element is stable and benign. But mix it with other stable elements under the right conditions and you could end up with something volatile. </p><p>"Similarly, we cannot completely dismiss any data breach as completely benign. There is always something that can be taken which could be combined with other data elements, or saved for future use. So while the risk may be low, we cannot say there is no risk at all. In all of this though, it is important to commend LastPass for their exemplary transparency in their incident response."</p><p><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">Password managers</a> are a popular solution for storing logins securely, and can be extremely beneficial for business use especially in roles burdened with a large number of critical passwords.</p><p>In addition to safely storing passwords, such managers also generate cryptographically secure passwords that are far more difficult for hackers to guess than the <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">more commonly used ones</a>.</p><p>LastPass has urged customers to follow its recommended security practices and is working with GoTo, Mandiant, and law enforcement services to investigate the issue.</p><p><em>IT Pro</em> has approached GoTo for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Revealed: The top 200 most common passwords of 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022</link>
                                                                            <description>
                            <![CDATA[ While the most common passwords worldwide are largely the same, gender and region did have an effect on frequency ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dLk6ZWjqWnfuPacRknr8AW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Nov 2022 10:58:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:description>                                                            <media:text><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sequential strings of numbers and ‘password’ remain the most popular password choices for users around the world despite their insecurity.</p><p>Annual research into the top 200 most popular passwords has been published by NordPass also revealed that in the UK, names of football teams also ranked highly among the most-used passwords of the year.</p><p>For example, ‘liverpool’ was the fourth most popular password of the year, while ‘arsenal’, ‘chelsea’, and ‘liverpool1’ were all in the top 15.</p><p>Regional results from the likes of France revealed similarly insecure password practices, but the actual passwords themselves differed. For example, 'azerty' was the third most popular password in the country - the equivalent of 'qwert' on a French keyboard layout.</p><p>NordPass also included datasets sorted by user gender, revealing some notable differences in password frequency. In the US, the most used password by users identifying as women was ‘guest’ versus the old favourite of ‘12345’ among users identifying as men.</p><p>Both genders in the UK used ‘password’ and ‘123456’ as their top choices, but stark differences were visible in the remainder of the top five results: ‘charlie’, ‘tigger’, and ‘sunshine’ versus ‘mosh2021’, ‘12345’, and ‘liverpool’ were the results for women and men respectively.</p><p>Data from all 30 countries, however, revealed general uniformity in passwords, with only the inclusion of ‘bigbasket’ as the seventh most-used password by women worldwide standing out as an anomaly.</p><p>The most secure password to make <a href="https://nordpass.com/most-common-passwords-list">the top 200 list</a> was ‘9136668099’, which NordPass estimates would take hackers around four days to crack. However, beyond this figure, it is still far from a secure password, as it contains no letters or special characters whatsoever.</p><p>Regularly updating one’s password is good security practice, and experts recommend straying away from using easy-to-guess words or phrases, or anything that a threat actor could link to you with no trouble.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/368049/best-password-managers-for-business" data-original-url="/software/368049/best-password-managers-for-business">Best password managers for business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369442/cisco-announces-duo-passwordless-authentication-for-single-sign-on-sso-apps" data-original-url="/security/369442/cisco-announces-duo-passwordless-authentication-for-single-sign-on-sso-apps">Cisco announces Duo Passwordless Authentication for Single Sign On (SSO) apps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a></p></div></div><p>There are a range of <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password-cracking techniques used by hackers</a> but brute force attacks, in which hackers guess a victim’s password using various forms of trial and error, are common. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sr7PL6RyX4xfWCPshjfCie" name="sr7PL6RyX4xfWCPshjfCie.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" mos="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a better password strategy for your business</strong></p><p class="fancy-box__body-text">Exploring the strategies and exploits that hackers are using to circumvent password security measures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business" data-original-url="/security/369393/building-a-better-password-strategy-for-your-business">FREE DOWNLOAD</a></p></div></div><p>Hackers can use powerful hardware such as <a href="https://www.itpro.com/hardware/components/369322/nvidias-rtx-4090-is-a-powerful-password-cracking-tool" data-original-url="https://www.itpro.com/hardware/components/369322/nvidias-rtx-4090-is-a-powerful-password-cracking-tool">GPUs for password-cracking</a>, which can cut down the time required to unearth credentials, but the simplest brute force attacks simply involve trying common passwords until access is granted - reason enough for users to stray away from using anything that resembles a password in the top 200.</p><p>Employees should not be using shared passwords across multiple logins, particularly for accounts pertaining to sensitive business data, to prevent data breaches. Businesses are often urged to use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> in addition to a strong password policy, to ensure that unwanted individuals have overcome that extra hurdle in order to access sensitive accounts.</p><p>It can be difficult to remember a series of strong, unique passwords - some businesses have said <a href="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember" data-original-url="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember">forgettable passwords are the best</a> - and for this reason many businesses opt to use <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">password managers</a>.</p><p>These can be used to create distinct passwords for all of a user’s accounts, and store them all behind a master password (used to access the password manager itself).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Building a better password strategy for your business ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business</link>
                                                                            <description>
                            <![CDATA[ Exploring the strategies and exploits that hackers are using to circumvent password security measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3piE71qspDFm4nqadnEK9R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Oct 2022 08:39:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT security leaders and hackers are consistently head-to-head in trying to ensure, and circumvent, password security. Security professionals know that weak credentials are a key aspect of cyber attacks, so it’s vital to have a layered defence strategy to not only protect your business, but also your channel partners.</p><p>This whitepaper discusses the current state of today’s password security, shares things to consider and avoid in developing your organisation’s password strategy, and looks at the latest tools and techniques coming to an ever evolving cyber security landscape.</p><p>Download now to learn:</p><ul><li>The biggest threats affecting password security</li><li>Best practices for ensuring strong credentials</li><li>and How password management tools can support security improvements</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4bnNgGoetdNzyX3NB4mHg" name="" alt="Enzoic logo" src="https://cdn.mos.cms.futurecdn.net/4bnNgGoetdNzyX3NB4mHg.jpg" mos="https://cdn.mos.cms.futurecdn.net/4bnNgGoetdNzyX3NB4mHg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49856/enzoic?locale=1&p=false&wp=10450"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Inside the password arms race ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369102/inside-the-password-arms-race</link>
                                                                            <description>
                            <![CDATA[ To keep your partner’s business protected, you always need to stay one step ahead ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o4skqTuPvSUsivnsugAHSj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Sep 2022 14:06:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract visualisation of padlock icon]]></media:description>                                                            <media:text><![CDATA[Abstract visualisation of padlock icon]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract visualisation of padlock icon]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXPUCybF5xfZTNWiRCeNu9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Since researchers first devised the notion of a username and password combination in the 1960s, the security world has been in constant battle with the exponential growth of the hacking landscape. These two ideas have been in a permanent struggle – akin to an ever-escalating arms race – in which each side endeavors to outmuscle the other.</p><p>Strong passwords are fundamental keystones of protection for every organization, although they work best when complemented with additional layers on top, such as multi-factor authentication (MFA). Relying too much on any individual layer, however, won’t do, as only hardening each of these layers respectively will stand organizations in good stead against the threats they face. Hackers, after all, have devised ingenious techniques to breach any layer; from brute-force password cracking to ‘pass-the-cookie’ attacks.</p><p>This ever escalating arms race is why hardening the password layer, using tools such as Enzoic Active Directory (AD), is a crucial step in safeguarding critical business assets. Such solutions offer simple methods to prevent the re-use of weak and stolen credentials - the top cause of hacking related breaches.</p><h3 class="article-body__section" id="section-the-password-arms-race"><span>The password arms race</span></h3><p>To illustrate just how touch-and-go the cyber security arms race is, we need only look at the first use of passwords in the 1960s, where the CTSS computing research project was also the victim of the first password hack. </p><p>Cyber security has changed an awful lot since then, as has the advice around best practice and how best to construct strong passwords. Passwords, after all, are only a viable layer when they can’t be easily guessed or otherwise hacked. Advice around constructing suitable passwords has evolved in the last few years, with the National Institute of Standards and Technology (NIST) recently offering guidelines that argue against several practices that were previously recommended.</p><p>No longer requiring different characters or scheduling regular resets, for example, are changes against what many considered best practice for years. Research shows it’s ineffective and likely to make passwords less secure because users are more likely to make easy to guess iterations (e.g. P@ssword1, P@ssword2, etc.) and reuse weak passwords across multiple accounts. NIST recommends that organizations prevent this by screening passwords against those found in past data breaches. NIST, finally, recommends limiting the number of failed password attempts, as well as salting (adding a random string of characters to a password) and hashing (converting the user-devised string to a unique string of characters) passwords to prevent them from being cracked.</p><p>Hackers have nevertheless devised an arsenal of <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password-cracking techniques</a> that these new NIST recommendations can help control. Also among the most widely used is <a href="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/botnets/33799/goldbrute-botnet-targeting-windows-rdp-systems-in-brute-force-hacking-spree">brute-force attacks</a>, which describe several methods that involve guessing passwords to access a system. This method relies on the fact that many people recycle passwords between accounts, and that so many also use extremely common and insecure strings without much thought. </p><p>Other methods are harder to prevent. Social engineering, for example, is a highly targeted and effective means by which cyber criminals gain access to employee credentials, often through digital or real-life manipulation. The use of phishing, in which fake landing pages for login portals or even fake password reset forms are sent to unsuspecting victims, is also highly prevalent. </p><h3 class="article-body__section" id="section-multi-factor-protection"><span>Multi-factor protection</span></h3><p>To help counter these methods, the industry devised a second layer of security known as 2FA, which can be any one of several additional factors including a physical key fob, a code sent through a text message, or a unique code generated through an app. While 2FA has been around for decades, it isn’t until recently its usage has become more prominent, becoming part of a sophisticated multi-layered approach to complement an existing, hardened password layer.</p><p>As in keeping with the history of information security, however, cyber criminals have even devised increasingly ingenious ways of bypassing MFA. In September 2020, for example, hackers exploited critical vulnerabilities in MFA protocols based on the WS-Trust security standard to infiltrate several cloud-based services <a href="https://www.itpro.com/cloud/cloud-security/357111/mfa-bypass-allows-hackers-to-infiltrate-microsoft-365" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-security/357111/mfa-bypass-allows-hackers-to-infiltrate-microsoft-365">including Microsoft 365</a>.</p><p>The following year, a similar incident saw <a href="https://www.itpro.com/security/two-factor-authentication-2fa/358323/cyber-criminals-bypassing-mfa-to-access-cloud-service" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/security/two-factor-authentication-2fa/358323/cyber-criminals-bypassing-mfa-to-access-cloud-service">brute-force login attempts and a 'pass-the-cookie' attack</a> against cloud services. In such an attack, a hacker can use browser cookies to defeat MFA by hijacking an authenticated session using stolen cookies to access web apps or online services with MFA enabled. More recently, in January 2022, <em>Crypto.com</em> confirmed hackers stole $34 million in cryptocurrency after exploiting its 2FA security layer. The details of the compromise weren’t clear, although it forced <em>Crypto.com</em> to migrate to an entirely new 2FA infrastructure, suggesting the previous architecture was vulnerable.</p><h3 class="article-body__section" id="section-hardening-your-layers"><span>Hardening your layers</span></h3><p>To safeguard your partner organization to the highest possible degree, it’s vital to invest in a multi-layered strategy. Hardening the password layer is an essential step in building your defense strategy, and there are several ways to go about doing so.</p><p>The first key step is to create strong passwords based on modern recommendations by the likes of NIST and others. They advise implementing policies that allow all characters to be used, eliminating arbitrary complexity rules (i.e. special characters), not requiring password resets, increasing the character allowance, and routinely screening passwords against blacklists of all common, easy-to-guess and previously compromised passwords.Further to this, requiring mandatory MFA is a crucial step on top of a hardened password layer, given hackers have been able to find ways to breach each layer in isolation.</p><p>Scanning the network for password files, too, allows MSPs to identify where all accessible files containing key credentials might be kept, so these documents can be locked away from potential intruders. </p><p>Using a password auditing tool, such as Enzoic for Active Directory Lite, is a great way to evaluate the organization and determine the scope of its problem with unsafe passwords. The free tool scans your partner organization’s Active Directory environment in order to identify common and weak passwords, breached and exposed passwords, and those that have been reused.</p><p>This tool isn’t to be confused with Enzoic for Active Directory, however, which expands on mere detection and offers a continuous solution to keep unsafe passwords away from your partner organization’s information systems. Enzoic enforces a policy that prevents unsafe passwords from being created and detects and automates remediation when good passwords become compromised.</p><p>Capable of being installed in 15 minutes or less, the solution also offers a completeness that competitors lack and aims to reduce the complexity of hardening the password layer. One-click NIST password compliance screening as well as capabilities to set password policies and produce summary reports for admins, combined with a continuously updating database, sets Enzoic for Active Directory apart. Organizations from manufacturing to financial service, and even public sector administrations such as the City of Keizer, Oregon have used Enzoic’s solutions to sharpen their password policies and make their systems more robust.</p><p>Although security has moved on since the 1960s, cyber criminals have always been engaged in systematically breaking down the defensive barriers organizations erect to safeguard their assets. In today’s age, one layer isn’t enough. Only a sophisticated approach which combines MFA with a hardened password layer can keep the cyber intruders out.</p><p><a href="https://www.enzoic.com/active-directory/?utm_source=ChannelPro&utm_medium=Art&utm_campaign=ChPart" rel="nofollow" target="_blank"><strong><em>Learn more about how Enzoic can help harden your password layer as part of a layered authentication strategy</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass breach: CEO says 'no evidence' of customer data being stolen ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen</link>
                                                                            <description>
                            <![CDATA[ The company said the incident was confined to a single developer account and its associated environment ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mSBbqchcpVTxv2G1HdexEa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Aug 2022 10:12:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:description>                                                            <media:text><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:text>
