<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4160+passkeys%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 04:44:26 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 04:44:26 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4160+passkeys%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hpr4160+passkeys%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694766/ai-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694430/it-security-nachrichten/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Sat, 25 Jul 2026 18:59:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer]]></title>
<description><![CDATA[Die Mail-Anbieter GMX und WEB.DE schalten ab sofort den Login per Passkey für ihre rund 38 Millionen Nutzer frei. Damit lässt sich das E-Mail-Postfach im Browser...Zum Beitrag: Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer

Wo du uns folgen kannst:
Facebook, Reddit, Googl...]]></description>
<link>https://tsecurity.de/de/3691534/it-nachrichten/passkeys-ziehen-bei-gmx-und-webde-ein-passwortloser-login-fuer-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691534/it-nachrichten/passkeys-ziehen-bei-gmx-und-webde-ein-passwortloser-login-fuer-nutzer/</guid>
<pubDate>Fri, 24 Jul 2026 14:33:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Mail-Anbieter GMX und WEB.DE schalten ab sofort den Login per Passkey für ihre rund 38 Millionen Nutzer frei. Damit lässt sich das E-Mail-Postfach im Browser...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/passkeys-ziehen-bei-gmx-und-web-de-ein-passwortloser-login-fuer-nutzer/">Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web.de und GMX rüsten Passkeys nach]]></title>
<description><![CDATA[Die United-Internet-Töchter GMX und Web.de führen jetzt Passkeys ein. Sie verbessern damit die Sicherheit und den Schutz vor Phishing.]]></description>
<link>https://tsecurity.de/de/3691429/it-security-nachrichten/webde-und-gmx-ruesten-passkeys-nach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691429/it-security-nachrichten/webde-und-gmx-ruesten-passkeys-nach/</guid>
<pubDate>Fri, 24 Jul 2026 13:42:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die United-Internet-Töchter GMX und Web.de führen jetzt Passkeys ein. Sie verbessern damit die Sicherheit und den Schutz vor Phishing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Web.de und GMX rüsten Passkeys nach]]></title>
<description><![CDATA[Die United-Internet-Töchter GMX und Web.de führen jetzt Passkeys ein. Sie verbessern damit die Sicherheit und den Schutz vor Phishing.]]></description>
<link>https://tsecurity.de/de/3691405/it-nachrichten/webde-und-gmx-ruesten-passkeys-nach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691405/it-nachrichten/webde-und-gmx-ruesten-passkeys-nach/</guid>
<pubDate>Fri, 24 Jul 2026 13:34:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die United-Internet-Töchter GMX und Web.de führen jetzt Passkeys ein. Sie verbessern damit die Sicherheit und den Schutz vor Phishing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Email threats changed after the Tycoon2FA take-down]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691276/it-nachrichten/email-threats-changed-after-the-tycoon2fa-take-down/</guid>
<pubDate>Fri, 24 Jul 2026 12:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.csoonline.com/article/4201146/tycoon2fa-takedown-reshapes-the-phishing-landscape.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tycoon2FA takedown reshapes the phishing landscape]]></title>
<description><![CDATA[Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.



“Phishing volume linked to the platform fell 92% from pre-disruption aver...]]></description>
<link>https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691257/it-security-nachrichten/tycoon2fa-takedown-reshapes-the-phishing-landscape/</guid>
<pubDate>Fri, 24 Jul 2026 12:26:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Traditional phishing techniques are in decline as a result of the <a href="https://www.csoonline.com/article/4140890/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform</a>, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.</p>



<p class="wp-block-paragraph">“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in <a href="https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/">the report</a>.</p>



<p class="wp-block-paragraph">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.</p>



<p class="wp-block-paragraph">Riding this shift in were a few notable phishing campaigns, including an automated <a href="https://www.csoonline.com/article/575559/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html">business email compromise</a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.</p>



<p class="wp-block-paragraph">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs/ subject fields, enabling password-less authentication methods, or moving to <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html">MFA</a> for accounts that still require passwords.</p>



<h2 class="wp-block-heading">Tycoon2FA disruption sent attackers exploring</h2>



<p class="wp-block-paragraph">The take-down of <a href="https://www.csoonline.com/article/4100393/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html">Tycoon2FA</a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.</p>



<p class="wp-block-paragraph">“After falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,” Microsoft said.</p>



<p class="wp-block-paragraph">The decline extended to QR Code <a href="https://www.csoonline.com/article/3557585/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html">lures</a> and fake CAPTCHA <a href="https://www.csoonline.com/article/3829416/fake-captcha-attacks-are-increasing-say-experts.html">pages</a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform’s customer base had not been able to migrate to a replacement infrastructure.</p>



<p class="wp-block-paragraph">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.</p>



<p class="wp-block-paragraph">The adaptation came in the form of using Microsoft <a href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html">Teams as a social engineering channel</a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. “Teams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,” Microsoft said.</p>



<p class="wp-block-paragraph">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft’s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.</p>



<h2 class="wp-block-heading">Phishing changes but the defense doesn’t</h2>



<p class="wp-block-paragraph">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.</p>



<p class="wp-block-paragraph">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.</p>



<p class="wp-block-paragraph">BEC attacks hit 9 million in March, falling to 3.9 million in June.</p>



<p class="wp-block-paragraph">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft’s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href="https://www.csoonline.com/article/3535222/mfa-adoption-is-catching-up-but-is-not-quite-there.html">MFA</a> to reduce the effectiveness of credential theft campaigns.</p>



<p class="wp-block-paragraph">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">FIDO </a>keys, and Microsoft Authenticator.</p>



<p class="wp-block-paragraph">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing-Fallen: KI-Mails, QR-Codes, falsche Warnungen – so schützen Sie sich]]></title>
<description><![CDATA[Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch s...]]></description>
<link>https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691032/windows-tipps/phishing-fallen-ki-mails-qr-codes-falsche-warnungen-so-schuetzen-sie-sich/</guid>
<pubDate>Fri, 24 Jul 2026 10:47:37 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zwei große Änderungen hat es in den vergangenen Jahren bei Phishing-Angriffen gegeben: Die Kriminellen erstellen mithilfe von generativer KI sprachlich fast perfekte Mails, die in Stil, Struktur und Tonalität kaum noch von legitimen Nachrichten zu unterscheiden sind. Wo früher holpriges Deutsch sofort Misstrauen geweckt hat, liest sich heute eine Phishing-Mail wie eine echte Mitteilung von Microsoft, einer Bank oder einem Paketdienst.</p>



<p>Auch das Design wirkt meist höchst professionell. Zum anderen sind auch die technischen Tricks beim Datendiebstahl heute höher entwickelt. Einige Maschen umgehen sogar eine Zwei-Faktor-Authentifizierung. Das Ziel der Angreifer bleiben vor allem Zugangsdaten, Session-Tokens und persönliche Infos.</p>



<h2 class="wp-block-heading">1. Microsoft-365-Log-in-Falle trickst Zwei-Faktor-Anmeldung aus</h2>



<p>Eine neue Angriffsmethode verwendet den originalen Microsoft-Anmeldedialog und kommt entsprechend fast ohne gefälschte Webseiten aus. Die Kriminellen nutzen dafür den Oauth-Device-Code-Flow. Das ist ein Anmeldeverfahren für Geräte oder Programme, die keinen brauchbaren Browser oder keine komfortable Texteingabe bieten, etwa Smart-TVs, IoT-Geräte, Drucker oder CLI-Tools. </p>



<p>Offiziell heißt er „OAuth 2.0 Device Authorization Grant“. Mit der Methode lassen sich auch Konten übernehmen, die mit einer Zwei-Faktor-Authentifizierung geschützt sind.</p>



<p>Die Kriminellen schicken an ihre Opfer eine Phishing-Nachricht und geben vor, das Gerät der Opfer müsste für den Log-in ins Microsoft-365-Konto neu autorisiert werden. Die Nachrichten beginnen meist harmlos, etwa mit „Ihre Sitzung ist abgelaufen“, und bieten einen Link zur Neuanmeldung. Wenn das Opfer dem Link in der Nachricht folgt, landet es zunächst auf einer gefälschten Website, schließlich aber beim offiziellen Microsoft-Authentifizierungsverfahren für Geräte und Anwendungen (Oauth-Device-Code-Flow).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269712915"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-M365-Phishing-Quelle-Proofpoint.jpg?quality=50&amp;strip=all" alt="Phishing Fallen M365 Phishing Quelle Proofpoint" class="wp-image-3187589" width="1140" height="1082" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bei diesem Trick übernehmen die Angreifer auch Konten, die mit einem zweiten Faktor geschützt sind. Dafür kombinieren sie die echten Authentifizierungsseiten von Microsoft und Phishing-Webseiten.</p></figcaption></figure><p class="imageCredit">Proofpoint</p></div>



<p>Es handelt sich um echte Microsoft-Meldungen und Webseiten. Allerdings autorisiert das Opfer nicht den Zugang zu seinem eigenen PC oder Smartphone, sondern eine Anwendung der Kriminellen. Diese bekommen nach der Freigabe durch das getäuschte Opfer einen Access-Token. Damit kann die feindliche Anwendung per API auf das Microsoft-Konto zugreifen, ohne dass noch einmal ein Passwort eingegeben werden muss.</p>



<p>Übrigens: Die meisten dieser Angriffe verstecken den Link zur gefälschten Website in einem QR-Code. Dieser entgeht den Spam-Filtern eher als ein üblicher Link, und es lässt die meisten Opfer vom PC auf das Smartphone wechseln. </p>



<p>Auf diesem ist es wegen des kleineren Bildschirms und oft fehlender Sicherheits-Software noch wahrscheinlicher, dass das Opfer die Täuschung nicht bemerkt. <a href="https://tinyurl.com/2xhd6n6d" target="_blank" rel="noreferrer noopener">Eine ausführliche Analyse der Angriffe auf Microsoft-365-Konten haben die Sicherheitsexperten von Proofpoint veröffentlicht</a>.</p>



<h2 class="wp-block-heading">2. Support-Masche: Ihr Computer ist gesperrt &amp; Co.</h2>



<p>Die Support-Masche ist zwar nicht neu, funktioniert aber nach wie vor: Noch immer fallen zahlreiche Menschen auf die perfide Betrugsstrategie herein. Zu den prominenten Opfern zählt Bundestagspräsidentin Julia Klöckner. </p>



<p>Mutmaßlich staatlich organisierte Angreifer kontaktierten sie über den Messenger-Dienst Signal und gaben sich als vermeintliche Signal-Support-Mitarbeiter aus. Unter einem Vorwand forderten sie Klöckner und weitere Politiker auf, ihre PIN einzugeben. Dadurch erlangten die Angreifer Zugriff auf die Signal-Konten der Betroffenen – und damit auf private Chats und Kontakte.</p>



<p>Das Bundesamt für Verfassungsschutz und das Bundesamt für Sicherheit in der Informationstechnik (BSI) haben gemeinsam einen <a href="https://tinyurl.com/yc89cfjd" target="_blank" rel="noreferrer noopener">Leitfaden veröffentlicht</a>, der potenziellen Opfern hilft zu prüfen, ob ihr Signal-Konto übernommen wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697134c5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-MS-Support-Quelle-Bundesnetzagentur.png" alt="Phishing Fallen MS Support Quelle Bundesnetzagentur" class="wp-image-3187588" width="938" height="640" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Phishing mit der Support-Masche. Durch eine vorgetäuschte Windows- oder Defender-Warnung werden Sie zu einem Telefongespräch mit den Angreifern gedrängt.</p></figcaption></figure><p class="imageCredit">Bundesnetzagentur</p></div>



<p>Ebenfalls weiterhin verbreitet sind Angriffe durch angebliche Microsoft-Support-Mitarbeiter. Die Betrüger kontaktieren ihre Opfer per Telefon, E-Mail oder über gefälschte Pop-up-Warnungen im Browser. </p>



<p>Dabei behaupten sie, der Windows-PC habe ein Sicherheitsproblem – etwa sei der Computer gesperrt oder mit Schadsoftware infiziert. Anschließend versuchen sie, die Betroffenen zur Installation einer Fernwartungssoftware oder eines vermeintlichen Sicherheitstools zu bewegen. Tatsächlich erhalten die Angreifer dadurch oft vollständigen Zugriff auf den Rechner.</p>



<h2 class="wp-block-heading">3. Gefälschter Microsoft Defender warnt</h2>



<p>Der Microsoft Defender ist ein Windows-Bordmittel und schützt PCs gegen alle bekannten PC-Viren. Entsprechend alarmierend ist für viele Nutzer eine Warnung dieses Antiviren-Tools. Eine gefälschte Form dieser Warnung erscheint mal per E-Mail, mal als Pop-up im Browser. In diesen Nachrichten wird behauptet, der Schutz des Defenders müsse kostenpflichtig erneuert werden. In der Folge werden die Nutzer auf gefälschte Shop-Webseiten geleitet, die eine Zahlung für einen Virenschutz verlangen.</p>



<p>Grundsätzlich gilt: Der Microsoft Defender ist auf Privat-PCs ein Bordmittel und kostenlos in Windows enthalten. Eine Zahlung ist nicht nötig. Sollte die Warnung per Mail bei Ihnen landen, löschen Sie diese einfach. Schlägt sie als Pop-up im Browser auf, schließen Sie einfach das Browser-Fenster, notfalls mit der Tastenkombination „Alt+F4”. </p>



<p><a href="https://tinyurl.com/yaz82hf3" target="_blank" rel="noreferrer noopener">Der Antivirenspezialist Norton hat eine Anleitung veröffentlicht</a>, die erklärt, wie sich solche Pop-up-Warnungen im Browser beseitigen lassen, falls sie sich im System festgesetzt haben.</p>



<h2 class="wp-block-heading">4. Microsoft-Onedrive: Cloud-Phishing über Freigaben</h2>



<p>Cloud-Dienste wie Onedrive von Microsoft nutzen viele Windows-Nutzer mehrmals täglich. Genau deshalb sind sie ein attraktives Ziel für Phishing. Statt klassischer E-Mails mit Dateianhängen erhalten die Nutzer Freigabe-Benachrichtigungen mit einem Betreff wie „Dokument wurde mit Ihnen geteilt“. Der Inhalt wirkt meist harmlos und oft beruflich relevant: Rechnungen, Projektpläne, Gehaltslisten oder interne Dokumente.</p>



<p>Besonders tückisch ist die Kombination aus echten und gefälschten Elementen. Manche Angriffe nutzen tatsächlich legitime Cloud-Plattformen, bieten dort aber manipulierte Dokumente an. Das Ziel dieser Angriffe sind mehrheitlich die Log-in-Daten der Opfer zu Ihren Cloud- und Mail-Konten. Diese werden dann von den Angreifern übernommen und etwa für neue Phishing-Attacken genutzt.</p>



<h2 class="wp-block-heading">5. Lieferdienste, Lieferdienste und noch mal Lieferdienste</h2>



<p>Phishing im Namen von Paketdiensten gehört zu den stabilsten Angriffsmustern überhaupt und wird gleichzeitig immer ausgefeilter. Der Grund ist die hohe Alltagstauglichkeit: Fast jeder erwartet regelmäßig Lieferungen und ist deshalb kaum misstrauisch, wenn eine Mail, SMS oder Whatsapp zum Thema Paketversand eintrudelt. Moderne Varianten enthalten nicht nur einfache Textlinks, sondern vollständige Tracking-Systeme.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697140c0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing.png?w=1200" alt="Phishing Fallen Paket Phishing" class="wp-image-3187584" width="1200" height="539" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Hier sehen Sie vier Schritte eines vorgeblichen Lieferdienstes, der Ihnen ein Paket zustellen möchte. In weiteren Schritten sollen Sie Ihr Kundenkonto mit persönlichen Daten vervollständigen und eine Expresslieferung bezahlen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Diese Seiten sind dynamisch aufgebaut und simulieren echte Logistikprozesse. Beim Sendungsverlauf heißt es dann etwa: „Zustellung fehlgeschlagen – bitte Adresse bestätigen“ oder „Letzte Möglichkeit zur Terminänderung“. Besonders kritisch ist die Kombination aus Zeitdruck und Kontext. Wer Opfer eines solchen Angriffs wird, gibt meist seine Log-in-Daten für Shopping- oder Zahlungsdienste preis. Oder er überweist den Angreifern direkt Geld, da angeblich Steuern, Bearbeitungsgebühren oder ein Expresszuschlag fällig sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697149f8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Paket-Phishing-Bezahlung.png?w=1200" alt="Phishing Fallen Paket Phishing Bezahlung" class="wp-image-3187585" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine Phishing-Webseite eines vorgeblichen Lieferdienstes, die hier eine Nachzahlung abrechnen möchte, bevor das Paket zugestellt werden kann.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p>Übrigens: Ab dem 1. Juli 2026 gibt es zusätzliche Abgaben auf Sendungen aus Nicht-EU-Ländern. Für Waren unter 150 Euro sind dann pauschal 3 Euro Zollgebühr und eine Einfuhrumsatzsteuer fällig. Einige Kurierdienste verlangen zusätzlich eine Servicepauschale für diese Zollanmeldung. Über die genauen Kosten informiert <a href="https://tinyurl.com/sztfupt4" target="_blank" rel="noreferrer noopener">eine Seite der Verbraucherzentrale NRW</a>. Es lohnt sich, die tatsächlichen Kosten zu kennen, denn es ist wahrscheinlich, dass zu diesem Termin vermehrt Phishing-Mails zu diesem Thema versendet werden.</p>



<h2 class="wp-block-heading">6. Phishing zu Online-Banking gibt es immer</h2>



<p>Phishing zum Online-Banking gibt es fast schon so lange wie das Online-Banking selbst. Die Bedrohungslage ist aber so angespannt wie nie, denn die Angriffe sind nun wirklich zahlreich. <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Über die neuesten Phishing-Fallen informieren unter anderem die Verbraucherzentralen</a>.</p>



<p>Beispiele aus dem Mai 2026 lauten etwa so: „Bestätigung Ihrer Mobilfunknummer erforderlich“. Absender ist vorgeblich die Easybank. Eine Fälschung von Commerzbank-Mails warnt vor einem fälligen „Photo-TAN Update“, bei dem ein „einmaliger Abgleich der Zugangsdaten“ nötig ist. </p>



<p>Andere Phishing-Mails geben vor, von der Deutschen Bank zu sein, und fordern eine Reaktivierung des „photoTAN-Sicherheitszertifikats“. Auch Kunden der DKB erhielten im Mai Phishing-Mails.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a632697157e7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-commerzbank2-Quelle-Verbraucherzentrale.png" alt="Phishing Fallen commerzbank2 Quelle Verbraucherzentrale" class="wp-image-3187583" width="460" height="665" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Eine aktuelle Phishing-Mail, die auf Kunden der Commerzbank abzielt. Im Text wird ordentlich Druck aufgebaut. Wer nicht reagiert, verliert angeblich „am nächsten Werktag“ den Zugriff auf sein Bankkonto.</p></figcaption></figure><p class="imageCredit">Verbraucherzentrale</p></div>



<p>Sollten Sie eine Mail von Ihrer Bank bekommen, klicken Sie auf keinen Fall auf einen der Links in dieser Mail. Wenn Sie sich unsicher sind, ob Sie reagieren sollen, rufen Sie die Website Ihrer Bank über Ihren Browser auf. </p>



<p>Sollte es tatsächlich ein Anliegen der Bank geben, wird es Ihnen nach dem Einloggen in Ihr Online-Konto angezeigt. Oder Sie rufen Ihre Bank einfach per Telefon an und fragen, ob Informationen von Ihnen benötigt werden.</p>



<h2 class="wp-block-heading">7. Phishing per Post: Kreditbetrug per Postident-Verfahren</h2>



<p>Diese Phishing-Angriffe erreichen Sie per Post in Ihrem echten Briefkasten. Die Briefe geben vor, von Ihrer Bank zu stammen, und fordern Sie auf, Ihre Daten erneut per Postident zu bestätigen. Postident ist ein Verfahren der Post, mit dem Sie Ihre Identität gegenüber anderen, etwa einer neuen Bank oder einem Kreditinstitut, bestätigen können. Wer das beigefügte Schreiben nutzt, legitimiert in der Regel einen hohen Kredit bei einer anderen Bank.</p>



<p>Schäden von 15.000 bis 25.000 Euro sind hier keine Seltenheit. Vorangegangen ist meist ein Diebstahl Ihrer genauen Daten (Postadresse, Hausbank, Arbeitgeber, Verdienst), den die Angreifer dann nutzen. An die Daten kommen die Kriminellen etwa über gefälschte Wohnungsinserate bei Immoscout24 oder ähnlichen Portalen. Wer sich auf eine Wohnung oder ein Haus mit Gehaltszetteln und weiteren Angaben bewirbt, hat bereits alle wichtigen Daten für den Postident-Betrug verraten. Seien Sie beim Postident-Verfahren stets besonders vorsichtig. Konkrete Tipps lesen Sie <a href="https://tinyurl.com/bdbnmxhn" target="_blank" rel="noreferrer noopener">hier</a>.</p>



<h2 class="wp-block-heading">Sicherheitstipps: Phishing erkennen und blockieren</h2>



<p><strong>An diesen Merkmalen erkennen Sie betrügerische Nachrichten:</strong></p>



<ul class="wp-block-list">
<li><strong>Unverlangter Kontakt:</strong> Sie erhalten eine E-Mail, Whatsapp oder SMS über eine Gutschrift, eine Lastschrift oder andere finanzielle Ansprüche, obwohl Sie aktuell keine Buchung storniert oder reklamiert haben.</li>



<li><strong>Zeitdruck:</strong> Die Nachricht suggeriert dringenden Handlungsbedarf und fordert zur schnellen Reaktion auf.</li>



<li><strong>Verdächtige Links:</strong> Die Links in der Nachricht sind hinter einem QR-Code maskiert, führen zu unpassenden Domains oder sind ungewöhnlich lang.</li>



<li><strong>Aufforderung zur Dateneingabe:</strong> Seriöse Unternehmen fordern in Nachrichten oder Mails nur äußerst selten zur Eingabe sensibler Daten auf.</li>



<li><strong>Unpersönliche Anrede:</strong> Oft fehlt die namentliche Ansprache oder es werden generische Formulierungen verwendet.</li>
</ul>



<p><strong>Diese Maßnahmen schützen vor Phishing-Fallen:</strong></p>



<ul class="wp-block-list">
<li><strong>E-Mail, SMS und Whatsapp &amp; Co. sind keine geschlossenen Nachrichtenkanäle:</strong> Sie müssen damit rechnen, auch betrügerische Nachrichten zu erhalten.</li>



<li><strong>Misstrauen Sie Links in Nachrichten:</strong> Klicken Sie keine Links an und scannen Sie keine QR-Codes, wenn Log-in-, Zahlungs- oder Sicherheitsaufforderungen in der Mail stehen. Öffnen Sie den jeweiligen Dienst im Browser über die manuelle Eingabe der Adresse.</li>



<li><strong>Nutzen Sie Browser und Passwortmanager als Frühwarnsystem: </strong>Wenn Ihr <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwortmanager</a> Ihre Log-in-Daten auf einer Webseite nicht einfügen möchte, dann ist die Domain vermutlich gefälscht. Achten Sie zudem auf die Warnungen Ihres Browsers.</li>



<li><strong>MFA aktivieren: </strong>Nutzen Sie immer eine Zwei- oder Multifaktor-Authentifizierung, wenn diese angeboten wird. Vor allem <a href="http://www.pcwelt.de/2107907" target="_blank" rel="noreferrer noopener">Passkeys</a> erhöhen die Sicherheit.</li>



<li><strong>Remote-Support misstrauen: </strong>Installieren Sie keine Fernwartungs-Tools, nachdem Sie unaufgefordert kontaktiert wurden.</li>



<li><strong>Freigaben hinterfragen: </strong>Wenn Sie Freigaben für Dateien in Cloud-Speichern erhalten, kontaktieren Sie zunächst den Absender, idealerweise telefonisch.</li>
</ul>



<p>Infos zu aktuellen Angriffen: Informieren Sie sich über Phishing-Kampagnen etwa bei der <a href="https://tinyurl.com/y58m5smy" target="_blank" rel="noreferrer noopener">Verbraucherzentrale NRW</a>.</p>



<p><strong>Als letzte Verteidigungslinie lassen sich Antivirenprogramme, Browserschutz und Spezial-Tools einsetzen:</strong></p>



<ul class="wp-block-list">
<li><strong>Antivirus:</strong> Große Sicherheits-Suiten wie <a href="https://www.awin1.com/cread.php?awinmid=14693&amp;awinaffid=486277&amp;clickref=rss&amp;platform=dl&amp;ued=http://www.gdata.de" target="_blank" rel="noreferrer noopener">G Data Internet Security</a> filtern Phishing-Mails heraus, bevor sie diese Nachrichten öffnen.</li>



<li><strong>Browser-Schutz: </strong>Browser von Sicherheitsanbietern blockieren viele aktuelle Phishing-Seiten, etwa der <a href="https://neobrowser.ai/" target="_blank" rel="noreferrer noopener">KI-Browser Norton Neo</a>.</li>



<li><strong>Spezial-Tools:</strong> KI-Chatbots wie <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11660&amp;clickref=rss&amp;ued=http://www.bitdefender.com/de-de/consumer/scamio" target="_blank" rel="noreferrer noopener">Scamio von Bitdefender</a> begutachten verdächtige Nachrichten und warnen vor gefährlichen Inhalten.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a63269717055"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Phishing-Fallen-Verdaechtige-Website-blockiert-Neo.png?w=1200" alt="Phishing Fallen Verdaechtige Website blockiert Neo" class="wp-image-3187587" width="1200" height="645" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Einen guten Phishing-Schutz erhalten Sie beispielsweise über Browser von Sicherheitsanbietern wie hier dem Browser Norton Neo.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit]]></title>
<description><![CDATA[A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and other information, according to a joint cybersecurity advisory issued in July 2026.

The activ...]]></description>
<link>https://tsecurity.de/de/3690812/it-security-nachrichten/russian-linked-hackers-target-zimbra-users-with-zero-day-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690812/it-security-nachrichten/russian-linked-hackers-target-zimbra-users-with-zero-day-exploit/</guid>
<pubDate>Fri, 24 Jul 2026 08:25:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Zimbra-phishing-campaign.gif" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Zimbra phishing campaign" decoding="async" title="Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit 1"></p>A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and other information, according to a joint cybersecurity advisory issued in July 2026.

The activity has been linked primarily to LAUNDRY BEAR, a Russian state-supported advanced persistent threat (APT) group tracked under several names across the cybersecurity industry. The advisory said the campaign has been active since at least July 2025 and has targeted organizations using the Zimbra Collaboration Suite (ZCS).

Unlike conventional phishing attacks that typically require victims to click a malicious link or open an attachment, the campaign uses a view-based <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="29111">exploit</a>. A user only needs to view a malicious email in a vulnerable version of ZCS webmail for the exploit to attempt execution.
<h3><strong>Zimbra Phishing Campaign Uses CVE-2025-66376</strong></h3>
The campaign centers on CVE-2025-66376, a vulnerability that was initially exploited as a <a href="https://thecyberexpress.com/zero-day-vulnerability-microsoft-sharepoint/" target="_blank" rel="noopener">zero-day vulnerability </a>before a patch was released. According to the <a href="https://www.ic3.gov/CSA/2026/260723.pdf" target="_blank" rel="nofollow noopener">advisory</a>, the activity began in July 2025, months before the vulnerability was published and patched.

The <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29110">vulnerability</a> allows a JavaScript payload contained in email content to execute because of improper sanitization of CSS @import directives within an email. The malicious payload uses Base64 encoding and XOR encryption and can be modified to help bypass basic threat detection signatures.

Once triggered, the payload attempts to collect and exfiltrate information through 12 stages. These include gathering the victim's email address and environment information, collecting two-factor authentication codes and application passwords, attempting to capture saved passwords, enabling mail protocols, gathering the Global Address List (GAL), and sending archived email <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29112">data</a>.

The advisory said the campaign's use of a zero-day exploit demonstrates the ability of LAUNDRY BEAR to operationalize novel <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29108">vulnerabilities</a> into a successful attack capability.
<h3><strong>LAUNDRY BEAR Targets Email and Sensitive Data</strong></h3>
The primary objective of the Russian state-supported <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29109">cyber</a> actors appears to be the covert acquisition of email data. The campaign attempts to steal the last 90 days of email communications, email addresses, passwords, the organization's Global Address List, 2FA tokens and newly created application passcodes.

The actors have targeted organizations connected to the defense industrial base, government, education, energy, law enforcement, media, non-governmental organizations and technology sectors.

The advisory said LAUNDRY BEAR likely identifies organizations with publicly exposed Zimbra infrastructure through port scanning and commercially available datasets. It may then compile individual user email addresses using commercial data, open-source intelligence or previously exfiltrated information.

The group has also used compromised accounts to distribute <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29114">phishing</a> emails. Since at least November 2025, malicious emails were reportedly sent from victim infrastructure, potentially using previously compromised accounts to make the activity harder to detect and to bypass anti-phishing measures.
<h3><strong>Ulej and Flowerbed Support Email Data Exfiltration</strong></h3>
The campaign uses a custom capability called Ulej, which was developed to exploit ZCS and exfiltrate sensitive information. The collected data is sent to infrastructure associated with the Flowerbed framework.

Flowerbed is a Python project using Docker and includes four containers: Catcher, Certbot, Nginx and Gardener. Catcher receives and aggregates stolen information, while Nginx operates as an HTTPS reverse proxy. The framework uses DNS and HTTPS channels for <a href="https://thecyberexpress.com/ai-driven-phishing-campaign/" target="_blank" rel="noopener">email data exfiltration</a>.

The advisory said the campaign can exfiltrate email content, contacts, attachments, authentication information and other data. The stolen information is initially stored by Catcher before being transferred to non-public-facing infrastructure.

The report also noted indications that artificial intelligence may have played a role in developing the Flowerbed codebase, highlighting the increasing use of AI in developing malicious capabilities.
<h3><strong>Organizations Urged to Patch Vulnerable Zimbra Systems</strong></h3>
The advisory urged organizations using ZCS to immediately ensure their systems are not running vulnerable versions. A patch for CVE-2025-66376 was released for ZCS versions 10.1.13 and 10.0.18.

If immediate patching is not possible, organizations are advised to have employees use alternative mail clients and avoid the Classic ZCS webmail client until the software is updated.

<a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29107">Security</a> teams are also advised to monitor internet-connected ZCS systems, workstations accessing those systems and network traffic for signs of suspicious activity. Recommended monitoring includes looking for large outbound data transfers to unfamiliar VPS providers, unusual DNS queries with random subdomains, sudden connections to newly established domains and connections involving <a class="wpil_keyword_link" href="https://thecyberexpress.com/how-to-get-a-vpn/" title="VPN" data-wpil-keyword-link="linked" data-wpil-monitor-id="29113">VPN</a> providers such as Mullvad.

Organizations should also consider authentication services that support passkeys and maintain network monitoring, packet capture or NetFlow data and relevant logs.

The advisory further recommends that organizations identifying victims revoke Application Passcodes and 2FA scratch keys and require affected employees to change their passwords. Security teams should also investigate the original phishing email and quarantine similar messages to prevent further exploitation and data theft.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr]]></title>
<description><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></description>
<link>https://tsecurity.de/de/3690810/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690810/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</guid>
<pubDate>Fri, 24 Jul 2026 08:19:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained]]></title>
<description><![CDATA[Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices. The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic. This article has been indexed…
Read more ...]]></description>
<link>https://tsecurity.de/de/3690043/it-security-nachrichten/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690043/it-security-nachrichten/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/</guid>
<pubDate>Thu, 23 Jul 2026 21:11:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices. The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/">Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained]]></title>
<description><![CDATA[Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices.
The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3690015/it-nachrichten/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690015/it-nachrichten/windows-11-security-cheat-sheet-bitlocker-passkeys-and-defender-explained/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-windows-11-security-cheat-sheet/">Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FalconID: Third-Party Passkeys]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:3 Passwords and traditional MFA remain common targets for phishing and credential theft. FalconID extends phishing-resistant, FIDO2-based passkeys to third-party applications, enabling secure, passwordless authentication across platforms like Entra ID, ...]]></description>
<link>https://tsecurity.de/de/3689966/it-security-video/falconid-third-party-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689966/it-security-video/falconid-third-party-passkeys/</guid>
<pubDate>Thu, 23 Jul 2026 20:24:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:3 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ipgkI3A9ubM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Passwords and traditional MFA remain common targets for phishing and credential theft. FalconID extends phishing-resistant, FIDO2-based passkeys to third-party applications, enabling secure, passwordless authentication across platforms like Entra ID, Okta, GitHub, and Salesforce.<br />
<br />
Passkeys are device-bound, centrally managed through the Falcon console, and continuously protected by Falcon security signals—allowing organizations to revoke access instantly when risk changes.<br />
<br />
🛡️ Falcon ID<br />
Learn more here: https://cs.link/urLrS<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #Cybersecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Goodbye SMS or phone calls — Microsoft is making passkeys the default authentication process for businesses]]></title>
<description><![CDATA[Microsoft says SMS and phone call authentication isn't up to the task anymore – and urges businesses to adopt passkeys.]]></description>
<link>https://tsecurity.de/de/3689745/it-nachrichten/goodbye-sms-or-phone-calls-microsoft-is-making-passkeys-the-default-authentication-process-for-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689745/it-nachrichten/goodbye-sms-or-phone-calls-microsoft-is-making-passkeys-the-default-authentication-process-for-businesses/</guid>
<pubDate>Thu, 23 Jul 2026 18:53:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft says SMS and phone call authentication isn't up to the task anymore – and urges businesses to adopt passkeys.]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite]]></title>
<description><![CDATA[Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Executive summary 
A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboratio...]]></description>
<link>https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689407/sicherheitsluecken/russian-state-supported-cyber-actors-conduct-phishing-campaign-targeting-users-of-zimbra-collaboration-suite/</guid>
<pubDate>Thu, 23 Jul 2026 16:59:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite</a></div>
<h2><strong>Executive summary</strong> </h2>
<p>A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see <a href="https://www.cisa.gov/#cyber1">Cybersecurity industry tracking</a>), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [<a href="https://www.cisa.gov/#wc1">1</a>].</p>
<p>LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities.</p>
<p>Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section.</p>
<p>This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies:</p>
<ul>
<li>United States National Security Agency (NSA)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Netherlands General Intelligence and Security Service (AIVD)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Defense Counterintelligence and Security Agency (DCSA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Department of the Treasury</li>
<li>United States Naval Criminal Investigative Service (NCIS)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
<li>Czech Republic National Cyber and Information Security Agency (NÚKIB)<a href="https://www.cisa.gov/#f1"><sup>1</sup></a></li>
<li>Danish Defence Intelligence Service (DDIS)<a href="https://www.cisa.gov/#f2"><sup>2</sup></a></li>
<li>Estonian Foreign Intelligence Service (EFIS)<a href="https://www.cisa.gov/#f3"><sup>3</sup></a></li>
<li>Finnish Defence Intelligence (FDI)<a href="https://www.cisa.gov/#f4"><sup>4</sup></a></li>
<li>Finnish Security and Intelligence Service (SUPO)<a href="https://www.cisa.gov/#f5"><sup>5</sup></a></li>
<li>French General Directorate for Internal Security (DGSI)<a href="https://www.cisa.gov/#f6"><sup>6</sup></a></li>
<li>French National Cybersecurity Agency (ANSSI)<a href="https://www.cisa.gov/#f7"><sup>7</sup></a></li>
<li>Italian External Intelligence and Security Agency (AISE)<a href="https://www.cisa.gov/#f8"><sup>8</sup></a></li>
<li>Italian Internal Intelligence and Security Agency (AISI)<a href="https://www.cisa.gov/#f9"><sup>9</sup></a></li>
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM)<a href="https://www.cisa.gov/#f10"><sup>10</sup></a></li>
<li>Polish Foreign Intelligence Agency (AW)<a href="https://www.cisa.gov/#f11"><sup>11</sup></a></li>
<li>The Military Counterintelligence Service of Poland (SKW)<a href="https://www.cisa.gov/#f12"><sup>12</sup></a></li>
<li>Spain National Intelligence Centre (CNI)<a href="https://www.cisa.gov/#f13"><sup>13</sup></a></li>
<li>Sweden National Cyber Security Centre (NCSC-SE)<a href="https://www.cisa.gov/#f14"><sup>14</sup></a></li>
</ul>
<p>The authoring agencies urge any organizations using ZCS to implement the recommendations listed within the <a href="https://www.cisa.gov/#mitigations1">Mitigations</a> section of this advisory to reduce the risk associated with this activity. This CSA also includes specific remediations for organizations to implement if they discover the presence of the listed <a href="https://www.cisa.gov/#ioc1">Indicators of compromise</a> (IOCs).  </p>
<p>As more organizations update their ZCS software based on this CSA, LAUNDRY BEAR may discontinue the current campaign exploiting this vulnerability; however, based on the success of this and previous campaigns, it is very likely that the group will continue to target ZCS and other email systems used by organizations in Western countries. The actors will almost certainly continue to rely on email to engage potential victims by exploiting novel vulnerabilities and, when necessary, use social engineering techniques to assist with their efforts. The authoring agencies recommend organizations regularly update their mail service software and continuously monitor their email systems and emails for malicious activity.</p>
<p>For a downloadable list of IOCs, see:</p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.xml">AA26-204A.stix.xml</a> (STIX XML)</li>
<li><a href="https://www.cisa.gov/sites/default/files/2026-07/AA26-204A.stix_.json">AA26-204A.stix.json</a> (STIX JSON)</li>
</ul>
<h2><strong>Cybersecurity industry tracking</strong><a class="ck-anchor"></a></h2>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, indicators of compromise (IOCs), and mitigation recommendations related to these Russian state-supported cyber actors. While not exhaustive, the following are threat group names commonly used for these actors within the cybersecurity community:</p>
<ul>
<li>LAUNDRY BEAR</li>
<li>Void Blizzard [<a href="https://www.cisa.gov/#wc2">2</a>]</li>
<li>CL-STA-1114 [<a href="https://www.cisa.gov/#wc3">3</a>]</li>
<li>TA488 (formerly UNK_PitStop) [<a href="https://www.cisa.gov/#wc4">4</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. government’s understanding for all activity related to these groupings.</p>
<h2><strong>Background</strong></h2>
<p>Public advisories from Netherlands General Intelligence and Security Service (AIVD), Netherlands Defence Intelligence and Security Service (MIVD), and Microsoft highlighted these Russian state-supported advanced persistent threat (APT) actors in May 2025, calling them LAUNDRY BEAR and Void Blizzard respectively [<a href="https://www.cisa.gov/#wc1">1</a>] [<a href="https://www.cisa.gov/#wc2">2</a>]. Both advisories assessed that the group was engaged in malicious cyber activity as early as April 2024.  </p>
<p>The May 2025 advisories highlighted a cluster of activity targeting cloud-based email environments, including Microsoft Exchange in particular, and abusing legitimate APIs to perform data exfiltration in bulk [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank">T1114.002</a>]. The group relied on unsophisticated means of initial access, including procuring stolen credentials on criminal marketplaces [<a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank">T1078</a>], and using social engineering techniques to lure targets into interacting with a malicious site masquerading as a legitimate one. As of April 2025, one of these sites resembled a European Defence &amp; Security Summit registration portal that required registrants to sign in to their Microsoft account to view. Once a user entered their Microsoft credentials into this malicious site, LAUNDRY BEAR’s modified version of the open source adversary emulation toolkit, Evilginx, intercepted the user’s credentials. LAUNDRY BEAR then used this authentication data, including passwords and session tokens, to access the compromised account and conduct mass email exfiltration, as well as harvest other information. This method of compromise is commonly known as an adversary-in-the-middle (AiTM) technique [<a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank">T1557</a>].  </p>
<p>Beginning around July 2025, LAUNDRY BEAR shifted toward a more technical method of email compromise, highlighting their continued efforts to covertly acquire email communications from a variety of Western organizations of interest and deliver them to the Russian Federation. Using a custom-developed capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank">T1587.001</a>] named “<em>Улей</em>” or “<em>Ulej</em>” (Russian for beehive), LAUNDRY BEAR successfully targeted and exfiltrated sensitive user information from organizations who use the Zimbra Collaboration Suite (ZCS) product [<a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank">T1114</a>]. Data LAUNDRY BEAR attempted to exfiltrate from compromised accounts included:</p>
<ul>
<li>Last 90 days of emails,</li>
<li>Email address,</li>
<li>Password [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank">T1589.001</a>],</li>
<li>Global Address List (GAL) [<a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank">T1087</a>],</li>
<li>Two-factor authentication (2FA) tokens, and</li>
<li>Newly-created Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank">T1098</a>].</li>
</ul>
<p>The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing. Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.</p>
<h2><strong>Targeting details</strong></h2>
<p>LAUNDRY BEAR has targeted and compromised users in various organizations, including those associated with:</p>
<ul>
<li>the Defense Industrial Base (DIB),  </li>
<li>the federal and local government,</li>
<li>education,</li>
<li>energy,</li>
<li>law enforcement,  </li>
<li>media,  </li>
<li>non-governmental organizations, and</li>
<li>technology.</li>
</ul>
<h2><strong>Technical details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v19/matrices/enterprise/" target="_blank">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 19. This advisory also uses <a href="https://d3fend.mitre.org/" target="_blank">MITRE D3FEND<sup>TM</sup></a> version 1.4.0<a href="https://www.cisa.gov/#f15"><sup>15</sup></a>. See <a href="https://www.cisa.gov/#appendixa">Appendix A</a> and <a href="https://www.cisa.gov/#appendixb">Appendix B</a> for tables of the activity mapped to MITRE ATT&amp;CK and D3FEND tactics, techniques, and countermeasures.</p>
<p><em>Ulej </em>is a novel data exfiltration and aggregation capability, that currently (as of the publication of this report) supports a campaign specifically targeting users of ZCS webmail servers. This capability is used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> [Common Weakness Enumeration (CWE) <a href="https://cwe.mitre.org/data/definitions/79.html" target="_blank">CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'</a>)], but likely could be adapted to exploit other vulnerabilities. It exfiltrates emails and other sensitive user data from a victim’s system immediately after exploitation and stores the data in an actor-controlled unattributable virtual private server (VPS) [<a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank">T1074.002</a>] running LAUNDRY BEAR’s “Flowerbed” collection framework. The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention.</p>
<h3><em><strong>Reconnaissance</strong></em></h3>
<p>LAUNDRY BEAR uses the <em>Ulej </em>capability to exploit the <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> vulnerability in organizations using ZCS. This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations. LAUNDRY BEAR likely identifies organizations with public-facing Zimbra infrastructure by port scanning [<a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank">T1595</a>] and fingerprinting datasets easily procured through various commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank">T1596.005</a>].  </p>
<p>After identifying a target organization, the group likely compiles email addresses for individual users to target with the exploit [<a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank">T1589.002</a>] from datasets offered by commercial vendors [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank">T1597.002</a>], open source intelligence [<a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank">T1593</a>], or previously exfiltrated data [<a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank">T1597</a>].  </p>
<h3><em><strong>Resource development </strong></em><a class="ck-anchor"></a></h3>
<p>The actors procure VPSs from a variety of providers [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank">T1583.003</a>], including those with Know Your Customer (KYC) requirements, and often use fabricated identities. LAUNDRY BEAR primarily uses Mullvad VPN [<a href="https://attack.mitre.org/versions/v19/techniques/T1583/">T1583</a>] when interacting with these servers, further demonstrating the group’s intent to mask their identity and maintain operations security (OPSEC). After the server is provisioned, an automated process deploys the Docker containers necessary for <em>Ulej’s</em> Flowerbed framework [<a href="https://attack.mitre.org/versions/v19/techniques/T1608/">T1608</a>], which then receives and aggregates the data <em>Ulej</em> exfiltrates. These servers are typically only used for 7-60 days before moving to new infrastructure.</p>
<h4><strong>Flowerbed framework</strong></h4>
<p>Flowerbed is a Python project that uses Docker for containerization. The project includes four different Docker containers:</p>
<ul>
<li>Catcher,</li>
<li>Certbot,</li>
<li>Nginx, and</li>
<li>Gardener.</li>
</ul>
<p>Catcher acts as both a DNS and HTTP server to receive and aggregate exfiltrated victim information [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/">T1048</a>]. For additional information on Catcher, refer to the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory. Flowerbed’s next container, Certbot, is based on one of the official Certbot containers, which allows for automated generation of Let’s Encrypt certificates using DNS challenges through Cloudflare. This certificate can then be used by the Nginx container, which serves as an HTTPS reverse proxy for Catcher, enabling Flowerbed to disguise some of its exfiltration activity through an encrypted communications channel [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank">T1048.002</a>]. The Nginx reverse proxy also validates that the Server Name Indicator (SNI) value contains “*.i.*” prior to forwarding the traffic to Catcher. If the SNI does not contain that string, the Nginx server returns a 444 error to the client. This is likely an attempt to reject non-Ulej connections. Finally, the Gardener container functions as a health check for the Catcher service. Gardener is a simple Python script that validates Catcher correctly receives and processes data.</p>
<p>The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development. This highlights how AI is increasingly being used to develop malicious capabilities [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank">T1588.007</a>]. The dependence on AI for a simple capability, such as Flowerbed, alongside a previous reliance on open source capabilities, such as Evilginx2 [<a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank">T1588.002</a>], likely indicates a lack of advanced technical knowledge within LAUNDRY BEAR, especially in relation to true software development capabilities.</p>
<h3><em><strong>Initial access</strong></em></h3>
<p>To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [<a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank">T1566</a>]. Through exploitation of <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>, this JavaScript payload is immediately executed once the user views the malicious email [<a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank">T1203</a>], such as the one shown in <a href="https://www.cisa.gov/#figure1"><strong>Figure 1</strong></a>, in the ZCS webmail platform. Since at least November 2025, LAUNDRY BEAR began sending these phishing emails from victim infrastructure through compromised accounts [<a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank">T1199</a>], as shown in the email metadata in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>. These compromised accounts were likely previous victims of this, or another LAUNDRY BEAR, campaign and their use is intended to further obfuscate and frustrate anti-phishing tools and training.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure1.png?itok=yrzcl7tK" width="604" height="235" alt="Figure 1: Example of malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 1: Example of malicious email</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure2.png?itok=vEulmmyx" width="604" height="102" alt="Figure 2: Headers from an example malicious email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 2: Headers from an example malicious email</strong></em></figcaption>
  </figure>
<p>According to the National Vulnerability Database (NVD), <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66376" target="_blank">CVE-2025-66376</a> was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [<a href="https://www.cisa.gov/#wc5">5</a>]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank">T1587.004</a>].  </p>
<p><strong>Utilization of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability.</strong></p>
<p>Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank">T1027.017</a>], as shown in <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a>. This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see <a href="https://www.cisa.gov/#figure3"><strong>Figure 3</strong></a>) [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank">T1027.013</a>]. The outer payload decodes and decrypts the inner payload using an XOR function and a hardcoded key and then executes the script contained within the inner payload containing the collection and exfiltration logic. By changing the key used for the XOR encryption of the inner payload or adding additional @import directives with non-functional code [<a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank">T1027.010</a>], LAUNDRY BEAR can easily generate new payloads that bypass basic threat detection signatures. This malicious payload attempts to collect and exfiltrate information in 12 asynchronous stages [<a href="https://attack.mitre.org/versions/v19/techniques/T1119/">T1119</a>]. The stages in order of appearance within the payload are as follows:</p>
<ol>
<li>sendStartPing,</li>
<li>gather_email,</li>
<li>gather_environment,</li>
<li>gather_2fa_codes,</li>
<li>gather_app_password,</li>
<li>gather_device_status,</li>
<li>gather_oauth_consumers,</li>
<li>gather_autocomplete_password,</li>
<li>enable_mail_protocols,</li>
<li>gather_gal,</li>
<li>sendArchives, and</li>
<li>sendFinishPing. </li>
</ol>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure3_0.png?itok=M-bj5-nb" width="607" height="577" alt="Figure 3: Malicious payload of example email">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 3: Malicious payload of example email</strong></em></figcaption>
  </figure>
<p>Use of a zero-day exploit within this campaign demonstrates the ability for even emerging threat groups like LAUNDRY BEAR to operationalize novel exploits into a highly successful capability [<a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank">T1587</a>].</p>
<h3><em><strong>Persistence and credential access</strong></em><a class="ck-anchor"></a></h3>
<p>To establish sustained persistence into the victim’s email account, the script attempts to modify account preferences and collect authentication information. Any collected credentials are later exfiltrated, as further described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. Other campaigns attributed to LAUNDRY BEAR also demonstrated the group’s ability to circumvent multi-factor authentication through session token replay [<a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank">T1550.004</a>], and the Zimbra campaign follows a similar trend.</p>
<p>The script used in this campaign tries to discover the victim’s email address during the <em>gather_email</em> stage [<a href="https://attack.mitre.org/techniques/T1087/" target="_blank">T1087</a>]. The script searches for this email address in two ways. First, it examines the <em>batchInfoResponse </em>variable, which an HTML script element on the webpage can define, for an email address. Even if the script finds an email address there, it also checks whether it acquired a Cross-Site Request Forgery (CSRF) token as described later in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory. If so, the script uses the “GetIdentitiesRequest” Simple Object Access Protocol (SOAP) command under the “ZimbraAccount” namespace to determine the victim’s email address [<a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank">T1185</a>] and then exfiltrates it. However, if the script does not have a CSRF token or the SOAP request fails, the script exfiltrates the email value recovered from the first method instead. If both attempts fail to capture the victim’s email, the script sends a JavaScript Object Notation (JSON) payload with a key of “email” and value of <em>null </em>over HTTPS and does not attempt DNS exfiltration.</p>
<p>During the <em>gather_autocomplete_password</em> stage, the script attempts to collect the victim’s saved password via the autocomplete feature of the victim’s password manager. The script injects two HTML div elements requesting login credentials onto the page outside of the victim’s view, as shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a><strong> </strong>and <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. After waiting five seconds, the script then attempts to extract the password provided automatically by the password manager from the input element shown in <a href="https://www.cisa.gov/#figure4"><strong>Figure 4</strong></a>. If there is no value in that input field, it checks the password input field shown in <a href="https://www.cisa.gov/#figure5"><strong>Figure 5</strong></a>. If neither input field contains a value, a JSON payload with a key of “autocomplete_password” and value of <em>null </em>is sent over HTTPS and DNS exfiltration is not attempted.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure4.png?itok=ZOZ8JHZC" width="1024" height="188" alt="Figure 4: First illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 4: First illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/figure5.png?itok=8xZU_GCa" width="1024" height="115" alt="Figure 5: Second illegitimate login HTML element">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 5: Second illegitimate login HTML element</strong></em></figcaption>
  </figure>
<p>LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the <em>enable_mail_protocols</em> stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent. This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.</p>
<p>ZCS does not support 2FA for some mail clients, including IMAP. To support users who rely on IMAP clients, ZCS allows for the generation of Application Passcodes. Application Passcodes are randomly generated passwords that can be used for clients that cannot support the normal 2FA process to authenticate. During the <em>gather_app_password</em> stage, the script makes a SOAP request using the “CreateAppSpecificPasswordRequest” command under the “ZimbraAccount” namespace to create a new Application Passcode [<a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank">T1556.006</a>]. The SOAP request uses “ZimbraWeb” as the name of the application.</p>
<p>Additionally, the script also attempts to collect 2FA tokens. During the <em>gather_2fa_codes</em> stage, the script makes a SOAP request using the “GetScratchCodesRequest” command under the “ZimbraAccount” namespace. The script then attempts to exfiltrate any non-null 2FA codes collected this way. The number of codes can vary, and each code is exfiltrated to Flowerbed individually.</p>
<h3><em><strong>Collection</strong></em><a class="ck-anchor"></a></h3>
<p>As demonstrated in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, this script relies heavily on SOAP requests to collect victim information. To make these requests, the script aims to acquire the victim’s current CSRF token, which it attempts to access within the webpage’s local storage using localStorage.getItem("csrfToken"). If the script is unable to acquire this CSRF token, it will be unable to make any SOAP requests. In addition to the SOAP commands documented in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> section, other SOAP commands executed to collect victim information are shown in <a href="https://www.cisa.gov/#table1"><strong>Table 1</strong></a>.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 1: Additional SOAP commands used</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>SOAP Command </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Namespace </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p><strong>Stage </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraSync </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>SearchGalRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>zimbraAccount </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW195872110 BCX8">
<div class="OutlineElement Ltr SCXW195872110 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script attempts to collect the victim’s GAL through brute force by searching for each two-character combination from a character set of “abcdefghijklmnopqrstuvwxyz1234567890.-_”. These queries are conducted using 20 batches of SOAP requests with 77 “SearchGalRequest” SOAP commands in each batch except for the last request containing only 58.</p>
<p>During the <em>gather_environment</em> stage, the script attempts to determine which type of ZCS webmail client the victim is using. The script checks the user’s current URL to determine the client type being used, checking for certain indicators (shown in <a href="https://www.cisa.gov/#table2"><strong>Table 2</strong></a>) to determine the client type. The corresponding value is then used as the payload when exfiltrating the client type.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 2: ZCS webmail client types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Indicator </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Client Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p><strong>Associated Value </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>?client=advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Advanced </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/h/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Standard </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>h </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>/modern/ </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>Modern </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW28945023 BCX8">
<div class="OutlineElement Ltr SCXW28945023 BCX8">
<p>m </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>As part of collection, the script attempts to harvest any emails not marked as “junk” from the last 90 days from the victim’s account. Emails are collected daily by an HTTP GET request to the URL path, “/home/~/?fmt=tgz&amp;meta=0&amp;query=date:-{DAY_OFFSET}d AND (not in:junk)”. The <em>{DAY_OFFSET}</em> value would be between 0 and 89 representing how many days ago the email was sent or received. To prevent redundant collection and exfiltration of emails, a variable with a name based on the email date being queried, using a format of <em>zd_comp_YYYY-MM-DD</em>, and value of <em>true</em>, is saved to the <em>window.top.localStorage</em> property. This variable is saved regardless of whether the email is successfully exfiltrated.  </p>
<p>According to Mozilla documentation, if the user is not in a private browsing session, any data stored to localStorage does not typically expire. This means that if the user happens to execute the script again from the same computer, the script avoids attempting to re-exfiltrate previously captured emails. However, the script always attempts to pull any emails with a <em>{DAY_OFFSET} </em>of zero. In other words, the script always pulls emails sent or received the same day it is run. After email results are returned from the query for each day of email activity, those results are then passed to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section.</p>
<p>The script also provides LAUNDRY BEAR with telemetry on any errors that occur during the collection process. This is accomplished by executing any collection or exfiltration code through helper functions that contain error handling logic. If an error occurs, a payload containing information on the error itself, the context of the error happening, and the stage in which the error occurred is sent to Flowerbed as described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section below. For cases where the error occurs within a SOAP request, “:api” is concatenated to the stage value in the payload. If an error occurs during the batch SOAP requests that occur when collecting the GAL of the victim, the stage value will use a format of <em>gather_gal:{VAL}:api</em>. The <em>{VAL}</em> placeholder indicates which batch request, a number from 0 to 19, the error occurred in. Errors that occur during the password autocomplete interception process will use “gather_autocomplete_password:dom” for the stage value. Finally, if an error occurs when attempting to collect or exfiltrate a specific day’s emails, the stage will include which day the error occurred on, using the previously defined placeholder <em>{DAY_OFFSET},</em> with a format of <em>sendArchive:day-{DAY_OFFSET}</em>.</p>
<h3><em><strong>Exfiltration</strong></em><a class="ck-anchor"></a></h3>
<p>At the end of each stage in the collection process, the script attempts to exfiltrate acquired information to Flowerbed. The script primarily relies on two forms of data exfiltration: DNS [<a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank">T1048.003</a>] and HTTPS. Some information is exfiltrated over both the DNS and HTTPS channels.</p>
<p>Prior to exfiltration, a randomized 10- or 11-character alphanumeric string is generated as an identifier for the victim. This identifier is included in the URL of both the DNS- and HTTPS-based exfiltration.  </p>
<h4><strong>DNS exfiltration</strong></h4>
<p>DNS exfiltration occurs through DNS A record queries. To ensure data exfiltrated through DNS is not corrupted when traversing through non-actor-controlled DNS infrastructure, <em>Ulej </em>maintains compliance with RFC 1035, Domain Names - Implementation and Specification, specifically accounting for the case insensitivity and subdomain length requirements. Base32 encoding is used to create a case-insensitive payload. Once the payload is encoded, a period (“.”) is added every 60 characters to ensure each subdomain is under 63 characters long. The script then creates a new image object sourced from a URL with the scheme defined in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a>. Any traffic involving DNS exfiltration will have “d-“ prefixing the victim identifier, and the subdomain immediately following indicates the type of information being exfiltrated.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure6.png?itok=Tv8RT8o8" width="1024" height="49" alt="Figure 6: Structure for information exfiltrated by DNS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 6: Structure for information exfiltrated by DNS</strong></em></figcaption>
  </figure>
<p>When the script generates an image object, the browser tries to retrieve the complete domain of the URL specified as the source of the image. This triggers a DNS request sent to the actor-controlled server and processed by Flowerbed. <a href="https://www.cisa.gov/#table3"><strong>Table 3</strong></a> lists both the information exfiltrated via DNS and their corresponding data type identifiers in the DNS queries.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 3: DNS exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p><strong>Data Type </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>e </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Client Type </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>c </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Zimbra Version </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment  </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>v </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>URL at Time of Exploitation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2FA Scratch Codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>2fa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pa </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW258158484 BCX8">
<div class="OutlineElement Ltr SCXW258158484 BCX8">
<p>pw </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<h4><strong>HTTPS exfiltration</strong></h4>
<p>Any information exfiltrated via DNS is also exfiltrated through HTTPS, as well as additional data including email content, contacts, attachments, and error logging information. By using Let’s Encrypt certificates, this group can quickly deploy new infrastructure and leverage encrypted HTTPS communications with valid server certificates when exfiltrating information from the victim’s environment. The HTTPS exfiltration capability only uses two HTTP content types, defined in <a href="https://www.cisa.gov/#table4"><strong>Table 4</strong></a>. Traffic associated with HTTPS exfiltration will use the URL scheme shown in <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>.  </p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 4: HTTPS exfiltration types</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>Content Type </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p><strong>URL Path </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/json </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/p </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>application/octet-stream </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW3397685 BCX8">
<div class="OutlineElement Ltr SCXW3397685 BCX8">
<p>/v/d </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%207.png?itok=CdTcyMdN" width="1024" height="50" alt="Figure 7: Structure for information exfiltrated by HTTPS">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 7: Structure for information exfiltrated by HTTPS</strong></em></figcaption>
  </figure>
<p>Some of the data transmitted via HTTPS uses the standard JSON content type format. The script includes the information in a POST request to actor-controlled infrastructure.  </p>
<p><a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> provides a summary of the JSON-based exfiltration.</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 5: HTTPS JSON exfiltration  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p><strong>JSON Key(s) </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Victim’s Email Address </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_email </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>email </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Client Type, Version, and Current URL </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>client, version, full_url </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Newly Created Application Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_app_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>app_password </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>Harvested Autocomplete Password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>gather_autocomplete_password </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW25077005 BCX8">
<div class="OutlineElement Ltr SCXW25077005 BCX8">
<p>autocomplete_password </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>The script transmits all HTTPS exfiltration not identified in <a href="https://www.cisa.gov/#table5"><strong>Table 5</strong></a> using the Octet-Stream content type as binary data. The POST requests for this method include a filename in the “X-Filename” header. Traditionally, developers use headers prefixed with “X-” to denote custom headers that do not follow a defined standard. The purpose of including this header remains unclear since the Catcher capability ignores the provided filename when saving the data. <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> summarizes the data exfiltrated in this format.</p>
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<div class="TableContainer Ltr SCXW189907655 BCX8">
<div class="WACAltTextDescribedBy SCXW189907655 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong> Table 6: HTTPS binary exfiltration</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Type of Information </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>Exfiltration Stage </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p><strong>X-Filename Header </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetInfoRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_environment </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetScratchCodesRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_2fa_codes </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetDeviceStatusRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_device_status </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>SOAP request for GetOAuthConsumersRequest </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_oauth_consumers </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>zimbra_batch_analytics.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Victim Organization’s Global Address List </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>gather_gal </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetry_{1-20}.json </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>Last 90 Days of Victim’s Emails </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>sendArchives </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW189907655 BCX8">
<div class="OutlineElement Ltr SCXW189907655 BCX8">
<p>telemetryData_{0-89}.json </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>The script sends all exfiltrated data identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> to the Catcher service exactly as received from the SOAP request in a JSON payload, except for email exfiltration. For email exfiltration, the script sends it as a GZIP compressed archive [<a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank">T1560</a>]. Although most of the exfiltration consists of valid JSON, the script still attempts to exfiltrate all information identified in <a href="https://www.cisa.gov/#table6"><strong>Table 6</strong></a> using the application/octet-stream content typing rather than application/json.</p>
<p>At the beginning and end of the collection and exfiltration activity, during the <em>sendStartPing</em> and <em>sendFinishPing </em>stages respectively, the script submits a POST request with a JSON payload to indicate that the script is starting or finishing execution. Throughout execution, the script also logs error events and send the logs using similar JSON payloads. The script sends the JSON in a POST request to the URL documented in <a href="https://www.cisa.gov/#figure2"><strong>Figure 2</strong></a>, using a URL path of “/v/p” and with a “subtype” key that shows which type of action it logged (<em>start, finish, or error</em>).  </p>
<h4><strong>Catcher</strong></h4>
<p><em>Ulej </em>exfiltrates information to Flowerbed to be handled by a service named Catcher. Catcher is a containerized Python application, running in Docker as part of Flowerbed, which is detailed in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section. It receives exfiltrated data and temporarily stores it, enabling its eventual transfer to infrastructure designed for long-term, secure storage.</p>
<p>Catcher acts as an HTTP server over port 8000 and a DNS server on port 53. As described in the <a href="https://www.cisa.gov/#resourcedev1">Resource development</a> section, the Flowerbed project uses an additional Docker container running an Nginx reverse proxy to enable HTTPS support. This reverse proxy uses a certificate generated by Let’s Encrypt and forwards all traffic with an SNI containing “*.i.*” to port 8000 within the Catcher container.</p>
<p>The DNS service can accept A, AAAA, MX, TXT, and CAA queries. For any MX, AAAA, or CAA queries, the server will always provide an empty response. The system only supports TXT records as needed to process Automatic Certificate Management Environment (ACME) requests, which enable the assignment of Let’s Encrypt certificates. If the server receives an A query, Catcher will always respond with the public IP address of the Flowerbed server.  </p>
<p>However, if a query includes a domain formatted as shown in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>, the service saves a log file in JSON format to disk containing the following details of the DNS query:</p>
<ul>
<li>Time of query,</li>
<li>Source IP address for query,</li>
<li>Queried domain, and</li>
<li>Type of query.</li>
</ul>
<p>The HTTP server typically responds with OK, except in cases where the path is “pixel.gif” when the response contains a 1x1 gif image with a SHA-256 hash of ef1955ae757c8b966c83248350331bd3a30f658ced11f387f8ebf05ab3368629. Like the DNS service, the HTTP service will only log entries when the domain found in the host header of the request follows the expected formatting as seen in <a href="https://www.cisa.gov/#figure6"><strong>Figure 6</strong></a> and <a href="https://www.cisa.gov/#figure7"><strong>Figure 7</strong></a>. As the HTTPS exfiltration uses non-standardized binary and JSON-formatted payloads when exfiltrating to Catcher, Catcher will check the content type of the request. If the content type is set to “application/json”, Catcher encodes the data in Base64 and includes it in the JSON log entry written to disk. If the content type is set to any other value, Catcher leaves the Base64 payload in the JSON log entry blank and saves the payload to a separate file with the same filename as the JSON log entry with a “.bin” file extension. An HTTPS exfiltration event causes Catcher to save a JSON formatted log file to disk containing the following information from the HTTP request:</p>
<ul>
<li>Time,</li>
<li>Source IP address,</li>
<li>Request method,</li>
<li>Host,</li>
<li>Path,</li>
<li>Query string,</li>
<li>Headers, and</li>
<li>Base64 payload.</li>
</ul>
<p>These JSON event log files and binary output files are then initially saved to the directory <em>/root/hits/tmp</em> and later moved to the <em>/root/hits/ready</em> directory once processed. This prevents incomplete files, which are still being uploaded to Catcher, from premature exfiltration from the server. Approximately every 60 seconds, a likely automated workflow establishes a Secure Shell (SSH) connection with the server hosting Flowerbed for a few seconds, almost certainly exfiltrating the data processed by Catcher to non-public-facing infrastructure. The command in <a href="https://www.cisa.gov/#figure8"><strong>Figure 8</strong></a> also executes hourly to remove all files last modified at least two days ago from the <em>/root/hits/ready</em> directory.</p>
<p><a class="ck-anchor"></a></p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-07/Figure%208-Command%20used%20for%20automated%20directory%20cleanup.png?itok=IqvZvbLK" width="1024" height="92" alt="Figure 8: Command used for automated directory cleanup">



