Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

LastPass data breach exposes customer data

LastPass data breach exposes customer data
A supply chain attack targeting the market intelligence platform Klue has resulted in the theft of OAuth tokens used by several high-profile organizations. The Icarus extortion group gained access to Klue's infrastructure by exploiting a dormant legacy credential for a prototype integration service. Once inside, the threat actors exfiltrated OAuth tokens that allowed them to query connected third-party environments, specifically targeting Salesforce CRM data.

Source

Microsoft Authenticator enforces manual number matching for personal accounts

Microsoft Authenticator enforces manual number matching for personal accounts
Microsoft is updating the sign-in experience for personal accounts by requiring users to manually type a two-digit code into the Authenticator app. This replaces the previous method where users simply chose the correct number from three visible options on their mobile device. The change is being rolled out gradually to ensure all users eventually transition to this more deliberate verification process.

Source

❌