                                <media:title type="plain"><![CDATA[The LastPass logo on a smartphone lying next to some bluetooth earphones]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/axSjZH7JHa7tzngVkrjz3D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password manager LastPass has revealed that a hacker was able to breach its development environment and steal some of its source code.</p><p>LastPass allows users to save passwords to multiple sites through its platform, and provides a browser extension to try and make it easier to enter websites without having to remember different passwords. To access the service, users only need to remember their master password.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/633265/lastpass-passwords-compromised-by-hack" data-original-url="/633265/lastpass-passwords-compromised-by-hack">LastPass passwords compromised by hack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/34424/lastpass-fixes-password-leaking-flaw" data-original-url="/security/34424/lastpass-fixes-password-leaking-flaw">LastPass fixes password-leaking flaw</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/25878/lastpass-phishing-hack-could-trick-users-into-giving-away-their-password" data-original-url="/security/25878/lastpass-phishing-hack-could-trick-users-into-giving-away-their-password">LastPass phishing hack could trick users into giving away their password</a></p></div></div><p>The company detected some unusual activity within portions of the <a href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" target="_blank" data-original-url="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">LastPass</a> development environment two weeks ago, said Karim Toubba, CEO of LastPass, in a blog post on Thursday. He added that the company hasn’t seen any evidence that the incident involved any access to customer data or encrypted vaults.</p><p>The unauthorised party gained access to the development environment through a single compromised <a href="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide" target="_blank" data-original-url="https://www.itpro.com/software/development/356827/how-to-become-a-developer-a-beginners-guide">developer</a> account and took portions of the source code and some proprietary technical information. The company’s products and services are operating normally, Toubba underlined.</p><p>In response to the incident, LastPass has deployed containment and mitigation measures and engaged a leading <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> forensics firm. It’s also evaluating further mitigation techniques to strengthen its environment.</p><p>“While our investigation is ongoing, we have achieved a state of containment, implemented additional enhanced security measures, and see no further evidence of unauthorised activity,” said Toubba.</p><p>The company clarified that users’ master password hasn’t been compromised and also doesn’t recommend any action on behalf of users or administrators for now.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1562864726840725504"></a></p></blockquote><div class="see-more__filter"></div></div><p>This isn’t the first time the company has been a victim of a hack. In 2011, the company told <a href="https://www.itpro.com/633265/lastpass-passwords-compromised-by-hack" target="_blank" data-original-url="https://www.itpro.com/633265/lastpass-passwords-compromised-by-hack">customers to change their passwords</a> due to a possible security breach. It reported that it had experienced a network traffic anomaly from a non-critical machine, and concluded that this could have been an attack.</p><p>The team admitted that it didn’t have a lot of evidence which signalled an explicit problem, but said “where there’s smoke there could be fire”.</p><p>In 2019, the company <a href="https://www.itpro.com/security/34424/lastpass-fixes-password-leaking-flaw" target="_blank" data-original-url="https://www.itpro.com/security/34424/lastpass-fixes-password-leaking-flaw">patched a vulnerability</a> which could have led to users exposing the password they previously used on the last site they visited. The flaw made the password manager susceptible to cyber criminals launching clickjacking attacks. It affected the company’s web extension when used on Google Chrome or Opera and was discovered by Google’s Project Zero team.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why convenience is the biggest threat to your security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368690/why-convenience-is-the-biggest-threat-to-your-security</link>
                                                                            <description>
                            <![CDATA[ The shortcuts and human error that lead to breaches - and how to guard against them ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vvyGKLS5AvacSdPQ7eJCY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Aug 2022 12:29:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man holding smart phone with data security on display at office]]></media:description>                                                            <media:text><![CDATA[Man holding smart phone with data security on display at office]]></media:text>
                                <media:title type="plain"><![CDATA[Man holding smart phone with data security on display at office]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RAY34UxMVj7EGX4oe3GWVF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security is an ongoing battle with which all IT decision makers are intimately acquainted. In this security arms race, more advanced and sophisticated tools are constantly needed to meet increasingly insidious attacks.</p><p>But no matter how clever the technologies you employ to defend your endpoints and root out malware, there is one vulnerability that particularly vexes businesses: human error. <a href="https://www.egress.com/blog/what-is-human-layer-security/2021-insider-breach-survey" rel="nofollow" target="_blank">Egress’s Insider Data Breach Survey 2021</a> found that 84% of IT leaders who had experienced a data breach named human error as the top cause of those breaches. Our natural tendency to take shortcuts for the sake of convenience and to neglect arduous best practice can allow bad actors to get around the best defences.</p><p>Fortunately, there are tools and techniques to educate and support your employees in making choices that best protect your business.</p><h3 class="article-body__section" id="section-the-risks-of-convenience"><span>The risks of convenience</span></h3><p>Human error strikes all across the business, and even IT and security professionals are not immune. </p><p>It may be convenient to neglect crossing the i’s and dotting the t’s when it comes to tedious security duties – especially with a growing pile of tickets that need responding to – but this can lead to serious consequences.</p><p>Ensuring that patches are up to date and systems and hardware are configured properly may not be the most glamorous of tasks – and might be easy to put off until later – but failure to do so can have serious consequences. The WannaCry ransomware attack in May 2017 affected hundreds of thousands of targets, leading to serious financial and operational damage across the globe. But Microsoft had released a patch to address this vulnerability three months prior to the attack, which just goes to show how many organisations let these simple but tedious tasks slip – and the dire consequences that can result.</p><p>When disasters do occur, backups are essential for disaster recovery – if they are properly configured and tested. However, the <a href="https://www.veeam.com/news/cxo-research-58-percent-of-data-backups-are-failing-creating-data-protection-challenges-and-limiting-digital-transformation-initiatives.html" rel="nofollow" target="_blank">Veeam Data Protection Report 2021</a> found that 58% of backups fail, leaving data unprotected. Again, this is an area where taking shortcuts can have serious consequences in the long run.</p><p>Outside of the IT department, cutting corners can lead to breaches at any level of the business. While passwords remain the primary method of controlling access to our systems and protecting them against bad actors, maintaining proper password hygiene can be seen as an inconvenience.</p><p>Unfortunately, this leads to corner-cutting behaviour like password reuse that makes it much easier for cyber criminals to compromise login credentials, allowing them to access critical systems and potentially cause serious harm to your organisation. It’s difficult to remember multiple long, complicated passwords, but using ‘12345’ or ‘p@ssw0rd’ for every login is an invitation for criminals to compromise these credentials and breach your network. Further, even a complex password can be risky if it’s used across multiple services.</p><p>Verizon’s <a href="https://www.verizon.com/business/resources/reports/dbir" rel="nofollow" target="_blank">2022 Data Breach Investigations Report</a> named stolen credentials as the primary route of access into organisational systems, accounting for almost 50% of breaches. It’s clear that employees need help with password security to ensure that your business isn’t left vulnerable for the sake of convenience.</p><h3 class="article-body__section" id="section-lightening-the-load"><span>Lightening the load</span></h3><p>The key to preventing risky, shortcut-taking behaviour is to support your workers so that good practice is not seen as inconvenient, and that arduous tasks and workloads are lightened as much as possible.</p><p>For IT teams, this means ensuring that workloads are managed properly so that IT personnel have the time to attend to patching, backups and other security-critical duties. Best practice guides and better approaches to time management will help staff members avoid getting swamped by requests and build a schedule that includes regular maintenance and monitoring.</p><p>This can be bolstered by automation and remote access solutions like Keeper Connection Manager. With the right tools, some vital duties can be automated to reduce IT department workloads while ensuring that essential maintenance takes place. For the things that can’t be automated, Keeper Connection Manager offers a secure, reliable and frictionless way to access and oversee key systems and hardware from anywhere, minimising the inconvenience and roadblocks that contribute to risky shortcuts.</p><p>Likewise, security awareness training and the right password management tools combine to greatly reduce the incidence of credentials being compromised. Understanding what makes a password secure is, naturally, key to ensuring that employees are making the right decisions when creating and updating login credentials – and a dependable password management system can take your protection to a whole new level.</p><p>Just as convenience can lead us astray, password managers help employees to make the right choices. Password managers enable users to generate random, unique and secure passwords based on customisable criteria and save them to a secure digital vault, eliminating the risks associated with weak passwords or password reuse. Services like Keeper Password Manager integrate across platforms and devices, meaning that users only need to remember one password, the master password that unlocks their Keeper vault.</p><p>Keeper Password Manager also allows IT teams to monitor and control employee password practices and require users to adhere to best practices, such as using unique, complex passwords for every account and using multi-factor authentication wherever it is supported. Keeper provides tools for role-based access control (RBAC) and least-privilege access, so if threat actors do manage to use a set of compromised credentials to breach your systems, they’ll be unable to move laterally within your network.</p><p>For extra protection, organisations can add Keeper BreachWatch, which monitors the dark web and alerts administrators if any company passwords are compromised in a public data breach. This way, administrators can force password resets as soon as possible.</p><p>Convenience will always tempt employees into making bad choices that compromise security. Your role is to ensure that they understand the consequences of these decisions and are armed with the tools and knowledge they need to make smart choices that will protect your business. When convenience and good practice align, your company will be in the best position possible.</p><p><a href="https://www.keepersecurity.com/en_GB/password-manager-enterprise.html?utm_source=ITPro&utm_medium=FeatureArticle&utm_id=Convenience+Biggest+Threat" rel="nofollow" target="_blank"><strong><em>Try Keeper for free today</em></strong></a> <strong><em>or </em></strong><a href="https://www.keeper.io/meetings/bcain2?utm_source=ITPro&utm_medium=FeatureArticle&utm_id=Convenience+Biggest+Threat" rel="nofollow" target="_blank"><strong><em>book a personalised demo</em></strong></a> <strong><em>to learn more about the best way to protect your organisation from cyber attacks</em></strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to incorporate password protection into your wider security strategy  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368689/how-to-incorporate-password-protection-into-your-wider-security</link>
                                                                            <description>
                            <![CDATA[ A comprehensive security strategy needs to incorporate password protection ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qBqPz4XZtxLi7cdb82evH8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dWCKJQ2eYKS8RCq9C2uio5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Aug 2022 13:29:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dWCKJQ2eYKS8RCq9C2uio5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of padlocks in hexagons]]></media:description>                                                            <media:text><![CDATA[Graphic of padlocks in hexagons]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of padlocks in hexagons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dWCKJQ2eYKS8RCq9C2uio5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The spectre of security breaches continues to plague businesses well into this year, with the latest edition of the government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022" rel="nofollow" target="_blank"><em>Cyber Security Breaches Survey</em></a> serving as a stark reminder of the threat both enterprises and small- and medium-sized businesses (SMBs) face. Of the organisations reporting cyber attacks, 31% estimate they were attacked on average once a week, while one in five reported a negative outcome as a direct consequence of a cyber attack.</p><p>In today’s climate, it’s more important than ever for SMBs and larger enterprises to solidify a comprehensive and broad cyber security strategy. This spans hardening the network infrastructure against infiltration to implementing firewalls and securing endpoint devices. One aspect of a business’s security strategy that’s frequently taken for granted, however, is password security. Password security is a common pain point because it might seem relatively straightforward to get right. As a result, it’s easy to overlook.</p><h3 class="article-body__section" id="section-plugging-the-gaps"><span>Plugging the gaps </span></h3><p>Indeed, according to Verizon’s latest <a href="https://www.verizon.com/business/resources/reports/dbir" rel="nofollow" target="_blank">data breach report</a>, 81% of hacking-related breaches exploited stolen and/or weak employee passwords. Password hygiene is a major issue across society – not just in the business world – with some of the most common passwords last year including ‘123456’ and ‘password’, which are used by millions of people. This reality is, sadly, also reflected across SMBs and enterprises, with Verizon’s research finding that 70% of employees reuse passwords at work, even though 91% know reusing passwords is poor practice. To make matters worse, 59% reuse passwords everywhere – in their personal and professional lives.</p><p>It’s important that organisations prioritise protecting login credentials across the breadth of their business, while layering this into the overall cyber security strategy alongside other practices like employee training and routine backups. This might not be as easy as it sounds, especially for SMBs that are particularly stretched on monetary and human resources. However, a number of inexpensive, low-maintenance tools exist to help businesses get on top of password security, including those offered by Keeper Security.</p><h3 class="article-body__section" id="section-building-your-cyber-security-layers"><span>Building your cyber security layers</span></h3><p>In modern data environments, comprehensive cybersecurity requires multiple layers of defence that work together. These layers would naturally include elements like cyber security training, as well as investing in protecting your endpoint devices. The starting point for defence-in-depth security is to implement a clearly defined access policy that determines which employees have access to what systems and data, as well as how passwords are created and stored.</p><p>First and foremost, your business must identify its weakest points in order to understand where there might be shortcomings. To achieve this, a business must assess who has access to what data and software, establish whether they need to have access to the elements of the business they do, and limit access if need be. This includes not just full-time employees but also remote workers, contractors, part-time staff and anybody who interacts with the systems that power your business. As a rule, the more people who have access to software or data, the broader your attack surface will be. There will be, unfortunately, more opportunities for a data breach, given that <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity">most threats originate from within</a>.</p><p>Businesses at this stage must create concrete policies around password management. This is a key step in building a multi-layered cyber security strategy. To that end, tools such as those provided by Keeper Security are key to implementing a zero-trust and zero-knowledge approach. In addition to password management and security, this approach requires secrets management, privileged access management (PAM), remote infrastructure security and encrypted messaging. In practice, this translates into using a unique encryption and data segregation framework to protect against remote data breaches.</p><p>The zero-trust security model is centred around the principles of assuming a breach, verifying explicitly and ensuring least-privilege access. An affordable and easy-to-use enterprise password manager (EPM) allows organisations to implement zero-trust network access while slashing administrative overhead. This improves reliability and performance while boosting employee productivity. Administrators will get access to the tools they need to enforce robust password security, verify users and devices and manage role-based access controls alongside least-privilege access and other policies like multi-factor authentication (MFA).</p><h3 class="article-body__section" id="section-security-for-businesses-of-all-sizes"><span>Security for businesses of all sizes</span></h3><p>Beyond EPM, Keeper Security offers a variety of products aimed at different-sized organisations, including Keeper Business and Keeper Enterprise, both of which apply least-privilege and zero-trust principles to password management. These foundational ideas form the basis of an essential identity access management (IAM) strategy.</p><p>Keeper Business provides businesses with complete visibility into employee password practices while giving them the tools to enforce company policies, monitor compliance and generate audit trails and reports. Keeper Enterprise, meanwhile, adds SSO support, SAML 2.0 authentication, automated team management, advanced MFA, alongside a host of advanced capabilities for larger businesses with hundreds of employees.</p><p>Keeper’s products, for which free trials and one-to-one demos are available, serve as a means to block some of the most common pathways to a data breach. You’ll be able to protect your organisation against a variety of threats, including those emanating from the dark web, while securely sharing passwords and applying information security best practice across your organisation’s data environment, regardless of its size or complexity.</p><p>Password protection is fundamental to creating a robust and holistic security strategy to keep your organisation safe from data breaches, ransomware and other password-related cyber attacks.</p><p><a href="https://www.keepersecurity.com/en_GB/password-manager-enterprise.html?utm_source=ITPro&utm_medium=FeatureArticle&utm_id=Password+Protection+Wider+Strategy" rel="nofollow" target="_blank"><strong><em>Try Keeper for free today</em></strong></a> <strong><em>or </em></strong><a href="https://www.keeper.io/meetings/bcain2?utm_source=ITPro&utm_medium=FeatureArticle&utm_id=Password+Protection+Wider+Strategy" rel="nofollow" target="_blank"><strong><em>book a personalised demo</em></strong></a> <strong><em>to learn more about the best way to protect your organisation from cyberattacks</em></strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Should you take your password manager off the internet?  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368656/should-you-take-your-password-manager-off-the-internet</link>