</div>
      <figcaption class="c-figure__caption"><em><strong>Figure 8: Command used for automated directory cleanup</strong></em></figcaption>
  </figure>
<h2><strong>Response strategies</strong></h2>
<h3><em><strong>Mitigations</strong></em><a class="ck-anchor"></a></h3>
<p>In many cases, by the time an organization identifies a compromise related to this campaign, numerous sensitive and proprietary emails have already been exfiltrated. The significant risk posed by this cyber threat emphasizes the importance for organizations that use ZCS and other similar webmail solutions to take proactive steps to mitigate this risk.</p>
<p>All organizations that use the ZCS webmail service should <strong>immediately prioritize</strong> ensuring that their ZCS is not running a vulnerable version. A patch for <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a> was released for both 10.1.13 and 10.0.18 versions of ZCS [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening">D3-AH</a>]. If immediate patching is not feasible, organizations should advise employees to use alternative mail clients to access email and avoid using the Classic ZCS webmail client until ZCS is updated to a non-vulnerable version [<a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank">d3f:Isolate</a>].</p>
<p>System administrators should closely monitor any Internet-connected ZCS or other email systems and the workstations that access those systems and promptly apply available software updates [<a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank">D3-AH</a>]. Administrators can maintain awareness of active vulnerability exploitation by referencing open source resources, including <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities Catalog</a> and <a href="https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/responding-to-active-exploitation" target="_blank">NCSC-UK’s Responding to active exploitation of vulnerabilities</a> guidance.</p>
<p>Organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. By doing so, organizations can work to eliminate the possibility of automated password collection from autocomplete or password reuse [<a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank">D3-CH</a>]. However, Application Passcodes may still be necessary and should be monitored closely.  </p>
<p>Organizations should implement network monitoring capabilities with collection and short-term retention of packet capture or NetFlow data and maintain log collection and storage [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#MaintainLogCollectionStorage3Q">CPG 3.Q</a>]. This will allow organizations to monitor for and identify suspicious network activity [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#IdentifyAdverseEvents4B">CPG 4.B</a>], such as:</p>
<ul>
<li>Significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank">D3-NTA</a>];</li>
<li>Frequent DNS queries for a suspicious domain with seemingly random subdomains [<a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank">D3-DNSTA</a>];</li>
<li>A sudden spike of connections to a server associated with a recently established domain [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>]; and  </li>
<li>Connections to internal services, such as webmail, from VPN providers frequently leveraged by this group for nefarious activity, such as Mullvad VPN [<a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation">D3-NTCD</a>].</li>
</ul>
<p>Additionally, for organizations that can inspect the content of outbound HTTPS connections via break-and-inspect infrastructure, security teams should identify traffic matching the characteristics described in the <a href="https://www.cisa.gov/#exfil1">Exfiltration</a> section of this advisory.</p>
<h3><em><strong>Indicators of compromise (IOCs)</strong></em><a class="ck-anchor"></a></h3>
<h4><strong>Flowerbed infrastructure</strong></h4>
<p>The following indicators have been attributed to use by LAUNDRY BEAR for their campaign targeting ZCS’s webmail service as of the publication of this advisory. (<strong>Disclaimer: </strong>Due to the frequency of operational structure changes by this group, these indicators are intended solely for historic attribution purposes. Some indicators, such as IPs, compromised emails, and domains, may be outdated, so organizations should check for current activity before acting on these IOCs.) <a href="https://www.cisa.gov/#table7"><strong>Table 7</strong></a> provides details about the server infrastructure used to host Flowerbed, and <a href="https://www.cisa.gov/#table8"><strong>Table 8</strong></a> lists the corresponding SHA-1 hash values for the Let’s Encrypt certificates used by that infrastructure [<a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank">D3-IAA</a>].</p>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 7: Flowerbed server infrastructure</strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>IP Address </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]104 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>8 July 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>15 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]18 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 August 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>14 October 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>37.120.247[.]228 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>185.86.79[.]95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>24 September 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>104.248.134[.]194 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>11 November 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>17 February 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>64.226.124[.]190 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 December 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>193.238.152[.]66 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>20 January 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>18 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>216.252.238[.]64 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>3 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>194.156.103[.]193 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>5 February 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW193774983 BCX8">
<div class="OutlineElement Ltr SCXW193774983 BCX8">
<p>30 March 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 8: Flowerbed X.509 certificate SHA-1 hashes  </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Associated Domain </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>X.509 SHA-1 Hash </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>First Seen </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p><strong>Last Seen </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>2e4f314bc9943cab5005d6fde0b271c74d47bc9d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Jul 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zmailanalytics[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>50a87d926621dd06389ba50d86e0ff574ed713a8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>6 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>13 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbra-metadata[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>c5a72420e7bb308d078e62128430897f82194c95 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>20 Aug 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>14 Oct 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.analyticemailmeter[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8959c4d29e29f02ea94ea8bb21c8df2594c5549d </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>24 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>8 Nov 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.emailanalytics.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>62eb76432597694edb01c1fe57aab0cfe03a7178 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>25 Sep 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>27 Sep 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.mailnalysis[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>cddf5c3be1e07f28140aed165b929bf2d614922a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Nov 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>17 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrastat[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18b3ad442ce73cc8656d51d75bbd7c855f2cb7e8 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>18 Dec 2025 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>28 Dec 2025 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.zimbrasoft.com[.]ua </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>1b25041ececf2457eef0270fc1d785cec8ec9ded </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>21 Jan 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>10 Feb 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.synacorzimbra[.]nl </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>e4fe6466a4f9a4249fe330651e914e45bbdca44a </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>5 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>22 Mar 2026 </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>*.i.istc-cloud[.]com </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>b6b77c9a455225d525834a403ca9ef5481ed0447 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>12 Feb 2026 </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW66173475 BCX8">
<div class="OutlineElement Ltr SCXW66173475 BCX8">
<p>30 Mar 2026 </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p>LAUNDRY BEAR has used the following email addresses to procure resources used for this campaign:</p>
<ul>
<li>ivanka.zurabishvili@proton[.]me,</li>
<li>zmul1@buildandconsulting[.]com,</li>
<li>garrysmithme@pinmx[.]net, and</li>
<li>hostingclient@pinmx[.]net.</li>
</ul>
<h4><strong>Phishing distribution</strong></h4>
<p>LAUNDRY BEAR primarily relied on ProtonMail for distribution of malicious email. However, as stated above, LAUNDRY BEAR’s more recent efforts likely have shifted to distributing the payload through previous victims.  </p>
<p>The following email addresses have distributed payloads attributed to this campaign:</p>
<ul>
<li>c.laurent.ejfa@proton[.]me,</li>
<li>j.moreau.epsc@proton[.]me,</li>
<li>liberty.insights@proton[.]me,</li>
<li>certain email addresses (presumably compromised) at the isofts.kiev[.]ua domain (i.e., ending with @isofts.kiev[.]ua), and</li>
<li>certain email addresses (presumably compromised) at the navs.edu[.]ua domain (i.e., ending with @navs.edu[.]ua).</li>
</ul>
<p>Additionally, the following are SHA-256 hashes of email samples containing the malicious payload attributed to this campaign:</p>
<ul>
<li>98df604ecc57f884a2e6ce3266a0013ad64455cac48442c2312cfa4765007aaf,</li>
<li>60db9abae75cd8ccc49dd7ea5feb41677566dcd442f12ebc5745ffd2810fb874,</li>
<li>b1f5beb1175fc5c7d1806a2f0d900eb124c54f0286c5c52b66eea7a6633adb1d, and</li>
<li>1517b3caa495f6c4e832df9c75fc94667e3c233773f7fa4e056d5e30e5ead760.</li>
</ul>
<h4><strong>Post-compromise artifacts</strong></h4>
<p>Currently, the script does not remove artifacts. This leaves additional opportunities to identify victims of this activity. While emphasis should always be placed on consistent monitoring of network traffic and endpoint activity, there are a variety of persistent artifacts described below that can be used to identify victims of this campaign.</p>
<p>This <em>Ulej </em>capability relies on creating a significant number of SOAP requests to collect account information for exfiltration. ZCS logs from these requests are stored, by default, in the <em>/opt/zimbra/log/mailbox.log</em> file [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. A significant amount of SOAP request activity that aligns with what was described in the <a href="https://www.cisa.gov/#persistence1">Persistence and credential access</a> and <a href="https://www.cisa.gov/#collection1">Collection</a> sections of this advisory could indicate a potential compromise. Specific examples of high-risk SOAP request activity might include:</p>
<ul>
<li>Many <em>SearchGalRequest </em>command requests from a single user over a short period of time;</li>
<li>Use of the <em>CreateAppSpecificPasswordRequest</em> command, especially in cases where it is creating an Application Passcode named “ZimbraWeb”; and</li>
<li>Use of the GetScratchCodesRequest command.</li>
</ul>
<p>While LAUNDRY BEAR uses the localStorage property to track what days had emails previously exfiltrated, defenders can use this property to identify victims of this campaign and determine the scope of exfiltrated information [<a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank">D3-PA</a>]. Review of the items stored in that property for an organization’s ZCS webmail client page on an endpoint device could indicate compromise if there are items named with a format of <em>zd_comp_YYYY-MM-DD,</em> as explained in the <a href="https://www.cisa.gov/#collection1">Collection</a> section of this advisory.</p>
<p>While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious. The ZCS webmail application can support 2FA natively and does not require the use of an Application Passcode, so there is no reason that there should be one named “ZimbraWeb.”</p>
<p>In instances where organizations identify victims of this campaign, they should also examine the inbox of the suspected victim for the original phishing email [<a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis" target="_blank">D3-MA</a>]. If an email that has a payload exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376">CVE-2025-66376</a> is discovered, <strong>steps should be taken immediately to identify and quarantine other instances of emails with similar body content, senders, and subject lines to prevent further exploitation and exfiltration.  </strong></p>
<h3><em><strong>Remediation</strong></em></h3>
<p>In the event an organization identifies activity associated with this campaign, that organization should take steps to minimize further exploitation. The organization should consider requesting that employees minimize use of the ZCS webmail client until the organization updates to a patched version that is not vulnerable to <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank">CVE-2025-66376</a>.</p>
<p>Organizations should use identifiers from the <a href="https://www.cisa.gov/#ioc1">IOCs</a> section of this report to identify any individuals compromised by this campaign and record the date(s) of compromise(s) to determine the scale and scope of emails exfiltrated.</p>
<p>All users from the organization should have all Application Passcodes and 2FA scratch keys revoked. Affected organizations should require all employees to change passwords in line with establishing minimum password strength requirements [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#EstablishMinimumPasswordStrength3B">CPG 3.B</a>] and creating unique credentials [<a href="https://www.cisa.gov/cybersecurity-performance-goals-2-0-cpg-2-0#CreateUniqueCredentials3C">CPG 3.C</a>], specifically noting that compromised employees might have had any password stored in a password manager exfiltrated.</p>
<h2><strong>Works cited</strong></h2>
<p>[1<a class="ck-anchor"></a>] Netherlands General Intelligence and Security Service (AIVD) and Netherlands Defence Intelligence and Security Service (MIVD). AIVD and MIVD identify a new Russian cyber threat actor. 2025. <a href="https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf" target="_blank">https://www.aivd.nl/site/binaries/site-content/collections/documents/2025/05/27/aivd-en-mivd-onderkennen-nieuwe-russische-cyberactor/Advisory+AIVD+en+MIVD+Public+report+on+new+cyber+actor.pdf</a></p>
<p>[2]<a class="ck-anchor"></a> Microsoft Corporation. New Russia-affiliated actor Void Blizzard targets critical sectors for espionage. 2025. <a href="https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/</a></p>
<p>[3]<a class="ck-anchor"></a> Palo Alto Networks Unit 42. Russian Global Webmail Espionage. 2026. <a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">https://unit42.paloaltonetworks.com/russian-webmail-espionage/ </a></p>
<p>[4]<a class="ck-anchor"></a> Proofpoint. TA488 Targets Zimbra Mailservers with Half-Click Exploits. 2026. <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit">https://www.proofpoint.com/us/blog/threat-insight/ta488-zcs-exploit</a></p>
<p>[5]<a class="ck-anchor"></a> Seqrite. Operation GhostMail: Russian APT exploits Zimbra Webmail to Target Ukraine State Agency. 2026. <a href="https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/" target="_blank">https://www.seqrite.com/blog/operation-ghostmail-zimbra-xss-russian-apt-ukraine/  </a></p>
<h2><strong>Footnotes</strong></h2>
<p><sup>1</sup><a class="ck-anchor"></a> Národní úřad pro kybernetickou a informační bezpečnost<br><sup>2</sup><a class="ck-anchor"></a><sup> </sup>Forsvarets Efterretningstjeneste<br><sup>3</sup><a class="ck-anchor"></a><sup> </sup>Välisluureamet<br><sup>4</sup><a class="ck-anchor"></a> Sotilastiedustelu<br><sup>5</sup><a class="ck-anchor"></a><sup> </sup> Suojelupoliisi<br><sup>6</sup><a class="ck-anchor"></a> Direction générale de la sécurité intérieure<br><sup>7</sup><a class="ck-anchor"></a> Agence nationale de la sécurité des systèmes d’information<br><sup>8</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Esterna<br><sup>9</sup><a class="ck-anchor"></a> Agenzia Informazioni e Sicurezza Interna<br><sup>10</sup><a class="ck-anchor"></a> Serviciul de Informații și Securitate al Republicii Moldova<br><sup>11 </sup><a class="ck-anchor"></a>Agencja Wywiadu<br><sup>12</sup><a class="ck-anchor"></a><sup> </sup>Służba Kontrwywiadu Wojskowego<br><sup>13</sup><a class="ck-anchor"></a><sup> </sup>Centro Nacional de Inteligencia<br><sup>14 </sup><a class="ck-anchor"></a>Nationellt Cybersäkerhetscenter<br><sup>15</sup><a class="ck-anchor"></a> MITRE and ATT&amp;CK are registered trademarks of The MITRE Corporation. MITRE D3FEND is a trademark of The MITRE Corporation.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>The authoring agencies acknowledge the contributions to this advisory from Palo Alto Networks Unit 42 and Proofpoint.</p>
<h2><strong>Disclaimer of endorsement</strong></h2>
<p>The information and opinions contained in this document are provided "as is" and without any warranties or guarantees. Reference herein to any specific commercial products, process, or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favoring by the United States Government, and this guidance shall not be used for advertising or product endorsement purposes.</p>
<p>Organizations have no obligation to respond or provide information back to the authoring organizations in response to this joint advisory. If, after reviewing the information provided, an organization decides to provide information to the authoring organizations, reporting must be consistent with all applicable laws and policies.</p>
<h2><strong>Purpose</strong></h2>
<p>This document was developed in furtherance of the authoring agencies’ cybersecurity missions, including their responsibilities to identify and disseminate threats, and to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.</p>
<h2><strong>Contact</strong></h2>
<div class="SCXW95230887 BCX8">
<div class="OutlineElement Ltr SCXW95230887 BCX8">
<p><strong>United States organizations </strong></p>
<ul>
<li><strong>National Security Agency</strong> <br>Cybersecurity Report Feedback: <a href="mailto:CybersecurityReports@nsa.gov" target="_blank"><u>CybersecurityReports@nsa.gov</u></a> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DIB_Defense@cyber.nsa.gov" target="_blank"><u>DIB_Defense@cyber.nsa.gov</u></a> <br>Media Inquiries / Press Desk: NSA Media Relations: 443-634-0721, <a href="mailto:MediaRelations@nsa.gov" target="_blank"><u>MediaRelations@nsa.gov</u></a> </li>
<li><strong>Cybersecurity and Infrastructure Security Agency</strong> <br>CISA’s 24/7 Operations Center (<a href="mailto:contact@cisa.dhs.gov" target="_blank"><u>contact@cisa.dhs.gov</u></a>), or by calling 1-844-Say-CISA (1-844-729-2472). </li>
<li><strong>Federal Bureau of Investigation</strong> <br>If you or someone you know has fallen victim to this campaign, file a complaint with <a class="Hyperlink SCXW95230887 BCX8" href="https://www.ic3.gov/" target="_blank" rel="noreferrer noopener"><u>IC3</u></a>. </li>
<li><strong>Defense Counterintelligence and Security Agency </strong> <br>DCSA Counterintelligence, Cyber Mission Center, Cyber Threat Operations Branch: <a href="mailto:DCSA.CI.CyberOps@mail.mil" target="_blank"><u>DCSA.CI.CyberOps@mail.mil</u></a> <br>Cleared Contactors (CCs) should contact their DCSA Counterintelligence Special Agent to report information pertaining to suspicious contacts or physical/digital efforts to obtain illegal or unauthorized access to the CC’s cleared facility/information, as required by 32 CFR 117. <br>Media/Public Inquiries: <a href="mailto:dcsa.quantico.dcsa-hq.mbx.pa@mail.mil" target="_blank"><u>dcsa.quantico.dcsa-hq.mbx.pa@mail.mil</u></a>  </li>
<li><strong>Department of Defense Cyber Crime Center </strong> <br>Defense Industrial Base Inquiries and Cybersecurity Services: <a href="mailto:DC3.DCISE@us.af.mil" target="_blank"><u>DC3.DCISE@us.af.mil</u></a> <br>Defense Industrial Base mandatory cyber incident reporting as required by 10 U.S. Code Sections 391 and 393 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 is submitted at <a href="https://dibnet.dod.mil/" target="_blank"><u>https://dibnet.dod.mil</u></a> <br>Media Inquiries / Press Desk: <a href="mailto:DC3.Information@us.af.mil" target="_blank"><u>DC3.Information@us.af.mil</u></a> </li>
<li><strong>Naval Criminal Investigative Service</strong> <br>To report criminal activity impacting the United States Navy, go to <a href="http://www.ncis.navy.mil/" target="_blank"><u>www.ncis.navy.mil</u></a> and click “Submit a Tip”</li>
</ul>
<p><strong>Dutch organizations</strong> </p>
<ul>
<li>Defence Intelligence and Security Service (MIVD): <a href="https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid" target="_blank"><u>https://www.defensie.nl/onderwerpen/m/militaire-inlichtingen-en-veiligheid</u></a>  </li>
<li>General Intelligence and Security Service (AIVD): <a href="https://www.aivd.nl/" target="_blank"><u>https://www.aivd.nl</u></a> </li>
</ul>
<p><strong>Australian organizations </strong></p>
<ul>
<li>Australian Signals Directorate <br>Visit <a href="https://www.cyber.gov.au/about-us/about-asd-acsc/contact-us#no-back" target="_blank"><u>cyber.gov.au</u></a> or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. </li>
</ul>
<p><strong>Canadian organizations </strong></p>
<ul>
<li>The Canadian Centre for Cyber Security (Cyber Centre), part of the Communications Security Establishment, encourages Canadian organizations to report cyber incidents and to strengthen the security of their networking devices.  <br>Report an incident or suspicious activity to the Cyber Centre by email at <a href="mailto:contact@cyber.gc.ca" target="_blank"><u>contact@cyber.gc.ca</u></a>, online via the reporting tool <a href="https://www.cyber.gc.ca/en/incident-management" target="_blank"><u>Report a cyber incident - Canadian Centre for Cyber Security</u></a> or by phone at 1-833-CYBER-88 (1-833-292-3788). </li>
</ul>
<p><strong>New Zealand organizations </strong></p>
<ul>
<li>New Zealand National Cyber Security Centre (NCSC-NZ): <a href="mailto:info@ncsc.govt.nz" target="_blank"><u>info@ncsc.govt.nz</u></a> </li>
</ul>
<p><strong>United Kingdom organizations </strong></p>
<ul>
<li>Report significant cyber security incidents to <a href="https://ncsc.gov.uk/report-an-incident" target="_blank"><u>ncsc.gov.uk/report-an-incident</u></a> (monitored 24/7) </li>
</ul>
<p><strong>Estonia organizations </strong></p>
<ul>
<li>Estonian Foreign Intelligence Service (EFIS): <a href="mailto:info@valisluureamet.ee" target="_blank"><u>info@valisluureamet.ee</u></a> </li>
</ul>
<p><strong>Finnish organizations </strong></p>
<ul>
<li>Finnish Security and Intelligence Service: <a href="https://supo.fi/en/contact" target="_blank"><u>supo.fi/en/contact</u></a> </li>
</ul>
<p><strong>French organizations </strong></p>
<ul>
<li>French organizations are encouraged to report suspicious activity or incident related information found in this advisory by contacting ANSSI/CERT-FR at: <a href="mailto:cert-fr@ssi.gouv.fr" target="_blank"><u>cert-fr@ssi.gouv.fr</u></a> or by phone at: 3218 or +33 9 70 83 32 18. </li>
</ul>
<p><strong>Italian Organizations </strong></p>
<ul>
<li>Italian External Intelligence and Security Agency (AISE):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a>  </li>
<li>Italian Internal Intelligence and Security Agency (AISI):  <br>Visit <a href="https://www.sicurezzanazionale.gov.it/" target="_blank"><u>https://www.sicurezzanazionale.gov.it/</u></a> </li>
</ul>
<div class="OutlineElement Ltr SCXW214395380 BCX8">
<p><strong>Moldovan organizations </strong></p>
</div>
<div class="ListContainerWrapper SCXW214395380 BCX8">
<ul type="disc">
<li>Security and Intelligence Service of the Republic of Moldova (SIS RM): <a href="mailto:cybersec@sis.md" target="_blank"><u>cybersec@sis.md</u></a> </li>
</ul>
</div>
<p><strong>Polish organizations </strong></p>
<ul>
<li>Polish Foreign Intelligence Agency (AW): <a href="mailto:ctiteam@aw.gov.pl" target="_blank"><u>ctiteam@aw.gov.pl</u></a></li>
</ul>
</div>
</div>
<h2><strong>Appendix A: MITRE ATT&amp;CK tactics and techniques</strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table9"><strong>Table 9</strong></a> through <a href="https://www.cisa.gov/#table19"><strong>Table 19</strong></a> for all the threat actor tactics and techniques referenced in this advisory.<a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 9: Reconnaissance </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Credentials </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/001/" target="_blank"><u>T1589.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to intercept a victim’s password from their password manager. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Gather Victim Identity Information: Email Addresses </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1589/002/" target="_blank"><u>T1589.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload attempts to grab the victim’s email address from various data stores. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Websites/Domains </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1593/" target="_blank"><u>T1593</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group likely leverages public information to support target development. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Active Scanning </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1595/" target="_blank"><u>T1595</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Port scanning can be used by this group to assist with determining exploitability of identified targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Open Technical Databases: Scan Databases </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/" target="_blank"><u>T1596.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Various public datasets can provide information to support discovery of exploitable targets. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/" target="_blank"><u>T1597</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previously exfiltrated data can be used to enhance target development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Search Closed Sources: Purchase Technical Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1597/002/" target="_blank"><u>T1597.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Commercial datasets can also be used to support target development efforts. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<div class="WACAltTextDescribedBy SCXW76044448 BCX8"><a class="ck-anchor"></a></div>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 10: Resource Development </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/" target="_blank"><u>T1583</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group used Mullvad VPN to anonymize traffic sent to operational infrastructure. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group procured VPS servers from a variety of vendors. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/" target="_blank"><u>T1587</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The <em>Ulej</em> capability was developed likely for use by this group to conduct spear phishing campaigns. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Malware </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/001/" target="_blank"><u>T1587.001</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel payload that steals a victim’s emails and other sensitive account information. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Develop Capabilities: Exploits </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/" target="_blank"><u>T1587.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Development of a novel, at the time, cross-site-scripting (XSS) exploit that enables execution of arbitrary JavaScript. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Tool </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/002/" target="_blank"><u>T1588.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Open source tools, such as Evilginx2, have also been used by the group. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obtain Capabilities: Artificial Intelligence </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/" target="_blank"><u>T1588.007</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group appears to have leveraged AI to support development efforts. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stage Capabilities </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1608/" target="_blank"><u>T1608</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Flowerbed is deployed to a procured server in the cloud. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 11: Initial Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized access to accounts. Additionally, this actor is believed to use previously compromised accounts to conduct spear phishing.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Trusted Relationship </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1199/" target="_blank"><u>T1199</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The group sends malicious payloads to targeted individuals using previously compromised accounts that might have an established relationship with the target.  </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Phishing </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1566/" target="_blank"><u>T1566</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The actors used spear phishing to lure users into opening malicious email. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 12: Execution </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exploitation for Client Execution </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1203/" target="_blank"><u>T1203</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>An XSS vulnerability was leveraged to execute the JavaScript payload. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 13: Persistence </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Manipulation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1098/" target="_blank"><u>T1098</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Enabling IMAP and Application Passcodes provides persistent access to the compromised account. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 14: Privilege Escalation </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Valid Accounts </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1078/" target="_blank"><u>T1078</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This actor has used commercial datasets to acquire account credentials and gain unauthorized privileged access to accounts.  </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 15: Stealth </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Command Obfuscation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/010/" target="_blank"><u>T1027.010</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated JavaScript payload sent to targets to exploit the XSS vulnerability. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: Encrypted/Encoded File </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/013/" target="_blank"><u>T1027.013</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload included both a Base64-encoded and XOR-encrypted inner payload. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Obfuscated Files or Information: SVG Smuggling </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1027/017/" target="_blank"><u>T1027.017</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The payload was contained in an “onload” attribute within an SVG image included in the malicious email. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Use Alternate Authentication Material: Web Session Cookie </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1550/004/" target="_blank"><u>T1550.004</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns using AiTM leveraged stealing and use of a victim’s session cookies to authenticate. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 16: Credential Access </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Modify Authentication Process: Multi-Factor Authentication </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1556/006/" target="_blank"><u>T1556.006</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Creating Application Passcodes to bypass 2FA and stealing a user’s “Scratch Keys,” which can be used in place of a 2FA token. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Adversary-in-the-Middle </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1557/" target="_blank"><u>T1557</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Previous campaigns used Evilginx2 as an AiTM toolkit to intercept credentials and session cookies. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 17: Collection </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Data Staged: Remote Data Staging </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1074/002/" target="_blank"><u>T1074.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltrated data was sent to an actor-controlled VPS prior to assumed long-term storage solutions. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/" target="_blank"><u>T1114</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>This group has emphasized collection of emails. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Email Collection: Remote Email Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1114/002/" target="_blank"><u>T1114.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are collected via API calls to the ZCS mail server and are not collected from emails stored directly on the victim’s device. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Automated Collection </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1119/" target="_blank"><u>T1119</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Upon execution, the JavaScript payload automatically collects all relevant information in stages. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Browser Session Hijacking </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1185/" target="_blank"><u>T1185</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>The JavaScript payload leverages the user’s authenticated browser session to make API requests as the user. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Archive Collected Data </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1560/" target="_blank"><u>T1560</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Emails are exfiltrated with GZIP compression. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<p><a class="ck-anchor"></a></p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 18: Discovery </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Account Discovery </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1087/" target="_blank"><u>T1087</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Stolen Global Access Lists provide the group with new users to target. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<p><a class="ck-anchor"></a></p>
</div>
</div>
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<div class="TableContainer Ltr SCXW76044448 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 19: Exfiltration </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Technique Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p class="text-align-center"><strong>Use</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/" target="_blank"><u>T1048</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Victim information was exfiltrated over both HTTPS and DNS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/002/" target="_blank"><u>T1048.002</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some payloads, especially ones with large amounts of data, were exfiltrated over HTTPS. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p><a href="https://attack.mitre.org/versions/v19/techniques/T1048/003/" target="_blank"><u>T1048.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW76044448 BCX8">
<div class="OutlineElement Ltr SCXW76044448 BCX8">
<p>Some smaller bandwidth payloads were exfiltrated over DNS using Base32 encoding. </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<h2><strong>Appendix B: MITRE D3FEND countermeasures </strong><a class="ck-anchor"></a></h2>
<p>See <a href="https://www.cisa.gov/#table20"><strong>Table 20</strong></a> for a mapping of several of the cybersecurity countermeasures mentioned in this advisory. <a class="ck-anchor"></a></p>
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<div class="TableContainer Ltr SCXW46665017 BCX8">
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em><strong>Table 20: MITRE D3FEND Countermeasures </strong></em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Countermeasure Title</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>ID</strong> </p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p class="text-align-center"><strong>Description</strong> </p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Application Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ApplicationHardening" target="_blank"><u>D3-AH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should immediately prioritize patching <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376" target="_blank"><u>CVE-2025-66376</u></a>.  </li>
<li>Organizations should promptly apply software updates to all email systems. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Isolate </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/tactic/d3f:Isolate/" target="_blank"><u>d3f:Isolate</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations that cannot feasibly patch should use alternative mail clients. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Credential Hardening </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:CredentialHardening" target="_blank"><u>D3-CH</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should consider using a third-party authentication service that supports passkeys to mediate access to ZCS and other services that do not natively support passkeys. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficAnalysis" target="_blank"><u>D3-NTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for significant amounts of outbound data being sent to IPs associated with VPS providers not used by the organization. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>DNS Traffic Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:DNSTrafficAnalysis" target="_blank"><u>D3-DNSTA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should monitor for frequent DNS queries to a suspicious domain for seemingly random subdomains. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Network Traffic Community Deviation </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:NetworkTrafficCommunityDeviation" target="_blank"><u>D3-NTCD</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should monitor for a sudden spike of connections to a server associated with a recently established domain. </li>
<li>Organizations should monitor for connections to internal services, such as webmail, from VPN providers. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Identifier Activity Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:IdentifierActivityAnalysis" target="_blank"><u>D3-IAA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Organizations should search for the listed known IOCs. </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p>Process Analysis </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="OutlineElement Ltr SCXW46665017 BCX8">
<p><a href="https://d3fend.mitre.org/technique/d3f:ProcessAnalysis" target="_blank"><u>D3-PA</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW46665017 BCX8">
<div class="ListContainerWrapper SCXW46665017 BCX8">
<ul type="disc">
<li>Organizations should search ZCS log files for specific commands used by the malicious script. </li>
<li>Organizations should search the localStorage property in web browsers for the ZCS webmail client for “ZimbraWeb” Application Passcodes. </li>
</ul>
</div>
</div>
</td>
</tr>
<tr>
<td>Message Analysis</td>
<td><a href="https://d3fend.mitre.org/technique/d3f:MessageAnalysis">D3-MA</a></td>
<td>Organizations that suspect they have victims of this campaign should search for emails with a malicious payload to identify other victims.</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Flaws in Passkey Implementation Show Old Attacks Still Work]]></title>
<description><![CDATA[Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.]]></description>
<link>https://tsecurity.de/de/3688781/it-security-nachrichten/flaws-in-passkey-implementation-show-old-attacks-still-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688781/it-security-nachrichten/flaws-in-passkey-implementation-show-old-attacks-still-work/</guid>
<pubDate>Thu, 23 Jul 2026 13:02:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027]]></title>
<description><![CDATA[Microsoft Entra is making passkeys the default sign-in method starting September 2026, with Microsoft-provided SMS and voice authentication fully retired by February 2027. There's no opt-out for the final deadline, so here's the complete timeline and prep checklist IT admins need to act on now.
T...]]></description>
<link>https://tsecurity.de/de/3687073/windows-tipps/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687073/windows-tipps/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027/</guid>
<pubDate>Wed, 22 Jul 2026 19:01:34 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Entra is making passkeys the default sign-in method starting September 2026, with Microsoft-provided SMS and voice authentication fully retired by February 2027. There's no opt-out for the final deadline, so here's the complete timeline and prep checklist IT admins need to act on now.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/07/22/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027/">Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Yubico Released YubiKey 5.8 With Secure Enterprise Workflows and AI-driven Approvals]]></title>
<description><![CDATA[Yubico has announced the release of YubiKey 5.8, a firmware update that enhances the functionality of hardware-backed passkeys beyond secure login authentication, extending into verified authorization workflows. This update, announced on July 21, 2026, is designed to support enterprise document s...]]></description>
<link>https://tsecurity.de/de/3685537/it-security-nachrichten/yubico-released-yubikey-58-with-secure-enterprise-workflows-and-ai-driven-approvals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685537/it-security-nachrichten/yubico-released-yubikey-58-with-secure-enterprise-workflows-and-ai-driven-approvals/</guid>
<pubDate>Wed, 22 Jul 2026 09:37:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yubico has announced the release of YubiKey 5.8, a firmware update that enhances the functionality of hardware-backed passkeys beyond secure login authentication, extending into verified authorization workflows. This update, announced on July 21, 2026, is designed to support enterprise document signing, digital identity wallets, secure payments, and human approvals for AI-driven actions. As enterprises face […]</p>
<p>The post <a href="https://cybersecuritynews.com/yubikey-5-8-released/">Yubico Released YubiKey 5.8 With Secure Enterprise Workflows and AI-driven Approvals</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys in der Praxis – Teil 1: Die Architektur von Passkeys]]></title>
<description><![CDATA[So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.]]></description>
<link>https://tsecurity.de/de/3683013/it-security-nachrichten/passkeys-in-der-praxis-teil-1-die-architektur-von-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683013/it-security-nachrichten/passkeys-in-der-praxis-teil-1-die-architektur-von-passkeys/</guid>
<pubDate>Tue, 21 Jul 2026 10:23:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys in der Praxis – Teil 1: Die Architektur von Passkeys]]></title>
<description><![CDATA[So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.]]></description>
<link>https://tsecurity.de/de/3682903/it-nachrichten/passkeys-in-der-praxis-teil-1-die-architektur-von-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682903/it-nachrichten/passkeys-in-der-praxis-teil-1-die-architektur-von-passkeys/</guid>
<pubDate>Tue, 21 Jul 2026 09:18:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3681353/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681353/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Mon, 20 Jul 2026 16:18:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5e2c46e97cc"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effect]]></title>
<description><![CDATA[The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft]]></description>
<link>https://tsecurity.de/de/3673148/it-security-nachrichten/passkeys-will-soon-be-the-default-authentication-method-in-microsoft-entra-id-heres-what-it-means-for-users-and-when-the-changes-come-into-effect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673148/it-security-nachrichten/passkeys-will-soon-be-the-default-authentication-method-in-microsoft-entra-id-heres-what-it-means-for-users-and-when-the-changes-come-into-effect/</guid>
<pubDate>Thu, 16 Jul 2026 12:54:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3672665/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672665/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Thu, 16 Jul 2026 09:32:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5888c7c4ad1"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vermeiden Sie diese fatalen IT-Fehler im Urlaub: Gehen Sie stattdessen so vor]]></title>
<description><![CDATA[Reisen macht in der Regel Spaß, besonders im Sommer, wenn alle im Urlaub sind. Daher kann es leicht passieren, dass man auch die Sorgen um die Cybersicherheit zu Hause zurücklässt. Leider machen Kriminelle keine Pause. Tatsächlich setzen sie gerade auf Ihre nachlässigen Gewohnheiten.



Doch mit ...]]></description>
<link>https://tsecurity.de/de/3672589/it-nachrichten/vermeiden-sie-diese-fatalen-it-fehler-im-urlaub-gehen-sie-stattdessen-so-vor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672589/it-nachrichten/vermeiden-sie-diese-fatalen-it-fehler-im-urlaub-gehen-sie-stattdessen-so-vor/</guid>
<pubDate>Thu, 16 Jul 2026 09:18:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reisen macht in der Regel Spaß, besonders im Sommer, wenn alle im <a href="https://www.pcwelt.de/article/2792204/mit-chatgpt-den-urlaub-planen-lohnt-sich-das-oder-nicht.html" target="_blank" rel="noreferrer noopener">Urlaub</a> sind. Daher kann es leicht passieren, dass man auch die Sorgen um die Cybersicherheit zu Hause zurücklässt. Leider machen Kriminelle keine Pause. Tatsächlich setzen sie gerade auf Ihre nachlässigen Gewohnheiten.</p>



<p>Doch mit ein paar kleinen Anpassungen können Sie Ihre freie Zeit wieder ganz unbeschwert genießen. Insbesondere diese vier Maßnahmen befassen sich mit Problemen, die immer wieder in den Nachrichten auftauchen – und sie sind recht einfach umzusetzen.</p>



<h2 class="wp-block-heading">Behalten Sie Ihre Bordkarte für sich</h2>



<p>Ihre Bordkarte kann viel über Sie preisgeben. Zunächst einmal kodieren Fluggesellschaften mehr Informationen in den Barcode, als auf der Karte angezeigt werden – Details wie Ihr Geburtsdatum, Ihre Reisepassnummer und Ihre Vielfliegernummer. </p>



<p>Ein besonders drastisches Beispiel liefert die US-Billigfluglinie Frontier Airlines. <a href="https://www.tomshardware.com/tech-industry/cyber-security/frontier-airlines-site-leaks-all-personal-info-with-just-a-glance-at-a-boarding-pass-researcher-claims-booking-number-and-last-name-nets-you-every-passengers-personal-info-including-address-passport-tsa-precheck-and-most-credit-card-info">Es stellt sich heraus,</a> dass jeder, der eine Kopie des QR-Codes eines Passagiers besitzt, sensible Daten aus dessen Konto abrufen kann – wie beispielsweise hinterlegte Kreditkartennummer, Anschrift, TSA-PreCheck-Nummer und Reisepassnummer –, indem er eine Anfrage an eine API stellt, die die Website des Unternehmens betreibt.</p>



<p>Selbst abgesehen von der Gefahr des Identitätsdiebstahls kann Ihnen jemand, der Ihre Bordkarte im Blick hat, erheblichen Ärger bereiten. Mit Ihrem vollständigen Namen und dem Bestätigungscode kann diese Person Ihre Flugdaten ändern oder Ihre Buchung sogar komplett stornieren.</p>



<p>Das Fazit: Schirmen Sie Ihren Bildschirm oder Ihr ausgedrucktes Ticket vor allen außer dem Mitarbeiter am Gate ab. Und veröffentlichen Sie auf keinen Fall ein Bild Ihrer Bordkarte in den sozialen Medien.</p>



<h2 class="wp-block-heading">Vermeiden Sie öffentliche Computer</h2>



<p>Die Nutzung eines gemeinsam genutzten PCs in einem Hotel (oder an einem anderen öffentlichen Ort) birgt Risiken. Diese Computer können mit Malware infiziert sein, die alle eingegebenen Daten, einschließlich Passwörter, erfasst. Oder sie ermöglichen es einem Hacker, sich unbefugten Zugriff auf alle Konten zu verschaffen, bei denen Sie sich angemeldet haben.</p>



<p>Auch durch ausgedruckte Dokumente können Sie digitale Spuren hinterlassen. Manche Drucker speichern eine Kopie der Druckaufträge – und aller darin enthaltenen persönlichen Daten.</p>



<p>Das Fazit: Verzichten Sie so weit wie möglich auf öffentliche Computer und Drucker. Wenn Sie unbedingt einen öffentlichen Computer nutzen müssen, verwenden Sie ein Inkognito-Browserfenster und <a href="https://www.pcwelt.de/article/3128548/hoeren-sie-auf-passwoerter-zu-verwenden-ersetzen-sie-diese-unbedingt-jetzt-alle-durch-passkeys.html" target="_blank" rel="noreferrer noopener">melden Sie sich mit einem Passkey statt mit einem Passwort an.</a></p>



<h2 class="wp-block-heading">Verwenden Sie ein VPN in öffentlichen WLAN-Netzen</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a588583e2797"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Proton-homescreen.png?w=1200" alt="Proton VPN" class="wp-image-3185467" width="1200" height="777" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Sam Singleton</p></div>



<p>Öffentliches WLAN kann aus zwei Gründen gefährlich sein. Erstens könnten andere Personen, die sich mit Ihnen im selben legitimen Netzwerk befinden, versuchen, Ihre Aktivitäten auszuspionieren. Zweitens könnten Sie sich versehentlich mit einem gefälschten kostenlosen WLAN-Netzwerk verbinden.</p>



<p>Im ersten Fall ist das Risiko, dass Sie sensible Daten an einen Hacker verlieren, heutzutage geringer. Die meisten Verbindungen zu Websites sind mittlerweile standardmäßig verschlüsselt. Einige wenige nutzen jedoch für bestimmte Aktivitäten nach wie vor unverschlüsselte Verbindungen, sodass das Risiko nicht gleich Null ist.</p>



<p>Was gefälschte WLAN-Netzwerke betrifft, so kann es passieren, dass Sie über gefälschte Anmeldeseiten Ihre Zugangsdaten preisgeben oder sogar Malware auf Ihr Gerät geschleust wird.</p>



<p>Das Fazit: Nutzen Sie Ihre Mobilfunkdaten für sensible Angelegenheiten wie Bankgeschäfte oder medizinische Belange. Ist dies nicht möglich, verwenden Sie ein <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">VPN (die besten VPNs stellen wir hier vor),</a> wenn Sie sich mit einem öffentlichen WLAN verbinden. Ein gutes VPN fungiert als geschützter Tunnel, der all Ihre Aktivitäten verschlüsselt und die von Ihnen besuchten Websites vor Netzwerkbeobachtern verbirgt.</p>



<h2 class="wp-block-heading">Verwenden Sie Ihr eigenes USB-Ladegerät</h2>



<p>Haben Sie schon einmal von„Juice Jacking“ gehört? Es handelt sich um eine beängstigend klingende, aber eher seltene Taktik, mit der auf gespeicherte Daten auf einem Smartphone zugegriffen wird – oder um Malware darauf zu installieren.</p>



<p>„Juice Jacking“ funktioniert folgendermaßen: Ein Hacker manipuliert einen USB-Ladeanschluss, wie er an Flughäfen, in Hotels und an anderen öffentlichen Orten zu finden ist. Wenn Sie Ihr Smartphone anschließen, sind Sie potenziell anfällig für Angriffe. Und was die Sache noch komplizierter macht: <a href="https://www.pcwelt.de/article/1781402/handy-nicht-an-oeffentlichen-ladestationen-laden.html" target="_blank" rel="noreferrer noopener">Sicherheitsexperten vertreten nach wie vor widersprüchliche Meinungen darüber, wie groß die Bedrohung durch „Juice Jacking“ tatsächlich ist.</a></p>



<p>Das Fazit: Verwenden Sie einfach Ihr eigenes USB-Ladegerät. Das hat einen doppelten Vorteil: Sie müssen sich weder Gedanken über „Juice Jacking“ noch über elektrische Schäden durch ein minderwertiges Ladegerät machen. (Ich habe einmal durch ein minderwertiges Ladegerät einen Anschluss an meinem Smartphone kurzgeschlossen. Das war wirklich ärgerlich.)</p>



<p>Ist das keine Option? Schalten Sie Ihr Smartphone vorsichtshalber aus, bevor Sie ein öffentliches Ladegerät verwenden.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artificial Intelligence]]></title>
<description><![CDATA[Latest from todaynewsDeepMind CEO again pushes for a frontier AI standards bodyDemis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.By Evan SchumanJul 15, 20268 minsArtificial IntelligenceGovernmentLaws and Regulation...]]></description>
<link>https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671869/ai-nachrichten/artificial-intelligence/</guid>
<pubDate>Wed, 15 Jul 2026 23:02:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><section class="latest-content"><div class="container"><header class="latest-content__header"><h2 class="latest-content__title sr-only"><span>Latest from today</span></h2></header><div class="grid latest-content__content"><div class="col-12 col-7@md col-8@lg"><div class="latest-content__content-featured"><a class="card card--xxl " href="https://www.computerworld.com/article/4197511/deepmind-ceo-again-pushes-for-a-frontier-ai-standards-body-2.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">news</span></div><div class="card__image"><div class="insider-image"><div class="image"><img width="400px" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197511-0-18848000-1784149211-shutterstock_2540223947.jpg?quality=50&amp;strip=all&amp;w=1046" data-id="idg_render_hero_index_one_card_image" sizes="
            (min-resolution: 3dppx) and (max-width: 600px) 900px,
            (min-resolution: 3dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 2dppx) and (max-width: 600px) 900px,
            (min-resolution: 2dppx) and (max-width: 1200px) 1200px,

            (min-resolution: 1dppx) and (max-width: 600px) 900px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1300px" alt="Image" loading="eager"></div></div></div><h3 class="card__title">DeepMind CEO again pushes for a frontier AI standards body</h3><p class="card__description">Demis Hassabis argues that a US government-led industry effort is needed to keep AGI-like developments safe; analysts aren’t so sure.</p><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T20:59:29+00:00">Jul 15, 2026</span></span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a>
		</div><div class="grid grid--cols-7@md grid--cols-8@lg latest-content__content-main"><div class="col-12 col-7@md col-4@lg latest-content__card-main"><a class="card " href="https://www.computerworld.com/article/4197437/apples-openai-lawsuit-the-lunacy-of-trying-to-limit-what-ex-employees-can-tell-future-employers.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197437-0-98299000-1784131210-thinkstockphotos-493608259-100632547-orig.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">Apple’s OpenAI lawsuit: The lunacy of trying to limit what ex-employees can tell future employers</h3><div class="card__info"><span>By Evan Schuman</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:59:35+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Government</span></span><span class="card__tag"><span class="tag">Laws and Regulations</span></span></div></a></div><div class="col-12 col-7@md col-4@lg latest-content__card-main"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/4197338/what-problems-would-an-ai-speaker-from-openai-actually-solve.html" aria-label="Go to content"><div class="card__header"><span class="card__content-type">opinion</span></div><div class="card__image">
			<div class="insider-image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4197338-0-98391100-1784130807-Apple-HomePod-mini-color-lineup.jpg?quality=50&amp;strip=all&amp;w=697" data-id="idg_render_hero_index_two_three_break" sizes="(min-resolution: 3dppx) and (max-width: 600px) 600px,
            (min-resolution: 3dppx) and (max-width: 1200px) 900px,

            (min-resolution: 2dppx) and (max-width: 600px) 600px,
            (min-resolution: 2dppx) and (max-width: 1200px) 900px,

            (min-resolution: 1dppx) and (max-width: 600px) 600px,
            (min-resolution: 1dppx) and (max-width: 2000px) 1024px" alt="Image"></div></div></div><h3 class="card__title">What problems would an AI speaker from OpenAI actually solve?</h3><div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T15:52:45+00:00">Jul 15, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Vendors and Providers</span></span></div></a></div></div></div><div class="col-12 col-5@md col-4@lg latest-content__content-secondary"><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4192438/how-to-unionize-your-tech-workplace.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">feature</span></div><h3 class="card__title">How to unionize your tech workplace</h3><div class="card__info"><span>By Robert Mitchell</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T11:00:00+00:00">Jul 15, 2026</span></span><span>18 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Careers</span></span><span class="card__tag"><span class="tag">IT Jobs</span></span><span class="card__tag"><span class="tag">Technology Industry</span></span></div></a>
		</div><div class="latest-content__card-secondary"><span class="nativo-loading"></span><a class="card nativo" href="https://www.computerworld.com/article/1613762/android-widgets.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">tip</span></div><h3 class="card__title">5 wild ways to make Android widgets more useful</h3><div class="card__info"><span>By JR Raphael</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T09:45:00+00:00">Jul 15, 2026</span></span><span>12 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Mobile Apps</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Microsoft is forcing an enterprise transition to passkeys</h3><div class="card__info"><span>By Taryn Plumb</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-15T02:04:06+00:00">Jul 14, 2026</span></span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Access Control</span></span><span class="card__tag"><span class="tag">Authentication</span></span><span class="card__tag"><span class="tag">Identity and Access Management</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196704/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Siri AI steals the show as the iOS 27 public beta lands</h3><div class="card__info"><span>By Jonny Evans</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T15:47:35+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Operating Systems</span></span><span class="card__tag"><span class="tag">iOS</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196309/with-its-latest-layoffs-microsoft-goes-all-in-on-ai.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">opinion</span></div><h3 class="card__title">With its latest layoffs, Microsoft goes all in on AI</h3><div class="card__info"><span>By Preston Gralla</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T11:00:00+00:00">Jul 14, 2026</span></span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">IT Strategy</span></span><span class="card__tag"><span class="tag">Microsoft</span></span></div></a>
		</div><div class="latest-content__card-secondary"><a class="card " href="https://www.computerworld.com/article/4196652/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures.html" aria-label="Go to content"><div class="card__header"> <span class="card__content-type">news</span></div><h3 class="card__title">Forg365 industrializes Microsoft 365 phishing with AI-generated lures</h3><div class="card__info"><span>By Prasanth Aby Thomas</span></div>
		<div class="card__info card__info--light"><span><span itemprop="datePublished" content="2026-07-14T09:51:16+00:00">Jul 14, 2026</span></span><span>4 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span><span class="card__tag"><span class="tag">Office Suites</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></a>
		</div></div></div></div></section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><div class="content-listing-articles"><div class="container"><h2 class="content-listing-articles__title">Articles</h2><div class="content-listing-articles__container content-listing-articles__container--collapsed" data-collapse-articles="6" data-content-listing-articles><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196365/openclaw-becomes-a-nonprofit-foundation-as-it-seeks-to-be-the-switzerland-of-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’</h3><p class="card__description">Analysts and consultants applaud the move as potentially delivering the development consistency that the current offerings lack, but some worry that treating the company as neutral is a mistake.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Evan Schuman</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>8 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Nonprofits</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196262/ai-is-killing-low-cost-smartphones.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">AI is killing low cost smartphones</h3><p class="card__description">Data from Omdia and Counterpoint shows that while Apple and Samsung thrive, the rest of the industry takes a dive</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Mobile Phones</span></span><span class="card__tag"><span class="tag">Smartphones</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4196220/meta-pulls-instagram-ai-feature-amid-privacy-concerns.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta pulls Instagram AI feature amid privacy concerns</h3><p class="card__description">By specifying a public account, users could allow the AI ​​model to use the person’s images as a reference without the account holder being notified.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Viktor Eriksson</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>1 min</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Instagram</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195176/qa-how-google-plans-to-reinvent-the-spreadsheet-with-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">feature</span></div><h3 class="card__title">Q&amp;A: How Google plans to reinvent the spreadsheet with AI</h3><p class="card__description">Soon, Google wants to see AI doing the spreadsheet busywork, says Eric Birnbaum, director of product management for Google Sheets.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Matthew Finnegan</span></div> <div class="card__info card__info--light"><span>Jul 13, 2026 </span><span>10 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Google Sheets</span></span><span class="card__tag"><span class="tag">Google Workspace</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">brandpost</span><span class="card__sponsor-text">Sponsored by Tether</span></div><h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3><p class="card__description"></p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By tether</span></div> <div class="card__info card__info--light"><span>Jul 9, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195828/rotten-to-its-core-apple-files-an-explosive-lawsuit-against-openai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news analysis</span></div><h3 class="card__title">‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI</h3><p class="card__description">Apple accuses OpenAI and former Apple Vice President Tang Tan of extensive coordinated data theft and asks whether OpenAI’s hardware plans are based around exfiltrated Apple info.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row "><a class="grid content-row-article" href="https://www.computerworld.com/article/4195657/apple-is-prepping-for-life-after-the-ai-gold-rush.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">opinion</span></div><h3 class="card__title">Apple is prepping for life after the AI gold rush</h3><p class="card__description">The company's interest in compression of AI models is the right approach.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Jonny Evans</span></div> <div class="card__info card__info--light"><span>Jul 11, 2026 </span><span>6 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195678/microsoft-exchange-server-on-prem-gets-a-little-harder-to-use.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Microsoft Exchange Server on prem gets a little harder to use</h3><p class="card__description">The lightweight web client is going away, placing more demands on systems still clinging to Microsoft’s on-prem email system.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Email Clients</span></span><span class="card__tag"><span class="tag">Microsoft Exchange</span></span><span class="card__tag"><span class="tag">Microsoft Outlook</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195636/mistral-joins-rush-to-build-physical-ai.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Mistral joins rush to build physical AI</h3><p class="card__description">Its Robostral Navigate AI model needs input from just one color camera, doing without Lidar, depth sensors, or multiple viewpoints.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Robotics</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195628/apple-will-buy-more-us-made-components-from-broadcom.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Apple will buy more US-made components from Broadcom</h3><p class="card__description">Chips and thin-film bulk acoustic resonator (FBAR) filters are on the menu.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Maxwell Cooter</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>2 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Networking</span></span><span class="card__tag"><span class="tag">Wi-Fi</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195528/meta-launches-low-cost-muse-spark-1-1-as-enterprise-ai-spending-comes-under-scrutiny-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">Meta launches low-cost Muse Spark 1.1 as enterprise AI spending comes under scrutiny</h3><p class="card__description">Meta says the model delivers competitive performance against OpenAI, Anthropic, and Google offerings while costing a fraction as much to run.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Anirban Ghoshal</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/1614899/android-contacts-management-ultimate-guide.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">how-to</span></div><h3 class="card__title">The ultimate guide to Android contacts management</h3><p class="card__description">Your Android phone's contacts are much more than just a glorified Rolodex. Ready for an unexpected productivity upgrade? </p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By JR Raphael</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>16 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Android</span></span><span class="card__tag"><span class="tag">Google</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div><div class="content-listing-articles__row content-listing-articles__row--hide"><a class="grid content-row-article" href="https://www.computerworld.com/article/4195494/openai-launches-chatgpt-work-as-it-broadens-gpt-5-6-rollout-2.html" aria-label="Go to content"><div class="col-12 col-7@md content-row-article__main"><div class="card card--lg"><div class="card__header"><span class="card__content-type">news</span></div><h3 class="card__title">OpenAI launches ChatGPT Work as it broadens GPT-5.6 rollout</h3><p class="card__description">The enterprise AI agent combines ChatGPT, Codex, and GPT-5.6 to automate workplace tasks as OpenAI broadens rollout of its latest frontier models.</p></div></div><div class="col-12 col-4@md col-start-9@md content-row-article__secondary"><div class="card card--lg"><div class="card__info"><span>By Gyana Swain</span></div> <div class="card__info card__info--light"><span>Jul 10, 2026 </span><span>5 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Productivity Software</span></span></div></div></div></a></div></div><div class="grid content-listing-articles__button-wrapper">
			<div class="col-6 col-4@md col-start-5@md"><div class="content-listing-articles__button-show">
					<button class="button button--tertiary" type="button" data-toggle="expand">
						<span>Show more</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-down"></use>
							</svg>
						</span>
					</button>
				</div>
				<div class="content-listing-articles__button-show content-listing-articles__button-show--hide">
					<button class="button button--tertiary" type="button" data-toggle="collapse">
						<span>Show less</span>
						<span>
							<svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
								<use xlink:href="#icon-chevron-up"></use>
							</svg>
						</span>
					</button>
				</div></div><div class="col-6 col-4@md content-listing-articles__button-view-all">
						<a class="button" href="https://www.computerworld.com/artificial-intelligence/feed/page/2/" target="_blank"> View all </a></div></div></div></div><section class="suggested-content-upcoming-events"><div class="container">
				<h2 class="suggested-content-upcoming-events__title">Upcoming Events</h2><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cio-100-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Sep/24</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/03/4141846-0-37933000-1772809522-CIO-Summit-2025_17.jpg?quality=50&amp;strip=all&amp;w=1045" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cio-100-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CIO 100 Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>24 Sep 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Microsoft 365</span></span></div></div>
			</div>
		</a><a class="grid suggested-content-upcoming-events__item" href="https://event.foundryco.com/cso-awards-conference-uk/" aria-label="Go to content"><div class="col-12 col-3@md suggested-content-upcoming-events__date-label dd"><span class="date-label">Nov/26</span></div><div class="col-12 col-4@md col-5@xl suggested-content-upcoming-events__image"><div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4141741-0-97812100-1780312469-60CB82BE-5D6E-40E0-8E5E-0151C8C46E7F.jpg?quality=50&amp;strip=all&amp;w=929" alt="Image"></div></div>
			<div class="col-12 col-5@md col-4@xl suggested-content-upcoming-events__card">
				<div class="card card--xl">
					<div class="card__header"><span class="card__content-type">conference</span><span class="card__external-link-icon" data-url="https://event.foundryco.com/cso-awards-conference-uk/"><svg class="icon icon--sm" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg"> <use xlink:href="#icon-arrow-up-right-from-square"></use></svg></span></div><h3 class="card__title">CSO Awards &amp; Conference UK</h3><div class="card__info card__info--light"><span>26 Nov 2026</span><span>London, UK</span></div>
		<div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span></div></div>
			</div>
		</a></div><div class="suggested-content-upcoming-events__button-container container">
						<a class="button" href="https://www.computerworld.com/events/"> View all events</a>
					</div>
				
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-resources">
				<div class="container">
				<h2 class="related-content-resources__title">Resources</h2><div class="grid related-content-resources__content"><div class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-resources__main-content">
			<div class="col-12 col-7@md col-6@lg">
				<a class="card card--xxl" href="https://us.resources.computerworld.com/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
					<div class="card__header">
						<span class="card__content-type">whitepaper</span>
					</div>
					<h3 class="card__title">Accelerate your cloud migration with Atlassian FastShift</h3>
					<p class="card__description"></p><p>Turn an Atlassian cloud migration into a faster, more predictable transformation. In this session, you’ll walk through the FastShift playbook.</p>
<p>The post <a rel="nofollow" href="https://com.wp.idg.zone/resources/accelerate-your-cloud-migration-with-atlassian-fastshift-6/">Accelerate your cloud migration with Atlassian FastShift</a> appeared first on <a rel="nofollow" href="https://com.wp.idg.zone/">Whitepaper Repository –</a>.</p>

					<div class="card__info">
						<span>
						By 
						Atlassian
						</span>
					</div>
					<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
			</div>
			<div class="col-2 related-content-resources__featured-image-wrapper">
				<img width="400px" loading="lazy" class="related-content-resources__image-featured" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040704.83.png" alt="Image">
			</div>
		</div><div class="col-12 col-5@md col-4@lg col-start-9@lg related-content-resources__cards"><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/warum-sich-teams-fur-cloud-entscheiden-9?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Warum sich Teams für Cloud entscheiden</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040716.4772.png" alt="Image">
				</div>
			</div><div class="grid grid--cols-5@md grid--cols-4@lg related-content-resources__card-wrapper">
				<div class="col-12 col-5@md col-3@lg">
					<a class="card card--sm" href="https://us.resources.computerworld.com/resources/pourquoi-les-equipes-optent-pour-la-solution-cloud-3?utm_source=rss-feed&amp;utm_medium=rss&amp;utm_campaign=feed" rel="noreferrer" aria-label="Go to content">
						<div class="card__header">
							<span class="card__content-type">whitepaper</span>
						</div>
						<h3 class="card__title">Pourquoi les équipes optent pour la solution cloud</h3>
						<div class="card__info">
							<span>
							By 
							Atlassian
							</span>
						</div>
						<div class="card__info card__info--light"><span>14 Jul 2026</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Business Operations</span></span><span class="card__tag"><span class="tag">Cloud</span></span><span class="card__tag"><span class="tag">Digital Transformation</span></span></div></a>
				</div>
				<div class="col-1">
					<img width="400px" loading="lazy" class="related-content-resources__image-side" src="https://us.resources.computerworld.com/wp-content/uploads/2026/07/atl_logo1784040728.9116.png" alt="Image">
				</div>
			</div></div>
		</div><div class="related-content-resources__button-container">
			<a class="button" target="_blank" href="https://us.resources.computerworld.com/"> View all </a>
		</div></div>
			</section><div class="advert">
						<div class="container advert__container">
							<div class="advert__content">
								<div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false"></div>
							</div>
						</div>
					</div><section class="related-content-podcasts"><div class="container"><h2 class="related-content-podcasts__title">Podcasts</h2><div class="grid related-content-podcasts__content"><a class="col-12 col-7@md col-8@lg grid grid--cols-7@md grid--cols-8@lg related-content-podcasts__main-content" href="https://www.computerworld.com/podcasts/2-minute-tech-briefing/" aria-label="Go to content"><div class="col-12 col-7@md col-2@lg related-content-podcasts__image">
			<div class="image image--aspect-ratio-1-1">
				<img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2025/11/100065453-0-01782600-1762961273-2-min-tech-briefing-logo-16x9-4.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Image">
			</div>
		</div><div class="col-12 col-7@md col-6@lg"><div class="card card--xl"><div class="card__header"><span class="card__content-type"> podcasts</span></div><h3 class="card__title">2-Minute Tech Briefing</h3><p class="card__description">Catch up on the latest enterprise IT news in a fast-paced video briefing with host Arnold Davick. Listen to the show on Computerworld, YouTube, Apple and Spotify.</p><div class="card__info card__info--light"><span>81  episodes</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Emerging Technology</span></span></div></div></div></a><ul class="col-12 col-5@md col-4@lg col-start-9@lg related-content-podcasts__cards"><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 81</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li><li class="related-content-podcasts__card"><a href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to episode"><div class="related-content-podcasts__episode-label">
			<span class="episode-label">
				<span> Ep. 80</span>
				<span>
				<svg class="icon" viewbox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
					<use xlink:href="#icon-podcast"></use>
				</svg>
			</span>
			</span>
		</div><div class="card card--xs"><h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3><div class="card__info">
				<span>By Arnold Davick</span>
			</div><div class="card__info card__info--light">
			<span>Mar 20, 2024</span><span>2 mins</span>
		</div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div></a></li></ul></div></div></section><section class="related-content-video"><div class="container"><h2 class="related-content-video__title">Video on demand</h2><div class="grid related-content-video__main">        <div class="col-12 col-4@lg related-content-video__main-card card card--xl">
            <div class="card__header"><span class="card__content-type">video</span></div>            
            <a class="card card--xl" href="https://www.computerworld.com/video/4196734/why-ai-agents-fail-when-enterprises-dont-define-the-job.html" aria-label="Go to content">
                <h3 class="card__title">Why AI agents fail when enterprises don’t define the job</h3>            </a>
                            <p class="card__description mt-3">Enterprises are investing heavily in AI agents, but many projects fail when companies skip clear goals, guardrails, governance and success metrics.</p>
            
                         <div class="card__info card__info--light"><span>Jul 14, 2026 </span><span>33 mins</span></div><div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div>        </div>
                <div class="col-12 col-8@lg related-content-video__video">
                            <div class="youtube-video">
                    &gt;
					
				</div>                </div>
                    </div>
        </div><div class="related-content-video__cards-container">
                        <div class="related-content-video__cards-wrap">
                            <ul class="grid related-content-video__cards">        <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4193952/why-enterprise-ai-projects-stall-before-delivering-real-value.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4193952-0-52301800-1783446508-youtube-thumbnail-gu6x40jhZ1s_3cbf50.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">Why enterprise AI projects stall before delivering real value</h3>
                                         <div class="card__info card__info--light"><span>Jul 7, 2026 </span><span>29 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">ROI and Metrics</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4191262/how-ai-is-breaking-job-interviews-skills-testing-and-evaluation.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4191262-0-24248500-1782847008-youtube-thumbnail-lVEejCXC4lU_b223c5.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is breaking job interviews, skills testing and evaluation</h3>
                                         <div class="card__info card__info--light"><span>Jun 30, 2026 </span><span>32 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Hiring</span></span><span class="card__tag"><span class="tag">IT Skills and Training</span></span></div>                </div>
            </a>
        </li>
                <li class="col-4@md related-content-video__card">
            <a class="related-content-video__card-link" href="https://www.computerworld.com/video/4188534/how-ai-is-reshaping-cybersecurity.html" aria-label="Go to content">
                <div class="related-content-video__card-image">
                    <div class="image">
                        <img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4188534-0-45176600-1782243369-youtube-thumbnail-5DLoQMU0nZc_de9df9.jpg?quality=50&amp;strip=all&amp;w=300" alt="Image" sizes="300px">
                    </div>
                </div>
                <div class="card card--xs">
                    <h3 class="card__title">How AI is reshaping cybersecurity</h3>
                                         <div class="card__info card__info--light"><span>Jun 23, 2026 </span><span>44 mins</span></div>                    <div class="card__tags"><span class="card__tag"><span class="tag">Cyberattacks</span></span><span class="card__tag"><span class="tag">Cybercrime</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div>                </div>
            </a>
        </li>
        </ul></div></div><div class="related-content-video__button-container"><a class="button" target="_self" href="https://www.computerworld.com/videos/">See all videos</a></div></section></div><section class="suggested-content-various"><div class="container"><div class="grid suggested-content-various__content"><div class="col-12 col-3@lg">
			<h2 class="suggested-content-various__title">Show me more</h2><div class="suggested-content-various__filters"><span class="suggested-content-various__filter"><button class="chip chip--filter chip--active" type="button" data-filter-key="latest">Latest</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="article">Articles</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="podcast">Podcasts</button></span><span class="suggested-content-various__filter"><button class="chip chip--filter" type="button" data-filter-key="video">Videos</button></span></div>
		</div><div class="col-12 col-9@lg suggested-content-various__items-wrap"><div class="grid grid--cols-9@lg suggested-content-various__items"><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4195055/apple-finally-calls-time-on-15-year-old-device-support.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">opinion</span> </div> <h3 class="card__title">Apple finally calls time on 15-year-old device support</h3> <div class="card__info"><span>By Jonny Evans</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T16:15:14+00:00">Jul 9, 2026</span><span>4 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Apple</span></span><span class="card__tag"><span class="tag">Smartphones</span></span><span class="card__tag"><span class="tag">iPhone</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4195055-0-47500100-1783613766-iPhone4s_3up_Photo_Siri_Sprgbd_PRINT.jpg?quality=50&amp;strip=all&amp;w=219" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194931/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">brandpost</span> <span class="card__sponsor-text">Sponsored by Tether</span></div> <h3 class="card__title">Physical AI will see the fusion of robotics and AI transform the world</h3> <div class="card__info"><span>By tether</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T11:11:53+00:00">9 Jul 2026</span><span>6 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194931-0-76347600-1783595551-QVAC-Paid-Ad-1-_-1200-x-800.png?w=375" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				article"><a class="suggested-content-various__link" href="https://www.computerworld.com/article/4194914/spacexai-launches-grok-4-5-touts-lower-coding-task-costs-than-ai-rivals-2.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">news</span> </div> <h3 class="card__title">SpaceXAI launches Grok 4.5, touts lower coding-task costs than AI rivals</h3> <div class="card__info"><span>By Prasanth Aby Thomas</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-07-09T10:26:11+00:00">Jul 9, 2026</span><span>5 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/07/4194914-0-24417700-1783592810-AI-vibe-coding-one-hand-is-robot-one-hand-is-human.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176380/microsoft-copilot-growth-claudebleed-risk-linkedin-gdpr-complaint-ep-84.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Microsoft Copilot Growth, ClaudeBleed Risk, LinkedIn GDPR Complaint | Ep. 84</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T15:04:16+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-46106000-1779462321-youtube-thumbnail-5PkKYThsKy8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4176367/chrome-gemini-ai-agents-cisa-infrastructure-cyber-resilience-ep-83.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">Chrome Gemini, AI Agents, CISA Infrastructure Cyber Resilience | Ep. 83</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-22T14:53:18+00:00">May 22, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-06017100-1779461653-youtube-thumbnail-XH7vduM7uz8.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				podcast"><a class="suggested-content-various__link" href="https://www.computerworld.com/podcast/4172579/ai-triage-gains-model-reviews-ask-jeeves-shutdown-ep-82.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">podcast</span> </div> <h3 class="card__title">AI Triage Gains, Model Reviews, Ask Jeeves Shutdown | Ep. 82</h3> <div class="card__info"><span>By Arnold Davick</span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-05-18T19:31:15+00:00">May 18, 2026</span><span>2 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/05/0-62824900-1779132751-youtube-thumbnail-P3R6blMndrU.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				latest,video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4185559/why-ai-agents-could-create-a-new-control-and-security-crisis.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Why AI agents could create a new control and security crisis</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-16T11:47:15+00:00">Jun 16, 2026</span><span>28 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Artificial Intelligence</span></span><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">IT Governance</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4185559-0-48713800-1781610470-youtube-thumbnail-uPpd9EJ4iNI_55eb26.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4182978/does-quality-suffer-when-ai-generates-code.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">Does quality suffer when AI generates code?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-09T14:32:51+00:00">Jun 9, 2026</span><span>35 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Code Security</span></span><span class="card__tag"><span class="tag">Developer</span></span><span class="card__tag"><span class="tag">Generative AI</span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4182978-0-61230000-1781015610-youtube-thumbnail-1hAfDQkuyhs_faa994.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div><div class="col-4@md col-3@lg suggested-content-various__item suggested-content-various__item--active" data-filter-value="
				video"><a class="suggested-content-various__link" href="https://www.computerworld.com/video/4180043/what-happens-when-ai-starts-selling-to-ai.html" aria-label="Go to content"><div class="card">
					<div class="card__header">
						<span class="card__content-type">video</span> </div> <h3 class="card__title">What happens when AI starts selling to AI?</h3> <div class="card__info"><span></span></div><div class="card__info card__info--light"><span itemprop="datePublished" content="2026-06-02T15:00:42+00:00">Jun 2, 2026</span><span>38 mins</span></div>
				 <div class="card__tags"><span class="card__tag"><span class="tag">Generative AI</span></span><span class="card__tag"><span class="tag">Procurement Software</span></span><span class="card__tag"><span class="tag">Salesforce Automation </span></span></div></div>
					<div class="image"><img width="400px" loading="lazy" src="https://www.computerworld.com/wp-content/uploads/2026/06/4180043-0-78180900-1780412479-youtube-thumbnail-jPv-TAenlto_c79318.jpg?quality=50&amp;strip=all&amp;w=444" alt="Image"></div>
				</a>
			</div></div></div></div></div></section>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft ändert seinen Anmeldevorgang: Was an deinem Arbeitscomputer bald anders läuft]]></title>
<description><![CDATA[Die sogenannte Entra-ID ist in vielen Unternehmen Pflicht. Künftig sind dort moderne Passkeys der Standard, Anmeldeformen wie SMS oder Sprachanrufe streicht Microsoft.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3670206/it-nachrichten/microsoft-aendert-seinen-anmeldevorgang-was-an-deinem-arbeitscomputer-bald-anders-laeuft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670206/it-nachrichten/microsoft-aendert-seinen-anmeldevorgang-was-an-deinem-arbeitscomputer-bald-anders-laeuft/</guid>
<pubDate>Wed, 15 Jul 2026 11:48:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die sogenannte Entra-ID ist in vielen Unternehmen Pflicht. Künftig sind dort moderne Passkeys der Standard, Anmeldeformen wie SMS oder Sprachanrufe streicht Microsoft.<a href="https://t3n.de/news/microsoft-aendert-seinen-anmeldevorgang-was-an-deinem-arbeitscomputer-bald-anders-laeuft-1752897/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkey-Registrierung: So kapern Kriminelle sie per Voice-Phishing]]></title>
<description><![CDATA[Passkeys gelten als ein entscheidender Schritt in Richtung einer passwortlosen, phishing-resistenten Zukunft. Doch gerade die Einführung solch robuster Authentifizierungsmechanismen wird zunehmend von raffinierten Hackern als Einfallstor missbraucht. 

Tags: #Cyber Crime | #Passkeys | #Phishing]]></description>
<link>https://tsecurity.de/de/3670108/it-security-nachrichten/passkey-registrierung-so-kapern-kriminelle-sie-per-voice-phishing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670108/it-security-nachrichten/passkey-registrierung-so-kapern-kriminelle-sie-per-voice-phishing/</guid>
<pubDate>Wed, 15 Jul 2026 11:08:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920.jpg" class="attachment-full size-full wp-post-image" alt="Voice Phishing" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/07/Voice-Phishing-Shutterstock-2793364849-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Passkey-Registrierung: So kapern Kriminelle sie per Voice-Phishing 1"></p>
    Passkeys gelten als ein entscheidender Schritt in Richtung einer passwortlosen, phishing-resistenten Zukunft. Doch gerade die Einführung solch robuster Authentifizierungsmechanismen wird zunehmend von raffinierten Hackern als Einfallstor missbraucht. 

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/passkeys-en">#Passkeys</a> | <a href="https://www.it-daily.net/thema/phishing">#Phishing</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669425/it-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:32:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is forcing an enterprise transition to passkeys]]></title>
<description><![CDATA[Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.



Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based iden...]]></description>
<link>https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669414/it-security-nachrichten/microsoft-is-forcing-an-enterprise-transition-to-passkeys/</guid>
<pubDate>Wed, 15 Jul 2026 04:20:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice.</p>



<p class="wp-block-paragraph">Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And following a transition period, Microsoft-provided SMS and voice authentication will officially end on February 1, 2027.</p>



<p class="wp-block-paragraph">With this move, Microsoft seems to be underlining the urgent need for a more secure authentication standard, as attackers up their game with AI.</p>



<p class="wp-block-paragraph">This is an “important milestone,” because it moves passwordless authentication from an optional security enhancement to the expected standard, noted <a href="https://www.sans.org/profiles/ensar-seker" target="_blank" rel="noreferrer noopener">Ensar Seker</a>, CISO at SOCRadar. “That shift is significant as attackers increasingly rely on AI to automate phishing campaigns, generate convincing login pages, and conduct large-scale credential theft.”</p>



<h2 class="wp-block-heading">Microsoft’s six-month passkey roll-out</h2>



<p class="wp-block-paragraph"><a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html" target="_blank">Passkeys</a> require users to authenticate via a fingerprint, facial scan, or lock screen mechanism, rather than a password. They can be stored on physical USB keys (like YubiKey), or as digital credentials on computers, phones, or in cloud accounts.</p>



<p class="wp-block-paragraph">This method, Microsoft contended, reduces reliance on phishable authentication tools like SMS and voice, and hardens protection against credential theft.</p>



<p class="wp-block-paragraph">Passkeys “work better for users and worse for cyberattackers,” <a href="https://www.linkedin.com/in/nadim-abdo/" target="_blank" rel="noreferrer noopener">Nadim Abdo</a>, Microsoft corporate VP for identity and network access engineering, wrote in a <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p class="wp-block-paragraph">Microsoft’s announced timeline for rolling out passkeys is relatively aggressive:</p>



<ul class="wp-block-list">
<li><strong>September 1, 2026</strong>: All SMS or voice-enabled users will be “auto-enabled and nudged” to register a passkey upon multifactor authentication (MFA) sign-in.</li>



<li><strong>September 18, 2026</strong>: Pricing, commercial terms, and a list of supported telecom providers will be shared for scenarios that still require SMS or voice authentication due to regulation or technical or operational challenges.</li>



<li><strong>October 30, 2026</strong>: Enterprises still using SMS and voice must select and configure a supported telecom provider through the Microsoft Security Store. From then on, they will be responsible for any telecom-related costs.</li>



<li><strong>February 1, 2027</strong>: Microsoft-provided telecom delivery for SMS and voice authentication ends as a native Microsoft Entra capability.</li>
</ul>



<p class="wp-block-paragraph">After February 1, enterprises that require SMS or voice for MFA must register a passkey before sign-in. There will be no opt-out option.</p>



<p class="wp-block-paragraph">It’s important to note that these dates apply to public cloud-hosted Entra ID. Support for other cloud environments will follow a separate timeline; additional guidance and dates are to come.</p>



<p class="wp-block-paragraph">While SMS and voice have served their purpose well, Abdo said, bringing MFA to billions of users who otherwise would have had none, the threat environment has changed in “speed, scale, and sophistication,” necessitating this move to passkeys.</p>



<h2 class="wp-block-heading">The benefits of passkeys</h2>



<p class="wp-block-paragraph">SOCRadar’s Seker pointed out that passkeys fundamentally change the attack surface because, unlike with passwords, there is no transmission of shared secrets that can be stolen by threat actors. Authentication requires possession of the user’s device, along with biometric verification or a PIN.</p>



<p class="wp-block-paragraph">“Even highly convincing AI-generated phishing pages cannot simply trick users into handing over a passkey the way they can with passwords or one-time codes,” he said.</p>



<p class="wp-block-paragraph">So why haven’t we seen widespread enterprise adoption? Identity ecosystems are “fragmented,” Seker noted, and many enterprises still rely on legacy applications that only support passwords. They also struggle with cross-platform compatibility, lifecycle management, recovery processes, shared accounts, and employee onboarding and offboarding.</p>



<p class="wp-block-paragraph">Further, “until recently, many organizations viewed passkeys as a consumer technology rather than an enterprise identity strategy,” he said.</p>



<p class="wp-block-paragraph">Microsoft’s move changes that equation, because Entra sits at the center of many organizations’ identity infrastructure, Seker noted. Default settings are typically the strongest drivers of security adoption, so when passwordless authentication becomes required rather than optional, organizations are far more likely to deploy it at scale.</p>



<p class="wp-block-paragraph">Its biggest benefit would be a “dramatic reduction” in credential-based attacks, Seker said. He pointed out that most successful compromises still begin with stolen credentials obtained through phishing, infostealer malware, password reuse, or adversary-in-the-middle attacks. Passkeys “eliminate or significantly reduce” many of those attack paths, while reducing password fatigue and the help desk costs related to password resets.</p>



<p class="wp-block-paragraph">In addition, rather than trying to continuously improve users’ ability to detect increasingly sophisticated phishing attempts, passkeys remove the credential from the equation altogether, Seker noted. “That represents a more sustainable long-term security strategy than relying solely on user awareness training.”</p>



<p class="wp-block-paragraph">Still, passkeys are not a silver bullet, as they do not stop endpoint compromise, session token theft, malicious insiders, or attackers who already have control of a trusted device. Enterprises must complement passkeys with endpoint protection, continuous monitoring, conditional access policies, and identity threat detection, Seker advised.</p>



<h2 class="wp-block-heading">How enterprises can prepare</h2>



<p class="wp-block-paragraph">To prepare for the shift to passkeys, Microsoft advised enterprises to review their authentication policy and identify the groups still using SMS or voice authentication. They should then select the best authentication method for user devices and workflows, and ensure all employees are given passkeys and security keys.</p>



<p class="wp-block-paragraph">Entra ID supports both synced passkeys (those stored in platform credential managers like iCloud Keychain and Google Password Manager), and device-bound passkeys such as Microsoft Authenticator passkeys, Entra passkey on Windows, or FIDO2 security keys.</p>



<p class="wp-block-paragraph">Seker advised enterprises to evaluate support for FIDO2 and passkeys across their identity infrastructure, and to develop clear enrollment and recovery procedures. They should also educate users on what’s changing, how passkeys work, and how they can complete registration. Further, Seker said, it’s important to establish secure device management practices and to continue enforcing least privilege, conditional access, and risk-based authentication policies throughout the transition.</p>



<p class="wp-block-paragraph">Ultimately, he pointed out, the move is crucial. “Over the next several years, organizations that continue relying primarily on passwords will likely face higher operational risk as AI continues to lower the cost and increase the effectiveness of credential-based attacks,” he said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.computerworld.com/article/4197029/microsoft-is-forcing-an-enterprise-transition-to-passkeys.html" target="_blank">Computerworld</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft macht Passkeys zum Standard in Entra ID]]></title>
<description><![CDATA[Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.]]></description>
<link>https://tsecurity.de/de/3668533/it-nachrichten/microsoft-macht-passkeys-zum-standard-in-entra-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668533/it-nachrichten/microsoft-macht-passkeys-zum-standard-in-entra-id/</guid>
<pubDate>Tue, 14 Jul 2026 17:50:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft macht Passkeys zum Standard in Entra ID]]></title>
<description><![CDATA[Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.]]></description>
<link>https://tsecurity.de/de/3668495/it-security-nachrichten/microsoft-macht-passkeys-zum-standard-in-entra-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668495/it-security-nachrichten/microsoft-macht-passkeys-zum-standard-in-entra-id/</guid>
<pubDate>Tue, 14 Jul 2026 17:41:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID gets passkeys default authentication starting September]]></title>
<description><![CDATA[Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]]]></description>
<link>https://tsecurity.de/de/3668017/it-security-nachrichten/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668017/it-security-nachrichten/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/</guid>
<pubDate>Tue, 14 Jul 2026 15:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Google adds FIDO2 keys and phone passkeys to Windows login via GCPW]]></title>
<description><![CDATA[Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows…
Read more →
The post Google adds FIDO2 key...]]></description>
<link>https://tsecurity.de/de/3667709/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667709/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</guid>
<pubDate>Tue, 14 Jul 2026 13:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/">Google adds FIDO2 keys and phone passkeys to Windows login via GCPW</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google adds FIDO2 keys and phone passkeys to Windows login via GCPW]]></title>
<description><![CDATA[Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Google Workspace accou...]]></description>
<link>https://tsecurity.de/de/3667678/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667678/it-security-nachrichten/google-adds-fido2-keys-and-phone-passkeys-to-windows-login-via-gcpw/</guid>
<pubDate>Tue, 14 Jul 2026 12:54:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Google Workspace account instead of, or alongside, a Windows username and password. The update allows organizations to strengthen account security by enabling administrators to enforce 2-step verification (2SV) with hardware security keys … <a href="https://www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/">Google adds FIDO2 keys and phone passkeys to Windows login via GCPW</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forg365 industrializes Microsoft 365 phishing with AI-generated lures]]></title>
<description><![CDATA[A newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.



The platform, called Fo...]]></description>
<link>https://tsecurity.de/de/3667518/it-nachrichten/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667518/it-nachrichten/forg365-industrializes-microsoft-365-phishing-with-ai-generated-lures/</guid>
<pubDate>Tue, 14 Jul 2026 12:02:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A newly documented <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html" target="_blank">phishing-as-a-service</a> platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.</p>



<p class="wp-block-paragraph">The platform, called Forg365, uses AI-assisted lure creation alongside device-code abuse and adversary-in-the-middle techniques, according to research published by security company <a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noreferrer noopener">ZeroBEC</a>.</p>



<p class="wp-block-paragraph">Forg365 was offered with a five-day free trial, followed by subscriptions priced at $400 per month or $3,800 per year, the researchers said.</p>



<p class="wp-block-paragraph">Customers can build phishing lures and control email delivery through a single operator panel. They can also manage captured account data and monitor compromised Microsoft 365 mailboxes. The service includes templates that impersonate widely used business platforms such as DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive.</p>



<p class="wp-block-paragraph">“Phishing-as-a-service has been around for quite a few years,” said <a href="https://omdia.tech.informa.com/authors/jonathan-ong" target="_blank" rel="noreferrer noopener">Jonathan Ong</a>, senior analyst for managed security services at Omdia. “But the degree to which AI is integrated into Forg365 and enables users is what makes it concerning.”</p>



<p class="wp-block-paragraph">Forg365’s significance lies in the industrialization and productization of the operator workflow, according to <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “It integrates AI-assisted lure creation, evasion, and post-compromise mailbox operations into a subscription service distributed through Telegram,” Datta said.</p>



<h2 class="wp-block-heading">How Forg365 works</h2>



<p class="wp-block-paragraph">ZeroBEC said the campaign it investigated began with an email built around a business-document and remittance-approval pretext. The message relied on legitimate cloud and email services before sending the recipient through several redirects.</p>



<p class="wp-block-paragraph">Forg365 classified visitors before deciding whether to display a device-code phishing page, an adversary-in-the-middle flow, or a harmless decoy.</p>



<p class="wp-block-paragraph">In the device-code attack, the victim is directed to a legitimate Microsoft authentication process and persuaded to enter a code that authorizes a session controlled by the attacker. The involvement of genuine Microsoft infrastructure can make the request appear credible.</p>



<p class="wp-block-paragraph">The platform can also relay authentication through an adversary-in-the-middle attack and capture session information. ZeroBEC said suspicious visitors were diverted to a benign page, helping the operators conceal the phishing flow from researchers and automated security tools.</p>



<h2 class="wp-block-heading">Complicating incident response</h2>



<p class="wp-block-paragraph">A browser extension called ForgCookie allows attackers to generate and refresh Microsoft single sign-on cookies from their own browsers, ZeroBEC said.</p>



<p class="wp-block-paragraph">Forg365 also advertises tools for keeping sessions active and monitoring a compromised inbox. Read-only access to the mailbox can then be shared through a password-protected link.</p>



<p class="wp-block-paragraph">As a result, resetting a password may not remove the attacker. Stolen refresh-token material or an attacker-controlled session could remain usable after the password is changed. Any devices registered during the compromise must also be investigated.</p>



<p class="wp-block-paragraph">“CISOs should treat two controls as co-equal priorities rather than sequential ones,” Datta said, referring to tightly restricting device-code authentication and deploying <a href="https://www.csoonline.com/article/574265/why-it-might-be-time-to-consider-using-fido-based-authentication-devices.html">phishing-resistant MFA</a> such as FIDO2 or WebAuthn passkeys.</p>



<p class="wp-block-paragraph">Organizations that do not require device-code authentication should consider <a href="https://www.csoonline.com/article/4134874/new-phishing-campaign-tricks-employees-into-bypassing-microsoft-365-mfa.html">blocking it in Microsoft Entra ID</a>, said <a href="https://confidis.co/about/our-leadership-team/" target="_blank" rel="noreferrer noopener">Keith Prabhu</a>, founder and CEO of Confidis. This can disrupt the device-code component of a Forg365 campaign, although it would not stop attacks that rely on adversary-in-the-middle techniques or stolen session cookies.</p>



<p class="wp-block-paragraph">Companies that still depend on device-code authentication should identify legitimate uses before imposing a broader restriction. Exceptions may be needed for some command-line tools, conference-room systems or other devices with limited input capabilities.</p>



<p class="wp-block-paragraph">Deploying phishing-resistant authentication may also require hardware security keys or managed smartphones and could increase support requests during the transition, Datta said.</p>



<p class="wp-block-paragraph">After detecting a compromise, response teams should revoke active refresh tokens and terminate existing sessions. Prabhu also recommended reviewing and revoking unauthorized OAuth permissions. Because ForgCookie runs in the attacker’s browser, defenders should look for repeated silent sign-ins and non-interactive Microsoft Graph activity from unfamiliar addresses, according to ZeroBEC.</p>



<p class="wp-block-paragraph">Mailbox forwarding rules and delegated access should be reviewed for unauthorized changes, Prabhu said. Such changes could allow attackers to monitor communications or retain access after a password reset.</p>



<p class="wp-block-paragraph">“IR teams should audit newly registered devices and remove any that cannot be attributed to the user,” Datta said. Teams should also check whether an attacker enrolled an unauthorized authenticator application or passkey during the compromise, she added.</p>



<p class="wp-block-paragraph">ZeroBEC found that some devices registered during its investigation had names beginning with “Forg365,” giving defenders a possible indicator of compromise.</p>



<p class="wp-block-paragraph"><em>The article originally appeared on <a href="https://www.csoonline.com/article/4196646/phishing-for-dummies-forg365-lowers-barrier-to-m365-account-takeovers.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Entra ID: Microsoft schafft SMS- und Sprachanmeldung ab]]></title>
<description><![CDATA[Microsoft macht Passkeys zum Standard für Entra ID und stellt die integrierte SMS- sowie Telefon-Authentifizierung ein. IT-Abteilungen müssen handeln.

Tags: #Cyber Security | #Microsoft]]></description>
<link>https://tsecurity.de/de/3667496/it-security-nachrichten/entra-id-microsoft-schafft-sms-und-sprachanmeldung-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667496/it-security-nachrichten/entra-id-microsoft-schafft-sms-und-sprachanmeldung-ab/</guid>
<pubDate>Tue, 14 Jul 2026 11:54:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920.jpg" class="attachment-full size-full wp-post-image" alt="Microsoft" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/03/Microsoft-Quelle-ACHPF-Shutterstock-2430933197-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Entra ID: Microsoft schafft SMS- und Sprachanmeldung ab 1"></p>
    Microsoft macht Passkeys zum Standard für Entra ID und stellt die integrierte SMS- sowie Telefon-Authentifizierung ein. IT-Abteilungen müssen handeln.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/microsoft-en">#Microsoft</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing for dummies: Forg365 lowers barrier to M365 account takeovers]]></title>
<description><![CDATA[A newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.



The platform, called Fo...]]></description>
<link>https://tsecurity.de/de/3667490/it-security-nachrichten/phishing-for-dummies-forg365-lowers-barrier-to-m365-account-takeovers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667490/it-security-nachrichten/phishing-for-dummies-forg365-lowers-barrier-to-m365-account-takeovers/</guid>
<pubDate>Tue, 14 Jul 2026 11:54:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A newly documented <a href="https://www.csoonline.com/article/4176814/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html" target="_blank">phishing-as-a-service</a> platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.</p>



<p class="wp-block-paragraph">The platform, called Forg365, uses AI-assisted lure creation alongside device-code abuse and adversary-in-the-middle techniques, according to research published by security company <a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noreferrer noopener">ZeroBEC</a>.</p>



<p class="wp-block-paragraph">Forg365 was offered with a five-day free trial, followed by subscriptions priced at $400 per month or $3,800 per year, the researchers said.</p>



<p class="wp-block-paragraph">Customers can build phishing lures and control email delivery through a single operator panel. They can also manage captured account data and monitor compromised Microsoft 365 mailboxes. The service includes templates that impersonate widely used business platforms such as DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive.</p>



<p class="wp-block-paragraph">“Phishing-as-a-service has been around for quite a few years,” said <a href="https://omdia.tech.informa.com/authors/jonathan-ong" target="_blank" rel="noreferrer noopener">Jonathan Ong</a>, senior analyst for managed security services at Omdia. “But the degree to which AI is integrated into Forg365 and enables users is what makes it concerning.”</p>



<p class="wp-block-paragraph">Forg365’s significance lies in the industrialization and productization of the operator workflow, according to <a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher. “It integrates AI-assisted lure creation, evasion, and post-compromise mailbox operations into a subscription service distributed through Telegram,” Datta said.</p>



<h2 class="wp-block-heading">How Forg365 works</h2>



<p class="wp-block-paragraph">ZeroBEC said the campaign it investigated began with an email built around a business-document and remittance-approval pretext. The message relied on legitimate cloud and email services before sending the recipient through several redirects.</p>



<p class="wp-block-paragraph">Forg365 classified visitors before deciding whether to display a device-code phishing page, an adversary-in-the-middle flow, or a harmless decoy.</p>



<p class="wp-block-paragraph">In the device-code attack, the victim is directed to a legitimate Microsoft authentication process and persuaded to enter a code that authorizes a session controlled by the attacker. The involvement of genuine Microsoft infrastructure can make the request appear credible.</p>



<p class="wp-block-paragraph">The platform can also relay authentication through an adversary-in-the-middle attack and capture session information. ZeroBEC said suspicious visitors were diverted to a benign page, helping the operators conceal the phishing flow from researchers and automated security tools.</p>



<h2 class="wp-block-heading">Complicating incident response</h2>



<p class="wp-block-paragraph">A browser extension called ForgCookie allows attackers to generate and refresh Microsoft single sign-on cookies from their own browsers, ZeroBEC said.</p>



<p class="wp-block-paragraph">Forg365 also advertises tools for keeping sessions active and monitoring a compromised inbox. Read-only access to the mailbox can then be shared through a password-protected link.</p>



<p class="wp-block-paragraph">As a result, resetting a password may not remove the attacker. Stolen refresh-token material or an attacker-controlled session could remain usable after the password is changed. Any devices registered during the compromise must also be investigated.</p>



<p class="wp-block-paragraph">“CISOs should treat two controls as co-equal priorities rather than sequential ones,” Datta said, referring to tightly restricting device-code authentication and deploying <a href="https://www.csoonline.com/article/574265/why-it-might-be-time-to-consider-using-fido-based-authentication-devices.html">phishing-resistant MFA</a> such as FIDO2 or WebAuthn passkeys.</p>



<p class="wp-block-paragraph">Organizations that do not require device-code authentication should consider <a href="https://www.csoonline.com/article/4134874/new-phishing-campaign-tricks-employees-into-bypassing-microsoft-365-mfa.html">blocking it in Microsoft Entra ID</a>, said <a href="https://confidis.co/about/our-leadership-team/" target="_blank" rel="noreferrer noopener">Keith Prabhu</a>, founder and CEO of Confidis. This can disrupt the device-code component of a Forg365 campaign, although it would not stop attacks that rely on adversary-in-the-middle techniques or stolen session cookies.</p>



<p class="wp-block-paragraph">Companies that still depend on device-code authentication should identify legitimate uses before imposing a broader restriction. Exceptions may be needed for some command-line tools, conference-room systems or other devices with limited input capabilities.</p>



<p class="wp-block-paragraph">Deploying phishing-resistant authentication may also require hardware security keys or managed smartphones and could increase support requests during the transition, Datta said.</p>



<p class="wp-block-paragraph">After detecting a compromise, response teams should revoke active refresh tokens and terminate existing sessions. Prabhu also recommended reviewing and revoking unauthorized OAuth permissions. Because ForgCookie runs in the attacker’s browser, defenders should look for repeated silent sign-ins and non-interactive Microsoft Graph activity from unfamiliar addresses, according to ZeroBEC.</p>



<p class="wp-block-paragraph">Mailbox forwarding rules and delegated access should be reviewed for unauthorized changes, Prabhu said. Such changes could allow attackers to monitor communications or retain access after a password reset.</p>



<p class="wp-block-paragraph">“IR teams should audit newly registered devices and remove any that cannot be attributed to the user,” Datta said. Teams should also check whether an attacker enrolled an unauthorized authenticator application or passkey during the compromise, she added.</p>



<p class="wp-block-paragraph">ZeroBEC found that some devices registered during its investigation had names beginning with “Forg365,” giving defenders a possible indicator of compromise.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID authentication overhaul to start in September 2026]]></title>
<description><![CDATA[Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users…
Read more →
The post Microsof...]]></description>
<link>https://tsecurity.de/de/3667429/it-security-nachrichten/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667429/it-security-nachrichten/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:21:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/">Microsoft Entra ID authentication overhaul to start in September 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID authentication overhaul to start in September 2026]]></title>
<description><![CDATA[Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA, they will be pro...]]></description>
<link>https://tsecurity.de/de/3667351/it-security-nachrichten/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667351/it-security-nachrichten/microsoft-entra-id-authentication-overhaul-to-start-in-september-2026/</guid>
<pubDate>Tue, 14 Jul 2026 10:54:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA, they will be prompted to register a passkey. Starting February 1, 2027, users who rely on SMS or voice for MFA will be required to register a passkey before they can sign in. … <a href="https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/">Microsoft Entra ID authentication overhaul to start in September 2026</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords]]></title>
<description><![CDATA[Microsoft is retiring phishable SMS and voice-based multifactor authentication in Microsoft Entra ID, replacing them with passkeys as the default sign-in method starting September 1, 2026. The move responds to a surge in AI-enabled phishing campaigns that Microsoft Threat Intelligence has observe...]]></description>
<link>https://tsecurity.de/de/3667323/it-security-nachrichten/microsoft-changes-entra-id-default-authentication-method-to-passkeys-replacing-passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667323/it-security-nachrichten/microsoft-changes-entra-id-default-authentication-method-to-passkeys-replacing-passwords/</guid>
<pubDate>Tue, 14 Jul 2026 10:38:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is retiring phishable SMS and voice-based multifactor authentication in Microsoft Entra ID, replacing them with passkeys as the default sign-in method starting September 1, 2026. The move responds to a surge in AI-enabled phishing campaigns that Microsoft Threat Intelligence has observed achieving click-through rates as high as 54%, compared to roughly 12% for traditional […]</p>
<p>The post <a href="https://cybersecuritynews.com/entra-id-default-authentication-passkeys/">Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID: Passkeys ab sofort Standard-Authentifizierung - Ad Hoc News]]></title>
<description><![CDATA[... -Gefahr. Digitales Vorhängeschloss-Symbol für Cybersicherheit mit leuchtenden Linien vor dunklem, futuristischem Hintergrund vernetzter Knoten.]]></description>
<link>https://tsecurity.de/de/3667109/it-security-nachrichten/microsoft-entra-id-passkeys-ab-sofort-standard-authentifizierung-ad-hoc-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667109/it-security-nachrichten/microsoft-entra-id-passkeys-ab-sofort-standard-authentifizierung-ad-hoc-news/</guid>
<pubDate>Tue, 14 Jul 2026 09:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... -Gefahr. Digitales Vorhängeschloss-Symbol für <b>Cybersicherheit</b> mit leuchtenden Linien vor dunklem, futuristischem Hintergrund vernetzter Knoten.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI verlangt künftig Hardware-Passkeys für Cyber-Modelle]]></title>
<description><![CDATA[Ab September gilt für Mitglieder von OpenAIs "Trusted Access for Cyber"-Programm eine neue Regel: Ohne physischen Passkey gibt es keinen Zugriff mehr auf die leistungsstärkeren Sicherheitsmodelle des Unternehmens.

