Security News

Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors
2022-05-16 11:46

Microsoft is alerting customers that its May Patch Tuesday update is causing authentications errors and failures tied to Windows Active Directory Domain Services. "After installing updates released May 10, 2022 on your domain controllers, you might see authentication failures on the server or client for services such as Network Policy Server, Routing and Remote access Service, Radius, Extensible Authentication Protocol, and Protected Extensible Authentication Protocol," Microsoft reported.

Microsoft: May Windows updates cause AD authentication failures
2022-05-12 07:11

Microsoft is investigating a known issue causing authentication failures for some Windows services after installing updates released during the May 2022 Patch Tuesday. Microsoft says the known issue is only triggered after installing the updates on servers used as domain controllers.

Yahoo Japan strives for universal passwordless authentication
2022-05-11 08:19

Yahoo Japan has revealed that it plans to go passwordless, and that 30 million of its 50 million monthly active users have already stopped using passwords in favor of a combination of FIDO and TXT messages. A case study penned by staff from Yahoo Japan and Google's developer team, explains that the company started work on passwordless initiatives in 2015 but now plans to go all-in because half of its users employ the same password on six or more sites.

Google to Add Passwordless Authentication Support to Android and Chrome
2022-05-05 21:57

"This will simplify sign-ins across devices, websites, and applications no matter the platform - without the need for a single password," Google said.The new Fast IDentity Online sign-in system does away with passwords entirely in favor of displaying a prompt asking a user to unlock the phone when signing into a website or an application.

GitHub to require two factor authentication for code contributors by late 2023
2022-05-05 04:01

GitHub has announced that it will require two factor authentication for users who contribute code on its service. "The software supply chain starts with the developer," wrote GitHub chief security officer Mike Hanley on the company blog.

Atlassian Drops Patches for Critical Jira Authentication Bypass Vulnerability
2022-04-22 22:52

Atlassian has published a security advisory warning of a critical vulnerability in its Jira software that could be abused by a remote, unauthenticated attacker to circumvent authentication protections. Tracked as CVE-2022-0540, the flaw is rated 9.9 out of 10 on the CVSS scoring system and resides in Jira's authentication framework, Jira Seraph.

Atlassian fixes critical Jira authentication bypass vulnerability
2022-04-22 14:05

Atlassian has published a security advisory to alert that its Jira and Jira Service Management products are affected by a critical authentication bypass vulnerability in Seraph, the company's web application security framework.Seraph is used in Jira and Confluence for handling all login and logout requests via a system of pluggable core elements.

Bypassing Two-Factor Authentication
2022-04-01 11:12

Some forms of MFA are stronger than others, and recent events show that these weaker forms aren't much of a hurdle for some hackers to clear. Sending a bunch of MFA requests and hoping the target finally accepts one to make the noise stop.

Product showcase: Secure online authentication “Made in Germany” by Swissbit
2022-03-30 05:00

New iShield FIDO2 USB-A / NFC security key protects access to applications and online services. With iShield FIDO2, the industrial storage and security products specialist Swissbit now introduces its first authenticator for the FIDO2 open authentication standard.

Okta authentication company’s customer data targeted by the Lapsus$ gang
2022-03-23 14:17

Okta is a large company that provides authentication services for companies like FedEx and Moody's to enable access to their networks. Those support engineers have limited access to data.