                                                                            <description>
                            <![CDATA[ How keeping data offline in a closed loop on a self-service model can help shore up all your apps and services ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8LtGmvjeRc2QRjUhAjbzQX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LsbcnA8EK3f4pqmSJHcVNf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Jul 2022 08:03:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LsbcnA8EK3f4pqmSJHcVNf-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A padlock sitting on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A padlock sitting on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A padlock sitting on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LsbcnA8EK3f4pqmSJHcVNf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In an ideal world, all your online applications and services would be secured with one unbreakable password that you would never forget. Unfortunately, this is nigh on impossible and it’s why password managers, such as Passwork, have become so popular.</p><p>A password manager is a type of software that allows users to generate and store passwords in easily accessible ways, such as on their devices or via a cloud application. At its most basic, a password manager can be used to create unique passwords that are harder for would-be attackers to crack. And because they are stored in accessible systems, they’re more convenient to users when logging on to their online services, sparing users from having to remember ones they create themselves.</p><p>The average person has anywhere between 30 and 100 passwords for all the services they access online and it's likely that many of those are for work. And as creatures of convenience, we often reuse passwords or create ones that are weak and easily compromised. What’s more, even if you managed to create unique passwords for all your applications, it's highly unlikely you’d manage to be able to pull every single one of them out of your brain at any given moment. Both the creation and retrieval of a password can be essentially automated with a password manager.</p><p>However, there are three different types of password managers. ‘On-device managers’ allow users to store data on a single machine, such as a laptop or smartphone. Cloud-based password managers store on a remote server so that it can be accessed via an internet connection and ‘self-hosted’ password managers work similarly while allowing users to store them on their own servers. </p><p>Here we look at cloud and self-hosted versions of password manager and explore the reasons a business might benefit from the latter.</p><h3 class="article-body__section" id="section-cloud-vs-self-hosted-password-managers"><span>Cloud vs self-hosted password managers</span></h3><p>Password managers allow businesses to sync their passwords across multiple devices and they are usually managed centrally by a designated administrator. This also means that the organisation can monitor, change and save all passwords used across the company. The administrator can also recover passwords, add and remove people from shared password groups, as well as assess the quality of passwords being used throughout the organisation. </p><p>There are two ways businesses can run password managers, either via a third party (cloud) or they can host it themselves on their own server. A self-hosted password manager limits the transit of data as passwords are only transferred around the organisation. Nothing is being sent to or from an off-location server. So, effectively the data can be cut off from the internet in a closed loop, and the businesses can reduce the risk to one password – the one you need to access the password manager itself.</p><p>To run a self-hosted password manager, a business will need an existing network and infrastructure, or the capacity to purchase it, as well as dedicated members of staff with the technical knowledge and resources to maintain it. This will come with the benefit of having greater control over the data the business holds and tighter security. Plus, it isn’t necessarily dependent on an internet connection, like a cloud-based password manager is. </p><p>Hybrid work models perhaps present one of the best use cases for a cloud-based password manager, as a distributed workforce can access their data from anywhere at any time. There is also an argument for those that work in the field, who may have to visit clients and need access to various online applications. And, for IT teams, a cloud-based system can allow them to access multiple services on every laptop within their company, wherever it resides.</p><p>However, this constant availability presents opportunities for phishing and other types of hacks that can compromise passwords and other more sensitive company data. Self-hosted password managers can allow the same level of remote access as cloud-based services at the business’s discretion, with the additional option of taking things offline if greater security is required.</p><h3 class="article-body__section" id="section-the-case-for-self-hosted-password-managers"><span>The case for self-hosted password managers</span></h3><p>When it comes to security, self-hosted password managers are a great option for businesses that have extreme privacy or compliance concerns, such as healthcare or financial organisations, or even governments where mass volumes of mission-critical or public data is processed.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EyL7oLngq7DXnT8bjd6qVZ" name="" alt="A screenshot of Passwork's password manager" src="https://cdn.mos.cms.futurecdn.net/EyL7oLngq7DXnT8bjd6qVZ.png" mos="https://cdn.mos.cms.futurecdn.net/EyL7oLngq7DXnT8bjd6qVZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Unlike most password managers, Passwork provides a self-hosted service that allows organisations to take full responsibility for their data and completely take it offline, for that extra bit of security. As a service solely aimed at businesses, Passwork is a class apart with its focus on user management, organisation and integration. </p><p>The platform also comes with a range of features to help teams collaborate. For instance, it has a search bar where colleagues can find and invite each other to use certain integrated services, or co-workers can also be tagged and brought into other vaults and folders. And, all passwords are stored in a structured way.</p><p>Passwords represent one of our most important, but vulnerable security assets. Services like Passwork that can take password management offline offer businesses an enhanced level of protection and control that is essential for keeping them secure.</p><p><a href="http://passwork.pro/?utm_source=itpro&utm_medium=article&utm_campaign=review" rel="nofollow" target="_blank"><strong><em>Learn more about Passwork’s self-hosted password manager</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The psychology of secure passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368438/the-psychology-of-secure-passwords</link>
                                                                            <description>
                            <![CDATA[ The tricks for overcoming poor security hygiene like weak passwords and password reuse ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wSzCPqW5iisPy12vbVrToS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jul 2022 11:49:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Encryption]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:description>                                                            <media:text><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:text>
                                <media:title type="plain"><![CDATA[Wooden head silhouette mounted on planks with cogs inside it. A magnifying glass shows details of the cogs.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HNidZTvZznte3bL5tD3wGA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords, in recent months, have been the source of much contention in cyber security, with the viability of conventional authentication methods under fire. Although a string of companies are bidding to remove passwords from the information security scene altogether, the reality is they’re still widely prevalent and likely to remain so. Most people lean on passwords to log into anything from personal email accounts to business-critical apps and services, so keeping them secure remains a paramount concern.</p><p>The threat of hackers cracking weak passwords, meanwhile, has only escalated in recent years. Not only has the spotlight been shone onto poor cyber security hygiene practices like password reuse, but a string of historic data breaches mean many credentials are in circulation around the web. Although it’s difficult to avoid a cyber security horror story in today’s age, the unfortunate truth is the majority of people are prone to reverting to easy solutions when devising passwords. Astoundingly, for example, the <a href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" rel="nofollow" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">most common password of 2021</a> was ‘123456’, which was used by more than 100 million individuals.</p><p>Insecure passwords have long been an issue, with cyber security expert Troy Hunt <a href="https://www.troyhunt.com/science-of-password-selection" rel="nofollow" target="_blank">expressing alarm in 2011</a> that passwords generally tend to follow a similar trend. They’re relatively short (between six and ten characters), simple (less than 1% had a non-alphanumeric character) and predictable (more than a third were in a common password dictionary). In the 11 years since, how much has actually changed? Not an awful lot, it seems, and businesses can’t risk their employees using short, simple and common passwords to access critical business systems. That’s where a password management tool, like Synology C2 Password, comes in to help us safeguard data with stronger access protections and password generation.</p><h3 class="article-body__section" id="section-guess-my-password"><span>Guess my password</span></h3><p>The state of password hygiene across society is poor – thanks, in a large part, to the way our brains work and the limitations of our memory. Beyond ‘123456’, the most common passwords in the top five are ‘password’, ‘1234578’, ‘qwerty’ and ‘123456789’, <a href="https://wpengine.com/resources/passwords-unmasked-infographic" rel="nofollow" target="_blank">according to WPengine</a>. Examining the top 50 most-used passwords suggests number sequences are incredibly common. Whole words such as ‘dragon’, ‘football’, ‘monkey’ and ‘master’ are also leant on heavily.</p><p>It confirms what many of us may have assumed; that people often instinctively choose passwords that might be easier to recall off the top of their head, rather than methodically choosing strong and complex passwords. There’s also the issue of password reuse. With so many passwords to remember, many people tend to just use the same one, or handful, across several user accounts. As a result, hackers wouldn’t need to employ sophisticated brute-force cracking tools often warned about to break into user accounts; they can simply reach for a handful of short and simple go-to words or number sequences.</p><p>Another trick many people lean on to complexify a weak password is to tack a number onto the end of it. Of the ten million passwords WPengine analysed, 8.4% ended with a number between 0 and 99; with people perhaps thinking it was easier to remember than using a more complicated letter and number combination. Of those, more than 20% of people used ‘1’ suggesting convenience is the key priority.</p><p>When choosing whole words as passwords, many people rather predictably tend to pick words from categories such as colours, animals, or fruits, in addition to first names, superheroes or even days of the week. This, of course, makes the job that much simpler for cyber criminals hoping to break into user accounts that aren’t protected with a password management tool. Poor password hygiene, indeed, does most of the heavy lifting. </p><h3 class="article-body__section" id="section-a-modern-remedy-to-age-old-problems"><span>A modern remedy to age-old problems</span></h3><p>How do we, collectively, move past the limits of our password-creating psychology? There are various methods to overcome poor password hygiene, including the National Cyber Security Centre (NCSC) recommendation to use three random words. Although the ‘three random word’ strategy is suited for use at both home and work, it might not be so simple for users to remember a few dozen different three-word combinations for the various apps, services and user accounts they’ll log in and out of on a daily basis.</p><p>Password reuse is, by far, the greatest risk with this strategy. Whild sensible on paper, most people will likely default to a handful of combinations and rotate as they see fit. Meanwhile, although two-factor authentication (2FA) might provide another barrier for cyber criminals, this isn’t entirely infallible and not all organisations offer such protective measures on every internal system.</p><p>Password managers are, by far, the most effective and simplest protective measure anyone can take when safeguarding their account credentials. The Synology C2 Password platform, in particular, is a shining example of a robust and free password management tool fitted with a litany of capabilities that collectively serve as a modern remedy to age-old problems associated with passwords.</p><p>Synology C2 Password allows users to store their passwords in a bank alongside other sensitive material like banking information, addresses and passport details, while keeping everything organised using categories, favourites and tags. The platform is also accessible across a multitude of devices, so you can add an item on your primary work machine and access it from your tablet, for example. Saved credentials, too, are also automatically filled in at login screens. </p><p>The most important feature, however, is the password generation tool. Synology C2 Password automatically generates and securely stores passwords for your essential apps and services, so you don’t have to generate and remember a complex and uncrackable password for each one you access. The use of AES-256 encryption to safeguard all data also ensures the password data cannot be remotely accessed or intercepted; items are encrypted before they leave your device to be stored on C2 servers. The decryption key, moreover, is stored on your devices and never shared with Synology C2 servers.</p><p>Poor password hygiene is a growing spectre in the security world, with the most common habits people lean on when devising passwords a huge factor. However, using a free password management tool like Synology C2 Password could be the most effective way to counter the shortcomings of human psychology, and completely wipe out the prevalence of bad habits like using number sequences or common words when setting passwords, or reusing passwords across multiple accounts.</p><p><a href="https://c2.synology.com/en-us/password/overview" rel="nofollow" target="_blank"><strong><em>Learn more about Synology C2 Password</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google merges Chrome and Android password managers after community feedback ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368410/google-merges-chrome-and-android-password-managers-after-community-feedback</link>
                                                                            <description>
                            <![CDATA[ The tech giant is also giving users the ability to generate passwords for iOS apps when Chrome is set as the autofill provider ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">di5L2qGQd6JGmFuYuxjLk1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Jul 2022 11:27:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png">