Tags: #OpenAI | #Passkeys]]></description>
<link>https://tsecurity.de/de/3667038/it-security-nachrichten/openai-verlangt-kuenftig-hardware-passkeys-fuer-cyber-modelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667038/it-security-nachrichten/openai-verlangt-kuenftig-hardware-passkeys-fuer-cyber-modelle/</guid>
<pubDate>Tue, 14 Jul 2026 08:35:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920.jpg" class="attachment-full size-full wp-post-image" alt="Yubikey" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/07/Yubico-Yubikey-Quelle-Formatoriginal-Shutterstock-2141732409-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="OpenAI verlangt künftig Hardware-Passkeys für Cyber-Modelle 1"></p>
    Ab September gilt für Mitglieder von OpenAIs "Trusted Access for Cyber"-Programm eine neue Regel: Ohne physischen Passkey gibt es keinen Zugriff mehr auf die leistungsstärkeren Sicherheitsmodelle des Unternehmens.

<p>Tags: <a href="https://www.it-daily.net/thema/openai">#OpenAI</a> | <a href="https://www.it-daily.net/thema/passkeys-en">#Passkeys</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID]]></title>
<description><![CDATA[Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.
The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog.]]></description>
<link>https://tsecurity.de/de/3666178/it-security-nachrichten/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666178/it-security-nachrichten/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/</guid>
<pubDate>Mon, 13 Jul 2026 20:53:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.</p>
<p>The post <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/">Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID</a> appeared first on <a href="https://www.microsoft.com/en-us/security/blog">Microsoft Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor for authentication]]></title>
<description><![CDATA[Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware sec...]]></description>
<link>https://tsecurity.de/de/3666124/web-tipps/google-credential-provider-for-windows-gcpw-now-supports-fido2-compliant-physical-security-keys-as-a-second-factor-for-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666124/web-tipps/google-credential-provider-for-windows-gcpw-now-supports-fido2-compliant-physical-security-keys-as-a-second-factor-for-authentication/</guid>
<pubDate>Mon, 13 Jul 2026 20:12:09 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google Credential Provider for Windows (GCPW) has been updated to support FIDO2-compliant physical security keys as a second factor for authentication. This update helps organizations improve their security posture by enabling administrators to enforce 2-Step Verification (2SV) using hardware security keys at the Windows login screen. Additionally, users can now use passkeys from nearby Bluetooth-connected mobile devices for their second-factor authentication.</p><p><br></p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR0zeCemaxqTCVO6rOV0FfMasB3e_Wsd4bVZFuQ_by6qzf6oOCWwxQ8fUHEm71h0NeQP4mlwRqqUyxhpNQ9LtePYgVFxN7FnPPoIyl7yf1GV_njZK1ExTx6odDrgn0quaJ432YywTJULkIbvAOLvg-78iXl5jY1Ve5OCFngVfggpWpcN-w3KlFQJRy6A0/s1025/Google%20Credential%20Provider%20for%20Windows%20(GCPW)%20now%20supports%20FIDO2-compliant%20physical%20security%20keys%20as%20a%20second%20factor%20for%20authentication%20-%206959.png" imageanchor="1"><img border="0" data-original-height="767" data-original-width="1025" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjR0zeCemaxqTCVO6rOV0FfMasB3e_Wsd4bVZFuQ_by6qzf6oOCWwxQ8fUHEm71h0NeQP4mlwRqqUyxhpNQ9LtePYgVFxN7FnPPoIyl7yf1GV_njZK1ExTx6odDrgn0quaJ432YywTJULkIbvAOLvg-78iXl5jY1Ve5OCFngVfggpWpcN-w3KlFQJRy6A0/s1600/Google%20Credential%20Provider%20for%20Windows%20(GCPW)%20now%20supports%20FIDO2-compliant%20physical%20security%20keys%20as%20a%20second%20factor%20for%20authentication%20-%206959.png"></a></div><h3>Getting started</h3><p></p><ul><li><b>Admins:</b> Visit the Help Center to <a href="https://knowledge.workspace.google.com/admin/security/deploy-2-step-verification?hl=en&amp;visit_id=639184417936026454-2171514902&amp;rd=1#step_5_enforce_2-step_verification_optional" target="_blank">learn more about enforcing 2SV</a>.</li><li><b>End users:</b> There is no end user setting for this feature.</li></ul><p></p><h3>Rollout pace</h3><p></p><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains</a>: Gradual rollout (up to 15 days for feature visibility)  starting on July 13, 2026</li></ul><p></p><h3>Availability</h3><p></p><ul><li>Available to all Google Workspace customers</li></ul><p></p><h3>Resources</h3><p></p><ul><li>Google Workspace Admin Help: <a href="https://support.google.com/a/answer/9543613" target="_blank">Prepare to install GCPW</a></li></ul><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID]]></title>
<description><![CDATA[Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID…
Read more →
The post Microsoft Entra I...]]></description>
<link>https://tsecurity.de/de/3666060/it-security-nachrichten/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666060/it-security-nachrichten/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/</guid>
<pubDate>Mon, 13 Jul 2026 19:38:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/">Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Application Security Team: Firefox Security & Privacy Newsletter 2026 Q2]]></title>
<description><![CDATA[Welcome to the Q2 2026 edition of the Firefox Security & Privacy Newsletter.

Security and privacy are core principles of Mozilla’s Manifesto and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into...]]></description>
<link>https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665507/tools/firefox-application-security-team-firefox-security-privacy-newsletter-2026-q2/</guid>
<pubDate>Mon, 13 Jul 2026 16:10:17 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q2 2026 edition of the Firefox Security &amp; Privacy Newsletter.</p>

<p>Security and privacy are core principles of <a href="https://www.mozilla.org/en-US/about/manifesto/">Mozilla’s Manifesto</a> and remain at the heart of Firefox’s development. In this edition, we highlight some of the key security and privacy initiatives from Q2 2026, grouped into the following areas:</p>

<ul>
  <li><strong>Firefox Product Security &amp; Privacy</strong>, new security and privacy features, protections, and integrations in Firefox</li>
  <li><strong>Core Security</strong>, platform security improvements, hardening efforts, and foundational enhancements</li>
  <li><strong>Community Engagement</strong>, highlights from our security research community and bug bounty program</li>
  <li><strong>Web Security &amp; Standards</strong>, progress on web technologies and standards that help websites better protect users from online threats</li>
</ul>

<h3>Preface</h3>

<p>Note: Some of the bugs linked below might not be accessible to the general public and restricted to specific work groups. <a href="https://firefox-source-docs.mozilla.org/bug-mgmt/processes/fixing-security-bugs.html#keeping-private-information-private">We de-restrict fixed security bugs after a grace-period</a>, until the majority of our user population have received Firefox updates. If a link does not work for you, please accept this as a precaution for the safety of all Firefox users.</p>

<h3>Firefox Product Security &amp; Privacy</h3>

<p><strong>Private Access Control Tokens (PACT):</strong> PACT is a cross-industry initiative designed to tackle one of the web’s most urgent challenges: enabling websites to reliably distinguish legitimate users and authorized automated agents from abusive traffic without compromising user privacy. To introduce the initiative, we published a <a href="https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/">technical deep dive on Mozilla Hacks</a> alongside a <a href="https://blog.mozilla.org/en/privacy-security/keeping-the-web-open-and-private-in-the-bot-era/">companion Mozilla blog post</a> that explains the vision, motivation, and privacy-preserving design behind PACT.</p>

<p><strong>Qualified Website Authentication Certificates (QWACs):</strong> Firefox is prepared to meet upcoming eIDAS requirements under the <a href="https://eidas.ec.europa.eu/efda/home">EU Digital Identity Framework.</a> <a href="https://eidas.ec.europa.eu/efda/discover/qwac">Qualified Website Authentication Certificates (QWACs), as required by the framework, are supported</a> in Firefox 153 (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2043399">Bug 2043399</a>) onwards.</p>

<p><strong>Hardening Firefox with Claude Mythos:</strong> In a <a href="https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/">blogpost</a> we shared how our AI-assisted security testing pipeline, powered by Claude Mythos, uncovered and helped remediate hundreds of previously hidden vulnerabilities in Firefox, significantly strengthening the browser’s security while demonstrating the transformative potential of AI to enhance defensive cybersecurity.</p>

<p><strong>Visual Indications for Geolocation Access:</strong> In light of some web pages using geolocation for activities that are not related to their maps functionality, Firefox now displays <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2038194">a real-time visual indicator</a> whenever a web page is accessing the user’s geolocation. Starting with Firefox 153, the address bar now provides a <a href="https://bug2038194.bmoattachments.org/attachment.cgi?id=9586032">real-time visual indicator</a> the moment a website begins accessing a user’s location, providing users with  immediate awareness and greater transparency into when and how their geolocation data is being used.</p>

<p><strong>Improving Website Compatibility in Private Browsing:</strong> Starting with Firefox 152, Private Browsing Mode now offers users the option to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1994405">temporarily lower tracking protections</a> for the current tab when stricter tracker blocking could be causing a website to malfunction.  Previously, this may have resulted in users turning off privacy protections completely to continue using visited web page. With our new feature, users can quickly restore site functionality of the current tab, preserving users’ overall privacy settings.</p>

<p><strong>Instant fresh start through new <a href="https://support.mozilla.org/en-US/kb/private-browsing-use-firefox-without-history">Fire Button</a>:</strong> Firefox 151 introduced the new Fire Button for Private Browsing, giving users an instant fresh start with a single click. Instead of closing and reopening a Private Window, users can <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1846495">immediately clear all browsing data and continue browsing in a clean session</a>, making Private Browsing faster, more convenient, and just as private.</p>

<p><strong>Advanced Anti-Fingerprinting Protections:</strong> Firefox 151 expands our default anti-fingerprinting defenses by ensuring the Available Screen Resolution, Touch Points, and Canvas APIs will provide uniform results for all of our users while also maintaining performance and compatibility. On macOS, for example, these enhancements are expected to reduce the share of users identified as unique by more than 20%, making it significantly harder for websites to uniquely identify and track users using obscure fingerprinting.</p>

<p><strong>Local Network Access Protections:</strong> Firefox now requires user permission before websites can access apps and services on a user’s local network or device, helping prevent unauthorized access and sneaky tracking attempts. The <a href="https://support.mozilla.org/en-US/kb/control-personal-device-local-network-permissions-firefox">LNA</a> feature is rolling out gradually, starting with Firefox Desktop 151 through 153. Android support will follow in upcoming releases.</p>

<h3>Core Security</h3>

<p><strong>Firefox CA Root Program:</strong> We published <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Root Store Policy v3.1</a>, introducing stricter transparency, documentation, and audit requirements for public CAs to strengthen trust in the Web PKI.</p>

<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010193"><strong>WebAuthn Related Origin Requests</strong></a><strong>:</strong> This feature allows seamless passkey sign-ins across related domains e.g., the same provider using multiple top-level domains. In contrast to other browsers, Firefox UI provides transparency and choice so users are aware and can control when websites request for passkeys from other, related sites.</p>

<h3>Community Engagement</h3>

<p><strong>Hosting Events:</strong> We organized and hosted multiple <a href="https://www.meetup.com/de-DE/berlin-mozilla-meetup/">web tech meet-ups in the Mozilla Berlin office</a>, bringing together the developer community to explore the latest advances in web technology, privacy, and security. If you’re in the area, we’d love to have you join us at a future event.</p>

<p><strong>Community Shares:</strong>  Firefox tracking protection was presented at the <a href="https://www.reddit.com/r/SnooSec/comments/1te55fx/thanks_for_joining_us_at_snoosec_nyc/">SnooSec conference held in the Reddit NYC office</a>. We also had a presentation about existing and upcoming protections against web tracking at the <a href="https://chemnitzer.linux-tage.de/2026/en">Chemnitz Linux Days</a> conference, and a talk about the latest browser-based XSS protections at <a href="https://owasp.glueup.com/event/owasp-global-appsec-eu-2026-vienna-austria-162243/">OWASP AppSec ‘26</a> in Vienna.</p>

<h3>Web Security &amp; Standards</h3>

<p><strong>Web Application Integrity, Consistency and Transparency (WAICT):</strong> We are working on WAICT, a new proposal to bring stronger integrity and transparency guarantees to web applications, helping make the web a more trustworthy platform for security-sensitive applications such as end-to-end encrypted messaging. We shared our technical vision in a <a href="https://hacks.mozilla.org/2026/05/trustworthy-javascript-for-the-open-web/">Mozilla Hacks blog post</a>, including a prototype implementation in Firefox Nightly that works with our <a href="https://demo.waict.dev/">WAICT Demo</a> and a <a href="https://github.com/waict-wg">draft specification</a>.</p>

<p><strong>Sanitizer API:</strong> We are advancing the Sanitizer API to make robust protection against cross-site scripting (XSS) vulnerabilities more accessible. By exploring an <a href="https://github.com/mozilla/explainers/blob/main/trusted-or-sanitized-html.md">implicit sanitizer policy</a> that integrates with Trusted Types, we aim to prevent an entire class of XSS attacks with no application code changes, making secure-by-default web applications easier to build and deploy.</p>

<h3>Looking Ahead</h3>

<p>Firefox users will receive these security and privacy improvements automatically. If you’re not already a user, <a href="https://firefox.com/">we recommend you give it a try</a>. Firefox helps you shape a more personal internet that puts you back in control - all while supporting the non-profit Mozilla in its mission to keep the web open, safe, and accessible for everyone.</p>

<p>Thank you to everyone who contributes to making Firefox and the web more secure and privacy-focused. You can have an impact too, just by <a href="https://bugzilla.mozilla.org/enter_bug.cgi">reporting bugs</a>, conducting research, contributing code, or providing feedback.</p>

<p>We look forward to sharing more updates in the Q3 2026 edition.</p>

<p><em>— The Firefox Security &amp; Privacy Teams</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 10 weiter nutzen oder upgraden? Unsere Empfehlungen für wirklich jeden Nutzer]]></title>
<description><![CDATA[Am 12. Oktober 2027 beendet Microsoft für Privatanwender den erweiterten Support (den man als Extended Security Updates, ESU, bezeichnet) für Windows 10 (Version 22H2 Home, Professional, Pro Education oder Workstations Edition). Nur Unternehmenskunden bekommen gegen Bezahlung noch länger Sicherhe...]]></description>
<link>https://tsecurity.de/de/3664653/windows-tipps/windows-10-weiter-nutzen-oder-upgraden-unsere-empfehlungen-fuer-wirklich-jeden-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664653/windows-tipps/windows-10-weiter-nutzen-oder-upgraden-unsere-empfehlungen-fuer-wirklich-jeden-nutzer/</guid>
<pubDate>Mon, 13 Jul 2026 10:39:26 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Am <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">12. Oktober 2027 beendet Microsoft für Privatanwender</a> den erweiterten Support (den man als <a href="https://www.microsoft.com/de-de/windows/extended-security-updates">Extended Security Updates, ESU</a>, bezeichnet) für Windows 10 (Version 22H2 Home, Professional, Pro Education oder Workstations Edition). Nur Unternehmenskunden bekommen gegen Bezahlung noch länger Sicherheits-Updates, und zwar bis 2028.</p>



<p>Das bedeutet: Nach dem 13. Oktober 2027 (nach der ursprünglichen Planung sollte bereits am 12.10.2026 Schluss sein, <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">doch Microsoft verlängerte den Supportzeitraum für Windows 10 noch einmal) </a>erhalten Sie als Privatanwender für Ihren Windows-10-Rechner keine Sicherheits-Updates mehr. Neu entdeckte Sicherheitslücken in Windows 10 schließt Microsoft dann grundsätzlich nicht mehr, stattdessen bleiben diese offen und können von Angreifern ausgenutzt werden.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihr Laptop bremst Sie aus? Dieses 2-in-1 lässt Sie produktiver arbeiten</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-1-1.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook X Flip vereint Leistung und Flexibilität: Der AMD Ryzen AI Prozessor mit dedizierter NPU liefert bis zu 50 TOPS KI-Leistung. Das 14 Zoll 2K-Touchdisplay (16:9) überzeugt mit scharfen Bildern, das Scharnier ermöglicht vier Nutzungsmodi. Dank Schnellladefunktion ist der Akku in 30 Minuten zu 50 % geladen – ideal für lange Arbeitstage unterwegs.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://www.amazon.de/HP-OmniBook-dedizierte-1920x1200-Touchscreen/dp/B0DYKVHN9S/ref=sr_1_3?__mk_de_DE=%C3%85M%C3%85%C5%BD%C3%95%C3%91&amp;crid=17T5EFAKLON23&amp;dib=eyJ2IjoiMSJ9.Urord4CgBJNJbYPPq1-tmQ.BfmMNE5BiLmKOdYlUYty3j3H7aTBSwU3lNWwIw7fq0g&amp;dib_tag=se&amp;keywords=B0DYKVHN9S&amp;qid=1783079697&amp;sprefix=b0dykvhn9s%2Caps%2C164&amp;sr=8-3&amp;th=1&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook X Flip</a></div></div>



<p>Bei besonders schwerwiegenden Sicherheitslücken sind aber weiterhin Ausnahmen möglich. Denn Microsoft hatte auch schon bei älteren, eingestellten Versionen wie Windows XP und Windows 7 in seltenen Fällen noch Patches nach Supportende veröffentlicht. Doch darauf dürfen Sie sich nicht verlassen.</p>



<p>Sie stehen also spätestens am 13. Oktober nächsten Jahres vor der Entscheidung, ob Sie Ihren Windows-10-Rechner noch weiternutzen wollen. Diese Möglichkeiten haben Sie:</p>



<h2 class="wp-block-heading toc">Upgrade auf Windows 11: Sicher, gratis, empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen möglichst kein Geld ausgeben und trotzdem relativ sicher vor Hackern und Viren sein. Zudem möchten Sie ein aktuelles Betriebssystem nutzen.</p>



<p>Der einfachste Weg besteht darin, dass Sie Ihr Windows 10 auf Windows 11 upgraden. <a href="https://support.microsoft.com/de-de/windows/upgrade-auf-windows-11-faq-fb6206a2-1a0f-448a-80f1-8668ee5b2bf9">Das ist für Sie kostenlos.</a> Einzige Hürde: <a href="https://www.pcwelt.de/article/1196400/windows-11-hardware-voraussetzungen-und-pruef-tool.html" target="_blank" rel="noreferrer noopener">Ihre Hardware muss für Windows 11 geeignet sein. </a>Das bedeutet: TPM 2.0, Secure Boot und kompatible Prozessoren ab der 8. Intel-Generation oder vergleichbare AMD-Modelle sind in Ihrem Rechner vorhanden.</p>



<p>Microsoft stellt die kostenlose <a href="https://go.microsoft.com/fwlink/?linkid=2169346" target="_blank" rel="noreferrer noopener">PC-Integritätsprüfungs-App</a> zur Verfügung, <a href="https://www.pcwelt.de/article/1198609/pc-health-check-ist-zurueck-microsoft-tool-prueft-ob-ihr-pc-fit-fuer-windows-11-ist.html" target="_blank" rel="noreferrer noopener">mit der Sie unter Windows 10 testen können,</a> ob die Aktualisierung möglich ist. Klicken Sie dazu nach dem Start des Tools auf „Jetzt überprüfen“.</p>



<p><strong>Tipp</strong>: Mit einigen Tricks können Sie Windows 11 auch auf Rechnern installieren, die für Windows 11 wegen veralteter Hardware nicht geeignet sind.</p>



<p><strong>Lösung:</strong> Wir erklären beide Upgrade-Wege – also für kompatible und für nichtkompatible Windows-10-Rechner – in dem Ratgeber “<a href="https://www.pcwelt.de/article//windows-10-update-auf-windows-11-24h2-so-gehts-kosten.html" target="_blank" rel="noreferrer noopener">Windows-10-Update auf Windows 11 24H2: Wie gehts? Was kostet es?</a>“.</p>



<p>Zur Installation auf Hardware, die eigentlich nicht für Windows 10 geeignet ist, können Sie zudem “<a href="https://www.pcwelt.de/article/1199049/windows-11-auf-jeder-hardware-installieren-so-gehts.html" target="_blank" rel="noreferrer noopener">Windows 11 auf jeder Hardware installieren – so geht´s</a>” lesen. Einen umfassenden Überblick zur Upgrade-Thematik bietet zudem unser Ratgeber “<a href="https://www.pcwelt.de/article/2915366/windows-10-nutzer-aufgepasst-das-muessen-sie-jetzt-unbedingt-tun.html" target="_blank" rel="noreferrer noopener">Windows-10-Nutzer aufgepasst: Das müssen Sie jetzt tun</a>“.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<h2 class="wp-block-heading toc">Neuen Windows-11-Rechner kaufen: Sicher, teuer, empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop hat bereits Macken, stürzt ab oder ist zu langsam. Sie benötigen ohnehin neue Hardware. </p>



<p>In diesem Fall ist der Kauf eines neuen Rechners oder Laptops ganz klar die beste Wahl für Sie. Damit machen Sie nichts falsch, allerdings müssen Sie dafür Geld in die Hand nehmen.</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3003041/die-besten-mini-pcs-im-test-fur-buro-streaming-gaming-und-server.html" target="_blank" rel="noreferrer noopener">Die besten Mini-PCs im Test – für Büro, Streaming, Gaming und Server</a></li>



<li><a href="https://b2c-contenthub.com/wp-admin/post.php?post=3143670&amp;action=edit">Die besten Mini-PCs bis 800 Euro im Test: Viel Leistung auf kleinstem Raum</a></li>



<li><a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Die besten Notebooks aller Klassen im Vergleich</a></li>



<li><a href="https://www.pcwelt.de/article/1207305/das-sind-die-besten-pcs-fuer-buero-und-home-office.html" target="_blank" rel="noreferrer noopener">Das sind die besten PCs fürs Büro und Homeoffice</a></li>
</ul>



<h2 class="wp-block-heading toc">Wechsel zu Linux: Sicher, kostenlos, aufwendig</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen möglichst kein Geld ausgeben und trotzdem relativ sicher vor Hackern und Viren sein. Und Sie benötigen Windows nicht zwingend für bestimmte Anwendungen oder Spiele.</p>



<p>Sie müssen sich in das neue Betriebssystem allerdings einarbeiten und neue Programme kennenlernen. Das kostet Zeit und vermutlich auch etwas Nerven. Der Lohn der Mühe: Sie sind endlich frei von Microsoft. So, wie es unser Kollege in “<a href="https://www.pcwelt.de/article/2651727/endlich-frei-von-windows-nie-mehr-microsoft-dank-diesem-tool.html" target="_blank" rel="noreferrer noopener">Nie mehr Windows: Dieses Tool macht Sie jetzt Microsoft-frei</a>” beschreibt.</p>



<p><strong>Lösung</strong>: In “<a href="https://www.pcwelt.de/article/2521785/linux-wie-windows-welche-distribution-ist-am-aehnlichsten.html" target="_blank" rel="noreferrer noopener">Linux wie Windows: Welche Distribution ist am ähnlichsten?</a>” stellen wir Ihnen zudem geeignete Linux-Distributionen vor. Außerdem empfehlen wir Ihnen den Artikel “<a href="https://www.pcwelt.de/article/1178186/linux-anfaenger.html" target="_blank" rel="noreferrer noopener">Linux für Windows-Umsteiger: 10 Fragen &amp; Antworten</a>“.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Wechsel zu einem Mac: Sicher, teuer, aufwendig</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop hat bereits Macken, stürzt ab oder ist zu langsam. Sie benötigen ohnehin neue Hardware und sind bereit, viel Geld auszugeben und sich in ein neues Betriebssystem einzuarbeiten.</p>



<p><strong>Lösung</strong>: iMacs und Macbooks sind leistungsfähig und sicher, bekommen lange Updates und sind langlebig. Sie sind aber auch teuer, wobei das Macbook Neo jetzt einen vergleichsweise preiswerten Einstieg ermöglicht, siehe “<a href="https://www.pcwelt.de/article/3079069/das-macbook-neo-fuer-700-euro-ist-microsofts-schlimmster-albtraum.html" target="_blank" rel="noreferrer noopener">Das Macbook Neo für 700 Euro ist Microsofts schlimmster Albtraum</a>“.</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://amazon.de/dp/B0GR6PN6BH?tag=pcwelt.de-21&amp;ascsubtag=4-0-2286220-7-0-0-0-0&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-2286220-7-0-0-0-0">Macbook Neo bei Amazon anschauen</a></div>


<h2 class="wp-block-heading toc">Wechsel zu einem Chromebook oder Googlebook: Sicher, günstig, bedingt empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihre alte Hardware läuft nicht mehr rund und Sie benötigen einen Laptop nur für wenig rechenintensive Aufgaben wie Surfen, Social Media, Streaming oder Office-Arbeiten. Sie wollen wenig Geld ausgeben und vergleichsweise sicher unterwegs sein. Sie arbeiten ohnehin immer schon durchgehend online.</p>



<p><strong>Lösung</strong>: In diesem Fall müssen Sie Ihren alten Windows-10-Laptop nicht zwingend durch ein teures Windows-11-Notebook oder ein Macbook ersetzen. Sondern können stattdessen auch ein vergleichsweise preiswertes Chromebook kaufen. Oder künftig ein Googlebook.</p>



<p>Chromebooks eignen sich als günstige Notebooks gut für alltägliche Aufgaben und Büroarbeiten. Dabei müssen Sie ganz auf das Ökosystem von Google vertrauen, im Gegenzug bekommen Sie <a href="https://www.pcwelt.de/article/2616240/darum-sind-chromebooks-sicherer-als-andere-laptops.html" target="_blank" rel="noreferrer noopener">viel Sicherheit vor Schadsoftware</a>. Hier finden Sie passende Geräte: <a href="https://www.pcwelt.de/article/2505538/die-besten-chromebooks-test.html" target="_blank" rel="noreferrer noopener">Die besten Chromebooks im Test.</a></p>



<p>Die Googlebooks sind die neueste Laptop-Familie von Google. Standardmäßig mit Gemini Intelligence und dem Magic Pointer an Bord. In “<a href="https://www.pcwelt.de/article/3138293/mit-den-googlebooks-will-google-den-laptop-markt-aufmischen-das-steckt-dahinter.html" target="_blank" rel="noreferrer noopener">Mit den Googlebooks will Google den Laptop-Markt aufmischen: Das steckt dahinter</a>” stellen wir Ihnen diese Geräte vor. Als Betriebssystem dient hier genauso wie bei den Chromebooks Chrome OS. Verkaufsstart soll im Herbst 2026 sein. Preise nennt Google noch keine, ebenso fehlen alle Informationen zur Hardware.</p>



<h2 class="wp-block-heading">Die letzte Chance</h2>



<p>Was aber tun, wenn man kein Geld für einen neuen Rechner hat, der alte PC aber das Upgrade auf Windows 11 wegen seiner schwachen Hardware nicht zulässt? Nun, dann bleibt theoretisch die Möglichkeit, Windows 10 weiter zu verwenden.</p>



<h2 class="wp-block-heading toc">Windows 10 nach Oktober 2027 weiternutzen: Nicht empfehlenswert</h2>



<p><strong>Für diese Zielgruppe: </strong>Ihr alter PC/Laptop läuft stabil und ist für Ihre Bedürfnisse ausreichend schnell. Sie wollen oder können kein Geld ausgeben und/oder benötigen weiter Windows 10 für bestimmte Anwendungen oder Spiele. Oder Sie wollen sich nicht mehr an ein neues Betriebssystem gewöhnen.</p>



<p><strong>Lösung: Beachten Sie die folgenden Hinweise</strong></p>



<p><strong>Virenscanner und Anwendungen aktuell halten</strong></p>



<p>Einen Windows-10-Rechner nach dem 12.10.2027 mit dem Internet zu verbinden, ist sehr gefährlich. Falls Sie das doch tun wollen und sich der Gefahr bewusst sind, dann halten Sie unbedingt den <a href="https://www.pcwelt.de/article/1203258/die-beste-antiviren-software-fuer-windows-10-fuers-buero.html">Virenscanner</a> und die Firewall auf dem PC immer aktuell. Aktualisieren Sie zudem immer alle Anwendungen auf dem Rechner, also beispielsweise die Browser.</p>



<p><strong>Defender bleibt aktuell</strong></p>



<p>Immerhin: Die vorhandenen Sicherheitsfunktionen des Betriebssystems bleiben aktiv, das gilt auch für den Malwareschutz. Sie veralten aber mit zunehmender Dauer. Der in Windows integrierte Microsoft Defender Antivirus wird aber weiterhin aktualisiert. Microsoft stellt hierfür die sogenannten „Security Intelligence Updates“ (die Datenbanken zur Erkennung neuer Viren und Malware) für alle Windows 10-Nutzer mindestens bis Oktober 2028 bereit. Dies garantiert einen grundlegenden und aktuellen Schutz vor Schadsoftware, auch wenn das Betriebssystem selbst nicht mehr gegen Schwachstellen im Code gepatcht wird.</p>



<p><strong>Meiden Sie unbekannte Webseiten und Downloads</strong></p>



<p>Die Firewall Ihres Routers schützt Ihren Windows-10-Rechner auch weiterhin. Gefährlich wird es aber, wenn Sie Webseiten im Browser aufrufen. Vermeiden Sie deshalb unbedingt den Besuch unbekannter Webseiten. Klicken Sie keine unbekannten Links an und seien Sie besonders vorsichtig bei Downloads – das gilt auch für Links und Dateianhänge in Mails. </p>



<p><strong>Kein Online-Banking</strong></p>



<p>Vermeiden Sie Einkäufe, Bezahlvorgänge und Online-Banking auf diesem Rechner. </p>



<p><strong>2FA besonders wichtig</strong></p>



<p>Schützen Sie alle Ihre Benutzerkonten durch die <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zweifaktorauthentifizierung</a> oder durch <a href="https://www.pcwelt.de/article/3128548/hoeren-sie-auf-passwoerter-zu-verwenden-ersetzen-sie-diese-stattdessen-jetzt-mit-passkeys.html" target="_blank" rel="noreferrer noopener">Passkeys</a>. Melden Sie sich bei all Ihren wichtigen Websites mit einem zusätzlichen Code (oder Schlüssel/Passwort) an, den Sie auf Ihrem Smartphone und nicht auf Ihrem jetzt anfälligen Windows-Computer speichern. Auf diese Weise können Malware oder Hacker Ihre Konten nicht über Ihren Computer übernehmen.</p>



<p><strong>Vom Internet trennen</strong></p>



<p>Falls Sie Ihren Windows-10-Rechner nach Oktober 2027 weiter nutzen wollen, um darauf beispielsweise ein fest installiertes Spiel zu spielen, für das Sie keine Internetverbindung benötigen, dann trennen Sie den Rechner am besten dauerhaft vom Internet. Und stecken Sie nur solche externen Datenträger wie USB-Sticks oder Festplatten an, die Sie mit einem aktuellen Virenscanner überprüft haben.</p>



<p>Weitere Ratschläge für die Weiternutzung von Windows 10 lesen Sie in “<a href="https://www.pcwelt.de/article/2620354/ab-heute-bekommt-windows-10-keine-sicherheits-updates-mehr-das-muessen-sie-jetzt-tun.html" target="_blank" rel="noreferrer noopener">Ab heute bekommt Windows 10 keine Sicherheits-Updates mehr – das müssen Sie jetzt tun</a>“. In diesem Zusammenhang sollten Sie auch die <a href="https://www.pcwelt.de/article/2872603/windows-10-support-ende-diese-datei-unbedingt-jetzt-runterladen.html" target="_blank" rel="noreferrer noopener">Windows-10-ISO-Datei herunterladen.</a></p>



<h2 class="wp-block-heading toc">Nutzen Sie Windows 10 in einer virtuellen Maschine: Sicher und gratis</h2>



<p>Falls Sie Windows 10 nur gelegentlich und nur für bestimmte Zwecke benötigen, können Sie das Betriebssystem auch in einer <a href="https://www.pcwelt.de/article/1179269/glossar-fachbegriffe-rund-um-virtuelle-pcs.html" target="_blank" rel="noreferrer noopener">virtuellen Maschine </a>installieren. Auf Ihrem Rechner läuft dann beispielsweise das aktuelle Windows 11 und Windows 10 starten Sie, wenn Sie es benötigen, als Gastsystem in der virtuellen Maschine.</p>



<h2 class="wp-block-heading toc">Updates für Windows 10 bis 2023: Sonderweg</h2>



<p>Eine Alternative, die Sie bereits jetzt nutzen können, ist die <a href="https://www.pcwelt.de/article/2431390/windows-10-bekommt-ab-oktober-2025-keine-updates-0patch-aendert-das.html" target="_blank" rel="noreferrer noopener">Sicherheitslösung 0Patch</a>. Dabei handelt es sich um ein Unternehmen, das Sicherheitsupdates für Windows 10 bis zum Jahr 2030 bereitstellt. Allerdings aktualisiert die cloudbasierte Software des Unternehmens nicht die Systemdateien von Windows 10, sondern aktiviert die Patches im Arbeitsspeicher des Rechners. Dadurch müssen diese bei jedem Start neu geladen werden. </p>



<p>Der Einstieg in die Software ist sogar kostenlos möglich. Wer umfassender geschützt sein will, <a href="https://0patch.com/pricing.html">kann die kostenpflichtige Version für 25 Euro pro Jahr zuzüglich Steuer buchen.</a></p>



<h2 class="wp-block-heading toc">Windows-10-Variante mit Updates bis 2032: Nicht legal</h2>



<p>Im Internet finden sich immer wieder Tipps, auf das Betriebssystem Windows 10 IoT Enterprise LTSC 2021 zu setzen. Dieses entspricht im Grunde genommen Windows 10 Enterprise mit allen Funktionen und erhält Updates bis 2032. <a href="https://learn.microsoft.com/de-de/windows/iot/iot-enterprise/commercialization/licensing" target="_blank" rel="noreferrer noopener">Lizenzrechtlich ist der Einsatz als Büro-PC aber nicht erlaubt</a>. </p>



<p>Technisch gesehen können Sie das Betriebssystem nach dem Kauf aber bis 2032 sicher einsetzen. Wie das geht, erklären wir in “<a href="https://www.pcwelt.de/article/2865406/windows-11-zu-windows-10-updowntool-anleitung-updates-bis-2032.html" target="_blank" rel="noreferrer noopener">Kostenlos von Windows 11 zu Windows 10 wechseln und Updates bis 2032 nutzen – so geht’s mit UpDownTool</a>“.</p>



<p><strong>Wichtig</strong>: Wie auch immer Ihre Entscheidung ausfällt, sollten Sie ein Backup Ihrer Daten auf dem alten Rechner machen. Mit <a href="https://software.pcwelt.de/offer/oo_diskimage_20_professional/43873?x-source=4-0-2620354-1-0-0-00001-0?x-source=rss" target="_blank" rel="noreferrer noopener">O&amp;O DiskImage</a> ist das kein Problem.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vishing-Attacken: Hacker erbeuten Microsoft-365-Passkeys in Echtzeit - Ad Hoc News]]></title>
<description><![CDATA[Kriminelle nutzen WhatsApp-Features und KI für Angriffe. Interpol gelingt Schlag gegen Cyberkriminalität mit fast 6.000 Festnahmen.]]></description>
<link>https://tsecurity.de/de/3662134/hacking/vishing-attacken-hacker-erbeuten-microsoft-365-passkeys-in-echtzeit-ad-hoc-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662134/hacking/vishing-attacken-hacker-erbeuten-microsoft-365-passkeys-in-echtzeit-ad-hoc-news/</guid>
<pubDate>Sat, 11 Jul 2026 18:25:54 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kriminelle nutzen WhatsApp-Features und KI für Angriffe. Interpol gelingt Schlag gegen Cyberkriminalität mit fast 6.000 Festnahmen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hongkong zwingt Krypto-Börsen zu Passkeys: 366 Mio. Dollar Phishing-Schaden]]></title>
<description><![CDATA[... Cybersicherheit und passwortlose Authentifizierung. Illustration mit AI erstellt übermittelt durch boerse-global.de. Die Securities and Futures ...]]></description>
<link>https://tsecurity.de/de/3660784/it-security-nachrichten/hongkong-zwingt-krypto-boersen-zu-passkeys-366-mio-dollar-phishing-schaden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660784/it-security-nachrichten/hongkong-zwingt-krypto-boersen-zu-passkeys-366-mio-dollar-phishing-schaden/</guid>
<pubDate>Fri, 10 Jul 2026 22:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Cybersicherheit</b> und passwortlose Authentifizierung. Illustration mit AI erstellt übermittelt durch boerse-global.de. Die Securities and Futures ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Vishing-Kit missbraucht Microsoft Entra Passkeys: Betreiber erbeuten unautorisierte Zugriffe]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Angreifer bringen Nutzer per Telefon dazu, eine neue Entra-Passkey-Registrierung in Microsoft 365 zu bestätigen. Dabei nutzen sie ein passwort- und mfa-orientiertes Phishing-Kit, das den Enrollment-Flow nahezu in Echtzeit nachbildet. Statt Passkeys auf dem Gerät zu...]]></description>
<link>https://tsecurity.de/de/3660226/it-security-nachrichten/vishing-kit-missbraucht-microsoft-entra-passkeys-betreiber-erbeuten-unautorisierte-zugriffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660226/it-security-nachrichten/vishing-kit-missbraucht-microsoft-entra-passkeys-betreiber-erbeuten-unautorisierte-zugriffe/</guid>
<pubDate>Fri, 10 Jul 2026 17:40:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-vishing-entra-passkey-enrollment-phishing-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Angreifer bringen Nutzer per Telefon dazu, eine neue Entra-Passkey-Registrierung in Microsoft 365 zu bestätigen. Dabei nutzen sie ein passwort- und mfa-orientiertes Phishing-Kit, das den Enrollment-Flow nahezu in Echtzeit nachbildet. Statt Passkeys auf dem Gerät zu erzeugen, registrieren die Täter eigene Schlüssel gegen das Microsoft-Konto des Opfers. Okta ordnet das […]</p>
<div><a href="https://www.it-boltwise.de/vishing-kit-missbraucht-microsoft-entra-passkeys-betreiber-erbeuten-unautorisierte-zugriffe.html">... den vollständigen Artikel <strong>»Vishing-Kit missbraucht Microsoft Entra Passkeys: Betreiber erbeuten unautorisierte Zugriffe«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/vishing-kit-missbraucht-microsoft-entra-passkeys-betreiber-erbeuten-unautorisierte-zugriffe.html">Vishing-Kit missbraucht Microsoft Entra Passkeys: Betreiber erbeuten unautorisierte Zugriffe</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Atlas Browser Is Shutting Down, OpenAI Confirms]]></title>
<description><![CDATA[ChatGPT Atlas is shutting down as OpenAI moves its browser features into the new ChatGPT desktop app. The standalone browser will remain available until August 9, after which OpenAI plans to discontinue the service and share further details through email and in-app notices.



The company introdu...]]></description>
<link>https://tsecurity.de/de/3659320/ios-mac-os/chatgpt-atlas-browser-is-shutting-down-openai-confirms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659320/ios-mac-os/chatgpt-atlas-browser-is-shutting-down-openai-confirms/</guid>
<pubDate>Fri, 10 Jul 2026 11:54:37 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ChatGPT Atlas is shutting down as OpenAI moves its browser features into the new ChatGPT desktop app. The standalone browser will remain available until August 9, after which OpenAI plans to discontinue the service and share further details through email and in-app notices.



The company introduced ChatGPT Atlas on Mac last October, followed by a dedicated Codex app with an in-app browser in April. OpenAI has now combined those tools inside one desktop app, which includes ChatGPT Work, Codex, and expanded browser controls.



New ChatGPT Desktop App Replaces Atlas



The updated desktop app includes multiple tabs, password management, autofill, downloads, printing, page search, passkeys, and enterprise sign-in support. Users can open the built-in browser by pressing Command and T on Mac.



OpenAI has also added a cloud browser to ChatGPT Work. The agent can search dynamic websites, complete forms, compare services, and collect information while users follow its progress through screenshots. Users can also take control of the browser whenever needed.



Chrome users can continue using ChatGPT through the new browser extension, which supports highlighted text, tab controls, local files, and ongoing tasks from the desktop app. OpenAI also plans to bring the extension to more browsers.




https://twitter.com/JamesZmSun/status/2075290224327057644]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts]]></title>
<description><![CDATA[Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run…
Read more →
The post Hackers Abuse Microsoft Entra Passkey Enrol...]]></description>
<link>https://tsecurity.de/de/3658002/it-security-nachrichten/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658002/it-security-nachrichten/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/</guid>
<pubDate>Thu, 09 Jul 2026 20:38:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/">Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple same passkeys show up when trying to sign into a website]]></title>
<description><![CDATA[If you use Google Chrome or Microsoft Edge and multiple instances of the same passkeys or passwords show up when trying to sign into a website, here is how you can fix the problem. You can use the same set of solutions for both browsers on Windows 11. Why does same passkey show up when […]
This a...]]></description>
<link>https://tsecurity.de/de/3657951/windows-tipps/multiple-same-passkeys-show-up-when-trying-to-sign-into-a-website/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657951/windows-tipps/multiple-same-passkeys-show-up-when-trying-to-sign-into-a-website/</guid>
<pubDate>Thu, 09 Jul 2026 20:10:38 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="400" src="https://www.thewindowsclub.com/wp-content/uploads/2026/06/Multiple-same-passkeys-show-up-7.jpg" class="attachment-full size-full wp-post-image" alt="Multiple same passkeys show up when trying to sign into a website" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/06/Multiple-same-passkeys-show-up-7.jpg 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/Multiple-same-passkeys-show-up-7-500x286.jpg 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/Multiple-same-passkeys-show-up-7-300x171.jpg 300w" sizes="(max-width: 700px) 100vw, 700px">If you use Google Chrome or Microsoft Edge and multiple instances of the same passkeys or passwords show up when trying to sign into a website, here is how you can fix the problem. You can use the same set of solutions for both browsers on Windows 11. Why does same passkey show up when […]</p>
<p>This article <a href="https://www.thewindowsclub.com/multiple-same-passkeys-show-up-when-trying-to-sign-into-a-website">Multiple same passkeys show up when trying to sign into a website</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts]]></title>
<description><![CDATA[Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run a phone based phishing campaign since April 2026 that tricks empl...]]></description>
<link>https://tsecurity.de/de/3657574/it-security-nachrichten/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657574/it-security-nachrichten/hackers-abuse-microsoft-entra-passkey-enrollment-to-hijack-enterprise-accounts/</guid>
<pubDate>Thu, 09 Jul 2026 17:50:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo Alto Networks Unit 42, has run a phone based phishing campaign since April 2026 that tricks employees into registering an attacker […]</p>
<p>The post <a href="https://cybersecuritynews.com/hackers-abuse-microsoft-entra-passkey-enrollment/">Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr]]></title>
<description><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></description>
<link>https://tsecurity.de/de/3656117/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656117/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</guid>
<pubDate>Thu, 09 Jul 2026 08:17:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></content:encoded>
</item>
<item>
<title><![CDATA[ATO 2026: Warum Passkeys den nächsten Angriff auf die Verifikation verschieben]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Passkeys machen den klassischen Account-Login mit gestohlenen Passwörtern zunehmend unattraktiv. Gleichzeitig verlagert sich Account Takeover (ATO) in Richtung der verbleibenden „Verifikations-Lücken“: Wiederanmeldung, Magic-Links und Schritt-für-Schritt-Checks. Ne...]]></description>
<link>https://tsecurity.de/de/3654338/it-security-nachrichten/ato-2026-warum-passkeys-den-naechsten-angriff-auf-die-verifikation-verschieben/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654338/it-security-nachrichten/ato-2026-warum-passkeys-den-naechsten-angriff-auf-die-verifikation-verschieben/</guid>
<pubDate>Wed, 08 Jul 2026 14:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ato-2026-verification-magic-link-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / LONDON (IT BOLTWISE) – Passkeys machen den klassischen Account-Login mit gestohlenen Passwörtern zunehmend unattraktiv. Gleichzeitig verlagert sich Account Takeover (ATO) in Richtung der verbleibenden „Verifikations-Lücken“: Wiederanmeldung, Magic-Links und Schritt-für-Schritt-Checks. Neue Zahlen zeigen, dass Identitätsbetrug sich zunehmend durch KI-generierte oder manipulierte Medien speist. Für Unternehmen bedeutet das: Sicherheitsarchitekturen müssen Verifikationsmedien, Risiko und Autorisierungsintention gemeinsam […]</p>
<div><a href="https://www.it-boltwise.de/ato-2026-warum-passkeys-den-naechsten-angriff-auf-die-verifikation-verschieben.html">... den vollständigen Artikel <strong>»ATO 2026: Warum Passkeys den nächsten Angriff auf die Verifikation verschieben«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ato-2026-warum-passkeys-den-naechsten-angriff-auf-die-verifikation-verschieben.html">ATO 2026: Warum Passkeys den nächsten Angriff auf die Verifikation verschieben</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Verification Step Is the New ATO Battleground in 2026]]></title>
<description><![CDATA[For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood.

That era is ending. Not because attacker...]]></description>
<link>https://tsecurity.de/de/3654215/it-security-nachrichten/the-verification-step-is-the-new-ato-battleground-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654215/it-security-nachrichten/the-verification-step-is-the-new-ato-battleground-in-2026/</guid>
<pubDate>Wed, 08 Jul 2026 14:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood.

That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in.

Passkeys are now mainstream.]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI legt Leitfaden für Passkeys vor - IT-Administrator.de]]></title>
<description><![CDATA[Passwörter gelten längst als Sicherheitsrisiko – Passkeys sollen es richten. Mit der TR-03188 legt das BSI erstmals eine detaillierte Richtlinie ...]]></description>
<link>https://tsecurity.de/de/3652624/it-security-nachrichten/bsi-legt-leitfaden-fuer-passkeys-vor-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652624/it-security-nachrichten/bsi-legt-leitfaden-fuer-passkeys-vor-it-administratorde/</guid>
<pubDate>Tue, 07 Jul 2026 21:38:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passwörter gelten längst als Sicherheitsrisiko – Passkeys sollen es richten. Mit der TR-03188 legt das BSI erstmals eine detaillierte Richtlinie ...]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI legt Leitfaden für Passkeys vor]]></title>
<description><![CDATA[BSI legt Leitfaden für Passkeys vor

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Di., 07.07.2026 - 15:00


            Passwörter gelten längst als Sicherheitsrisiko – Passkeys sollen es richten. Mit der T...]]></description>
<link>https://tsecurity.de/de/3651633/server/bsi-legt-leitfaden-fuer-passkeys-vor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651633/server/bsi-legt-leitfaden-fuer-passkeys-vor/</guid>
<pubDate>Tue, 07 Jul 2026 15:15:44 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">BSI legt Leitfaden für Passkeys vor</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/bsi-leitfaden-passkey-server-technische-richtlinie"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/news-bsi-richtlinie-passkey-server.jpg?itok=TwDmHXpF" width="480" height="319" alt="Ein Smartphone zeigt ein leuchtendes Symbol aus Person und Schlüssel, im Hintergrund ein Laptop mit Schutzschild-Symbol und Häkchen, davor ein USB-Sicherheitstoken sowie stilisierte Darstellungen eines digitalen Vorhängeschlosses und eines Fingerabdrucks, alles in blauem Neon-Design vor dunklem Hintergrund." title="Passkeys setzen auf kryptografische Schlüssel statt auf Passwörter. Mit der TR-03188 gibt das BSI Betreibenden nun einen Leitfaden für die sichere Umsetzung an die Hand. (Quelle. ChatGPT/OpenAI)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-07T15:00:00+02:00" title="Dienstag, Juli 7, 2026 - 15:00" class="datetime">Di., 07.07.2026 - 15:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Passwörter gelten längst als Sicherheitsrisiko – Passkeys sollen es richten. Mit der TR-03188 legt das BSI erstmals eine detaillierte Richtlinie vor, die zeigt, wie Webseitenbetreibende Passkey-Server sicher konfigurieren und welche Integrationslösung sich für sie eignet.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/bsi-leitfaden-passkey-server-technische-richtlinie" rel="tag" title="BSI legt Leitfaden für Passkeys vor" hreflang="en">Weiterlesen<span class="visually-hidden"> über BSI legt Leitfaden für Passkeys vor</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Geräteverknüpfung mit WhatsApp wird einfacher]]></title>
<description><![CDATA[WhatsApp könnte die Verbindung zusätzlicher Geräte bald deutlich einfacher machen. Anstelle des bisherigen QR-Code-Scans sollen künftig Passkeys die Verknüpfung erleichtern.]]></description>
<link>https://tsecurity.de/de/3651030/it-nachrichten/geraeteverknuepfung-mit-whatsapp-wird-einfacher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651030/it-nachrichten/geraeteverknuepfung-mit-whatsapp-wird-einfacher/</guid>
<pubDate>Tue, 07 Jul 2026 11:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WhatsApp könnte die Verbindung zusätzlicher Geräte bald deutlich einfacher machen. Anstelle des bisherigen QR-Code-Scans sollen künftig Passkeys die Verknüpfung erleichtern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Singapore’s Shift to Passkeys Reveals a Password Problem]]></title>
<description><![CDATA[Singapore's rollout of passkeys for Singpass signals a critical shift in digital identity. This article explores how device-bound authentication, such as Windows Hello for Business, helps Singaporean organizations move beyond vulnerable passwords.
The post Singapore’s Shift to Passkeys Reveals a ...]]></description>
<link>https://tsecurity.de/de/3649832/it-nachrichten/singapores-shift-to-passkeys-reveals-a-password-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649832/it-nachrichten/singapores-shift-to-passkeys-reveals-a-password-problem/</guid>
<pubDate>Mon, 06 Jul 2026 22:48:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Singapore's rollout of passkeys for Singpass signals a critical shift in digital identity. This article explores how device-bound authentication, such as Windows Hello for Business, helps Singaporean organizations move beyond vulnerable passwords.</p>
<p>The post <a href="https://www.techrepublic.com/article/passkey-apac/">Singapore’s Shift to Passkeys Reveals a Password Problem</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ExpressVPN adds passkeys on password manager, passes security audit]]></title>
<description><![CDATA[ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new independent security assessment by Cure53, which found no severe vulnerabilities ...]]></description>
<link>https://tsecurity.de/de/3649780/it-security-nachrichten/expressvpn-adds-passkeys-on-password-manager-passes-security-audit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649780/it-security-nachrichten/expressvpn-adds-passkeys-on-password-manager-passes-security-audit/</guid>
<pubDate>Mon, 06 Jul 2026 22:07:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new independent security assessment by Cure53, which found no severe vulnerabilities in the application after reviewing its architecture and mobile apps. ExpressVPN, which is best known …</p>
<p>The post <a href="https://cyberinsider.com/expressvpn-adds-passkeys-on-password-manager-passes-security-audit/">ExpressVPN adds passkeys on password manager, passes security audit</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Visa bringt KI-Agenten an die (digitale) Ladenkasse]]></title>
<description><![CDATA[Bestellung abgeschlossen: Das Programm Visa Agentic Ready schafft die Grundlagen, damit KI-Agenten künftig sicher und autonom Einkäufe im Web tätigen können. Visa



Bislang zumindest. Nachdem Mitte März 2026 das Pilotprogramms „Visa Agentic Ready“ an den Start ging, hat der Zahlungsdienstleister...]]></description>
<link>https://tsecurity.de/de/3640873/it-security-nachrichten/visa-bringt-ki-agenten-an-die-digitale-ladenkasse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640873/it-security-nachrichten/visa-bringt-ki-agenten-an-die-digitale-ladenkasse/</guid>
<pubDate>Thu, 02 Jul 2026 13:05:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/260702-Visa-Transaktion-im-KI-Handel-Demo_5_Bestellung-abgeschlossen.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Visa KI-Transaktion Bestellung abgeschlossen" class="wp-image-4192171" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Bestellung abgeschlossen: Das Programm Visa Agentic Ready schafft die Grundlagen, damit KI-Agenten künftig sicher und autonom Einkäufe im Web tätigen können. </figcaption></figure><p class="imageCredit">Visa</p></div>



<p>Bislang zumindest. Nachdem Mitte März 2026 das Pilotprogramms „<a href="https://www.visa.de/uber-visa/newsroom/press-releases.3438238.html">Visa Agentic Ready</a>“ an den Start ging, hat der Zahlungsdienstleister nun auf dem Visa Payments Forum in Paris erste Live-Transaktionen im KI-gestützten Handel in Europa vorgestellt. Dabei kauften KI-Agenten im Namen der Karteninhaber auf Websites der teilnehmenden Händler ein. Die Zahlungen wurden in Zusammenarbeit mit mehr als 30 kartenausgebenden Finanzinstituten aus Europa realisiert.</p>



<h2 class="wp-block-heading">Zweite Phase des Programms Visa Agentic Ready</h2>



<p>Dieser Schritt markiert die nächste Phase des „Visa Agentic-Ready“-Programms, mit dem das Zahlungstechnologieunternehmen Infrastruktur, Standards und Partner zusammenbringt, die für die Entwicklung des KI-gestützten Handels in der Praxis erforderlich sind.</p>



<p>Grundlage für die neue digitale Shopping-Variante ist die Plattform „Visa Intelligent Commerce“ für sichere, KI-gestützte Einkäufe. Visa verbindet dabei über sein Netzwerk Finanzinstitute, Händler und KI-Systeme und ermöglicht sichere, authentifizierte Zahlungen im Einklang mit den regulatorischen Anforderungen in Europa.</p>



<p>Um die Transaktionen von KI-Agenten abzusichern, kommt das gemeinsam mit Cloudflare entwickelte <a href="https://www.computerwoche.de/article/4073710/shoppen-mit-ki-was-das-trusted-agent-protocol-von-visa-kann.html">Trusted Agent Protocol (TAP)</a> sowie ein spezielles Agent Directory zum Einsatz. Die Funktionen sollen Händlern dabei helfen, verifizierte KI-Agenten über verschiedene Plattformen und Umgebungen hinweg sicher zu erkennen und vertrauenswürdige von nicht verifizierten Zugriffen zu unterscheiden. Zugleich, so der Zahlungsdienstleister, behielten Händler die Kontrolle darüber, wie Agenten auf ihre Websites zugreifen, Produkte anzeigen und Transaktionen abschließen.</p>



<p>Eine neue Infrastruktur im Handel ist dafür laut Visa nicht erforderlich. TAP könne mit bestehenden E-Commerce-Protokollen zusammenarbeiten, die Händler nahtlos in ihre bevorzugten Plattformen einbinden können. Die Implementierung wird von Infrastrukturanbietern wie Cloudflare und Akamai unterstützt.</p>



<h2 class="wp-block-heading">Sicherheit und Kontrolle mit Visa Payment Passkeys</h2>



<p>Die Teilnahme kartenausgebender Finanzinstitute am KI-gestützten Handel wird über Visa Payment Passkeys ermöglicht. Dabei handelt es sich um eine vertrauenswürdige und regulatorisch konforme Authentifizierungsmethode, bei der biometrische Merkmale genutzt werden, um die Identität von Nutzern zu bestätigen.</p>



<p>Zu den teilnehmenden Händlern gehörten das Kölner Unternehmen Cleverbridge, lastminute.com, Frasers und BrickDepot. Deutlich besser schaut es bei den kartenausgebenden Finanzinstituten aus. Zu den mehr als 30 europäischen Banken, die bereits mithilfe von Visa-Payment-Passkeys erfolgreich Live-Transaktionen mit KI-Agenten bei teilnehmenden Händlern umgesetzt haben, zählen hierzulande:</p>



