Microsoft enforces number matching to fight MFA fatigue attacks

Bleeping computer reports* Microsoft has started enforcing number matching in Microsoft Authenticator push notifications to fend off multi-factor authentication (MFA) fatigue attacks. In such attacks (also known as push bombing or MFA push spam), cybercriminals flood the targets with mobile push notifications asking them to approve attempts to log into their corporate accounts using stolen … More Microsoft enforces number matching to fight MFA fatigue attacks

VPNFilter update: More bad news for routers

New research into VPNFilter finds more devices hit by malware that’s nastier than first thought, making rebooting and remediating of routers more urgent. At the bottom of this article is a revised list of routers believed to be at particular risk from the malicious code known as VPNFilter, according to ongoing research by Cisco’s Talos … More VPNFilter update: More bad news for routers

Firms using WebEx at risk of poisoned Flash attacks

Companies should check they are running latest version of WebEx, and beware attacks via the road less travelled. A critical vulnerability has been found in Cisco’s WebEx conferencing software – widely used by businesses – that could be exploited by an attacker to spread malware directly to other meeting participants, tricking them into executing it … More Firms using WebEx at risk of poisoned Flash attacks