                                                            <media:credit><![CDATA[Google]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:description>                                                            <media:text><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image of three devices with open padlocks on their screens connected to a series of asterisks representing a password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2avCogaCVrzjp8oj7rnZRR-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google is merging its Chrome and Android password manager to make it more consistent, as part of a number of new updates that aim to make the feature generally easier to use and more secure.</p><p>The tech giant is rolling out a simplified and unified management experience that’s the same in Chrome and Android settings, after receiving feedback that managing passwords between the two has been confusing at times. </p><p>“We're always grateful for feedback, and many of you have shared that managing passwords between Chrome and Android has been confusing at times: "It's the same info in both places, so why does it look so different?” wrote Ali Sarraf, product manager in Chrome.</p><p>Google will also automatically group passwords if a user <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">has multiple ones for the same sites</a> or apps. They will also be able to create a shortcut on their Android home screen to make it easier to access their passwords.</p><p>The company is also giving users the ability to generate passwords for iOS apps when they set Chrome as their autofill provider.</p><p>Chrome can automatically check passwords when users enter them into a site, but now it’s hoping to provide them with extra confidence by checking them in bulk with Password Checkup.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords" data-original-url="/network-internet/web-browser/358385/google-chrome-makes-it-easier-to-fix-weak-passwords">Google Chrome makes it easier to fix weak passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/32928/google-launches-password-checkup-and-cross-account-protection" data-original-url="/security/32928/google-launches-password-checkup-and-cross-account-protection">Google launches Password Checkup and Cross Account Protection</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/359666/google-now-allows-you-to-password-protect-your-activity" data-original-url="/policy-legislation/data-protection/359666/google-now-allows-you-to-password-protect-your-activity">Google now allows you to password-protect your activity page</a></p></div></div><p>It will now be able to flag not only <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">compromised passwords</a>, but also weak and re-used passwords on Android. Users will be able to use the automated password change feature on Android to fix any passwords that Google warns them about. Additionally, the company is expanding its compromised password warning to all Chrome users on Android, Chrome OS, iOS, Windows, MacOS and Linux.</p><p>Lastly, Google is also allowing users to add their passwords directly to its app, and is bringing this functionality to Google Password Manager on all platforms. The tech giant will also bring Touch-to-Login to Chrome on Android to speed up logging in by allowing users to securely log into sites directly from the overlay at the bottom of the screen.</p><p>Google hasn’t explicitly said when the updates will be rolled out, but said they will be introduced over the next few months.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NordPass teams up with insurance provider Cowbell Cyber to improve security awareness ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/362304/nordpass-teams-with-cyber-insurance-provider-cowbell-cyber</link>
                                                                            <description>
                            <![CDATA[ Policy holders will be eligible for a 15% discount on NordPass Business ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8AEdLgkQqkuBECUZcjzFBo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FBAz686afN3nNwWvoPfQBj-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Feb 2022 11:29:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Big Data]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/FBAz686afN3nNwWvoPfQBj-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person holding a tablet with the NordPass app displayed]]></media:description>                                                            <media:text><![CDATA[A person holding a tablet with the NordPass app displayed]]></media:text>
                                <media:title type="plain"><![CDATA[A person holding a tablet with the NordPass app displayed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FBAz686afN3nNwWvoPfQBj-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password manager NordPass has inked a new deal with cyber insurance provider Cowbell Cyber, which will provide its policy holders with discounted cyber security tools.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361099/cyber-security-and-insurance-companies-evolving-with-the-threat-of-ransomware" data-original-url="/security/cyber-security/361099/cyber-security-and-insurance-companies-evolving-with-the-threat-of-ransomware">How are cyber security and insurance companies evolving with the threat of ransomware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361039/amazon-to-offer-cyber-insurance-to-uk-smbs" data-original-url="/security/cyber-security/361039/amazon-to-offer-cyber-insurance-to-uk-smbs">Amazon to offer cyber insurance to UK SMBs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361137/only-a-third-of-businesses-have-ransomware-insurance" data-original-url="/security/ransomware/361137/only-a-third-of-businesses-have-ransomware-insurance">Only a third of businesses have taken out insurance against ransomware attacks</a></p></div></div><p>Cowbell Cyber, which provides custom-designed policies based on risk profiles, operates a <a href="https://www.itpro.com/disaster-recovery-dr/33803/tips-to-improve-your-disaster-recovery-strategy" data-original-url="https://www.itpro.com/disaster-recovery-dr/33803/tips-to-improve-your-disaster-recovery-strategy">continuous risk assessment</a> platform that alerts policyholders to security vulnerabilities, improving risk posture and preventing potential incidents.</p><p><a href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" data-original-url="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">NordPass</a> will now be incorporated into Cowbell Rx, Cowbell's referral platform for cyber security solutions and risk management, as part of the deal. Policy holders will also be offered a 15% discount on NordPass Business.</p><p>“With ever-increasing cybercrime, we highly encourage all of our customers to think about cyber insurance. Implementing and using a password manager, having <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">Multi-Factor Authentication (MFA)</a> in place, or having an import detection response tool - all of these things reduce your risk, and that ultimately may increase your chances of <a href="https://www.itpro.com/security/cyber-security/360131/cyber-insurance-premiums-increased-by-a-third-in-the-last-12-months" data-original-url="https://www.itpro.com/security/cyber-security/360131/cyber-insurance-premiums-increased-by-a-third-in-the-last-12-months">securing a cyber-insurance policy</a>,” commented ​​Gerald Kasulis, head of business and channel operations at NordPass.</p><p>NordPass has also announced an upcoming free webinar on cyber insurance and ways to assess cyber hygiene. Participants will be able to hear about the biggest concerns they have regarding cyber-risks, as well as how they can improve their cyber security.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D3vMu3mdChC5wPGRmKXEDQ" name="D3vMu3mdChC5wPGRmKXEDQ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/D3vMu3mdChC5wPGRmKXEDQ.png" mos="https://cdn.mos.cms.futurecdn.net/D3vMu3mdChC5wPGRmKXEDQ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Putting the insurance industry back in safe hands</strong></p><p class="fancy-box__body-text">The role of payments in digital transformation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/digital-transformation/362198/putting-the-insurance-industry-back-in-safe-hands" data-original-url="/business-strategy/digital-transformation/362198/putting-the-insurance-industry-back-in-safe-hands">FREE DOWNLOAD</a></p></div></div><p>The webinar is being led by Arch Insurance Group’s VP and cyber risk product leader Shiraz Saeed, AmTrust Financial Services’ VP and head of cyber claims Andrew Lipton, and Cowbell Cyber’s head of claims and risk engineering Theresa Le.</p><p>“Together with our partners NordPass, Cowbell brings streamlined access to top cybersecurity solutions to current and future policyholders to maximize their ability to be secure,” said Theresa Le.</p><p>“We connect directly with trusted partners to improve the cyber risk profile of our policyholders.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCA donates 225 million passwords to Have I Been Pwned ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361882/nca-donates-225m-passwords-haveibeenpwned</link>
                                                                            <description>
                            <![CDATA[ The move comes as both UK and US national crime-fighting agencies collaborate with the popular compromised credential checker ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3jdTneonDxG8XvCUBFV7SL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jqAJydWdmhm6ozXfzkwDAT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Dec 2021 10:08:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jqAJydWdmhm6ozXfzkwDAT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password is seen in a maginfying glass written in green text while surrounded by binary code written in blue text]]></media:description>                                                            <media:text><![CDATA[Password is seen in a maginfying glass written in green text while surrounded by binary code written in blue text]]></media:text>
                                <media:title type="plain"><![CDATA[Password is seen in a maginfying glass written in green text while surrounded by binary code written in blue text]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jqAJydWdmhm6ozXfzkwDAT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>National crime authorities in the UK and US have committed to providing <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">compromised passwords</a> they find during the course of their crime-fighting everyday work to Have I Been Pwned (HIBP), a popular website to check compromised login credentials.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/361386/arrests-made-in-uk-as-nca-helps-dismantle-dark-web-crime-gang" data-original-url="/security/cyber-crime/361386/arrests-made-in-uk-as-nca-helps-dismantle-dark-web-crime-gang">NCA arrests 24 Brits over ties to global dark web criminal network</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers" data-original-url="/security/information-security-infosec/361806/skip-three-words-use-password-managers">Skip the three words thing, go straight for the ‘use a password manager, dammit’ jugular</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" data-original-url="/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">Top 200 most common passwords of 2021 revealed</a></p></div></div><p>The UK's <a href="https://www.itpro.com/security/cyber-crime/361386/arrests-made-in-uk-as-nca-helps-dismantle-dark-web-crime-gang" data-original-url="https://www.itpro.com/security/cyber-crime/361386/arrests-made-in-uk-as-nca-helps-dismantle-dark-web-crime-gang">National Crime Agency</a> (NCA) donated more than 225 million passwords it had stored after detecting them through the course of their normal work, growing HIBP's bank of hacked passwords by more than a third.</p><p>Prior to the NCA's donation, HIBP stored 613 million <a href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" data-original-url="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">compromised passwords</a> in its database. The NCA offered up a bank of passwords more than 585 million-strong and after parsing out the duplicates, Troy Hunt, owner of the website, found a little more than 225 million passwords that weren't currently in his database.</p><p>Speaking to Hunt, the NCA said the donated <a href="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers" data-original-url="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers">passwords</a> were found in a UK business' cloud storage facility and were an accumulation of datasets both known and unknown. It meant the compromised credentials were now in the public domain but couldn't be attributed to any company or platform which is why the agency engaged HIBP.</p><p>Hunt also announced the FBI will now be collaborating with HIBP with an injection pipeline into the site. The FBI has been helping HIBP build an open source tool that allows law enforcement and crime-fighting agencies like the FBI and NCA to feed compromised credentials directly into the HIBP website via an injection pipeline.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M2WpDQRjBJ3Hd2qkprKffM" name="M2WpDQRjBJ3Hd2qkprKffM.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" mos="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Busting the myths about SSO</strong></p><p class="fancy-box__body-text">Why SSO capability is critical to the success of IAM</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/single-sign-on-sso/361519/busting-the-myths-about-sso" data-original-url="/security/single-sign-on-sso/361519/busting-the-myths-about-sso">FREE DOWNLOAD</a></p></div></div><p>Hunt transitioned the site into a .NET framework earlier this year which allowed him to build the pipeline, a tool that hopes to make it easier for law enforcement to donate more passwords in the future. </p><p>"Today's release is about turning on the firehose of new passwords and making them immediately available to everyone for free," said Hunt, <a href="https://www.troyhunt.com/open-source-pwned-passwords-with-fbi-feed-and-225m-new-nca-passwords-is-now-live">announcing the news</a> on his blog. "Having this open to the community, owned by the community and supported by the FBI and NCA is an enormously pleasing result, and I couldn't be happier than to end the year on this note"</p><p>HIBP is a website that allows users to query its database with their email addresses and passwords to check if their credentials have been included in data breaches. When checking email addresses, the website will inform users of what company's data breach in which their email address was compromised.</p><p>Its password checker also tells users how many times their password has been seen after being included in a data breach and provide guidance on how to change passwords and manage new ones.</p><p>A growing bank of data allows HIBP to be more useful to consumers and businesses, and makes stolen credentials less useful in the hands of criminals.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top 200 most common passwords of 2021 revealed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed</link>
                                                                            <description>
                            <![CDATA[ Unsurprisingly, the vast majority take less than a second to crack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e9VKkzBYwe92SJqhmemwRJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jBo5VEVAV35pLtDmGMHedS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Dec 2021 11:38:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jBo5VEVAV35pLtDmGMHedS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A render of a black computer screen whit random white characters indicating a bank of passwords, with the word password highlighted in green text]]></media:description>                                                            <media:text><![CDATA[A render of a black computer screen whit random white characters indicating a bank of passwords, with the word password highlighted in green text]]></media:text>
                                <media:title type="plain"><![CDATA[A render of a black computer screen whit random white characters indicating a bank of passwords, with the word password highlighted in green text]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jBo5VEVAV35pLtDmGMHedS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The 200 most common passwords used across the world in 2021 have been revealed with '123456' coming out on top, used by more than 100 million individuals.</p><p>The team at NordPass evaluated a 4TB password database compiled by independent cyber security researchers investigating various incidents throughout the year across 50 countries.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="/security/cyber-security/361037/what-makes-a-password-secure">What makes a password secure?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords" data-original-url="/security/361695/over-90-of-it-decision-makers-reuse-passwords">More than 90% of IT decision makers reuse passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by" data-original-url="/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by">Robust password policies cut cyber attacks by 60%</a></p></div></div><p>Years of campaigning for stronger password policies from the cyber security industry seems to have fallen on deaf ears yet again as only two of the global top ten contained characters other than sequential numbers. Although the two outliers were not much better, with 'qwerty' sitting at the fourth spot, just ahead of 'password' at fifth.</p><p>With the <a href="https://nordpass.com/most-common-passwords-list/?utm_source=campaign&utm_medium=email&utm_campaign=Brand">top 200 passwords</a> also ranked by how quickly they could be <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">cracked</a> by computers, the two most secure passwords in the list, sitting at places 54 and 123 respectively, were 'myspace1' and 'michelle' - each taking 3 hours to crack.</p><p>Most of the list would take less than a second to crack, according to NordPass, with honourable mentions going to 'zag12wsx' and 'jennifer' being the only other two to break the one-hour mark, taking one and two hours to crack, respectively.</p><p>In the UK, the top 10 passwords used by both men and women were a mix of sequential numbers, riffs on the old classic 'password', football teams, and actual first names.</p><p>It would appear Liverpool FC is the most popular team in the world, or the one whose fans are most relaxed about <a href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure">password security</a> - depending on perspective, since it appeared the highest in the list at 121st, and 3rd overall in the UK.</p><p>Ferrari and Porsche were the two car manufacturers users trusted the most when it came to choosing their passwords, comfortably beating all the others on the market. </p><p>Dolphins were the most popular animal in many of the 50 countries evaluated by the NordPass team, which also noted men were more likely to use swear words as their passwords than women. </p><p>In a battle of the bands, Metallica outranked Slipknot with 88,453 and 75,204 uses respectively, and One Direction made a comeback to the top 200 in 2021 after falling off the list in 2020.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wqVfoTN8Euzuya6uVxfxRM" name="wqVfoTN8Euzuya6uVxfxRM.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wqVfoTN8Euzuya6uVxfxRM.jpg" mos="https://cdn.mos.cms.futurecdn.net/wqVfoTN8Euzuya6uVxfxRM.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Container network security guide for dummies</strong></p><p class="fancy-box__body-text">Enforcing Kubernetes best practices</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/containers/361744/container-network-security-guide" data-original-url="/development/containers/361744/container-network-security-guide">FREE DOWNLOAD</a></p></div></div><p>None of the top 200 passwords of the year are recommended for use if keeping personal data private is a priority, but NordPass offered some tips to achieve greater password security for 2022.</p><p>Complex passwords should always be favoured, and these typically contain at least 12 characters with a mix of uppercase and lowercase letters, numbers, and symbols.</p><p>Although it can be <a href="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember" data-original-url="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember">difficult to track all passwords</a> when they're all different, it is recommended to have <a href="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords" data-original-url="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords">different passwords for each website and service</a> used. Password managers can help here as the practice lowers the likelihood of losing access to multiple services in a single breach. </p><p>Updating passwords every 90 days is also a tedious endeavour but can also help in securing digital identities, according to NordPass, and is commonplace in businesses with a <a href="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by" data-original-url="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by">strong security posture</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is single sign-on (SSO)?  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso</link>