<ul class="wp-block-list">
<li>comdirect,</li>



<li>Commerzbank,</li>



<li>Deutsche Kreditbank (DKB),</li>



<li>ING und</li>



<li>S-Payment.</li>
</ul>



<p>„Wir sehen jetzt, wie KI-Agenten im Auftrag von Menschen direkt bei echten Händlern einkaufen können. Der nächste Schritt wird sein, dies im großen Maßstab auszurollen”, erklärt Tobias Czekalla, Deutschland-Chef bei Visa. Die Rolle von Visa dabei sei, Partner, Infrastruktur und Standards zusammenzubringen, um den KI-gestützten Handel gemeinsam voranzubringen.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing token theft]]></title>
<description><![CDATA[When you log into a service you’re given an authentication token. Each
further request to the site includes that token, allowing the server to
figure out who you are and ensuring that you have access to your
data. Depending on site policy, this token may either be stored in memory
(and so vanish ...]]></description>
<link>https://tsecurity.de/de/3640320/downloads/preventing-token-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640320/downloads/preventing-token-theft/</guid>
<pubDate>Thu, 02 Jul 2026 08:31:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When you log into a service you’re given an authentication token. Each
further request to the site includes that token, allowing the server to
figure out who you are and ensuring that you have access to your
data. Depending on site policy, this token may either be stored in memory
(and so vanish if you restart your browser) or disk. The token is the proof
of your identity. As far as the site is concerned, anyone with your token is
you. These tokens may be traditional browser cookies, but they may also be
stored in either site local storage or (if you’re not using a browser) in
some other storage location.</p>
<p>In recent years we’ve seen infostealer malware (like
<a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141b" target="_blank" rel="noopener">LummaC2</a>)
gain the ability to exfiltrate user tokens, allowing attackers to gain
access to the user’s data without needing to retain access to the user’s
machine. This attack is viable even if the site has strong MFA requirements,
so passkeys don’t help. Encrypting the tokens on disk doesn’t prevent the
malware from scraping them out of the browser’s RAM or obtaining whatever
key is used to encrypt them. This feels like a pretty hard problem to solve.</p>
<p>But that hasn’t stopped people from trying! Dirk Balfanz wrote an IETF draft
describing a mechanism for using <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-obc-01" target="_blank" rel="noopener">self-signed certificates for TLS
authentication</a>. This
uses the <a class="link" href="https://en.wikipedia.org/wiki/Mutual_authentication#mTLS" target="_blank" rel="noopener">mutual
authentication</a>
feature of the TLS protocol that requires both sides prove their identity to
each other. In regular TLS, the remote site presents a signed certificate
that tells you who it is. When performing mutual authentication, you then
present a certificate to the remote site telling it who <em>you</em> are. These
client certificates are largely unused outside enterprise environments
because they’re a <em>huge</em> pain to deploy. It’s not so much that this has
sharp edges, it’s that it’s entirely made of sharp edges. Managing
certificate deployment to your devices is hard. Browsers get confused if the
certificates change under them. You have one certificate and it lives
forever, so sites you present it to can track your identity. Users are
prompted to choose a certificate to authenticate with, and if they pick the
wrong one everything breaks and is hard to recover. I’ve deployed this and I
did not have a good time.</p>
<p>But Balfanz’s idea was simple. Rather than require certificates to be
deployed, browsers would simply generate a certificate on the fly. The goal
wasn’t to prove the device or user’s identity in any global way - but it
would associate a TLS session with a specific certificate. You could then,
for example, include a hash of the certificate in the cookie, and if someone
tried to use that cookie without presenting that certificate then the cookie
could be rejected. If the browser used a hardware-backed private key for the
certificate then it would be impossible for an attacker to steal it. Sure,
you could still steal cookies, but you wouldn’t be able to use them.</p>
<p>This was written almost 15 years ago, and seems simple, elegant, and
functional. It didn’t happen. Part of the reason for that is that, well, it
wasn’t quite so simple. One problem was privacy related. Cookies are only
sent after the TLS session is established, so anyone monitoring the network
doesn’t know anything about the user identity. A naive implementation of
this approach would have meant the client certificate being sent before
session establishment, and now user identity can be tracked (no longer an
issue if this was implemented on top of TLS 1.3, but this was a log time
ago). This was avoided by reordering the client handshake, but that meant
having to modify the TLS specification and implementations would have to be
updated to support this. Another was that figuring out the granularity of
the certificates was difficult. You’d want to use different certificates for
every site to avoid them effectively becoming tracking cookies, but you need
to provide the certificate before cookies are set, and you don’t know what
origin the site is going to set in its cookies. If you generate a
certificate for a.example.com and a different one for b.example.com, and
a.example.com sets a cookie for *.example.com and includes the certificate
you used for a.example.com, that cookie isn’t going to work on b.example.com
and things are broken. This meant supporting it wasn’t as straightforward as
it seemed - you’d need to ensure that your cookie scope was compatible with
the certificate scope. You could probably make this work well enough by
aligning it with the <a class="link" href="https://publicsuffix.org/" target="_blank" rel="noopener">Public Suffix List</a>, but
there was still some risk of expectations not being aligned.</p>
<p>And, perhaps most importantly, <a class="link" href="https://datatracker.ietf.org/doc/html/rfc5077" target="_blank" rel="noopener">TLS session
resumption</a> (replaced by
<a class="link" href="https://datatracker.ietf.org/doc/html/rfc8446#page-15" target="_blank" rel="noopener">pre-shared keys</a> in
TLS 1.3) somewhat defeats the purpose of the exercise - clients store state
that allows them to re-establish a TLS connection without performing
certificate exchange (this reduces overhead if a connection gets interrupted
or you switch to a new network or anything along those lines), and anyone in
a position to steal cookies could steal that state as well.</p>
<p>The followup attempt was <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-channelid-01" target="_blank" rel="noopener">channel
IDs</a>.
This simplified the implementation somewhat - rather than certificates, a
raw public key would be sent, along with proof of possession of the private
key in the form of a signature over a portion of the TLS handshake. This was
required even in the event of session resumption, which avoided having to
worry about theft of session secrets. The timing of the exchange was after
the encrypted session had been established, so user identity couldn’t be
leaked that way either. Cookies could then be bound to this
identifier. Unfortunately it didn’t really deal with the problem of scoping
keys in a way that would match cookie requirements, and the spec suggests
that the right way of handling this is to scope keys to TLDs, which would
enable user tracking across sites (Chrome’s implementation apparently
restricted it to eTLD+1, which would match the third party cookie policy and
avoid the tracking risk).</p>
<p>Chrome added support for this, but it was <a class="link" href="https://groups.google.com/a/chromium.org/g/net-dev/c/AjFQjBmaEQE/m/gIXoV3IFCQAJ?utm_medium=email&amp;utm_source=footer" target="_blank" rel="noopener">removed in early
2018</a>. The
discussion of some of the pain points in that message is interesting,
explicitly calling out problems with connection coalescing across domains
and the incompatibility with zero-RTT TLS1.3. The overall consensus at the
time seems to be that trying to solve this entirely at the TLS layer has too
many rough edges, and a different approach should be taken.</p>
<p>And so almost 7 years after the initial draft for origin bound certificates,
we come to <a class="link" href="https://datatracker.ietf.org/doc/html/rfc8471" target="_blank" rel="noopener">token
binding</a>. This ended up being
a rather more complex endeavour, covering 3 different RFCs describing how it
impacts TLS, how to incorporate it into HTTP, and how to manage all the
various parties involved in the process. The short version is that it’s
pretty similar to channel ID, except that there’s also a documented
mechanism for allowing tokens to be bound to one party and consumed by
another, avoiding any need for widely scoped keys. Token binding effectively
solved all the issues in the original proposal, but at the cost of somewhat
more complexity.</p>
<p>The RFC was finalised in October 2018. Chrome removed its (incomplete,
draft) support for token binding in November 2018. Edge carried support
until late 2024. Despite getting all the way through the RFC process, it’s
functionally dead.</p>
<p>The process up until this point had been largely initiated by Google, with
Microsoft contributing significantly to the token binding standards. The
work had been focused on identifying a generic solution to the problem
rather than tying it to any specific authentication flow. The next step was
in a different direction - rather than trying to fix this for the entire
internet, how about we try to fix it for OAuth?</p>
<p><a class="link" href="https://datatracker.ietf.org/doc/html/rfc8705" target="_blank" rel="noopener">RFC 8705</a> is titled “OAuth
2.0 Mutual-TLS Client Authentication and Certificate-Bound Access
Tokens”. This is basically the 2011 approach, but (a) with an explicit
definition of how the certificate should be incorporated into issued auth
cookies, and (b) with a proviso that well uh if you’re going to use tokens
issued by your IdP to authenticate to someone else then well you’re going to
need to use the same cert for both. This is probably fine for the
company-owned-laptop case where you’re actually fine with multiple sites
being able to tie identities together (that’s kind of the point here!), and
also works for “I am using an app and not a browser”, but doesn’t work for
more generic scenarios. It also doesn’t seem to take the session resumption
case into account at all? Support for RFC8705 seems poor, as far as I can
tell of the big players only Auth0 implements it. In theory it works fine
with self-signed client certs but in reality that’s going to be almost as
difficult to support across multiple platforms as just issuing proper client
certs in the first place, so deployment is going to be kind of a pain. But
the good news is it doesn’t rely on any TLS extensions or custom browser
behaviour, so at the client side it works fine with any browser.</p>
<p>Which brings us on to <a class="link" href="https://datatracker.ietf.org/doc/html/rfc9449" target="_blank" rel="noopener">RFC
9449</a>, “Demonstrating Proof
of Possession”. This goes even further than RFC8705 in terms of reducing the
burden of deployment - it works fine with existing browsers, <em>and</em> it
doesn’t even require any certs. The client generates a keypair and provides
the pubkey when requesting the cookie. The cookie contains the pubkey. Every
request to the service now provides the cookie with the pubkey and also
provides a signature over the URI and HTTP method. If the signature matches
the pubkey in the token then clearly the signature came from the machine the
token was issued to, and everything is good.</p>
<p>This does come with some downsides, though. The first is that it uses
browser interfaces to generate the keys (typically
<a class="link" href="https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/generateKey" target="_blank" rel="noopener">crypto.subtle.generatekey()</a>)
and as far as I can tell there are no browsers that guarantee that that key
is going to be generated in hardware even if it’s marked non-exportable, so
anyone able to steal the cookies can also steal the keys. The second is that
the signature only covers the URI and HTTP method, and not the message
content or any other headers, so anyone able to exfiltrate a valid signature
can replay it against the same URI with different message content. The
recommended way to handle this is to reject any signatures that weren’t
generated within the last few seconds, which is a wonderful additional way
to allow clock skew to give you a Bad Day. And the third is that every
single request has to be separately signed, which is not intrinsically a
problem because computers are fast and have multiple cores, but if you’re
trying to solve the first problem by sticking the key in a TPM then you’re
dealing with something that’s slow and single threaded and that’s maybe
acceptable if you’re using client certificates (because there’s going to be
one signature per session and you can use the same session for multiple
requests) but probably not if you’re dealing with a user opening a browser
that restores previous tabs and each of those is a webapp that fires off 100
requests in parallel.</p>
<p>In case it wasn’t clear, I don’t like DPoP. It doesn’t feel like it actually
solves the underlying problem that we see in the real world (malware running
in a context where if it can grab the tokens it can grab the keys), it adds
a massive amount of overhead, and it has baked in replay vulnerabilities. I
don’t know why it exists and I’m incredibly suspicious of vendors telling me
that it fixes my problems, because if they’re telling me that then I’m going
to end up assuming that they either don’t understand my problems or they
don’t understand their technology, and neither of those is good.</p>
<p>Still. Then we get to the thing that prompted me to write this - Chrome’s
announcement that they had <a class="link" href="https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html" target="_blank" rel="noopener">launched device-bound session
credentials</a>. This
is interesting because it’s a Chrome feature that’s explicitly intended to
counter on-device malware, which was one of the things that was out of scope
in 2018 when token binding was being removed. Since this is entire web level
it doesn’t have to be an RFC, and so is instead defined <a class="link" href="https://w3c.github.io/webappsec-dbsc/" target="_blank" rel="noopener">by
W3C</a>. I’m going to handwave all the
complexity and say that it’s basically a way to register a public key when a
cookie is issued, and then prove possession of the private key when it’s
time to renew the cookie. By making the cookies shortlived and having
support for rotating them in the background, user impact is basically zero
and while it’s still possible for an attacker to exfiltrate and use a cookie
they’ll only be able to do so for a short window before it needs to be
refreshed - something the attacker can’t do, since they don’t have the
private key. This avoids the DPoP overhead because you only need to do
signing once per cookie per cookie lifetime, and not on every single
request. I don’t <em>like</em> this due to the window where exfiltrated tokens can
be used, but it feels like a strict improvement over the status quo. An
extension called <a class="link" href="https://github.com/w3c/webappsec-dbsc/blob/main/DBSCE/Overview.md" target="_blank" rel="noopener">device-bound session credentials for
enterprise</a>
allows pre-enrollment of device keys, so even though the actual runtime DBCE
flow doesn’t involve certificates, certificates can be used for device
registration in enterprise environments and you can make sure that auth
cookies only go to trusted devices. Unfortunately this is Chrome-only, and
so we’re going to need to wait for it to be backported to all the random app
frameworks for it to have widespread support on mobile or for almost
everyone’s desktop app that’s actually three websites in an Electron
wrapper. Mozilla’s <a class="link" href="https://github.com/mozilla/standards-positions/issues/912#issuecomment-4840591341" target="_blank" rel="noopener">current
position</a>
is that they’re not in favour of it, so I guess we’ll see where Safari lands
in terms of broad uptake.</p>
<p>The last thing on my list is <a class="link" href="https://datatracker.ietf.org/doc/draft-mw-oauth-tls-session-bound-tokens/04/" target="_blank" rel="noopener">another client cert/OAuth
binding</a>,
this one still in draft state at the time of writing. This one is aimed
primarily at the use of agent-driven tooling, where you have something
running in the background using a whole bunch of tools that are each acting
on your behalf. Authenticating to all of them separately isn’t a fun time,
but giving broadly scoped access tokens to a non-deterministic agent and
trusting that it’ll never post them somewhere public also isn’t a fun
time. The key distinction between it and RFC8705 is that it’s aimed at
<em>connections</em> rather than <em>sessions</em>, which avoids the worries about session
resumption. This is done with <a class="link" href="https://datatracker.ietf.org/doc/html/rfc5705" target="_blank" rel="noopener">TLS
Exporters</a>, which in TLS 1.3
should be unique to the connection even over session resumption (TLS 1.2 may
reuse some of the same key material for exporters over session resumption,
so it’s recommended to enforce 1.3 for this). By providing a new signature
alongside the cookie on every new connection, the client proves that it
still has access to the private key. This is a very new spec and I haven’t
had much time to work through it yet, but my naive understanding is that
unlike RFC8705 this would require some additional client support to be able
to regenerate the client signature on every TLS reconnection.</p>
<p>This doesn’t avoid all the problems that RFC8705 has, including how to scope
certificates. For the agentic use case that probably doesn’t matter - all
these tools are acting on behalf of the same user, it’s fine if all the
sites involved know they’re the same user. But it doesn’t solve the general
purpose user use case, and right now DBSC seems like the best we have there.</p>
<p>But. Part of me still wonders whether <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-obc-01" target="_blank" rel="noopener">Dirk
Balfanz’s</a>
approach was the right one. Yes, there’s risk associated with TLS session
resumption, but in the worst case you could just switch that off for high
risk setups. The cookie scope argument is real, and also in cases where it
could violate privacy the site owner could already choose to broaden their
cookie scope and violate your privacy, and in cases where it breaks things
you could just not make use of it. The other problems are largely fixed by
TLS 1.3, and then we’re just left with “Browsers handle client certificates
badly” to which my answer is “Yes, and we should fix that anyway”.</p>
<p>Despite having a pretty good answer to this solution over a decade ago, the
closest we have to actual deployment is something that offers strictly worse
security guarantees. And tokens keep getting stolen, and compromises keep
occurring, and for the most part people shrug and get on with things.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: secIT digital: Diese Anti-Phishing-Ansätze helfen wirklich]]></title>
<description><![CDATA[Ende September auf der secIT digital: hilfreiche Tipps zur Umsetzung vom Cyber Resilience Act und Grundschutz++. Außerdem: mit Passkeys & Co. gegen Phishing.]]></description>
<link>https://tsecurity.de/de/3638117/it-nachrichten/heise-angebot-secit-digital-diese-anti-phishing-ansaetze-helfen-wirklich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638117/it-nachrichten/heise-angebot-secit-digital-diese-anti-phishing-ansaetze-helfen-wirklich/</guid>
<pubDate>Wed, 01 Jul 2026 12:16:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ende September auf der secIT digital: hilfreiche Tipps zur Umsetzung vom Cyber Resilience Act und Grundschutz++. Außerdem: mit Passkeys &amp; Co. gegen Phishing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for Desktop]]></title>
<description><![CDATA[The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.Chrome 150.0.7871.46 (Linux) 150.0.7871.46/.47 Windows/Mac contains a number of fixes and improvements -- a list of changes is avail...]]></description>
<link>https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637049/it-security-nachrichten/stable-channel-update-for-desktop/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>The Chrome team is delighted to announce the promotion of Chrome 151 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Chrome </span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)">150.0.7871.46 (Linux) </span></span></span></span></span><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span>150.0.7871.46/.47 </span><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)">Windows/Mac </span></span></span><span><span color="rgba(0, 0, 0, 0.87)">contains a number of fixes and improvements -- a list of changes is available in the</span><a href="https://chromium.googlesource.com/chromium/src/+log/149.0.7827.201..150.0.7871.47?pretty=fuller&amp;n=10000"> log</a><span color="rgba(0, 0, 0, 0.87)">. Watch out for upcoming</span><a href="https://chrome.blogspot.com/"> </a><a href="https://chrome.blogspot.com/">Chrome</a> </span><span>and</span><a href="https://blog.chromium.org/"> Chromium</a><span> blog posts about new features and big efforts delivered in 151.</span></span></span></span></p><div><span>Security Fixes and Rewards<br></span><span>Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.<br></span><span>This update includes </span><a href="https://issues.chromium.org/issues?q=customfield1223088:0-M150"><span>382</span></a><span> security fixes. Please see the </span><a href="https://www.chromium.org/Home/chromium-security"><span>Chrome Security Page</span></a><span> for more information.<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506558270"><span>506558270</span></a><span>]</span><span> Critical </span><span>CVE-2026-13774: Use after free in Extensions. </span><span>Reported by Google on 2026-04-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511766407"><span>511766407</span></a><span>]</span><span> Critical </span><span>CVE-2026-13775: Use after free in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513012139"><span>513012139</span></a><span>]</span><span> Critical </span><span>CVE-2026-13776: Type Confusion in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128566"><span>513128566</span></a><span>]</span><span> Critical </span><span>CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513167952"><span>513167952</span></a><span>]</span><span> Critical </span><span>CVE-2026-13778: Use after free in WebUSB. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513222854"><span>513222854</span></a><span>]</span><span> Critical </span><span>CVE-2026-13779: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514769383"><span>514769383</span></a><span>]</span><span> Critical </span><span>CVE-2026-13780: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516457532"><span>516457532</span></a><span>]</span><span> Critical </span><span>CVE-2026-13781: Insufficient validation of untrusted input in Skia. </span><span>Reported by Google on 2026-05-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516683433"><span>516683433</span></a><span>]</span><span> Critical </span><span>CVE-2026-13782: Use after free in Browser. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962178"><span>516962178</span></a><span>]</span><span> Critical </span><span>CVE-2026-13783: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516962715"><span>516962715</span></a><span>]</span><span> Critical </span><span>CVE-2026-13784: Use after free in Views. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517021684"><span>517021684</span></a><span>]</span><span> Critical </span><span>CVE-2026-13785: Use after free in Bluetooth. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/518007821"><span>518007821</span></a><span>]</span><span> Critical </span><span>CVE-2026-13786: Use after free in Ozone. </span><span>Reported by Google on 2026-05-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522919313"><span>522919313</span></a><span>]</span><span> Critical </span><span>CVE-2026-13787: Use after free in Chromoting. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523119897"><span>523119897</span></a><span>]</span><span> Critical </span><span>CVE-2026-13788: Use after free in Fullscreen. </span><span>Reported by Google on 2026-06-12<br></span><span>[$36000][</span><a href="https://issues.chromium.org/issues/493847920"><span>493847920</span></a><span>]</span><span> High </span><span>CVE-2026-13789: Use after free in GPU. </span><span>Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-18<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/457771782"><span>457771782</span></a><span>]</span><span> High </span><span>CVE-2026-13790: Side-channel information leakage in Scroll. </span><span>Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer on 2025-11-04<br></span><span>[$10000][</span><a href="https://issues.chromium.org/issues/503850012"><span>503850012</span></a><span>]</span><span> High </span><span>CVE-2026-13791: Insufficient validation of untrusted input in Downloads. </span><span>Reported by Ron Masas (Imperva) on 2026-04-17<br></span><span>[$4000][</span><a href="https://issues.chromium.org/issues/496012368"><span>496012368</span></a><span>]</span><span> High </span><span>CVE-2026-13792: Use after free in Touchbar. </span><span>Reported by Weipeng Jiang (@Krace) of VRI on 2026-03-25<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/510829679"><span>510829679</span></a><span>]</span><span> High </span><span>CVE-2026-13793: Insufficient policy enforcement in SVG. </span><span>Reported by pakhunov.anton.n@gmail.com on 2026-05-07<br></span><span>[$2500][</span><a href="https://issues.chromium.org/issues/513893425"><span>513893425</span></a><span>]</span><span> High </span><span>CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Daniel Rodríguez on 2026-05-16<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/476591032"><span>476591032</span></a><span>]</span><span> High </span><span>CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS. </span><span>Reported by maitai on 2026-01-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/491894115"><span>491894115</span></a><span>]</span><span> High </span><span>CVE-2026-13796: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-03-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025645"><span>499025645</span></a><span>]</span><span> High </span><span>CVE-2026-13797: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499048914"><span>499048914</span></a><span>]</span><span> High </span><span>CVE-2026-13798: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499252371"><span>499252371</span></a><span>]</span><span> High </span><span>CVE-2026-13799: Use after free in QUIC. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500108770"><span>500108770</span></a><span>]</span><span> High </span><span>CVE-2026-13800: Inappropriate implementation in Updater. </span><span>Reported by Google on 2026-04-06</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/500587568"><span>500587568</span></a><span>]</span><span> High </span><span>CVE-2026-13801: Integer overflow in Chromecast. </span><span>Reported by Google on 2026-04-08</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/501623322"><span>501623322</span></a><span>]</span><span> High </span><span>CVE-2026-13802: Use after free in Views. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501669642"><span>501669642</span></a><span>]</span><span> High </span><span>CVE-2026-13803: Type Confusion in Chrome Tabs. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501873032"><span>501873032</span></a><span>]</span><span> High </span><span>CVE-2026-13804: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502282040"><span>502282040</span></a><span>]</span><span> High </span><span>CVE-2026-13805: Use after free in GFX. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503333798"><span>503333798</span></a><span>]</span><span> High </span><span>CVE-2026-13806: Insufficient validation of untrusted input in Accessibility. </span><span>Reported by Google on 2026-04-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504194494"><span>504194494</span></a><span>]</span><span> High </span><span>CVE-2026-13807: Use after free in Import. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504221510"><span>504221510</span></a><span>]</span><span> High </span><span>CVE-2026-13808: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504222227"><span>504222227</span></a><span>]</span><span> High </span><span>CVE-2026-13809: Side-channel information leakage in Safe Browsing. </span><span>eported by Google on 2026-04-19<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/504600482"><span>504600482</span></a><span>]</span><span> High </span><span>CVE-2026-13810: Inappropriate implementation in Input. </span><span>Reported by dilipsc03@gmail.com on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506149253"><span>506149253</span></a><span>]</span><span> High </span><span>CVE-2026-13811: Use after free in IME. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508293203"><span>508293203</span></a><span>]</span><span> High </span><span>CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508462149"><span>508462149</span></a><span>]</span><span> High </span><span>CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511712766"><span>511712766</span></a><span>]</span><span> High </span><span>CVE-2026-13814: Use after free in Views. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722207"><span>511722207</span></a><span>]</span><span> High </span><span>CVE-2026-13815: Use after free in Blink. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511735715"><span>511735715</span></a><span>]</span><span> High </span><span>CVE-2026-13816: Insufficient validation of untrusted input in File Input. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511739631"><span>511739631</span></a><span>]</span><span> High </span><span>CVE-2026-13817: Insufficient validation of untrusted input in Glic. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511823182"><span>511823182</span></a><span>]</span><span> High </span><span>CVE-2026-13818: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512962749"><span>512962749</span></a><span>]</span><span> High </span><span>CVE-2026-13819: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512986879"><span>512986879</span></a><span>]</span><span> High </span><span>CVE-2026-13820: Out of bounds read in Skia. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513142445"><span>513142445</span></a><span>]</span><span> High </span><span>CVE-2026-13821: Use after free in Canvas. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513148038"><span>513148038</span></a><span>]</span><span> High </span><span>CVE-2026-13822: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513163011"><span>513163011</span></a><span>]</span><span> High </span><span>CVE-2026-13823: Use after free in Glic. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177497"><span>513177497</span></a><span>]</span><span> High </span><span>CVE-2026-13824: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513209610"><span>513209610</span></a><span>]</span><span> High </span><span>CVE-2026-13825: Uninitialized Use in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513237800"><span>513237800</span></a><span>]</span><span> High </span><span>CVE-2026-13826: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513371963"><span>513371963</span></a><span>]</span><span> High </span><span>CVE-2026-13827: Use after free in Updater. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513399832"><span>513399832</span></a><span>]</span><span> High </span><span>CVE-2026-13828: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513490996"><span>513490996</span></a><span>]</span><span> High </span><span>CVE-2026-13829: Insufficient validation of untrusted input in Settings. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727494"><span>513727494</span></a><span>]</span><span> High </span><span>CVE-2026-13830: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513781328"><span>513781328</span></a><span>]</span><span> High </span><span>CVE-2026-13831: Use after free in GPU. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513822378"><span>513822378</span></a><span>]</span><span> High </span><span>CVE-2026-13832: Use after free in Headless. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513920082"><span>513920082</span></a><span>]</span><span> High </span><span>CVE-2026-13833: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513925114"><span>513925114</span></a><span>]</span><span> High </span><span>CVE-2026-13834: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-05-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514338102"><span>514338102</span></a><span>]</span><span> High </span><span>CVE-2026-13835: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514420555"><span>514420555</span></a><span>]</span><span> High </span><span>CVE-2026-13836: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514429130"><span>514429130</span></a><span>]</span><span> High </span><span>CVE-2026-13837: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514445398"><span>514445398</span></a><span>]</span><span> High </span><span>CVE-2026-13838: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/514449396"><span>514449396</span></a><span>]</span><span> High </span><span>CVE-2026-13839: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-18<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/514609778"><span>514609778</span></a><span>]</span><span> High </span><span>CVE-2026-13840: Insufficient policy enforcement in Canvas. </span><span>Reported by Binglin Song on 2026-05-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/515467789"><span>515467789</span></a><span>]</span><span> High </span><span>CVE-2026-13841: Integer overflow in Skia. </span><span>Reported by Google on 2026-05-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/516836297"><span>516836297</span></a><span>]</span><span> High </span><span>CVE-2026-13842: Incorrect security UI in Chrome for iOS. </span><span>Reported by Azza Tegar Naufal Ataullah on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516869032"><span>516869032</span></a><span>]</span><span> High </span><span>CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516926115"><span>516926115</span></a><span>]</span><span> High </span><span>CVE-2026-13844: Use after free in Updater. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516936863"><span>516936863</span></a><span>]</span><span> High </span><span>CVE-2026-13845: Use after free in DOM. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/516999424"><span>516999424</span></a><span>]</span><span> High </span><span>CVE-2026-13846: Use after free in USB. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517073397"><span>517073397</span></a><span>]</span><span> High </span><span>CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-27<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517345069"><span>517345069</span></a><span>]</span><span> High </span><span>CVE-2026-13848: Use after free in Forms. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517351411"><span>517351411</span></a><span>]</span><span> High </span><span>CVE-2026-13849: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/517610676"><span>517610676</span></a><span>]</span><span> High </span><span>CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/519692255"><span>519692255</span></a><span>]</span><span> High </span><span>CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/522560124"><span>522560124</span></a><span>]</span><span> High </span><span>CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-06-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523224019"><span>523224019</span></a><span>]</span><span> High </span><span>CVE-2026-13853: Use after free in Journeys. </span><span>Reported by Google on 2026-06-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/523690961"><span>523690961</span></a><span>]</span><span> High </span><span>CVE-2026-13854: Use after free in Ozone. </span><span>Reported by Google on 2026-06-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/524395469"><span>524395469</span></a><span>]</span><span> High </span><span>CVE-2026-13855: Use after free in Ozone. </span><span>Reported by Google on 2026-06-16<br></span><span>[$8000][</span><a href="https://issues.chromium.org/issues/508092634"><span>508092634</span></a><span>]</span><span> Medium </span><span>CVE-2026-13856: Insufficient validation of untrusted input in Speech. </span><span>Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-04-30<br></span><span>[$5000][</span><a href="https://issues.chromium.org/issues/479203484"><span>479203484</span></a><span>]</span><span> Medium </span><span>CVE-2026-13857: Inappropriate implementation in Geometry. </span><span>Reported by Luan Herrera (@lbherrera_) on 2026-01-27<br></span><span>[$3000][</span><a href="https://issues.chromium.org/issues/507090179"><span>507090179</span></a><span>]</span><span> Medium </span><span>CVE-2026-13858: Out of bounds read in FFmpeg. </span><span>Reported by Wongi Lee (@_qwerty_po) of Theori with Xint Code, Jungwoo Lee (@physicube) on 2026-04-27<br></span><span>[$2000][</span><a href="https://issues.chromium.org/issues/484756087"><span>484756087</span></a><span>]</span><span> Medium </span><span>CVE-2026-13859: Inappropriate implementation in ANGLE. </span><span>Reported by Jason Villaluna on 2026-02-15<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/417052041"><span>417052041</span></a><span>]</span><span> Medium </span><span>CVE-2026-13860: Incorrect security UI in Autofill. </span><span>Reported by Khalil Zhani on 2025-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495456765"><span>495456765</span></a><span>]</span><span> Medium </span><span>CVE-2026-13861: Use after free in Core. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495897416"><span>495897416</span></a><span>]</span><span> Medium </span><span>CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys &amp; Security Keys). </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496012495"><span>496012495</span></a><span>]</span><span> Medium </span><span>CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-03-25<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496399913"><span>496399913</span></a><span>]</span><span> Medium </span><span>CVE-2026-13864: Insufficient policy enforcement in WebHID. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497090912"><span>497090912</span></a><span>]</span><span> Medium </span><span>CVE-2026-13865: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497207698"><span>497207698</span></a><span>]</span><span> Medium </span><span>CVE-2026-13866: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497345177"><span>497345177</span></a><span>]</span><span> Medium </span><span>CVE-2026-13867: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497453475"><span>497453475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13868: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497610642"><span>497610642</span></a><span>]</span><span> Medium </span><span>CVE-2026-13869: Use after free in Device. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497634837"><span>497634837</span></a><span>]</span><span> Medium </span><span>CVE-2026-13870: Use after free in WebView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497961376"><span>497961376</span></a><span>]</span><span> Medium </span><span>CVE-2026-13871: Insufficient data validation in GuestView. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497977983"><span>497977983</span></a><span>]</span><span> Medium </span><span>CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498085466"><span>498085466</span></a><span>]</span><span> Medium </span><span>CVE-2026-13873: Out of bounds memory access in Layout. </span><span>Reported by Google on 2026-03-31<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498411773"><span>498411773</span></a><span>]</span><span> Medium </span><span>CVE-2026-13874: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498721671"><span>498721671</span></a><span>]</span><span> Medium </span><span>CVE-2026-13875: Insufficient validation of untrusted input in GPU. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498722200"><span>498722200</span></a><span>]</span><span> Medium </span><span>CVE-2026-13876: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-04-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498820206"><span>498820206</span></a><span>]</span><span> Medium </span><span>CVE-2026-13877: Insufficient validation of untrusted input in ANGLE. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499007266"><span>499007266</span></a><span>]</span><span> Medium </span><span>CVE-2026-13878: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499022239"><span>499022239</span></a><span>]</span><span> Medium </span><span>CVE-2026-13879: Use after free in Bluetooth. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499025880"><span>499025880</span></a><span>]</span><span> Medium </span><span>CVE-2026-13880: Use after free in USB. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499100491"><span>499100491</span></a><span>]</span><span> Medium </span><span>CVE-2026-13881: Insufficient data validation in WebAppInstalls. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499162550"><span>499162550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13882: Inappropriate implementation in USB. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500030250"><span>500030250</span></a><span>]</span><span> Medium </span><span>CVE-2026-13883: Type Confusion in ANGLE. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500077014"><span>500077014</span></a><span>]</span><span> Medium </span><span>CVE-2026-13884: Heap buffer overflow in Chromecast. </span><span>Reported by Google on 2026-04-06<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500474409"><span>500474409</span></a><span>]</span><span> Medium </span><span>CVE-2026-13885: Use after free in Skia. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500475136"><span>500475136</span></a><span>]</span><span> Medium </span><span>CVE-2026-13886: Policy bypass in Isolated Web Apps. </span><span>Reported by Google on 2026-04-07<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500508524"><span>500508524</span></a><span>]</span><span> Medium </span><span>CVE-2026-13887: Insufficient policy enforcement in NFC. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500566906"><span>500566906</span></a><span>]</span><span> Medium </span><span>CVE-2026-13888: Use after free in Extensions. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500588580"><span>500588580</span></a><span>]</span><span> Medium </span><span>CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/500601345"><span>500601345</span></a><span>]</span><span> Medium </span><span>CVE-2026-13890: Out of bounds read in Chromecast. </span><span>Reported by Google on 2026-04-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501631475"><span>501631475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13891: Insufficient validation of untrusted input in Extensions. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501674841"><span>501674841</span></a><span>]</span><span> Medium </span><span>CVE-2026-13892: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501729582"><span>501729582</span></a><span>]</span><span> Medium </span><span>CVE-2026-13893: Insufficient validation of untrusted input in WebUI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501741117"><span>501741117</span></a><span>]</span><span> Medium </span><span>CVE-2026-13894: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501770542"><span>501770542</span></a><span>]</span><span> Medium </span><span>CVE-2026-13895: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501820076"><span>501820076</span></a><span>]</span><span> Medium </span><span>CVE-2026-13896: Insufficient policy enforcement in Glic. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501877896"><span>501877896</span></a><span>]</span><span> Medium </span><span>CVE-2026-13897: Insufficient policy enforcement in Chromecast. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501925480"><span>501925480</span></a><span>]</span><span> Medium </span><span>CVE-2026-13898: Use after free in Cast Receiver. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502109002"><span>502109002</span></a><span>]</span><span> Medium </span><span>CVE-2026-13899: Use after free in HTML. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502374993"><span>502374993</span></a><span>]</span><span> Medium </span><span>CVE-2026-13900: Insufficient validation of untrusted input in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503585173"><span>503585173</span></a><span>]</span><span> Medium </span><span>CVE-2026-13901: Insufficient validation of untrusted input in Serial. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503725717"><span>503725717</span></a><span>]</span><span> Medium </span><span>CVE-2026-13902: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503912196"><span>503912196</span></a><span>]</span><span> Medium </span><span>CVE-2026-13903: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504185807"><span>504185807</span></a><span>]</span><span> Medium </span><span>CVE-2026-13904: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504192688"><span>504192688</span></a><span>]</span><span> Medium </span><span>CVE-2026-13905: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504613867"><span>504613867</span></a><span>]</span><span> Medium </span><span>CVE-2026-13906: Out of bounds read in Codecs. </span><span>Reported by Google on 2026-04-20<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505156685"><span>505156685</span></a><span>]</span><span> Medium </span><span>CVE-2026-13907: Inappropriate implementation in iOSWeb. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505242189"><span>505242189</span></a><span>]</span><span> Medium </span><span>CVE-2026-13908: Insufficient validation of untrusted input in Omnibox. </span><span>Reported by Google on 2026-04-22<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505933538"><span>505933538</span></a><span>]</span><span> Medium </span><span>CVE-2026-13909: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507231605"><span>507231605</span></a><span>]</span><span> Medium </span><span>CVE-2026-13910: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507239830"><span>507239830</span></a><span>]</span><span> Medium </span><span>CVE-2026-13911: Insufficient data validation in Spellcheck. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508259433"><span>508259433</span></a><span>]</span><span> Medium </span><span>CVE-2026-13912: Incorrect security UI in Safe Browsing. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508260619"><span>508260619</span></a><span>]</span><span> Medium </span><span>CVE-2026-13913: Insufficient policy enforcement in Autofill. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508273690"><span>508273690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13914: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508275293"><span>508275293</span></a><span>]</span><span> Medium </span><span>CVE-2026-13915: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508283108"><span>508283108</span></a><span>]</span><span> Medium </span><span>CVE-2026-13916: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/508286935"><span>508286935</span></a><span>]</span><span> Medium </span><span>CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/509712284"><span>509712284</span></a><span>]</span><span> Medium </span><span>CVE-2026-13918: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-05<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511249430"><span>511249430</span></a><span>]</span><span> Medium </span><span>CVE-2026-13919: Insufficient data validation in Extensions. </span><span>Reported by Google on 2026-05-08<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511722559"><span>511722559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13920: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511738175"><span>511738175</span></a><span>]</span><span> Medium </span><span>CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511748106"><span>511748106</span></a><span>]</span><span> Medium </span><span>CVE-2026-13922: Side-channel information leakage in Paint. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511772034"><span>511772034</span></a><span>]</span><span> Medium </span><span>CVE-2026-13923: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511784747"><span>511784747</span></a><span>]</span><span> Medium </span><span>CVE-2026-13924: Insufficient validation of untrusted input in WebView. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511802911"><span>511802911</span></a><span>]</span><span> Medium </span><span>CVE-2026-13925: Inappropriate implementation in Downloads. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511814550"><span>511814550</span></a><span>]</span><span> Medium </span><span>CVE-2026-13926: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511826446"><span>511826446</span></a><span>]</span><span> Medium </span><span>CVE-2026-13927: Insufficient validation of untrusted input in UI. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512162479"><span>512162479</span></a><span>]</span><span> Medium </span><span>CVE-2026-13928: Insufficient validation of untrusted input in Enterprise. </span><span>Reported by Google on 2026-05-11<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/512249559"><span>512249559</span></a><span>]</span><span> Medium </span><span>CVE-2026-13929: Insufficient validation of untrusted input in DevTools. </span><span>Reported by LegioSec on 2026-05-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512937764"><span>512937764</span></a><span>]</span><span> Medium </span><span>CVE-2026-13930: Insufficient policy enforcement in Actor. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997441"><span>512997441</span></a><span>]</span><span> Medium </span><span>CVE-2026-13931: Inappropriate implementation in Media. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513001690"><span>513001690</span></a><span>]</span><span> Medium </span><span>CVE-2026-13932: Inappropriate implementation in Sharing. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513002625"><span>513002625</span></a><span>]</span><span> Medium </span><span>CVE-2026-13933: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513006636"><span>513006636</span></a><span>]</span><span> Medium </span><span>CVE-2026-13934: Insufficient validation of untrusted input in Dawn. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513009005"><span>513009005</span></a><span>]</span><span> Medium </span><span>CVE-2026-13935: Side-channel information leakage in ComputePressure. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513044658"><span>513044658</span></a><span>]</span><span> Medium </span><span>CVE-2026-13936: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513046494"><span>513046494</span></a><span>]</span><span> Medium </span><span>CVE-2026-13937: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513143921"><span>513143921</span></a><span>]</span><span> Medium </span><span>CVE-2026-13938: Integer overflow in Fonts. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513149760"><span>513149760</span></a><span>]</span><span> Medium </span><span>CVE-2026-13939: Insufficient validation of untrusted input in WebShare. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513158425"><span>513158425</span></a><span>]</span><span> Medium </span><span>CVE-2026-13940: Uninitialized Use in Cast. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513183855"><span>513183855</span></a><span>]</span><span> Medium </span><span>CVE-2026-13941: Inappropriate implementation in SiteSettings. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513186670"><span>513186670</span></a><span>]</span><span> Medium </span><span>CVE-2026-13942: Insufficient validation of untrusted input in Video Capture. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513204116"><span>513204116</span></a><span>]</span><span> Medium </span><span>CVE-2026-13943: Uninitialized Use in CSS. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513224212"><span>513224212</span></a><span>]</span><span> Medium </span><span>CVE-2026-13944: Inappropriate implementation in DataTransfer. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513226551"><span>513226551</span></a><span>]</span><span> Medium </span><span>CVE-2026-13945: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513274039"><span>513274039</span></a><span>]</span><span> Medium </span><span>CVE-2026-13946: Inappropriate implementation in ScriptInjections. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513280648"><span>513280648</span></a><span>]</span><span> Medium </span><span>CVE-2026-13947: Uninitialized Use in XR. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513286820"><span>513286820</span></a><span>]</span><span> Medium </span><span>CVE-2026-13948: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513311569"><span>513311569</span></a><span>]</span><span> Medium </span><span>CVE-2026-13949: Insufficient policy enforcement in Payments. </span><span>Reported by Google on 2026-05-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513360781"><span>513360781</span></a><span>]</span><span> Medium </span><span>CVE-2026-13950: Uninitialized Use in GPU. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513394321"><span>513394321</span></a><span>]</span><span> Medium </span><span>CVE-2026-13951: Policy bypass in USB. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513401808"><span>513401808</span></a><span>]</span><span> Medium </span><span>CVE-2026-13952: Inappropriate implementation in PerformanceAPIs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513459192"><span>513459192</span></a><span>]</span><span> Medium </span><span>CVE-2026-13953: Inappropriate implementation in SplitView. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513504934"><span>513504934</span></a><span>]</span><span> Medium </span><span>CVE-2026-13954: Insufficient policy enforcement in XML. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513508305"><span>513508305</span></a><span>]</span><span> Medium </span><span>CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513515168"><span>513515168</span></a><span>]</span><span> Medium </span><span>CVE-2026-13956: Incorrect security UI in PageInfo. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513553557"><span>513553557</span></a><span>]</span><span> Medium </span><span>CVE-2026-13957: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513567306"><span>513567306</span></a><span>]</span><span> Medium </span><span>CVE-2026-13958: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513609249"><span>513609249</span></a><span>]</span><span> Medium </span><span>CVE-2026-13959: Insufficient validation of untrusted input in Blink. </span><span>Reported by Google on 2026-05-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513714023"><span>513714023</span></a><span>]</span><span> Medium </span><span>CVE-2026-13960: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513719481"><span>513719481</span></a><span>]</span><span> Medium </span><span>CVE-2026-13961: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513721370"><span>513721370</span></a><span>]</span><span> Medium </span><span>CVE-2026-13962: Insufficient data validation in PDF. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513727626"><span>513727626</span></a><span>]</span><span> Medium </span><span>CVE-2026-13963: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513735096"><span>513735096</span></a><span>]</span><span> Medium </span><span>CVE-2026-13964: Insufficient policy enforcement in WebView. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737952"><span>513737952</span></a><span>]</span><span> Medium </span><span>CVE-2026-13965: Use after free in Oilpan. </span><span>Reported by Google on 2026-05-16<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513741393"><span>513741393</span></a><span>] </span><span>Medium </span><span>CVE-2026-13966: Inappropriate implementation in History. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751951"><span>513751951</span></a><span>] </span><span>Medium </span><span>CVE-2026-13967: Type Confusion in V8. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762145"><span>513762145</span></a><span>] </span><span>Medium </span><span>CVE-2026-13968: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513762962"><span>513762962</span></a><span>] </span><span>Medium </span><span>CVE-2026-13969: Uninitialized Use in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513779283"><span>513779283</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13970: Uninitialized Use in Media. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513780208"><span>513780208</span></a><span>]</span><span> </span><span>Medium </span><span>CVE-2026-13971: Uninitialized Use in Skia. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513792140"><span>513792140</span></a><span>]</span><span> Medium </span><span>CVE-2026-13972: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513832989"><span>513832989</span></a><span>]</span><span> Medium </span><span>CVE-2026-13973: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513850475"><span>513850475</span></a><span>]</span><span> Medium </span><span>CVE-2026-13974: Integer overflow in Safe Browsing. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513857658"><span>513857658</span></a><span>] </span><span>Medium </span><span>CVE-2026-13975: Out of bounds read in ANGLE. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513858286"><span>513858286</span></a><span>] </span><span>Medium </span><span>CVE-2026-13976: Heap buffer overflow in Storage. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513859894"><span>513859894</span></a><span>] </span><span>Medium </span><span>CVE-2026-13977: Inappropriate implementation in HTMLParser. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513866949"><span>513866949</span></a><span>] </span><span>Medium </span><span>CVE-2026-13978: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513988889"><span>513988889</span></a><span>] </span><span>Medium </span><span>CVE-2026-13979: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513989973"><span>513989973</span></a><span>] </span><span>Medium </span><span>CVE-2026-13980: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513990408"><span>513990408</span></a><span>] </span><span>Medium </span><span>CVE-2026-13981: Inappropriate implementation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514006829"><span>514006829</span></a><span>]</span><span> Medium </span><span>CVE-2026-13982: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009910"><span>514009910</span></a><span>] </span><span>Medium </span><span>CVE-2026-13983: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514010404"><span>514010404</span></a><span>] </span><span>Medium </span><span>CVE-2026-13984: Incorrect security UI in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514013849"><span>514013849</span></a><span>] </span><span>Medium </span><span>CVE-2026-13985: Inappropriate implementation in MediaCapture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020959"><span>514020959</span></a><span>] </span><span>Medium </span><span>CVE-2026-13986: Inappropriate implementation in Media UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039122"><span>514039122</span></a><span>] </span><span>Medium </span><span>CVE-2026-13987: Incorrect security UI in Mobile. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514040614"><span>514040614</span></a><span>] </span><span>Medium </span><span>CVE-2026-13988: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514056221"><span>514056221</span></a><span>] </span><span>Medium </span><span>CVE-2026-13989: Insufficient policy enforcement in PageInfo. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058439"><span>514058439</span></a><span>] </span><span>Medium </span><span>CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514061117"><span>514061117</span></a><span>] </span><span>Medium </span><span>CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514063409"><span>514063409</span></a><span>] </span><span>Medium </span><span>CVE-2026-13992: Inappropriate implementation in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514064139"><span>514064139</span></a><span>] </span><span>Medium </span><span>CVE-2026-13993: Incorrect security UI in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067416"><span>514067416</span></a><span>] </span><span>Medium </span><span>CVE-2026-13994: Inappropriate implementation in Credential Management. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514067524"><span>514067524</span></a><span>] </span><span>Medium </span><span>CVE-2026-13995: Insufficient validation of untrusted input in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068972"><span>514068972</span></a><span>] </span><span>Medium </span><span>CVE-2026-13996: Incorrect security UI in Permissions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514069689"><span>514069689</span></a><span>] </span><span>Medium </span><span>CVE-2026-13997: Incorrect security UI in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070501"><span>514070501</span></a><span>] </span><span>Medium </span><span>CVE-2026-13998: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071697"><span>514071697</span></a><span>] </span><span>Medium </span><span>CVE-2026-13999: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514461552"><span>514461552</span></a><span>] </span><span>Medium </span><span>CVE-2026-14000: Inappropriate implementation in XML. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514481943"><span>514481943</span></a><span>] </span><span>Medium </span><span>CVE-2026-14001: Inappropriate implementation in Network. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514489361"><span>514489361</span></a><span>] </span><span>Medium </span><span>CVE-2026-14002: Inappropriate implementation in Geolocation. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514503077"><span>514503077</span></a><span>] </span><span>Medium </span><span>CVE-2026-14003: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514538751"><span>514538751</span></a><span>] </span><span>Medium </span><span>CVE-2026-14004: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514740273"><span>514740273</span></a><span>] </span><span>Medium </span><span>CVE-2026-14005: Use after free in Omnibox. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515423596"><span>515423596</span></a><span>] </span><span>Medium </span><span>CVE-2026-14006: Use after free in Navigation. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516425999"><span>516425999</span></a><span>] </span><span>Medium </span><span>CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy. </span><span>Reported by Google on 2026-05-25</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516781007"><span>516781007</span></a><span>] </span><span>Medium </span><span>CVE-2026-14008: Uninitialized Use in WebXR. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516819850"><span>516819850</span></a><span>] </span><span>Medium </span><span>CVE-2026-14009: Insufficient data validation in Passwords. </span><span>Reported by Google on 2026-05-26</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516924151"><span>516924151</span></a><span>] </span><span>Medium </span><span>CVE-2026-14010: Uninitialized Use in Codecs. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/516944556"><span>516944556</span></a><span>] </span><span>Medium </span><span>CVE-2026-14011: Out of bounds read in SurfaceCapture. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517110749"><span>517110749</span></a><span>] </span><span>Medium </span><span>CVE-2026-14012: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517114175"><span>517114175</span></a><span>] </span><span>Medium </span><span>CVE-2026-14013: Inappropriate implementation in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517155893"><span>517155893</span></a><span>] </span><span>Medium </span><span>CVE-2026-14014: Inappropriate implementation in Paint. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517207235"><span>517207235</span></a><span>] </span><span>Medium </span><span>CVE-2026-14015: Inappropriate implementation in WebRTC. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517234388"><span>517234388</span></a><span>] </span><span>Medium </span><span>CVE-2026-14016: Insufficient policy enforcement in SVG. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517241992"><span>517241992</span></a><span>] </span><span>Medium </span><span>CVE-2026-14017: Inappropriate implementation in Navigation. </span><span>Reported by Google on 2026-05-27</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517350251"><span>517350251</span></a><span>] </span><span>Medium </span><span>CVE-2026-14018: Use after free in Updater. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517455455"><span>517455455</span></a><span>] </span><span>Medium </span><span>CVE-2026-14019: Inappropriate implementation in Passwords. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517598518"><span>517598518</span></a><span>] </span><span>Medium </span><span>CVE-2026-14020: Insufficient validation of untrusted input in WebXR. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517731924"><span>517731924</span></a><span>] </span><span>Medium </span><span>CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517791835"><span>517791835</span></a><span>] </span><span>Medium </span><span>CVE-2026-14022: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518063436"><span>518063436</span></a><span>] </span><span>Medium </span><span>CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518245882"><span>518245882</span></a><span>] </span><span>Medium </span><span>CVE-2026-14024: Use after free in Ozone. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[$2000][</span><a href="https://issues.chromium.org/issues/506482786"><span>506482786</span></a><span>]</span><span> Low </span><span>CVE-2026-14025: Use after free in Views. </span><span>Reported by asjidkalam on 2026-04-26<br></span><span>[$1000][</span><a href="https://issues.chromium.org/issues/507263861"><span>507263861</span></a><span>]</span><span> Low </span><span>CVE-2026-14026: Incorrect security UI in SplitView. </span><span>Reported by adisahilna35@gmail.com on 2026-04-28<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/361375787"><span>361375787</span></a><span>]</span><span> Low </span><span>CVE-2026-14027: Use after free in SignIn. </span><span>Reported by Sven Dysthe (@svn-dys) on 2024-08-21<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/401816601"><span>401816601</span></a><span>]</span><span> Low </span><span>CVE-2026-14028: Incorrect security UI in Chrome for iOS. </span><span>Reported by Ameen Basha M K on 2025-03-09<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/488762971"><span>488762971</span></a><span>]</span><span> Low </span><span>CVE-2026-14030: Incorrect security UI in SplitView. </span><span>Reported by Khalil Zhani on 2026-03-01<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495459838"><span>495459838</span></a><span>]</span><span> Low </span><span>CVE-2026-14031: Incorrect security UI in File Input. </span><span>Reported by Google on 2026-03-23<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495783474"><span>495783474</span></a><span>]</span><span> Low </span><span>CVE-2026-14032: Use after free in Bluetooth. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/495848160"><span>495848160</span></a><span>]</span><span> Low </span><span>CVE-2026-14033: Insufficient policy enforcement in Media. </span><span>Reported by Google on 2026-03-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496368832"><span>496368832</span></a><span>]</span><span> Low </span><span>CVE-2026-14034: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496371586"><span>496371586</span></a><span>]</span><span> Low </span><span>CVE-2026-14035: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496411061"><span>496411061</span></a><span>]</span><span> Low </span><span>CVE-2026-14036: Insufficient policy enforcement in Bluetooth. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/496522611"><span>496522611</span></a><span>]</span><span> Low </span><span>CVE-2026-14037: Insufficient policy enforcement in GPU. </span><span>Reported by Google on 2026-03-26<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497241148"><span>497241148</span></a><span>]</span><span> Low </span><span>CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page. </span><span>Reported by Google on 2026-03-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497358012"><span>497358012</span></a><span>]</span><span> Low </span><span>CVE-2026-14039: Insufficient policy enforcement in GetUserMedia. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497488593"><span>497488593</span></a><span>]</span><span> Low </span><span>CVE-2026-14040: Use after free in BrowserTag. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497544822"><span>497544822</span></a><span>]</span><span> Low </span><span>CVE-2026-14041: Insufficient policy enforcement in Serial. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497558336"><span>497558336</span></a><span>]</span><span> Low </span><span>CVE-2026-14042: Inappropriate implementation in Isolated Web Apps. </span><span>Reported by Google on 2026-03-29<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497632232"><span>497632232</span></a><span>]</span><span> Low </span><span>CVE-2026-14043: Use after free in GetUserMedia. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497670996"><span>497670996</span></a><span>]</span><span> Low </span><span>CVE-2026-14044: Use after free in ANGLE. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497723649"><span>497723649</span></a><span>]</span><span> Low </span><span>CVE-2026-14045: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/497959724"><span>497959724</span></a><span>]</span><span> Low </span><span>CVE-2026-14046: Inappropriate implementation in CustomTabs. </span><span>Reported by Google on 2026-03-30<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/498864176"><span>498864176</span></a><span>]</span><span> Low </span><span>CVE-2026-14047: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-02<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/499189601"><span>499189601</span></a><span>]</span><span> Low </span><span>CVE-2026-14048: Use after free in Chromecast. </span><span>Reported by Google on 2026-04-03<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501659888"><span>501659888</span></a><span>]</span><span> Low </span><span>CVE-2026-14049: Inappropriate implementation in GPU. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501708647"><span>501708647</span></a><span>]</span><span> Low </span><span>CVE-2026-14050: Insufficient policy enforcement in Passwords. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501747804"><span>501747804</span></a><span>]</span><span> Low </span><span>CVE-2026-14051: Uninitialized Use in GamepadAPI. </span><span>Reported by Google on 2026-04-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501810874"><span>501810874</span></a><span>]</span><span> Low </span><span>CVE-2026-14052: Insufficient policy enforcement in FileSystem. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501836539"><span>501836539</span></a><span>]</span><span> Low </span><span>CVE-2026-14053: Insufficient policy enforcement in Extensions. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501851312"><span>501851312</span></a><span>]</span><span> Low </span><span>CVE-2026-14054: Insufficient policy enforcement in Network. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501857663"><span>501857663</span></a><span>]</span><span> Low </span><span>CVE-2026-14055: Insufficient validation of untrusted input in Device Trust. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/501888426"><span>501888426</span></a><span>]</span><span> Low </span><span>CVE-2026-14056: Insufficient validation of untrusted input in Media. </span><span>Reported by Google on 2026-04-12<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502212647"><span>502212647</span></a><span>]</span><span> Low </span><span>CVE-2026-14057: Insufficient policy enforcement in FedCM. </span><span>Reported by Google on 2026-04-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502354038"><span>502354038</span></a><span>]</span><span> Low </span><span>CVE-2026-14058: Policy bypass in Parser. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502363986"><span>502363986</span></a><span>]</span><span> Low </span><span>CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502372527"><span>502372527</span></a><span>]</span><span> Low </span><span>CVE-2026-14060: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502434484"><span>502434484</span></a><span>]</span><span> Low </span><span>CVE-2026-14061: Inappropriate implementation in Dawn. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502448128"><span>502448128</span></a><span>]</span><span> Low </span><span>CVE-2026-14062: Inappropriate implementation in Views. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502473563"><span>502473563</span></a><span>]</span><span> Low </span><span>CVE-2026-14063: Out of bounds memory access in Chromecast. </span><span>Reported by Google on 2026-04-14<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/502714977"><span>502714977</span></a><span>]</span><span> Low </span><span>CVE-2026-14064: Use after free in PageInfo. </span><span>Reported by Google on 2026-04-15<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503617508"><span>503617508</span></a><span>]</span><span> Low </span><span>CVE-2026-14065: Insufficient validation of untrusted input in PageInfo. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/503779807"><span>503779807</span></a><span>]</span><span> Low </span><span>CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-04-17<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504069465"><span>504069465</span></a><span>]</span><span> Low </span><span>CVE-2026-14067: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-04-18<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/504210171"><span>504210171</span></a><span>]</span><span> Low </span><span>CVE-2026-14068: Inappropriate implementation in Omnibox. </span><span>Reported by Google on 2026-04-19<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505136542"><span>505136542</span></a><span>]</span><span> Low </span><span>CVE-2026-14069: Integer overflow in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/505137978"><span>505137978</span></a><span>]</span><span> Low </span><span>CVE-2026-14070: Uninitialized Use in WebNN. </span><span>Reported by Google on 2026-04-21<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/506143724"><span>506143724</span></a><span>]</span><span> Low </span><span>CVE-2026-14071: Side-channel information leakage in WebAudio. </span><span>Reported by Google on 2026-04-24<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507099867"><span>507099867</span></a><span>]</span><span> Low </span><span>CVE-2026-14072: Incorrect security UI in SplitView. </span><span>Reported by FARISSAL B on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/507237563"><span>507237563</span></a><span>]</span><span> Low </span><span>CVE-2026-14073: Insufficient policy enforcement in WebXR. </span><span>Reported by Google on 2026-04-28<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511743480"><span>511743480</span></a><span>]</span><span> Low </span><span>CVE-2026-14074: Side-channel information leakage in WebAuthentication. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511808800"><span>511808800</span></a><span>]</span><span> Low </span><span>CVE-2026-14075: Policy bypass in Chrome for iOS. </span><span>Reported by Google on 2026-05-10<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/511815165"><span>511815165</span></a><span>]</span><span> Low </span><span>CVE-2026-14076: Policy bypass in Network. </span><span>Reported by Google on 2026-05-10<br></span><span>[TBD][</span><a href="https://issues.chromium.org/issues/511869411"><span>511869411</span></a><span>]</span><span> Low </span><span>CVE-2026-14077: Incorrect security UI in Select. </span><span>Reported by pwn.ai on 2026-05-11<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512953564"><span>512953564</span></a><span>]</span><span> Low </span><span>CVE-2026-14078: Policy bypass in WebRTC. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512971938"><span>512971938</span></a><span>]</span><span> Low </span><span>CVE-2026-14079: Policy bypass in Network. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/512997517"><span>512997517</span></a><span>]</span><span> Low </span><span>CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher. </span><span>Reported by Google on 2026-05-13<br></span><span>[N/A][</span><a href="https://issues.chromium.org/issues/513030698"><span>513030698</span></a><span>]</span><span> Low </span><span>CVE-2026-14081: Insufficient policy enforcement in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513049578"><span>513049578</span></a><span>] </span><span>Low </span><span>CVE-2026-14082: Race in Storage. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513128322"><span>513128322</span></a><span>] </span><span>Low </span><span>CVE-2026-14083: Insufficient validation of untrusted input in HTML. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513138148"><span>513138148</span></a><span>] </span><span>Low </span><span>CVE-2026-14084: Insufficient validation of untrusted input in Chromoting. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513155863"><span>513155863</span></a><span>] </span><span>Low </span><span>CVE-2026-14085: Side-channel information leakage in CSS. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513169718"><span>513169718</span></a><span>] </span><span>Low </span><span>CVE-2026-14086: Insufficient policy enforcement in HID. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513177237"><span>513177237</span></a><span>] </span><span>Low </span><span>CVE-2026-14087: Insufficient validation of untrusted input in WebNN. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513178869"><span>513178869</span></a><span>] </span><span>Low </span><span>CVE-2026-14088: Uninitialized Use in Canvas. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513188254"><span>513188254</span></a><span>] </span><span>Low </span><span>CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513194241"><span>513194241</span></a><span>] </span><span>Low </span><span>CVE-2026-14090: Out of bounds read in CameraCapture. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513208773"><span>513208773</span></a><span>] </span><span>Low </span><span>CVE-2026-14091: Use after free in DevTools. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513212892"><span>513212892</span></a><span>] </span><span>Low </span><span>CVE-2026-14092: Insufficient policy enforcement in Privacy. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513240099"><span>513240099</span></a><span>] </span><span>Low </span><span>CVE-2026-14093: Use after free in Cast. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513264273"><span>513264273</span></a><span>] </span><span>Low </span><span>CVE-2026-14094: Use after free in Installer. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513271007"><span>513271007</span></a><span>] </span><span>Low </span><span>CVE-2026-14095: Insufficient validation of untrusted input in Browser. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513310821"><span>513310821</span></a><span>] </span><span>Low </span><span>CVE-2026-14096: Object lifecycle issue in Input. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513333529"><span>513333529</span></a><span>] </span><span>Low </span><span>CVE-2026-14097: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-14</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513375767"><span>513375767</span></a><span>] </span><span>Low </span><span>CVE-2026-14098: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513382161"><span>513382161</span></a><span>] </span><span>Low </span><span>CVE-2026-14099: Use after free in Chrome for iOS. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513383891"><span>513383891</span></a><span>] </span><span>Low </span><span>CVE-2026-14100: Insufficient data validation in NetworkCache. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513454805"><span>513454805</span></a><span>] </span><span>Low </span><span>CVE-2026-14101: Insufficient policy enforcement in Sandbox. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513455047"><span>513455047</span></a><span>] </span><span>Low </span><span>CVE-2026-14102: Use after free in Passwords. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513465245"><span>513465245</span></a><span>] </span><span>Low </span><span>CVE-2026-14103: Use after free in SSL. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513484193"><span>513484193</span></a><span>] </span><span>Low </span><span>CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513528117"><span>513528117</span></a><span>] </span><span>Low </span><span>CVE-2026-14105: Insufficient policy enforcement in Speech. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513532778"><span>513532778</span></a><span>] </span><span>Low </span><span>CVE-2026-14106: Insufficient validation of untrusted input in Text. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513544566"><span>513544566</span></a><span>] </span><span>Low </span><span>CVE-2026-14107: Use after free in Scheduling. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513689974"><span>513689974</span></a><span>] </span><span>Low </span><span>CVE-2026-14108: Use after free in PDFium. </span><span>Reported by Google on 2026-05-15</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513694957"><span>513694957</span></a><span>] </span><span>Low </span><span>CVE-2026-14109: Insufficient policy enforcement in Mojo. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513698452"><span>513698452</span></a><span>] </span><span>Low </span><span>CVE-2026-14110: Inappropriate implementation in DarkMode. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513710926"><span>513710926</span></a><span>] </span><span>Low </span><span>CVE-2026-14111: Use after free in WebProtect. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513713946"><span>513713946</span></a><span>] </span><span>Low </span><span>CVE-2026-14112: Inappropriate implementation in Enterprise. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513737335"><span>513737335</span></a><span>] </span><span>Low </span><span>CVE-2026-14113: Use after free in Updater. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513743129"><span>513743129</span></a><span>] </span><span>Low </span><span>CVE-2026-14114: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513745699"><span>513745699</span></a><span>] </span><span>Low </span><span>CVE-2026-14115: Insufficient validation of untrusted input in Cast. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513747800"><span>513747800</span></a><span>] </span><span>Low </span><span>CVE-2026-14116: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513751020"><span>513751020</span></a><span>] </span><span>Low </span><span>CVE-2026-14117: Insufficient validation of untrusted input in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513772764"><span>513772764</span></a><span>] </span><span>Low </span><span>CVE-2026-14118: Insufficient data validation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513775483"><span>513775483</span></a><span>] </span><span>Low </span><span>CVE-2026-14119: Type Confusion in Bluetooth. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513777411"><span>513777411</span></a><span>] </span><span>Low </span><span>CVE-2026-14120: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513789382"><span>513789382</span></a><span>] </span><span>Low </span><span>CVE-2026-14121: Use after free in Chromoting. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513824891"><span>513824891</span></a><span>] </span><span>Low </span><span>CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513856644"><span>513856644</span></a><span>] </span><span>Low </span><span>CVE-2026-14123: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513867710"><span>513867710</span></a><span>] </span><span>Low </span><span>CVE-2026-14124: Inappropriate implementation in CredentialProvider. </span><span>Reported by Google on 2026-05-16</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513918431"><span>513918431</span></a><span>] </span><span>Low </span><span>CVE-2026-14125: Uninitialized Use in ANGLE. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/513992796"><span>513992796</span></a><span>] </span><span>Low </span><span>CVE-2026-14126: Incorrect security UI in UI. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514009654"><span>514009654</span></a><span>] </span><span>Low </span><span>CVE-2026-14127: Inappropriate implementation in Printing. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514015836"><span>514015836</span></a><span>] </span><span>Low </span><span>CVE-2026-14128: Insufficient data validation in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514018024"><span>514018024</span></a><span>] </span><span>Low </span><span>CVE-2026-14129: Incorrect security UI in PreviewTab. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514019522"><span>514019522</span></a><span>] </span><span>Low </span><span>CVE-2026-14130: Incorrect security UI in Omnibox. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514020982"><span>514020982</span></a><span>] </span><span>Low </span><span>CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039492"><span>514039492</span></a><span>] </span><span>Low </span><span>CVE-2026-14132: Inappropriate implementation in WebXR. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514039947"><span>514039947</span></a><span>] </span><span>Low </span><span>CVE-2026-14133: Race in History Embeddings. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514055973"><span>514055973</span></a><span>] </span><span>Low </span><span>CVE-2026-14134: Inappropriate implementation in Autofill. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514058566"><span>514058566</span></a><span>] </span><span>Low </span><span>CVE-2026-14135: Insufficient validation of untrusted input in Network. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514068611"><span>514068611</span></a><span>] </span><span>Low </span><span>CVE-2026-14136: Incorrect security UI in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514070067"><span>514070067</span></a><span>] </span><span>Low </span><span>CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514071775"><span>514071775</span></a><span>] </span><span>Low </span><span>CVE-2026-14138: Inappropriate implementation in WebAppInstalls. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072495"><span>514072495</span></a><span>] </span><span>Low </span><span>CVE-2026-14139: Inappropriate implementation in TabStrip. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072607"><span>514072607</span></a><span>] </span><span>Low </span><span>CVE-2026-14140: Insufficient validation of untrusted input in Input. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514072867"><span>514072867</span></a><span>] </span><span>Low </span><span>CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514073460"><span>514073460</span></a><span>] </span><span>Low </span><span>CVE-2026-14142: Inappropriate implementation in Extensions. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514075028"><span>514075028</span></a><span>] </span><span>Low </span><span>CVE-2026-14143: Incorrect security UI in Passwords. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514079793"><span>514079793</span></a><span>] </span><span>Low </span><span>CVE-2026-14144: Incorrect security UI in Views. </span><span>Reported by Google on 2026-05-17</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514485825"><span>514485825</span></a><span>] </span><span>Low </span><span>CVE-2026-14145: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514550047"><span>514550047</span></a><span>] </span><span>Low </span><span>CVE-2026-14146: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/514632767"><span>514632767</span></a><span>] </span><span>Low </span><span>CVE-2026-14147: Inappropriate implementation in CSS. </span><span>Reported by Google on 2026-05-19</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515426873"><span>515426873</span></a><span>] </span><span>Low </span><span>CVE-2026-14148: Type Confusion in CSS. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/515427046"><span>515427046</span></a><span>] </span><span>Low </span><span>CVE-2026-14149: Use after free in Audio. </span><span>Reported by Google on 2026-05-21</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517376041"><span>517376041</span></a><span>] </span><span>Low </span><span>CVE-2026-14150: Insufficient validation of untrusted input in Speech. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517381770"><span>517381770</span></a><span>] </span><span>Low </span><span>CVE-2026-14151: Inappropriate implementation in AI. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517534944"><span>517534944</span></a><span>] </span><span>Low </span><span>CVE-2026-14152: Out of bounds write in ANGLE. </span><span>Reported by Google on 2026-05-28</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517684077"><span>517684077</span></a><span>] </span><span>Low </span><span>CVE-2026-14153: Inappropriate implementation in Glic. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/517741170"><span>517741170</span></a><span>] </span><span>Low </span><span>CVE-2026-14154: Inappropriate implementation in DevTools. </span><span>Reported by Google on 2026-05-29</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518246925"><span>518246925</span></a><span>] </span><span>Low </span><span>CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span>[N/A][</span><a href="https://issues.chromium.org/issues/518247789"><span>518247789</span></a><span>] </span><span>Low </span><span>CVE-2026-14156: Policy bypass in StorageAccessAPI. </span><span>Reported by Google on 2026-05-30</span></div><div><span><br></span></div><div><span>We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.</span></div><p><span><br></span></p><p><span>Many of our security bugs are detected using </span><a href="https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer"><span>AddressSanitizer</span></a><span>, </span><a href="https://code.google.com/p/memory-sanitizer/wiki/MemorySanitizer"><span>MemorySanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/undefinedbehaviorsanitizer"><span>UndefinedBehaviorSanitizer</span></a><span>, </span><a href="https://www.chromium.org/developers/testing/control-flow-integrity/"><span>Control Flow Integrity</span></a><span>, </span><a href="https://chromium.googlesource.com/chromium/src/+/HEAD/testing/libfuzzer/README.md"><span>libFuzzer</span></a><span>, or </span><a href="https://github.com/google/afl"><span>AFL</span></a><span>.</span></p><p><span face="Roboto, sans-serif"><span color="rgba(0, 0, 0, 0.87)"><span color="rgba(0, 0, 0, 0.87)"><span><br></span></span></span></span></p><p><span><span>Interested in switching release channels? Find out how<span> </span></span><a href="https://www.chromium.org/getting-involved/dev-channel">here</a><span>. If you find a new issue, please let us know by<span> </span></span><a href="https://crbug.com/">filing a bug</a><span>. The<span> </span></span><a href="https://support.google.com/chrome/community">community help forum</a><span> is also a great place to reach out for help or learn about common issues.</span></span></p><p><span><br></span></p><p><span>Daniel Yip</span></p><p><span color="rgba(0, 0, 0, 0.87)"></span></p><p><span>Google Chrome</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei-Faktor-Authentifizierung: Alles, was Sie wissen müssen]]></title>
<description><![CDATA[Onlinezugänge ausschließlich mit Passwörtern zu schützen, ist nicht mehr zeitgemäß. Die Zwei-Faktor-Authentifizierung (2FA) sichert Ihre wichtigsten Konten mit einer zweiten, unabhängigen Hürde ab. Sie ist in wenigen Minuten eingerichtet, in den meisten Fällen kostenlos und bringt einen enormen S...]]></description>
<link>https://tsecurity.de/de/3633061/windows-tipps/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633061/windows-tipps/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen/</guid>
<pubDate>Mon, 29 Jun 2026 15:38:06 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Onlinezugänge ausschließlich mit Passwörtern zu schützen, ist nicht mehr zeitgemäß. Die Zwei-Faktor-Authentifizierung (2FA) sichert Ihre wichtigsten Konten mit einer zweiten, unabhängigen Hürde ab. Sie ist in wenigen Minuten eingerichtet, in den meisten Fällen kostenlos und bringt einen enormen Sicherheitsgewinn. Wie das konkret funktioniert und wo Sie anfangen sollten, erfahren Sie hier.</p>



<h2 class="wp-block-heading toc">1. Warum reicht ein Passwort nicht mehr?</h2>



<p>Laut dem <a href="https://sec.hpi.de/ilc/?lang=de" data-type="link" data-id="https://sec.hpi.de/ilc/?lang=de" target="_blank" rel="noreferrer noopener">HPI Identity Leak Checker des Hasso-Plattner-Instituts</a> sind inzwischen mehr als 14,5 Milliarden Zugangsdaten durch Datenlecks öffentlich im Netz zugänglich – täglich kommen rund 1,5 Millionen neue hinzu. </p>



<p>Die Gefahr ist alles andere als abstrakt: Schon eine einzige Sicherheitslücke bei einem Onlinedienst kann Ihr Kennwort ins Darknet befördern. Kriminelle testen solche gestohlenen Zugangsdaten dann automatisiert bei Amazon, PayPal, Mailanbietern und weiteren Diensten.</p>



<p>Das eigentlich kritische Szenario ist, wenn Sie dasselbe Passwort auch für Ihre E-Mail-Adresse nutzen, denn damit verlieren Sie einen Generalschlüssel. Über die “Passwort vergessen”-Funktion können Angreifer von dort aus weitere Konten übernehmen. Weil dabei Geldforderungen, Einkäufe auf Ihre Kosten und Ähnliches schnell folgen, ist ein zweiter Schutzfaktor keine Kür, sondern Pflicht.</p>



<p>Sichere und einmalige Passwörter für jeden Dienst erstellen und verwalten Sie am einfachsten <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">mit einem Passwortmanager</a>. Die 2FA kommt dann obendrauf: Selbst wer Ihr Passwort kennt, kommt ohne den zweiten Faktor nicht rein.</p>



<h2 class="wp-block-heading toc">2. Wie funktioniert 2FA?</h2>



<p>Das Prinzip ist relativ simpel: Zum Log-in brauchen Sie zwei voneinander unabhängige Dinge:</p>



<ol class="wp-block-list">
<li><strong>Etwas, das Sie wissen</strong>, also Ihr Passwort.</li>



<li><strong>Etwas, das Sie besitzen</strong>, zum Beispiel Ihr Smartphone, eine App oder ein Hardware-Token.</li>
</ol>



<p>Beim Onlinebanking ist dieses Konzept bereits Standard und gesetzlich vorgeschrieben: Selbst wenn jemand Ihre PIN kennt, kommt er ohne einen zweiten Bestätigungsschritt nicht ans Geld. Dasselbe Prinzip lässt sich auf nahezu jedes Onlinekonto anwenden – E-Mail, Onlineshops, soziale Netzwerke und Passwortmanager.</p>



<p>In der Praxis sieht das so aus: Sie melden sich wie gewohnt mit Benutzername und Passwort an. Dann fragt der Dienst nach einem zweiten Code per SMS, per App oder per Hardware-Schlüssel. Erst danach öffnet sich der Zugang.</p>



<p>Damit es halbwegs komfortabel bleibt, werden einmal eingeloggte Geräte in der Regel als “vertrauenswürdig” markiert. Zu Hause am eigenen PC müssen Sie also nicht jedes Mal den zweiten Faktor eingeben, nur auf fremden oder neuen Geräten.</p>



<h2 class="wp-block-heading toc">3. Welche 2FA-Methoden gibt es und wie sicher sind sie?</h2>



<p>Nicht alle 2FA-Verfahren sind gleich stark. Aufgelistet von schwach bis stark:</p>



<h3 class="wp-block-heading">Per SMS oder E-Mail (schwach)</h3>



<p>Der Dienst schickt einen Einmalcode ans Handy oder per Mail. Schnell eingerichtet, aber anfällig: Schadsoftware auf dem Smartphone kann SMS-Codes auslesen. <a href="https://www.pcwelt.de/article/2430399/betrug-mit-neuer-sim-karte-wie-gefaehrlich-ist-sim-swapping-wirklich.html" data-type="link" data-id="https://www.pcwelt.de/article/2430399/betrug-mit-neuer-sim-karte-wie-gefaehrlich-ist-sim-swapping-wirklich.html" target="_blank" rel="noreferrer noopener">Noch gefährlicher ist SIM-Swapping</a>. Kriminelle bringen dabei Mobilfunkanbieter durch Social Engineering dazu, Ihre Handynummer auf eine neue SIM umzubuchen, und erhalten damit alle künftigen SMS-Codes direkt. </p>



<p>Als E-Mail-Code ist die Methode ebenfalls schwach, da ein kompromittiertes Mailkonto den Schutz sofort aushebelt. Besser als kein zweiter Faktor, aber nur als letzte Option wählen.</p>



<h3 class="wp-block-heading">Per Authenticator-App / TOTP (gut)</h3>



<p>Eine App auf dem Smartphone erzeugt alle 30 Sekunden einen neuen sechsstelligen Code. Dieser Code ist zeitgebunden und kann nur auf dem jeweiligen Gerät generiert werden. Das Verfahren heißt TOTP (Time-based One-time Password) und ist der heute verbreitetste 2FA-Standard.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4275293c87c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/04/google-authenticator-new-version-ios.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Authenticator on iOS" class="wp-image-1800176" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Google Authenticator ist eine der bekanntesten kostenlosen TOTP-Apps.</p></figcaption></figure><p class="imageCredit">PCWorld</p></div>



<p>Bewährte Apps dafür sind der <a href="https://support.google.com/accounts/answer/1066447" target="_blank" rel="noreferrer noopener">Google Authenticator</a> und <a href="https://www.microsoft.com/de-de/security/mobile-authenticator-app" target="_blank" rel="noreferrer noopener">Microsoft Authenticator</a>. Empfehlenswertere Alternativen mit verschlüsseltem Backup – damit kein Neustart bei Smartphone-Wechsel nötig ist – sind <a href="https://getaegis.app/" target="_blank" rel="noreferrer noopener">Aegis Authenticator</a> (Android, Open Source), <a href="https://2fas.com/" target="_blank" rel="noreferrer noopener">2FAS</a> (Android und iOS, Open Source) sowie <a href="https://ente.io/auth/" target="_blank" rel="noreferrer noopener">Ente Auth</a> (plattformübergreifend).</p>



<p>Wer <a href="https://bitwarden.com/de-de/" data-type="link" data-id="https://bitwarden.com/de-de/" target="_blank" rel="noreferrer noopener">Bitwarden</a>, <a href="https://www.kqzyfj.com/click-3275038-14510609?sid=rss&amp;url=https://1password.com/de" target="_blank" rel="noreferrer noopener">1Password</a> oder <a href="https://go.getproton.me/aff_c?offer_id=42&amp;aff_id=16944&amp;url_id=1499" target="_blank" rel="noreferrer noopener">Proton Pass</a> nutzt, kann TOTP-Codes auch direkt im Passwortmanager verwalten.</p>



<p><strong>Wichtig zu wissen:</strong> TOTP-Codes sind zwar besser als SMS, aber nicht phishingsicher. Eine gefälschte Log-in-Seite kann Passwort und TOTP-Code in Echtzeit abfangen und sofort beim echten Dienst verwenden (Adversary-in-the-Middle-Angriff). Für die meisten Nutzer ist das Risiko gering, aber es existiert.</p>



<p><strong>Vorsicht gilt auch bei Push-Benachrichtigungen:</strong> Manche Dienste senden statt eines Codes eine Push-Anfrage ans Smartphone (“Waren das Sie?”). Angreifer nutzen inzwischen sogenanntes MFA-Fatigue: Sie bombardieren das Opfer mit Dutzenden solcher Anfragen, bis eine aus Versehen oder aus Frustration genehmigt wird. Neuere Apps begegnen dem mit Nummernabgleich, das heißt, Sie müssen eine im Browser angezeigte Zahl in der App bestätigen.</p>



<h3 class="wp-block-heading">Per Hardware-Token / FIDO2-Stick (sehr gut)</h3>



<p>Ein kleines Gerät, das per USB, NFC oder Bluetooth mit dem Computer oder Smartphone verbunden wird. Beim Log-in tippen Sie nicht nur einen Code ein, sondern drücken kurz eine Taste am Stick. Der integrierte Krypto-Chip übernimmt die Authentifizierung. FIDO2 ist der aktuelle Standard; ältere U2F-Sticks sind veraltet und sollten nicht mehr neu gekauft werden. Das bekannteste Modell ist der YubiKey und schon ab rund 35 Euro auf Amazon erhältlich.</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn shopping-cart-icon-white link-6-button" href="https://www.amazon.de/Yubico-Sicherheitsschl%C3%BCssel-Zwei-Faktor-Authentifizierung-Anschluss-FIDO-zertifiziert/dp/B0BVNRXFHT/?tag=pcwelt.de-21&amp;ascsubtag=4-0-1206889-7-0-0-0-0&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="nofollow" data-vars-link-position="CTA Button" data-domain-name="amazon" data-subtag="4-0-1206889-7-0-0-0-0">Jetzt YubiKey auf Amazon kaufen</a></div>


<p>FIDO2-Sticks sind phishingsicher, weil die Authentifizierung an die echte Domain des Dienstes gebunden ist. Eine Phishing-Seite bekommt keinen nutzbaren Schlüssel, wenngleich Sie dort Ihre Zugangsdaten eingeben.</p>



<h2 class="wp-block-heading toc">4. Passkeys: Noch sicherer – und ohne Passwort</h2>



<p>Neben klassischer 2FA hat sich seit 2023 ein neues Verfahren in der Praxis etabliert, das Passwort und zweiten Faktor in einem einzigen Schritt ersetzt: <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" data-type="link" data-id="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Ein Passkey ist ein kryptografisches Schlüsselpaar, das auf Ihrem Gerät gespeichert wird. Beim Einloggen bestätigen Sie sich mit Biometrie (Fingerabdruck, Gesicht) oder Geräte-PIN. Der entscheidende Vorteil: Passkeys sind strukturell phishingsicher. Da die Authentifizierung kryptografisch an die echte Website gebunden ist, kann eine gefälschte Log-in-Seite keinen nutzbaren Schlüssel abgreifen.</p>



<p>Passkeys werden inzwischen von Apple, Google und Microsoft nativ unterstützt. Große Dienste wie Amazon, Paypal, GitHub, Dropbox und viele weitere bieten sie bereits an. Moderne Passwortmanager wie Bitwarden, 1Password und Proton Pass können Passkeys speichern und geräteübergreifend synchronisieren.</p>



<p><strong>Kurzum: Wo Passkeys verfügbar sind, sind sie die beste Wahl. Sie sind sicherer als TOTP und bequemer als Hardware-Token. <a href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2024/241001_Nutzung_Passkeys.html" data-type="link" data-id="https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2024/241001_Nutzung_Passkeys.html" target="_blank" rel="noreferrer noopener">Das BSI empfiehlt Passkeys ausdrücklich.</a></strong></p>



<h2 class="wp-block-heading toc">5. Welche Konten benötigen 2FA?</h2>



<p>Nicht jedes Konto muss doppelt abgesichert sein. Der Zugang zum Hobbyforum ist ärgerlich, wenn er geknackt wird, aber der Schaden ist zugegebenermaßen gering. Konzentrieren Sie sich auf die Konten, bei denen ein Einbruch wirklich wehtut:</p>



<ul class="wp-block-list">
<li>Ihre E-Mail-Adresse (Generalschlüssel für Passwort-Resets)</li>



<li>Ihr Passwortmanager</li>



<li>Bezahldienste wie Paypal</li>



<li>Onlineshops mit hinterlegter Zahlungsmethode (Amazon, Otto etc.)</li>



<li>Soziale Netzwerke mit hoher Reichweite</li>
</ul>



<p>Fünf bis zehn Konten reichen für die meisten Nutzer. Welche Dienste 2FA unterstützen und welche Methoden sie jeweils anbieten, zeigt das <a href="https://2fa.directory/de/" target="_blank" rel="noreferrer noopener">2FA Directory</a>.</p>



<h2 class="wp-block-heading">6. Wie richte ich 2FA ein?</h2>



<p>Das Vorgehen ist bei fast allen Diensten gleich: In den Kontoeinstellungen unter “Sicherheit” oder “Datenschutz” finden Sie die 2FA-Option. Falls nicht, hilft eine Google-Suche nach “Zwei-Faktor-Authentifizierung” plus dem Dienstnamen.</p>



<p><strong>Beispiel Amazon:</strong> Melden Sie sich an und gehen Sie zu “Mein Konto → Anmelden und Sicherheit → Einstellungen für die Zwei-Schritt-Verifizierung (2SV): Bearbeiten”. Amazon verschickt zunächst eine Bestätigungsmail. Danach wählen Sie Ihre bevorzugte Methode und folgen den weiteren Anweisungen.</p>



<p><strong>Unsere</strong> <strong>Empfehlung:</strong> Richten Sie, wo möglich, gleich zwei verschiedene Methoden ein (zum Beispiel Authenticator-App und Backup-Code). Das schützt vor dem Aussperren, falls ein Gerät verloren geht.</p>



<h2 class="wp-block-heading toc">7. Was tun, wenn der zweite Faktor verloren geht?</h2>



<p>Das ist das häufigste Bedenken, aber es gibt eine einfache Lösung: <strong>Backup-Codes.</strong> Die meisten Dienste erlauben beim Einrichten von 2FA, einmalige Wiederherstellungscodes zu erzeugen. Diese sollten Sie:</p>



<ol class="wp-block-list">
<li>sofort abrufen,</li>



<li>ausdrucken oder sicher notieren,</li>



<li>an einem sicheren Ort aufbewahren (und im Passwortmanager speichern).</li>
</ol>



<p>Mit diesen Codes kommen Sie auch dann rein, wenn Smartphone, Token oder App nicht mehr verfügbar sind. Und was, wenn kein Backup-Code eingerichtet ist? Dann bleibt in der Regel nur der Weg über den Kundensupport des jeweiligen Dienstes, was mühsam und nicht immer erfolgreich ist.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der Passkey-Zwiespalt: Warum das passwortlose Unternehmen stockt]]></title>
<description><![CDATA[FIDO2 und Passkeys versprechen Schutz vor Phishing. Doch in Enterprise-Infrastrukturen stoßen IT-Leiter auf komplexe Recovery- und Legacy-Probleme.

Tags: #Cyber Security | #Passkeys]]></description>
<link>https://tsecurity.de/de/3631987/it-security-nachrichten/der-passkey-zwiespalt-warum-das-passwortlose-unternehmen-stockt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631987/it-security-nachrichten/der-passkey-zwiespalt-warum-das-passwortlose-unternehmen-stockt/</guid>
<pubDate>Mon, 29 Jun 2026 07:23:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920.jpg" class="attachment-full size-full wp-post-image" alt="Authentifizierung, fido authentifizierung, sicherheitslücke fido, schwachstelle fido, FIDO, Passkey" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/08/Passkey-FIDO_Shutterstock_2228409043_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Der Passkey-Zwiespalt: Warum das passwortlose Unternehmen stockt 1"></p>
    FIDO2 und Passkeys versprechen Schutz vor Phishing. Doch in Enterprise-Infrastrukturen stoßen IT-Leiter auf komplexe Recovery- und Legacy-Probleme.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/passkeys">#Passkeys</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr]]></title>
<description><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></description>
<link>https://tsecurity.de/de/3630742/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630742/it-nachrichten/heise-angebot-ix-workshop-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</guid>
<pubDate>Sun, 28 Jun 2026 10:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></content:encoded>
</item>
<item>
<title><![CDATA[PC-WELT Sonderheft 6/2026: Windows 11 unauthorisiert – jetzt am Kiosk]]></title>
<description><![CDATA[Nach gut elf Jahren ist Schluss, ab Herbst wird es für Windows 10 keine Sicherheitsupdates mehr geben. Geht es nach Microsoft, steigen Anwender einfach auf Windows 11 um. Doch was tun, wenn das an den unnötig hohen Hardware-Hürden zu scheitern droht? Wir haben die passenden Anleitungen, wie Sie S...]]></description>
<link>https://tsecurity.de/de/3626761/it-nachrichten/pc-welt-sonderheft-62026-windows-11-unauthorisiert-jetzt-am-kiosk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626761/it-nachrichten/pc-welt-sonderheft-62026-windows-11-unauthorisiert-jetzt-am-kiosk/</guid>
<pubDate>Fri, 26 Jun 2026 10:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nach gut elf Jahren ist Schluss, ab Herbst wird es für Windows 10 keine Sicherheitsupdates mehr geben. Geht es nach Microsoft, steigen Anwender einfach auf Windows 11 um. Doch was tun, wenn das an den unnötig hohen Hardware-Hürden zu scheitern droht? Wir haben die passenden Anleitungen, wie Sie Setup-Sperren umgehen.</p>



<p>Der Zeitpunkt für den Kauf eines neuen Rechners ist denkbar schlecht. Die Preise für RAM und SSDs sind in den vergangenen Monaten geradezu explodiert. Deutlich günstiger als neue Geräte sind gebrauchte Notebooks und PCs mit vorinstalliertem Windows 11 und Gewährleistung vom Händler. Wir haben Tipps und Adressen zum Refurbished-Kauf recherchiert.</p>



<p>Holen Sie mehr aus Ihrem aktuellen Windows 11, egal ob als Einsteiger oder als erfahrener Anwender! Microsoft entwickelt sein Betriebssystem ständig fort, Stillstand gab es bei Windows noch nie – und das nun schon seit über 40 Jahren. Mit diesem Sonderheft bleiben Sie und Ihr System auf dem neuesten Stand.</p>



<p>Das und vieles mehr lesen Sie im neuen PC-WELT Sonderheft 6/2026: Windows 11. Jetzt am Kiosk oder bequem im PC-WELT-Shop bestellen!</p>



<h2 class="wp-block-heading">Das sind die Themen in der neuen PC-WELT Sonderheft 6/2026: Windows 11 unauthorisiert</h2>



<h2 class="wp-block-heading">Funktionen freischalten</h2>



<ul class="wp-block-list">
<li><strong>Windows bleibt sich treu und unvollendet.</strong> Auch nach 40 Jahren entwickelt Microsoft stetig weiter: Alle Neuerungen und ein Ausblick.</li>



<li><strong>Recall: Tipps &amp; Tricks zur neuen KI-Suche.</strong> Die KI-Suche nach PC-Inhalten hält nicht ganz, was Microsoft verspricht: PC-Welt hilft weiter.</li>



<li><strong>Zehn versteckte Tricks für Windows 11.</strong> Eine offizielle Windows-Anleitung fehlt. Unser Ratgeber verrät, wonach man sonst suchen müsste.</li>



<li><strong>Wie gut hilft KI bei PC-Problemen?</strong> Bei IT-Problemen ist KI häufig schneller als die Google-Suche: eine Anleitung mit Beispielen.</li>
</ul>



<h2 class="wp-block-heading">System ausreizen</h2>



<ul class="wp-block-list">
<li><strong>Secure-Boot-Probleme lösen.</strong> Die alten Sicherheitszertifikate laufen aus. Was jetzt zu tun ist.</li>



<li><strong>Windows-Funktionen radikal erweitern.</strong> Rüsten Sie nach, was Microsoft weglässt. Unsere Tools integrieren geniale Funktionen ins System.</li>



<li><strong>Windows optimal einstellen.</strong> Schneller und effizienter am PC: Viele Aufgaben lassen sich ganz oder teilweise automatisieren.</li>



<li><strong>Windows 11 Power-Check.</strong> So identifizieren Sie die Prozesse, die Ihren Computer ausbremsen.</li>



<li>…</li>
</ul>



<h2 class="wp-block-heading">PC abschotten</h2>



<ul class="wp-block-list">
<li><strong>Sieben Zeichen für einen Hacker-Angriff.</strong> Deuten Sie die Warnsignale für Schadcode im PC richtig, bevor er Schaden anrichten kann.</li>



<li><strong>Browser-Sicherheit selbst testen.</strong> Sicher wird Ihr Browser erst, wenn Sie den Schutz erhöhen und alle Schwachstellen prüfen.</li>



<li><strong>Passkeys: Endlich sicher einloggen.</strong> Passwörter sind per se unsicher, da hilft auch kein Passworttool. Anders sieht das bei Passkeys aus.</li>



<li><strong>Hacker-Angriffe mit KI erkennen.</strong> Künstliche Intelligenz macht PC-Angriffe zwar einfacher, hilft aber auch beim Schutz von Windows.</li>
</ul>



<h2 class="wp-block-heading">Support-Aus für Windows 10</h2>



<ul class="wp-block-list">
<li><strong>Windows 10: Was tun zum Support-Ende?</strong> Offiziell ist im Herbst endgültig Schluss. Mit Spezialupdates läuft Windows 10 danach sicher weiter.</li>



<li><strong>Windows-Upgrade: Jede Blockade lösen.</strong> Die Systemvoraussetzungen von Windows 11 sind hoch, doch die Sperre lässt sich aushebeln.</li>



<li><strong>Festplatte klonen und PC umziehen.</strong> Kloning-Tools zum Systemumzug auf größere SSDs eignen sich auch für ganz neue PCs.</li>



<li><strong>Notebooks und PCs gebraucht günstiger.</strong> Hohe Speicherpreise verteuern neue Computer. Deutlich günstiger ist Refurbished-Hardware.</li>



<li>…</li>
</ul>



<h2 class="wp-block-heading">Die Highlights der DVD</h2>



<ul class="wp-block-list">
<li><strong>Download-DVD. </strong>Acht Vollversionen im Wert von 228 Euro, über 120 Tools – Die DVD zu dieser Ausgabe enthält insgesamt über 120 Programme, Vollversionen und weitere Tools, die komplette Liste finden Sie auf Seite 7. Ab Seite 8 stellen wir Ihnen die acht Vollversionen vor, inklusive aller Infos zur Registrierung. Die Erläuterungen zur Anwendung der Software haben wir wie gewohnt direkt in die Ratgeberartikel integriert.</li>
</ul>



<p>Das <strong>PC-WELT Sonderheft</strong> <strong>6/2026: Windows 11</strong> ist für 9,90 Euro am Kiosk erhältlich. Sie können das Heft auch <a href="https://shop.pcwelt.de/pcwelt/pcwelt-magazin-sonderhefte-sonderausgaben" target="_blank" rel="noreferrer noopener">bestellen</a> und sich nach Hause liefern lassen oder als ePaper herunterladen.</p>



<p>Es gibt die PC-WELT auch in <a href="https://shop.pcwelt.de/pcwelt/pcwelt-magazin-plus-digital" target="_blank" rel="noreferrer noopener">digitaler Form</a> für Ihr Android-Gerät, iPad, iPhone, Windows Phone oder Windows 8.</p>



<p><strong>Tipp:</strong> Mit dem praktischen <a href="https://shop.pcwelt.de/pcwelt/abo/pcwelt-sonderheft-service/pc-welt-sonderheft-service" target="_blank" rel="noreferrer noopener">PC-WELT Sonderheft-Service</a> verpassen Sie keine Ausgabe und erhalten diese zudem zum Vorzugspreis.</p>



<p>Statt einzelner Hefte bieten wir auch eine sehr günstige und einfache Flatrate an. Dabei bezahlen Sie nicht mehr pro Heft oder für ein Abo, sondern für einen Zeitabschnitt. Für einen Monat zahlen Sie beispielsweise 6,99 Euro. Als Inhaber der Flatrate haben Sie Zugriff auf <strong>alle Ausgaben der PC-WELT</strong>, ebenso auf <strong>alle Sonderhefte</strong> und auf alle Publikationen unserer Schwester-Zeitschriften <strong>AndroidWelt</strong> und <strong>LinuxWelt</strong>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enpass 6.12.3 veröffentlicht: Verbesserungen für Passkeys und Autofill]]></title>
<description><![CDATA[Für den Passwortmanager Enpass steht ab sofort Version 6.12.3 für Windows, macOS und Linux bereit. Das Update erweitert die Unterstützung für Passkeys und verbessert das Zusammenspiel zwischen Desktop-Anwendung und Browser-Erweiterung, so die Entwickler. Neu ist unter anderem, dass die Desktop-Ap...]]></description>
<link>https://tsecurity.de/de/3623685/it-nachrichten/enpass-6123-veroeffentlicht-verbesserungen-fuer-passkeys-und-autofill/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623685/it-nachrichten/enpass-6123-veroeffentlicht-verbesserungen-fuer-passkeys-und-autofill/</guid>
<pubDate>Thu, 25 Jun 2026 09:32:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Für den Passwortmanager Enpass steht ab sofort Version 6.12.3 für Windows, macOS und Linux bereit. Das Update erweitert die Unterstützung für Passkeys und verbessert das Zusammenspiel zwischen Desktop-Anwendung und Browser-Erweiterung, so die Entwickler. Neu ist unter anderem, dass die Desktop-App...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/enpass-6-12-3-veroeffentlicht-verbesserungen-fuer-passkeys-und-autofill/">Enpass 6.12.3 veröffentlicht: Verbesserungen für Passkeys und Autofill</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Eine neue Ära der Cybersicherheit: Liste der Unternehmen, die Passkeys nicht implementiert haben]]></title>
<description><![CDATA[Die Passkeys-Technologie, die als die zuverlässigste Methode zum Schutz von Konten vor Hackerangriffen in der digitalen Welt gilt,…]]></description>
<link>https://tsecurity.de/de/3623018/it-security-nachrichten/eine-neue-aera-der-cybersicherheit-liste-der-unternehmen-die-passkeys-nicht-implementiert-haben/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623018/it-security-nachrichten/eine-neue-aera-der-cybersicherheit-liste-der-unternehmen-die-passkeys-nicht-implementiert-haben/</guid>
<pubDate>Thu, 25 Jun 2026 01:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Passkeys-Technologie, die als die zuverlässigste Methode zum Schutz von Konten vor Hackerangriffen in der digitalen Welt gilt,…]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-06-24]]></title>
<description><![CDATA[171 posts were published in the last hour 21:31 : New website names and shames companies that still don’t offer passkeys to users 21:7 : Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks 21:7 : Malicious Edge Extension Uses…
Read more →
The post IT Security News Daily Summ...]]></description>
<link>https://tsecurity.de/de/3622957/it-security-nachrichten/it-security-news-daily-summary-2026-06-24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622957/it-security-nachrichten/it-security-news-daily-summary-2026-06-24/</guid>
<pubDate>Thu, 25 Jun 2026 00:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>171 posts were published in the last hour 21:31 : New website names and shames companies that still don’t offer passkeys to users 21:7 : Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks 21:7 : Malicious Edge Extension Uses…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-24/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-24/">IT Security News Daily Summary 2026-06-24</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-25 00h : 4 posts]]></title>
<description><![CDATA[4 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-06-24 21:31 : New website names and shames companies that still don’t offer passkeys to users 21:7 : Operation Endgame Disrupts StealC, Amadey and SocGholish…
Read more →
The post IT Security News Hourly Summary 2...]]></description>
<link>https://tsecurity.de/de/3622954/it-security-nachrichten/it-security-news-hourly-summary-2026-06-25-00h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622954/it-security-nachrichten/it-security-news-hourly-summary-2026-06-25-00h-4-posts/</guid>
<pubDate>Thu, 25 Jun 2026 00:08:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>4 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-06-24 21:31 : New website names and shames companies that still don’t offer passkeys to users 21:7 : Operation Endgame Disrupts StealC, Amadey and SocGholish…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-25-00h-4-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-25-00h-4-posts/">IT Security News Hourly Summary 2026-06-25 00h : 4 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New website names and shames companies that still don’t offer passkeys to users]]></title>
<description><![CDATA[According to a new site, 24% of the most popular websites in the world don’t offer support for passkeys, which are considered the most secure way to log in to apps and services. This article has been indexed from Security…
Read more →
The post New website names and shames companies that still don...]]></description>
<link>https://tsecurity.de/de/3622877/it-security-nachrichten/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622877/it-security-nachrichten/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/</guid>
<pubDate>Wed, 24 Jun 2026 23:35:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>According to a new site, 24% of the most popular websites in the world don’t offer support for passkeys, which are considered the most secure way to log in to apps and services. This article has been indexed from Security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/">New website names and shames companies that still don’t offer passkeys to users</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New website names and shames companies that still don’t offer passkeys to users]]></title>
<description><![CDATA[According to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log into apps and services.]]></description>
<link>https://tsecurity.de/de/3622841/it-security-nachrichten/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622841/it-security-nachrichten/new-website-names-and-shames-companies-that-still-dont-offer-passkeys-to-users/</guid>
<pubDate>Wed, 24 Jun 2026 23:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[According to a new site, 24% of the most popular websites in the world don't offer support for passkeys, which are considered the most secure way to log into apps and services.]]></content:encoded>
</item>
<item>
<title><![CDATA[Weniger als die Hälfte der Deutschen weiß, was Phishing ist]]></title>
<description><![CDATA[Die Begriffe „Cyberangriff“ und „Zwei-Faktor-Authentifizierung“ sind vielen Deutschen geläufig. Doch bei konkreten Bedrohungen wie „Phishing“ und „Malware“ oder neuen Schutzmaßnahmen wie Passkeys stößt das Wissen schnell an seine Grenzen. Das zeigt eine aktuelle Bitkom-Studie.]]></description>
<link>https://tsecurity.de/de/3621370/it-security-nachrichten/weniger-als-die-haelfte-der-deutschen-weiss-was-phishing-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621370/it-security-nachrichten/weniger-als-die-haelfte-der-deutschen-weiss-was-phishing-ist/</guid>
<pubDate>Wed, 24 Jun 2026 14:38:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Begriffe „Cyberangriff“ und „Zwei-Faktor-Authentifizierung“ sind vielen Deutschen geläufig. Doch bei konkreten Bedrohungen wie „Phishing“ und „Malware“ oder neuen Schutzmaßnahmen wie Passkeys stößt das Wissen schnell an seine Grenzen. Das zeigt eine aktuelle Bitkom-Studie.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Auto-Fix Weak Passwords in iOS 27]]></title>
<description><![CDATA[Weak passwords remain one of the biggest reasons online accounts get hacked. Apple has addressed this problem in iOS 27 with a new Passwords app feature that can automatically replace weak, reused, or compromised passwords with stronger ones. 



Using Apple Intelligence and Safari, the system ca...]]></description>
<link>https://tsecurity.de/de/3621111/ios-mac-os/how-to-auto-fix-weak-passwords-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621111/ios-mac-os/how-to-auto-fix-weak-passwords-in-ios-27/</guid>
<pubDate>Wed, 24 Jun 2026 13:10:43 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Weak passwords remain one of the biggest reasons online accounts get hacked. Apple has addressed this problem in iOS 27 with a new Passwords app feature that can automatically replace weak, reused, or compromised passwords with stronger ones. 



Using Apple Intelligence and Safari, the system can securely navigate supported websites, update credentials, and save the new password for you. This removes the need to manually visit every website and change passwords one by one.



If you use the Passwords app on your iPhone, here is how you can automatically fix weak passwords in iOS 27.



