Security News

Fail2Ban: Ban hosts that cause multiple authentication errors
2024-05-24 05:00

Fail2Ban is an open-source tool that monitors log files, such as /var/log/auth. Log, and blocks IP addresses that exhibit repeated failed login attempts.

Authelia: Open-source authentication and authorization server
2024-05-22 04:30

Authelia is an open-source authentication and authorization server that offers 2FA and SSO for applications through a web portal. Authelia connects directly to the reverse proxy but never to the application backends.

Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass
2024-05-22 03:45

Users of Veeam Backup Enterprise Manager are being urged to update to the latest version following the discovery of a critical security flaw that could permit an adversary to bypass authentication...

Bitbucket artifact files can leak plaintext authentication secrets
2024-05-21 19:05

Threat actors were found breaching AWS accounts using authentication secrets leaked as plaintext in Atlassian Bitbucket artifact objects. As developers may not be aware that these secrets are exposed in artifact files, the source code may be published to public repositories where threat actors can steal them.

Critical GitHub Enterprise Server Flaw Allows Authentication Bypass
2024-05-21 16:16

GitHub has rolled out fixes to address a maximum severity flaw in the GitHub Enterprise Server (GHES) that could allow an attacker to bypass authentication protections. Tracked...

Microsoft to start enforcing Azure multi-factor authentication in July
2024-05-17 18:53

Starting in July, Microsoft will begin gradually enforcing multi-factor authentication for all users signing into Azure to administer resources. "Service principals, managed identities, workload identities, and similar token-based accounts used for automation are excluded. Microsoft is still gathering customer input for certain scenarios such as break-glass accounts and other special recovery processes," explained Azure product manager Naj Shahid.

6 Mistakes Organizations Make When Deploying Advanced Authentication
2024-05-14 10:51

Deploying advanced authentication measures is key to helping organizations address their weakest cybersecurity link: their human users. Having some form of 2-factor authentication in place is a...

Google Simplifies 2-Factor Authentication Setup (It's More Important Than Ever)
2024-05-07 10:02

Google on Monday announced that it's simplifying the process of enabling two-factor authentication (2FA) for users with personal and Workspace accounts. Also called, 2-Step Verification (2SV), it...

LSA Whisperer: Open-source tools for interacting with authentication packages
2024-04-26 04:30

LSA Whisperer consists of open-source tools designed to interact with authentication packages through their unique messaging protocols. "Many authentication packages generally support their internal APIs, known as package calls, and relatively few are documented or used outside of Microsoft. I wanted to document as many of these calls as possible and implement a tool for interacting with them so we could identify which would provide value for red team assessments," Evan McBroom, Senior Software Engineer at SpecterOps, told Help Net Security.

What is multi-factor authentication (MFA), and why is it important?
2024-04-23 03:30

Setting up MFA can seem daunting for consumers just beginning to clean up their security postures. In this Help Net Security video, Larry Kinkaid, Manager, Cybersecurity Consulting at BARR Advisory, shares tips for consumers who need simple, accessible ways to secure their private data.