                                                                            <description>
                            <![CDATA[ We explain how SSO works and why you need it ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bSmDyfnMsNdmwmYTNonRmE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h5fd6uTnz6Uqg5A5ottzJ7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Dec 2021 16:31:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gabriella Buckner ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h5fd6uTnz6Uqg5A5ottzJ7-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close-up shot of a login portal ]]></media:description>                                                            <media:text><![CDATA[A close-up shot of a login portal ]]></media:text>
                                <media:title type="plain"><![CDATA[A close-up shot of a login portal ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h5fd6uTnz6Uqg5A5ottzJ7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You might think that using the same credentials for everything means a bigger chance of a data breach. After all, aren’t we always being warned not to reuse <a href="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure" data-original-url="https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure">passwords</a> to avoid compromising a large string of accounts rather than just one?</p><p>Not when it comes to single sign-on, or SSO.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M2WpDQRjBJ3Hd2qkprKffM" name="M2WpDQRjBJ3Hd2qkprKffM.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" mos="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Busting the myths about SSO</strong></p><p class="fancy-box__body-text">Why SSO capability is critical to the success of IAM</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/single-sign-on-sso/361519/busting-the-myths-about-sso" data-original-url="/security/single-sign-on-sso/361519/busting-the-myths-about-sso">FREE DOWNLOAD</a></p></div></div><p>Usually used in a business context, SSO is an authentication method and just one component of identity and access management (IAM), a security strategy giving users access only to the business applications they need for work so that any hackers only get so far within a victim’s limited network.</p><p>SSO allows your organisation to control access through a single log-in portal that then gives your employee access to all approved applications within your business.</p><p>As the use of cloud applications, <a href="https://www.itpro.com/business-strategy/flexible-working/361495/redefining-the-where-of-hybrid-work" data-original-url="https://www.itpro.com/business-strategy/flexible-working/361495/redefining-the-where-of-hybrid-work">hybrid work</a>, and the sophistication of cyber attacks grow, this tech is especially helpful for replacing many of the on-premises security measures that are no longer as effective.</p><p>So should your organisation adopt a single sign-on platform as part of its security strategy?</p><h3 class="article-body__section" id="section-how-does-sso-work"><span>How does SSO work?</span></h3><p>SSO solutions hold your credentials and identity data in a single identity repository, or identity store, giving you access to all the apps and services your organisation has given permission for you to access.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/361695/over-90-of-it-decision-makers-reuse-passwords" data-original-url="/security/361695/over-90-of-it-decision-makers-reuse-passwords">More than 90% of IT decision makers reuse passwords</a></p></div></div><p>When you log in with an identity provider, such as logging into a site via Facebook or Google, the provider verifies your identity and passes along a token of authentication to the site you’re trying to access. The idea is that once logged in via the identity provider, it’s the token that gets you seamless access to all permitted sites and services, rather than a different set of credentials each time.</p><h3 class="article-body__section" id="section-the-benefits-of-single-sign-on"><span>The benefits of single sign-on</span></h3><p>Still wondering how having one password instead of multiple means stronger security rather than weaker?</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by" data-original-url="/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by">Robust password policies cut cyber attacks by 60%</a></p></div></div><p>Implementing SSO offers your organisation a plethora of benefits, and one of these is that by nature of only having one password to remember, users can create stronger ones and are less likely to use previous or simpler passwords to save time.</p><p>Instead, they save time by not having to sign in to different apps and websites multiple times a day or waste time with password recovery for all of the passwords they’re forced to keep track of.</p><p>In addition to an improved user experience, SSO saves administrators time and headache by giving them central management of a variety of security controls. From one platform, you can set required password complexity, how often users have to reset their passwords or re-enter them to ensure they’re still active, what apps and websites users have access to, and more.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></p></div></div><p>It also makes it easier to implement <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a>, which improves security by requiring users to confirm their identity through other avenues, such as a code received by text. Instead of identifying and launching MFA on each app, you simply need to set it up for one portal and be done with it.</p><h3 class="article-body__section" id="section-the-drawbacks-of-single-sign-on"><span>The drawbacks of single sign-on</span></h3><p>There are still a few issues with SSO that you need to consider before adopting it.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M2WpDQRjBJ3Hd2qkprKffM" name="M2WpDQRjBJ3Hd2qkprKffM.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" mos="https://cdn.mos.cms.futurecdn.net/M2WpDQRjBJ3Hd2qkprKffM.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Busting the myths about SSO</strong></p><p class="fancy-box__body-text">Why SSO capability is critical to the success of IAM</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/single-sign-on-sso/361519/busting-the-myths-about-sso" data-original-url="/security/single-sign-on-sso/361519/busting-the-myths-about-sso">FREE DOWNLOAD</a></p></div></div><p>You could run the risk of employees still using easy-to-guess passwords, which then gives a hacker access to all applications once they have that one password. As mentioned earlier, you can prevent this from happening by setting requirements for the complexity of the password, or using MFA.</p><p>The centralised server that makes management so much easier can also cause everyone to lose access to their applications if it were to go down. This makes it a prime target for attackers, and arguably a single point of failure.</p><p>However, by filling the security gaps ahead of time, you can reduce the risk of a breach happening and the damage any successful breach can cause, while still reaping the benefits of better security, user experience, and efficiency.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chinese hackers target ManageEngine password manager ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361487/chinese-hackers-target-manageengine-password-manager</link>
                                                                            <description>
                            <![CDATA[ Around nine organizations in the technology, defense, health care, energy, and education industries hit in new campaign ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cXnjSm5pWayy6pqUN45tU8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X96amkjBXj9bShZZgqpNmT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Nov 2021 18:28:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X96amkjBXj9bShZZgqpNmT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Laptop screen with a man entering a password]]></media:description>                                                            <media:text><![CDATA[Laptop screen with a man entering a password]]></media:text>
                                <media:title type="plain"><![CDATA[Laptop screen with a man entering a password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X96amkjBXj9bShZZgqpNmT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have warned of a new Chinese hacking campaign using a known flaw in the Zoho ManageEngine ADSelfService Plus password manager to steal data.</p><p><a href="https://www.itrpo.com/hacking">Hackers</a> gained initial access to targeted organizations by exploiting a recently patched vulnerability in Zoho’s ManageEngine product, ADSelfService Plus, tracked in CVE-2021-40539, according to <a href="https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge">researchers at Palo Alto Network’s Unit 42</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/operating-systems/361462/vulnerability-in-linux-kernel-could-let-hackers-remotely-take" data-original-url="/software/operating-systems/361462/vulnerability-in-linux-kernel-could-let-hackers-remotely-take">Vulnerability in Linux kernel could let hackers remotely take over systems</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/361399/critical-macos-vulnerability-found-to-bypass-sip-restrictions" data-original-url="/security/361399/critical-macos-vulnerability-found-to-bypass-sip-restrictions">Critical macOS vulnerability found to bypass SIP restrictions</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361400/critical-vulnerability-discovered-in-popular-cicd-framework" data-original-url="/security/cyber-security/361400/critical-vulnerability-discovered-in-popular-cicd-framework">Critical vulnerability discovered in popular CI/CD framework</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can" data-original-url="/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can">Kaspersky Password Manager generates passwords that can be 'cracked in seconds'</a></p></div></div><p>Researchers added this campaign is separate from one described in a US Cybersecurity and Infrastructure Security Agency (CISA) <a href="https://us-cert.cisa.gov/ncas/alerts/aa21-259a">advisory</a> published in September.</p><p>The flaw, CVE-2021-40539, allows for REST API authentication bypass with resultant remote code execution in vulnerable devices. The <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/09/07/zoho-releases-security-update-adselfservice-plus">Zoho patched the flaw</a> in September.</p><p>In this campaign, hackers used leased infrastructure in the US to scan hundreds of vulnerable organizations across the internet. Researchers said exploitation attempts began on September 22 and continued into early October. During that window, the actor successfully compromised at least nine global entities in the technology, defense, health care, energy, and education industries.</p><p>After the initial exploitation, a payload was uploaded to the victim network which installed a Godzilla webshell. </p><p>“This activity was consistent across all victims; however, we also observed a smaller subset of compromised organizations who subsequently received a modified version of a new backdoor called <a href="https://github.com/Maka8ka/NGLite">NGLite</a>,” said researchers.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GmEy94iCPBFPs9V6HWFekm" name="GmEy94iCPBFPs9V6HWFekm.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" mos="https://cdn.mos.cms.futurecdn.net/GmEy94iCPBFPs9V6HWFekm.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The best defence against ransomware</strong></p><p class="fancy-box__body-text">How ransomware is evolving and how to defend against it</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/361095/the-best-defence-against-ransomware" data-original-url="/security/ransomware/361095/the-best-defence-against-ransomware">FREE DOWNLOAD</a></p></div></div><p>Hackers then used either the webshell or the NGLite payload to run commands and move laterally to other systems on the network while they exfiltrated files of interest simply by downloading them from the web server. </p><p>“Once the actors pivoted to a domain controller, they installed a new credential-stealing tool that we track as KdcSponge,” said researchers.</p><p>Researchers said Godzilla and NGLite were developed with Chinese instructions and are publicly available for download on GitHub. </p><p>“We believe threat actors deployed these tools in combination as a form of redundancy to maintain access to high-interest networks,” researchers added.</p><p>Researchers said the hackers' main goal was to gain persistent access to the network and gather and exfiltrate sensitive documents from the compromised organization.</p><p>“The threat actor gathered sensitive files to a staging directory and created password-protected multi-volume RAR archives in the Recycler folder. The actor exfiltrated the files by directly downloading the individual RAR archives from externally facing web servers,” researchers added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Telegram bots are out to steal your one-time passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/361070/telegram-bots-are-out-to-steal-your-one-time-passwords</link>
                                                                            <description>
                            <![CDATA[ New scam lets cyber criminals steal money from victims ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uPG25fEu17kdVw3Q1mGVnP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dKMuiWaNZr2GNDbBd7iEFD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Sep 2021 13:23:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dKMuiWaNZr2GNDbBd7iEFD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Smartphone displaying Signal, Telegram and WhatsApp applications]]></media:description>                                                            <media:text><![CDATA[Smartphone displaying Signal, Telegram and WhatsApp applications]]></media:text>
                                <media:title type="plain"><![CDATA[Smartphone displaying Signal, Telegram and WhatsApp applications]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dKMuiWaNZr2GNDbBd7iEFD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are using <a href="https://www.itpro.com/tag/bots" data-original-url="https://www.itpro.com/bots">bots</a> on the Telegram messenger app to steal credentials with a one-time password, intercept control of user accounts, and steal bank funds. </p><p>Hackers are using a bot script called SMSRanger to send automatic messages to people, allegedly on behalf of a bank, PayPal, or other popular financial applications, <a href="https://intel471.com/blog/otp-password-bots-telegram">According to a security researcher at Intel471</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/359242/hackboss-malware-is-using-telegram-to-steal-cryptocurrency-from" data-original-url="/technology/cryptocurrencies/359242/hackboss-malware-is-using-telegram-to-steal-cryptocurrency-from">HackBoss malware is using Telegram to steal cryptocurrency from other hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/358646/weekly-threat-roundup-solarwinds-style-hack-macos-big-sur" data-original-url="/security/vulnerability/358646/weekly-threat-roundup-solarwinds-style-hack-macos-big-sur">Weekly threat roundup: SolarWinds-style hack, macOS Big Sur, Telegram</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/357661/over-23000-hacked-databases-found-telegram-discord" data-original-url="/security/hacking/357661/over-23000-hacked-databases-found-telegram-discord">Over 23,000 hacked databases shared over Telegram and Discord</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30525/flaw-in-telegram-app-could-spread-malware" data-original-url="/security/30525/flaw-in-telegram-app-could-spread-malware">Flaw in Telegram app could spread malware</a></p></div></div><p>Automatic messages prompt users to send one-time password (OTP) codes along with other account information. If successful, Telegram bots collect codes, enabling hackers to bypass the bank's OTP verification system, hack a user’s account, and withdraw funds. </p><p>Researchers said SMSRanger is easy to use. The ability to specify numbers, goals, and the company the program will masquerade as is quite simple, so the criminal only needs to know some basic script commands in Telegram. This means SMSRanger is popular not only among experienced cyber criminals, but also among relatively unskilled ones.</p><p>Once the hacker enters the target's phone number, the bot does the rest of the work, ultimately granting access to any successfully attacked account. Researchers said hackers using the tool have about an 80% efficacy rate if the victim answered the call and the user’s full information was accurate and updated.</p><p>Researchers also discovered another bot called BloodOTPbot. This can send users a fraudulent OTP code via SMS. The bot requires an attacker to spoof the victim’s phone number and impersonate a bank or company representative.</p><p>“The bot then would attempt to call the victim and use social engineering techniques to obtain a verification code,” said researchers.</p><p>The operator would receive a notification from the bot during the call specifying when to request the OTP during the authentication process. The bot would text the code to the operator once the victim received the OTP and entered it on the phone’s keyboard, added researchers.</p><p>A third bot, known as SMS Buster, requires a bit more effort to obtain account information. The bot provides options to disguise a call and make it appear as a legitimate contact from a specific bank, letting the attackers dial from any phone number.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iAVch4E74nXskoYH6rVd54" name="iAVch4E74nXskoYH6rVd54.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" mos="https://cdn.mos.cms.futurecdn.net/iAVch4E74nXskoYH6rVd54.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Modernise endpoint protection and leave your legacy challenges behind</strong></p><p class="fancy-box__body-text">The risk of keeping your legacy endpoint security tools</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges" data-original-url="/security/endpoint-security/360946/modernise-endpoint-protection-and-leave-your-legacy-challenges">FREE DOWNLOAD</a></p></div></div><p>“From there, an attacker could follow a script to trick a victim into providing sensitive details such as an ATM personal identification number (PIN), card verification value (CVV) and OTP, which could then be sent to an individual’s Telegram account. The bot, which was used by attackers targeting Canadian victims, gives users the chance to launch attacks in French and English,” said researchers.</p><p>The researchers added they have seen accounts illegally accessed at eight different Canadian-based banks.</p><p>“The ease by which attackers can use these bots cannot be understated. While there’s some programming ability needed to create the bots, a bot user only needs to spend money to access the bot, obtain a phone number for a target, and then click a few buttons,” researchers said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What makes a password secure? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/361037/what-makes-a-password-secure</link>