Table of contentsAuto-Fix Weak Passwords Using the Passwords AppManually Change Weak Passwords When Auto-Fix Is UnavailableEnable Compromised Password DetectionReplace Passwords with PasskeysUse Strong Password Suggestions for New AccountsFAQsSummaryConclusion



Auto-Fix Weak Passwords Using the Passwords App



The biggest password security upgrade in iOS 27 is the new automatic password repair feature. When the Passwords app detects a weak, reused, or compromised password, it can update the credential on supported websites and save the new password automatically.








Open the Passwords app on your iPhone.



Authenticate with Face ID, Touch ID, or your passcode.



Tap Security.



Review accounts marked as Weak Password, Reused Password, or Compromised Password.



Select the affected account.



Tap the option to Automatically Fix Password if available.



Confirm the action.



Wait while Apple Intelligence and Safari securely update the password.



The new strong password will be saved automatically in the Passwords app.




Manually Change Weak Passwords When Auto-Fix Is Unavailable



Not every website currently supports automatic password updates. In those cases, you can still change the password manually.




Open the Passwords app.



Tap Security.



Select the account with the security warning.



Tap Change Password.



Follow the website's password update process.



Let iPhone generate a strong password when prompted.



Save the changes and verify the update.




Enable Compromised Password Detection



To receive alerts about leaked or unsafe passwords, make sure password monitoring is turned on.




Open Settings.



Tap Apps.



Select Passwords.



Turn on Detect Compromised Passwords.



Return to the Passwords app and review security recommendations regularly.




Replace Passwords with Passkeys



Many services now support passkeys, which are more secure than traditional passwords.




Open the account settings for a supported website or app.



Look for Passkey setup options.



Follow the on-screen instructions.



Save the passkey using Face ID or Touch ID.



Use the passkey for future sign-ins.




Use Strong Password Suggestions for New Accounts



Whenever you create a new account, iOS 27 can generate a unique password automatically.




Start creating a new account in an app or website.



Tap the password field.



Select Use Strong Password when prompted.



Save the credential in the Passwords app.



Complete account registration.




FAQs



What is the Auto-Fix Password feature in iOS 27? It is a new Apple Intelligence-powered feature that can automatically update weak or compromised passwords on supported websites and save the new credentials in the Passwords app.  Does Auto-Fix work on every website? No. The feature currently works only with supported websites and services. Unsupported sites still require manual password changes.  Will I see progress while the password is being changed? Yes. iOS 27 can display the process through a Live Activity so you can monitor the update.  Are the new passwords stored automatically? Yes. Once the password is updated, the Passwords app saves the new credential securely.  Is the feature secure? Apple says the system uses Apple Intelligence with on-device processing and Private Cloud Compute protections for supported tasks.  



Summary




Open the Passwords app and check the Security section.



Use Auto-Fix Password for supported accounts.



Change passwords manually when automatic updates are unavailable.



Enable Detect Compromised Passwords in Settings.



Switch to passkeys whenever possible.



Use Apple's strong password generator for new accounts.



Review security recommendations regularly.




Conclusion



iOS 27 makes password security much easier by automatically fixing weak and compromised passwords on supported websites. Instead of manually updating every account, you can let Apple Intelligence handle much of the process while securely storing the new credentials in the Passwords app. Combined with passkeys and compromised password alerts, this update gives iPhone users a simpler way to keep their accounts protected.]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Windows 11’s Hidden Productivity and AI Tools]]></title>
<description><![CDATA[Explore Windows 11 tools you may be missing, from Copilot Vision and Recall to Live Captions, Snipping Tool, Paint, passkeys, and Snap layouts.]]></description>
<link>https://tsecurity.de/de/3603029/it-nachrichten/inside-windows-11s-hidden-productivity-and-ai-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603029/it-nachrichten/inside-windows-11s-hidden-productivity-and-ai-tools/</guid>
<pubDate>Tue, 16 Jun 2026 21:46:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Explore Windows 11 tools you may be missing, from Copilot Vision and Recall to Live Captions, Snipping Tool, Paint, passkeys, and Snap layouts.]]></content:encoded>
</item>
<item>
<title><![CDATA[Readers reply: Experts say we should use passkeys, but can a smartphone pin really be safer than a password?]]></title>
<description><![CDATA[The long-running series in which readers answer other readers’ questions on subjects ranging from trivial flights of fancy to profound scientific and philosophical conceptsThis week’s question: Is ‘ripen at home’ fruit the supermarkets’ idea of a joke?I’ve been struggling to get my head around th...]]></description>
<link>https://tsecurity.de/de/3597075/it-security-nachrichten/readers-reply-experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597075/it-security-nachrichten/readers-reply-experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password/</guid>
<pubDate>Sun, 14 Jun 2026 15:05:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The long-running series in which readers answer other readers’ questions on subjects ranging from trivial flights of fancy to profound scientific and philosophical concepts</p><ul><li><p>This week’s question: <a href="https://www.theguardian.com/lifeandstyle/2026/jun/14/ripen-at-home-fruit-supermarkets">Is ‘ripen at home’ fruit the supermarkets’ idea of a joke?</a></p><p></p></li></ul><p>I’ve been struggling to get my head around the idea that a passkey, which can be a pin on your phone, or facial recognition, can be safer than using a complicated password and two-factor authentication.</p><p>I get that having something unique to your device, not stored on a company’s server, is unphishable and less hackable by cybercrims, but what if your phone is nicked and someone guesses the password? And what if you lose your phone?</p> <a href="https://www.theguardian.com/lifeandstyle/2026/jun/14/readers-reply-experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys im Unternehmen: Schatten-IT sabotiert Passwortlosigkeit - it-daily.net]]></title>
<description><![CDATA[Doch abseits der offiziellen IT-Infrastruktur stoßen Sicherheitsverantwortliche auf ein unbemerktes Problem. Während die Haupteingänge der Konzerne ...]]></description>
<link>https://tsecurity.de/de/3594959/it-security-nachrichten/passkeys-im-unternehmen-schatten-it-sabotiert-passwortlosigkeit-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594959/it-security-nachrichten/passkeys-im-unternehmen-schatten-it-sabotiert-passwortlosigkeit-it-dailynet/</guid>
<pubDate>Sat, 13 Jun 2026 06:27:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Doch abseits der offiziellen <b>IT</b>-Infrastruktur stoßen Sicherheitsverantwortliche auf ein unbemerktes Problem. Während die Haupteingänge der Konzerne ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys im Unternehmen: Wenn die Schatten-IT die Passwortlosigkeit sabotiert]]></title>
<description><![CDATA[Konzerne stellen auf sichere Passkeys um, doch inoffizielle Apps der Fachabteilungen nutzen weiter schwache Passwörter. Wie IT-Leiter die Lücke schließen.

Tags: #Cyber Security | #Passkeys | #Schatten-IT]]></description>
<link>https://tsecurity.de/de/3594927/it-security-nachrichten/passkeys-im-unternehmen-wenn-die-schatten-it-die-passwortlosigkeit-sabotiert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594927/it-security-nachrichten/passkeys-im-unternehmen-wenn-die-schatten-it-die-passwortlosigkeit-sabotiert/</guid>
<pubDate>Sat, 13 Jun 2026 05:37:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920.jpg" class="attachment-full size-full wp-post-image" alt="Passkey" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Passkeys im Unternehmen: Wenn die Schatten-IT die Passwortlosigkeit sabotiert 1"></p>
    Konzerne stellen auf sichere Passkeys um, doch inoffizielle Apps der Fachabteilungen nutzen weiter schwache Passwörter. Wie IT-Leiter die Lücke schließen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/passkeys">#Passkeys</a> | <a href="https://www.it-daily.net/thema/schatten-it">#Schatten-IT</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prevent account takeovers with Device Bound Session Credentials (DBSC), now generally available in the Chrome browser for Windows]]></title>
<description><![CDATA[Previously available in beta, Device Bound Session Credentials (DBSC) in the Chrome browser on Windows is now generally available and enabled by default for Google Workspace users.DBSC strengthens account security after users are logged in and helps bind a session cookie — small files used by web...]]></description>
<link>https://tsecurity.de/de/3589217/web-tipps/prevent-account-takeovers-with-device-bound-session-credentials-dbsc-now-generally-available-in-the-chrome-browser-for-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589217/web-tipps/prevent-account-takeovers-with-device-bound-session-credentials-dbsc-now-generally-available-in-the-chrome-browser-for-windows/</guid>
<pubDate>Thu, 11 Jun 2026 01:54:54 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Previously <a href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc" target="_blank">available in beta</a>, Device Bound Session Credentials (DBSC) in the Chrome browser on Windows is now generally available and enabled by default for Google Workspace users.<div><br></div><div>DBSC strengthens account security after users are logged in and helps bind a session cookie — small files used by websites to remember user information — to the device a user authenticated from. Even if malware was present on the user’s device, DBSC reduces the risk of session theft and makes it meaningfully more difficult for malicious actors to exploit stolen session cookies.</div><div><br></div><div>With this change to general availability, Workspace admins no longer need to take action to enable DBSC in the Admin console. Organizations can also bolster protections with more granular account attributes when using DBSC together with <a href="https://support.google.com/a/answer/9275380" target="_blank">context-aware access</a> (CAA). To monitor DBSC binding events, admins can view the audit logs available in the security investigation tool.</div><div><br></div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzz8uJumSBMVVgEukdcSPSlfdx5zffpgl2_zQPv-ec10DS0CSh-OF_aQcGK47P4iY5Wi2ALSfV5azpGSuTpxqjfvdP4FSN69PSyrUBQzylmCAvBE57j8Y-leWZMQn5mDYYaC9T8r7vc_R2KKIjRYjPFaiUG2ub3NMyXnJiwilGWZ7swjbGP-6ewSAq1RY/s1818/Prevent%20account%20takeovers%20with%20Device%20Bound%20Session%20Credentials%20(DBSC),%20now%20generally%20available%20in%20the%20Chrome%20browser%20for%20Windows%20-%205212.png" imageanchor="1"><img border="0" data-original-height="1227" data-original-width="1818" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzz8uJumSBMVVgEukdcSPSlfdx5zffpgl2_zQPv-ec10DS0CSh-OF_aQcGK47P4iY5Wi2ALSfV5azpGSuTpxqjfvdP4FSN69PSyrUBQzylmCAvBE57j8Y-leWZMQn5mDYYaC9T8r7vc_R2KKIjRYjPFaiUG2ub3NMyXnJiwilGWZ7swjbGP-6ewSAq1RY/s16000/Prevent%20account%20takeovers%20with%20Device%20Bound%20Session%20Credentials%20(DBSC),%20now%20generally%20available%20in%20the%20Chrome%20browser%20for%20Windows%20-%205212.png"></a></td></tr><tr><td class="tr-caption"><i>An example of the audit log and log details for a DBSC event in the admin console</i></td></tr></tbody></table><h3>Getting started</h3><div><ul><li><b>Admins: </b>This feature is ON by default for all Google Workspace customers, and there is no administrator control to disable it.</li><li><b>End users: </b>There is no end user setting for this feature.</li></ul></div><h3>Rollout pace</h3><div><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Gradual rollout (up to 60 days for feature visibility) started on May 25, 2026</li></ul></div><h3>Availability</h3><div><ul><li>Available to all Google Workspace customers, Workspace Individual subscribers, and users with personal Google accounts</li></ul></div><h3>Resources</h3><div><ul><li>Google Workspace Admin Help: <a href="https://support.google.com/a/answer/15956470" target="_blank">Prevent cookie theft with session binding</a></li></ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How long would it take a hacker to crack your password? - YouTube]]></title>
<description><![CDATA[Dein Passwort fällt in Sekunden — diese 5 Dinge stoppen jeden Hacker. Länge schlägt Komplexität, ein Manager, 2FA und Passkeys ändern alles.]]></description>
<link>https://tsecurity.de/de/3588696/hacking/how-long-would-it-take-a-hacker-to-crack-your-password-youtube/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588696/hacking/how-long-would-it-take-a-hacker-to-crack-your-password-youtube/</guid>
<pubDate>Wed, 10 Jun 2026 21:09:10 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dein Passwort fällt in Sekunden — diese 5 Dinge stoppen jeden <b>Hacker</b>. Länge schlägt Komplexität, ein Manager, 2FA und Passkeys ändern alles.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Intelligence can now replace weak passwords without user intervention]]></title>
<description><![CDATA[Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. Automatically Fix Passwords (Source: Apple) Introduced as a standalone app in 2024, Passwords gives users a central place to store...]]></description>
<link>https://tsecurity.de/de/3584341/it-security-nachrichten/apple-intelligence-can-now-replace-weak-passwords-without-user-intervention/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584341/it-security-nachrichten/apple-intelligence-can-now-replace-weak-passwords-without-user-intervention/</guid>
<pubDate>Tue, 09 Jun 2026 13:38:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple’s next generation of Apple Intelligence, the company’s personal intelligence system, expands its capabilities and introduces new security features in Passwords. Automatically Fix Passwords (Source: Apple) Introduced as a standalone app in 2024, Passwords gives users a central place to store and access passwords, passkeys, Wi-Fi credentials, and verification codes. It alerts users when a password is weak, reused, or exposed in a known data breach and recommends updating it. Any required changes previously had … <a href="https://www.helpnetsecurity.com/2026/06/09/apple-intelligence-automated-passwords-security-updates/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/09/apple-intelligence-automated-passwords-security-updates/">Apple Intelligence can now replace weak passwords without user intervention</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[QNAP erweitert QuTS hero um HA und Snapshots - IT-Administrator.de]]></title>
<description><![CDATA[Ergänzt wird das Sicherheitskonzept durch Funktionen wie FIDO2-Passkeys, Secure Boot, zentralisierte KMIP-Schlüsselverwaltung sowie zusätzliche ...]]></description>
<link>https://tsecurity.de/de/3583170/it-security-nachrichten/qnap-erweitert-quts-hero-um-ha-und-snapshots-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583170/it-security-nachrichten/qnap-erweitert-quts-hero-um-ha-und-snapshots-it-administratorde/</guid>
<pubDate>Tue, 09 Jun 2026 01:36:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ergänzt wird das Sicherheitskonzept durch Funktionen wie FIDO2-Passkeys, Secure Boot, zentralisierte KMIP-Schlüsselverwaltung sowie zusätzliche ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Experts say we should use passkeys, but can a smartphone PIN really be safer than a password?]]></title>
<description><![CDATA[The long-running series in which readers answer other readers’ questions explores a topical issue of personal cybersecurityReaders reply: If an alien asked you: ‘What is music?’ what would you play for them?I’ve been struggling to get my head around the idea that a passkey, which can be a PIN on ...]]></description>
<link>https://tsecurity.de/de/3579428/it-nachrichten/experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579428/it-nachrichten/experts-say-we-should-use-passkeys-but-can-a-smartphone-pin-really-be-safer-than-a-password/</guid>
<pubDate>Sun, 07 Jun 2026 15:32:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The long-running series in which readers answer other readers’ questions explores a topical issue of personal cybersecurity</p><ul><li><p>Readers reply: <a href="https://www.theguardian.com/lifeandstyle/2026/jun/07/readers-reply-alien-music-playlist-first-contact">If an alien asked you: ‘What is music?’ what would you play for them?</a></p></li></ul><p>I’ve been struggling to get my head around the idea that a passkey, which can be a PIN on your phone, or facial recognition, can be safer than using a complicated password, and two factor authentication.</p><p>I get that having something unique to your device, not stored on a company’s server is unphishable, and less hackable by cybercrims, but what if your phone is nicked and someone guesses the password? And what if you lose your phone?</p> <a href="https://www.theguardian.com/lifeandstyle/2026/jun/07/passkeys-pin-password-cybersecurity">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Edge goes passwordless with Windows Hello — marking a major shift toward biometric and device-based security]]></title>
<description><![CDATA[Microsoft's Edge browser retired passwords and is moving to Windows Hello and passkeys.]]></description>
<link>https://tsecurity.de/de/3575497/windows-tipps/microsoft-edge-goes-passwordless-with-windows-hello-marking-a-major-shift-toward-biometric-and-device-based-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575497/windows-tipps/microsoft-edge-goes-passwordless-with-windows-hello-marking-a-major-shift-toward-biometric-and-device-based-security/</guid>
<pubDate>Fri, 05 Jun 2026 15:24:40 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft's Edge browser retired passwords and is moving to Windows Hello and passkeys.]]></content:encoded>
</item>
<item>
<title><![CDATA[Dell Pro 5: Neue Maus mit Fingerabdruckleser macht Passwörter hinfällig]]></title>
<description><![CDATA[Wer im Büro einen stationären Rechner für Office-Aufgaben verwendet, kann mit einer neuen Maus von Dell künftig die Eingabe von Passwörtern oder PINs auch ohne den Einsatz von Passkeys oder Gesichtserkennung hinfällig machen. Möglich wird dies durch einen in der Maus integrierten Fingerabdruckles...]]></description>
<link>https://tsecurity.de/de/3575442/it-security-nachrichten/dell-pro-5-neue-maus-mit-fingerabdruckleser-macht-passwoerter-hinfaellig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575442/it-security-nachrichten/dell-pro-5-neue-maus-mit-fingerabdruckleser-macht-passwoerter-hinfaellig/</guid>
<pubDate>Fri, 05 Jun 2026 15:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159158.html"><img hspace="5" border="0" align="left" alt="Maus, Fingerabdruckleser, Fingerprint Reader, Enhanced Sign-in Security, Dell Pro 5, M526C, ESS" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/91338.png"></a>
			Wer im Büro einen stationären Rechner für Office-Aufgaben verwendet, kann mit einer neuen Maus von <a href="https://winfuture.de/special/dell-xps-13/" title="Dell XPS Special">Dell</a> künftig die Eingabe von Passwörtern oder PINs auch ohne den Einsatz von Passkeys oder Gesichtserkennung hinfällig machen. Möglich wird dies durch einen in der Maus integrierten Fingerabdruckleser.			(<a href="https://winfuture.de/news,159158.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3568487/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568487/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Wed, 03 Jun 2026 08:32:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1fca192f2e4"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android: Google vereinfacht sicheren Transfer von Passkeys und Passwörtern]]></title>
<description><![CDATA[Mit dem Juni-Update der Play-System-Dienste für Android können Nutzer Passwörter und Passkeys nun sicher zwischen verschiedenen Passwortmanagern austauschen.]]></description>
<link>https://tsecurity.de/de/3568411/it-nachrichten/android-google-vereinfacht-sicheren-transfer-von-passkeys-und-passwoertern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568411/it-nachrichten/android-google-vereinfacht-sicheren-transfer-von-passkeys-und-passwoertern/</guid>
<pubDate>Wed, 03 Jun 2026 07:47:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit dem Juni-Update der Play-System-Dienste für Android können Nutzer Passwörter und Passkeys nun sicher zwischen verschiedenen Passwortmanagern austauschen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android: Google vereinfacht sicheren Transfer von Passkeys und Passwörtern]]></title>
<description><![CDATA[Mit dem Juni-Update der Play-System-Dienste für Android können Nutzer Passwörter und Passkeys nun sicher zwischen verschiedenen Passwortmanagern austauschen.]]></description>
<link>https://tsecurity.de/de/3568388/it-security-nachrichten/android-google-vereinfacht-sicheren-transfer-von-passkeys-und-passwoertern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568388/it-security-nachrichten/android-google-vereinfacht-sicheren-transfer-von-passkeys-und-passwoertern/</guid>
<pubDate>Wed, 03 Jun 2026 07:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit dem Juni-Update der Play-System-Dienste für Android können Nutzer Passwörter und Passkeys nun sicher zwischen verschiedenen Passwortmanagern austauschen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Play System Update Juni 2026: Passwort-Export und neues Store-Design]]></title>
<description><![CDATA[Google schraubt pünktlich zum Monatsanfang wieder an den Play Services und dem Play Store. Die Version 26.21 der Play Dienste bringt eine nützliche Neuerung für den Google Passwortmanager. Nutzer können nun Passwörter und Passkeys über den sogenannten Credential Exchange Standard...Zum Beitrag: G...]]></description>
<link>https://tsecurity.de/de/3566920/it-nachrichten/google-play-system-update-juni-2026-passwort-export-und-neues-store-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566920/it-nachrichten/google-play-system-update-juni-2026-passwort-export-und-neues-store-design/</guid>
<pubDate>Tue, 02 Jun 2026 18:33:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google schraubt pünktlich zum Monatsanfang wieder an den Play Services und dem Play Store. Die Version 26.21 der Play Dienste bringt eine nützliche Neuerung für den Google Passwortmanager. Nutzer können nun Passwörter und Passkeys über den sogenannten Credential Exchange Standard...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/google-play-system-update-juni-2026-passwort-export-und-neues-store-design/">Google Play System Update Juni 2026: Passwort-Export und neues Store-Design</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Play Services for June Now Rolling Out]]></title>
<description><![CDATA[Google is shipping out the latest build of Google Play Services, that being v26.21. Inside, users will find quite a few new things for Google Play itself, as well as one feature each for developer services and general security/privacy. Google lists that users can now import and export passwords a...]]></description>
<link>https://tsecurity.de/de/3566910/it-nachrichten/google-play-services-for-june-now-rolling-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566910/it-nachrichten/google-play-services-for-june-now-rolling-out/</guid>
<pubDate>Tue, 02 Jun 2026 18:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google is shipping out the latest build of Google Play Services, that being v26.21. Inside, users will find quite a few new things for Google Play itself, as well as one feature each for developer services and general security/privacy. Google lists that users can now import and export passwords and passkeys between Google Password Manager...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/06/02/google-play-services-for-june-now-rolling-out/">Google Play Services for June Now Rolling Out</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra pushes passkeys, tightens identity security]]></title>
<description><![CDATA[Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication…
Read ...]]></description>
<link>https://tsecurity.de/de/3565796/it-security-nachrichten/microsoft-entra-pushes-passkeys-tightens-identity-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565796/it-security-nachrichten/microsoft-entra-pushes-passkeys-tightens-identity-security/</guid>
<pubDate>Tue, 02 Jun 2026 13:07:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-entra-pushes-passkeys-tightens-identity-security/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-entra-pushes-passkeys-tightens-identity-security/">Microsoft Entra pushes passkeys, tightens identity security</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Entra pushes passkeys, tightens identity security]]></title>
<description><![CDATA[Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication update...]]></description>
<link>https://tsecurity.de/de/3565717/it-security-nachrichten/microsoft-entra-pushes-passkeys-tightens-identity-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565717/it-security-nachrichten/microsoft-entra-pushes-passkeys-tightens-identity-security/</guid>
<pubDate>Tue, 02 Jun 2026 12:38:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication updates Phishing-resistant MFA is now available on Linux desktops through the Microsoft identity broker. The feature supports Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, bringing Linux support in line with … <a href="https://www.helpnetsecurity.com/2026/06/02/microsoft-entra-latest-security-updates/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/02/microsoft-entra-latest-security-updates/">Microsoft Entra pushes passkeys, tightens identity security</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3565113/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565113/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Tue, 02 Jun 2026 08:46:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1e7c1906edf"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI requires stronger authentication for users of its most powerful AI models]]></title>
<description><![CDATA[Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI…
Read more →
The post OpenAI requires stronger au...]]></description>
<link>https://tsecurity.de/de/3563924/it-security-nachrichten/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563924/it-security-nachrichten/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/</guid>
<pubDate>Mon, 01 Jun 2026 19:37:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/">OpenAI requires stronger authentication for users of its most powerful AI models</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI requires stronger authentication for users of its most powerful AI models]]></title>
<description><![CDATA[Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empowering its users t...]]></description>
<link>https://tsecurity.de/de/3563854/it-security-nachrichten/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563854/it-security-nachrichten/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models/</guid>
<pubDate>Mon, 01 Jun 2026 19:23:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empowering its users to take control of their own security posture with more secure authentication options. Starting June 1, 2026, individuals in TAC with access to OpenAI’s most powerful and … <a href="https://www.helpnetsecurity.com/2026/06/01/yubico-openai-passkeys-requirements/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/01/yubico-openai-passkeys-requirements/">OpenAI requires stronger authentication for users of its most powerful AI models</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s time to ditch passwords for passkeys – what are they?]]></title>
<description><![CDATA[Passwords have been the default way to log in to online accounts for decades. But developers never created them to handle the threats people face… The post It’s time to ditch passwords for passkeys – what are they? appeared first…
Read more →
The post It’s time to ditch passwords for passkeys – w...]]></description>
<link>https://tsecurity.de/de/3562233/it-security-nachrichten/its-time-to-ditch-passwords-for-passkeys-what-are-they/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562233/it-security-nachrichten/its-time-to-ditch-passwords-for-passkeys-what-are-they/</guid>
<pubDate>Mon, 01 Jun 2026 09:37:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Passwords have been the default way to log in to online accounts for decades. But developers never created them to handle the threats people face… The post It’s time to ditch passwords for passkeys – what are they? appeared first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/its-time-to-ditch-passwords-for-passkeys-what-are-they/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/its-time-to-ditch-passwords-for-passkeys-what-are-they/">It’s time to ditch passwords for passkeys – what are they?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3562074/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562074/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Mon, 01 Jun 2026 08:17:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1d239d7eef2"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys: NCSC erklärt Biometrie zur sichersten Authentifizierung - BornCity]]></title>
<description><![CDATA[Die hardwaregestützte Sicherheit der neuen Passkey- und DBSC-Implementierungen kommt daher zur rechten Zeit. Tags: Authentifizierung, Cybersicherheit, ...]]></description>
<link>https://tsecurity.de/de/3560407/it-security-nachrichten/passkeys-ncsc-erklaert-biometrie-zur-sichersten-authentifizierung-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560407/it-security-nachrichten/passkeys-ncsc-erklaert-biometrie-zur-sichersten-authentifizierung-borncity/</guid>
<pubDate>Sun, 31 May 2026 09:49:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die hardwaregestützte <b>Sicherheit</b> der neuen Passkey- und DBSC-Implementierungen kommt daher zur rechten Zeit. Tags: Authentifizierung, Cybersicherheit, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie diese bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys.



Passkeys müssen nicht auswendig gelernt werden, können direkt au...]]></description>
<link>https://tsecurity.de/de/3560352/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560352/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-diese-bessere-alternative/</guid>
<pubDate>Sun, 31 May 2026 09:17:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys</a>.</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bddd47b6bf"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[VaultJacking Attack Exposes Google Password Vaults via Single PIN]]></title>
<description><![CDATA[A newly disclosed phishing technique dubbed “VaultJacking” is raising serious concerns across the cybersecurity community after researchers demonstrated how a single captured Google Password Manager (GPM) PIN can expose an entire user credential vault. The attack shows that even passkeys…
Read mo...]]></description>
<link>https://tsecurity.de/de/3553849/it-security-nachrichten/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553849/it-security-nachrichten/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/</guid>
<pubDate>Thu, 28 May 2026 13:05:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed phishing technique dubbed “VaultJacking” is raising serious concerns across the cybersecurity community after researchers demonstrated how a single captured Google Password Manager (GPM) PIN can expose an entire user credential vault. The attack shows that even passkeys…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/">VaultJacking Attack Exposes Google Password Vaults via Single PIN</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VaultJacking Attack Exposes Google Password Vaults via Single PIN]]></title>
<description><![CDATA[A newly disclosed phishing technique dubbed “VaultJacking” is raising serious concerns across the cybersecurity community after researchers demonstrated how a single captured Google Password Manager (GPM) PIN can expose an entire user credential vault. The attack shows that even passkeys widely p...]]></description>
<link>https://tsecurity.de/de/3553830/it-security-nachrichten/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553830/it-security-nachrichten/vaultjacking-attack-exposes-google-password-vaults-via-single-pin/</guid>
<pubDate>Thu, 28 May 2026 12:52:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed phishing technique dubbed “VaultJacking” is raising serious concerns across the cybersecurity community after researchers demonstrated how a single captured Google Password Manager (GPM) PIN can expose an entire user credential vault. The attack shows that even passkeys widely promoted as phishing-resistant can be indirectly compromised when attackers target the underlying sync infrastructure […]</p>
<p>The post <a href="https://gbhackers.com/google-password-vaults-via-single-pin/">VaultJacking Attack Exposes Google Password Vaults via Single PIN</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[An diesen 5 verräterischen Zeichen erkennen Sie Hackerangriffe und reagieren richtig]]></title>
<description><![CDATA[Ihr PC wird von anderen im Netzwerk gefunden



Symptom: Obwohl Sie auf Ihrem PC keine Dateien freigegeben haben, wird Ihr PC von anderen Rechnern im Netzwerk gefunden. Er erscheint im Windows-Explorer unter „Netzwerk“ mit seinem Windows-Computernamen. Wer spezielle Tools wie den Angry IP Scanner...]]></description>
<link>https://tsecurity.de/de/3553438/windows-tipps/an-diesen-5-verraeterischen-zeichen-erkennen-sie-hackerangriffe-und-reagieren-richtig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553438/windows-tipps/an-diesen-5-verraeterischen-zeichen-erkennen-sie-hackerangriffe-und-reagieren-richtig/</guid>
<pubDate>Thu, 28 May 2026 10:40:06 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading toc">Ihr PC wird von anderen im Netzwerk gefunden</h2>



<p><strong>Symptom: </strong>Obwohl Sie auf Ihrem PC keine Dateien freigegeben haben, wird Ihr PC von anderen Rechnern im Netzwerk gefunden. Er erscheint im Windows-Explorer unter „Netzwerk“ mit seinem Windows-Computernamen. Wer spezielle Tools wie den <a href="https://angryip.org/" target="_blank" rel="noreferrer noopener">Angry IP Scanner</a> nutzt, findet den PC unter Umständen auch dann, wenn er im Windows-Explorer nicht auftaucht.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e828db"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Netzwerk.png" alt="Hacker Angriff Netzwerk" class="wp-image-3138565" width="823" height="672" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Windows-Explorer zeigt unter „Netzwerk“ einige Windows-PCs an. Das bedeutet, diese Rechner haben die Netzwerkerkennung eingeschaltet. Unter Umständen haben Sie auch Ordner freigegeben.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Harmlose Ursache: </strong>Sie haben in den Netzwerkeinstellungen die Netzwerkerkennung eingeschaltet. Dadurch ist Ihr Windows im Netzwerk sichtbar. Das heißt aber nicht, dass andere auf Ihre Dateien zugreifen können, zumindest dann nicht, wenn die „Datei- und Druckerfreigabe“ deaktiviert ist. Das Auftauchen als Netzwerkteilnehmer bei anderen Systemen ist harmlos.</p>



<p>Das gilt sogar dann, wenn dort Standardfreigaben wie C$, Admin$ angezeigt werden, solange diese ein Passwort verlangen. Und natürlich sind auch Dateifreigaben harmlos, wenn diese gewollt sind.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e82ee7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Netzwerk-Einstellungen.png" alt="Hacker Angriff Netzwerk Einstellungen" class="wp-image-3138566" width="979" height="697" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Soll Ihr Windows-PC für andere Rechner im Netzwerk unsichtbar bleiben, müssen auf dieser Seite der Einstellungen von Windows alle vier Schalter auf Aus stehen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Gefährliche Ursache: </strong>Nicht Sie haben eine Dateifreigabe aktiviert, sondern ein Schadcode.</p>



<p><strong>Untersuchung und Lösung: </strong>Öffnen Sie die Einstellungen von Windows etwa per Win-I und wählen Sie „Netzwerk und Internet &gt; Erweiterte Netzwerkeinstellungen &gt; Erweiterte Freigabeeinstellungen“. Prüfen Sie dort, die Schalter für „Netzwerkerkennung“ und für „Datei- und Druckerfreigabe“.</p>



<p>Wenn Sie keine Dateien auf Ihrem PC im Netzwerk freigeben wollen, deaktivieren Sie beide Optionen, und zwar sowohl unter „Private Netzwerke“, als auch unter „Öffentliche Netzwerke“. Falls eine Dateifreigabe aktiv war, muss das aber nicht zwingend ein Schädling gewesen sein. Vielleicht haben Sie selbst vor längerer Zeit diese Freigaben aktiviert.</p>



<h2 class="wp-block-heading toc">Die Internetverbindung ist langsam</h2>



<p><strong>Symptom: </strong>Das Hoch- oder Herunterladen von Dateien ist ungewöhnlich langsam, sogar das Aufrufen von Webseiten stockt.</p>



<p><strong>Harmlose Ursachen: </strong>Sehr wahrscheinlich ist einer der typischen Bremsklötze beim Surfen schuld. Allen voran die WLAN-Verbindung. Wer etwa in einem Mehrparteienhaus wohnt, erlebt Leistungseinbrüche im WLAN, wenn die Nachbarn nach Hause kommen und das Internet nutzen. Dann können plötzlich einzelne oder alle Funkkanäle verstopft sein. Die Folge: Die Surfgeschwindigkeit bricht ein.</p>



<p>Der zweite Flaschenhals ist eine nicht instabile Internetverbindung. Das kommt sowohl bei DSL- als auch bei Kabelanschlüssen vor. Wenn die Nachbarschaft – in diesem Fall sind alle gemeint, die an einem Verteilerkasten (Kabelverzweiger) hängen – nach dem Abendessen mit Downloads und Video-Streams anfängt, dann tröpfeln die Daten oft nur noch durch die Leitung. Denn alle Nutzer teilen sich die Bandbreite, die beim Verteilerkasten ankommt.</p>



<p><strong>Und schließlich: </strong>Auch Familienmitglieder können am lahmen Internet-Tempo schuld sein: Wenn einer 4K-Videos streamt und ein anderer GB-weise Spiele herunterlädt, geht so manche Internetverbindung in die Knie.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e83563"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-FritzOS825.png?w=1200" alt="Hacker Angriff FritzOS825" class="wp-image-3138564" width="1200" height="796" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Wer eine Fritzbox nutzt und Version 8 von Fritz-OS installiert hat, kann sich im „Online-Monitor“ des Routers den Traffic jedes Netzwerkgerätes ansehen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Gefährliche Ursache: </strong>Tatsächlich kann das Internet auch dann stocken, wenn gerade ein Erpresser-Trojaner Ihren gesamten Datenbestand ins Internet hochlädt. Das machen diese Schädlinge mittlerweile fast immer, bevor sie die Daten verschlüsseln. Denn so können die Kriminellen Sie gleich zweimal erpressen.</p>



<p>Einmal mit den verschlüsselten Daten auf Ihrem PC und zum zweiten mit der Drohung, Ihre Daten öffentlich ins Internet zu stellen. Das ist vor allem bei Firmengeheimnissen eine starke Drohung. Und es sind auch meist Unternehmen, die von Erpresserviren betroffen sind. Privatanwender werden zum Glück nur noch selten Opfer von Ransomware. Auf Null ist das Risiko einer Infektion allerdings nicht gesunken.</p>



<p><strong>Untersuchung: </strong>Ob von Ihrem Rechner viele Daten ins Internet geladen werden, verrät ein schneller Blick in den Taskmanager. Rufen Sie ihn mit der Tastenkombination Strg-Umschalt-Esc auf und wählen Sie „Leistung“ und dann „Ethernet“ oder „WLAN“, je nachdem, was Sie verwenden. Um zu prüfen, ob von anderen PCs in Ihrem Netzwerk viele Daten ins Internet fließen, lässt sich mit der Fritzbox prüfen, wenn diese mit Fritz-OS 8 läuft.</p>



<p>In der Weboberfläche der Fritzbox wählen Sie „Internet &gt; Online-Monitor“. Das orangefarbene Diagramm zeigt den Upstream, also die Datenmenge, die von der Fritzbox ins Internet übertragen wird. Mit einem Klick auf „Einzelne Geräte“ vergleichen Sie den Datenverkehr von bis zu sieben Geräten. So finden Sie leicht heraus, welches Gerät die Bandbreite am stärksten beansprucht.</p>



<p>Ein lahmendes WLAN schließen Sie am schnellsten immer noch mit einem Netzwerkkabel aus, das die WLAN-Verbindung testweise ersetzt.</p>



<p><strong>Lösung: </strong>Sollten Sie tatsächlich eine Ransomware dabei erwischen, wie sie Ihre Daten ins Internet hochlädt, heißt es: Internetverbindung kappen. Ziehen Sie das Netzwerkkabel vom PC ab und deaktivieren Sie das WLAN. Das geht über einen Klick auf das WLAN-Symbol im Infobereich von Windows 11 und einen weiteren auf das WLAN-Symbol im Schnellmenü.</p>



<p>Nun heißt es, den PC mit einem Antiviren-Stick zu booten und mit einer aktuellen <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Antiviren-Software</a> den Erpresservirus zu finden und zu löschen. Einen solchen Stick erstellen Sie etwa mit dem Tool Sardu. <a href="http://www.pcwelt.de/1161281" target="_blank" rel="noreferrer noopener">Hier gibt es einen ausführlichen Ratgeber</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e83bc0"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Sardu.png" alt="Hacker Angriff Sardu" class="wp-image-3138561" width="802" height="652" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Mit dem Tool Sardu erstellen Sie mit wenigen Mausklicks eigene Multi-Boot-USB-Sticks, etwa mit mehreren Antiviren-Tools darauf. Sardu lässt sich nach einer Registrierung schneller bedienen.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<h2 class="wp-block-heading toc">Gefälschte Antivirus-Meldungen</h2>



<p><strong>Symptom: </strong>Plötzlich taucht eine Virenwarnung auf dem Bildschirm auf, oft im Vollbildmodus. Sofortiger Handlungsbedarf wird angemahnt. Meist ertönt auch eine Sirene in hoher Lautstärke.</p>



<p><strong>Harmlose Ursache:</strong> In den meisten Fällen hat eine Website ein Fenster im Vollbildmodus gestartet und zeigt eine gefälschte Warnung an. Dieser Angriff ist erst einmal harmlos, da es sich nur um eine Webseite, manchmal um ein Bild handelt. Mit der Esc-Taste lässt sich der Vollbildmodus beenden. Unter Umständen hat es die Website geschafft, sich im Browser zu verankern. Dann taucht die Warnung beim nächsten PC- oder Browser-Start wieder auf (siehe „Untersuchung und Lösung“).</p>



<p><strong>Gefährliche Ursache: </strong>Der Trick mit der Webseite im Vollbildmodus wird dann gefährlich, wenn Sie den Anweisungen der Warnung folgen. Die fordern meist, den Kauf einer vermeintlichen Antiviren-Software oder die Installation eines Tools, das den Angreifern Zugriff auf Ihren PC gewährt. Natürlich kann die Warnung auch von Ihrem Antiviren-Programm stammen. Über folgende einfache Untersuchung finden Sie es heraus.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e8416a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Autoruns.png" alt="Hacker Angriff Autoruns" class="wp-image-3138562" width="984" height="658" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Das Tool Autoruns listet fast alle Startrampen in Windows und Software auf. So entdecken Sie nervige Programme, die nach einem Neustart immer wieder automatisch aktiv sind.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Untersuchung und Lösung: </strong>Eine Virenwarnung im Vollbildmodus ist ungewöhnlich. Der Druck auf die Esc-Taste sollte den Vollbildmodus beenden und offenbaren, ob die Warnung von einem Browser-Fenster stammt, was harmlos wäre, oder von Ihrem Antiviren-Programm. Wem das aktive Fenster gehört, ist in der Taskleiste ersichtlich.</p>



<p>Handelt es sich um eine Warnung in einem Browser-Fenster, schließen Sie dieses einfach. Sollte es beim nächsten Systemstart wieder auftauchen, müssen Sie die Startrampen des Browsers und gegebenenfalls von Windows nach einem passenden Eintrag absuchen und diesen löschen. Dabei helfen ein Blick in die Browser-Einstellungen und das Tool Autoruns.</p>



<p>Sollte die Warnung tatsächlich von Ihrem Antiviren-Programm stammen, folgen Sie seinen Anweisungen. Diese sollten Sie nicht zum Kauf eines Antiviren-Programms drängen. Allerdings: Viele kostenlose Tools warnen Sie vor verschiedensten Dingen, etwa Fehlern in der Registry, fehlender VPN‑Verbindung etc., und drängen Sie dann zum Kauf der Vollversion. Der Unterschied zwischen einer falschen Virenwarnung, einer bösartigen Website und einer vorgeschlagenen Tuning-Maßnahme des kostenlosen Antiviren-Programms ist oft nicht allzu groß.</p>



<h2 class="wp-block-heading toc">Der PC wacht von selbst aus dem Ruhezustand auf</h2>



<p><strong>Symptom: </strong>Sie haben Ihren PC heruntergefahren, doch plötzlich startet er von alleine. Bei älteren PCs sieht man das HDD-Lämpchen blinken. Bei neuen Laptops verrät der Blick in den Taskmanager unter „Leistung &gt; Datenträger“, dass viele Daten geschrieben oder gelesen werden.</p>



<p><strong>Harmlose Ursachen: </strong>Die erste harmlose Ursache kann eine Unterbrechung in der Stromzufuhr sein. Viele PCs sind so eingestellt, dass sie nach einer Stromunterbrechung starten. Wahrscheinlicher aber ist, dass Ihr PC sich im Ruhezustand befand und von Windows selbst für eine Wartungsarbeit, meist ein Update, oder für einen Virenscan gestartet wurde.</p>



<p><strong>Gefährliche Ursache: </strong>Möglicherweise hat aber ein RAT oder eine andere Fernzugriffs-Software Ihren PC aufgeweckt. RAT steht für Remote Access Trojans, also einen Schädling, mit dessen Hilfe Kriminelle Ihren PC über das Internet steuern können.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e847c3"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Aufgabenplanung.png" alt="Hacker Angriff Aufgabenplanung" class="wp-image-3138563" width="1024" height="681" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>In der Aufgabenplanung sind unter anderem die Tasks eingetragen, die Ihren PC aus dem Ruhezustand aufwecken. Sehr übersichtlich ist der Planer nicht, aber ein Blick in „Letzte Laufzeit“ hilft meist weiter.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Untersuchung und Lösung: </strong>Der erste Blick sollte der Update-Historie von Windows gelten. Die Tastenkombi Win-I startet die Einstellungs-App und unter „Windows Update &gt; Update Verlauf“ sehen Sie die letzten Installationen von Patches &amp; Co. mit Datum, allerdings ohne Uhrzeit. Findet sich hier nichts Passendes, lohnt ein Blick in die Aufgabenplanung von Windows, da sich die meisten harmlosen, geplanten Tasks dort eintragen. Geben Sie dafür <em>Aufgabenplanung </em>in das Windows-Suchfeld ein und starten Sie das gleichnamige Tool.</p>



<p>Im mittleren Fenster unter „Trigger“ sehen Sie in vielen Fällen den Startzeitpunkt einer Aufgabe. Oft sind das schnell erfassbare Angaben, etwa „Jeden Tag um 13:00“. In einigen Fällen muss man rechnen, etwa bei „Jeden Tag um 11:12 Uhr – nach Auslösung alle 9 Stunden“. Sehr hilfreich ist die Spalte „Letzte Laufzeit“.</p>



<p>Falls sich in Ihrem System viele Einträge in der Aufgabenplanung finden, kann die Recherche etwas mühsam, aber dennoch lohnenswert sein. Eine weitere Möglichkeit der Ursachenfindung ist die Kontrolle des Startprotokolls in der Windows-Ereignisanzeige. <a href="http://www.pcwelt.de/1145880" target="_blank" rel="noreferrer noopener">Einen ausführlichen Ratgeber dazu finden Sie hier</a>. Lassen sich keine harmlosen Ursachen finden, muss der <a href="http://www.pcwelt.de/1161281" target="_blank" rel="noreferrer noopener">Antiviren-Stick ran und nach Schädlingen suchen</a>.</p>



<h2 class="wp-block-heading toc">Sicherheitswarnungen von Webseiten häufen sich</h2>



<p><strong>Symptom: </strong>Beim Besuch Ihrer bevorzugten Websites häufen sich Captchas. Vielleicht gibt es dazu Aufforderungen zu einem Passwort-Reset oder gar eine Log-in-Blockaden.</p>



<p><strong>Harmlose Ursachen: </strong>Webseiten nutzen Captchas, wenn Sie aktuell stark von automatisierten Log-in-Versuchen betroffen sind. Das muss überhaupt nichts mit Ihnen zu tun haben. Captcha steht übrigens für Completely Automated Public Turing Test to tell Computers and Humans apart“, also für einen Test zur Unterscheidung von Mensch und Maschine.</p>



<p>Ein Passwort-Reset führen Webseiten durch, wenn Hacker in Datenbanken eindringen konnten und Log-in-Daten der Nutzer gestohlen haben. Das klingt nicht besonders harmlos, wenn aber der Webseiten-Betreiber alle betroffenen Passwörter sofort zurückgesetzt hat, entsteht für die Nutzer in der Regel kein Schaden. Wichtig ist, dass Sie Ihr Passwort nicht auch für andere Dienste verwendet haben.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e84e21"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-Captcha1.png?w=757" alt="Hacker Angriff Captcha1" class="wp-image-3138567" width="757" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>So sieht ein klassisches Captcha aus. Es soll verhindern, dass automatisierte Log-in-Versuche einen Webdienst angreifen und etwa massenhaft Passwörter für einen Log-in ausprobieren.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Gefährliche Ursache: </strong>Hacker konnten Ihren PC oder ein anderes Gerät aus Ihrem Netzwerk infizieren und es zu einem Bot-Netzwerk anschließen. Dann gehen von Ihrem Gerät DoS-Attacken aus. Es bombardiert Server im Internet mit Anfragen, mit dem Ziel, den Server unbrauchbar zu machen. Das wiederum verwandelt Ihre IP-Adresse in eine feindliche Adresse, die genauer untersucht wird, wenn Sie sie bei einem Log-in benutzen.</p>



<p>Möglich ist auch, dass ein Hacker versucht, sich in Ihre Online-Dienste einzuloggen, etwa mit Log-in-Daten aus dem Internet. Da Sie ja sicher für jeden Dienst ein eigenes Passwort verwenden, hat der Hacker damit keinen Erfolg, aber seine wiederholten Anmeldeversuche machen natürlich den Diensteanbieter misstrauisch, weshalb er Captchas und andere Sicherheitsmaßnahmen einschaltet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a17ff4e853b5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Hacker-Angriff-captcha2.png" alt="Hacker Angriff captcha2" class="wp-image-3138560" width="340" height="112" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Modernere Captchas fragen nur nach einem Klick in der Checkbox und prüfen anhand der Mausbewegung und des Timings, ob der Klick von einem Menschen oder einer Maschine stammt.</p></figcaption></figure><p class="imageCredit">Arne Arnold</p></div>



<p><strong>Untersuchung und Lösung: </strong>Werden Ihnen Captchas bei einem Dienst neu angezeigt, ist das wenig alarmierend. Am einfachsten warten Sie eine Woche und schauen, ob der Dienst die Captchas wieder weglässt. Wenn nicht, oder wenn Sie umgehend aktiv werden möchten, können Sie zwei Dinge tun: Aktivieren Sie für alle Ihre Online-Konten eine Zwei-Faktor-Authentifizierung. Das erhöht den Schutz gegen Passwort-Diebstahl immens. Am besten nutzen Sie <a href="http://www.pcwelt.de/2107907" target="_blank" rel="noreferrer noopener">Passkeys</a>, wenn der Dienst diese anbietet.</p>



<p>Um zu prüfen, ob andere Geräte in Ihrem Netzwerk Angriffe auf Webseiten führen, hilft für den Anfang ein Blick in den Online-Monitor der Fritzbox (siehe Punkt „Die Internetverbindung ist langsam“). Wenn dort ein Gerät Daten sendet, obwohl Sie es aktuell nicht nutzen, sollten Sie dieses Gerät weiter untersuchen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smartphone hat ausgedient? Löschen Sie unbedingt Ihre Daten! So geht’s richtig]]></title>
<description><![CDATA[Ein altes Smartphone ist mehr als nur ausrangierte Technik. Es steckt voller persönlicher Spuren: Fotos, Chatverläufe, Kontakte, Passwörter, Banking-Apps und oft sogar Zugänge zu Ihren wichtigsten Online-Konten.



Wer ein Gerät verkauft, verschenkt oder entsorgt, sollte deshalb nicht einfach auf...]]></description>
<link>https://tsecurity.de/de/3551299/windows-tipps/smartphone-hat-ausgedient-loeschen-sie-unbedingt-ihre-daten-so-gehts-richtig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551299/windows-tipps/smartphone-hat-ausgedient-loeschen-sie-unbedingt-ihre-daten-so-gehts-richtig/</guid>
<pubDate>Wed, 27 May 2026 15:41:02 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Ein altes Smartphone ist mehr als nur ausrangierte Technik. Es steckt voller persönlicher Spuren: Fotos, Chatverläufe, Kontakte, Passwörter, Banking-Apps und oft sogar <a href="https://www.pcwelt.de/article/3089032/alte-geraete-aus-konten-entfernen-anleitung-wichtig.html" target="_blank" rel="noreferrer noopener">Zugänge zu Ihren wichtigsten Online-Konten</a>.</p>



<p>Wer ein Gerät verkauft, verschenkt oder entsorgt, sollte deshalb nicht einfach auf Zurücksetzen tippen und hoffen, dass damit alle sensiblen Daten verschwinden. Denn zwischen einfachem Löschen und unwiderruflichem Entfernen liegt in der Praxis ein erheblicher Unterschied. Wir zeigen Ihnen Schritt für Schritt, wie Sie Ihr <a href="http://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Smartphone</a> sicher vorbereiten – und Ihre Daten zuverlässig schützen.</p>



<h2 class="wp-block-heading">Die Lösch-Illusion: Warum einfaches Entfernen nicht reicht</h2>



<p>Viele Nutzer glauben: Datei gelöscht, Problem erledigt. In Wirklichkeit verschwinden Daten oft aber nicht sofort komplett vom Speicher. Häufig wird zunächst nur der Verweis auf die Datei entfernt – die eigentlichen Datenblöcke bleiben jedoch erhalten, bis sie irgendwann überschrieben werden.</p>



<p>Mit spezieller Software lassen sich auf schlecht vorbereiteten Geräten mitunter Fotos, Dokumente oder andere Datenfragmente wiederherstellen. Besonders ältere Smartphones sind davon betroffen. Die gute Nachricht: Moderne Geräte sind deutlich besser geschützt. Seit Android 6.0 und bei Apple schon länger ist die Vollverschlüsselung (File-Based Encryption) Standard. Selbst wenn also Fragmente auf dem Chip bleiben, sind sie ohne den individuellen Schlüssel, der beim Werksreset gelöscht beziehungsweise unzugänglich gemacht wird, nur noch digitaler Buchstabensalat.</p>



<p><strong>Beachten Sie aber</strong>: Bei Altgeräten in der Schublade oder Billig-Modellen mit veralteter Software greift dieser Automatismus nicht immer – hier ist Handarbeit gefragt.</p>



<h2 class="wp-block-heading">Phase 1: Erst retten, dann löschen</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a16f252e5d0f"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Whatsapp-Automatische-Backups.png?w=538" alt="Whatsapp Automatische Backups" class="wp-image-3138869" width="538" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Chats können Sie etwa mit Whatsapp automatisch in der Cloud sichern. Doch Vorsicht: Backups von Videos sind hier standardmäßig deaktiviert.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Bevor der digitale Radiergummi zum Einsatz kommt, sollten Sie alles sichern, was Sie behalten möchten.</p>



<p><strong>Fotos und Videos sichern: </strong>Prüfen Sie zuerst, ob Ihre Bilder bereits in einer Cloud gespeichert sind – etwa über <a href="https://photos.google.com/login" target="_blank" rel="noreferrer noopener">Google Fotos</a> oder <a href="https://www.icloud.com/" target="_blank" rel="noreferrer noopener">iCloud</a>. Wer lieber lokal sichert, kopiert Fotos <a href="https://www.pcwelt.de/article/1145684/datenaustausch_von_android_auf_den_pc-smartphone_und_pc.html" target="_blank" rel="noreferrer noopener">per USB-Kabel auf den PC</a> oder eine externe Festplatte. Wie das auch mit einem defekten Akku gelingt, <a href="https://www.pcwelt.de/article/2662268/daten-von-smartphones-mit-defektem-akku-retten.html" target="_blank" rel="noreferrer noopener">lesen Sie hier</a>.</p>



<p><strong>Kontakte und Kalender prüfen: </strong>Kontakte und Termine liegen heute oft direkt im Google-Konto, bei Apple oder in anderen Cloud-Diensten. Doch nur weil ein Kontakt auf dem Handy steht, heißt das nicht, dass er bereits in der Cloud gesichert ist. Kontrollieren Sie den Status lieber selbst und stoßen Sie die Synchronisierung im Zweifel manuell an:</p>



<ul class="wp-block-list">
<li><strong>Android:</strong> Gehen Sie zu <strong>Einstellungen &gt; Passwörter, Passkeys &amp; Konten (oder Benutzer &amp; Konten)</strong>. Tippen Sie auf Ihr Konto und wählen Sie <strong>Kontosynchronisierung</strong>. Prüfen Sie die hier angezeigte Liste. Über das Drei-Punkt-Menü oben rechts können Sie „Jetzt synchronisieren“ wählen, um alle Daten (Kontakte, Kalender, Drive) auf den neuesten Stand zu bringen.</li>
</ul>



<ul class="wp-block-list">
<li><strong>iPhone:</strong> Öffnen Sie die <strong>Einstellungen</strong>, tippen Sie ganz oben auf Ihren Namen und dann auf <strong>iCloud</strong>. Unter „Apps, die iCloud verwenden“ sollten Kontakte und Kalender auf „Ein“ stehen. Um sicherzugehen, dass das Backup aktuell ist, tippen Sie weiter unten auf <strong>iCloud-Backup</strong> und wählen Sie <strong>Backup jetzt erstellen</strong>.</li>
</ul>



<p><strong>Messenger nicht vergessen: </strong>Gerade Messenger-Apps werden beim Umzug oft stiefmütterlich behandelt, dabei lagern hier oft sensible Daten und private Fotos. Das Problem: Viele Messenger speichern Daten nicht automatisch im allgemeinen System-Backup Ihres Smartphones:</p>



<ul class="wp-block-list">
<li><strong>Whatsapp:</strong> Hier müssen Sie proaktiv in die Einstellungen gehen (<strong>Einstellungen &gt; Chats &gt; Chat-Backup</strong>), um den aktuellen Stand Ihrer Chats in der Cloud (Google Drive oder iCloud) zu sichern. Prüfen Sie unbedingt, ob auch Videos eingeschlossen werden sollen, diese werden standardmäßig oft vom Backup ausgeschlossen, weil sie viel Speicherplatz schlucken können.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Signal:</strong> Der Sicherheits-Primus ist hier besonders streng, es verzichtet bewusst auf klassische Cloud-Backup. Sie müssen manuell eine Backup-Datei erstellen und diese auf ein externes Medium (PC oder SD-Karte) sichern oder den direkten Gerät-zu-Gerät-Umzug nutzen, solange Sie das alte Handy noch haben.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Telegram:</strong> Weil Telegram cloudbasiert arbeitet, sind Ihre Chats meist sicher. Aber Achtung: <strong>Geheime Chats</strong> werden nur lokal auf dem Gerät gespeichert und sind nach einem Reset unwiederbringlich verloren.</li>
</ul>



<ul class="wp-block-list">
<li><strong>Threema:</strong> Dieser Messenger erfordert ein manuell erstelltes Backup – entweder lokal oder über Threema Safe. Ohne dieses Backup lassen sich ID und Chatverläufe nach einem Reset nicht wiederherstellen.</li>
</ul>



<p><strong>Wichtiger Sonderfall: </strong>Besonders heikel sind Apps für <a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung</a> wie Google Authenticator oder Microsoft Authenticator. Werden diese nicht vorher übertragen, kann der Zugang zu Mail-, Bank- oder Social-Media-Konten verloren gehen. Ein verfrühter Reset sperrt Sie hier unter Umständen tagelang von Ihren Konten aus, bis ein neuer Aktivierungsbrief per Post kommt oder der Support reagiert.</p>



<p>Denken Sie auch an Banking-Apps. Manchmal muss ein altes Gerät erst im Online-Banking abgemeldet werden, bevor Sie ein neues freischalten können. Prüfen Sie zudem Ihre Messenger: Mitunter verlangt die Ende-zu-Ende-Verschlüsselung nach einer Bestätigung auf dem Altgerät, bevor der Umzug auf das neue Handy final abgeschlossen ist.</p>



<h2 class="wp-block-heading">Phase 2: Konten entkoppeln – sonst droht die Sperre</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a16f252e6932"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Konten-Entfernen-Android.png?w=538" alt="Konten Entfernen Android" class="wp-image-3138873" width="538" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Wichtige Konten sollten Sie auf einem alten Handy am besten manuell abmelden.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Viele Smartphones besitzen eine <a href="https://www.pcwelt.de/article/3138631/geniale-schutz-techniken-von-google-machen-android-jetzt-deutlich-sicherer.html">Diebstahlsi</a><a href="https://www.pcwelt.de/article/3138631/geniale-schutz-techniken-von-google-machen-android-jetzt-deutlich-sicherer.html" target="_blank" rel="noreferrer noopener">c</a><a href="https://www.pcwelt.de/article/3138631/geniale-schutz-techniken-von-google-machen-android-jetzt-deutlich-sicherer.html">herung</a>. Das ist sinnvoll – kann beim Verkauf aber zum Problem werden. Besonders tückisch ist die sogenannte Reaktivierungssperre. Sie soll Dieben das Handwerk legen, macht Ihnen als ehrlichem Verkäufer aber einen Strich durch die Rechnung, wenn das Gerät noch mit Ihrer Cloud-ID verknüpft ist.</p>



<p>Ein Reset über das Recovery-Menü (per Tastenkombination) löscht zwar die Daten, sperrt das Handy aber beim nächsten Start komplett. Erst das manuelle Abmelden in den Kontoeinstellungen gibt die Hardware-ID für den Nachbesitzer wirklich frei.</p>



<p><strong>Android, Google-Sperre (FRP): </strong>Bleibt das Google-Konto auf dem Gerät aktiv, kann nach dem Zurücksetzen die sogenannte Factory Reset Protection greifen. Der neue Besitzer kommt dann ohne Ihre Zugangsdaten nicht weiter.</p>



<p><strong>iPhone, Aktivierungssperre: </strong>Bei Apple-Geräten muss „Wo ist?“ deaktiviert und das Gerät aus der Apple-ID entfernt werden. Sonst bleibt das iPhone gesperrt.</p>



<p><strong>Deshalb sollten Sie vorher Folgendes erledigen:</strong></p>



<ul class="wp-block-list">
<li><strong>Aus Hauptkonten abmelden:</strong> Gehen Sie in die Einstellungen und entfernen Sie manuell das Google-Konto beziehungsweise die Apple-ID.</li>



<li><strong>„Wo ist?“ / Gerätesuche deaktivieren:</strong> Dies ist bei iPhones der entscheidende Schritt, um die Aktivierungssperre zu lösen.</li>



<li><strong>Zusatz-Sperren prüfen:</strong> Bei Samsung-Geräten unbedingt auch vom „Samsung-Account“ abmelden.</li>



<li><strong>SIM-Karte und Speicherkarte entnehmen:</strong> Ein Klassiker, der im Eifer des Gefechts oft vergessen wird.</li>



<li><strong>Zubehör entkoppeln:</strong> Trennen Sie in den Bluetooth-Einstellungen die Verbindung zu Smartwatches oder Kopfhörern.</li>
</ul>



<h2 class="wp-block-heading">Phase 3: Der sichere Werksreset</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a16f252e7260"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Android-alle-Daten-loschen-Reset.png?w=538" alt="Android alle Daten löschen Reset" class="wp-image-3138874" width="538" height="1201" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Der letzte Schritt: Mit dem Werksreset schicken Sie Ihr Smartphone auf eine Zeitreise Richtung Auslieferungszustand.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Wenn die Daten gesichert und die Konten entkoppelt sind, folgt der finale Schritt. Beim Werksreset wird das Dateisystem Ihres Smartphones quasi auf null gesetzt. Dabei werden nicht nur Ihre Apps und Einstellungen entfernt, sondern bei modernen Geräten auch der digitale Verschlüsselungs-Key vernichtet. Ohne diesen Schlüssel sind die auf dem Speicherchip verbleibenden Datenfragmente für Unbefugte wertlos.</p>



<p><strong>Wichtig:</strong> Achten Sie darauf, dass Ihr Akku noch mindestens <strong>50 Prozent Ladung</strong> hat oder das Gerät am Ladekabel hängt. Ein Abbruch während des Löschvorgangs durch einen leeren Akku kann das Betriebssystem beschädigen und das Handy im schlimmsten Fall unbrauchbar machen.</p>



<h3 class="wp-block-heading">So stoßen Sie den Vorgang an:</h3>



<h3 class="wp-block-heading">Android zurücksetzen</h3>



<p>Weil jeder Hersteller (Samsung, Xiaomi, Google) seine Menüs auf andere Art strukturiert, nutzen Sie am besten die Suchfunktion oben in den Einstellungen und geben dort „Zurücksetzen“ ein. Der Standardpfad lautet oft:</p>



<ol start="1" class="wp-block-list">
<li><strong>Einstellungen</strong> öffnen.</li>



<li><strong>System</strong> oder <strong>Allgemeine Verwaltung</strong> wählen.</li>



<li>Auf <strong>Optionen zum</strong> <strong>Zurücksetzen </strong>oder auf <strong>Zurücksetzen</strong> tippen.</li>



<li><strong>Auf Werkseinstellungen zurücksetzen</strong> (oder „Alle Daten löschen“) wählen.</li>
</ol>



<h3 class="wp-block-heading">iPhone zurücksetzen</h3>



<p>Apple hat den Pfad in neueren iOS-Versionen etwas versteckt, um versehentliches Löschen zu verhindern:</p>



<ol start="1" class="wp-block-list">
<li><strong>Einstellungen</strong> öffnen.</li>



<li><strong>Allgemein</strong> wählen.</li>



<li>Ganz nach unten scrollen zu <strong>iPhone übertragen/zurücksetzen</strong>.</li>



<li><strong>Inhalte &amp; Einstellungen löschen</strong> auswählen und mit dem Sperrcode bestätigen.</li>
</ol>



<h2 class="wp-block-heading">Für besonders Vorsichtige: Löschen mit Nachdruck</h2>



<p>Wer ganz sicher gehen möchte – etwa bei einem älteren Android-Gerät – kann nach dem ersten Reset den Speicher möglichst vollständig mit belanglosen Daten füllen. Zum Beispiel einfache lange Videos oder große Dateien darauf abspeichern. Anschließend setzen Sie das Gerät ein zweites Mal zurück. Experten nennen dieses Verfahren „Sanitizing“.</p>



<p>Indem Sie den Speicher mit unkritischen Daten fluten, werden die physikalischen Speicherzellen, die zuvor Ihre privaten Daten vorgehalten haben, mit neuen Bit-Mustern überschrieben. Jenseits forensischer Labormethoden sind Ihre Daten damit endgültig im digitalen Nirwana verschwunden. Das ergibt manchmal übrigens auch <a href="https://www.pcwelt.de/article/1082423/daten-sicher-und-endgultig-loeschen-so-gehts.html" target="_blank" rel="noreferrer noopener">bei normalen Festplatten</a> Sinn.</p>



<p><strong>Pro-Tipp:</strong> Wenn das Handy defekt ist und sich nicht mehr löschen lässt, hilft nur die mechanische Zerstörung des Speicherchips, bevor es zum Recycling wandert. Ein Locher oder ein schwerer Hammer sind hier die letzten Argumente für endgültigen Datenschutz. Achten Sie dabei aber unbedingt darauf, dass kein Akku mehr im Gerät steckt!</p>



<h2 class="wp-block-heading">Checkliste für Verkauf, Weitergabe oder Entsorgung</h2>



<p><strong>Bevor Ihr Smartphone den Besitzer wechselt, denken Sie an Folgendes:</strong></p>



<ul class="wp-block-list">
<li>Daten gesichert?</li>



<li>Konten entfernt?</li>



<li>SIM-Karte entnommen?</li>



<li>microSD-Karte entfernt?</li>



<li>Werksreset durchgeführt?</li>



<li>Ladegerät und Zubehör geprüft?</li>



<li>Gehäuse und Anschlüsse gereinigt?</li>



<li>Zustand fotografiert und Rechnung/Zubehör beigelegt (bei Verkauf)?</li>
</ul>



<h2 class="wp-block-heading">Smartphone entsorgen? Bitte nicht in den Hausmüll</h2>



<p>Defekte Altgeräte gehören nicht in den Restmüll. Akkus und Elektronik enthalten wertvolle Rohstoffe, Akkus können in der Abfallwirtschaft Brände auslösen. Nutzen Sie kommunale Sammelstellen, Recyclinghöfe oder Rücknahmeprogramme des Handels. Tipps dazu finden Sie auch <a href="https://www.verbraucherzentrale.de/wissen/umwelt-haushalt/abfall/wohin-mit-dem-alten-handy-so-entsorgen-sie-es-richtig-11260" target="_blank" rel="noreferrer noopener">bei der Verbraucherzentrale</a>.</p>



<h2 class="wp-block-heading">Fazit: Ein paar Minuten schützen vor unnötigen Risiken</h2>



<p>Ein altes Smartphone ist kein harmloses Stück Technik, sondern meist ein Speicher voller privater Informationen. Wer das Gerät ohne Vorbereitung weitergibt, riskiert unnötige Einblicke in sein digitales Leben. Mit Backup, Konten-Entkopplung und sauberem Werksreset ist das Thema jedoch schnell erledigt.</p>



<p>Wenn Sie jetzt auf der Suche nach einem neuen Handy sind, hilft unsere Kaufberatung:</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">Die besten Smartphones im Test</a></li>



<li><a href="https://www.pcwelt.de/article/2780193/beste-smartphones-handys-bis-500-euro.html" target="_blank" rel="noreferrer noopener">Smartphones bis 500 Euro: Die besten Mittelklasse-Handys im Test</a></li>



<li><a href="https://www.pcwelt.de/article/2778347/beste-budget-smartphones-bis-300-euro.html" target="_blank" rel="noreferrer noopener">Die besten Smartphones bis 300 Euro im Test</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Look at Hardware Security Keys for Passkeys]]></title>
<description><![CDATA[Passkeys can be combined with hardware security keys to implement advanced security features when a particularly robust security strategy is required.]]></description>
<link>https://tsecurity.de/de/3550062/it-security-nachrichten/a-look-at-hardware-security-keys-for-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550062/it-security-nachrichten/a-look-at-hardware-security-keys-for-passkeys/</guid>
<pubDate>Wed, 27 May 2026 08:53:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passkeys can be combined with hardware security keys to implement advanced security features when a particularly robust security strategy is required.]]></content:encoded>
</item>
<item>
<title><![CDATA[PlayStation-Hacking: Social Engineering hebelt 2FA und Passkeys aus - Ad-hoc-news.de]]></title>
<description><![CDATA[Soziale Manipulation statt Hacking: Angreifer nutzen menschliche Schwachstelle im PlayStation-Support aus. Schwerwiegende Sicherheitslücken im ...]]></description>
<link>https://tsecurity.de/de/3549058/hacking/playstation-hacking-social-engineering-hebelt-2fa-und-passkeys-aus-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549058/hacking/playstation-hacking-social-engineering-hebelt-2fa-und-passkeys-aus-ad-hoc-newsde/</guid>
<pubDate>Tue, 26 May 2026 21:05:17 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Soziale Manipulation statt <b>Hacking</b>: Angreifer nutzen menschliche Schwachstelle im PlayStation-Support aus. Schwerwiegende Sicherheitslücken im ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Passwordless security and the new identity battleground]]></title>
<description><![CDATA[For years, passwords were the only thing that mattered for securing our online presence, but the discussion around authentication is evolving rapidly. Passkeys, biometrics, device trust, and adaptive identity management solutions are often cited as the key to the next…
Read more →
The post Passwo...]]></description>
<link>https://tsecurity.de/de/3547166/it-security-nachrichten/passwordlesssecurity-and-the-new-identity-battleground/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547166/it-security-nachrichten/passwordlesssecurity-and-the-new-identity-battleground/</guid>
<pubDate>Tue, 26 May 2026 09:36:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For years, passwords were the only thing that mattered for securing our online presence, but the discussion around authentication is evolving rapidly. Passkeys, biometrics, device trust, and adaptive identity management solutions are often cited as the key to the next…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/passwordless-security-and-the-new-identity-battleground/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/passwordless-security-and-the-new-identity-battleground/">Passwordless security and the new identity battleground</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Expert panel: Passwordless security and the new identity battleground]]></title>
<description><![CDATA[For years, passwords were the only thing that mattered for securing our online presence, but the discussion around authentication is evolving rapidly. Passkeys, biometrics, device trust, and adaptive identity management solutions are often cited as the key to the next level of security, while att...]]></description>
<link>https://tsecurity.de/de/3547101/it-security-nachrichten/expert-panelpasswordlesssecurity-and-the-new-identity-battleground/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547101/it-security-nachrichten/expert-panelpasswordlesssecurity-and-the-new-identity-battleground/</guid>
<pubDate>Tue, 26 May 2026 09:07:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For years, passwords were the only thing that mattered for securing our online presence, but the discussion around authentication is evolving rapidly. Passkeys, biometrics, device trust, and adaptive identity management solutions are often cited as the key to the next level of security, while attackers are focusing on directly targeting our identity infrastructure. Session hijacking, [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security experts caution MFA alone can no longer stop threat actors]]></title>
<description><![CDATA[Cybersecurity experts are warning enterprise admins about an increasing number of phishing campaigns aimed at stealing Microsoft 365 (M365) access tokens to bypass multifactor authentication login protection.



Phishing kits aimed at capturing M365 tokens aren’t new; some reports say these kits ...]]></description>
<link>https://tsecurity.de/de/3546742/it-security-nachrichten/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546742/it-security-nachrichten/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors/</guid>
<pubDate>Tue, 26 May 2026 05:21:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Cybersecurity experts are warning enterprise admins about an increasing number of phishing campaigns aimed at stealing Microsoft 365 (M365) access tokens to bypass multifactor authentication login protection.</p>



<p>Phishing kits aimed at capturing M365 tokens aren’t new; some reports say these kits have been around since 2021. One of the latest is <a href="https://www.csoonline.com/article/4153742/eviltokens-abuses-microsoft-device-code-flow-for-account-takeovers.html" target="_blank">EvilTokens</a>, which <a href="https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/" target="_blank" rel="noreferrer noopener">researchers at Sekoia say</a> has been circulating since February. And earlier this month, Microsoft also <a href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/" target="_blank" rel="noreferrer noopener">issued a warning</a> about other adversary-in-the middle phishing schemes that steal authentication tokens, and, separately, about <a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/" target="_blank" rel="noreferrer noopener">campaigns that exploit OAuth protocol functionality</a> to manipulate URL redirection to bypass conventional phishing defenses.</p>



<h2 class="wp-block-heading">Lowers the barrier to entry</h2>



<p>But, said the US Federal Bureau of Investigation (FBI) <a href="https://www.ic3.gov/PSA/2026/PSA260521" target="_blank" rel="noreferrer noopener">in a warning last week</a>, the new <a href="https://www.csoonline.com/article/4176464/fbi-warns-of-kali-oauth-stealers.html" target="_blank">Kali365</a> phishing-as-a-service platform “lowers the barrier of entry, providing less technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.”</p>



<p>It’s increasingly being leveraged by threat actors. On April 24, for example, security vendor Arctic Wolf said that it had detected <a href="https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/" target="_blank" rel="noreferrer noopener">a large-scale device code phishing campaign</a> impacting organizations that was run by a threat actor using the Kali365 service. Four days later, researchers at Gurucul <a href="https://gurucul.com/latest-threats/new-kali365-phaas-kit-being-abused-in-the-wild/" target="_blank" rel="noreferrer noopener">issued a similar warning</a>, adding the new Kali365 kit “is rapidly becoming a preferred weapon” of threat actors. Both Kali365 and EvilTokens platforms trick employees into entering a code on a legitimate Microsoft login page that allows attackers to steal OAuth tokens.</p>



<p>But, Gurucul warned CSOs, “[Kali365] signals a shift toward highly professionalized attack models.” The researchers noted, “This is not just a single hacker working in isolation. Instead, it is a full-scale commercial operation. It is designed to lower the barrier for entry for criminals globally. By providing a ready-made infrastructure for deception, this kit places sophisticated capabilities in the hands of novice attackers.”</p>



<h2 class="wp-block-heading">Move beyond MFA as a ‘checklist item’</h2>



<p>CSOs should take the warnings as a reminder that phishing detection lessons are an essential part of security awareness training for all employees.</p>



<p>The FBI caution “[also] reminds us that multifactor authentication is no longer the single step that must be present for protection,” said <a href="https://www.digitaldefence.ca/company/" target="_blank" rel="noreferrer noopener">Robert Beggs</a>, CEO of Canadian incident response firm Digital Defence.</p>



<p>“Organizations have to move beyond having it as a ‘checklist item’ and instead focus on a defense in depth approach. Organizations have to block or tightly restrict Microsoft’s <a href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code" target="_blank" rel="noreferrer noopener">OAuth device code authentication flow</a> using Conditional Access. Additional controls include revoking OAuth tokens proactively, monitoring for unauthorized device registrations, and monitoring to detect new or malicious inbox rules.”</p>



<h2 class="wp-block-heading">Professional attack model</h2>



<p>The Kali365 service provides templates, management dashboards, and integrated tools that lower the skill barrier for implementing large-scale attacks to the threat actor subscribing to it. Subscriptions start at $250 for 30 days and go up to $2,000 for 365 days.</p>



<p>Once signed up, Arctic Wolf said, Kali365 affiliates can rapidly generate branded phishing lures impersonating common enterprise services such as Adobe Acrobat Sign, DocuSign, and SharePoint. The service includes a modular lure‑generation system that allows threat actors to produce hundreds of distinct variants by mixing language localization, presentation layout, Microsoft‑ecosystem impersonations, and multiple document formats in English, Spanish, French, German, Portuguese, Italian, Dutch, Japanese, Korean, Chinese, Arabic, Turkish, Polish, and Russian.</p>



<p>Beggs noted that the use of AI generated phishing lures, assuming the AI has been properly trained against the client business and supplied with the correct cultural contexts, results in trustworthy-appearing documents that are difficult to identify and block in a large-scale attack.</p>



<p>Subscribers can take advantage of eight hard-coded email templates, with subject lines like “Voicemail from [with room for a name]”, “Signature Required,” “Invoice #INV,”, “Document Shared,” and “Account notification for [with room for an email address].”</p>



<p>Arctic Wolf said it has also seen cases where, after gaining initial access, the threat actor created malicious inbox rules within Microsoft 365, configuring rules that automatically moved emails containing keywords such as “spam,” “phish,” “click,” “link,” and “SharePoint” to a separate folder and marked them as read. This behavior effectively suppressed security-related notifications and warnings to the user, enabling the threat actor to maintain access while reducing the likelihood of detection.</p>



<p>In device code mode, victims are redirected to an obfuscated landing page that is designed to only render in a real browser session. Upon page load, the Kali365 backend dynamically generates a legitimate Microsoft OAuth device code<strong>.</strong></p>



<p>According to the FBI, the attack then works like many other phishing scams: An attacker sends a phishing email with a message that includes a link to a legitimate Microsoft verification page, and instructions to enter the generated code. This code authorizes the attacker’s device to access the victim’s account. The Kali365 backend then captures OAuth access and refresh tokens, giving the threat actor access to the targeted individual’s/entity’s Microsoft 365 account, including Outlook, Teams, and OneDrive, until the compromise is detected and the tokens revoked. Using those tokens, the attacker doesn’t need to enter a password or complete any additional MFA challenges.</p>



<p>In some cases, Arctic Wolf added, following token acquisition, the threat actor would use the authenticated session to register an additional device within the victim’s Microsoft environment. This step extended access beyond the initial token by establishing a trusted device association tied to the compromised account.</p>



<h2 class="wp-block-heading">Mitigation</h2>



<p>In its alert, the FBI urged Microsoft 365 admins to restrict device code flow, since limiting or blocking device authentication codes can help prevent or minimize this style of attack. They should also create conditional access policies to block device code flow for all users, with limited exceptions for required business processes; audit existing device code flow usage to identify legitimate dependencies before creating a conditional access policy; and block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices.</p>



<p>If an admin cannot completely restrict device code flow usage, the FBI says they should exclude emergency access accounts to prevent lockouts.</p>



<p><a href="https://cybercrimeanalytics.com/about/" target="_blank" rel="noreferrer noopener">Christopher Kayser</a>, CEO at Cybercrime Analytics and author of the book <em>Cybercrime Through Social Engineering</em>, said IT departments must find ways to reinforce to employees that they should not be quick to click on communications that seem unusual or potentially fraudulent. And it’s not just ordinary employees who can be hit by phishing scams, he pointed out. Higher levels of management with authority to transfer funds are targeted by business email compromise (BEC) scams.</p>



<p>Typically, he added, when signing into M365, users aren’t asked to input a code; they should be reminded that an email that asks for a code should be a red flag that triggers a call to the IT department.</p>



<h2 class="wp-block-heading">Identity-centric security is key</h2>



<p><a href="https://www.infotech.com/profiles/fritz-jean-louis" target="_blank" rel="noreferrer noopener">Fritz Jean-Louis</a>, principal cybersecurity advisor at Info-Tech Research Group, said defenders should shift to identity-centric security and treat phishing primarily as an identity compromise risk.</p>



<p>This not only means enforcing phishing-resistant MFA through passkeys or other FIDO2 approved login measures, but also strengthening session controls, and monitoring for anomalous authentication behavior, including token misuse and suspicious OAuth activity.</p>



<p>Admins should also adopt continuous access evaluation, moving beyond point-in-time authentication by dynamically assessing user and device risk throughout active sessions, enabling real-time response to evolving threats.</p>



<p>In addition, responders should leverage behavioral signals by measuring activity and encouraging users to report suspect behavior, and incorporating human telemetry, such reporting speed and interaction patterns, into detection strategies.</p>



<p>Jean-Louis said admins also need to reduce their organization’s blast radius by implementing stronger outbound monitoring, automated containment triggers, and tighter controls on account misuse, to limit lateral spread.</p>



<p>Finally, he recommended that admins segment high-risk users and functions by applying enhanced security controls and providing isolated environments for executives, finance, and privileged IT roles.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passwortmanager Enpass: Mac-App komplett überarbeitet]]></title>
<description><![CDATA[Der Passwortmanager Enpass hat seine desktop-Anwendung für macOS umfassend überarbeitet. Mit Version 6.12 erhält die App eine neue Oberfläche, die sich stärker am aktuellen Designs des Mac-Betriebssystems orientiert. Nach Angaben des Anbieters steht dabei nicht nur die optische Modernisierung im ...]]></description>
<link>https://tsecurity.de/de/3545040/ios-mac-os/passwortmanager-enpass-mac-app-komplett-ueberarbeitet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545040/ios-mac-os/passwortmanager-enpass-mac-app-komplett-ueberarbeitet/</guid>
<pubDate>Mon, 25 May 2026 09:56:25 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/passwortmanager-enpass-mac-app-komplett-ueberarbeitet-280367/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/05/enpass-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="Enpass Feature" decoding="async"></a><p>Der Passwortmanager Enpass hat seine desktop-Anwendung für macOS umfassend überarbeitet. Mit Version 6.12 erhält die App eine neue Oberfläche, die sich stärker am aktuellen Designs des Mac-Betriebssystems orientiert. Nach Angaben des Anbieters steht dabei nicht nur die optische Modernisierung im Vordergrund. Auch häufig genutzte Abläufe wurden angepasst, um die Verwaltung von Passwörtern, Passkeys und anderen […]</p>
<p>The post <a href="https://www.ifun.de/passwortmanager-enpass-mac-app-komplett-ueberarbeitet-280367/">Passwortmanager Enpass: Mac-App komplett überarbeitet</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys einsetzen: Ein Leitfaden für CISOs und Verantwortliche - B2B Cyber Security]]></title>
<description><![CDATA[Digitale Sicherheitskonzepte mit Passwortschutz und Cybersecurity-Tools. Anzeige. Beitrag teilen.]]></description>
<link>https://tsecurity.de/de/3543270/it-security-nachrichten/passkeys-einsetzen-ein-leitfaden-fuer-cisos-und-verantwortliche-b2b-cyber-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543270/it-security-nachrichten/passkeys-einsetzen-ein-leitfaden-fuer-cisos-und-verantwortliche-b2b-cyber-security/</guid>
<pubDate>Sun, 24 May 2026 10:35:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Digitale Sicherheitskonzepte mit Passwortschutz und Cybersecurity-Tools. Anzeige. Beitrag teilen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zu anfällig für Betrug: Microsoft schafft 2-Faktor-Authentifizierung ab und setzt auf Passkeys]]></title>
<description><![CDATA[Microsoft will Nutzer besser vor Passwortdiebstahl schützen: Bald sollen keine Codes per SMS mehr für den Login verschickt werden.]]></description>
<link>https://tsecurity.de/de/3540275/downloads/zu-anfaellig-fuer-betrug-microsoft-schafft-2-faktor-authentifizierung-ab-und-setzt-auf-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540275/downloads/zu-anfaellig-fuer-betrug-microsoft-schafft-2-faktor-authentifizierung-ab-und-setzt-auf-passkeys/</guid>
<pubDate>Fri, 22 May 2026 18:46:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img align="right" alt="" width="60" height="34" src="https://quadro.burda-forward.de/ctf/c016954c-d12c-4aaa-b125-1c0c2510658f.4345e24c-f9a7-43de-8bdc-4f0fd912ae1b.jpg?im=AspectCrop%2Csize%3D%2830%2C+17%29%2Cgravity%3DCenter%2CallowExpansion%3BResize%3D%2860%2C+34%29%2Caspect%3Dfit%3BBackgroundColor%2Ccolor%3Dffffff&amp;impolicy=chip&amp;hash=540d7d30cfd1f24ea1c8d5605ed60e842408bbe3386d289fd62756792d15eec3"> Microsoft will Nutzer besser vor Passwortdiebstahl schützen: Bald sollen keine Codes per SMS mehr für den Login verschickt werden.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Phasing Out SMS Authentication Codes for Personal Accounts in Favor of Passkeys]]></title>
<description><![CDATA[Microsoft has announced that it will discontinue SMS-based authentication and account recovery for personal Microsoft accounts. Thank you for being a Ghacks reader. The post Microsoft Phasing Out SMS Authentication Codes for Personal Accounts in Favor of Passkeys appeared first…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3539022/it-security-nachrichten/microsoft-phasing-out-sms-authentication-codes-for-personal-accounts-in-favor-of-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539022/it-security-nachrichten/microsoft-phasing-out-sms-authentication-codes-for-personal-accounts-in-favor-of-passkeys/</guid>
<pubDate>Fri, 22 May 2026 11:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft has announced that it will discontinue SMS-based authentication and account recovery for personal Microsoft accounts. Thank you for being a Ghacks reader. The post Microsoft Phasing Out SMS Authentication Codes for Personal Accounts in Favor of Passkeys appeared first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-phasing-out-sms-authentication-codes-for-personal-accounts-in-favor-of-passkeys/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-phasing-out-sms-authentication-codes-for-personal-accounts-in-favor-of-passkeys/">Microsoft Phasing Out SMS Authentication Codes for Personal Accounts in Favor of Passkeys</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft won't send you SMS texts for login anymore - why it's pushing passkeys instead]]></title>
<description><![CDATA[Text messages are a weak, vulnerable way to authenticate account logins. Soon, you'll have to switch to one of these safer, more secure methods.]]></description>
<link>https://tsecurity.de/de/3536927/it-security-nachrichten/microsoft-wont-send-you-sms-texts-for-login-anymore-why-its-pushing-passkeys-instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536927/it-security-nachrichten/microsoft-wont-send-you-sms-texts-for-login-anymore-why-its-pushing-passkeys-instead/</guid>
<pubDate>Thu, 21 May 2026 17:26:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Text messages are a weak, vulnerable way to authenticate account logins. Soon, you'll have to switch to one of these safer, more secure methods.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft schafft SMS-Verifizierung für private Microsoft-Konten in Kürze ab]]></title>
<description><![CDATA[Seit einiger Zeit ist es möglich, sich bei der Anmeldung in einem Microsoft-Konto durch einen per SMS empfangenen sechsstelligen Code zu authentifizieren. Windows Latest berichtet nun, dass die SMS-Verifizierung in Kürze auslaufen wird.



