Blog | G5 Cyber Security

Weak Apple DEP Authentication Leaves Enterprises Vulnerable to Social Engineering Attacks and Rogue Devices

Duo Labs has been researching the security of Apple’s Device Enrollment Program (DEP) In this research, Duo Labs discovered an authentication weakness in DEP, used by many organizations to automatically enroll devices in their Mobile Device Management (MDM) server. This has a few real-world implications: An attacker can potentially enroll any device into an organization’s MDM server – which could allow them to obtain privileged access. Not every organization has implemented this protection, even though Apple publicly documents these best practices in their Apple Business Manager Help documentation.”]

Source: https://duo.com/blog/weak-apple-dep-authentication-leaves-enterprises-vulnerable-to-social-engineering-attacks-and-rogue-devices

Exit mobile version