                                                                            <description>
                            <![CDATA[ IT security is constantly evolving to counter threats, but the password remains a key part of our security arsenal ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xn6KJwY2szwQWnK2rtMz4e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UPWeshVaVNBNQNyMeSsrQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Sep 2021 16:08:57 +0000</pubDate>                                                                                                                                <updated>Tue, 28 Sep 2021 17:08:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UPWeshVaVNBNQNyMeSsrQ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a laptop with padlock and network graphic superimposed]]></media:description>                                                            <media:text><![CDATA[Hands typing on a laptop with padlock and network graphic superimposed]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a laptop with padlock and network graphic superimposed]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UPWeshVaVNBNQNyMeSsrQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The password has been a vital tool for computers for decades. In the mid-‘60s Fernando Corbato, an academic at the Massachusetts Institute for Technology (MIT), devised a system that allowed multiple people to access a computer at the same time. Corbato gave each user a password that kept their files hidden away from others so their activities weren’t interrupted.</p><p>Fast-forward to 2021 and Corbato’s humble solution is the key to unlocking our digital lives – from bank accounts and emails to the apps and cloud services we use daily for work. People are logging in to more devices than ever, and with the post-COVID shift to hybrid work the number of passwords businesses and employees are juggling is multiplying.</p><p>However, with this password proliferation comes an increased threat of cyber attacks and data breaches. The recent RockYou2021 leak saw a 100GB text file emerge compiling a staggering 8.4 billion compromised passwords. Websites like Have I Been Pwned? and BreachAlarm will scan for new data leaks and tell you if your password has been stolen.</p><p>Hackers utilise a variety of tactics to snare valuable credentials. They can be acquired on the dark web, where cyber criminals make a business out of exchanging leaked data for money. Brute force attacks see automated software applications running through different character combinations in a bid to break in.</p><p>Phishing, meanwhile, is when social engineering is used to pressure and intimidate would-be victims into giving over personal information. For example, individuals may receive a scam email about needing to change their online banking password – there’ll then be directed to a fake website that resembles a bank login page with the hope they’ll give over details.</p><p>With so many cyber threats to contend with, ensuring that passwords are secure and effective is critical. In fact, the recent Incident Response Analyst Report 2021 found that a robust password policy reduces the likelihood of being attacked by 60%.</p><h3 class="article-body__section" id="section-creating-effective-passwords"><span>Creating effective passwords</span></h3><p>But what exactly makes a password secure? They are a key tool in our security arsenal and rely on individuals to create and use them every day. However, not all are created equal. If they are too easy to guess, they’ll be easy to break – and if they’re being reused then multiple accounts are at risk of being compromised.</p><p>A good password shouldn’t be obvious or use common keyboard runs like ‘qwerty’ or sequential numbers like ‘123456’. Personal information that’s easy to guess, like a name or date of birth, should be avoided, too. Password length is crucial – anything under 12 characters is at risk of being cracked, so aim for 15 characters or more. The longer it is, the harder it is for a brute force attack to be successful.</p><p>Longstanding password guidelines suggest mixing up letters, numbers and symbols to help add an extra layer of complexity to your password. Frequently, these will be a requirement when you set a new password. It’s best to steer away from common character substitutions. For example, Synology becoming Syn010gy is unlikely to give you any significant benefit as these changes from letters to numbers are easy to guess. There are several random password generators online that can be used to come up with a random string of characters.</p><p>However, more recent thinking has been leaning towards passphrases as a more secure and user-friendly solution. The National Cyber Security Centre (NCSC) recommends the use of three random, unconnected words for a password. These phrases are easier to remember and to type, and the use of multiple words tends to generate longer, and therefore more secure, passwords.</p><p>Ironically, enforcing complexity requirements has been found to make passwords weaker in some cases, as users tend to struggle to remember random strings of characters and so are likely to fall back on some simple, predictable patterns (such as the aforementioned substitutions). Choosing three random words, it is believed, will increase the overall diversity of passwords in the ecosystem, reducing the likelihood of different users ending up with the same passwords and thus creating a tougher environment for attackers to operate in.</p><p>Setting up two-factor authentication (2FA), be it biometric or a number/character token, will give another layer of protection. However, using SMS for 2FA is best avoided as these can easily be intercepted. Instead, apps like Authy, Google Authenticator or Microsoft Authenticator generate PINs that can be used to complete the login, although not all apps support these services.</p><h3 class="article-body__section" id="section-a-password-management-solution"><span>A password management solution</span></h3><p>Whether you’re an individual, a small business or large corporation, keeping up to speed with password security is vital. For businesses, it’s particularly important to ensure that staff are well educated and supported in this area so sensitive data is protected. Make sure that all vendor-supplied passwords on devices are changed before they make their way to staff, and give individual logins to apps and services to all users who need them, avoiding password sharing.</p><p>One solution to help with password security is Synology’s C2 Password management system. Here you can store, sync and secure passwords and personal information – plus, thanks to unlimited device syncing you can access credentials from anywhere using an online portal or browser extension. C2 Password can also be used to generate complex combinations of letters, numbers and symbols, and keep all of them stored together in the same place.</p><p>Sensitive data is safeguarded through end-to-end encryption, too. Data goes through AES 256 encryption before it leaves a device, with decryption carried out only at the destination. The key to encrypt and decrypt is stored only on the individual device, not Synology C2 servers, to give an extra layer of protection. What’s more, C2 Password is free to individuals and businesses.</p><p>Juggling a selection of unique and uncrackable passwords might seem like hard work, but with a solid understanding of what makes them secure and the right tools in place to organise them, you’ll find peace of mind and a seamless, stress-free online experience.</p><p><a href="http://pubads.g.doubleclick.net/gampad/clk?id=5799540218&iu=/359/impcount.co.uk" rel="nofollow" target="_blank"><strong><em>Discover more about Synology C2 Password and how it can safeguard your credentials</em></strong></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Robust password policies cut cyber attacks by 60% ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/360865/better-patch-management-and-password-policies-cut-cyber-attacks-by</link>
                                                                            <description>
                            <![CDATA[ Research shows that hackers most often use brute force password attacks and flaw exploitation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3YvsihiY147YRWyCEbaVmR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6dPwiZwS44BaYhycKNoFrN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Sep 2021 13:20:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6dPwiZwS44BaYhycKNoFrN-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A list of poorly-constructed passwords on a notepad]]></media:description>                                                            <media:text><![CDATA[A list of poorly-constructed passwords on a notepad]]></media:text>
                                <media:title type="plain"><![CDATA[A list of poorly-constructed passwords on a notepad]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6dPwiZwS44BaYhycKNoFrN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Deploying an appropriate patch management policy decreases the risk of hacking by 30%, while a robust password policy reduces the likelihood of being attacked by 60%, according to a new report.</p><p>The <a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2021/09/13085018/Incident-Response-Analyst-Report-eng-2021.pdf">Incident Response Analyst Report 2021</a>, published by IT security firm Kaspersky, found brute force is the most widely used initial vector to penetrate a company’s network. Compared to the previous year, the share of brute force attacks has skyrocketed from 13% to 31.6%. The report’s authors said this was perhaps due to the pandemic and the boom of remote working.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/open-source/360819/hackers-use-open-source-tools-to-steal-usernames-and-passwords" data-original-url="/development/open-source/360819/hackers-use-open-source-tools-to-steal-usernames-and-passwords">Hackers use open source tools to steal usernames and passwords</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts" data-original-url="/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts">1Password Business review: First choice for business travel and guest accounts</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/360163/keeper-security-review-keeps-corporate-password-management-simple" data-original-url="/software/360163/keeper-security-review-keeps-corporate-password-management-simple">Keeper Security review: Keeps corporate password management simple</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can" data-original-url="/security/information-security-infosec/360139/passwords-generated-by-kaspersky-password-manager-can">Kaspersky Password Manager generates passwords that can be 'cracked in seconds'</a></p></div></div><p>The analysis of anonymized data from incident response (IR) cases found that the second most seen attack is vulnerability exploitation with a 31.5% share. The research showed that vulnerabilities from 2020 were used in only a few incidents. In other cases, adversaries used older, unpatched vulnerabilities, such as CVE-2019-11510, CVE-2018-8453, and CVE-2017-0144.</p><p>Over half of attacks that started with malicious emails, brute force, and external application exploitation were detected in hours (18%) or days (55%). The report added that some of these attacks lasted much longer, with an average duration of up to 90.4 days. </p><p>The report also found that industrial businesses were the most affected by cyber attacks (22%), followed by <a href="https://www.itpro.com/tag/government" data-original-url="https://www.itpro.com/tags/government">government</a> institutions (19%). </p><p>Analysis of the data from incident responses found that in 44% of all incidents, hackers used existing, well known offensive tools from GitHub, such as Mimikatz, AdFind, and Masscan. They also used specialized commercial frameworks, such as Cobalt Strike.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="GxhMTQpj855AqijVp9SdDh" name="GxhMTQpj855AqijVp9SdDh.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/GxhMTQpj855AqijVp9SdDh.png" mos="https://cdn.mos.cms.futurecdn.net/GxhMTQpj855AqijVp9SdDh.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Defeating ransomware with unified security from WatchGuard</strong></p><p class="fancy-box__body-text">How SMBs can defend against the onslaught of ransomware attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360798/defeating-ransomware-with-unified-security-from-watchguard" data-original-url="/security/ransomware/360798/defeating-ransomware-with-unified-security-from-watchguard">FREE DOWNLOAD</a></p></div></div><p>Konstantin Sapronov, head of Kaspersky’s global emergency response team said that even if the IT security department does its best to ensure safety of the company’s infrastructure, legacy OS usage, low-end equipment, compatibility issues, and human factors often result in security breaches that can jeopardize an organization’s security.</p><p>“Protective measures alone can’t provide a holistic cyber defense. Therefore, they should always be combined with detection and response tools that are able to recognize and eliminate an attack at an early stage, as well as address the cause of the incident,” Sapronov said.</p><p>The report urged organizations to deploy a robust password policy, including multi-factor authentication (MFA) and identity and access management tools, and ensure software is patched regularly to fix vulnerabilities.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 1Password Business review: First choice for business travel and guest accounts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/360257/1password-business-review-first-choice-for-business-travel-and-guest-accounts</link>
                                                                            <description>
                            <![CDATA[ 1Password provides a great user experience, but its entry level tier in particular lacks some surprising features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gNT1UTNU7BiWd3zV9avZKL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Q5k2mrfxjTKvgMNTZN8W6W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jul 2021 09:28:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Q5k2mrfxjTKvgMNTZN8W6W-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of 1Password&amp;#039;s password management vault]]></media:description>                                                            <media:text><![CDATA[A screenshot of 1Password&amp;#039;s password management vault]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of 1Password&amp;#039;s password management vault]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Q5k2mrfxjTKvgMNTZN8W6W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>1Password has a good reputation among password managers, but is perhaps best known for its Travel Mode, which temporarily removes any vaults that haven’t been marked safe for travel from your accounts. This is particularly useful for organisations whose staff regularly do business in countries with strict border policies that allow officials to access travellers' devices, <a href="https://www.itpro.com/security/28458/us-may-force-travellers-to-unlock-their-devices" data-original-url="https://www.itpro.com/security/28458/us-may-force-travellers-to-unlock-their-devices">such as the United States</a>. </p><p>1Password’s business subscriptions allow travel mode to be enabled for staff by administrators, who can also define travel-safe password vaults.</p><h2 id="1password-business-review-client-features">1Password Business review: Client features</h2><p>1Password conveniently positions a link to an app download page at the bottom left of its web-based vault interface, and you’ll be offered clients for macOS, Windows, iOS, Android and whatever browser you happen to be using at the time. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/360163/keeper-security-review-keeps-corporate-password-management-simple" data-original-url="/software/360163/keeper-security-review-keeps-corporate-password-management-simple">Keeper Security review: Keeps corporate password management simple</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/360084/dashlane-review-a-very-web-focused-password-manager" data-original-url="/security/360084/dashlane-review-a-very-web-focused-password-manager">Dashlane review: A very web-focused password manager</a></p></div></div><p>Although it’s not offered on the download page, there is also a Linux desktop client, currently in beta but nonetheless functional. There’s also a <a href="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface" data-original-url="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface">command-line tool</a> for ease of scripting and automation on all three major desktop operating systems.</p><p>You’ll find more predefined categories for stored items than many other password managers, and while this doesn’t make for any real functional difference, it’s helpful to be reminded that you can, in fact, use your business password manager to make sure your team has all their software license keys stored somewhere safe, for example.</p><p>As you’d expect, you can save notes, personal details, credit cards and important documents, as well as passwords. Everyone in your Team gets 1GB of storage, increasing to 5GB for Business users.</p><p>Whether you access it via mobile, desktop, web or browser plug-in, 1Password gives each user easy access to both Private and Shared vaults, as well as alerting them to any issues with the security of their passwords via the 1Password Watchtower.</p><p>Companies that subscribe to 1Password Business get a free Family account for each user, too. These can be accessed via the same master password and help to encourage your users to store their personal passwords in their personal space. However, unlike some other providers, such as Keeper Security, the account is free only for so long as their business account exists.</p><h2 id="1password-business-review-management-features">1Password Business review: Management features</h2><p>All of 1Password’s business subscriptions come with a number of guest accounts: five for Teams, 20 for Business. These are designed so you can grant access to specific password vaults to clients, accountants, and short-term or limited role contractors and freelancers, without having to pay for a full user seat.</p><p>Users can be added manually by email address or invited to sign up with a link sent to an address on an approved domain, but you can also invite people via Slack connector, and Business users can connect their Active Directory users using a dedicated bridge.</p><p>Business subscribers can also create user Groups with different access and admin permissions. Both Business and Teams users can create Vaults and assign different read/write permissions to their contents on a person-by-person basis.</p><p>However, more sophisticated access permissions are once again only available to Business subscribers: Access to 1Password can be allowed or blocked by continent, IP address, and app version. You can similarly force security rules regarding master password strength and require two-factor authentication. Sadly, this is a rather limited selection compared to the likes of LastPass and Dashlane.</p><h2 id="1password-business-review-verdict">1Password Business review: Verdict</h2><p>1Password’s business offerings start with entry-level Teams tier, priced at $19.95 per month for up to ten seats, with the usual array of managed storage vaults, two-factor authentication, a tidy admin interface and basic permissions management. </p><p>However, if you need more than ten users - along with more granular permissions and user role management, activity logs and support for a range of single sign-on solutions - then you’ll want a Business subscription, at $95.88 (£69) per user, per year - but that’s rather expensive compared to <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a> and even <a href="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use" data-original-url="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use">LastPass’s</a> equivalents.</p><p>Despite the cost and odd feature tiers, though, 1Password is pleasant to use, and the travel mode could be a killer app for an extremely international company.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keeper Security review: Keeps corporate password management simple ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/360163/keeper-security-review-keeps-corporate-password-management-simple</link>