Es sieht so aus, als wolle Microsoft, dass Nutzer, die si...]]></description>
<link>https://tsecurity.de/de/3532183/it-nachrichten/microsoft-schafft-sms-verifizierung-fuer-private-microsoft-konten-in-kuerze-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532183/it-nachrichten/microsoft-schafft-sms-verifizierung-fuer-private-microsoft-konten-in-kuerze-ab/</guid>
<pubDate>Wed, 20 May 2026 10:32:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Seit einiger Zeit ist es möglich, sich bei der Anmeldung in einem Microsoft-Konto durch einen per SMS empfangenen sechsstelligen Code zu authentifizieren. Windows Latest <a href="https://www.windowslatest.com/2026/05/19/microsoft-is-killing-sms-codes-for-microsoft-account-sign-in-aggressively-pushes-passkeys-on-windows-11/">berichtet </a>nun, dass die SMS-Verifizierung in Kürze auslaufen wird.</p>



<p>Es sieht so aus, als wolle Microsoft, dass Nutzer, die sich noch auf die SMS-Verifizierung verlassen, künftig stattdessen auf <a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html">Passkeys </a>umsteigen. Dies kommt jedoch nicht überraschend, da Microsoft bereits vor einem Jahr damit begonnen hat, <a href="https://www.pcwelt.de/article/2770526/microsoft-zwingt-neuen-nutzern-login-ohne-passwort-auf.html" target="_blank" rel="noreferrer noopener">Passkeys für neue Microsoft-Konten vorzuschreiben.</a></p>



<p>Im Gegensatz zu einem Passwort, das lediglich aus einer Zeichenfolge besteht, die von Hackern gestohlen oder erraten werden kann, besteht ein Passkey tatsächlich aus zwei einzigartigen Schlüsseln: Ein Schlüssel wird auf Ihrem Gerät gespeichert und durch biometrische Daten (z. B. Gesichtserkennung, Fingerabdrücke oder PIN-Codes) geschützt, der andere Schlüssel wird von der Website, der App oder dem Dienst verwaltet, für den Sie ein Benutzerkonto erstellt haben. Für eine erfolgreiche Anmeldung sind beide Schlüssel erforderlich.</p>



<p>Der Umstieg auf Passkeys ist der klügste Schritt, den Sie für Ihre digitale Sicherheit unternehmen können, insbesondere wenn Sie noch SMS-Codes verwenden. Denn SMS-Authentifizierungscodes sind nicht sicher: Experten warnen: <a href="https://www.pcwelt.de/article/2563603/sicherheitsexperten-warnen-vor-zwei-faktor-authentifizierung.html" target="_blank" rel="noreferrer noopener">Darum sollten Sie keine Zwei-Faktor-Authentifizierung mit SMS nutzen.</a> Und Microsoft sagt ganz offen: „SMS-basierte Authentifizierung ist mittlerweile eine der Hauptursachen für Betrug“.</p>



<p>Leider hat Microsoft außer dem Wort „bald“ keinen konkreten Zeitplan für die Abschaffung der SMS-Authentifizierung genannt. Daher sollten Sie dies als Priorität behandeln und so schnell wie möglich umstellen.</p>



<p>Was ist, wenn Sie keine Passkeys verwenden können, beispielsweise wenn Sie versuchen, sich auf einer virtuellen Maschine bei Windows anzumelden? Zum Zeitpunkt der Erstellung dieses Artikels gibt es keine klare Antwort darauf. Microsoft scheint entschlossen zu sein, Passkeys durchzusetzen, und wir können nur abwarten, wie das Unternehmen die Anmeldungen in Fällen ohne Passkeys regeln wird.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft schafft SMS-Codes für private Konten ab]]></title>
<description><![CDATA[Microsoft stellt die SMS-Verifizierung für private Konten ein. Nutzer müssen künftig auf sicherere Alternativen wie Passkeys umsteigen.

Tags: #Cyber Security | #Microsoft | #Passkeys]]></description>
<link>https://tsecurity.de/de/3532089/it-security-nachrichten/microsoft-schafft-sms-codes-fuer-private-konten-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532089/it-security-nachrichten/microsoft-schafft-sms-codes-fuer-private-konten-ab/</guid>
<pubDate>Wed, 20 May 2026 09:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_.jpg" class="attachment-full size-full wp-post-image" alt="microsoft" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/07/Microsoft-Authenticator-1920-shttuerstock-2609416765-quelle-PJ_McDonnell-Shutterstock.com_-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Microsoft schafft SMS-Codes für private Konten ab 1"></p>
    Microsoft stellt die SMS-Verifizierung für private Konten ein. Nutzer müssen künftig auf sicherere Alternativen wie Passkeys umsteigen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/microsoft">#Microsoft</a> | <a href="https://www.it-daily.net/thema/passkeys">#Passkeys</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft plans to end SMS two-factor authentication, potentially setting the pace for a passwordless Windows 11 future: "SMS as MFA is horribly vulnerable on multiple fronts."]]></title>
<description><![CDATA[Microsoft is pulling the plug on SMS-based two-factor authentication because it has become a leading source of fraud, replacing it with passkeys and verified email.]]></description>
<link>https://tsecurity.de/de/3530638/windows-tipps/microsoft-plans-to-end-sms-two-factor-authentication-potentially-setting-the-pace-for-a-passwordless-windows-11-future-sms-as-mfa-is-horribly-vulnerable-on-multiple-fronts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530638/windows-tipps/microsoft-plans-to-end-sms-two-factor-authentication-potentially-setting-the-pace-for-a-passwordless-windows-11-future-sms-as-mfa-is-horribly-vulnerable-on-multiple-fronts/</guid>
<pubDate>Tue, 19 May 2026 21:54:05 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft is pulling the plug on SMS-based two-factor authentication because it has become a leading source of fraud, replacing it with passkeys and verified email.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft finally ends using SMS codes for account sign-in — with passkeys officially taking over]]></title>
<description><![CDATA[Microsoft believes that the future of authentication is passwordless, secure, and user-friendly.]]></description>
<link>https://tsecurity.de/de/3529979/it-nachrichten/microsoft-finally-ends-using-sms-codes-for-account-sign-in-with-passkeys-officially-taking-over/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529979/it-nachrichten/microsoft-finally-ends-using-sms-codes-for-account-sign-in-with-passkeys-officially-taking-over/</guid>
<pubDate>Tue, 19 May 2026 18:47:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft believes that the future of authentication is passwordless, secure, and user-friendly.]]></content:encoded>
</item>
<item>
<title><![CDATA[MiniPlasma-Exploit und Exchange-Zero-Day: Microsofts Sicherheitsalptraum - BornCity]]></title>
<description><![CDATA[... Microsoft Exchange Server. Die Schwachstelle mit der Kennung CVE-2026 ... Microsoft drängt auf die Einführung von Passkeys unter Windows 11 ...]]></description>
<link>https://tsecurity.de/de/3529968/windows-server/miniplasma-exploit-und-exchange-zero-day-microsofts-sicherheitsalptraum-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529968/windows-server/miniplasma-exploit-und-exchange-zero-day-microsofts-sicherheitsalptraum-borncity/</guid>
<pubDate>Tue, 19 May 2026 18:45:54 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Microsoft Exchange <b>Server</b>. Die Schwachstelle mit der Kennung CVE-2026 ... Microsoft drängt auf die Einführung von Passkeys unter <b>Windows</b> 11 ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft schafft SMS-Codes bei privaten Konten schrittweise ab]]></title>
<description><![CDATA[Microsoft will bei privaten Microsoft-Konten künftig auf SMS als Methode für Anmeldung und Kontowiederherstellung verzichten. Das Ganze passiert nicht von heute auf morgen, die Richtung ist aber klar, weg von SMS, hin zu Passkeys und verifizierten E-Mail-Adressen. Das ist aus...Zum Beitrag: Micro...]]></description>
<link>https://tsecurity.de/de/3529443/it-nachrichten/microsoft-schafft-sms-codes-bei-privaten-konten-schrittweise-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529443/it-nachrichten/microsoft-schafft-sms-codes-bei-privaten-konten-schrittweise-ab/</guid>
<pubDate>Tue, 19 May 2026 16:18:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft will bei privaten Microsoft-Konten künftig auf SMS als Methode für Anmeldung und Kontowiederherstellung verzichten. Das Ganze passiert nicht von heute auf morgen, die Richtung ist aber klar, weg von SMS, hin zu Passkeys und verifizierten E-Mail-Adressen. Das ist aus...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/microsoft-schafft-sms-codes-bei-privaten-konten-schrittweise-ab/">Microsoft schafft SMS-Codes bei privaten Konten schrittweise ab</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei-Faktor-Authentifizierung: Microsoft streicht den Weg über SMS]]></title>
<description><![CDATA[Microsoft beendet den Versand von SMS-Codes für die Anmeldung bei privaten Konten. Der Konzern stuft das Verfahren wegen der Gefahr durch SIM-Swapping als Sicherheitsrisiko ein. Nutzer müssen nun auf moderne Passkeys oder Authentifizierungs-Apps umsteigen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3528550/it-security-nachrichten/zwei-faktor-authentifizierung-microsoft-streicht-den-weg-ueber-sms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528550/it-security-nachrichten/zwei-faktor-authentifizierung-microsoft-streicht-den-weg-ueber-sms/</guid>
<pubDate>Tue, 19 May 2026 11:37:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158775.html"><img hspace="5" border="0" align="left" alt="Design, Interface, Ui, Windows 11 24H2, Login, Windows hello, Windows 11 23h2, Passkey" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/77257.png"></a>
			Microsoft beendet den Versand von SMS-Codes für die Anmeldung bei privaten Konten. Der Konzern stuft das Verfahren wegen der Gefahr durch SIM-Swapping als Sicherheitsrisiko ein. Nutzer müssen nun auf moderne Passkeys oder Authentifizierungs-Apps umsteigen.			(<a href="https://winfuture.de/news,158775.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is killing SMS codes for Microsoft account sign-in, aggressively pushes passkeys on Windows 11]]></title>
<description><![CDATA[Microsoft is phasing out SMS authentication for personal accounts, citing SIM-swap fraud and phishing risks. While the tech giant pushes users toward biometric passkeys and passwordless logins, the death of text message verification could cause serious headaches for developers and power users.
Th...]]></description>
<link>https://tsecurity.de/de/3527485/windows-tipps/microsoft-is-killing-sms-codes-for-microsoft-account-sign-in-aggressively-pushes-passkeys-on-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527485/windows-tipps/microsoft-is-killing-sms-codes-for-microsoft-account-sign-in-aggressively-pushes-passkeys-on-windows-11/</guid>
<pubDate>Tue, 19 May 2026 01:38:08 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft is phasing out SMS authentication for personal accounts, citing SIM-swap fraud and phishing risks. While the tech giant pushes users toward biometric passkeys and passwordless logins, the death of text message verification could cause serious headaches for developers and power users.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/05/19/microsoft-is-killing-sms-codes-for-microsoft-account-sign-in-aggressively-pushes-passkeys-on-windows-11/">Microsoft is killing SMS codes for Microsoft account sign-in, aggressively pushes passkeys on Windows 11</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker nutzen KI: Die neue Welle der Cyberangriffe rollt - Ad-hoc-news.de]]></title>
<description><![CDATA[Hacker nutzen KI für täuschend echte Angriffe. Quishing und Device-Code-Phishing steigen rasant, während Tech-Riesen auf Passkeys setzen.]]></description>
<link>https://tsecurity.de/de/3526859/hacking/hacker-nutzen-ki-die-neue-welle-der-cyberangriffe-rollt-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526859/hacking/hacker-nutzen-ki-die-neue-welle-der-cyberangriffe-rollt-ad-hoc-newsde/</guid>
<pubDate>Mon, 18 May 2026 19:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> nutzen KI für täuschend echte Angriffe. Quishing und Device-Code-Phishing steigen rasant, während Tech-Riesen auf Passkeys setzen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Reportedly Testing Passkey Transfer Support in Google Password Manager]]></title>
<description><![CDATA[Google is said to be working on allowing users to move passkeys stored on their Android handset across apps. The company could soon add options in the Password Manager for importing and exporting both passwords and passkeys. The currently available "Import passwords and Export passwords options w...]]></description>
<link>https://tsecurity.de/de/3525359/it-nachrichten/google-reportedly-testing-passkey-transfer-support-in-google-password-manager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525359/it-nachrichten/google-reportedly-testing-passkey-transfer-support-in-google-password-manager/</guid>
<pubDate>Mon, 18 May 2026 11:02:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google is said to be working on allowing users to move passkeys stored on their Android handset across apps. The company could soon add options in the Password Manager for importing and exporting both passwords and passkeys. The currently available "Import passwords and Export passwords options will soon be replaced by new Import passwords &amp; passkeys and Export pas...]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows als Schlüssel: Entra Passkeys kommen - IT-Administrator.de]]></title>
<description><![CDATA[Bislang setzt Microsoft Windows Hello for Business als bevorzugte ... Eine präparierte E-Mail genügt: In Microsoft Exchange Server klafft ...]]></description>
<link>https://tsecurity.de/de/3522194/windows-server/windows-als-schluessel-entra-passkeys-kommen-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3522194/windows-server/windows-als-schluessel-entra-passkeys-kommen-it-administratorde/</guid>
<pubDate>Sat, 16 May 2026 15:30:53 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bislang setzt Microsoft <b>Windows</b> Hello for Business als bevorzugte ... Eine präparierte E-Mail genügt: In Microsoft Exchange <b>Server</b> klafft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Welcome to BlackFile: Inside a Vishing Extortion Operation]]></title>
<description><![CDATA[Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo

Introduction 
Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice ...]]></description>
<link>https://tsecurity.de/de/3520439/it-security-nachrichten/welcome-to-blackfile-inside-a-vishing-extortion-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520439/it-security-nachrichten/welcome-to-blackfile-inside-a-vishing-extortion-operation/</guid>
<pubDate>Fri, 15 May 2026 19:07:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructure, leveraging Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data for subsequent extortion attempts. This post details UNC6671’s attack lifecycle and provides defenders with actionable guidance to detect and mitigate these identity-centric threats.</span></p>
<p><span>Since emerging in early 2026, UNC6671 has maintained a high operational cadence. GTIG assesses that the group has targeted dozens of organizations across North America, Australia, and the UK.</span></p>
<p><span>GTIG previously highlighted UNC6671 as a distinct cluster in a</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft"><span>prior report</span></a><span> detailing similar SaaS data-theft techniques utilized by ShinyHunters (UNC6240). While UNC6671 has co-opted the ShinyHunters brand in at least one instance to inject artificial credibility into their threats, GTIG assesses that the operations are independent. This distinction is supported by UNC6671's use of separate TOX communication channels, unique domain registration patterns, and the launch of a dedicated "BlackFile" data leak site (DLS).</span></p>
<p><span>These compromises are not the result of a security vulnerability in vendor products or infrastructure. Instead, this campaign continues to highlight the effectiveness of social engineering and underscores the critical importance of organizations</span> <a href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc" rel="noopener" target="_blank"><span>moving toward phishing-resistant MFA</span></a><span> to protect their SaaS and identity platforms</span>.</p>
<h3><span>Initial Access</span></h3>
<p><span>UNC6671 initial access operations rely on high-volume voice phishing (vishing), often characterized by meticulous social engineering tactics, synchronized with real-time credential harvesting. These vishing calls are typically made by "callers" hired by the threat actor. </span></p>
<h4><span>IT Deployment Pretext</span></h4>
<p><span><span>The callers often call targeted employees' personal cellular phones to bypass security tooling and move the victim away from standard support channels. They typically masquerade as internal IT or help desk personnel, citing a mandatory migration to passkeys or a required multi-factor authentication (MFA) update. This pretext justifies directing the victim to a credential harvesting site and provides a logical cover for any subsequent security alerts generated during the compromise. UNC6671 has shifted from unique, organization-tailored credential harvesting domains to a subdomain-based model. <span>These domains are typically registered with Tucows. </span></span><span> Recent campaigns have used subdomains explicitly referencing "passkey" or "enrollment" themes to enhance the legitimacy of the help desk pretext</span>.</span></p>
<ul>
<li role="presentation"><code>&lt;organization&gt;.enrollms[.]com</code></li>
<li role="presentation"><code>&lt;organization&gt;.passkeyms[.]com</code></li>
<li role="presentation"><code>&lt;organization&gt;.setupsso[.]com</code></li>
</ul>
<h4><span>Real-Time MFA Interception</span></h4>
<p><span>The vishing call functions as a live adversary-in-the-middle (AitM) attack. The process follows a rapid, procedural lifecycle</span><span>:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Redirection</strong><span>: The victim is directed to a lookalike subdomain mirroring the organization's single sign-on (SSO) portal.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Credential Capture</strong><span>: As the victim inputs their username and password, the threat actor captures these in real-time and immediately submits them to the legitimate SSO provider.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>MFA Bypass</strong><span>: When the legitimate portal issues an MFA challenge (Push, SMS, or TOTP), the victim—believing they are completing a setup step—provides the code or approval to the threat actor.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Device Registration</strong><span>: Upon gaining access, the threat actor immediately navigates to the user's security settings to register a new, attacker-controlled MFA device to ensure persistence.</span></p>
</li>
</ul>
<p><span>The speed of this execution ensures the threat actor can establish a permanent foothold before the victim or the organization's Security Operations Center (SOC) can identify the anomaly.</span></p>
<h3><span>Data Theft</span></h3>
<p><span>Following successful authentication, UNC6671 leverages SSO access to move laterally across the victim's SaaS applications to enable data theft operations. The threat actors appear to be focused on targeting Microsoft 365 and Okta environments, using compromised accounts to access SharePoint, OneDrive, and other connected SaaS applications such as Zendesk and Salesforce. In several instances, the actors specifically queried internal search functions for string literals such as "confidential" and "SSN" to prioritize theft of perceived high-value data.</span></p>
<h4><span>Programmatic Data Exfiltration</span></h4>
<p><span>Upon establishing persistence, UNC6671 transitions from interactive browser-based reconnaissance to automated exfiltration. In multiple engagements, we observed the use of scripts to harvest high-value data from SharePoint and OneDrive repositories.</span></p>
<p><span>In addition to relying on methods that triggered standard FileDownloaded events, the threat actor has also used <span>less conspicuous</span> approaches. These include the threat actor’s use of formal APIs, such as Microsoft Graph</span><span>, as well as  the python-requests library</span><span> and PowerShell to issue direct HTTP GET requests against document resource URLs. Notably, by repurposing valid session cookies (e.g., FedAuth) captured during the initial vishing phase, the actor has been able to "stream" file content directly to attacker-controlled infrastructure.</span></p>
<p><span>In these cases, the request mimics a standard web client fetch rather than a formal "Download" command. As a result, the activity is frequently recorded as a FileAccessed event rather than FileDownloaded. This 'direct fetch' method naturally blends into routine traffic, which may bypass detection in many Security Operations Centers (SOCs) that prioritize FileDownloaded events and treat FileAccessed as benign.</span></p>
<h4><span>Forensic Artifacts and Scripting</span></h4>
<p><span>Analysis of Microsoft 365 Unified Audit Log (UAL) telemetry revealed several consistent forensic indicators of UNC6671 activity, including clear evidence of scripted exfiltration. Most notably, the threat actor frequently showed User-Agent mismatches; while they spoofed the ClientAppId for "Microsoft Office" to bypass basic conditional access filters, the recorded UserAgent strings identified scripting engines such as python-requests/2.28.1 or WindowsPowerShell/5.1. This discrepancy suggests that access was driven by automated scripts rather than human interaction with the SharePoint user interface. Additionally, these access attempts consistently originated from non-standard infrastructure, such as commercial VPN exit nodes and hosting providers.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "CreationTime": "2026-02-24T14:36:15",
  "Operation": "FileDownloaded",
  "Workload": "SharePoint",
  "ClientIP": "179.43.185.226", 
  "UserId": "victim.user@organization.com",
  "UserAgent": "python-requests/2.28.1",
  "ApplicationDisplayName": "Microsoft Office",
  "IsManagedDevice": false,
  "SourceFileName": "2382_REDACTED_MSA_v3.docx",
  "SourceRelativeUrl": "Shared Documents/Legal/MasterMSA/Archive",
  "SiteUrl": "https://organization.sharepoint.com/sites/Legal_Archive/",
  "AppAccessContext": {
    "ClientAppId": "d3590ed6-52b3-4102-aeff-aad2292ab01c",
    "ClientAppName": "Microsoft Office",
    "TokenIssuedAtTime": "1601-01-01T00:00:00"
  }
}</code></pre>
<p><span><span>Figure 1: FileDownloaded event observed in early UNC6671 intrusions</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "CreationTime": "2026-03-18T20:06:41",
  "Operation": "FileAccessed",
  "Workload": "SharePoint",
  "UserId": "victim.user@company.com",
  "ClientIP": "179.43.185.226", 
  "UserAgent": "python-requests/2.28.1",
  "ApplicationDisplayName": "python-requests",
  "IsManagedDevice": false,
  "SourceRelativeUrl": "Shared Documents/Data Analytics/Power BI Version History",
  "SourceFileName": "Weekly Production Report.pbix",
  "SiteUrl": "https://company.sharepoint.com/sites/ProductionOps/",
  "AppAccessContext": {
    "ClientAppName": "python-requests",
    "CorrelationId": "b94b01a2-2019-c000-2262-5ff1d0ff6cc8"
  }
}</code></pre>
<p><span><span>Figure 2: FileAccessed event from later UNC6671 intrusions</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The speed and scale of UNC6671’s data exfiltration also reflects the automated nature of these scripts, which allows the threat actors to exfiltrate massive volumes of data at high speeds. In one case, the threat actor used their Python script from a remote IP to access and download over a million individual files from a victim's SharePoint and OneDrive environments.</span><span> In another case, the threat actor rapidly iterated through tens of thousands of SharePoint file interactions.</span></p>
<h3><span>Extortion</span></h3>
<p><span>UNC6671 conducts highly targeted extortion campaigns, beginning with unbranded ransom notes sent from programmatically generated from consumer  email accounts. Once a victim engages via the unique, encrypted communication channel (such as Tox or Session) provided by the threat actor in the initial ransom note, the operators identify themselves under the "BlackFile" brand. While the operators typically open negotiations with initial demands in the millions of dollars, they often pivot to low six-figure demands when met with active engagement. Notably, while the initial emails typically do not contain errors, at least some follow up emails have contained mistakes suggesting that those are human generated.</span></p>
<p><span>In cases where the operator is met with silence or resistance, the group aggressively escalates pressure. During a recent incident, after the victim was unresponsive, UNC6671 pivoted to an aggressive spam campaign. Using dozens of Gmail accounts with randomly generated usernames, the threat actor flooded employee mailboxes with messages before automated restrictions kicked in based on their sending behavior and their accounts were restricted. We have also observed these threat actors sending threatening voicemails to C-suite executives and, in severe cases, utilizing swatting tactics against company personnel</span>.</p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>Subject:</strong><span> [COMPANY NAME] DATA BREACH 72 HOURS TO CONTACT US <br></span><strong>From:</strong><span> </span><code>[pseudorandom_alphanumeric_string]@gmail.com</code></p>
<p><span>Hello [Company Name] Executives and HR,</span></p>
<p><span>We have managed to export ~[X] TB of data from your network due to your terrible security practices and negligent data storing practices.</span></p>
<p><span>Here is a brief overview of data exported from your network:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>[X]+ GB of internal company files (SharePoint &amp; OneDrive) containing confidential business processes, NDAs, project cost estimates, subcontractor contracts, and HR records.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Tens of thousands of emails from executive mailboxes, including strategic planning documents, litigation history files, government relations correspondence, and confidential project pricing documents.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Complete CRM and support ticket exports (Salesforce &amp; Zendesk) containing hundreds of thousands of customer records, PII, billing details, and communication logs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Complete corporate directory (Entra) dumps including employee names, mobile numbers, job titles, and hierarchy.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>~[X] ServiceNow IT infrastructure records (computers, servers, cloud resources).</span></p>
</li>
</ol>
<p><span>You have exactly 72 hours to contact the [Tox / Session] ID provided below. If you fail to contact the ID provided by us within the timeframe stated, we will be forced to publish your data to the public. We will also be forced to contact each company you work with via the employee team contact phone numbers and email addresses provided and explain how [Company Name] has terrible security protocols and does not care about its customers.</span></p>
<p><span>We are willing to engage in good faith negotiation terms. Upon contacting us, a full list of all data exported from your network will be sent to you for review. You will be able to pick up to 3 files to confirm and verify we have what we are claiming.</span></p>
<p><strong>[Tox / Session] ID:</strong><span> [Unique Alphanumeric String]</span></p>
<p><span>Silence may not always be wise in situations like this. We will not be ignored. Make the right choice and cooperate with us so this can be a learning experience for you.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Figure 3: <span>Generalized example initial unbranded extortion note from UNC6671</span></span></span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>Subject:</strong><span> [COMPANY NAME] DATA BREACH 72 HOURS TO CONTACT US <br></span><strong>From:</strong><span> </span><code>[pseudorandom_alphanumeric_string]@gmail.com</code></p>
<p><span>Dearest executive,</span></p>
<p><span>You have picked to ignore the first deadline to contact us. That is not smart do not ignore us it will only make things worse. We are BlackFile. Do not play games with us. We are giving a final deadline of 72 hours to contact us so we can reach an agreement.</span></p>
<p><span>We copied over [X] TB+ of data from your SharePoint &amp; M365 instance (legal documents, operational documents, client documents, sales documents, development documents, etc) over [X]gb of Salesforce data, full ZenDesk support ticket export for [X]+ customers, ALL ticket history including old and new tickets and their contents. Total taken from your network is over [X]TB+</span></p>
<p><span>Do not be alarmed as you can secure the proteciton of your data by choosing to work with us. Nothing taken from your network has been disclosed to the public or shared with third parties as of now.</span></p>
<p><span>Reach out to us on session to receive all details and evidense that we accessed your network. We will use Session to communicate with you. You can get Session by visiting getsession(.)org</span></p>
<p><span>Reach out to the following ID using Session: <strong>[Unique Session ID]</strong></span></p>
<p><span>Do not reply to this email. Instead alert the rest of your HR and SOC/IT Security Team. We give you a final deadline of 72 hours to confirm reciept that you received this email by contacting us on Session.</span></p>
<p><span>If you fail to contact us a second time then a majority of the emails taken from your network will receive a notification from us explaining you failed to come to an agreement with us to protect your customers PII and other sensitive information. Additionally we will message journalists about this breach and your failure to come to a resolution with us before finally uploading all data taken from you to our blog for the public.</span></p>
<p><span>Do not let a data recovery company tell you not to negotate us we are BlackFile and we do not play games. The data we took from you can seriously damage your reputation if released is it really worth having that happen over ignoring us?</span></p>
<p><span>Blackfile</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Figure 4: <span>Generalized example follow up extortion email which included branding not present in initial messages</span></span></span></p></div>
<div class="block-paragraph_advanced"><h4><span>Evolution of Ransom Notes</span></h4>
<p><span>Throughout their operations in early 2026, UNC6671's ransom notes exhibited an evolution in formatting, branding, and communication methods. Initially, the threat actors used highly aggressive, short-term deadlines, often giving early victims generic 24 or 48 hour windows to respond. This appeared to become more standardized in late January when they gave subsequent targets a strict 72-hour deadline. Their email subject lines also evolved into a formalized, all-caps structure: </span><code>[COMPANY NAME] DATA BREACH 72 HOURS TO CONTACT US</code><span>.</span></p>
<p><span>During this same period, the group’s identity and preferred communication channels shifted. Early extortion emails were unbranded, with the actors demanding contact via Tox (a peer-to-peer instant messaging protocol). By February 2026, the group formally adopted the "BlackFile" moniker and transitioned their communication demands exclusively to Session (a decentralized, privacy-focused messenger), providing victims with Session IDs and client download instructions. Additionally, while early extortion notes were sent from external emails that could easily be flagged by spam filters or ignored, since at least March 2026, UNC6671 <span>has leveraged hijacked internal corporate email and Microsoft Teams accounts</span>. </span></p>
<h5><span>The BlackFile Data Leak Site (DLS)</span></h5>
<p><span>The threat actors launched the BlackFile Data Leak Site (DLS) on February 6, 2026, claiming to operate as "security researchers." Despite maintaining a dedicated DLS, the group's approach to data exposure deviates significantly from the maximum-publicity, high-noise model employed by other actors. UNC6671 does not publicly advertise their leak site or attempt to index it for search engines. Furthermore, the group has typically only leaked limited file samples and directory listings rather than full datasets; to date, GTIG has not observed the actor leak victim data in full.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/blackfile-fig5.max-1000x1000.png" alt="BlackFile DLS">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="zobw2">Figure 5: BlackFile DLS</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/blackfile-fig6.max-1000x1000.png" alt="BlackFile DLS Deletion Process">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="zobw2">Figure 6: BlackFile DLS Deletion Process</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/blackfile-fig7.max-1000x1000.png" alt="BlackFile DLS Shutdown Announcement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="zobw2">Figure 7: BlackFile DLS Shutdown Announcement</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Notably, the BlackFile DLS site went offline in late April 2026, but briefly came back online on May 11, 2026 to share the below message before shutting down again. In this message, the threat actor stated "BlackFile is shutting down… under this name." As of the time of publication, the DLS site is inaccessible.</span></p></div>
<div class="block-paragraph_advanced"><h3><span>Remediation and Hardening</span></h3>
<p><span>GTIG recommends the following mitigations and hunting strategies:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Deploy Credential Guarding: </strong><span>Configure environment-specific protections to catch credential submission at the point of impact. In Google Workspace, enable Password Alert to monitor for corporate password hashes being entered into unauthorized domains. For Microsoft environments, leverage Microsoft Defender's Credential Protection and SmartScreen to intercept submissions on known phishing or low-reputation sites. These automated technical controls act as a final fail-safe, triggering immediate password resets or security alerts when a user inadvertently interacts with a malicious page.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement Phishing-Resistant MFA: </strong><span>Transition away from SMS-based or push-notification MFA. Implement FIDO2-compliant security keys or passkeys, which are resistant to the adversary-in-the-middle (AiTM) and vishing tactics employed by UNC6671.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Monitor IdP Logs:</strong><span> Review identity provider logs for </span><code>system.multifactor.factor.setup</code><span> events that are immediately preceded by user.authentication.auth_via_mfa failures or "Abandoned" challenges.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Correlate Infrastructure:</strong><span> Alert on authentication attempts originating from known commercial VPNs or hosting providers that are abnormal for the user's typical geographic location.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Audit SaaS API Activity:</strong><span> Monitor Microsoft 365, SharePoint, and Salesforce audit logs for anomalous, high-volume file downloads (FileDownloaded or FileAccessed events) originating from generic scripting user agents (e.g., PowerShell, Python).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Monitor User-Agents: </strong><span>Monitor for specific IdP SDK User-Agents on devices not previously associated with a user's profile.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Re-Evaluate "Access" Severity:</strong><span> Security Operations Centers (SOCs) should treat </span><code>FileAccessed</code><span> events with the same criticality as </span><code>FileDownloaded</code><span> when the </span><code>User-Agent</code><span> identifies it as a programming library (Python, Go, etc.) or a command-line tool.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Audit for Direct File Streaming:</strong><span> Monitor for </span><code>FileAccessed</code><span> logs where the </span><code>AppAccessContext</code><span> indicates a headless client or where the volume of "Accessed" files in a short window exceeds human browsing capability.</span></p>
</li>
</ul>
<h3><span>Outlook and Implications</span></h3>
<p><span>The recent shutdown of the BlackFile data leak site (DLS) accompanied by the actors' own declaration that they are shutting down "under this name" signals a possible transition phase rather than a permanent cessation of their threat activity. Historical precedents across the extortion ecosystem demonstrate that major threat clusters commonly rebrand or disperse their operations following disruption or voluntary shutdowns. These events can serve several strategic functions: evading law enforcement or competitor scrutiny, quietly resolving pending extortion cases, or preparing to pivot to a more viable brand while simultaneously also allowing time for the threat actors to retool and/or set up new infrastructure. Even if the BlackFile brand is permanently retired, the techniques leveraged by UNC6671, specifically their focus on data theft from cloud and SaaS environments, represent a highly successful trend in the cyber crime threat landscape that we also highlighted in the </span><a href="https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026#key-findings-for-h2-2025-4-1"><span>Google Cloud H1 2026 Cloud Threat Horizons Report</span></a><span>. Organizations can review our prior blog post with</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas"><span> actionable hardening, logging, and detection recommendations</span></a><span> to help protect against these threats.</span></p>
<h3><span>Indicators of Compromise (IOCs)</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided indicators of compromise (IOCs) in a free </span><a href="https://www.virustotal.com/gui/collection/59b667464a0d3c503320bfa43b165d4633288fd0d4226ff51108ac0f9dd02a97/summary" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users. At the time of publication, identified phishing domains have been added to Google Safe Browsing.</span></p>
<p><span>While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking.</span></p>
<h3><span>Google Security Operations (SecOps)</span></h3>
<p><span>Google SecOps customers have access to broad category rules under the Okta and O365 rule packs that detect the behaviors outlined in this report. The activity discussed in the blog post is detected in Google SecOps under the following rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta Admin Console Access Failure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta Suspicious Actions from Anonymized IP</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint Bulk File Access or Download via PowerShell</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint High Volume File Access Events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 Sharepoint Query for Proprietary or Privileged Information</span></p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Password Manager: Passkeys lassen sich bald wohl einfacher umziehen]]></title>
<description><![CDATA[Passkeys gelten als sichere Lösung für die Anmeldung bei Webdiensten, hatten bisher unter Android aber einen Haken. Wer seine digitalen Schlüssel im Google Passwortmanager gespeichert hat, kommt dort so einfach nicht wieder weg. Google scheint diesen Lock-in-Effekt nun anzugehen. In...Zum Beitrag...]]></description>
<link>https://tsecurity.de/de/3516990/it-nachrichten/google-password-manager-passkeys-lassen-sich-bald-wohl-einfacher-umziehen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516990/it-nachrichten/google-password-manager-passkeys-lassen-sich-bald-wohl-einfacher-umziehen/</guid>
<pubDate>Thu, 14 May 2026 16:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passkeys gelten als sichere Lösung für die Anmeldung bei Webdiensten, hatten bisher unter Android aber einen Haken. Wer seine digitalen Schlüssel im Google Passwortmanager gespeichert hat, kommt dort so einfach nicht wieder weg. Google scheint diesen Lock-in-Effekt nun anzugehen. In...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/google-password-manager-passkeys-lassen-sich-bald-wohl-einfacher-umziehen/">Google Password Manager: Passkeys lassen sich bald wohl einfacher umziehen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Goodbye, Passwords. Welcome, Passkeys.]]></title>
<description><![CDATA[Passwords have never been very secure, even super complicated ones that are impossible to remember. It’s time to embrace passkeys.]]></description>
<link>https://tsecurity.de/de/3514924/it-security-nachrichten/goodbye-passwords-welcome-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514924/it-security-nachrichten/goodbye-passwords-welcome-passkeys/</guid>
<pubDate>Wed, 13 May 2026 22:23:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passwords have never been very secure, even super complicated ones that are impossible to remember. It’s time to embrace passkeys.]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto bets on identity security for autonomous AI with Idira launch]]></title>
<description><![CDATA[Palo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises.



The company is positioning Idira as a next-generation identity security platform that ...]]></description>
<link>https://tsecurity.de/de/3513683/it-security-nachrichten/palo-alto-bets-on-identity-security-for-autonomous-ai-with-idira-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513683/it-security-nachrichten/palo-alto-bets-on-identity-security-for-autonomous-ai-with-idira-launch/</guid>
<pubDate>Wed, 13 May 2026 14:37:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Palo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises.</p>



<p>The company is positioning Idira as a next-generation identity security platform that goes beyond traditional privileged access management (PAM) systems by applying dynamic privilege controls across every type of identity inside an enterprise.</p>



<p>“For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds,” Peretz Regev, chief product &amp; technology officer at Palo Alto, said in a blog <a href="https://www.paloaltonetworks.com/blog/2026/05/idira-journey-democratize-privilege-controls/" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p>The launch follows Palo Alto’s <a href="https://www.csoonline.com/article/4131325/palo-alto-closes-privileged-access-gap-with-25b-cyberark-acquisition.html?utm=hybrid_search" target="_blank">acquisition</a> and integration of CyberArk, which forms a key foundation of the platform.</p>



<h2 class="wp-block-heading">Palo Alto’s bet on AI-era identity security</h2>



<p>“The fundamental problem today is scale,” said Rohan Vaidya, AVP Sales India and SAARC.  “Most organisations are already running AI agents — and those agents authenticate, call APIs, access sensitive data, and can escalate their own privileges to complete a task. No legacy IAM or PAM platform was designed to see any of that, let alone control it.”</p>



<p>With Idira, Palo Alto attempts to address these risks by treating every identity in the organization as privileged.</p>



<p>“What Idira does differently is operate as a single control plane across all three identity types; human, machine, and agentic. On the discovery side, it continuously scans SaaS, cloud, and developer environments to surface every active agent and machine identity, enriching each one with context: who owns it, what it can access, and what permissions are actually in use. That alone closes a <a href="https://www.csoonline.com/article/4163365/what-cisos-need-to-get-right-as-identity-enters-the-agentic-era.html?utm=hybrid_search">blind spot</a> most security teams don’t even know they have,” Vaidya said.</p>



<p>Analysts say Idira is attempting to address gaps that traditional identity-management platforms such as <a href="https://www.csoonline.com/article/573175/auth0-s-openfga-explained-open-source-universal-authorization.html?utm=hybrid_search">Auth0</a> and SailPoint were not originally designed to handle, particularly around governing autonomous AI agents in real time.</p>



<p>“Auth0 excels at consumer identity and enterprise single sign-on, but its core architecture is not natively designed to govern the dynamic, autonomous nature of generative AI agents. SailPoint, on the other hand, provides excellent AI-driven insights for human access governance, such as role discovery and certification recommendations, but it primarily focuses on lifecycle management and compliance rather than runtime security for autonomous actors,” explained Amit Jaju, senior managing director at Ankura Consulting.</p>



<p>Jaju added that what genuinely sets Idira apart is that instead of granting an agent static access tokens (which Auth0 or SailPoint might manage), Idira dynamically elevates privileges exactly when an agent needs to execute a task and instantly revokes them afterward.</p>



<h2 class="wp-block-heading">CISOs navigate AI risks</h2>



<p>For enterprises, the launch reflects a broader industry shift toward identity-centric cybersecurity models as organizations deploy generative AI tools, autonomous agents, and cloud-native applications at scale.</p>



<p>Analysts say the growing number of non-human identities is creating operational and security challenges because many existing identity systems were originally built to manage employees and IT administrators rather than AI agents and automated services.</p>



<p>“A self-contained AI agent can engage with systems, initiate processes, and make decisions without any form of human validation. This presents a much bigger threat surface. Current technologies that help manage this issue address only some aspects of the problem, many having been built without the intent of handling machine speed, highly dynamic environments,” said Devroop Dhar, co-founder and CEO at Primus Partners.</p>



<p>As identity, cloud security, artificial intelligence governance, and SOC workflows continue to converge, organizations will find themselves becoming more and more reliant on one particular ecosystem, Dhar said. The advantage here is ease of operation, a consolidated view, and greater integration.</p>



<p>The downside is less flexibility over time. Breaking away from the system at a later date may prove challenging since identity management procedures and other processes will be woven deeply into business operations. In the coming years, CISOs will favour ecosystems that support open architectures, Dhar noted.</p>



<p>Analysts also caution that none of the platforms eliminates the need for multilayered security. Organizations will need to maintain good identity hygiene practices, implement least privilege, utilize <a href="https://www.csoonline.com/article/1312195/redefining-multi-factor-authentication-why-we-need-passkeys.html?utm=hybrid_search">MFA</a>, rotate credentials, and conduct constant monitoring.</p>



<p>“Another aspect to address relates to agent governance. There must be a clear understanding of what assets can be accessed by agents, under what circumstances human intervention is required, and how agent activities are monitored,” said Dhar.</p>



<p>Enterprises must invest in prompt filtering systems to prevent prompt injection attacks, which currently stand as the largest vulnerability in AI systems, Jaju said. “They should also engage in continuous adversarial testing and agentic red teaming before deploying any autonomous system into a production environment.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple needs to fix admin authentication in ABM]]></title>
<description><![CDATA[Apple’s platforms are secure by design, but when it comes to authentication, the company seems to be protecting employees more than it protects IT admins. It’s an attack vector just waiting to be exploited — if it hasn’t been already.



As noted first by Six Colors, the problem is that administr...]]></description>
<link>https://tsecurity.de/de/3507593/it-nachrichten/apple-needs-to-fix-admin-authentication-in-abm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507593/it-nachrichten/apple-needs-to-fix-admin-authentication-in-abm/</guid>
<pubDate>Mon, 11 May 2026 17:32:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple’s platforms are secure by design, but when it comes to authentication, the company seems to be protecting employees more than it protects IT admins. It’s an attack vector just waiting to be exploited — if it hasn’t been already.</p>



<p>As noted first by <em><a href="https://sixcolors.com/post/2026/05/apple-in-the-enterprise-a-2026-report-card/" target="_blank" rel="noreferrer noopener">Six Colors</a></em>, the problem is that administrator and People Manager accounts on <a href="https://www.computerworld.com/article/4160334/how-to-think-about-apple-business.html">Apple Business Manager</a> (ABM) <a href="https://support.apple.com/en-ca/guide/apple-business-essentials/welcome/web" target="_blank" rel="noreferrer noopener">can’t sign in using federated authentication</a>, even though they manage the federation process for everyone else. </p>



<h2 class="wp-block-heading"><strong>What are the implications?</strong></h2>



<p>What this means in practice is that when admins engage with the authentication process, they need to do so using non-federated Apple Account sign-in with Apple’s two‑factor authentication (typically via a trusted device or trusted phone number using SMS/voice). That’s weird; it means the key accounts that manage protection for sometimes thousands of devices are still only protected by a six-digit SMS code sent to a specified phone number. We know that SMS authentication is risky, with three well-known attack paths:</p>



<ul class="wp-block-list">
<li><strong>SIM swapping</strong>, where an assailant contacts your cellular company posing as you and convinces them to transfer your phone number to a SIM in their control. Once that takes place, all your SMS codes go to them.</li>



<li><strong>Phishing</strong>, such as a fake login page that acts normally but intercepts your SMS code once you enter it, capturing and immediately using it to attack your actual account.</li>



<li><strong>Interception</strong>, in which sophisticated, usually nation-state-adjacent attackers exploit the known vulnerabilities of SMS to intercept messages in transit.</li>
</ul>



<p>While it is true most small and mid-size businesses probably don’t need to worry about that third attack possibility, and the second can be mitigated against by being careful never to use a link provided in an email to access key accounts, the first exploit sits within the reach of determined attackers.</p>



<h2 class="wp-block-heading"><strong>A hole in the bucket</strong></h2>



<p>The consequences of a successful attack can be serious. Equipped with a compromised ABM account, an attacker could reassign enrolled devices to an MDM server they control, wipe devices, or push malicious apps/profiles or configurations at your devices. Those outcomes are, shall we say, sub-optimal.</p>



<p>I’m certain Apple has thought about this. It has, after all, introduced a range of security protections for all its devices, including managed devices. But in this case, it’s left things a little exposed. That weakness is made more critical because Apple’s system permits just a small number of administrators for each ABM setup, regardless of company size. </p>



<p>As a result, an attacker might be able to penetrate a company with perhaps tens of thousands of users simply by identifying five names to target with any/all of the above attacks. Apple does not need to leave this hole in its security bucket.</p>



<h2 class="wp-block-heading"><strong>What can you do to improve protection?</strong></h2>



<p>There are some easy wins when you try to protect your business while using Apple’s existing system:</p>



<ul class="wp-block-list">
<li>The best practice seems to be for admins to use a dedicated phone number that is only used to handle the ABM and never anything else.</li>



<li>The number should have SIM swap protection in place. You might be able to set this up with a call to your carrier to have this applied to the account.</li>



<li>The number of active admin accounts should be limited to a minimum to narrow the target surface.</li>
</ul>



<h2 class="wp-block-heading"><strong>What can Apple do better?</strong></h2>



<p>Apple needs to change things up. Doing so needn’t be horrifically complex, either, as most of these mitigations are already in place elsewhere in its ecosystem. Here are some suggestions:</p>



<ul class="wp-block-list">
<li>Extend authenticator support to ABM admin accounts.</li>



<li>Introduce Passkeys for admin accounts.</li>



<li>Put FIDO2 support in place so admins can use hardware security keys to authenticate, if they choose.</li>



<li>Introduce mitigations such as conditional access, so logins from unexpected locations aren’t respected.</li>



<li>Introduce support for Sign in with Apple, using biometric data to a specific device as a second factor.</li>
</ul>



<p>All of these protections are already available in the Apple ecosystem; all Apple needs is to divert a little of its R&amp;D cash into implementing the same protections in Apple Business Manager. From what I’ve seen, the Apple admin community would rejoice if it did. I imagine the <a href="https://www.computerworld.com/article/4160334/how-to-think-about-apple-business.html">Apple Business team</a> is already lobbying for it to find the resources to do just that.</p>



<p><em>Please follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys Aren’t Nearly as Effective as We Thought]]></title>
<description><![CDATA[I thought I discovered a genuinely novel research technique and even submitted a CFP I’ll have to retract after this. Still, I think there’s little awareness or actual implementation of this technique so I’m putting it out there in a blog for general awareness.I am sitting there a few weeks ago, ...]]></description>
<link>https://tsecurity.de/de/3505271/hacking/passkeys-arent-nearly-as-effective-as-we-thought/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505271/hacking/passkeys-arent-nearly-as-effective-as-we-thought/</guid>
<pubDate>Sun, 10 May 2026 22:07:34 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I thought I discovered a genuinely novel research technique and even submitted a CFP I’ll have to retract after this. Still, I think there’s little awareness or actual implementation of this technique so I’m putting it out there in a blog for general awareness.</p><p>I am sitting there a few weeks ago, thinking through AiTM (Adversary-in-the-Middle) proxy phishing and how most red teams are just hoping their victims don’t choose a FIDO2 phishing-resistant MFA method, and a thought hits me. I am already proxying traffic bidirectionally. Every request the victim sends and every response the IdP sends back goes through my server before either side sees it. Instead of just snooping and intercepting session tokens, what if I just rewrite the server’s response before forwarding it?</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/876/1*w6EKwUfAhs4u4gViefgCJw.png"><figcaption>A <strong>is </strong>for Adversary in the Middle in my latest childrens book.. after all..</figcaption></figure><p>Specifically, what if I rewrite the auth-method picker the IdP renders so the victim never even <strong>sees </strong>the passkey option at all? They would just see push, SMS, TOTP, and password.. something I could intercept. They would pick one, because the picker would look completely normal, and I would capture whatever they picked through the proxy as usual. The cryptography of the passkey would never be engaged. I would not have to defeat anything FIDO2 cares about. I would just edit the menu.</p><p>I built it. Tested end-to-end against Google, Microsoft and Okta. Baked it into the <a href="https://phishu.net/"><strong>PhishU Framework</strong></a>, the spear-phishing simulation and training platform I have been building for over a decade (formerly PhishAPI), as a default capability. I even submitted a CFP to DEF CON, convinced I had something fully unique to demonstrate on stage. 😅</p><p>Then I sat down to research prior work before publishing my long-form blog. Turns out at least one research group and a black hat phishing kit had a similar idea recently.</p><p>The technique even has a name in the public security research lexicon: <strong>Authentication Method Redaction Attacks</strong>. I’ve previously blogged and presented on <a href="https://curtbraz.medium.com/you-aint-got-no-problem-jules-i-m-on-the-multifactor-e05d5e2a6ade">MFA downgrade attacks</a> before, but this is more specific.</p><p>Even though I built mine independently, the convergent finding actually says something interesting about the gap itself. Anyone who looks at bypassing passkey deployments long enough is going to hit the same observation.</p><p>So this writeup is not about discovery. It is about awareness. And there are a few specific pieces of my implementation I have not seen covered in the prior literature, which I will flag as we go.</p><h3>The 95% gap</h3><p>Across Microsoft Entra, Google Workspace, and Okta, <strong>fewer than 5 percent of organizations that rolled out passkeys also enforce phishing-resistant authentication at the policy layer</strong>. The other 95 percent shipped passkey enrollment and called it phishing-resistant authentication. It is not.</p><p>If you are on a security team that pushed passkeys this year, I would bet money you are in that 95 percent. Not because you do not know what you are doing, but because every major IdP’s admin documentation explicitly recommends enrolling a backup factor alongside the passkey for account recovery. SMS. Voice. Push. TOTP. Authenticator app. The vendor literally tells you to do it.</p><p>That backup factor is the entire attack surface.</p><h3>Surface 1: Hide the row</h3><p>When the IdP renders the auth-method picker as clickable HTML, the proxy walks the rendered DOM after page load and removes rows whose text matches passkey labels. “Use your passkey.” “Security key.” “Hardware security key.” Hidden via combined display, visibility, and height styles so sibling JavaScript that iterates the picker does not break, and the victim sees a picker with the phishing-resistant option silently absent. No error. No warning. No UI artifact. Everything else on the page renders unchanged.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*HIXVGilAVAaAn5mdW7sXaw.png"><figcaption>Original picker state before response-side manipulation</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U8Zfu8CeFY7Ph1h1lIt1-A.png"><figcaption>Modified picker state after phishing-resistant options are removed</figcaption></figure><p>This surface is the most-covered one in the public prior art. The Evilginx PoC against GitHub does exactly this, and Push Security’s writeup describes the potential technique. <strong>My contribution at this surface is not the technique itself. It is that PhishU now ships it as an integrated default-on capability inside a defender-side phishing-simulation platform</strong> rather than as a one-off offensive phishlet. Every PhishU customer running an AiTM landing page against an IdP that supports passkeys gets the strip automatically, and the captures land in the same per-user campaign reports as every other engagement result. That packaging matters because defenders need a measurable answer to what would actually happen if this hit our org, not a custom-built tool per simulation.</p><h3>Surface 2: Catch the API</h3><p>The DOM-stripping technique fails on flows that never render a clickable picker. When the IdP invokes <em>navigator.credentials.get</em> directly to launch the browser’s native passkey UI, there is no DOM element to hide. Same problem with Chrome’s conditional UI hint, the autofill-style “Use passkey from another device” suggestion that appears below the email field when the input has <em>autocomplete=“username webauthn”</em> and the page calls <em>navigator.credentials.get</em> with <em>mediation: conditional</em>. That hint surfaces on every page load on the legitimate Google sign-in page even in incognito, and the trigger is browser-native, not DOM-rendered.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDpzJIiQYhoU9TEO_igcVA.png"><figcaption>Chrome’s hybrid-transport “Use passkey from another device” hint as it appears on the legitimate identity provider origin. On the AiTM proxy origin, the WebAuthn API shim catches the underlying API call before the browser surfaces this dropdown.</figcaption></figure><p>The PhishU runtime injects a JavaScript shim at script-load time that intercepts both <em>navigator.credentials.get</em> and <em>navigator.credentials.create</em>. When called with a publicKey argument, that is, a WebAuthn ceremony, the shim returns an immediate rejection with the standard <em>NotAllowedError</em>. Non-WebAuthn credential types (password autofill, federated, OTP) pass through unchanged. The browser receives the rejection before any platform UI surfaces. The conditional UI hint never appears in the autofill dropdown. The native passkey prompt never opens. The page’s existing error-fallback branch fires, the user transitions to use another method or sees the password field, and they sign in the way they always do.</p><p><strong>This is where I will humbly stake a novelty claim</strong>. The published prior art on this attack class focuses on DOM-level picker stripping. WebAuthn API hijacking has been described elsewhere as a malicious-browser-extension technique, but I have not found public coverage of intercepting these calls from inside an AiTM-proxied page via response-injected JavaScript. The WebAuthn API shim is, as far as I can tell, original to PhishU’s implementation. If anyone has a reference that contradicts this, I would genuinely like to see it. I will update this post.</p><h3>Surface 3: The IdPs help us out</h3><p>Even before the shim runs, the IdPs are doing some of the work for us. Google’s “passkeys instead of passwords” feature checks server-side signals before deciding whether to route a user to passkey-first sign-in: prior session cookies on the legitimate origin, device-state hints, and platform conditional UI availability. None of these signals exist on a proxy origin. Real victims arriving at the proxy origin look to Google’s backend exactly like any other unfamiliar device, and Google defaults to password-first for unfamiliar devices.</p><p>To test, I enrolled my own Google Workspace account in “passkeys instead of passwords,” logged out, and signed in via the AiTM proxy in incognito Chrome. Google did not surface passkey-first at all. It went straight to a password prompt, then 2SV picker. Exactly what an unfamiliar-device sign-in looks like. The IdP made the technique easier without us doing anything.</p><p>I have not seen this structural-assist observation called out in the public literature. It is not a finding that takes much to verify (anyone can reproduce it in 15 minutes with a Workspace account and an AiTM proxy), but it changes the framing. For many real-world AiTM scenarios against Google, the proxy does not have to fight passkey-first routing because the IdP refuses to offer it on unknown-device origins automatically.</p><h3>What you should actually do</h3><p>If you rolled out passkeys, here is the no-BS test. Open your IdP admin console.</p><p><strong>Microsoft Entra:</strong> Did you set up a Conditional Access policy with Authentication Strength = Phishing-resistant MFA? AND did you also use Authentication Methods Policy to disable SMS, voice, and Authenticator-app fallback for users in scope?</p><p><strong>Google Workspace:</strong> Did you enroll the relevant users in Advanced Protection Program?</p><p><strong>Okta:</strong> Did you set Authenticator Policy = Possession + Hardware-protected? AND did you set a Sign-on Policy that requires it for sensitive apps? Or, restrict to Okta Verify only? (There’s a separate blog coming for an issue I discovered specific to Okta Verify..)</p><p>If the answer to either half is no, your passkey rollout is incomplete. <strong>Authentication is only as strong as its weakest enrolled fallback method.</strong> We have been saying this for years. Enrolling passkeys without disabling phishable fallbacks is a passkey enrollment program. It is not a phishing-resistant authentication program. There is a real difference.</p><p>And, fair warning, I am unavoidably biased about my own tool here. Once you have made those policy changes, you actually need to verify they hold under fire. That means simulating the technique against an authorized cohort of your own users. Drop a PhishU AiTM landing page in front of your test population, run a campaign, and let the dashboard tell you who picked the weak fallback and who got blocked at the policy enforcement layer. If your enforcement is working, the report tells you so. If 80 percent of your engineering team picked SMS, that is also extremely useful information. Either result beats assuming.</p><h3>More</h3><p>If you want the full technical breakdown, surface walkthrough with code references, the empirical findings written up in detail, the tiered defensive playbook for orgs that cannot do strict enforcement everywhere overnight, and side-by-side proof-of-concept screenshots, it is on the PhishU corporate blog: Passkeys Are Nearly Useless Against Live AiTM: The 95% Enforcement Gap (https://phishu.net/blogs/blog-testing-passkey-fallback-abuse-in-the-phishu-framework.html).</p><p>If you want to learn more about the PhishU Framework itself, what other AiTM, OAuth consent grant, device code, B2B invite, and ClickFix scenarios it covers, pricing, etc, that is at <a href="https://phishu.net./">https://phishu.net.</a> And if you sign up for a demo or trial right now I will mail you a signed copy of my book, “S is for Spear Phishing”, for <strong>free </strong>(you cover the $5 shipping). First 50 sign-ups while supplies last.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*3ryP1SEehUxpvc00.png"><figcaption>S is for Spear Phishing: Cybersecurity ABCs</figcaption></figure><p>Thanks to Push Security, eSentire, and the rest of the researchers who wrote about this before me. The work is real. I just got there later. Awareness is what is mostly missing now and implemention/training in a tool, and that is where I think there is still room to push.</p><p>Stay safe out there!</p><p>— Curtis Brazzell</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=54eed4eecf4a" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/passkeys-arent-nearly-as-effective-as-we-thought-54eed4eecf4a">Passkeys Aren’t Nearly as Effective as We Thought</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft setzt auf Passkeys und KI-Sicherheit - IT BOLTWISE x Artificial Intelligence]]></title>
<description><![CDATA[Diese Umstellung erfordert eine strategische Neuausrichtung der E-Mail-Infrastruktur, um den neuen Sicherheitsstandards gerecht zu werden. Microsoft ...]]></description>
<link>https://tsecurity.de/de/3505196/it-security-nachrichten/microsoft-setzt-auf-passkeys-und-ki-sicherheit-it-boltwise-x-artificial-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505196/it-security-nachrichten/microsoft-setzt-auf-passkeys-und-ki-sicherheit-it-boltwise-x-artificial-intelligence/</guid>
<pubDate>Sun, 10 May 2026 21:06:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Diese Umstellung erfordert eine strategische Neuausrichtung der E-Mail-Infrastruktur, um den neuen Sicherheitsstandards gerecht zu werden. Microsoft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Passwort hat ausgedient: Microsoft setzt voll auf Passkeys - WinFuture]]></title>
<description><![CDATA[DesignPickle, Sicherheit, Internet, Laptop, Verschlüsselung, Kryptographie, Schlüssel, schloss, ... Cybersicherheit: E-Mails bleiben größtes ...]]></description>
<link>https://tsecurity.de/de/3503717/it-security-nachrichten/das-passwort-hat-ausgedient-microsoft-setzt-voll-auf-passkeys-winfuture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503717/it-security-nachrichten/das-passwort-hat-ausgedient-microsoft-setzt-voll-auf-passkeys-winfuture/</guid>
<pubDate>Sat, 09 May 2026 23:23:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[DesignPickle, <b>Sicherheit</b>, Internet, Laptop, Verschlüsselung, Kryptographie, Schlüssel, schloss, ... Cybersicherheit: E-Mails bleiben größtes ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Das Passwort hat ausgedient: Microsoft setzt voll auf Passkeys]]></title>
<description><![CDATA[Schluss mit Passwörtern: Microsoft dreht den traditionellen Kenn­wörtern den Hahn zu. Aufgerüttelt durch KI-gestützten Phishing-Attacken, die über 50 Prozent Klickrate erreichen, will Microsoft nur noch Passkeys zulassen und schafft Sicherheitsfragen ab.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3503378/it-security-nachrichten/das-passwort-hat-ausgedient-microsoft-setzt-voll-auf-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3503378/it-security-nachrichten/das-passwort-hat-ausgedient-microsoft-setzt-voll-auf-passkeys/</guid>
<pubDate>Sat, 09 May 2026 18:40:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158602.html"><img hspace="5" border="0" align="left" alt="Sicherheit, Internet, Laptop, Verschlüsselung, Kryptographie, Schlüssel, schloss, Ende-zu-Ende-Verschlüsselung, Absicherung, Verschlüsselungssoftware, Kryptografie" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/42496.png"></a>
			Schluss mit Passwörtern: Microsoft dreht den traditionellen Kenn­wörtern den Hahn zu. Aufgerüttelt durch <a href="https://winfuture.de/special/kuenstliche-intelligenz/" title="Künstliche Intelligenz Special">KI-gestützten</a> Phishing-Attacken, die über 50 Prozent Klickrate erreichen, will Microsoft nur noch Passkeys zulassen und schafft Sicherheitsfragen ab.			(<a href="https://winfuture.de/news,158602.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkey-Einführung: Strategischer Leitfaden für moderne Unternehmen]]></title>
<description><![CDATA[Technologische Integration in den Identitäts-Stack. Für CISOs (Chief Information Security Officers) stellt die Einführung von Passkeys weniger eine ...]]></description>
<link>https://tsecurity.de/de/3502557/it-security-nachrichten/passkey-einfuehrung-strategischer-leitfaden-fuer-moderne-unternehmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3502557/it-security-nachrichten/passkey-einfuehrung-strategischer-leitfaden-fuer-moderne-unternehmen/</guid>
<pubDate>Sat, 09 May 2026 09:24:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Technologische Integration in den Identitäts-Stack. Für CISOs (Chief Information <b>Security</b> Officers) stellt die Einführung von Passkeys weniger eine ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkey-Einführung: Strategischer Leitfaden für moderne Unternehmen]]></title>
<description><![CDATA[Passkeys bieten Schutz vor Phishing und Infostealern. Ein neues Playbook von Sophos unterstützt CISOs bei der komplexen Integration in bestehende IT-Strukturen.

