Get a Pentest and security assessment of your IT network.

News

Russia State-Sponsored Hackers Used Misconfigured MFA to Breach NGO

Russian hackers exploited a misconfigured Cisco Duo multifactor authentication (MFA) account at a nongovernment organization. They created a rogue account and used it to exploit a known Windows Print Spooler vulnerability, aka PrintNightmare. The FBI and CISA recommend reviewing MFA policies to prevent such a re-enrollment action, and making sure all software is updated, patched, and not prone to known flaws. The actors gained the credentials via brute-force password guessing attack, allowing them access to a victim account.”]

Source: https://www.darkreading.com/application-security/russia-state-sponsored-hackers-used-misconfigured-mfa-to-breach-ngo

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2