                                                                            <description>
                            <![CDATA[ Very polished business password management includes free lifetime personal accounts for all your users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jyZouwT8uQzg4XoqbDVmLg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LGVMFaxWM9peAu5qHexvZJ-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 Jul 2021 08:22:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/LGVMFaxWM9peAu5qHexvZJ-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Keeper Security]]></media:description>                                                            <media:text><![CDATA[A screenshot of Keeper Security]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Keeper Security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LGVMFaxWM9peAu5qHexvZJ-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Launched in 2009, Keeper Security’s cross-platform password manager is one of the better known options on the market. While it doesn’t have a free tier for either personal or business users, trials are available, it’s competitively priced at all tiers, and the company has historically been reasonably prompt in rolling out security patches once vulnerabilities are reported.</p><p>Keeper’s Business tier is straightforward: at a cost of £40 per user, per year (which works out at £3.33 per month but is billed annually), your users each get a personal encrypted vault and shared team folders, and you get a neat admin console from which to manage everything. You also get 100GB of storage to share between your users. </p><h2 id="keeper-security-review-client-features">Keeper Security review: Client features</h2><p>Keeper desktop clients are available for Windows, Linux, and macOS, with mobile apps for iOS and Android. Unlike <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a>, which supports phones that don’t use Google’s services framework, the Android version of Keeper can only be installed via the Play Store.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/360084/dashlane-review-a-very-web-focused-password-manager" data-original-url="/security/360084/dashlane-review-a-very-web-focused-password-manager">Dashlane review: A very web-focused password manager</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">LastPass is crippling its free tier. Here’s how to ditch it</a></p></div></div><p>Unsurprisingly, the clients provide access to all the vaults that each user has assigned to them, as well as tools to check on the security and strength of their passwords. The desktop applications make it easy to work with password-protected files, software tools and servers, and include hotkeys to easily enter usernames and passwords where needed, which is particularly helpful if your users regularly have to login to desktop applications and remote servers. </p><p>As you’d expect, there are also browser extensions for the usual suspects: Chrome, Firefox, Safari, IE, Edge and Opera are all supported. These plugins can both store and enter passwords on websites.</p><p>Keeper also offers an Enterprise tier, and as is usually the case, the enterprise service uses the same client as the consumer version. However, each user also gets a free personal Keeper Unlimited account, for use on unlimited devices, forever, even if they leave the company or if your business stops using Keeper. Your company won’t have admin access to these personal accounts, but they mean that your users won’t be tempted to store their own passwords in their business accounts - which in turn makes it less likely that you and your admin team will accidentally breach your employees’ privacy.</p><h2 id="keeper-security-review-management-features">Keeper Security review: Management features</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4BCvbZowg9SJqNeQxYKsxk" name="4BCvbZowg9SJqNeQxYKsxk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4BCvbZowg9SJqNeQxYKsxk.jpg" mos="https://cdn.mos.cms.futurecdn.net/4BCvbZowg9SJqNeQxYKsxk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 IBM Security X-Force Insider Threat Report</strong></p><p class="fancy-box__body-text">Top discovery methods and recommendations for insider attacks</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360176/2021-ibm-security-x-force-insider-threat-report" data-original-url="/security/cyber-security/360176/2021-ibm-security-x-force-insider-threat-report">FREE DOWNLOAD</a></p></div></div><p>Keeper’s admin console feels spacious and easy to use. A dashboard gives you an overview of your user accounts, their <a href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">password strength</a> and use of <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">2FA</a>, as well as any potentially compromised accounts thrown up by Keeper’s optional BreachWatch service, which we’ll talk more about shortly. </p><p>You can assign users to roles and teams, and use these to configure granular access rights, permissions and requirements. Roles can be assigned enforcement policies, from password requirements, 2FA, sharing restrictions, changing the behaviour of the browser extension, restricting access to password vaults based on IP address, and more. </p><p>Keeper’s enforcement policies don’t give you quite as much control over your users’ privileges as <a href="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use" data-original-url="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use">LastPass</a>'s more expensive Enterprise service - there are no geolocation restrictions that aren’t IP-based, for example - but the controls are slightly more granular than Bitwarden’s comparably-priced services offer. </p><p>Overall, Keeper provides one of the best at-a-glance admin consoles, and is among the easiest to manage.</p><h2 id="keeper-security-review-add-ons">Keeper Security review: Add-ons</h2><p>Updating to Keeper Enterprise gets you single sign-on support, AD and LDAP sync (including Azure AD provisioning), access to APIs, extra 2FA options and email auto-provisioning. Keeper invites larger companies to discuss their needs in person, but you can actually upgrade Business accounts to Enterprise yourself via an option in the web interface for an extra £15 per user, per year; again billed annually. You can also add more storage as needed, with 1TB coming in at £375.00 per year.</p><p>Other optional add-ons include Breachwatch (£15 per user, per year), which alerts you to any passwords that may have been exposed in security breaches, an Advanced Reporting and Alerts module (£8 per user, per year) to reveal potential security issues by tracking failed logins and 2FA hits. There’s also a dedicated onboarding specialist from Keeper, and a secure chat system (£15 per user, per year).</p><p>The modularity of this approach may or may not appeal, but it helps to keep pricing of the core service simple and modest. </p><h2 id="keeper-security-review-verdict">Keeper Security review: Verdict</h2><p>Keeper takes a heavily encrypted zero-knowledge approach to securing your stored data, but it’s working to create less friction for users by minimising the frequency with which they have to log in and enter long master passwords, for example by emphasising <a href="https://www.keepersecurity.com/blog/2021/01/12/keeper-bolsters-zero-trust-security-with-keeperpush-device-approvals-and-keeper-sso-connect-cloud-deployments">device approval solely via push notifications</a> to a previously approved device.</p><p>Bitwarden is cheaper and has a broader range of features, making it our current favourite password management service, but Keeper has better policy management via its top tier and is a great choice for business password security - particularly if you’ll use the optional add-ons.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dashlane review: A very web-focused password manager ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/360084/dashlane-review-a-very-web-focused-password-manager</link>
                                                                            <description>
                            <![CDATA[ A polished password manager with slightly limited platform support but plenty of security features ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7TUoTh9cBrfXD3N15FisoG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A6i72sBe4T2MnfGspvHk8B-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jul 2021 08:15:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/A6i72sBe4T2MnfGspvHk8B-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Dashlane&amp;#039;s password management console]]></media:description>                                                            <media:text><![CDATA[A screenshot of Dashlane&amp;#039;s password management console]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Dashlane&amp;#039;s password management console]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A6i72sBe4T2MnfGspvHk8B-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Headquartered in the US, Dashlane is a well-established password management service with a polished interface, a wide range of cross-platform web extensions, and a desktop app for Windows.</p><p>The company has two enterprise-oriented offerings, Team and Business, and the main difference between them is that the more expensive Business tier supports SAML-based SSO, which can be easily integrated with Active Directory, Shibboleth, and other single-sign-on systems. </p><p>This review will begin with Dashlane Team, designed to provide scalable, coordinated password management to small and medium enterprises who don’t need to link staff access to password libraries with an SSO system.</p><h2 id="dashlane-review-user-features">Dashlane review: User features</h2><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">LastPass is crippling its free tier. Here’s how to ditch it</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/355161/how-to-change-wifi-password" data-original-url="/infrastructure/network-internet/355161/how-to-change-wifi-password">7 simple steps to change your Wi-Fi password</a></p></div></div><p>The user interface is just like the personal version of Dashlane. Every user in your business gets a Premium personal account if you subscribe to Dashlane Team, or a six-user Family account if you use Dashlane Business.</p><p>If the user has an existing Dashlane account, this can be added by invitation: they’ll be added to your business account and their subscription will be covered by your Dashlane Team fees. They’ll have two separate password Spaces for personal and business passwords, helping to encourage good password management habits, helping to avoid staff using their work account for personal data and generally keeping everything a little more secure.</p><p>Note that users cannot be a member of multiple Dashlane business plans via the same email address. While this is unlikely to be a problem for staff, who should be using their company email address anyway, it may throw up issues involving freelance and contract colleagues in edge cases.</p><p>Users can access Dashlane via a web app and a browser extension for Chrome, Firefox, Edge, and Safari, which will also work on most browsers derived from those. There are dedicated clients for macOS, Windows, iOS, and Android. However, there’s no such client for Linux, for Android distributions that don’t include Google Play, or for other minority operating systems or use cases, such as command line automation.</p><p>While web passwords can be auto-filled if your Dashlane admin has allowed it, the desktop clients don’t have a KeePass-style autofill feature, so you’ll have to cut and paste passwords required for desktop applications.</p><p>Annoyingly, if you manually add a password entry, you aren’t offered the password generation tool when you add the password. Dashlane also insists that you add a website, although this actually can be any series of words, rather than the suggested URL. However, all of this makes Dashlane feel disproportionately web-focused.</p><p>At least Dashlane’s web extensions do a nice job of automatically detecting and offering to save passwords and personal details, storing payments and secure notes, generating strong passwords, and allowing users to import existing passwords through a compliant CSV file.</p><p>Dashlane’s mobile apps were recently found to include <a href="https://reports.exodus-privacy.eu.org/en/reports/com.dashlane/latest">a number of trackers</a> , most of which are used for crash reporting. </p><p>Beyond that, the company informs IT Pro that “Adjust is used for paid marketing attribution (primarily to fairly compensate partners who help Dashlane with marketing)”, while Braze is used for customer communication. Dashlane says that “these third-party integrations do not involve any exchange of personal data for money or any other consideration”.</p><h2 id="dashlane-review-management-features">Dashlane review: Management features</h2><p>At the heart of managing Dashlane Team is the console, which provides more of a guided introduction to its features than many of its rivals. When you log in for the first time, you’re invited to add your colleagues, either by pasting in their email addresses or by dropping in a TXT or CSV file listing them. You can re-open this at any point by clicking the ‘Add users’ button on the console’s Users tab, which shows your active, revoked and pending users. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="h388diQyR5igVUgsxxNYqd" name="h388diQyR5igVUgsxxNYqd.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" mos="https://cdn.mos.cms.futurecdn.net/h388diQyR5igVUgsxxNYqd.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IT Pro 20/20: Does cyber security's public image need a makeover?</strong></p><p class="fancy-box__body-text">Issue 18 of IT Pro 20/20 looks at recent efforts to retire the 'hacker' stereotype, and how the threat landscape has changed over the past 20 years</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover" data-original-url="/security/cyber-security/360060/it-pro-2020-does-cyber-securitys-public-image-need-a-makeover">FREE DOWNLOAD</a></p></div></div><p>Revoked accounts are not deleted by default: they transfer into their user’s hands. If you want to remove access to shared company passwords when a user leaves, you have to enable this feature, which requires you to designate at least one company domain. They get to keep their non-corporate passwords, but anything associated with your business email domain is removed when the user is revoked from your Dashlane Team.</p><p>To help you learn your way around, a helpful list of actionable items is pegged to the bottom of the console until you clear them. These prompt you to install the Dashlane extension for your browser, add extra admin users, and enable account recovery so you and your admin team can help users if they lose their master password.</p><p>For monitoring purposes, a dashboard shows you the number of user seats currently active, as well as the status of invitations and users’ passwords, including strength analysis and an alert of any compromised passwords: those for sites known to have been breached, and which have not been changed since the breach.</p><p>Groups, predictably enough, allows you to put users into groups for easy corporate password sharing. When adding users, you have to type in – or at least, start typing – each email address, even if they’re already in your Dashlane Team.</p><p>If you have outside contractors associated with your Dashlane account, you should add them to an appropriate group, which will make it easier to revoke their passwords by removing them from the group once they’ve finished their contract.</p><p>An Activity Log tab tracks everything that’s happened in your admin portal, and makes it easy to spot any potential security issues. Finally, the Settings screens let you enable account recovery and business domains, mentioned earlier, and enforce security policies such as log-out times and enforced two-factor authentication. You can also disable the default auto-login and autofill for specific websites, disable password sharing, and more. For Dashlane Business users, these screens also include configuration of SAML provisioning, SSO, and Active Directory integration.</p><p>This is also where you can enable the Dashlane VPN. This is a standard consumer VPN service, a white label version of Hotspot Shield, which is also available to personal Dashlane subscribers. Although not to be confused with a secure VPN connection to your office network, it can provide a modicum of security against ISP or local network level snooping on your users’ traffic.</p><p>It’s available for Dashlane Teams users running Windows, macOS, Android, or iOS. Dashlane Business only provides it for mobile platforms, and other operating systems aren’t covered by either subscription, with no OpenVPN profiles available for manual configuration, either.</p><h2 id="dashlane-review-verdict">Dashlane review: Verdict</h2><p>Dashlane Teams costs $5 per user, per month, billed annually, while Dashlane Business, which adds single sign-on support, costs $8 per user, per month. This is very much par for the course when it comes to password manager pricing, and cheaper than some, but 1Password, <a href="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use" data-original-url="https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use">LastPass</a> and Bitwarden all have comparable subscriptions for less, particularly versus the Business tier.</p><p>We’re fans of Dashlane’s polished interface and management controls, and its zero-knowledge, authenticated-device based <a href="https://blog.dashlane.com/dashlane-patented-security-architecture">security architecture</a> is highly credible. The whole package makes it one of the <a href="https://www.itpro.com/software/368049/best-password-managers-for-business" data-original-url="https://www.itpro.com/software/368049/best-password-managers-for-business-2022">best password managers for businesses</a> on the market, and one of the <a href="https://www.itpro.com/software/368049/best-password-managers-for-business" data-original-url="https://www.itpro.com/software/368049/best-password-managers-for-business-2022">best password managers</a> for every other type of user.</p><p>Your team won’t be disappointed by the user experience here, but <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a> is cheaper and supports a wider range of operating systems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass review: Great to administrate, a little clunky to use ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/360005/lastpass-review-great-to-administrate-a-little-clunky-to-use</link>
                                                                            <description>
                            <![CDATA[ LastPass has the most comprehensive admin portal around but it’s excessively browser-focused ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">p6Jtv88ujEQQKaiEbjBHEw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QQkuudouRiD6bGp3g3Xpcj-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Jun 2021 11:17:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/QQkuudouRiD6bGp3g3Xpcj-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Screenshot of LastPass password vault]]></media:description>                                                            <media:text><![CDATA[Screenshot of LastPass password vault]]></media:text>
                                <media:title type="plain"><![CDATA[Screenshot of LastPass password vault]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QQkuudouRiD6bGp3g3Xpcj-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>LastPass is one of the most recognisable brands in the password management space, although the company has not always been seen in glowing terms by the wider community.</p><p>It recently <a href="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it" data-original-url="https://www.itpro.com/security/358632/lastpass-is-crippling-its-free-tier-heres-how-to-ditch-it">raised the ire of consumers</a> with changes that force free users of its password management service to choose between using it on either desktop or mobile devices, something which caused a spike in the number of people looking for alternatives to the service. </p><p>That said, its business services are as strong as ever, and you could be doing yourself and your company a disservice by passing over LastPass. In fact, we've ranked the software as one of the <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">best password managers</a> on the market, as well as one of the <a href="https://www.itpro.com/software/368049/best-password-managers-for-business" data-original-url="https://www.itpro.com/software/368049/best-password-managers-for-business-2022">best business password managers</a>.</p><h2 id="lastpass-review-client-interface">LastPass review: Client interface</h2><p>LastPass’s web browser plugin and mobile clients are still among the most widely-used by general consumers, so there’s likely to be less of a knowledge gap when it comes to adoption. </p><p>On the desktop, LastPass is only available as a browser plugin. It supports the most popular browsers on Windows, macOS and Linux, so compatibility won’t be a problem for anyone. The LastPass vault is well designed, and, assuming the admin allows it, web passwords will be automatically captured and entered. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a></p></div></div><p>However, if you need to use or store passwords from elsewhere, such as servers you regularly access via FTP or SSH, you’ll have to manually create an entry using a web vault, and the password generator isn’t available when you do this.</p><p>Users can also store payment and address data and secure notes, including encrypted attachments. Like many other password management services, LastPass allows users to link their personal accounts. These are loaded as a new sub-folder in their enterprise vault, allowing them to access their personal passwords. Enterprise policies are applied to this folder when accessed via the user’s work account.</p><p>A <a href="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface" data-original-url="https://www.itpro.com/operating-systems/34493/take-command-of-your-computer-with-a-command-line-interface">command line</a> application is also available for management and automation, and is particularly handy for creating and giving access to shared company folders.</p><p>LastPass was recently found to be using <a href="https://reports.exodus-privacy.eu.org/en/reports/165465">a number of trackers</a> on its Android app, including some behavioural analytics and profiling tools, alongside more expected crash and error trackers. LastPass tells us that “aggregate data provided by trackers help to identify and troubleshoot issues within the product and prioritize areas to improve and optimize the end user experience.” However, these can be disabled in your LastPass vault, accessible from a desktop browser</p><h2 id="lastpass-review-management-interface">LastPass review: Management interface</h2><p>LastPass has a particularly nice dashboard to help you manage your users. Heads-up displays show total, active, registered and blocked users, figures on the number of policies you have in place and how many users are geofenced, and a chart showing successful and failed authentications – useful for spotting efforts to penetrate your users’ accounts.</p><p>LastPass Business and Identity users can be added via a wide range of Single Sign-On portals, but admins for Teams will have to invite everyone by email. Once added, users can be assigned to groups and roles to give them access to different shared vaults and features. Admins can view each user’s saved sides, shared folders, and registered devices.</p><p>Policies can be applied to groups and individuals, and range from standard security policies to specific password and multifactor authentication requirements, blocking access from specific countries or devices, and a wealth of other settings. Our only complaint is that the policy list is a little cramped, as they’re shoved into a skinny bar at the right of the interface.</p><p>Identity tier subscribers can also roll-out LastPass’s passwordless access systems, allowing users to access their vaults more easily when connected from a specific IP address, geographic location, and enabling device authentication and biometric login models.</p><h2 id="lastpass-review-pricing">LastPass review: Pricing</h2><p>LastPass’s business offerings start with Teams, priced at £40.80 per user, per year, and intended for SMBs or workgroups with up to 50 users, although this is a recommendation rather than a hard limit. This provides each user with an industry-standard password storage vault with optional <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication</a>, shared folders for your team, and a dashboard to administrate everything.</p><p>The next tier up, Enterprise, has no recommended ceiling on user numbers, and adds <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" data-original-url="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">Single Sign-On support</a>, personal customer support, API and app integrations, and customisable security policies.</p><p>These are extremely flexible, and include settings such as requiring users to link a personal vault to keep them from using their business account to store their own day-to-day passwords, access restriction based on IP address, automatic logout windows, and highly specific control of the kind of secure data and passwords that can be stored or shared.</p><p>A more expensive Identity tier adds extra authentication options, taken from LastPass’s subscription-based multi-factor authentication toolset.</p><p>Unlike rivals including Keeper and <a href="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for" data-original-url="https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for">Bitwarden</a>, users within a Teams, Enterprise, or Identity subscription don’t get a free LastPass Personal subscription to go with it.</p><h2 id="lastpass-review-verdict">LastPass review: Verdict</h2><p>LastPass is still an industry leader, and has one of the best management interfaces around, although the lack of a desktop client for users feels like an omission in a business environment. It’s not cheap, either: Many rivals provide equivalents to the features of LastPass’s Enterprise tier, priced at £61.44 per user, per year, for less. A flat-fee site license is also available for larger businesses.</p><p>The adaptive multifactor authentication options of the top Identity tier, designed to provide users with secure and passwordless access to both their vaults and other business identity challenges, are unique, although some rivals such as Keeper are developing similar tools in parallel. LastPass Identity is certainly costly, at £81.60 per user, per year, and its comprehensive identity verification functions – also available without password management – are beyond the scope of this review.</p><p>The lack of a desktop client is an irrelevance to web-oriented personal users, but if you have staff members who’ll be accessing desktop applications and remote servers without going via a web browser, flipping to a browser plug-in just to copy out passwords can slow the workflow.</p><p>LastPass’s online vault is still great to use, and its top tiers are lavish when it comes to providing features, but for price and convenience, Bitwarden and Dashlane provide a better business password management solution right now.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bitwarden review: Worth paying for ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/software/359931/bitwarden-review-worth-paying-for</link>
                                                                            <description>
                            <![CDATA[ The competitively priced newcomer is at the forefront of password management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nNhTuoqrHnJXSFchUaZWyG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MhXaW9gbfJuGRBkwkcgKDK-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Jun 2021 10:15:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Antivirus]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ K.G. Orphanides ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/sZCck6JUYUwhUf9f8q9pWc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/MhXaW9gbfJuGRBkwkcgKDK-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A screenshot of Bitwarden&amp;#039;s password management interface]]></media:description>                                                            <media:text><![CDATA[A screenshot of Bitwarden&amp;#039;s password management interface]]></media:text>
                                <media:title type="plain"><![CDATA[A screenshot of Bitwarden&amp;#039;s password management interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MhXaW9gbfJuGRBkwkcgKDK-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bitwarden is one of the best password managers on the market today, gunning for the password management crown with a massively feature-packed, cross-platform free consumer tier. It’s also almost unique in having a free business tier which, while limited to two users, is an obvious choice for micro-businesses and partnerships.</p><p>The main drawback is that it has more limited <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">2FA options</a> and lacks support for advanced features such as attaching encrypted files to entries and password vault health reports.</p><p>Bitwarden Teams expands on this free two-person tier, with an API for easy automation, event logs, user groups, a directory connector to automatically manage users when they’re added to your corporate LDAP server, extra two-factor authentication options, password vault health analysis, and the ability to grant emergency access rights to trusted users.</p><p>For larger businesses, Bitwarden Enterprise is very competitively priced, supports <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso" data-original-url="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">SSO</a> and granular policy control, has the transparency benefit of open-source code and the convenience of a fully managed service. It’s also priced comparably to the mid- or entry-level tiers of many rivals, and if you want, you can even self-host it on your own servers with no additional licensing.</p><h2 id="bitwarden-review-client-features">Bitwarden review: Client features</h2><p>The web-based incarnation of Bitwarden’s vault and settings are more functional than beautiful. Everything’s pretty easy to find, although we’d have liked download links to the critical Bitwarden apps to be more clearly signposted. You’ll find them on the pull-down from your profile icon at the top right, or on the <a href="http://bitwarden.com/download">company's website</a>.</p><p>Dedicated desktop apps are available for Windows, macOS and Linux. Mobile apps cater to iOS and Android, with the open source F-Droid store hosting a copy for de-Googleised Android devices. An extensive range of browsers are covered, including Firefox, Safari, Chrome, and browsers that share their rendering engines, even with the unusual addition of a Tor Browser.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password" data-original-url="/security/cyber-security/354918/four-quick-tips-to-create-an-unbreakable-password">Four quick tips to create an unbreakable password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/359713/fbi-partners-with-have-i-been-pwned-on-breached-password-database" data-original-url="/security/data-breaches/359713/fbi-partners-with-have-i-been-pwned-on-breached-password-database">FBI partners with 'Have I Been Pwned' on breached password database</a></p></div></div><p>Bitwarden’s command line tool (which primarily exists to make automation easier) is available for bash and <a href="https://www.itpro.com/microsoft-windows/34535/powershell-vs-cmd-unlocking-the-power-of-windows" data-original-url="https://www.itpro.com/microsoft-windows/34535/powershell-vs-cmd-unlocking-the-power-of-windows">PowerShell</a>, and can be found via a number of package managers including NPM – the recommended install path if you’re already using node.js – Homebrew, Chocolatey and Snap.</p><p>The client is eminently easy to use and does exactly what you’d expect from a password manager. Corporate users of Bitwarden get a free personal account, which they’ll log into to access their corporate password collection. When they save a password, they'll be prompted to choose whether it belongs to their personal account or in the business’. Business passwords have to be in a collection, and the collections that each user is given access show up in their clients and online vault.</p><p>The Google Play Store version of Bitwarden’s Android client was <a href="https://reports.exodus-privacy.eu.org/en/reports/com.x8bit.bitwarden/latest">recently found to include two trackers</a>, which the company has <a href="https://bitwarden.com/help/article/security-faqs/#q-what-third-party-services-libraries-or-identifiers-are-used">convincingly justified</a> as required for push notifications and crash reporting; if you’d rather avoid them, they are not included in the version distributed on F-Droid.</p><h2 id="bitwarden-review-management-features">Bitwarden review: Management features</h2><p>Users can be invited with standard, limited privileges to access items in collections that have been assigned to them and, if they are given write access, to add, edit and delete passwords and secure notes from those collections.</p><p>Managers have the power to assign users and groups to collections, as well as to create and delete said collections. Admins can create and assign users to user groups, invite new users, manage policies, check event logs and export the organisation's vault data en masse, making this a role of trusted authority.</p><p>Only the owners can control billing, subscriptions and integrations for third-party applications and services. However, custom roles can also be created, providing granular control over exactly who gets to do what. Additional permissions are available to Enterprise admins via the Bitwarden Business portal.</p><p>We’re not too keen on this division between the main management interface and this dedicated portal for making policies and SSO. It’s easy to use, and we like the addition of features such as the ability to deny personal password ownership for organisation users and mandate specific security and password options. However, there aren’t quite as many settings here as you’ll find in comparable services from Dashlane, Keeper, and LastPass, and relatively few options are spread across rather too many pages.</p><h2 id="bitwarden-review-verdict">Bitwarden review: Verdict</h2><p>Bitwarden’s Free Organization tier, as the name suggests, is entirely free, but has limited features. For those who need more than two users and two collections, Bitwarden Teams costs $36 per user, per year or $4 per user, per month and the Enterprise tier costs $60 per user, per year or $6 per user, per month if you don’t want to commit to a full year.</p><p>This puts it among the cheapest business password management services around, and the Enterprise tier, with its fine-grained policy control, would benefit businesses of almost any size, even if they don’t need SSO. Furthermore, <a href="https://bitwarden.com/help/article/security-faqs">Bitwarden’s transparent, audited, zero-knowledge approach to security</a> is solid and <a href="https://bitwarden.com/help/security">thoroughly documented</a>.</p><p>Although its admin interface isn’t the most polished around, Bitwarden’s excellent feature set and well-designed range of cross-platform clients, as well as its low prices, make it our top pick for both <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">best password manager</a>, and <a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">best free password manager</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>