Tags: #Cyber Security | #Passkeys]]></description>
<link>https://tsecurity.de/de/3502267/it-security-nachrichten/passkey-einfuehrung-strategischer-leitfaden-fuer-moderne-unternehmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3502267/it-security-nachrichten/passkey-einfuehrung-strategischer-leitfaden-fuer-moderne-unternehmen/</guid>
<pubDate>Sat, 09 May 2026 06:09:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920.jpg" class="attachment-full size-full wp-post-image" alt="Passkey" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/10/Passkeys-Shutterstock-2362734213-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Passkey-Einführung: Strategischer Leitfaden für moderne Unternehmen 1"></p>
    Passkeys bieten Schutz vor Phishing und Infostealern. Ein neues Playbook von Sophos unterstützt CISOs bei der komplexen Integration in bestehende IT-Strukturen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/passkeys-en">#Passkeys</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS]]></title>
<description><![CDATA[Introduction
Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. As detailed in our companion report, 'Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft', these campaigns ...]]></description>
<link>https://tsecurity.de/de/3501439/it-security-nachrichten/guidance-from-the-frontlines-proactive-defense-against-shinyhunters-branded-data-theft-targeting-saas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501439/it-security-nachrichten/guidance-from-the-frontlines-proactive-defense-against-shinyhunters-branded-data-theft-targeting-saas/</guid>
<pubDate>Fri, 08 May 2026 23:20:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. As detailed in our companion report,</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft"><span> </span><span>'Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft'</span></a><span>, these campaigns leverage evolved voice phishing (vishing) and victim-branded credential harvesting to successfully compromise single sign-on (SSO) credentials and enroll unauthorized devices into victim multi-factor authentication (MFA) solutions.</span></p>
<p><span>This activity is not the result of a security vulnerability in vendors' products or infrastructure. Instead, these intrusions rely on the effectiveness of social engineering to bypass identity controls and pivot into cloud-based software-as-a-service (SaaS) environments.</span></p>
<p><span>This post provides actionable <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas#:~:text=1.%20hardening">hardening</a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas#:~:text=2.%20logging">logging</a>, and <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas#:~:text=3.%20detections">detection</a> recommendations to help organizations protect against these threats. Organizations responding to an active incident should focus on rapid containment steps, such as severing access to infrastructure environments, SaaS platforms, and the specific identity stores typically used for lateral movement and persistence. Long-term defense requires a transition toward </span><a href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc" rel="noopener" target="_blank"><span>phishing-resistant MFA</span></a><span>, such as FIDO2 security keys or passkeys, which are more resistant to social engineering than push-based or SMS authentication.</span></p>
<h3><span>Containment</span></h3>
<p><span>Organizations responding to an active or suspected intrusion by these threat clusters should prioritize rapid containment to sever the attacker’s access to prevent further data exfiltration. Because these campaigns rely on valid credentials rather than malware, containment must prioritize the revocation of session tokens and the restriction of identity and access management operations.</span></p>
<h4><span>Immediate Containment Actions</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Revoke active sessions:</strong><span> Identify and disable known compromised accounts and revoke all active session tokens and OAuth authorizations across IdP and SaaS platforms.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrict password resets:</strong><span> Temporarily disable or heavily restrict public-facing self-service password reset portals to prevent further credential manipulation.  Do not allow the use of self-service password reset for administrative accounts.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Pause MFA registration:</strong><span> Temporarily disable the ability for users to register, enroll, or join new devices to the identity provider (IdP).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Limit remote access:</strong><span> Restrict or temporarily disable remote access ingress points, such as VPNs, or Virtual Desktops Infrastructure (VDI), especially from untrusted or non-compliant devices.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enforce device compliance:</strong><span> Restrict access to IdPs and SaaS applications so that authentication can only originate from organization-managed, compliant devices and known trusted egress locations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement 'shields up' procedures:</strong><span> Inform the service desk of heightened risk and shift to manual, high-assurance verification protocols for all account-related requests. In addition, remind technology operations staff not to accept any work direction via SMS messages from colleagues.</span></p>
</li>
</ul>
<p><span>During periods of heightened threat activity, Mandiant recommends that organizations temporarily route all password and MFA resets through a rigorous manual identity verification protocol, such as the live video verification described in the Hardening section of this post. When appropriate, organizations should also communicate with end-users, HR partners, and other business units to stay on high-alert during the initial containment phase. Always report suspicious activity to internal IT and Security for further investigation.</span></p>
<h3><span>1. Hardening</span><strong> </strong></h3>
<p><span>Defending against threat clusters associated with ShinyHunters-branded extortion begins with tightening manual, high-risk processes that attackers frequently exploit, particularly password resets, device enrollments, and MFA changes.</span></p>
<h4><span>Help Desk Verification</span></h4>
<p><span>Because these campaigns often target human-driven workflows through social engineering, vishing, and phishing, organizations should implement stronger, layered identity verification processes for support interactions, especially for requests involving account changes such as password resets or MFA modifications. Threat actors have also been known to impersonate third-party vendors to voice phish (vish) help desks and persuade staff to approve or install malicious SaaS application registrations.</span></p>
<p><span>As a temporary measure during heightened risk, organizations should require verification that includes the caller’s identity, a valid ID, and a visual confirmation that the caller and ID match. </span></p>
<p><span>To implement this, organizations should require help desk personnel to:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Require a live video call where the user holds a physical government ID next to their face. The agent must visually verify the match.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Confirm the name on the ID matches the employee’s corporate record.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require out-of-band approval from the user's known manager before processing the reset.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reject requests based solely on employee ID, SSN, or manager name. ShinyHunters possess this data from previous breaches and may use it to verify their identity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If the user calls the helpdesk for a password reset, never perform the reset without calling the user back at a known good phone number to prevent spoofing.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If a live video call is not possible, require an alternative high-assurance path. It may be required for the user to come in person to verify their identity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Optionally, after a completed interaction, the help desk agent can send an email to the user’s manager indicating that the change is complete with a picture from the video call of the user who requested the change on camera.</span></p>
</li>
</ul>
<h5><span>Special Handling for Third-Party Vendor Requests</span></h5>
<p><span>Mandiant has observed incidents where attackers impersonate support personnel from third-party vendors to gain access. In these situations, the standard verification principals may not be applicable.</span></p>
<p><span>Under no circumstances should the Help Desk move forward with allowing access. The agent must halt the request and follow this procedure:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>End the inbound call without providing any access or information</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Independently contact the company's designated account manager for that vendor using trusted, on-file contact information</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require explicit verification from the account manager before proceeding with any request</span></p>
</li>
</ul>
<h5><span>End User Education</span></h5>
<p><span>Organizations should educate end users on best practices especially when being reached out directly without prior notice.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Conduct internal Vishing and Phishing exercises to validate end user adoption of security best practices</span><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Educate that passwords should not be shared, regardless of who is asking for it.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Encourage users to exercise extreme caution when being requested to reset their own passwords and MFA; especially during off-business hours.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If they are unsure of the person or number they are being contacted by, have them cease all communications and contact a known support channel for guidance.</span></p>
</li>
</ul>
<h4><span>Identity &amp; Access Management</span></h4>
<p><span>Organizations should implement a layered series of controls to protect all types of identities. Access to cloud identity providers (IdPs), cloud consoles, SaaS applications, document and code repositories should be restricted since these platforms often become the control plane for privilege escalation, data access, and long-term persistence.</span></p>
<p><span>This can be achieved by:</span></p>
<ul>
<li role="presentation"><span>Limiting access to trusted egress points and physical locations</span></li>
<li role="presentation"><span>Review and understand what “local accounts” exist within SaaS platforms:</span>
<ul>
<li role="presentation"><span>Ensure any default username/passwords have been updated according to the organization’s password policy.</span></li>
<li role="presentation"><span>Limit the use of ‘local accounts’ that are not managed as part of the organization’s primary centralized IdP.</span></li>
</ul>
</li>
<li role="presentation"><span>Reducing the scope of non-human accounts (access keys, tokens, and non-human accounts)</span>
<ul>
<li role="presentation"><span>Where applicable, organizations should implement network restrictions across non-human accounts. </span></li>
<li role="presentation"><span>Activity correlating to long-lived tokens (OAuth / API) associated with authorized / trusted applications should be monitored to detect abnormal activity.</span></li>
</ul>
</li>
<li role="presentation"><span>Limit access to organization resources from managed and compliant devices only. Across managed devices:</span>
<ul>
<li role="presentation"><span>Implement device posture checks via the Identity Provider.</span></li>
<li role="presentation"><span>Block access from devices with prolonged inactivity.</span></li>
<li role="presentation"><span>Block end users ability to enroll personal devices. </span></li>
</ul>
</li>
<li role="presentation"><span>Where access from unmanaged devices is required, organizations should: </span>
<ul>
<li role="presentation"><span>Limit non-managed devices to web only views.</span></li>
<li role="presentation"><span>Disable ability to download/store corporate/business data locally on unmanaged personal devices.</span></li>
<li role="presentation"><span>Limit session durations and prompt for re-authentication with MFA.</span></li>
</ul>
</li>
<li role="presentation"><span>Rapid enhancement to MFA methods, such as:</span>
<ul>
<li role="presentation">Removal of SMS, phone call, push notification, and/or email as authentication controls.</li>
<li role="presentation">Requiring strong, phishing resistant MFA methods such as:
<ul>
<li role="presentation">Authenticator apps that require phishing resistant MFA (FIDO2 Passkey Support may be added to existing methods such as Microsoft Authenticator.)</li>
<li role="presentation">FIDO2 security keys for authenticating identities that are assigned privileged roles.</li>
</ul>
</li>
<li role="presentation"><span>Enforce multi-context criteria to enrich the authentication transaction.</span>
<ul>
<li role="presentation"><span><span>Examples include not only validating the identity, but also specific device and location attributes as part of the authentication transaction.</span></span>
<ul>
<li role="presentation"><span><span>For organizations that leverage Google Workspace, these concepts can be enforced by using context-aware access policies. </span></span></li>
<li role="presentation"><span><span>For organizations that leverage Microsoft Entra ID, these concepts can be enforced by using a Conditional Access Policy. </span></span></li>
<li role="presentation"><span><span>For organizations that leverage Okta, these concepts can be enforced by using Okta policies and rules.</span></span></li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>Attackers are consistently targeting non-human identities due to the limited number of detections around them, lack of baseline of normal vs abnormal activity, and common assignment of privileged roles attached to these identities. Organizations should: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Identify and track all programmatic identities and their usage across the environment, including where they are created, which systems they access, and who owns them.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Centralize storage in a secrets manager (cloud-native or third-party) and prevent credentials from being embedded in source code, config files, or CI/CD pipelines.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Restrict authentication IPs for programmatic credentials so they can only be used from trusted third-party or internal IP ranges wherever technically feasible.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Transition to workload identity federation: Where feasible, replace long-lived static credentials (such as AWS access keys or service account keys) with workload identity federation mechanisms (often based on OIDC). This allows applications to authenticate using short-lived, ephemeral tokens issued by the cloud provider, dramatically reducing the risk of credential theft from code repositories and file systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce strict scoping and resource binding by tying credentials to specific API endpoints, services, or resources. For example, an API key should not simply have “read” access to storage, but be limited to a particular bucket or even a specific prefix, minimizing blast radius if it is compromised.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Baseline expected behavior for each credential type (typical access paths, destinations, frequency, and volume) and integrate this into monitoring and alerting so anomalies can be quickly detected and investigated.</span></p>
</li>
</ul>
<p><span>Additional platform-specific hardening measures include: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Okta</strong></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Enable Okta </span><a href="https://help.okta.com/en-us/content/topics/security/threat-insight/about-threatinsight.htm" rel="noopener" target="_blank"><span>ThreatInsight</span></a><span> to automatically block IP addresses identified as malicious.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Restrict Super Admin access to specific network zones (corporate VPN).</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Microsoft Entra ID</strong></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Implement common </span><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-policy-common?tabs=secure-foundation" rel="noopener" target="_blank"><span>Conditional Access Policies</span></a><span> to block unauthorized authentication attempts and restrict high-risk sign-ins.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Configure </span><a href="https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-risk-policies" rel="noopener" target="_blank"><span>risk-based policies</span></a><span> to trigger password changes or MFA when risk is detected.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Restrict who is allowed to register applications in Entra ID and require administrator approval for all application registrations.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Google Workspace</strong></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Use </span><a href="https://support.google.com/a/answer/12645308?hl=en" rel="noopener" target="_blank"><span>Context-Aware Access</span></a><span> levels to restrict Google Drive and Admin Console access based on device attributes and IP address.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Enforce 2-Step Verification (2SV) for all Google Workspace users.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Use </span><a href="https://landing.google.com/intl/en_in/advancedprotection/" rel="noopener" target="_blank"><span>Advanced Protection</span></a><span> to protect high-risk users from targeted phishing, malware, and account hijacking.</span></p>
</li>
</ul>
</ul>
<h4><span>Infrastructure and Application Platforms </span></h4>
<p><span>Infrastructure and application platforms such as Cloud consoles and SaaS applications are frequent targets for credential harvesting and data exfiltration. Protecting these systems typically requires implementing the previously outlined identity controls, along with platform-specific security guardrails, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Restrict management-plane access so it’s only reachable from the organization’s network and approved VPN ranges.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Scan for and remediate exposed secrets, including sensitive credentials stored across these platforms.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce device access controls so access is limited to managed, compliant devices.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Monitor configuration changes to identify and investigate newly created resources, exposed services, or other unauthorized modifications.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Implement logging and detections to identify:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Newly created or modified network security group (NSG) rules, firewall rules, or publicly exposed resources that enable remote access.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Creation of programmatic keys and credentials (e.g., access keys).</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Disable API/CLI access for non-essential users by restricting programmatic access to those who explicitly require it for management-plane operations.</span></p>
</li>
</ul>
<h4><span>Platform Specifics</span></h4>
<ul>
<li aria-level="1">
<p role="presentation"><strong>GCP</strong></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Configure security perimeters with </span><a href="https://docs.cloud.google.com/vpc-service-controls/docs/overview"><span>VPC Service Controls (VPC-SC)</span></a><span> to prevent data from being copied to unauthorized Google Cloud resources even if they have valid credentials.<br></span><span><br></span><span>Set additional guardrails with </span><a href="https://cloud.google.com/blog/products/identity-security/just-say-no-build-defense-in-depth-with-iam-deny-and-org-policies"><span>organizational policies and deny policies</span></a><span> applied at the organization level. This stops developers from introducing misconfigurations that could be exploited by attackers. For example, enforcing organizational policies like “iam.disableServiceAccountKeyCreation” will prevent generating new unmanaged service account keys that can be easily exfiltrated.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Apply </span><a href="https://docs.cloud.google.com/iam/docs/conditions-overview"><span>IAM Conditions</span></a><span> to sensitive role bindings. Restrict roles so they only activate if the resource name starts with a specific prefix or if the request comes during specific working hours. This limits the blast radius of a compromised credential.</span></p>
</li>
</ul>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>AWS</strong></p>
<ul>
<li aria-level="2">
<p role="presentation"><span>Apply </span><a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html" rel="noopener" target="_blank"><span>Service Control Policies (SCPs)</span></a><span> at the root level of the AWS Organization that limit the attack surface of AWS services. For example, deny access in unused regions, block creation of IAM access keys, and prevent deletion of backups, snapshots, and critical resources.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Define data perimeters through </span><a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_rcps.html" rel="noopener" target="_blank"><span>Resource Control Policies (RCPs)</span></a><span> that restrict access to sensitive resources (like S3 buckets) to only trusted principals within your organization, preventing external entities from accessing data even with valid keys.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Implement alerts on common reconnaissance commands such as GetCallerIdentity API calls originating from non-corporate IP addresses. This is often the first reconnaissance command an attacker runs to verify their stolen keys.</span></p>
</li>
</ul>
</li>
<li><strong><span>Azure</span></strong>
<ul>
<li aria-level="2">Enforce <a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-device-compliance" rel="noopener" target="_blank">Conditional Access Policies (CAPs)</a> that block access to administrative applications unless the device is "Microsoft Entra hybrid joined" and "Compliant." This prevents attackers from accessing resources using their own tools or devices.</li>
<li aria-level="2">Eliminate standing admin access and require Just-In-Time (JIT) through <a href="https://docs.azure.cn/en-us/entra/id-governance/privileged-identity-management/pim-configure" rel="noopener" target="_blank">Privileged Identity Management (PIM)</a> for elevation for roles such as Global Administrator, mandating an approval workflow and justification for each activation.</li>
<li aria-level="2">Enforce the use of <a href="https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview" rel="noopener" target="_blank">Managed Identities for Azure resources</a> accessing other services. This removes the need for developers to handle or rotate credentials for service principals, eliminating the static key attack vector.</li>
</ul>
</li>
<li><strong>Source Code Management</strong>
<ul>
<li>Enforce Single Sign-On (SSO) with SCIM for automated lifecycle management and mandate FIDO2/WebAuthn to neutralize phishing. Additionally, replace broad access tokens with short-lived, Fine-Grained Personal Access Tokens (PATs) to enforce least privilege.</li>
<li>Prevent credential leakage by enabling native "Push Protection" features or implementing blocking CI/CD workflows (such as TruffleHog) that automatically reject commits containing high-entropy strings before they are merged.</li>
<li>Mitigate the risk of malicious code injection by requiring cryptographic commit signing (GPG/S/MIME) and mandating a minimum of two approvals for all Pull Requests targeting protected branches.</li>
<li>Conduct scheduled historical scans to identify and purge latent secrets that evaded preventative controls, ensuring any compromised credentials are immediately rotated and forensically investigated.</li>
</ul>
</li>
<li><strong>Salesforce</strong>
<ul>
<li>Reference <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6040-proactive-hardening-recommendations#:~:text=programmatic%20credentials%20protections"><span>Mandiant’s Salesforce Hardening blog post</span></a></li>
<li>Reference Salesforce “<a href="https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/" rel="noopener" target="_blank"><span>Protecting Salesforce Data After an Identity Compromise</span></a><span>” blog post</span></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><h3><span>2. Logging</span></h3>
<p><span>Modern SaaS intrusions rarely rely on payloads or technical exploits. Instead, Mandiant consistently observes attackers leveraging valid access (frequently gained via vishing or MFA bypass) to abuse native SaaS capabilities such as bulk exports, connected apps, and administrative configuration changes.</span></p>
<p><span>Without clear visibility into these environments, detection becomes nearly impossible. If an organization cannot track which identity authenticated, what permissions were authorized, and what data was exported, they often remain unaware of a campaign until an extortion note appears.</span></p>
<p><span>This section focuses on ensuring your organization has the necessary visibility into identity actions, authorizations, and SaaS export behaviors required to detect and disrupt these incidents before they escalate.</span></p>
<h4><span>Identity Provider</span><strong> </strong></h4>
<p><span>If an adversary gains access through vishing and MFA manipulation, the first reliable signals will appear in the SSO control plane, not inside a workstation. In this example, the goal is to ensure Okta and Entra ID ogs identify who authenticated, what MFA changes occurred, and where access originated from.</span></p>
<h4><span>What to Enable and Ingest into the SIEM</span></h4>
<h5><span>Okta</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://developer.okta.com/docs/reference/api/event-types/?_gl=1%2A1he4agd%2A_gcl_au%2AMTI5ODE1Mjc3Ny4xNzY5NzkwMjMz%2A_ga%2AMTk4MDY0NzkxMi4xNzY5NzkwMjMz%2A_ga_QKMSDV5369%2AczE3Njk3OTAyMzIkbzEkZzEkdDE3Njk3OTA3ODQkajE4JGwwJGgw" rel="noopener" target="_blank"><span>Authentication events</span></a><span> (successful and failed sign-ins)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA lifecycle events (enrollment/activation and changes to authentication factors or devices)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Administrative identity events that capture security-relevant actions (e.g., changes that affect authentication posture)</span></p>
</li>
</ul>
<h5><span>Entra ID</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Authentication events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities" rel="noopener" target="_blank"><span>Audit logs </span></a><span>for MFA changes / authentication method</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit logs for security posture changes that affect authentication</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Conditional Access policy changes</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Changes to Named Locations / trusted locations</span></p>
</li>
</ul>
</ul>
<h5><span>What “Good” Looks Like Operationally</span></h5>
<p><span>You should be able to quickly identify:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Authentication factor, device enrollment activity, and the user responsible</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Source IP, geolocation, (and ASN if available) associated with that enrollment</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Whether access originated from the organization’s expected egress and identify access paths</span></p>
</li>
</ul>
<h4><span>Platform</span></h4>
<h5><span>Google Workspace Logging </span></h5>
<p><span>Defenders should ensure they have visibility into OAuth authorizations, mailbox deletion activity (including deletion of security notification emails), and Google Takeout exports</span><strong>. </strong></p>
<h5><span>What You Need in Place Before Logging</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Correct edition + investigation surfaces available: Confirm your Workspace edition supports the Audit and investigation tool and the Security Investigation tool (if you plan to use it).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Correct admin privileges: Ensure the account has Audit &amp; Investigation privilege (to access OAuth/Gmail/Takeout log events) and Security Center privilege.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If you need Gmail message content: Validate edition + privileges allow viewing message content during investigations. </span></p>
</li>
</ul>
<h5><span>What to Enable and Ingest into the SIEM</span></h5>
<p><strong><span>OAuth / App authorization logs</span></strong></p>
<p><span>Enable and ingest </span><a href="https://support.google.com/a/answer/6124308?hl=en#zippy=%2Caudit-and-investigation-tool" rel="noopener" target="_blank"><span>token/app authorization logs</span></a><span> to observe:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Which application was authorized (app name + identifier)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Which user granted access</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>What scopes were granted</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Source IP and geolocation for the authorization</span></p>
</li>
</ul>
<p><span>This is the telemetry required to detect suspicious app authorizations and add-on enablement that can support mailbox manipulation.</span></p>
<p><strong><span>Gmail audit logs</span></strong></p>
<p><span>Enable and ingest </span><a href="https://support.google.com/a/answer/11479100?hl=en#zippy=%2Caudit-and-investigation-tool" rel="noopener" target="_blank"><span>Gmail audit events</span></a><span> that capture:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Message deletion actions (including permanent delete where available)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Message direction indicators (especially useful for outbound cleanup behavior)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Message metadata (e.g., subject) to support detection of targeted deletions of security notification emails</span></p>
</li>
</ul>
<p><strong><span>Google Takeout audit logs</span></strong></p>
<p><span>Enable and ingest </span><a href="https://support.google.com/a/answer/10276199?hl=en#zippy=%2Caudit-and-investigation-tool" rel="noopener" target="_blank"><span>Takeout logs</span></a><span> to capture:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Export initiation and completion events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User and source IP/geo for the export activity</span></p>
</li>
</ul>
<h4><span>Salesforce Logging </span></h4>
<p><span>Activity observed by Mandiant includes the use of Salesforce Data Loader and large-scale access patterns that won’t be visible if only basic login history logs are collected. </span><a href="http://salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/" rel="noopener" target="_blank"><span>Additional Salesforce telemetry</span></a><span> that captures logins, configuration changes, connected app/API activity, and export behavior is needed to investigate SaaS-native exfiltration. Detailed implementation guidance for these visibility gaps can be found in Mandiant’s </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6040-proactive-hardening-recommendations?e=48754805"><span>Targeted Logging and Detection Controls for Salesforce</span></a><span>.</span></p>
<h5><span>What You Need in Place Before Logging</span></h5>
<ul>
<li role="presentation"><span>Entitlement check (must-have)</span>
<ul>
<li role="presentation"><span>Most security-relevant </span><a href="https://resources.docs.salesforce.com/260/latest/en-us/sfdc/pdf/salesforce_security_impl_guide.pdf" rel="noopener" target="_blank"><span>Salesforce logs</span></a><span> are gated behind </span><a href="https://help.salesforce.com/s/articleView?id=xcloud.real_time_event_monitoring_overview.htm&amp;type=5" rel="noopener" target="_blank"><span>Event Monitoring</span></a><span>, delivered through Salesforce Shield or the Event Monitoring add-on. Confirm you are licensed for the event types you plan to use for detection.</span></li>
</ul>
</li>
<li role="presentation"><span>Choose the collection method that matches your operations</span>
<ul>
<li role="presentation"><span>Use real-time event monitoring (RTEM) if you need near real-time detection.</span></li>
<li role="presentation"><span>Use event log files (ELF) if you need predictable batch exports for long-term storage and retrospective investigations.</span></li>
<li role="presentation"><span>Use event log objects (ELO) if you require queryable history via Salesforce Object Query Language (often requires Shield/add-on).</span></li>
</ul>
</li>
<li role="presentation"><span>Enable the events you intend to detect on</span>
<ul>
<li role="presentation"><span>Use </span><a href="https://developer.salesforce.com/docs/atlas.en-us.securityImplGuide.meta/securityImplGuide/event_monitoring_monitor_events_with_event_manager.htm" rel="noopener" target="_blank"><span>Event Manager</span></a><span> to explicitly turn on the event categories you plan to ingest, and ensure the right teams have access to view and operationalize the data (profiles/permission sets).</span></li>
</ul>
</li>
<li role="presentation"><span>Threat Detection and Enhanced Transaction Security</span>
<ul>
<li role="presentation"><span>If your environment uses </span><a href="https://developer.salesforce.com/docs/atlas.en-us.securityImplGuide.meta/securityImplGuide/real_time_em_threat_detection.htm" rel="noopener" target="_blank"><span>Threat Detection</span></a><span> or </span><a href="https://developer.salesforce.com/docs/atlas.en-us.securityImplGuide.meta/securityImplGuide/enhanced_transaction_security_policy_types.htm" rel="noopener" target="_blank"><span>ETS</span></a><span>, verify the event types that feed those controls and ensure your log ingestion platform doesn’t omit the events you expect to alert on.</span></li>
</ul>
</li>
</ul>
<h5><span>What to Enable and Ingest into the SIEM</span></h5>
<p><strong><span>Authentication and access</span></strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>LoginHistory (who logged in, when, from where, success/failure, client type)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>LoginEventStream (richer login telemetry where available)</span></p>
</li>
</ul>
<p><strong>Administrative/configuration visibility</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>SetupAuditTrail (changes to admin and security configurations)</span></p>
</li>
</ul>
<p><strong>API and export visibility</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>ApiEventStream (API usage by users and connected apps)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>ReportEventStream (report export/download activity)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>BulkApiResultEvent (bulk job result downloads—critical for bulk extraction visibility)</span></p>
</li>
</ul>
<p><strong>Additional high-value sources (if available in your tenant)</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>LoginAsEventStream (impersonation / “login as” activity)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>PermissionSetEvent (permission grants/changes)</span></p>
</li>
</ul>
<h4><span>SaaS Pivot Logging </span></h4>
<p><span>Threat actors often pivot from compromised SSO providers into additional SaaS platforms, including DocuSign and Atlassian. Ingesting audit logs from these platforms into a SIEM environment enables the detection of suspicious access and large-scale data exfiltration following an identity compromise.</span></p>
<h5><span>What You Need in Place Before Logging</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>You need tenant-level admin permissions to access and configure audit/event logging.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Confirm your plan/subscriptions include the audit/event visibility you are trying to collect (Atlassian org audit log capabilities can depend on plan/Guard tier; DocuSign org-level activity monitoring is provided via DocuSign Monitor).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>API access (If you are pulling logs programmatically): Ensure the tenant is able to use the vendor’s audit/event APIs (DocuSign Monitor API; Atlassian org audit log API/webhooks depending on capability).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Retention reality check: Validate the platform’s native audit-log retention window meets your investigation needs.</span></p>
</li>
</ul>
<h5><span>What to Enable and Ingest into the SIEM</span></h5>
<p><strong>DocuSign (audit/monitoring logs)</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Authentication events (successful/failed sign-ins, SSO vs password login if available)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://support.docusign.com/s/document-item?language=es&amp;bundleId=pqz1702943441912&amp;topicId=concb8f3294-71f0-478b-a228-dcc29dfd433a.html&amp;_LANG=esxm" rel="noopener" target="_blank"><span>Administrative changes</span></a><span> (user/role changes, org-level setting changes)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://support.docusign.com/s/document-item?language=en_US&amp;rsc_301&amp;bundleId=oeq1643226594604&amp;topicId=hha1578456343641.html&amp;_LANG=enus" rel="noopener" target="_blank"><span>Envelope access</span></a><span> and bulk activity (envelope viewed/downloaded, document downloaded, bulk send, bulk download/export where available)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>API activity (API calls, integration keys/apps used, client/app identifiers)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Source context (source IP/geo, user agent/client type)</span></p>
</li>
</ul>
<p><strong>Atlassian (Jira/Confluence audit logs)</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://support.atlassian.com/security-and-access-policies/docs/audit-log-activities-database/" rel="noopener" target="_blank"><span>Authentication events</span></a><span> (SSO sign-ins, failed logins)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Privilege and admin changes (role/group membership changes, org admin actions)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Confluence/Jira data access at scale:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Confluence: space/page view/download/export events (especially exports)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Jira: project access, issue export, bulk actions (where available)</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>API token and app activity (API token created/revoked, OAuth app connected, marketplace app install/uninstall)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Source context (source IP/geolocation, user agent/client type)</span></p>
</li>
</ul>
<h4><span>Microsoft 365 Audit Logging </span></h4>
<p><span>Mandiant has observed threat actors leveraging PowerShell to download sensitive data from SharePoint and OneDrive as part of this campaign. To detect the activity, it is necessary to ingest </span><a href="https://learn.microsoft.com/en-us/purview/audit-log-activities" rel="noopener" target="_blank"><span>M365 audit telemetry</span></a><span> that records file download operations along with client context (especially the user agent).</span></p>
<h5><span>What You Need in Place Before Logging</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Microsoft Purview Audit is available and enabled: Your tenant must have Microsoft Purview Audit turned on and usable (Audit “Standard” vs “Premium” affects capabilities/retention).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Correct permissions to view/search audit: Assign the compliance/audit roles required to access audit search and records.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SharePoint/OneDrive operations are present in the Unified Audit Log: Validate that SharePoint/OneDrive file operations are being recorded (this is where operations like file download/access show up).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Client context is captured: Confirm audit records include UserAgent (when provided by the client) so you can identify PowerShell-based access patterns in SharePoint/OneDrive activity.</span></p>
</li>
</ul>
<h5><span>What to Enable and Ingest into the SIEM</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><code>FileDownloaded</code><span> and </span><code>FileAccessed</code><span> (</span><a href="https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema" rel="noopener" target="_blank"><span>SharePoint/OneDrive</span></a><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User agent/client identifier (to surface WindowsPowerShell-style user agents)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User identity, source IP, geolocation</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Target resource details</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><h3><span>3. Detections</span></h3>
<p><span>The following detections target behavioral patterns Mandiant has identified in ShinyHunters related intrusions. In these scenarios, attackers typically gain initial access by compromising SSO platforms or manipulating MFA controls, then leverage native SaaS capabilities to exfiltrate data and evade detection.The following use cases are categorized by area of focus, including Identity Providers and Productivity Platforms. </span></p>
<p><strong>Note: </strong><span>This activity is not the result of a security vulnerability in vendors' products or infrastructure. Instead, these intrusions rely on the effectiveness of ShinyHunters related intrusions.</span></p>
<h4><span>Implementation Guidelines</span></h4>
<p><span>These rules are presented as YARA-L pseudo-code to prioritize clear detection logic and cross-platform portability. Because field names, event types, and attribute paths vary across environments, consider the following variables:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Ingestion Source:</strong><span> Differences in how logs are ingested into Google SecOps.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Parser Mapping:</strong><span> Specific UDM (Unified Data Model) mappings unique to your configuration.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Telemetry Availability:</strong><span> Variations in logging levels based on your specific SaaS licensing.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Reference Lists: </strong><span>Curated allowlists/blocklists the organization will need to create to help reduce noise and keep alerts actionable.</span></p>
</li>
</ul>
<p><strong>Note: </strong><span>Mandiant recommends testing these detections prior to deployment by validating the exact event mappings in your environment and updating the pseudo-fields to match your specific telemetry.</span></p>
<h4><span>Okta</span></h4>
<h5><span>MFA Device Enrollment or Changes (Post-Vishing Signal)</span></h5>
<p><span>Detects MFA device enrollment and MFA life cycle changes that often occur immediately after a social-engineered account takeover. When this alert is triggered, immediately review the affected user’s downstream access across SaaS applications (Salesforce, Google Workspace, Atlassian, DocuSign, etc.) for signs of large-scale access or data exports.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> In this intrusion pattern, MFA manipulation is a primary “account takeover” step. Because MFA lifecycle events are rare compared to routine logins, any modification occurring shortly after access is gained serves as a high-fidelity indicator of potential compromise.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta system Log MFA lifecycle events (enroll/activate/deactivate/reset)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>principal.user</code><span>, </span><code>principal.ip</code><span>, </span><code>client.user_agent</code><span>, geolocation/ASN (if enriched)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Optional: proximity to password reset, recovery, or sign-in anomalies (same user, short window)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$mfa.metadata.vendor_name = "Okta"
$mfa.metadata.product_event_type in ( "okta.user.mfa.factor.enroll", "okta.user.mfa.factor.activate",  "okta.user.mfa.factor.deactivate", "okta.user.mfa.factor.reset_all" )
$u= $mfa.principal.user.userid
$t_mfa = $mfa.metadata.event_timestamp

$ip = coalesce($mfa.principal.ip, $mfa.principal.asset.ip)
$ua = coalesce($mfa.network.http.user_agent, $mfa.extracted.fields["userAgent"], "") 

$reset.metadata.vendor_name = "Okta"
$reset.metadata.product_event_type in (
"okta.user.password.reset",  "okta.user.account.recovery.start" )
$t_reset = $reset.metadata.event_timestamp

$auth.metadata.vendor_name = "Okta"
$auth.metadata.product_event_type in ("okta.user.authentication.sso", "okta.user.session.start")
$t_auth = $auth.metadata.event_timestamp

match:
$u over 30m

condition:
// Always alert on MFA lifecycle change
$mfa and
// Optional sequence tightening (enrichment only, not mandatory):
// If reset/auth exists in the window, enforce it happened before the MFA change.
(
(not $reset and not $auth) or
(($reset and $t_reset &lt; $t_mfa) or ($auth and $t_auth &lt; $t_mfa))
)</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Suspicious admin.security Actions from Anonymized IPs</span></h5>
<p><span>Alert on Okta admin/security posture changes when the admin action occurs from suspicious network context (proxy/VPN-like indicators) or immediately after an unusual auth sequence.</span></p>
<p><span>Why this is high-fidelity: Admin/security control changes are low volume and can directly enable persistence or reduce visibility.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta admin/system events (e.g., policy changes, MFA policy, session policy, admin app access)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>“Anonymized” network signal: VPN/proxy ASN, “datacenter” reputation, TOR list, etc.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Actor uses unusual client/IP for admin activity</span></p>
</li>
</ul>
<p><strong>Reference lists</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>VPN_TOR_ASNS</code><span> (proxy/VPN ASN list)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$a.metadata.vendor_name = "Okta"
$a.metadata.product_event_type in ("okta.system.policy.update","okta.system.security.change","okta.user.session.clear","okta.user.password.reset","okta.user.mfa.reset_all")  
userid=$a.principal.user.userid
// correlate with a recent successful login for the same actor if available
$l.metadata.vendor_name = "Okta"
$l.metadata.product_event_type = "okta.user.authentication.sso"
userid=$l.principal.user.userid

match:
userid over 2h

condition:
$a and $l</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Google Workspace</span></h4>
<h5><span>OAuth Authorization for ToogleBox Recall</span></h5>
<p><span>Detects OAuth/app authorization events for ToogleBox recall (or the known app identifier), indicating mailbox manipulation activity.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> This is a tool-specific signal tied to the observed “delete security notification emails” behavior.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Workspace OAuth / token authorization log event</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>App name, app ID, scopes granted, granting user, source IP/geo</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Optional: privileged user context (e.g., admin, exec assistant)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$e.metadata.vendor_name = "Google Workspace"
$e.metadata.product_event_type in ("gws.oauth.grant", "gws.token.authorize") // placeholders
// match app name OR app id if you have it
(lower($e.target.application) contains "tooglebox" or
lower($e.target.application) contains "recall")
condition:
$e</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Gmail Deletion of Okta Security Notification Email</span></h5>
<p><span>Detects deletion actions targeting Okta security notification emails (e.g., “Security method enrolled”).</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Targeted deletion of security notifications is intentional evasion, not normal email behavior.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Gmail audit log delete/permanent delete (or mailbox cleanup) event</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Subject matches a small set of security-notification strings</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Time correlation: deletion shortly after receipt (optional)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$d.metadata.vendor_name = "Google Workspace"
$d.metadata.product_event_type in ("gws.gmail.message.delete",
                                       "gws.gmail.message.trash",
                                       "gws.gmail.message.permanent_delete") // PLACEHOLDER
regex_match(lower($d.target.email.subject),
"(security method enrolled|new sign-in|new device|mfa|authentication|verification)")
$u = $d.principal.user.userid
$t = $d.metadata.event_timestamp

match:
$u over 30m

condition:
$d and count($d) &gt;= 2   // tighten: at least 2 in 30m; adjust if too strict
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Google Takeout Export Initiated/Completed</span></h5>
<p><span>Detects Google Takeout export initiation/completion events.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Takeout exports are uncommon in corporate contexts; in this campaign they represent a direct data export path.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Takeout audit events (e.g., initiated, completed)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User, source IP/geo, volume</span></p>
</li>
</ul>
<p><strong>Reference lists</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>TAKEOUT_ALLOWED_USERS</code><span> </span><span>(rare; HR offboarding workflows, legal export workflows)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$start.metadata.vendor_name = "Google Workspace"
$start.metadata.product_event_type = "gws.takeout.export.start"      
$user = $start.principal.user.userid
$job  = $start.target.resource.id   // if available; otherwise remove job join

$done.metadata.vendor_name = "Google Workspace"
$done.metadata.product_event_type  = "gws.takeout.export.complete"   
$bytes = coalesce($done.target.file.size, $done.extensions.bytes_exported)

match:
// takeout can take hours; don't use 10m here, adjust accordingly
$start.principal.user.userid = $done.principal.user.userid over 24h
// if you have a job/export id, this makes it *much* cleaner
$start.target.resource.id = $done.target.resource.id
condition:
$start and $done and
$start.metadata.event_timestamp &lt; $done.metadata.event_timestamp and
$bytes &gt;= 500000000   // 500MB start point; tune
not ($u in %TAKEOUT_ALLOWED_USERS) // OPTIONAL: remove if you don't maintain it</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Cross-SaaS</span></h4>
<h5><span>Attempted Logins from Known Campaign Proxy/IOC Networks</span></h5>
<p><span>Detects authentication attempts across SaaS/SSO providers originating from IPs/ASNs associated with the campaign.</span></p>
<p><span>Why this is high-fidelity: These IPs and ASNs lack legitimate business overlap; matches indicate direct interaction between compromised credentials and known adversary-controlled infrastructure.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Authentication attempts across Okta / Salesforce / Workspace / Atlassian / DocuSign</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>principal.ip</code><span> matches IOC IPs or ASN list</span></p>
</li>
</ul>
<p><strong>Reference lists</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>SHINYHUNTERS_PROXY_IPS</code></p>
</li>
<li aria-level="1">
<p role="presentation"><code>VPN_TOR_ASNS</code></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$e.metadata.product_event_type in (
      "okta.login.attempt", "workday.sso.login.attempt",
      "gws.login.attempt",  "salesforce.login.attempt",
      "atlassian.login.attempt", "docusign.login.attempt"
    ) 
(
      $e.principal.ip in %SHINYHUNTERS_PROXY_IPS or
      $e.principal.ip.asn in %VPN_TOR_ASNS
)

condition:
$e</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Identity Activity Outside Normal Business Hours</span></h5>
<p><span>Detects identity events occurring outside normal business hours, focusing on high-risk actions (sign-ins, password reset, new MFA enrollment and/or device changes).</span></p>
<p><strong>Why this is high-fidelity:</strong><span> A strong indication of abnormal user behavior when also constrained to sensitive actions and users who rarely perform them.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>User sign-ins, password resets, MFA enrollment, device registrations</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Timestamp bucket: late evening / friday afternoon / weekends</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$e.metadata.vendor_name = "Okta"
$e.metadata.product_event_type in ("okta.user.password.reset","okta.user.mfa.factor.activate","okta.user.mfa.factor.reset_all") // PLACEHOLDER
outside_business_hours($e.metadata.event_timestamp, "America/New_York") 
// Include the business hours your organization functions in
$u = $e.principal.user.userid

condition:
$e</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Successful Sign-in From New Location and New MFA Method</span></h5>
<p><span>Detects a successful login that is simultaneously from a new geolocation and uses a newly registered MFA method.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> This pattern represents a compound condition that aligns with MFA manipulation and unfamiliar access context.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Successful authentication</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>New geolocation compared to user baseline</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>New factor method compared to user baseline (or recent MFA enrollment)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Optional sequence: MFA enrollment occurs after login</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$login.metadata.vendor_name = "Okta"
$login.metadata.product_event_type = "okta.login.success" 
$u = $login.principal.user.userid
$geo = $login.principal.location.country
$t_l = $login.metadata.event_timestamp
$m = $login.security_result.auth_method // if present; otherwise join to factor event

condition:
$login and
first_seen_country_for_user($u, $geo) and
first_seen_factor_for_user($u, $m)</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>Multiple MFA Enrollments Across Different Users From the Same Source IP</span></h5>
<p><span>Detects the same source IP enrolling/changing MFA for multiple users in a short window.</span></p>
<p><strong>Why this is high-fidelity:</strong><span>This pattern mirrors a known social engineering tactic where threat actors manipulate help desk admins to enroll unauthorized devices into a victim’s MFA - spanning multiple users from the same source address</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta MFA lifecycle events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Same </span><code>src_ip</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Distinct user count threshold</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Tight window</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$m.metadata.vendor_name = "Okta"
$m.metadata.product_event_type in ("&lt;OKTA_MFA_ENROLL_EVENT&gt;", "&lt;OKTA_MFA_DEVICE_ENROLL_EVENT&gt;") 
$ip  = coalesce($m.principal.ip, $m.principal.asset.ip)
$uid = $m.principal.user.userid

match:
$ip over 10m

condition:
count_distinct($uid) &gt;= 3</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Network</span></h4>
<h5><span>Web/DNS Access to Credential Harvesting, Portal Impersonation Domains</span></h5>
<p><span>Detects DNS queries or HTTP referrers matching brand and SSO/login keyword lookalike patterns.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Captures credential-harvesting infrastructure patterns when you have network telemetry.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>DNS question name or HTTP referrer/URL</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Regex match for brand + SSO keywords</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Exclusions for your legitimate domains</span></p>
</li>
</ul>
<p><strong>Reference lists</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Allowlist (small) of legitimate domains (optional)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
$event.metadata.event_type in ("NETWORK_HTTP", "NETWORK_DNS")
// pick ONE depending on which log source you're using most
// DNS:
$domain = lower($event.network.dns.questions.name)
// If you’re using HTTP instead, swap the line above to:
// $domain = lower($event.network.http.referring_url)

condition:
regex_match($domain, ".*(yourcompany(my|sso|internal|okta|access|azure|zendesk|support)|(my|sso|internal|okta|access|azure|zendesk|support)yourcompany).*"
)
and not regex_match($domain, ".*yourcompany\\.com.*")
and not regex_match($domain, ".*okta\\.yourcompany\\.com.*")</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Microsoft 365</span></h4>
<h5><span>M365 SharePoint/OneDrive: FileDownloaded with WindowsPowerShell User Agent</span></h5>
<p><span>Detects SharePoint/OneDrive downloads with PowerShell user-agent that exceed a byte threshold or count threshold within a short window.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> PowerShell-driven SharePoint downloading and burst volume indicates scripted retrieval.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>FileDownloaded/FileAccessed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User agent contains PowerShell</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Bytes transferred OR number of downloads in window</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Timestamp window (ordering implicit) and min&lt;max check</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
  $e.metadata.vendor_name = "Microsoft"
  (
    $e.target.application = "SharePoint" or
    $e.target.application = "OneDrive"
  )
  $e.metadata.product_event_type = /FileDownloaded|FileAccessed/
  $e.network.http.user_agent = /PowerShell/ nocase
  $user = $e.principal.user.userid
  $bytes = coalesce($e.target.file.size, $e.extensions.bytes_transferred) 
  $ts = $e.metadata.event_timestamp

match:
  $user over 15m

condition:
  // keep your PowerShell constraint AND require volume
  $e and (sum($bytes) &gt;= 500000000 or count($e) &gt;= 20) and min($ts) &lt; max($ts)</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>M365 SharePoint: High Volume Document FileAccessed Events</span></h5>
<p><span>Detects SharePoint document file access events that exceed a count threshold and minimum unique file types within a short window.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Burst volume may indicate scripted retrieval or usage of the Open-in-App feature within SharePoint.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>FileAccessed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Filtering on common document file types (e.g., PDF) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Number of downloads in window</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Minimum unique file types</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
  $e.metadata.vendor_name = "Microsoft"
  $e.metadata.product_event_type = "FileAccessed"
  $e.target.application = "SharePoint"
  $e.target.file.full_path = /\.(doc[mx]?|xls[bmx]?|ppt[amx]?|pdf)$/ nocase)
  $file_extension_extract = re.capture($e.target.file.full_path, `\.([^\.]+)$`)
  $session_id = $e.network.session_id

match:
  $session_id over 5m

outcome:
  $target_url_count = count_distinct(strings.coalesce($e.target.file.full_path))
  $extension_count = count_distinct($file_extension_extract)

condition:
  $e and $target_url_count &gt;= 50 and $extension_count &gt;= 3</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>M365 SharePoint: High Volume Document FileDownloaded Events</span></h5>
<p><span>Detects SharePoint document file downloaded events that exceed a count threshold and minimum unique file types within a short window.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Burst volume may indicate scripted retrieval, which may also be generated by legitimate backup processes.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>FileDownloaded</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Filtering on common document file types (e.g., PDF) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Number of downloads in window</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Minimum unique file types</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
  $e.metadata.vendor_name = "Microsoft"
  $e.metadata.product_event_type = "FileDownloaded"
  $e.target.application = "SharePoint"
  $e.target.file.full_path = /\.(doc[mx]?|xls[bmx]?|ppt[amx]?|pdf)$/ nocase)
  $file_extension_extract = re.capture($e.target.file.full_path, `\.([^\.]+)$`)
  $session_id = $e.network.session_id

match:
  $session_id over 5m

outcome:
  $target_url_count = count_distinct(strings.coalesce($e.target.file.full_path))
  $extension_count = count_distinct($file_extension_extract)

condition:
  $e and $target_url_count &gt;= 50 and $extension_count &gt;= 3</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>M365 SharePoint: Query for Strings of Interest</span></h5>
<p><span>Detects SharePoint queries for files relating to strings of interest, such as sensitive documents, clear-text credentials, and proprietary information.</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Multiple searches for strings of interest by a single account occurs infrequently. Generally, users will search for project or task specific strings rather than general labels (e.g., “confidential”).</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>SearchQueryPerformed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Filtering on strings commonly associated with sensitive or privileged information </span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
  $e.metadata.vendor_name = "Microsoft"
  $e.metadata.product_event_type = "SearchQueryPerformed"
  $e.target.application = "SharePoint"
  $e.additional.fields["search_query_text"] = /\bpoc\b|proposal|confidential|internal|salesforce|vpn/ nocase

condition:
  $e</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>M365 Exchange Deletion of MFA Modification Notification Email</span></h5>
<p><span>Detects deletion actions targeting Okta and other platform security notification emails (e.g., “Security method enrolled”).</span></p>
<p><strong>Why this is high-fidelity:</strong><span> Targeted deletion of security notifications can be intentional evasion and is not typically performed by email users.</span></p>
<p><strong>Key signals</strong></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>M365 Exchange audit log delete/permanent delete (or mailbox cleanup) event</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Subject matches a small set of security-notification strings</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Time correlation: deletion shortly after receipt (optional)</span></p>
</li>
</ul>
<p><strong>Pseudo-code (YARA-L)</strong></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
  $e.metadata.vendor_name = "Microsoft"
  $e.target.application = "Exchange"
  $e.metadata.product_event_type = /^(SoftDelete|HardDelete|MoveToDeletedItems)$/ nocase
  $e.network.email.subject = /new\s+(mfa|multi-|factor|method|device|security)|\b2fa\b|\b2-Step\b|(factor|method|device|security|mfa)\s+(enroll|registered|added|change|verify|updated|activated|configured|setup)/ nocase

  // filtering specifically for new device registration strings
  $e.network.email.subject = /enroll|registered|added|change|verify|updated|activated|configured|setup/ nocase

  // tuning out new device logon events
  $e.network.email.subject != /(sign|log)(-|\s)?(in|on)/ nocase

condition:
  $e</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft]]></title>
<description><![CDATA[Introduction 
Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harv...]]></description>
<link>https://tsecurity.de/de/3501438/it-security-nachrichten/vishing-for-access-tracking-the-expansion-of-shinyhunters-branded-saas-data-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501438/it-security-nachrichten/vishing-for-access-tracking-the-expansion-of-shinyhunters-branded-saas-data-theft/</guid>
<pubDate>Fri, 08 May 2026 23:20:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. Once inside, the threat actors target cloud-based software-as-a-service (SaaS) applications to exfiltrate sensitive data and internal communications for use in subsequent extortion demands.</span></p>
<p><span>Google Threat Intelligence Group (GTIG) is currently tracking this activity under multiple threat clusters (UNC6661, UNC6671, and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion"><span>UNC6240</span></a><span>) to enable a more granular understanding of evolving partnerships and account for potential impersonation activity. While this methodology of targeting identity providers and SaaS platforms is consistent with our prior observations of threat activity preceding ShinyHunters-branded extortion, the breadth of targeted cloud platforms continues to expand as these threat actors seek more sensitive data for extortion. <span>Further, they appear to be escalating their extortion tactics with recent incidents including harassment of victim personnel, among other tactics</span></span><span>.</span></p>
<p><span>This activity is not the result of a security vulnerability in vendors' products or infrastructure. Instead, it continues to highlight the effectiveness of social engineering and underscores the importance of organizations </span><a href="https://workspace.google.com/blog/identity-and-security/defending-against-account-takeovers-top-threats-passkeys-and-dbsc" rel="noopener" target="_blank"><span>moving towards phishing-resistant MFA</span></a><span> where possible. Methods such as FIDO2 security keys or passkeys are resistant to social engineering in ways that push-based or SMS authentication are not.</span></p>
<p><span>Mandiant has also published a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas"><span>comprehensive guide with proactive hardening and detection recommendations</span></a><span>, and Google published a </span><a href="https://security.googlecloudcommunity.com/community-blog-42/new-to-google-secops-leveraging-okta-curated-detections-to-detect-shinyhunters-related-activity-6693" rel="noopener" target="_blank"><span>detailed walkthrough for operationalizing these findings</span></a><span> within Google Security Operations. </span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/vishing-shinyhunters-fig1-white.max-1000x1000.png" alt="attack path diagram">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="e0hj0">Figure 1: Attack path diagram</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>UNC6661 Vishing and Credential Theft Activity</span></h3>
<p><span>In incidents spanning early to mid-January 2026, UNC6661 pretended to be IT staff and called employees at targeted victim organizations claiming that the company was updating MFA settings. The threat actor directed the employees to victim-branded credential harvesting sites to capture their SSO credentials and MFA codes, and then registered their own device for MFA. The credential harvesting domains attributed to UNC6661 commonly, but not exclusively, use the format &lt;companyname&gt;sso.com or &lt;companyname&gt;internal.com and have often been registered with NICENIC.</span></p>
<p><span>In at least some cases, the threat actor gained access to accounts belonging to Okta customers. Okta </span><a href="https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/" rel="noopener" target="_blank"><span>published</span></a><span> a report about phishing kits targeting identity providers and cryptocurrency platforms, as well as follow-on vishing attacks. While they associate this activity with multiple threat clusters, at least some of the activity appears to overlap with the ShinyHunters-branded operations tracked by GTIG.</span></p></div>
<div class="block-paragraph_advanced"><p><span>After gaining initial access, UNC6661 moved laterally through victim customer environments to exfiltrate data from various SaaS platforms (log examples in Figures 2 through 5). While the targeting of specific organizations and user identities is deliberate, analysis suggests that the subsequent access to these platforms is likely opportunistic, determined by the specific permissions and applications accessible via the individual compromised SSO session. These compromises did not result from security vulnerabilities in the vendors' products or infrastructure.</span></p>
<p><span>In some cases, they have appeared to target specific types of information. For example, the threat actors have conducted searches in cloud applications for documents containing specific text including "poc," "confidential," "internal," "proposal," "salesforce," and "vpn" or targeted personally identifiable information (PII) stored in Salesforce. Additionally, UNC6661 may have targeted Slack data at some victims' environments, based on a claim made in a ShinyHunters-branded data leak site (DLS) entry.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "AppAccessContext": {
    "AADSessionId": "[REDACTED_GUID]",
    "AuthTime": "1601-01-01T00:00:00",
    "ClientAppId": "[REDACTED_APP_ID]",
    "ClientAppName": "Microsoft Office",
    "CorrelationId": "[REDACTED_GUID]",
    "TokenIssuedAtTime": "1601-01-01T00:02:56",
    "UniqueTokenId": "[REDACTED_ID]"
  },
  "CreationTime": "2026-01-10T13:17:11",
  "Id": "[REDACTED_GUID]",
  "Operation": "FileDownloaded",
  "OrganizationId": "[REDACTED_GUID]",
  "RecordType": 6,
  "UserKey": "[REDACTED_USER_KEY]",
  "UserType": 0,
  "Version": 1,
  "Workload": "SharePoint",
  "ClientIP": "[REDACTED_IP]",
  "UserId": "[REDACTED_EMAIL]",
  "ApplicationId": "[REDACTED_APP_ID]",
  "AuthenticationType": "OAuth",
  "BrowserName": "Mozilla",
  "BrowserVersion": "5.0",
  "CorrelationId": "[REDACTED_GUID]",
  "EventSource": "SharePoint",
  "GeoLocation": "NAM",
  "IsManagedDevice": false,
  "ItemType": "File",
  "ListId": "[REDACTED_GUID]",
  "ListItemUniqueId": "[REDACTED_GUID]",
  "Platform": "WinDesktop",
  "Site": "[REDACTED_GUID]",
  "UserAgent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294",
  "WebId": "[REDACTED_GUID]",
  "DeviceDisplayName": "[REDACTED_IPV6]",
  "EventSignature": "[REDACTED_SIGNATURE]",
  "FileSizeBytes": 31912,
  "HighPriorityMediaProcessing": false,
  "ListBaseType": 1,
  "ListServerTemplate": 101,
  "SensitivityLabelId": "[REDACTED_GUID]",
  "SiteSensitivityLabelId": "",
  "SensitivityLabelOwnerEmail": "[REDACTED_EMAIL]",
  "SourceRelativeUrl": "[REDACTED_RELATIVE_URL]",
  "SourceFileName": "[REDACTED_FILENAME]",
  "SourceFileExtension": "xlsx",
  "ApplicationDisplayName": "Microsoft Office",
  "SiteUrl": "[REDACTED_URL]",
  "ObjectId": "[REDACTED_URL]/[REDACTED_FILENAME]"
}</code></pre>
<p><span>Figure 2: <span>SharePoint/M365 log example</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>"Login","20260120163111.430","SLB:[REDACTED]","[REDACTED]","[REDACTED]","192","25","/index.jsp","","1jVcuDh1VIduqg10","Standard","","167158288","5","Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/IP_ADDRESS_REMOVED Safari/537.36","","9998.0","user@[REDACTED_DOMAIN].com","TLSv1.3","TLS_AES_256_GCM_SHA384","","https://[REDACTED_IDP_DOMAIN]/","[REDACTED].my.salesforce.com","CA","","","0LE1Q000000LBVK","2026-01-20T16:31:11.430Z","[REDACTED]","76.64.54[.]159","","LOGIN_NO_ERROR","76.64.54[.]159",""</code></pre>
<p><span>Figure 3: <span>Salesforce log example</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "Timestamp": "2026-01-21T12:5:2-03:00",
  "Timestamp UTC": "[REDACTED]",
  "Event Name": "User downloads documents from an envelope",
  "Event Id": "[REDACTED_EVENT_ID]",
  "User": "[REDACTED]@example.com",
  "User Id": "[REDACTED_USER_ID]",
  "Account": "[REDACTED_ORG_NAME]",
  "Account Id": "[REDACTED_ACCOUNT_ID]",
  "Integrator Key": "[REDACTED_KEY]",
  "IP Address": "73.135.228[.]98",
  "Latitude": "[REDACTED]",
  "Longitude": "[REDACTED]",
  "Country/Region": "United States",
  "State": "Maryland",
  "City": "[REDACTED]",
  "Browser": "Chrome 143",
  "Device": "Apple Mac",
  "Operating System": "Mac OS X 10",
  "Source": "Web",
  "DownloadType": "Archived",
  "EnvelopeId": "[REDACTED_ENVELOPE_ID]"
}</code></pre>
<p><span>Figure 4: <span>Docusign log example</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>In at least one incident where the threat actor gained access to an Okta customer account, UNC6661 enabled the </span><a href="https://www.tooglebox.com/features/email-recall" rel="noopener" target="_blank"><span>ToogleBox Recall</span></a><span> add-on for the victim's Google Workspace account, a tool designed to search for and permanently delete emails. They then deleted a "Security method enrolled" email from Okta, almost certainly to prevent the employee from identifying that their account was associated with a new MFA device.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "Date": "2026-01-11T06:3:00Z",
  "App ID": "[REDACTED_ID].apps.googleusercontent.com",
  "App name": "ToogleBox Recall",
  "OAuth event": "Authorize",
  "Description": "User authorized access to ToogleBox Recall for specific Gmail and Apps Script scopes.",
  "User": "user@[REDACTED_DOMAIN].com",
  "Scope": "https://www.googleapis.com/auth/gmail.addons.current.message.readonly, https://www.googleapis.com/auth/gmail.addons.execute, https://www.googleapis.com/auth/script.external_request, https://www.googleapis.com/auth/script.locale, https://www.googleapis.com/auth/userinfo.email",
  "API name": "",
  "Method": "",
  "Number of response bytes": "0",
  "IP address": "149.50.97.144",
  "Product": "Gmail, Apps Script Runtime, Apps Script Api, Identity, Unspecified",
  "Client type": "Web",
  "Network info": "{\n  \"Network info\": {\n    \"IP ASN\": \"201814\",\n    \"Subdivision code\": \"\",\n    \"Region code\": \"PL\"\n  }\n}"
}</code></pre>
<p><span>Figure 5: <span>ToogleBox Recall auth log entry example</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>In at least one case, after conducting the initial data theft, UNC6661 used their newly obtained access to compromised email accounts to send additional phishing emails to contacts at cryptocurrency-focused companies. The threat actor then deleted the outbound emails, likely in an attempt to obfuscate their malicious activity.</span></p>
<p><span>GTIG attributes the subsequent extortion activity following UNC6661 intrusions to </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion"><span>UNC6240</span></a><span>, based on several overlaps, including the use of a common Tox account for negotiations, ShinyHunters-branded extortion emails, and Limewire to host samples of stolen data. In mid-January 2026 extortion emails, UNC6240 outlined what data they allegedly stole, specifying a payment amount and destination BTC address, and threatening consequences if the ransom was not paid within 72 hours, which is consistent with prior extortion emails (Figure 6). They also provided proof of data theft via samples hosted on Limewire. GTIG also observed extortion text messages sent to employees and received reports of victim websites being targeted with distributed denial-of-service (DDoS) attacks.</span></p>
<p><span>Notably, in late January 2026 a new ShinyHunters-branded DLS named "SHINYHUNTERS" emerged listing several alleged victims who may have been compromised in these most recent extortion operations. The DLS also lists contact information (shinycorp@tutanota[.]com, shinygroup@onionmail[.]com) that have previously been associated with UNC6240.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/vishing-shinyhunters-fig6.max-1000x1000.png" alt="Ransom note extract">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="e0hj0">Figure 6: Ransom note extract</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>Similar Activity Conducted by UNC6671</span></h3>
<p><span>Also beginning in early January 2026, UNC6671 conducted vishing operations masquerading as IT staff and directing victims to enter their credentials and MFA authentication codes on a victim-branded credential harvesting site. The credential harvesting domains used the same structure as UNC6661, but were more often registered using Tucows. In at least some cases, the threat actors have gained access to Okta customer accounts. Mandiant has also observed evidence that UNC6671 leveraged PowerShell to download sensitive data from SharePoint and OneDrive. <span>While many of these TTPs are consistent with UNC6661, an extortion email stemming from UNC6671 activity was unbranded and used a different Tox ID for further contact. The threat actors employed aggressive extortion tactics following UNC6671 intrusions, including harassment of victim personnel. The extortion tactics and difference in domain registrars suggests that separate individuals may be involved with these sets of activity</span>.</span></p>
<h3><span>Remediation and Hardening</span></h3>
<p><span>Mandiant has published a comprehensive guide with </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas"><span>proactive hardening and detection recommendations</span></a><span>.</span></p>
<h3><span>Outlook and Implications</span></h3>
<p><span>This recent activity is similar to prior operations associated with UNC6240, which have frequently used vishing for initial access and have <a href="https://www.salesforce.com/blog/protecting-salesforce-data-after-an-identity-compromise/" rel="noopener" target="_blank">targeted Salesforce data</a>. It does, however, represent an expansion in the number and type of targeted cloud platforms, suggesting that the associated threat actors are modifying their operations to gather more sensitive data for extortion operations. Further, the use of a compromised account to send phishing emails to cryptocurrency-related entities suggests that associated threat actors may be building relationships with potential victims to expand their access or engage in other follow-on operations. Notably, this portion of the activity appears operationally distinct, given that it appears to target individuals instead of organizations.</span></p>
<h3><span>Indicators of Compromise (IOCs)</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a free </span><a href="https://www.virustotal.com/gui/collection/214da7a4bb12360a85e03a15da1ff74284e09651a33f4f760ee01230439c16af" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users.</span></p>
<h4><span>Phishing Domain Lure Patterns </span></h4>
<p><span>Threat actors associated with these clusters frequently register domains designed to impersonate legitimate corporate portals. At time of publication all identified phishing domains have been added to </span><a href="https://safebrowsing.google.com/" rel="noopener" target="_blank"><span>Chrome Safe Browsing</span></a><span>. These domains typically follow specific naming conventions using a variation of the organization name:</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Pattern</strong></p>
</td>
<td>
<p><strong>Examples (Defanged)</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Corporate SSO</span></p>
</td>
<td>
<p><span>&lt;companyname&gt;sso[.]com, my&lt;companyname&gt;sso[.]com, my-&lt;companyname&gt;sso[.]com</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Internal Portals</span></p>
</td>
<td>
<p><span>&lt;companyname&gt;internal[.]com, www.&lt;companyname&gt;internal[.]com, my&lt;companyname&gt;internal[.]com</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Support/Helpdesk</span></p>
</td>
<td>
<p><span>&lt;companyname&gt;support[.]com, ticket-&lt;companyname&gt;[.]support, support-&lt;companyname&gt;[.]com</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Identity Providers</span></p>
</td>
<td>
<p><span>&lt;companyname&gt;okta[.]com, &lt;companyname&gt;azure[.]com, on&lt;companyname&gt;zendesk[.]com</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Access Portal</span></p>
</td>
<td>
<p><span>&lt;companyname&gt;access[.]com, www.&lt;companyname&gt;access[.]com, my&lt;companyname&gt;acess[.]com</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Network Indicators</span></h4>
<p><span>Many of the network indicators identified in this campaign are associated with commercial VPN services or residential proxy networks, including Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and nsocks. Mandiant recommends that organizations exercise caution when using these indicators for broad blocking and prioritize them for hunting and correlation within their environments.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IOC</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>Association</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>24.242.93[.]122</span></p>
</td>
<td>
<p><span>11427</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>23.234.100[.]107</span></p>
</td>
<td>
<p><span>11878</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>23.234.100[.]235</span></p>
</td>
<td>
<p><span>11878</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>73.135.228[.]98</span></p>
</td>
<td>
<p><span>33657</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>157.131.172[.]74</span></p>
</td>
<td>
<p><span>46375</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>149.50.97[.]144</span></p>
</td>
<td>
<p><span>201814</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>67.21.178[.]234</span></p>
</td>
<td>
<p><span>400595</span></p>
</td>
<td>
<p><span>UNC6661</span></p>
</td>
</tr>
<tr>
<td>
<p><span>142.127.171[.]133</span></p>
</td>
<td>
<p><span>577</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>76.64.54[.]159</span></p>
</td>
<td>
<p><span>577</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>76.70.74[.]63</span></p>
</td>
<td>
<p><span>577</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>206.170.208[.]23</span></p>
</td>
<td>
<p><span>7018</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>68.73.213[.]196</span></p>
</td>
<td>
<p><span>7018</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>37.15.73[.]132</span></p>
</td>
<td>
<p><span>12479</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>104.32.172[.]247</span></p>
</td>
<td>
<p><span>20001</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>85.238.66[.]242</span></p>
</td>
<td>
<p><span>20845</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>199.127.61[.]200</span></p>
</td>
<td>
<p><span>23470</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>209.222.98[.]200</span></p>
</td>
<td>
<p><span>23470</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>38.190.138[.]239</span></p>
</td>
<td>
<p><span>27924</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
<tr>
<td>
<p><span>198.52.166[.]197</span></p>
</td>
<td>
<p><span>395965</span></p>
</td>
<td>
<p><span>UNC6671</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Google Security Operations</span></h4>
<p><a href="https://cloud.google.com/security/products/security-operations"><span>Google Security Operations</span></a><span> customers have access to these broad category rules and more under the Okta, Cloud Hacktool, and O365 rule packs. A walkthrough for </span><a href="https://security.googlecloudcommunity.com/community-blog-42/new-to-google-secops-leveraging-okta-curated-detections-to-detect-shinyhunters-related-activity-6693" rel="noopener" target="_blank"><span>operationalizing these findings</span></a><span> within the Google Security Operations is available in Part Three of this series. The activity discussed in the blog post is detected in Google Security Operations under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Okta Admin Console Access Failure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta Super or Organization Admin Access Granted</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta Suspicious Actions from Anonymized IP</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Okta User Assigned Administrator Role</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint Bulk File Access or Download via PowerShell</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint High Volume File Access Events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 SharePoint High Volume File Download Events</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 Sharepoint Query for Proprietary or Privileged Information</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>O365 Deletion of MFA Modification Notification Email</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Workspace ToogleBox Recall OAuth Application Authorized</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code> $e.metadata.product_name = "Okta"
    $e.metadata.product_event_type = /\.(add|update_|(policy.rule|zone)\.update|create|register|(de)?activate|grant|reset_all|user.session.access_admin_app)$/
    (
         $e.security_result.detection_fields["anonymized IP"] = "true" or
         $e.extracted.fields["debugContext.debugData.tunnels"] = /\"anonymous\":true/
    )
    $e.security_result.action = “ALLOW”</code></pre>
<p><span><span>Figure 7: Hunting query for suspicious Okta actions conducted from anonymized IPs</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$e.metadata.vendor_name = "Google Workspace"
   $e.metadata.event_type = "USER_RESOURCE_ACCESS"
   $e.metadata.product_event_type = "authorize"
   $e.target.resource.name = /ToogleBox Recall/ nocase</code></pre>
<p><span><span>Figure 8: Hunting query for Google Workspace authorization events for ToogleBox Recall</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$e.principal.ip_geo_artifact.network.organization_name = /mullvad.vpn|oxylabs|9proxy|netnut|infatica|nsocks/ nocase or
   $e.extracted.fields["debugContext.debugData.tunnels"] = /mullvad.vpn|oxylabs|9proxy|netnut|infatica|nsocks/ nocase</code></pre>
<p><span><span>Figure 9: Hunting query for suspicious VPN / proxy services observed in this campaign</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$e.network.http.user_agent = /Geny\s?Mobile/ nocase
   $event.security_result.action != "BLOCK"</code></pre>
<p><span><span>Figure 10: Hunting query for suspicious user-agent string observed in this campaign</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>   $e.metadata.log_type = "OFFICE_365"   
  ($e.metadata.product_event_type = "FileDownloaded" or $e.metadata.product_event_type = "FileAccessed")
   (
     $e.target.application = "SharePoint" or
     $e.principal.application = "SharePoint"
   )
   $e.network.http.user_agent = /PowerShell/ nocase</code></pre>
<p><span><span>Figure 11: Hunting query for programmatic file access or downloads from SharePoint where the User-Agent identifies as PowerShell</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
   $e.metadata.log_type = "OFFICE_365"   
   $e.metadata.product_event_type = "FileAccessed"
   (
     $e.target.application = "SharePoint" or
     $e.principal.application = "SharePoint"
   )
   $e.target.file.full_path = /\.(doc[mx]?|xls[bmx]?|ppt[amx]?|pdf)$/ nocase
   $file_extension_extract = re.capture($e.target.file.full_path, `\.([^\.]+)$`)
   $event.security_result.action != "BLOCK"
   $session_id = $e.network.session_id

 match:
    $session_id over 5m

outcome:
   $target_url_count = count_distinct(strings.coalesce($e.target.file.full_path))
   $extension_count = count_distinct($file_extension_extract)

condition:
   $e and $target_url_count &gt;= 50 and $extension_count &gt;= 3</code></pre>
<p><span><span>Figure 12: Hunting query for high volume document file access from SharePoint</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>events:
   $e.metadata.log_type = "OFFICE_365"   
   $e.metadata.product_event_type = "FileDownloaded"
   (
     $e.target.application = "SharePoint" or
     $e.principal.application = "SharePoint"
   )
   $e.target.file.full_path = /\.(doc[mx]?|xls[bmx]?|ppt[amx]?|pdf)$/ nocase
   $file_extension_extract = re.capture($e.target.file.full_path, `\.([^\.]+)$`)
   $event.security_result.action != "BLOCK"
   $session_id = $e.network.session_id

 match:
    $session_id over 5m

outcome:
   $target_url_count = count_distinct(strings.coalesce($e.target.file.full_path))
   $extension_count = count_distinct($file_extension_extract)

condition:
   $e and $target_url_count &gt;= 50 and $extension_count &gt;= 3</code></pre>
<p><span><span>Figure 13: Hunting query for high volume document file downloads from SharePoint</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$e.metadata.log_type = "OFFICE_365"   
   $e.metadata.product_event_type = "SearchQueryPerformed"
   $e.additional.fields["search_query_text"] = /\bpoc\b|proposal|confidential|internal|salesforce|vpn/ nocase</code></pre>
<p><span><span>Figure 14: Hunting query for SharePoint queries for strings of interest</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$e.metadata.log_type = "OFFICE_365"   
   $e.target.application = "Exchange"
   $e.metadata.product_event_type = /^(SoftDelete|HardDelete|MoveToDeletedItems)$/ nocase
   $e.network.email.subject = /new\s+(mfa|multi-|factor|method|device|security)|\b2fa\b|\b2-Step\b|(factor|method|device|security|mfa)\s+(enroll|registered|added|change|verify|updated|activated|configured|setup)/ nocase

   // filtering specifically for new device registration strings
   $e.network.email.subject = /enroll|registered|added|change|verify|updated|activated|configured|setup/ nocase
    
   // tuning out new device logon events
   $e.network.email.subject != /(sign|log)(-|\s)?(in|on)/ nocase</code></pre>
<p><span><span>Figure 15: Hunting query for O365 Exchange deletion of MFA modification notification email</span></span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Beginners Guide: Cross-Device Passkeys]]></title>
<description><![CDATA[Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.]]></description>
<link>https://tsecurity.de/de/3501437/it-security-nachrichten/a-beginners-guide-cross-device-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501437/it-security-nachrichten/a-beginners-guide-cross-device-passkeys/</guid>
<pubDate>Fri, 08 May 2026 23:20:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.]]></content:encoded>
</item>
<item>
<title><![CDATA[Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition]]></title>
<description><![CDATA[Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden

UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms.
Background
Threat actors leverage destructive malware to destroy data, eliminate evidence ...]]></description>
<link>https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501421/it-security-nachrichten/proactive-preparation-and-hardening-against-destructive-attacks-2026-edition/</guid>
<pubDate>Fri, 08 May 2026 23:19:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden</p>
<hr></div>
<div class="block-paragraph_advanced"><p><em>UPDATE (March 13): <span>Added guidance around abuse or misuse of endpoint / MDM platforms</span>.</em></p>
<h3><span>Background</span></h3>
<p><span>Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable. Destructive cyberattacks can be a powerful means to achieve strategic or tactical objectives; however, the risk of reprisal is likely to limit the frequency of use to very select incidents. Destructive cyberattacks can include destructive malware, wipers, or modified ransomware.</span></p>
<p><span><span>When conflict erupts, cyber attacks are an inexpensive and easily deployable weapon. It should come as no surprise that instability leads to increases in attacks. </span>This blog post provides proactive recommendations for organizations to prioritize for protecting against a destructive attack within an environment. The recommendations include practical and scalable methods that can help protect organizations from not only destructive attacks, but potential incidents where a threat actor is attempting to perform reconnaissance, escalate privileges, laterally move, maintain access, and achieve their mission. </span></p>
<p><span>The detection opportunities outlined in this blog post are meant to act as supplementary monitoring to existing security tools. Organizations should leverage endpoint and network security tools as additional preventative and detective measures. These tools use a broad spectrum of detective capabilities, including signatures and heuristics, to detect malicious activity with a reasonable degree of fidelity. The custom detection opportunities referenced in this blog post are correlated to specific threat actor behavior and are meant to trigger anomalous activity that is identified by its divergence from normal patterns. Effective monitoring is dependent on a thorough understanding of an organization's unique environment and usage of pre-established baselines.</span></p>
<h3><span>Organizational Resilience</span></h3>
<p><span>While the core focus of this blog post is aligned to technical- and tactical-focused security controls, technical preparation and recovery are not the </span><span>only</span><span> strategies. Organizations that include crisis preparation and orchestration as key components of security governance can naturally adopt a "living" resilience posture. This includes:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Out-of-Band Incident Command and Communication</strong><span>: Establish a pre-validated, "out-of-band" communication platform that is completely decoupled from the corporate identity plane. This ensures that the key stakeholders and third-party support teams can coordinate and communicate securely, even if the primary communication platform is unavailable.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Defined Operational Contingency and Recovery Plans: </strong><span>Establish baseline operational requirements, including manual procedures for vital business functions to ensure continuity during restoration or rebuild efforts. Organizations must also develop prioritized application recovery sequences and map the essential dependencies needed to establish a secure foundation for recovery goals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Pre-Establish Trusted Third-Party Vendor Relationships: </strong><span>Based on the range of technologies and platforms vital to business operations, develop predefined agreements with external partners to ensure access to specialists for legal / contractual requirements, incident response, remediation, recovery, and ransomware negotiations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Practice and Refine the Recovery: </strong><span>Conduct exercises that validate the end-to-end restoration of mission-critical services using isolated, immutable backups and out-of-band communication channels, ensuring that recovery timelines (RTO) and data integrity (RPO) are tested, practiced, and current. </span></p>
</li>
</ul>
<h3><span>Google Security Operations</span></h3>
<p><a href="https://cloud.google.com/security/products/security-operations"><span>Google Security Operations</span></a><span> (SecOps) customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats, Mandiant Frontline Threats, Mandiant Hunting Rules, CDIR SCC Enhanced Data Destruction Alerts rule packs. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>BABYWIPER File Erasure</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Evidence Destruction And Cleanup Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CMD Launching Application Self Delete</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Copy Binary From Downloads</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Rundll32 Execution Of Dll Function Name Containing Special Character</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Services Launching Cmd</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>System Process Execution Via Scheduled Task</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Dllhost Masquerading</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Backdoor Writing Dll To Disk For Injection</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Multiple Exclusions Added To Windows Defender In Single Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path Exclusion Added to Windows Defender</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Change to CurrentControlSet Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Powershell Set Content Value Of 0</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Overwrite Disk Using DD Utility</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Bcdedit Modifications Via Command</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Disabling Crash Dump For Drive Wiping</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Wbadmin Commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Fsutil File Zero Out</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><h3><span>Recommendations Summary</span></h3>
<p><span>Table 1 provides a high-level overview of guidance in this blog post.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Focus Area</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=1.%20External-Facing%20Assets"><span>External-Facing Assets</span></a></p>
</td>
<td>
<p><span>Protect against the risk of threat actors exploiting an externally facing vector or leveraging existing technology for unauthorized remote access.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=2.%20Critical%20Asset%20Protections"><span>Critical Asset Protections</span></a></p>
</td>
<td>
<p><span>Protect specific high-value infrastructure and prepare for recovery from a destructive attack.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=3.%20On-Premises%20Lateral%20Movement%20Protections"><span>On-Premises Lateral Movement Protections</span></a></p>
</td>
<td>
<p><span>Protect against a threat actor with initial access into an environment from moving laterally to further expand their scope of access and persistence.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=4.%20Credential%20Exposure%20and%20Account%20Protections"><span>Credential Exposure and Account Protections</span></a></p>
</td>
<td>
<p><span>Protect against the exposure of privileged credentials to facilitate privilege escalation.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks#:~:text=5.%20Preventing%20Destructive%20Actions%20in%20Kubernetes%20and%20CI%2FCD%20Pipelines"><span>Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></a></p>
</td>
<td>
<p><span>Protect the integrity and availability of Kubernetes environments and CI/CD pipelines.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 1: </span><span>Overview of recommendations</span></span></div></div>
<div class="block-paragraph_advanced"><h3><span>1. External-Facing Assets</span></h3>
<h4><span>Identify, Enumerate, and Harden</span></h4>
<p><span>To protect against a threat actor exploiting vulnerabilities or misconfigurations via an external-facing vector, organizations must determine the scope of applications and organization-managed services that are externally accessible. Externally accessible applications and services (including both on-premises and cloud) are often targeted by threat actors for initial access by exploiting known vulnerabilities, brute-forcing common or default credentials, or authenticating using valid credentials. </span></p>
<p><span>To proactively identify and validate external-facing applications and services, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Leveraging a </span><span>vulnerability scanning technology to identify assets and associated vulnerabilities. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Performing a focused vulnerability assessment or penetration test with the goal of identifying external-facing vectors that could be leveraged for authentication and access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Verifying with technology vendors if the products leveraged by an organization for external-facing services require patches or updates to mitigate known vulnerabilities. </span></p>
</li>
</ul>
<p><span>Any identified vulnerabilities should not only be patched and hardened, but the identified technology platforms should also be reviewed to ensure that evidence of suspicious activity or technology/device modifications have not already occurred.</span></p>
<p><span>The following table provides an overview of capabilities to proactively review and identify external-facing assets and resources within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Attack Surface Discovery Capability</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/security-command-center"><span>Security Command Center</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html" rel="noopener" target="_blank"><span>AWS Config / Inspector</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/external-attack-surface-management/" rel="noopener" target="_blank"><span>Defender External Attack Surface Management (Defender EASM</span></a><span>)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span><span>Table 2: Overview of cloud provider attack surface discovery capabilities</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Enforce Multi-Factor Authentication</span></h4>
<p><span>External-facing assets that leverage single-factor authentication (SFA) are highly susceptible to brute-forcing attacks, password spraying, or unauthorized remote access using valid (stolen) credentials. External-facing applications and services that currently allow for SFA should be configured to support multi-factor authentication (MFA). Additionally, MFA should be leveraged for accessing not only on-premises external-facing managed infrastructure, but also for cloud-based resources (e.g., software-as-a-service [SaaS] such as Microsoft 365 [M365]). </span></p>
<p><span>When configuring multifactor authentication, the following methods are commonly considered (and ranked from most to least secure):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Fast IDentity Online 2 (FIDO2)/WebAuthn security keys or passkeys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Software/hardware Open Authentication (OAUTH) token</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Authenticator application (e.g., Duo/Microsoft [MS] Authenticator/Okta Verify)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Time-based One Time Password (TOTP)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Push notification (least preferred option) using number matching when possible</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Phone call</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Short Message Service (SMS) verification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Email-based verification</span></p>
</li>
</ul>
<h4><span>Risks of Specific MFA Methods</span></h4>
<h5><span>Push Notifications</span></h5>
<p><span>If an organization is leveraging push notifications for MFA (e.g., a notification that requires acceptance via an application or automated call to a mobile device), threat actors can exploit this type of MFA configuration for attempted access, as a user may inadvertently accept a push notification on their device without the context of where the authentication was initiated. </span></p>
<h5><span>Phone/SMS Verification</span></h5>
<p><span>If an organization is leveraging phone calls or SMS-based verification for MFA, these methods are not encrypted and are susceptible to potentially being intercepted by a threat actor. These methods are also vulnerable if a threat actor is able to transfer an employee's phone number to an attacker-controlled subscriber identification module (SIM) card. This would result in the MFA notifications being routed to the threat actor instead of the intended employee. </span></p>
<h5><span>Email-Based Verification</span></h5>
<p><span>If an organization is leveraging email-based verification for validating access or for retrieving MFA codes, and a threat actor has already established the ability to access the email of their target, the actor could potentially also retrieve the email(s) to validate and complete the MFA process. </span></p>
<p><span>If any of these MFA methods are leveraged, consider:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Training remote users to never accept or respond to a logon notification when they are not actively attempting to log in.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Establishing a method for users to report suspicious MFA notifications, as this could be indicative of a compromised account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensuring there are messaging policies in place to prevent the auto-forwarding of email messages outside the organization.</span></p>
</li>
</ul>
<h5><span>Time-Based One-Time Password</span></h5>
<p><span>Time-based one-time password (TOTP) relies on a shared secret, called a seed, known by both the authenticating system and the authenticator possessed by an end user. If a seed is compromised, the TOTP authenticator can be duplicated and used by a threat actor.</span></p>
<h4><span><span>Detection Opportunities for External-Facing Assets and MFA Attempts</span></span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Brute Force</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
</td>
<td>
<p><span>Search for a single user with an excessive number of failed logins from external Internet Protocol (IP) addresses. </span></p>
<p><span>This risk can be mitigated by enforcing a strong password, MFA, and lockout policy.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Password Spray</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
</td>
<td>
<p><span>Search for a high number of accounts with failed logins, typically from the similar origination addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA conditions for the same account. This may be indicative of a previously compromised credential.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Multiple Failed MFA Same Source</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/003/" rel="noopener" target="_blank"><span>T1110.003 – Password Spray</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for multiple failed MFA prompts for different users from the same source. This may be indicative of multiple compromised credentials and an attempt to "spray" MFA prompts/tokens for access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Authentication from an Account with Elevated Privileges</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Privileged accounts should use internally managed and secured privileged access workstations for access and should not be accessible directly from an external (untrusted) source.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Adversary in the Middle (AiTM) Session Token Theft</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/" rel="noopener" target="_blank"><span>T1557 - Adversary in the Middle</span></a></p>
</td>
<td>
<p><span>Monitor for sign-ins where the authentication method succeeds but the session originates from an IP/ASN inconsistent with the user's prior sessions. </span></p>
<p><span>Detect logins from newly registered domains or known reverse-proxy infrastructure (EvilProxy, Tycoon 2FA). </span></p>
<p><span>Correlate sign-in logs for "isInteractive: true" sessions with anomalous user-agent strings or geographically impossible travel.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MFA Fatigue / Prompt Bombing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1621/" rel="noopener" target="_blank"><span>T1621 - MFA Request Generation</span></a></p>
</td>
<td>
<p><span>Search for accounts receiving more than five MFA push notifications within a 10-minute window without a corresponding successful authentication. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Post-Authentication MFA Device Registration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/005/" rel="noopener" target="_blank"><span>T1098.005 - Account Manipulation - Device Registration</span></a></p>
</td>
<td>
<p><span>Monitor audit logs for new MFA device registrations (AuthenticationMethodRegistered) occurring within 60 minutes of a sign-in from a new IP or device. Attackers who steal session tokens via AiTM immediately register their own MFA device for persistent access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>OAuth/Consent Phishing</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1550/001/" rel="noopener" target="_blank"><span>T1550.001 - Use Alternate Authentication Material</span></a></p>
</td>
<td>
<p><span>Monitor for OAuth application consent grants with high-privilege scopes (Mail.Read, Files.ReadWrite.All) from unrecognized application IDs.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 3: Detection opportunities for external-facing assets and MFA attempts</span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>2. Critical Asset Protections</span></h3>
<h4><span>Domain Controller and Critical Asset Backups</span></h4>
<p><span>Organizations should verify that backups for domain controllers and critical assets are available and protected against unauthorized access or modification. Backup processes and procedures should be exercised on a continual basis. Backups should be protected and stored within secured enclaves that include both network and identity segmentation. </span></p>
<p><span>If an organization's Active Directory (AD) were to become corrupted or unavailable due to ransomware or a potentially destructive attack, restoring Active Directory from domain controller backups may be the only viable option to reconstitute domain services. The following domain controller recovery and reconstitution best practices should be proactively reviewed by organizations: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Verify that there is a known good backup of domain controllers and </span><code>SYSVOL</code><span> shares (e.g., from a domain controller – backup </span><code>C:\Windows\SYSVOL</code><span>).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span><span>For domain controllers, a system state backup is preferred.</span> <br><br></span><strong>Note:</strong><span> </span><span>For a system state backup to occur, </span><span>Windows Server Backup</span><span> must be installed as a feature on a domain controller. </span></p>
</li>
<li aria-level="1">
<p role="presentation">The following command can be run from an elevated command prompt to initiate a system state backup of a domain controller.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>wbadmin start systemstatebackup -backuptarget:&lt;targetDrive&gt;:</code></pre>
<p><span>Figure 1: Command to perform a system state backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li><span>The following command can be run from an elevated command prompt to perform a </span><code>SYSVOL</code><span> backup. (</span><span>Manage auditing and security log</span><span> permissions must also be configured for the account performing the backup.)</span></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>robocopy c:\windows\sysvol c:\sysvol-backup /copyall /mir /b /r:0 /xd</code></pre>
<p><span>Figure 2: Command to perform a SYSVOL backup</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Proactively identify domain controllers that hold flexible single master operation (FSMO) roles, as these domain controllers will need to be prioritized for recovery in the event that a full domain restoration is required. </span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>netdom query fsmo</code></pre>
<p><span>Figure 3: Command to identify domain controllers that hold FSMO roles</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li aria-level="1">
<p role="presentation"><span>Offline backups: Ensure offline domain controller backups are secured and stored separately from online backups. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Encryption: Backup data should be encrypted both during transit (over the wire) and when at rest or mirrored for offsite storage. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DSRM Password validation: Ensure that the Directory Services Restore Mode (DSRM) password is set to a known value for each domain controller. This password is required when performing an authoritative or nonauthoritative domain controller restoration. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Configure alerting for backup operations: Backup products and technologies should be configured to detect and provide alerting for operations critical to the availability and integrity of backup data (e.g., deletion of backup data, purging of backup metadata, restoration events, media errors). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce role-based access control (RBAC): Access to backup media and the applications that govern and manage data backups should use RBAC to restrict the scope of accounts that have access to the stored data and configuration parameters. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Testing and verification: Both authoritative and nonauthoritative domain controller restoration processes should be documented and tested on a regular basis. The same testing and verification processes should be enforced for critical assets and data.</span></p>
</li>
</ul>
<h4><span>Business Continuity Planning</span></h4>
<p><span>Critical asset recovery is dependent upon in-depth planning and preparation, which is often included within an organization's business continuity plan (BCP). Planning and recovery preparation should include the following core competencies:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A well-defined understanding of crown jewels data and supporting applications that align to backup, failover, and restoration tasks that prioritize mission-critical business operations</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clearly defined asset prioritization and recovery sequencing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Thoroughly documented recovery processes for critical systems and data</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trained personnel to support recovery efforts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Validation of recovery processes to ensure successful execution</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Clear delineation of responsibility for managing and verifying data and application backups</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Online and offline data backup retention policies, including initiation, frequency, verification, and testing (for both on-premises and cloud-based data)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Established service-level agreements (SLAs) with vendors to prioritize application and infrastructure-focused support</span></p>
</li>
</ul>
<p><span>Continuity and recovery planning can become stale over time, and processes are often not updated to reflect environment and personnel changes. Prioritizing evaluations, continuous training, and recovery validation exercises will enable an organization to be better prepared in the event of a disaster.</span></p>
<h4><span>Detection Opportunities for Backups</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div> </div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Volume Shadow Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 – Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor will delete volume shadow copies to inhibit system recovery. This can be accomplished using the command line, PowerShell, and other utilities.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for unauthorized users attempting to access the media and applications that are used to manage data backups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Usage of the DSRM Password</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Monitor security event logs on domain controllers for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Event ID 4794 - An attempt was made to set the Directory Services Restore Mode administrator password</span></p>
</li>
</ul>
<p><span>Monitoring the following registry key on domain controllers:<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DSRMAdminLogonBehavior</code></pre>
<p><span>Figure 4: DSRM registry key for monitoring</span></p>
<p><span>The possible values for the registry key noted in Figure 4 are:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>0</code><span> (default): The DSRM Administrator account can only be used if the domain controller is restarted in Directory Services Restore Mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>1</code><span>: The DSRM Administrator account can be used for a console-based log on if the local </span><span>Active Directory Domain Services</span><span> service is stopped.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>2</code><span>: The DSRM Administrator account can be used for console or network access without needing to reboot a domain controller.</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table <span>4: Detection opportunities for backups</span></span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>IT and OT Segmentation</span></h4>
<p><span>Organizations should ensure that there is both physical and logical segmentation between corporate information technology (IT) domains, identities, networks, and assets and those used in direct support of operational technology (OT) processes and control. By enforcing IT and OT segmentation, organizations can inhibit a threat actor's ability to pivot from corporate environments to mission-critical OT assets using compromised accounts and existing network access paths. </span></p>
<p><span>OT environments should leverage separate identity stores (e.g., dedicated Active Directory domains), which are not trusted or cross-used in support of corporate identity and authentication. </span><strong>The compromise of a corporate identity or asset should not result in a threat actor's ability to directly pivot to accessing an asset that has the ability to influence an OT process.</strong></p>
<p><span>In addition to separate AD forests being leveraged for IT and OT, segmentation should also include technologies that may have a dual use in the IT and OT environments (backup servers, antivirus [AV], endpoint detection and response [EDR], jump servers, storage, virtual network infrastructure). OT segmentation should be designed such that if there is a disruption in the corporate (IT) environment, the OT process can safely function independently, without a direct dependency (account, asset, network pathway) with the corporate infrastructure. For any dependencies that cannot be readily segmented, organizations should identify potential short-term processes or manual controls to ensure that the OT environment can be effectively isolated if evidence of an IT (corporate)-focused incident were detected. </span></p>
<p><span>Segmenting IT and OT environments is a best practice recommended by industry standards such as the National Institute of Standards and Technology (NIST) <em>SP 800-82r3</em></span><span>: <a href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf" rel="noopener" target="_blank">Guide to Operational Technology (OT) Security</a></span><span> and </span><a href="https://www.isa.org/intech-home/2018/september-october/departments/new-standard-specifies-security-capabilities-for-c" rel="noopener" target="_blank"><span>IEC 62443</span></a><span> (formerly ISA99).</span></p>
<p><span>According to these best-practice standards, segmenting IT and OT networks should include the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OT attack surface reduction by restricting the scope of ports, services, and protocols that are directly accessible within the OT network from the corporate (IT) network.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Incoming access from corporate (IT) into OT must terminate within a segmented OT demilitarized zone (DMZ). The OT DMZ must require that a separate level of authentication and access be granted (outside of leveraging an account or endpoint that resides within the corporate IT domain). </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Explicit firewall rules should restrict both incoming traffic from the corporate environment and outgoing traffic from the OT environment.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Firewalls should be configured using the principle of deny by default, with only approved and authorized traffic flows permitted. Egress (internet) traffic flows for all assets that support OT should also follow the deny-by-default model.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Identity (account) segmentation must be enforced between corporate IT and OT. An account or endpoint within either environment should not have any permissions or access rights assigned outside of the respective environment. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote access to the OT environment should not leverage similar accounts that have remote access permissions assigned within the corporate IT environment. </span><strong>MFA using separate credentials should be enforced for remotely accessing OT assets and resources.</strong></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Training and verification of manual control processes, including isolation and reliability verification for safety systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secured enclaves for storing backups, programming logic, and logistical diagrams for systems and devices that comprise the OT infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The default usernames and passwords associated with OT devices should always be changed from the default vendor configuration(s). </span></p>
</li>
</ul>
<h4><span>Detection Opportunities for IT and OT Segmented Environments</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Service Scanning</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1046/" rel="noopener" target="_blank"><span>T1046 – Network Service Scanning</span></a></p>
</td>
<td>
<p><span>Search for instances where a threat actor is performing internal network discovery to identify open ports and services between segmented environments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Authentication Attempts Between Segmented Environments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for failed logins for accounts limited to one environment attempting to log in within another environment. This can detect threat actors attempting to reuse credentials for lateral movement between networks.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 5: Detection opportunities for IT and OT segmented environments</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Egress Restrictions</span></h4>
<p><span>Servers and assets that are infrequently rebooted are highly targeted by threat actors for establishing backdoors to create persistent beacons to command-and-control (C2) infrastructure. By blocking or severely limiting internet access for these types of assets, an organization can effectively reduce the risk of a threat actor compromising servers, extracting data, or installing backdoors that leverage egress communications for maintaining access.</span></p>
<p><span>Egress restrictions should be enforced so that servers, internal network devices, critical IT assets, OT assets, and field devices cannot attempt to communicate to external sites and addresses (internet resources). The concept of deny by default should apply to all servers, network devices, and critical assets (including both IT and OT), with only allow-listed and authorized egress traffic flows explicitly defined and enforced. Where possible, this should include blocking recursive Domain Name System (DNS) resolutions not included in an allow-list to prevent communication via DNS tunneling.</span></p>
<p><span>If possible, egress traffic should be routed through an inspection layer (such as a proxy) to monitor external connections and block any connections to malicious domains or IP addresses. Connections to uncategorized network locations (e.g., a domain that has been recently registered) should not be permitted. Ideally, DNS requests would be routed through an external service (e.g., Cisco Umbrella, Infoblox DDI) to monitor for lookups to malicious domains. </span></p>
<p><span>Threat actors often attempt to harvest credentials (including New Technology Local Area Network [LAN] Manager [NTLM] hashes) based upon outbound Server Message Block (SMB) or Web-based Distributed Authoring and Versioning (WebDAV) communications. Organizations should review and limit the scope of egress protocols that are permissible from </span><strong>any</strong><span> endpoint within the environment. While Hypertext Transfer Protocol (HTTP) (Transmission Control Protocol (TCP)/80) and HTTP Secure (HTTPS) (TCP/443) egress communications are likely required for many user-based endpoints, the scope of external sites and addresses can potentially be limited based upon web traffic-filtering technologies. Ideally, organizations should only permit egress protocols and communications based upon a predefined allow-list. Common high-risk ports for egress restrictions include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File Transfer Protocol (FTP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (RDP)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Secure Shell (SSH)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Server Message Block (SMB)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Trivial File Transfer Protocol (TFTP) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WebDAV</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Suspicious Egress Traffic Flows</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>External Connection Attempt to a Known Malicious IP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Leverage threat feeds to identify attempted connections to known bad IP addresses.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>External Communications from Servers, Critical Assets, and Isolated Network Segments</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/tactics/TA0011/" rel="noopener" target="_blank"><span>TA0011 – Command and Control</span></a></p>
</td>
<td>
<p><span>Search for egress traffic flows from subnets and addresses that correlate to servers, critical assets, OT segments, and field devices.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connections Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 6: Detection opportunities for suspicious egress traffic flows</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Virtualization Infrastructure Protections</span><strong> </strong></h4>
<p><span>Threat actors often target virtualization infrastructure (e.g., VMware vSphere, Microsoft Hyper-V) as part of their reconnaissance, lateral movement, data theft, and potential ransomware deployment objectives. Securing virtualization infrastructure requires a Zero Trust network posture as a primary defense. Because management appliances often lack native MFA for local privileged accounts, identity-based security alone can be a high-risk single point of failure. If credentials are compromised, the logical network architecture becomes the final line of defense protecting the virtualization management plane.</span></p>
<p><span>To reduce the attack surface of virtualized infrastructure, a best practice for VMware vSphere vCenter ESXi and Hyper-V appliances and servers is to isolate and restrict access to the management interfaces, essentially enclaving these interfaces within isolated virtual local area networks (VLANs) (network segments) where connectivity is only permissible from dedicated subnets where administrative actions can be initiated.</span></p>
<p><span>To protect the virtualization control plane, organizations must consider a "defense-in-depth" network model. This architecture integrates physical isolation and east-west micro-segmentation to remove all access paths from untrusted networks. The result is a management zone that remains isolated and resilient, even during an active intrusion.</span></p>
<h5><span>VMware vSphere Zero-Trust Network Architecture</span><span> </span></h5>
<p><span>The primary goal is to ensure that even if privileged credentials are compromised, the logical network remains the definitive defensive layer preventing access to virtualization management interfaces.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Immutable VLAN Segmentation</strong><span>: Enforce strict isolation using distinct 802.1Q VLAN IDs for host management, Infrastructure/VCSA, vMotion (non-routable), Storage (non-routable), and production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Virtual Routing and Forwarding (VRF)</strong><span>: Transition all infrastructure VLANs into a dedicated VRF instance. This ensures that even a total compromise of the "User" or "Guest" zones results in no available route to the management zone(s).</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>ALLOW:</strong><span> TCP/443 (UI/API) and TCP/902 (MKS) from the PAW subnet only.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SSH (TCP/22) and VAMI (TCP/5480) from all sources </span><span>except</span><span> the PAW subnet.</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy:</strong><span> Enforce outbound filtering at the hardware gateway (as the VCSA GUI cannot manage egress). To prevent persistence using C2 traffic and data exfiltration, block all internet access except to specific, verified update servers (e.g., VMware Update Manager) and authorized identity providers.</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Complement network firewalls with host-level filtering to eliminate visibility gaps within the same VLAN.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VCSA (Photon OS)</strong><span>: Transition the default policy to "Default Deny" via the VAMI or, preferably, at the OS level using iptables/nftables for granular source/destination mapping. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>ESXi Hypervisors: </strong><span>Restrict all services (SSH, Web Access, NFC/Storage) to specific management IPs by deselecting "Allow connections from any IP address."</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://knowledge.broadcom.com/external/article/377036/how-to-block-all-traffic-on-vcenter-exce.htm" rel="noopener" target="_blank">VMware vSphere VCSA host based firewalls</a>.</span></p>
<p><span>A <a href="https://kb.vmware.com/s/article/1012382" rel="noopener" target="_blank">listing of administrative ports</a> associated with VMWare vCenter (that should be targeted for isolation).</span></p>
<h5><span>Hyper-V Zero-Trust Network Architecture </span></h5>
<p><span>Similar to vSphere, Hyper-V requires strict isolation of its various traffic types to prevent lateral movement from guest workloads to the management plane.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>VLAN Segmentation:</strong><span> Organizations must enforce isolation using distinct VLANs for Host Management, Live Migration, Cluster Heartbeat (CSV), and Production Guest VMs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Non-Routable Networks:</strong><span> Traffic for Live Migration and Cluster Shared Volumes (CSV) should be placed on non-routable VLANs to ensure these high-bandwidth, sensitive streams cannot be intercepted from other segments.</span></p>
</li>
</ul>
<h6><span>Layer 3 and 4 Access Policies</span></h6>
<p><span>The management network must be accessible only from trusted, hardened sources.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>PAW-Exclusive Access:</strong><span> Deconstruct all direct routes from the general corporate LAN to management subnets. Access must originate strictly from a designated Privileged Access Workstation (PAW) subnet.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Ingress Filtering (Management Zone)</strong><span>:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><strong>ALLOW</strong><span>: WinRM / PowerShell Remoting (TCP/5985 and TCP/5986), RDP (TCP/3389), and WMI/RPC (TCP/135 and dynamic RPC ports)strictly from the PAW subnet. If using Windows Admin Center, allow HTTPS (TCP/443) to the gateway.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><strong>DENY</strong><span>: Explicitly block SMB (TCP/445), RPC/WMI (TCP/135), and all other management traffic from untrusted sources to prevent credential theft and lateral movement.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><strong>Restrictive Egress Policy: </strong><span>Enforce outbound filtering at the network gateway. To prevent persistence using C2 traffic and data exfiltration, block all internet access from Hyper-V hosts except to specific, verified update servers (e.g., internal WSUS), authorized Active Directory Domain Controllers, and Key Management Servers (KMS).</span></p>
</li>
</ul>
<h6><span>Host-Based Firewall Enforcement</span></h6>
<p><span>Use the Windows Firewall with Advanced Security (WFAS) to achieve a defense-in-depth posture at the host level.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Scope Restriction: </strong><span>For all enabled management rules (e.g., File and Printer Sharing, WMI, PowerShell Remoting), modify the Remote IP Address scope to "These IP addresses" and enter only the PAW and management server subnets.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Management Logging: </strong><span>Enable logging for Dropped Packets in the Windows Firewall profile. This allows the SIEM to ingest "denied" connection attempts, which serve as high-fidelity indicators of internal reconnaissance or unauthorized access attempts.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/jj721516(v=ws.11)" rel="noopener" target="_blank">Hyper-V host based firewalls</a>.</span></p>
<p><span>Additional information related to <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/plan/plan-hyper-v-security-in-windows-server" rel="noopener" target="_blank">securing Hyper-V</a>.</span><span> </span></p>
<h5><span>General Virtualization Hardening </span></h5>
<p><span>To protect management interfaces for VMware vSphere the VMKernel network interface card (NIC) should </span><strong>not</strong><span> be bound to the same virtual network assigned to virtual machines running on the host. Additionally, ESXi servers can be configured in lockdown mode, which will only allow console access from the vCenter server(s). Additional information related to <a href="https://kb.vmware.com/s/article/1008077" rel="noopener" target="_blank">lockdown mode</a></span><span>.</span></p>
<p><span>The SSH protocol (TCP/22) provides a common channel for accessing a physical virtualization server or appliance (vCenter) for administration and troubleshooting. Threat actors commonly leverage SSH for direct access to virtualization infrastructure to conduct destructive attacks. In addition to enclaving access to administrative interfaces, SSH access to virtualization infrastructure should be disabled and only enabled for specific use-cases. If SSH is required, network ACLs should be used to limit where connections can originate.</span></p>
<p><span>Identity segmentation should also be configured when accessing administrative interfaces associated with virtualization infrastructure. If Active Directory authentication provides direct integrated access to the physical virtualization stack, a threat actor that has compromised a valid Active Directory account (with permissions to manage the virtualization infrastructure) could potentially use the account to directly access virtualized systems to steal data or perform destructive actions.</span></p>
<p><span>Authentication to virtualized infrastructure should rely upon dedicated and unique accounts that are configured with strong passwords and that are </span><strong>not</strong><span> co-used for additional access within an environment. Additionally, accessing management interfaces associated with virtualization infrastructure should only be initiated from isolated privileged access workstations, which prevent the storing and caching of passwords used for accessing critical infrastructure components.</span></p>
<h5><span>Protecting Hypervisors Against Offline Credential Theft and Exfiltration</span></h5>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address security gaps and mitigate the risk of offline credential theft from the hypervisor layer. The core of this attack is an offline credential theft technique known as a "Disk Swap." Once an adversary has administrative control over the hypervisor (vSphere or Hyper-V), they perform the following steps:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Target Identification:</strong><span> The actor identifies a critical virtualized asset, such as a Domain Controller (DC) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Offline Manipulation:</strong><span> The target VM is powered off, and its virtual disk file (e.g., .vmdk for VMware or .vhd/.vhdx for Hyper-V) is detached.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>NTDS.dit Extraction</strong><span>: The disk is attached to a staging or "orphaned" VM under the attacker's control. From this unmonitored machine, they copy the NTDS.dit Active Directory database.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Stealthy Recovery</strong><span>: The disk is re-attached to the original DC, and the VM is powered back on, leaving minimal forensic evidence within the guest operating system.</span></p>
</li>
</ul>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To defend against this logic, organizations must implement a defense-in-depth strategy that focuses on cryptographic isolation and strict lifecycle management.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Virtual Machine Encryption</strong><span>: Organizations must encrypt all Tier 0 virtualized assets (e.g., Domain Controllers, PKI, and Backup Servers). Encryption ensures that even if a virtual disk file is stolen or detached, it remains unreadable without access to the specific keys. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Strict Decommissioning Processes</strong><span>: Do not leave powered-off or "orphaned" virtual machines on datastores. These "ghost" VMs are ideal staging environments for attackers. Formally decommission assets by deleting their virtual disks rather than just removing them from the inventory.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Harden Hypervisor Accounts</strong><span>: Disable or restrict default administrative accounts (such as root on ESXi or the local Administrator on Hyper-V hosts). Enforce </span><a href="https://knowledge.broadcom.com/external/article/336894/enabling-or-disabling-lockdown-mode-on-a.html" rel="noopener" target="_blank"><span>Lockdown Mode</span></a><span> (VMware ESXi feature) where possible to prevent direct host-level changes outside of the central management plane.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Remote Audit Logging</strong><span>: Enable and forward all hypervisor-level audit logs (e.g., hostd.log, vpxa.log, or Windows Event Logs for Hyper-V) to a centralized SIEM. </span></p>
</li>
</ul>
<h5><span>Protecting Backups</span></h5>
<p><span>Security measures must encompass both production and backup environments. An attack on the production plane is often coupled with a simultaneous focus on backup integrity, creating a total loss of operational continuity. Virtual disk files (VMDK for VMware and VHD/VHDX for Hyper-V) represent a high-value target for offline data theft and direct manipulation.</span></p>
<h6><span>Hardening and Mitigation Guidance</span></h6>
<p><span>To mitigate the risk of offline theft and backup manipulation, organizations must implement a "Default Encrypted" policy across the entire lifecycle of the virtual disk .</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>At-Rest Encryption for all Tier-0 Assets:</strong><span> Implement vSphere VM Encryption or Hyper-V Shielded VMs for all critical infrastructure (e.g., Domain Controllers, Certificate Authorities). This ensures that the raw VMDK or VHDX files are cryptographically protected, rendering them unreadable if detached or mounted by an unauthorized party.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Encrypted Backup Repositories</strong><span>: Ensure that the backup application is configured to encrypt backup data at rest using a unique key stored in a separate, hardened Key Management System (KMS). This prevents "direct manipulation" of the backup files even if the backup storage itself is compromised. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Network Isolation of Storage &amp; Backups: </strong><span>Isolate the storage management network and the backup infrastructure into dedicated, non-routable VLANs. Access to the backup console and repositories must require phishing-resistant MFA and originate from a designated Privileged Access Workstation (PAW).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Immutability and Air-Gapping</strong><span>: Use Immutable Backup Repositories to ensure that once a backup is written, it cannot be modified or deleted by any user including a compromised administrator for a set period. This provides a definitive recovery point in the event of a ransomware attack or intentional data sabotage.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Monitoring Virtualization Infrastructure</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Access Attempt to Virtualized Infrastructure</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for attempted logins to virtualized infrastructure by unauthorized accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized SSH Connection Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/004/" rel="noopener" target="_blank"><span>T1021.004 – Remote Services: SSH</span></a></p>
</td>
<td>
<p><span>Search for instances where an SSH connection is attempted when SSH has not been enabled for an approved purpose or is not expected from a specific origination asset.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>ESXi Shell/SSH Enablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter</span></a></p>
</td>
<td>
<p><span>Monitor ESXi hostd.log and shell.log for the SSH service being enabled via DCUI, vSphere client, or API calls. Alert on any ESXi SSH enablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk VM Power-Off Events</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1529/" rel="noopener" target="_blank"><span>T1529 - System Shutdown/Reboot</span></a></p>
</td>
<td>
<p><span>Detect sequences where multiple VMs are powered off within a short time window (e.g., &gt;5 VMs in 10 minutes) via vCenter events. </span></p>
<p><span>Correlate with vpxd.log "ReceivedPowerOffVM" events.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VMDK File Access from Non-Standard Processes</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing .vmdk, .vmx, .vmsd, or .vmsn files outside of normal VMware service processes (hostd, vpxd, fdm). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>execInstalledOnly Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses: Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor ESXi shell.log for execution of "esxcli system settings encryption set" with "--require-exec-installed-only=F" or "--require-secure-boot=F". Alert on any cryptographic enforcement disablement event that was not preceded by an approved change request.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>vCenter SSO Identity Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/" rel="noopener" target="_blank"><span>T1556 - Modify Authentication Process</span></a></p>
</td>
<td>
<p><span>Monitor vCenter events and vpxd.log for modifications to SSO identity sources, including the addition of new LDAP providers or changes to vshphere.local administrator group membership. Alert on an identity source change not initiated from a designated PAW subnet.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VM Disk Detach and Reattach to Non-Inventory VM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1486/" rel="noopener" target="_blank"><span>T1486 - Data Encrypted for Impact</span></a></p>
</td>
<td>
<p><span>Detect sequences where a virtual disk is removed from a Tier-0 asset via "vim.event.VmReconfiguredEvent" and subsequently attached to an orphaned or non-standard inventory VM. </span></p>
<p><span>Correlate with "vim.event.VmRegisteredEvent" events on non-standard datastore paths within the same time window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>VCSA Shell Command Anomaly</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1059/004/" rel="noopener" target="_blank"><span>T1059.004 - Command and Scripting Interpreter: Unix Shell</span></a></p>
</td>
<td>
<p><span>Monitor VCSA shell audit logs for execution of high-risk commands (e.g., wget, curl, psql, certificate-manager) by any user following an interactive SSH session. Alert on any instance where these commands are executed outside of an approved change window.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Snapshot Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Detects sequences where snapshots are removed across multiple VMs within a short time window via vCenter events. Correlate with "vim-cmd vmsvc/snapshot.removeall" execution in hostd.log to confirm host-level action.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 7: Detection opportunities for VMware vSphere </span></div></div>
<div class="block-paragraph_advanced"><h4><span>Protecting Against DDoS Attacks</span></h4>
<p><span>A distributed denial-of-service (DDoS) attack is an example of a disruptive attack that could impact the availability of cloud-based resources and services. Modernized DDoS protection must extend beyond the legacy concepts of filtering and rate-limiting, and include cloud-native capabilities that can scale to combat adversarial capabilities.</span></p>
<p><span>In addition to third-party DDoS and web application access protection services, the following table provides an overview of DDoS protection capabilities within common cloud-based infrastructures.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>DDoS Protection Capability </strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/armor"><span>Google Cloud Armor</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/shield/" rel="noopener" target="_blank"><span>AWS Shield</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/ddos-protection" rel="noopener" target="_blank"><span>Azure DDoS Protection</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Platform Agnostic </span></p>
</td>
<td>
<p><a href="https://www.imperva.com/products/web-application-firewall-waf/" rel="noopener" target="_blank"><span>Imperva WAF</span></a></p>
<p><a href="https://www.akamai.com/glossary/what-is-a-waf" rel="noopener" target="_blank"><span>Akamai WAF</span></a></p>
<p><a href="https://www.cloudflare.com/ddos/" rel="noopener" target="_blank"><span>Cloudflare DDoS Protection</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 8: Common cloud capabilities to mitigate DDoS attacks</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening the Cloud Perimeter </span></h4>
<p><span>With the hybrid operating model of modern day infrastructure, cloud consoles and SaaS platforms are high-value targets for credential harvesting and data exfiltration. Minimizing these risks requires a dual-defense strategy: robust identity controls to prevent unauthorized access, and platform-specific guardrails to protect access to resources, data, and to minimize the attack surface. </span></p>
<h5><span>Strong Authentication Enforcement</span></h5>
<p><span>Strong authentication is the foundational requirement for cloud resilience and securing cloud infrastructure. Similar to on-premises environments, a compromise of a privileged credential, token, or session could lead to unintended consequences that result in a high-impact event for an organization. To mitigate these pervasive risks, organizations must unconditionally enforce strong authentication for all external-facing cloud services, administrative portals, and SaaS platforms. </span></p>
<p><span>Organizations should enforce the usage of phishing-resistant authenticators such as FIDO2 (WebAuthn) hardware tokens or passkeys, or certificate based authentication for accounts assigned privileged roles and functions. For non-privileged users, authenticator software (Microsoft Authenticator or Okta Verify) should be configured to utilize device-bound factors such as Windows Hello for Business or TouchID.</span></p>
<p><span>Additionally, organizations should leverage the concept of authenticators (identity + device attestation) as part of the authentication transaction. This includes enforcing a validated-device access policy that restricts privileged access to only originate from managed, compliant, and healthy devices. Trusted network zones should be defined in order to restrict access to cloud resources from the open internet. Untrusted network zones should be defined to restrict authentication from anonymizing services such as VPNs or TOR. Using device-bound session credentials where possible mitigates the risk of session token theft.</span></p>
<h5><span>Identity and Device Segmentation for Privileged Actions</span></h5>
<p><span>The implementation of privileged access workstations (PAWs) is a critical defense against threat actors attempting to compromise administrative sessions. A PAW is a highly hardened, dedicated hardware endpoint used exclusively for sensitive administrative tasks.</span></p>
<p><span>Administrators should leverage a non-privileged account for daily tasks, while privileged actions are restricted to only being permissible from the hardened PAW, or from explicitly defined IP ranges. This "air-gap" between communication and administration prevents an adversary from moving laterally from a compromised non-privileged identity to a privileged context within hybrid environments. </span></p>
<h5><span>Just-in-Time Access and the Principle of Least Privilege</span></h5>
<p><span>Static, standing privileges present a security risk in hybrid environments. Following a zero-trust cloud architecture, administrative privileges should be entirely ephemeral. Implementing Just-In-Time (JIT) and Just-Enough-Access (JEA) mechanisms ensures that administrators are granted only the specific, granular permissions necessary to perform a discrete task, and only for a highly limited duration, after which the permissions are automatically revoked. This architectural model provides organizations with the ability to enforce approvals for privileged actions, enhanced monitoring, and detailed visibility regarding any privileged actions taken within a specific session.</span></p>
<h5><span>Securing Non-Human Identities</span></h5>
<p><span>Organizations should implement identity governance practices that include processes to rotate API keys, certificates, service account secrets, tokens, and sessions on a predefined basis. AI agents or identities correlating to autonomous outcomes should be configured with strictly scoped permissions and associated monitoring. Non-privileged users should be restricted from authorizing third-party application integrations or creating API keys without organizational approval.</span></p>
<p><span>Continuous scanning should be performed to identify and remediate hard-coded secrets and sensitive credentials across all cloud and SaaS environments.</span></p>
<h5><span>Storage Infrastructure Security and Immutable Backups</span></h5>
<p><span>The strategic objective of a destructive cyberattack—whether for extortion or sabotage—is to prolong recovery and reconstitution efforts by ensuring data is irrecoverable. Modern adversaries systematically target the backup plane as part of a destructive event. If backups remain mutable or share an identity plane with the primary environment, attackers can delete or encrypt them, transforming an incident into a prolonged and chaotic recovery exercise.</span></p>
<p><span>While modern-day redundancy for backups should include multiple data copies across diverse media, geographic separation can be a subverted defensive strategy if logical access is unified. To ensure resilience against destructive attacks, the secondary recovery environment should reside within a sovereign cloud tenant or isolated subscription. This environment should be governed by an independent Identity and Access Management (IAM) plane, using distinct credentials and administrative personas that share no commonality with the production environment.</span></p>
<p><span>Backups within an isolated environment must be anchored by immutable storage architectures. By leveraging hardware-verified Write-Once, Read-Many (WORM) technology, the recovery plane ensures that data integrity is mathematically guaranteed. Once committed, data cannot be modified, encrypted, or deleted—even by accounts with root or global administrative privileges, until the retention period expires. This creates a definitive "fail-safe" that ensures a known-good recovery point remains accessible regardless of potential security risks in the primary environment.</span></p>
<p><span>Additional defense-in-depth security architecture controls relevant to common cloud-based infrastructures are included in Table 9.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Cloud Provider</strong></p>
</td>
<td>
<p><strong>Identity Controls</strong></p>
</td>
<td>
<p><strong>Secrets Governance</strong></p>
</td>
<td>
<p><strong>Network Controls</strong></p>
</td>
<td>
<p><strong>Policy Guardrails</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Google Cloud</span></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/iam/docs/deny-overview"><span>IAM Deny Policies</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/products/secret-manager"><span>Secret Manager</span></a></p>
</td>
<td>
<p><a href="https://cloud.google.com/security/vpc-service-controls"><span>VPC Service Controls</span></a></p>
</td>
<td>
<p><a href="https://docs.cloud.google.com/resource-manager/docs/organization-policy/overview"><span>Organization Policy Service</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Amazon Web Services</span></p>
</td>
<td>
<p><a href="https://aws.amazon.com/iam/identity-center/" rel="noopener" target="_blank"><span>IAM Identity Center</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/secrets-manager/" rel="noopener" target="_blank"><span>Secrets Manager</span></a></p>
</td>
<td>
<p><a href="https://aws.amazon.com/verified-access/" rel="noopener" target="_blank"><span>Verified Access</span></a></p>
</td>
<td>
<p><a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html" rel="noopener" target="_blank"><span>Service Control Policies</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft Azure</span></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure" rel="noopener" target="_blank"><span>Entra ID (PIM)</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/key-vault" rel="noopener" target="_blank"><span>Azure Key Vault</span></a></p>
</td>
<td>
<p><a href="https://azure.microsoft.com/en-us/products/virtual-network/" rel="noopener" target="_blank"><span>Azure Virtual Network</span></a></p>
<p><a href="https://azure.microsoft.com/en-us/products/private-link" rel="noopener" target="_blank"><span>Private Link</span></a></p>
</td>
<td>
<p><a href="https://learn.microsoft.com/en-us/azure/governance/policy/overview" rel="noopener" target="_blank"><span>Azure Policy</span></a></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Agnostic Security Solutions</span></p>
</td>
<td>
<p><a href="https://www.okta.com/learn/okta-identity-cloud/" rel="noopener" target="_blank"><span>Okta</span></a></p>
<p><a href="https://www.sailpoint.com/products/identity-security-cloud" rel="noopener" target="_blank"><span>SailPoint</span></a></p>
<p><a href="https://www.pingidentity.com/en/platform/pingone-advanced-identity-cloud.html" rel="noopener" target="_blank"><span>Ping Identity</span></a></p>
</td>
<td>
<p><a href="https://www.hashicorp.com/en/products/vault/use-cases/secrets-management" rel="noopener" target="_blank"><span>Hashicorp Vault</span></a><span> </span><a href="https://docs.cyberark.com/secrets-manager-saas/latest/en/content/get%20started/key_concepts/secrets.html" rel="noopener" target="_blank"><span>CyberArk</span></a></p>
</td>
<td>
<p><a href="https://help.zscaler.com/zpa/understanding-zpa-zia-and-zscaler-client-connector-clouds" rel="noopener" target="_blank"><span>Zscaler</span></a></p>
<p><a href="https://www.netskope.com/products/security-service-edge" rel="noopener" target="_blank"><span>Netskope SSE</span></a></p>
</td>
<td>
<p><a href="https://www.wiz.io/" rel="noopener" target="_blank"><span>Wiz</span></a></p>
<p><a href="https://www.paloaltonetworks.com/prisma/cloud" rel="noopener" target="_blank"><span>Palo Alto Prisma Cloud</span></a></p>
<p><a href="https://orca.security/" rel="noopener" target="_blank"><span>Orca Security</span></a></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 9: Common cloud capabilities for infrastructure hardening</span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Protecting Cloud Infrastructure and Resources</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Account Abuse</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid Accounts: Cloud Accounts</span></a></p>
</td>
<td>
<p><span>Monitor cloud audit logs for authentication from unseen source IPs, anomalous ASNs, or impossible travel patterns. </span></p>
<p><span>Alert on IAM policy modifications, new role assignments, and service account key creation by accounts without prior administrative API activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement via Cloud Interfaces</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/007/" rel="noopener" target="_blank"><span>T1021.007 - Remote Services: Cloud Services</span></a></p>
</td>
<td>
<p><span>Detect interactive console sign-ins from IPs that previously only performed programmatic API/CLI access. Alert on cloud CLI execution from non-administrative endpoints. </span></p>
<p><span>Monitor for cross-service lateral movement where a single identity authenticates to multiple cloud services in a compressed timeframe outside its historical access pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modify Cloud Compute Configurations</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1578/005/" rel="noopener" target="_blank"><span>T1578.005 - Modify Cloud Compute Configurations</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized compute changes including bulk instance creation or deletion deviating from change management baselines. </span></p>
<p><span>Alert on snapshot creation of production volumes by non-backup accounts, disk detach/reattach targeting domain controller or database instances for offline credential theft, and network/firewall modifications exposing internal services to public access.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Cloud Log Enumeration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1654/" rel="noopener" target="_blank"><span>T1654 - Log Enumeration</span></a></p>
</td>
<td>
<p><span>Monitor for API calls listing or accessing logging configurations from identities without documented operational need. </span></p>
<p><span>Alert on enumeration of SIEM integration settings, log export destinations, and alert rule definitions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Mass Deletion &amp; Impact</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Alert when bulk delete API calls exceed baseline thresholds targeting compute instances, storage, databases, or virtual networks. </span></p>
<p><span>Detect deletion or retention reduction of recovery-critical resources including backup vaults, snapshot schedules, and disaster recovery configurations.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Backup Policy Modification or Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1490/" rel="noopener" target="_blank"><span>T1490 - Inhibit System Recovery</span></a></p>
</td>
<td>
<p><span>Monitor for unauthorized modifications to backup configurations, including changes to WORM retention policies, backup vault access policies, snapshot deletion, or backup schedule disablement. </span></p>
<p><span>Alert on backup storage account access from identities other than designated backup service accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Conditional Access or Security Policy Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1556/009/" rel="noopener" target="_blank"><span>T1556.009 - Conditional Access Policies</span></a></p>
</td>
<td>
<p><span>Monitor cloud identity provider audit logs for modifications to Conditional Access Policies, MFA enforcement rules, legacy authentication blocking rules, or PIM/JIT role settings. Alert on changes that add location or device exclusions to MFA policies, disable legacy protocol blocks, extend privilege role activation durations, or register new authentication methods on privileged accounts.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 10: Detection opportunities for protecting cloud infrastructure and resources</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Securing Endpoint and Mobile Device Management Platforms</span></h4>
<p><span>Protecting endpoint and Mobile Device Management (MDM) platforms is crucial to ensuring the security and availability of devices used in support of operations. In the context of </span><a href="https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf" rel="noopener" target="_blank"><span>wiper</span></a><span> and destructive-style attacks, these platforms represent the "keys to the kingdom" that threat actors can target to turn an organization’s own infrastructure against itself.</span></p>
<p><strong>Force Multiplier:</strong><span> MDM and endpoint management tools have the inherent ability to push configurations and scripts to enrolled and managed devices. If compromised, a threat actor can use these legitimate administrative platforms to deploy wiper malware or execute remote wipe commands simultaneously across the entire enterprise, achieving destruction in minutes.  </span></p>
<p><span>Unlike ransomware, where data might be recoverable via decryption, wiper attacks aim for the permanent destruction of the Master Boot Record (MBR), GUID Partition Table (GPT), Master File Table (MFT), or overwrite the file system making endpoint devices inaccessible. </span></p>
<h5><span>Proactive Hardening</span></h5>
<p><span>Enforcing strong identity and network controls for securing the management plane can prevent an attacker from gaining access to endpoint and MDM platforms and abusing intended functionality (e.g., deploying wiper scripts or issuing  "Remote Wipe" or "Factory Reset" commands).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enforce strong authentication (e.g., phishing-resistant MFA, including FIDO2) for identities assigned privileged roles and functions.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce session lifetimes, idle session timeouts and utilize device-bound session protection to protect against token replay attacks.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require access policies and </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" rel="noopener" target="_blank"><span>multi-admin approval</span></a><span> for authorization of specific actions. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce long-standing administrative permissions and migrate to a Just-in-Time (JIT) or Just-Enough-Access (JEA) access model for privileged roles and actions.  </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For Microsoft Intune, leverage a combination of </span><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/scope-tags" rel="noopener" target="_blank"><span>role-based access control (RBAC) and scope tags</span></a><span> to reduce the blast radius and minimize the risk of compromised privileged identities being leveraged to impact a large scope of managed devices / endpoints. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit admin roles for anything including “Remote tasks/wipe/erase” permissions - and ensure these events are forwarded to a centralized SIEM. Additionally, reduce the scope of administrators that can perform these actions to the minimum required for business operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Reduce scope of API token permissions following the principle of least privilege. Remove or expire tokens after a period of inactivity. Rotate tokens on a regular basis.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>For cloud-hosted MDM platforms, utilize access policies to enforce network- and location-based allow listing. For local/on-premises MDM servers, utilize firewalls to restrict access to MDM infrastructure (management plane).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If supported, configure wipe protection to prevent against mass device wiping within a specific threshold.  An example of this configuration within the Omnissa Workspace ONE platform is available </span><a href="https://docs.omnissa.com/bundle/WorkspaceONE-UEM-Managing-DevicesV2406/page/WipeProtection.html" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review existing scripts and configuration profiles deployed via the MDM platform to identify and remediate any hardcoded plain text passwords, API keys, or other sensitive secrets.</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Securing Endpoint and Mobile Device Management Platforms</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Wipe or Factory Reset Command Issued</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor endpoint management platform audit logs for issuance of remote wipe, factory reset, or retire commands. </span></p>
<p><span>Alert on any wipe command targeting more than a threshold number of devices within a defined time window, or wipe commands issued outside approved change windows.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous MDM/EDR Administrator Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/004/" rel="noopener" target="_blank"><span>T1078.004 - Valid accounts: Cloud accounts</span></a></p>
</td>
<td>
<p><span>Monitor authentication logs for endpoint management platform admin consoles for sign-ins from unrecognized IPs, non-compliant devices, or locations inconsistent with the administrator’s historical access pattern. </span></p>
<p><span>Alert on admin authentication that bypasses Conditional Access or lacks phishing-resistant MFA.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Script or Configuration Profile Deployment</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1072/" rel="noopener" target="_blank"><span>T1072 - Software Deployment Tools</span></a></p>
</td>
<td>
<p><span>Monitor of mass deployment of new scripts, configuration profiles, or software packages pushed to device groups via the management platform.</span></p>
<p><span> Alert when a deployment targets all devices or broad scope tags rather than specific groups, particularly when initiated by an account that has not previously performed bulk deployments.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Administrative Role or Permission Modification</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 - Account Manipulation</span></a></p>
</td>
<td>
<p><span>Monitor platform audit logs for changes to administrative roles, RBAC assignments, or scope tag modifications.</span></p>
<p><span> Alert on elevation of accounts to roles with remote task, wipe, or retire permissions, and on removal of multi-admin approval requirements.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>API Key creation or Anomalous API access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/001/" rel="noopener" target="_blank"><span>T1098.001 - Additional Cloud Credentials</span></a></p>
</td>
<td>
<p><span>Monitor for creation of new API keys, tokens, or service principal credentials for the endpoint management platform. </span></p>
<p><span>Alert on API calls from previously unseen source IPs or user-agents, and on API activity outside business hours. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Management Platform Audit Log Tampering or Disablement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/008/" rel="noopener" target="_blank"><span>T1562.008 - Impair Defenses: Disable or Modify Cloud Logs</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to the platform’s audit logging configuration, including disablement of change management logging, redirection of syslog export destinations, or deletion of audit log entries. </span></p>
<p><span>Alert on changes to log retention settings or export configurations.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>3. On-Premises Lateral Movement Protections</span></h3>
<h4><span>Endpoint Hardening</span></h4>
<h5><span>Windows Firewall Configurations</span></h5>
<p><span>Once initial access to on-premises infrastructure is established, threat actors will conduct lateral movement to attempt to further expand the scope of access and persistence. To protect Windows endpoints from being accessed using common lateral movement techniques, a Windows Firewall policy can be configured to restrict the scope of communications permitted between endpoints within an environment. A Windows Firewall policy can be enforced locally or centrally as part of a Group Policy Object (GPO) configuration. At a minimum, the common ports and protocols leveraged for lateral movement that should be blocked between workstation-to-workstation and workstations to non-domain controllers and non-file servers include:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>SMB (TCP/445, TCP/135, TCP/139)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop Protocol (TCP/3389)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (WinRM)/Remote PowerShell (TCP/80, TCP/5985, TCP/5986)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI) (dynamic port range assigned through Distributed Component Object Model (DCOM))</span></p>
</li>
</ul>
<p><span>Using a GPO (Figure 5), the settings listed in Table 11 can be configured for the Windows Firewall to control </span><strong>inbound</strong><span> communications to endpoints in a managed environment. The referenced settings will effectively block all inbound connections for the </span><span>Private</span><span> and </span><span>Public</span><span> profiles, and for the </span><span>Domain</span><span> profile, only allow connections that do not match a predefined block rule. </span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Windows Firewall with Advanced Security</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Figure 5: GPO path for creating Windows Firewall rules</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Profile Setting</strong></p>
</td>
<td>
<p><strong>Firewall State</strong></p>
</td>
<td>
<p><strong>Inbound Connections</strong></p>
</td>
<td>
<p><strong>Log Dropped Packets</strong></p>
</td>
<td>
<p><strong>Log Successful Connections</strong></p>
</td>
<td>
<p><strong>Log File Path</strong></p>
</td>
<td>
<p><strong>Log File Maximum Size (KB)</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Allow</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Private</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Public</span></p>
</td>
<td>
<p><span>On</span></p>
</td>
<td>
<p><span>Block All Connections</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><span>Yes</span></p>
</td>
<td>
<p><code>%systemroot%\system32\LogFiles\Firewall\pfirewall.log</code></p>
</td>
<td>
<p><span>4,096</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 11: Windows Firewall recommended configuration state</span></div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig6.max-1000x1000.png" alt="Windows Firewall Recommendation Configurations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 6: Windows Firewall recommendation configurations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, to ensure that only centrally managed firewall rules are enforced (and cannot be overridden by a threat actor), the settings for </span><span>Apply local firewall rules</span><span> and </span><span>Apply local connection security rules</span><span> can be set to </span><span>No</span><span> for all profiles.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig7.max-1000x1000.png" alt="Windows Firewall Domain Profile Customized Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 7: Windows Firewall domain profile customized settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To quickly contain and isolate systems, the centralized Windows Firewall setting of </span><span>Block all connections</span><span> (Figure 8) will prevent any inbound connections from being established to a system. This is a setting that can be enforced on workstations and laptops, but will likely impact operations if enforced for servers, although if there is evidence of an active threat actor lateral pivoting within an environment, it may be a necessary step for rapid containment.</span></p>
<p><strong>Note:</strong><span> </span><span>If this control is being used temporarily to facilitate containment as part of an active incident, once the incident has been contained and it has been deemed safe to re-establish connectivity among systems within an environment, the </span><span>Inbound Connections</span><span> setting can be changed back to </span><span>Allow</span><span> using a GPO.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig8.max-1000x1000.png" alt="Windows Firewall - Block All Connections Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="2sb2o">Figure 8: Windows Firewall - Block All Connections settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>If blocking all inbound connectivity for endpoints during a containment event is not practical, or for the </span><span>Domain</span><span> profile configurations, at a minimum, the protocols listed in Table 12 should be enforced using either a GPO or via the commands referenced within the table.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>For any specific applications that may require inbound connectivity to end-user endpoints, the local firewall policy should be configured with specific IP address exceptions for origination systems that are authorized to initiate inbound connections to such devices.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Protocol/Port</strong></p>
</td>
<td>
<p><strong>Windows Firewall Rule</strong></p>
</td>
<td>
<p><strong>Command Line Enforcement</strong></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>SMB</span></p>
<p><span>TCP/445, TCP/139, TCP/135</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>File and Print Sharing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Remote Desktop</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Management Instrumentation (WMI)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Windows Remote Management (Compatibility)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>TCP/5986</span></p>
</li>
</ul>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Remote Desktop Protocol</span></p>
<p><span>TCP/3389</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p><code>netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=no</code></p>
</td>
</tr>
<tr>
<td>
<p role="presentation"><span>Windows Remote Management/PowerShell Remoting</span></p>
<p><span>TCP/80, TCP/5985, TCP/5986</span></p>
</td>
<td>
<p role="presentation"><span>Predefined Rule Name:</span></p>
</td>
<td>
<p role="presentation"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></p>
<p role="presentation"><span>Via PowerShell:</span></p>
<p><code>Disable-PSRemoting -Force</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 12: Windows Firewall suggested block rules</span></p>
</div>
</div></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig9.max-1000x1000.png" alt="Windows Firewall Suggested Rule Blocks via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ibnn4">Figure 9: Windows Firewall suggested rule blocks via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>NTLM Authentication Configurations</span></h5>
<p><span>Threat actors often attempt to harvest credentials (including Windows NTLMv1 hashes) based upon outbound SMB or WebDAV communications. Organizations should review NTLM settings for Windows-based endpoints, and work to harden, disable, or restrict NTLMv1 authentication requests. </span></p>
<p><span>To fully restrict NTLM authentication to remote servers, the following GPO settings can be leveraged:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Allow all</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit all</span></p>
</li>
<li aria-level="1"><span>Deny all</span></li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>If "</span><code>Deny all</code><span>" is selected, the client computer cannot authenticate (send credentials) to a remote server using NTLM authentication. Before setting to "</span><code>Deny all,</code><span>" organizations should configure the GPO setting with the "</span><code>Audit all</code><span>" enforcement. With this configuration, audit and block events will be recorded within the Operational event log on endpoints (</span><code>Applications and Services Log\Microsoft\Windows\NTLM</code><span>).</span></p>
<p><span>If any recorded NTLM authentication events are required, organizations can configure the "</span><code>Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication</code><span>" setting to define a listing of remote servers, which are required to use NTLM authentication.</span></p>
<h4><span>Detection Opportunities for SMB, WMI, and NTLM Communications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of SMB Connections</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – SMB/Windows Admin Shares</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in SMB connections that fall outside of a normal pattern.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Outbound Connection Attempted Over SMB</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1212/" rel="noopener" target="_blank"><span>T1212 – Exploitation for Credential Access</span></a></p>
</td>
<td>
<p><span>Search for external connection attempts over SMB, as this may be an attempt to harvest credential hashes.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used to Call a Remote Service</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1047/" rel="noopener" target="_blank"><span>T1047 – Windows Management Instrumentation</span></a></p>
</td>
<td>
<p><span>Search for WMI being used via a command line or PowerShell to call a remote service for execution.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WMI Being Used for Ingress Tool Transfer</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1105/" rel="noopener" target="_blank"><span>T1105 – Ingress Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for suspicious usage of WMI to download external resources. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Forced NTLM Authentication Using SMB or WebDAV</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1187/" rel="noopener" target="_blank"><span>T1187 – Forced Authentication</span></a></p>
</td>
<td>
<p><span>Search for potential NTLM authentication attempts using SMB or WebDAV.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay via Coercion</span></p>
</td>
<td>
<p><span>T1187 - Forced Authentication</span></p>
</td>
<td>
<p><span>Monitor for NTLM authentication attempts from Domain Controllers or privileged servers to unexpected destinations, particularly to HTTP endpoints (AD CS web enrollment). </span></p>
<p><span>Detect PetitPotam by monitoring for EfsRpcOpenFileRaw calls, DFSCoerce via DFS-related named pipe access, and PrinterBug via SpoolService RPC calls.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 13: Detection opportunities for SMB, WMI, and NTLM communications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Remote Desktop Protocol Hardening</span></h4>
<p><span>Remote Desktop Protocol (RDP) is a common method used by threat actors to remotely connect to systems, laterally move from the perimeter onto a larger scope of internal systems, and perform malicious activities (such as data theft or ransomware deployment). External-facing systems with RDP open to the internet present an elevated risk. Threat actors may exploit this vector to gain initial access to an organization and then perform lateral movement into the organization to complete their mission objectives.</span></p>
<p><span>Proactively, organizations should scan their public IP address ranges to identify systems with RDP (TCP/3389) and other protocols (SMB – TCP/445) open to the internet. At a minimum, RDP and SMB should not be directly exposed for ingress and egress access to/from the internet. If required for operational purposes, explicit controls should be implemented to restrict the source IP addresses, which can interface with systems using these protocols. The following hardening recommendations should also be implemented.</span></p>
<h5><span>Enforce Multi-Factor Authentication</span></h5>
<p><span>If external-facing RDP must be used for operational purposes, MFA should be enforced when connecting using this method. This can be accomplished either via the integration of a third-party MFA technology or by leveraging a Remote Desktop Gateway and Azure Multifactor Authentication Server using Remote Authentication Dial-In User Service (<a href="https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg" rel="noopener" target="_blank">RADIUS</a>)</span><span>.</span></p>
<h5><span>Leverage Network-Level Authentication</span></h5>
<p><span>For external-facing RDP servers, Network-Level Authentication (NLA) provides an extra layer of preauthentication before a connection is established. NLA can also be useful for protecting against brute-force attacks, which often target open internet-facing RDP servers.</span></p>
<p><span>NLA can be configured either via the user interface (UI) (Figure 10) or via Group Policy (Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig10.max-1000x1000.png" alt="Enabling NLA via the UI">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 10: Enabling NLA via the UI</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Using a GPO, the setting for NLA can be configured via:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Remote Desktop Services &gt; Remote Desktop Session Host &gt; Security &gt; Require user authentication for remote connections by using Network Level Authentication</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig11.max-1000x1000.png" alt="Enabling NLA via Group Policy">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="bx1dm">Figure 11: Enabling NLA via Group Policy</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Some caveats about leveraging NLA for RDP:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop client v7.0 (or greater) must be leveraged.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NLA uses CredSSP to pass authentication requests on the initiating system. CredSSP stores credentials in Local Security Authority (LSA) memory on the initiating system, and these credentials may remain in memory even after a user logs off the system. This provides a potential exposure risk for credentials in memory on the source system.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>On the RDP server, users permitted for remote access using RDP must be assigned the </span><span>Access this computer from the network</span><span> privilege when NLA is enforced. </span><strong>This privilege is often explicitly denied for user accounts to protect against lateral movement techniques.</strong></p>
</li>
</ul>
<h5><span>Restrict Administrative Accounts from Leveraging RDP on Internet-Facing Systems</span></h5>
<p><span>For external-facing RDP servers, highly privileged domain and local administrative accounts should not be permitted access to authenticate with the external-facing systems using RDP (Figure 12). </span></p>
<p><span>This can be enforced using Group Policy, configurable via the following path: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment &gt; Deny log on through Terminal Services</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig12.max-1000x1000.png" alt="Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ro2xo">Figure 12: Group Policy configuration for restricting highly privileged domain and local administrative accounts from leveraging RDP</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for RDP Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>RDP Authentication Integration </span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1110/" rel="noopener" target="_blank"><span>T1110 – Brute Force</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Existing authentication rules should include RDP attempts. This includes use cases for:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Brute Force</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Password Spraying</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single User</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MFA Failures Single Source</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>External Authentication from an Account with Elevated Privileges</span></p>
</li>
</ul>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Connection Attempts over RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/001/" rel="noopener" target="_blank"><span>T1021.001 – Remote Desktop Protocol</span></a></p>
</td>
<td>
<p><span>Searching for anomalous RDP connection attempts over known RDP ports such as TCP/3389.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 14: Detection Opportunities for RDP Usage</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Disabling Administrative/Hidden Shares</span></h4>
<p><span>To conduct lateral movement, threat actors may attempt to identify administrative or hidden network shares, including those that are not explicitly mapped to a drive letter and use these for remotely binding to endpoints throughout an environment. As a protective or rapid containment measure, organizations may need to quickly disable default administrative or hidden shares from being accessible on endpoints. This can be accomplished by either modifying the registry, stopping a service, or by using the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">MSS (Legacy) Group Policy template</a></span><span>.</span></p>
<p><span>Common administrative and hidden shares on endpoints include:</span></p>
<ul>
<li role="presentation"><code>ADMIN$</code></li>
<li role="presentation"><code>C$</code></li>
<li role="presentation"><code>D$</code></li>
<li role="presentation"><code>IPC$</code></li>
</ul></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><strong>Note:</strong><span> </span><span>Disabling administrative and hidden shares on servers, specifically including domain controllers, may significantly impact the operation and functionality of systems within a domain-based environment.</span></p>
<span>Additionally, if PsExec is used in an environment, disabling the admin (</span><code>ADMIN$</code><span>) share can restrict the capability for this tool to be used to remotely interface with endpoints.</span></td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h5><span>Registry Method</span></h5>
<p><span>Using the registry, administrative and hidden shares can be disabled on endpoints (Figure 13 and Figure 14).</span></p>
<h6><span>Workstations</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareWks"
Value = "0"</code></pre>
<p><span>Figure 13: Registry value disabling administrative shares on workstations</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Servers</span></h6></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
DWORD Name = "AutoShareServer"
Value = "0"</code></pre>
<p><span>Figure 14: Registry value disabling administrative shares on servers</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Service Method</span></h5>
<p><span>By stopping the </span><span>Server</span><span> service on an endpoint, the ability to access any shares hosted on the endpoint will be disabled (Figure 15).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig15.max-1000x1000.png" alt="Server service properties">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 15: Server service properties</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the MSS (Legacy) Group Policy template, administrative and hidden shares can be disabled on either a server or workstation via a GPO setting (Figure 16).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareServer)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MSS (Legacy) &gt; MSS (AutoShareWks)</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig16.max-1000x1000.png" alt="Disabling Administrative And Hidden Shares via the MSS (Legacy) Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="7xllt">Figure 16: Disabling administrative and hidden shares via the MSS (Legacy) Group Policy template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Accessing Administrative or Hidden Shares</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Network Discovery: Suspicious Usage of the Net Command</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1049/" rel="noopener" target="_blank"><span>T1049 - System Network Connections Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1135/" rel="noopener" target="_blank"><span>T1135 - Network Share Discovery</span></a></p>
</td>
<td>
<p><span>Search for suspicious use of the </span><code>net</code><span> command to enumerate systems and file shares within an environment.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 15: Detection opportunities for accessing administrative or hidden shares</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Hardening Windows Remote Management</span></h4>
<p><span>Threat actors may leverage Windows Remote Management (WinRM) to laterally move throughout an environment. </span><strong>WinRM is enabled by default on all Windows Server operating systems (since Windows Server 2012 and above)</strong><span>, but disabled on all client operating systems (Windows 7 and Windows 10) and older server platforms (Windows Server 2008 R2).</span></p>
<p><span>PowerShell remoting (PS remoting) is a native Windows remote command execution feature that is built on top of the WinRM protocol.</span></p>
<p><span>Windows client (nonserver) operating system platforms where WinRM is disabled indicates that there is:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>No WinRM listener configured</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No Windows firewall exception configured</span></p>
</li>
</ul>
<p><span>By default, WinRM uses TCP/5985 and TCP/5986, which can be either disabled using the Windows Firewall or configured so that a specific subset of IP addresses can be authorized for connecting to endpoints using WinRM.</span></p>
<p><span>WinRM and PowerShell remoting can be explicitly disabled on endpoint using either a PowerShell command (Figure 17) or specific GPO settings.</span></p>
<h5><span>PowerShell</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 17: PowerShell command to disable WinRM/PowerShell remoting on an endpoint</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Running </span><code>Disable-PSRemoting -Force</code><span> does not prevent local users from creating PowerShell sessions on the local computer or for sessions destined for remote computers.</span></p>
<p><span>After running the command, the message recorded in Figure 18 will be displayed. These steps provide additional hardening, but after running the </span><code>Disable-PSRemoting -Force</code><span> command, PowerShell sessions destined for the target endpoint will not be successful.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig18.max-1000x1000.png" alt="Warning message after disabling PSRemoting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="gwqyc">Figure 18: Warning message after disabling PSRemoting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>To enforce the additional steps for disabling WinRM via PowerShell (Figure 19 through Figure 22):</span></p>
<ol>
<li><span>Stop and disable the </span><span>WinRM</span><span> service.<br><br></span>
<pre class="language-plain"><code>Stop-Service WinRM -PassThruSet-Service WinRM -StartupType Disabled</code></pre>
<p><span>Figure 19: PowerShell command to stop and disable the WinRM service</span></p>
<span><br></span></li>
<li><span><span>Disable the listener that accepts requests on any IP address.<br><br></span></span>
<pre class="language-plain"><code>dir wsman:\localhost\listener

Remove-Item -Path WSMan:\Localhost\listener\&lt;Listener name&gt;</code></pre>
<p><span>Figure 20: PowerShell commands to delete a WSMan listener</span></p>
<span><span><br></span></span></li>
<li><span><span>Disable the firewall exceptions for WS-Management communications.<br><br></span></span>
<pre class="language-plain"><code>Set-NetFirewallRule -DisplayName 'Windows Remote Management (HTTP-In)' -Enabled False </code></pre>
<p><span>Figure 21: PowerShell command to disable firewall exceptions for WinRM</span></p>
<span><span><br></span></span></li>
<li><span><span><span>Restore the value of </span><code>the LocalAccountTokenFilterPolicy</code><span> to 0, which restricts remote access to members of the Administrators group on the computer.<br><br></span></span></span>
<pre class="language-plain"><code>Set-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system -Name LocalAccountTokenFilterPolicy -Value 0</code></pre>
<p><span><span><span><span>Figure 22: PowerShell command to configure the registry key for LocalAccountTokenFilterPolicy</span></span></span></span></p>
</li>
</ol></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Disabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>If this setting is configured as </span><span>Disabled</span><span>, the WinRM service will not respond to requests from a remote computer, regardless of whether any WinRM listeners are configured.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Shell &gt; Allow Remote Shell Access </span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul>
<p><span>This policy setting will manage the configuration of remote access to all supported shells to execute scripts and commands.</span></p>
<h4><span>Detection Opportunities for WinRM Usage</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized WinRM Execution Attempt</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for command execution attempts for WinRM on a system where WinRM has been disabled.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Process Creation Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for anomalous process creation events using WinRM that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Suspicious Network Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for network activity over known WinRM ports, such as TCP/5985 and TCP/5986, to identify anomalous connections that deviate from an established baseline.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote WMI Connection Using WinRM</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/006/" rel="noopener" target="_blank"><span>T1021.006 - Remote Services: Windows Remote Management</span></a></p>
</td>
<td>
<p><span>Search for remote WMI connection attempts using WinRM. </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 16: Detection opportunities for WinRM use</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Restricting Common Lateral Movement Tools and Methods</span></h4>
<p><span>Table 17 provides a consolidated summary of security configurations that can be leveraged to combat against common remote access tools and methods used for lateral movement within environments.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Tool/Tactic</span></p>
</th>
<th scope="col">
<p><span>Mitigating Security Configurations (Target Endpoints)</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><span>PsExec (using the current logged-on user account, without the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is not leveraged, authentication will use Kerberos or NTLM for the current logged-on user of the source endpoint and will register as a Type 3 (network) logon on the destination endpoint.</span></p>
<p><span>PsExec high-level functionality:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Connects to the hidden </span><code>ADMIN$</code><span> share (mapping to the </span><code>C:\Windows</code><span> folder) on a remote endpoint via SMB (TCP/445).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Uses the Service Control Manager (SCM) to start the </span><code>PSExecsvc</code><span> service and enable a named pipe on a remote endpoint.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Input/output redirection for the console is achieved via the created named pipe.</span></p>
</li>
</ul>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on locally</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny log on through Terminal Services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DCOM:Machine Access Restrictions in Security Descriptor Definition Language (SDDL) Syntax</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network</span></p>
</li>
</ul>
<p><strong>Option 2: </strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 23: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
<p><strong>Option 3:</strong></p>
<p><span>Disable administrative and hidden shares.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PsExec (with Alternative Credentials, via the </span><code>-u</code><span> switch)</span></p>
<p><span>If the </span><code>-u</code><span> switch is leveraged, authentication will use the alternate supplied credentials and will register as a Type 3 (network) and Type 2 (interactive) logon on the destination endpoint.</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=no</code></pre>
<p><span>Figure 24: PowerShell command to disable inbound file and print sharing (SMB) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Remote Desktop Protocol (RDP)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Remote Desktop" new enable=no</code></pre>
<p><span>Figure 25: PowerShell command to disable inbound Remote Desktop (RDP) for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>PS remoting and WinRM</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>PowerShell command:<br><br></span></p>
<pre class="language-plain"><code>Disable-PSRemoting -Force</code></pre>
<p><span>Figure 26: PowerShell command to disable PowerShell remoting for an endpoint</span></p>
<p><strong>Option 2:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; Windows Components &gt; Windows Remote Management (WinRM) &gt; WinRM Service &gt; Allow remote server management through WinRM</span></p>
</li>
</ul>
<p><strong>Option 3:</strong></p>
<p><span>Windows Firewall rule:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="Windows Remote Management" new enable=no</code></pre>
<p><span>Figure 27: PowerShell command to disable inbound WinRM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Distributed Component Object Model (DCOM)</span></p>
</td>
<td>
<p><strong>Option 1:</strong></p>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Local Policies &gt; Security Options</span></p>
</li>
</ul>
<p><span>Both of these settings allow an organization to define additional computer-wide controls that govern access to all DCOM–based applications on an endpoint.</span></p>
<p><span>When users or groups that are provided permissions are specified, the security descriptor field is populated with the SDDL representation of those groups and privileges.</span></p>
<p><span>Users and groups can be given explicit </span><span>Allow</span><span> or </span><span>Deny</span><span> privileges for both local and remote access using DCOM.</span></p>
<p><strong>Option 2:</strong></p>
<p><span>Windows Firewall rules:<br><br></span></p>
<pre class="language-plain"><code>netsh advfirewall firewall set rule group="COM+ Network Access" new enable=no

netsh advfirewall firewall set rule group="COM+ Remote Administration" new enable=no</code></pre>
<p><span>Figure 28: PowerShell commands to disable inbound DCOM for an endpoint using a local Windows Firewall rule</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-party remote access applications (e.g., VNC/DameWare/ScreenConnect) that rely upon specific interactive and remote logon permissions being configured on an endpoint.</span></p>
</td>
<td>
<p><span>GPO configuration:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 17: Common lateral movement tools/methods and mitigating security controls</span></div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Common Lateral Movement Tools and Methods</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous PsExec Usage</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1569/002/" rel="noopener" target="_blank"><span>T1569.002 – System Services: Service Execution</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1021/002/" rel="noopener" target="_blank"><span>T1021.002 – Remote Services: SMB/Windows Admin Shares</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1570/" rel="noopener" target="_blank"><span>T1570 – Lateral Tool Transfer</span></a></p>
</td>
<td>
<p><span>Search for attempted execution of PsExec on systems where PsExec is disabled or where it deviates from normal activity.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Process Creation Event Involving a COM Object by Different User</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for process creation events including COM objects that are initiated by an account that is not currently the logged-in user for the system.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>High Volume of DCOM-Related Activity</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1021/003/" rel="noopener" target="_blank"><span>T1021.003 – Remote Services: Distributed Component Object Model</span></a></p>
</td>
<td>
<p><span>Search for a sharp increase in volume of DCOM-related activity. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Third-Party Remote Access Applications</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 – Remote Access Software</span></a></p>
</td>
<td>
<p><span>Search for anomalous use of</span><strong> </strong><span>third-party remote access applications. This type of activity could indicate a threat actor is attempting to use third-party remote access applications as an alternate communication channel or for creating remote interactive sessions.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>BYOVD - EDR/AV Tampering via Vulnerable Drivers</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1068/" rel="noopener" target="_blank"><span>T1068 - Exploitation for Privilege Escalation</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Impair Defenses</span></a></p>
</td>
<td>
<p><span>Monitor for kernel driver installations (Sysmon Event ID 6) where the loaded driver hash matches known vulnerable drivers from the LOLDrivers project.</span></p>
<p><span>Alert on new service creation (Event ID 7045) loading .sys files from user-writable paths (e.g., %TEMP%, %APPDATA%). </span></p>
</td>
</tr>
<tr>
<td>
<p><span>RMM Tool Abuse for Lateral Movement</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1219/" rel="noopener" target="_blank"><span>T1219 - Remote Access Tools</span></a></p>
</td>
<td>
<p><span>Monitor for installation or execution of legitimate RMM tools (ScreenConnect/ConnectWise, AnyDesk, Atera, Splashtop, TeamViewer) that are not part of the organization's approved toolset.</span></p>
<p><span>Monitor for new service installations matching known RMM tool signatures.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 18: Detection opportunities for common lateral movement tools and methods</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Additional Endpoint Hardening</span></h4>
<p><span>To help protect against malicious binaries, malware, and encryptors being invoked on endpoints, additional security hardening technologies and controls should be considered. Examples of additional security controls for consideration for Windows-based endpoints are provided as follows.</span></p>
<h5><span>Windows Defender Application Control</span></h5>
<p><span>Windows Defender Application Control is a set of inherent configuration settings within Active Directory that provide lockdown and control mechanisms for controlling which applications and files users can run on endpoints. With this functionality, the following types of rules can be configured within GPOs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Publisher rules: Can be leveraged to allow or restrict execution of files based upon digital signatures and other attributes</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Path rules: Can be leveraged to allow or restrict file execution or access based upon files residing in specific path</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File hash rules: Can be leveraged to allow or restrict file execution based on a file's hash</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/applocker-overview" rel="noopener" target="_blank">Windows Defender Application Control</a></span><span>.</span></p>
<h5><span>Microsoft Defender Attack Surface Reduction</span></h5>
<p><span>Microsoft Defender Attack Surface Reduction (ASR) rules can help protect against various threats, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>A threat actor launching executable files and scripts that attempt to download or run files</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor running obfuscated or suspicious scripts</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking credential theft tools that interface with Local Security Authority Subsystem Service (LSASS)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>A threat actor invoking PsExec or WMI commands</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Normalizing and blocking behaviors that applications do not usually initiate as part of standardized activity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Blocking executable content from email clients and web mail (phishing)</span></p>
</li>
</ul>
<p><span>ASR requires a Windows E3 license or above. A Windows E5 license provides advanced management capabilities for ASR.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction" rel="noopener" target="_blank">Microsoft Defender Attack Surface Reduction functionality</a></span><span>.</span></p>
<h5><span>Controlled Folder Access</span></h5>
<p><span>Controlled folder access can help protect data from being encrypted by ransomware. Beginning with Windows 10 version 1709+ and Windows Server 2019+, controlled folder access was introduced within Windows Defender Antivirus (as part of Windows Defender Exploit Guard). </span></p>
<p><span>Once controlled folder access is enabled, applications and executable files are assessed by Windows Defender Antivirus, which then determines if an application is malicious or safe. If an application is determined to be malicious or suspicious, it will be blocked from making changes to any files in a protected folder.</span></p>
<p><span>Once enabled, controlled folder access will apply to a number of system folders and default locations, including:</span></p></div>
<div class="block-paragraph_advanced"><ul>
<li>Documents
<ul>
<li><code>C:\users\&lt;username&gt;\Documents</code></li>
<li><code>C:\users\Public\Documents</code></li>
</ul>
</li>
<li>Pictures
<ul>
<li><code>C:\users\&lt;username&gt;\Pictures</code></li>
<li><code>C:\users\Public\Pictures</code></li>
</ul>
</li>
<li>Videos
<ul>
<li><code>C:\users\&lt;username&gt;\Videos</code></li>
<li><code>C:\users\Public\Videos</code></li>
</ul>
</li>
<li>Music
<ul>
<li><code>C:\users\&lt;username&gt;\Music</code></li>
<li><code>C:\users\Public\Music</code></li>
</ul>
</li>
<li>Desktop
<ul>
<li><code>C:\users\&lt;username&gt;\Desktop</code></li>
<li><code>C:\users\Public\Desktop</code></li>
</ul>
</li>
<li>Favorites
<ul>
<li><code>C:\users\&lt;username&gt;\Favorites</code></li>
</ul>
</li>
</ul></div>
<div class="block-paragraph_advanced"><p><span>Additional folders can be added using the Windows Security application, Group Policy, PowerShell, or mobile device management (MDM) configuration service providers (CSPs). Additionally, applications can be allow-listed for access to protected folders.</span></p>
<p><strong>Note:</strong><span> </span><span>For controlled folder access to fully function, Windows Defender's </span><span>Real Time Protection</span><span> setting must be enabled.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-controlled-folders" rel="noopener" target="_blank">controlled folder access</a></span><span>.</span></p>
<h5><span>Tamper Protection</span></h5>
<p><span>Threat actors will often attempt to disable security features on endpoints. Tamper protection either in Windows (via Microsoft Defender for Endpoint) or integrated within third-party AV/EDR platforms can help protect security tools from being modified or stopped by a threat actor. Organizations should review the configuration of security technologies that are deployed to endpoints and verify if tamper protection is (or can be) enabled to protect against unauthorized modification. Once implemented, organizations should test and validate that the tamper protection controls behave as expected as different products offer different levels of protection.</span></p>
<p><span>Additional information related to <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection" rel="noopener" target="_blank">tamper protection for Windows Defender for Endpoint</a></span><span>.</span></p>
<h4><span>Detection Opportunities for Tamper Protection Events</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Threat Actor Attempting to Disable Security Tooling on an Endpoint</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/001/" rel="noopener" target="_blank"><span>T1562.001 - Disable or Modify Tools</span></a></p>
</td>
<td>
<p><span>Monitor for evidence of processes or command-line arguments correlating to security tools/services being stopped.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 19: Detection opportunities for tamper protection events</span></div></div>
<div class="block-paragraph_advanced"><h3><span>4. Credential Exposure and Account Protections</span></h3>
<h4><span>Identification of Privileged Accounts and Groups</span></h4>
<p><span>Threat actors will prioritize identifying privileged accounts as part of reconnaissance efforts. Once identified, threat actors will attempt to obtain credentials for these accounts for lateral movement, persistence, and mission fulfillment.</span></p>
<p><span>Organizations should proactively focus on identifying and reviewing the scope of accounts and groups within Active Directory that have an elevated level of privilege. An elevated level of privilege can be determined by the following criteria:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into default domain and Exchange-based privileged groups (Figure 29)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or nested groups that are assigned membership into security groups protected by </span><code>AdminSDHolder</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for organizational units (OUs) housing privileged accounts, groups, or endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned specific extended right permissions either directly at the root of the domain or for OUs where permissions are inherited by child objects. Examples include:</span></p>
<ul>
<li><code>DS-Replication-Get-Changes-All</code></li>
<li><code>Administer Exchange Information Store</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>Create-Inbound-Forest-Trust</code></li>
<li><code>Migrate-SID-History</code></li>
<li><code>Reanimate-Tombstones</code></li>
<li><code>View Exchange Information Store Status</code></li>
<li><code>User-Force-Change-Password</code></li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned permissions for modifying or linking GPOs</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned explicit permissions on domain controllers or Tier 0 endpoints</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups assigned directory service replication permissions</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts or groups with local administrative access on all endpoints (or a large scope of critical assets) in a domain</span></p>
</li>
</ul>
<p><span>To identify accounts that are provided membership into default domain-based privileged groups or are protected by </span><code>AdminSDHolder</code><span>, the following PowerShell cmdlets can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>get-ADGroupMember -Identity "Domain Admins" -Recursive | export-csv -path &lt;output directory&gt;\DomainAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Enterprise Admins" -Recursive | export-csv -path &lt;output directory&gt;\EnterpriseAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Schema Admins" -Recursive | export-csv -path &lt;output directory&gt;\SchemaAdmins.csv -NoTypeInformation

get-ADGroupMember -Identity "Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Administrators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Account Operators" -Recursive | export-csv -path &lt;output directory&gt;\AccountOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Backup Operators" -Recursive | export-csv -path &lt;output directory&gt;\BackupOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Cert Publishers" -Recursive | export-csv -path &lt;output directory&gt;\CertPublishers.csv -NoTypeInformation 

get-ADGroupMember -Identity "Print Operators" -Recursive | export-csv -path &lt;output directory&gt;\PrintOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "Server Operators" -Recursive | export-csv -path &lt;output directory&gt;\ServerOperators.csv -NoTypeInformation 

get-ADGroupMember -Identity "DNSAdmins" -Recursive | export-csv -path &lt;output directory&gt;\DNSAdmins.csv -NoTypeInformation 

get-ADGroupMember -Identity "Group Policy Creator Owners" -Recursive | export-csv -path &lt;output directory&gt;\Group-Policy-Creator-Owners.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Trusted Subsystem" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Trusted-Subsystem.csv -NoTypeInformation

get-ADGroupMember -Identity "Exchange Windows Permissions" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Windows-Permissions.csv -NoTypeInformation 

get-ADGroupMember -Identity "Exchange Recipient Administrators" -Recursive | export-csv -path &lt;output directory&gt;\Exchange-Recipient-Admins.csv -NoTypeInformation 

get-ADUser -Filter {(AdminCount -eq 1) -And (Enabled -eq $True)} | Select-Object Name, DistinguishedName | export-csv -path &lt;output directory&gt;\AdminSDHolder_Enabled.csv</code></pre>
<p><span>Figure 29: Commands to identify domain and exchange-based privileged accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>Any privileged accounts granted membership into additional security groups can provide a threat actor with a potential path to domain administration-level permissions based upon endpoints where the accounts have permissions to log on or remotely access systems.</span></p>
<p><span>Ideally, only a small scope of accounts should be provided with highly privileged access within a domain. Accounts with highly privileged permissions should </span><strong>not</strong><span> be leveraged for daily use; used for interactive or remote logons to workstations, laptops, or common servers; or used for performing functions on non-domain controller (Tier 0) assets.For additional recommendations for restricting access for privileged accounts, reference the Privileged Account Logon Restrictions</span><span> section of this blog post.</span></p>
<h4><span>Detection Opportunities for Privileged Accounts, Groups, and GPO Modifications</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Interactive or Remote Logon of a Highly Privileged Account to an Unauthorized System</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Account and Group Discovery</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for command-line events where a user is attempting to enumerate privileged accounts and groups.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Account Added to Highly Privileged Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Identify when accounts are added to highly privileged groups. While this can occur as part of normal activity, it should be infrequent and limited to specific accounts.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Modification of Group Policy Objects</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Identify when GPOs are created or modified.</span></p>
<p><span>GPOs can also be exported and reviewed to identify last modification timestamps.<br><br></span></p>
<pre class="language-plain"><code>get-gpo -all | export-csv -path "c:\temp\gpo-listing-all.csv" -NoTypeInformation</code></pre>
<p><span>Figure 30: PowerShell cmdlet to export and review GPO creation and modification timestamps</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DCSync Attack</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/006/" rel="noopener" target="_blank"><span>T1003.006 - OS Credential Dumping</span></a></p>
</td>
<td>
<p><span>Monitor for non-domain-controller sources issuing directory replication requests (</span><span>DS-Replication-Get-Changes</span><span> and </span><span>DS-Replication-Get-Changes-All</span><span>). </span></p>
<p><span>Event ID 4662 with properties matching the replication GUIDs (</span><span>1131f6aa-*, 1131f6ad-*</span><span>) from non-domain-controller source addresses is a high-fidelity indicator of DCSync.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 20: Detection opportunities for privileged accounts, groups, and GPO modifications</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged and Service Account Protections</span></h4>
<h5><span>Identify and Review Noncomputer Accounts Configured with an SPN</span></h5>
<p><span>Accounts with service principal names (SPNs) are commonly targeted by threat actors for privilege escalation. Using Kerberos, any domain user can request a Kerberos service ticket (TGS) from a domain controller for any account configured with an SPN. Noncomputer accounts likely are configured with guessable (nonrandom) passwords. Regardless of the domain function level or the host's Windows version, SPNs that are registered under a noncomputer account will use the legacy RC4-HMAC encryption suite rather than Advanced Encryption Standard (AES). The key used for encryption and decryption of the RC4-HMAC encryption type represents an unsalted NTLM hash version of the account's password, which could be derived via cracking the ticket.</span></p>
<p><span>Organizations should review Active Directory to identify noncomputer accounts configured with an SPN. Noncomputer accounts correlated to registered SPNs are likely service accounts and provide a method for a threat actor (without administrative privileges) to potentially derive (crack) the plain-text password for the account (Kerberoasting). To identify noncomputer accounts configured with an SPN, the PowerShell cmdlet referenced in Figure 31 can be run from a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Get-ADUser -Filter {(ServicePrincipalName -like "*")} | Select-Object name,samaccountname,sid,enabled,DistinguishedName</code></pre>
<p><span>Figure 31: PowerShell cmdlet to identify noncomputer accounts configured with an SPN</span></p></div>
<div class="block-paragraph_advanced"><p><span>Where possible, organizations should deregister noncomputer accounts with SPNs configured. Where SPNs are needed, organizations should mitigate the risk associated with Kerberoasting attacks. Accounts with SPNs should be configured with strong, unique passwords (e.g., minimum 25+ characters) with the passwords rotated on a periodic basis for the accounts. Furthermore, privileges should be reviewed and reduced for these accounts to ensure that each account has the minimum required privileges needed for the intended function.</span></p>
<p><span>Accounts with SPNs should be considered in-scope for the proactive hardening measures detailed throughout this blog post.</span></p>
<p><strong>Note:</strong><span> </span><span>SPNs should never be associated with regular interactive user accounts.</span></p>
<h4><span>Detection Opportunities for Noncomputer Accounts Configured with an SPN</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Potential Kerberoasting Attempt Using RC4</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/003/" rel="noopener" target="_blank"><span>T1558.003 – Steal or Forge Kerberos Tickets: Kerberoasting</span></a></p>
</td>
<td>
<p><span>Searching for a Kerberos request using downgraded RC4 encryption.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>AS-REP Roasting</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1558/004/" rel="noopener" target="_blank"><span>T1558.004 - Steal or Forge Kerberos Tickets</span></a></p>
</td>
<td>
<p><span>Monitor Event ID 4768 for Kerberos authentication requests using RC4 encryption (0x17) for accounts with the "</span><span>Do not require Kerberos preauthentication</span><span>" flag set. Unlike Kerberoasting (which targets SPNs), AS-REP Roasting targets accounts with disabled preauthentication (which should be reviewed and mitigated).</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 21: Detection opportunities for noncomputer accounts configured with an SPN</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Privileged Account Logon Restrictions</span></h4>
<p><span>Privileged and service account credentials are commonly used for lateral movement and establishing persistence.</span></p>
<p><span>For any accounts that have privileged access throughout an environment, the accounts should not be used on standard workstations and laptops, but rather from designated systems (e.g., privileged access workstations [PAWs]) that reside in restricted and protected VLANs and tiers. Dedicated privileged accounts should be defined for each tier, with controls that enforce that the accounts can only be used within the designated tier. Guardrail enforcement for privileged accounts can be defined within GPOs or by using authentication policy silos (Windows Server 2012 R2 domain-functional level or above).</span></p>
<p><span>The recommendations for restricting the scope of access for privileged accounts are based upon Microsoft's guidance for securing privileged access. For additional information, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/security/compass/privileged-access-access-model</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos</span></a></p>
</li>
</ul>
<h5><span>User Rights Assignments</span></h5>
<p><span>As a proactive hardening or quick containment measure, consider blocking any accounts with privileged AD access from being able to log in (remotely or locally) to standard workstations, laptops, and common access servers (e.g., virtualized desktop infrastructure).</span></p>
<p><span>The settings referenced as follows are configurable using user rights assignments defined within GPOs via the path of: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></p>
</li>
</ul>
<p><span>Accounts delegated with domain-based privileged access should be explicitly denied access to standard workstations and laptop systems within the context of the following settings (which can be configured using GPO settings similar to what are depicted in Figure 32):</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Deny access to this computer from the network (also include</span><strong> </strong><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>) (</span><code>SeDenyNetworkLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a batch job (</span><code>SeDenyBatchLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon as a service (</span><code>SeDenyServiceLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon locally (</span><code>SeDenyInteractiveLogonRight</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deny logon through Terminal Services (</span><code>SeDenyRemoteInteractiveLogonRight</code><span>)</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig32.max-1000x1000.png" alt="Example of Privileged Account Access Restrictions for a Standard Workstation Using GPO Settings">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="l6xux">Figure 32: Example of privileged account access restrictions for a standard workstation using GPO settings</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, using GPOs, permissions can be restricted on endpoints to protect against privilege escalation and potential data theft by reducing the scope of accounts that have the following user rights assignments:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Debug programs (</span><code>SeDebugPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Back up files and directories (</span><code>SeBackupPrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Restore files and directories (</span><code>SeRestorePrivilege</code><span>) </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Take ownership of files or other objects (</span><code>SeTakeOwnershipPrivilege</code><span>)</span></p>
</li>
</ul>
<h4><span>Detection Opportunities for Privileged Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of a Privileged Account from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts correlating to highly privileged accounts authenticating to systems that reside outside of the Tier 0 layer.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 22: Detection opportunities for privileged account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Service Account Logon Restrictions</span></h4>
<p><span>Organizations should also consider enhancing the security of domain-based service accounts to restrict the capability for the accounts to be used for interactive, remote desktop, and, where possible, network-based logons. </span></p>
<p><strong><span>Minimum recommended logon hardening for service accounts (on endpoints where the service account is not required for interactive or remote logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li>Deny logon locally (<code>SeDenyInteractiveLogonRight</code>)</li>
<li>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</li>
</ul>
</li>
</ul>
<p><strong><span>Additional recommended logon hardening for service accounts (on endpoints where the service accounts is not required for network-based logon purposes):</span></strong></p>
<ul>
<li><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
</ul>
</li>
</ul>
<p><span>If a service account is only required to be leveraged on a single endpoint to run a specific service, the service account can be further restricted to only permit the account's usage on a predefined listing of endpoints (Figure 33).</span></p>
<ul>
<li><span>Active Directory Users and Computers &gt; Select the account</span>
<ul>
<li><span>Account tab</span>
<ul>
<li><span>Log On To button &gt; Select the proper scope of computers for access</span></li>
</ul>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig33.max-1000x1000.png" alt="Option to Restrict an Account to Log onto Specific Endpoints">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="i2oc9">Figure 33: Option to restrict an account to log onto specific endpoints</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Service Account Logons</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Logon from a Service Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for login attempts for a service account on a new (unexpected) endpoint. This will require baselining service accounts to expected (approved) systems.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 23: Detection opportunities for service account logons</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Managed/Group Managed Service Accounts</span></h4>
<p><span>Organizations with static service accounts should review the feasibility of migrating the service accounts to be managed service accounts (MSAs) or group managed service accounts (gMSAs).</span></p>
<p><span>MSAs were first introduced with the Windows Server 2008 R2 Active Directory schema (domain-functional level) and provide automatic password management (30-day rotation) for dedicated service accounts that are associated with running services on specific endpoints.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Standard MSA: The account is associated with a single endpoint, and the complex password for the account is automatically managed and changed on a predefined frequency (30 days by default). While an MSA can only be associated with a single computer account, multiple services on the same endpoint can leverage the MSA.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Group managed service account (gMSA): First introduced with Windows Server 2012 and are very similar to MSAs, but allow for a single gMSA to be leveraged across </span><span>multiple</span><span> endpoints.</span></p>
</li>
</ul>
<p><span>Common uses for MSAs and gMSAs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Scheduled Tasks</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Internet Information Services (IIS) application pools</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Structured Query Language (SQL) services (SQL 2012 and later) – Express editions are </span><strong>not</strong><span> supported by MSAs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Microsoft Exchange services</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Network Load Balancing (clustering) – gMSAs only</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Third-party applications that support MSAs</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>Threat actors can potentially discover accounts and groups that have permissions to read/leverage the password for a gMSA for privilege escalation and lateral movement. This can be accomplished by leveraging the </span><code>get-adserviceaccount</code><span> PowerShell cmdlet and enumerating the </span><code>msDS-GroupMSAMembership</code><span> (</span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span>) configuration for a gMSA, which stores the security principals that can access the gMSA password. It is important that when configuring managed service accounts, organizations focus on restricting the scope of accounts and groups that have the ability to obtain and leverage the password for the managed service accounts and enforce structured monitoring of these accounts and groups.</span></p>
<p><span>For additional information related to MSAs and gMSAs, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009" rel="noopener" target="_blank"><span>https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/managed-service-accounts-understanding-implementing-best/ba-p/397009</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview" rel="noopener" target="_blank"><span>https://docs.microsoft.com/en-us/windows-server/security/group-managed-service-accounts/group-managed-service-accounts-overview</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Managed/Group Managed Service Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Group Membership Addition</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1069/" rel="noopener" target="_blank"><span>T1069 – Permission Groups Discovery</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for MSAs/gMSAs and the associated </span><code>PrincipalsAllowedToRetrieveManagedPassword</code><span> or </span><code>PrincipalsAllowedToDelegateToAccount</code><span> permissions, which could provide the ability to leverage the MSA/gMSA for malicious purposes.</span></p>
<p><span>Example reconnaissance commands for querying for MSAs/gMSAs and associated attributes:<br><br></span></p>
<pre class="language-plain"><code>get-adserviceaccount

get-adserviceaccount -filter {name -eq 'account-name'} -prop * | select Name, MemberOf, PrincipalsAllowedToDelegateToAccount, PrincipalsAllowedToRetrieveManagedPassword</code></pre>
<p><span>Figure 34: Example reconnaissance commands for querying for MSAs/gMSAs</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 24: Detection opportunities for managed/group managed service accounts</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Protected Users Security Group</span></h4>
<p><span>By leveraging the Protected Users security group for privileged accounts, an organization can minimize various exposure factors and common exploitation methods by a threat actor or malware variant obtaining credentials for privileged accounts on disk or in memory from endpoints.</span></p>
<p><span>Beginning with Microsoft Windows 8.1 and Microsoft Windows Server 2012 R2 (and above), the Protected Users security group was introduced to manage credential exposure within an environment. Members of this group automatically have specific protections applied to accounts, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The Kerberos ticket granting ticket (TGT) expires after four hours, rather than the normal 10-hour default setting.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>No NTLM hash for an account is stored in LSASS, since only Kerberos authentication is used (NTLM authentication is disabled for an account).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Cached credentials are blocked. A domain controller must be available to authenticate the account.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>WDigest authentication is disabled for an account, regardless of an endpoint's applied policy settings.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DES and RC4 cannot be used for Kerberos preauthentication (Server 2012 R2 or higher); rather, Kerberos with AES encryption will be enforced.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Accounts cannot be used for either constrained or unconstrained delegation (equivalent to enforcing the </span><span>Account is sensitive and cannot be delegated</span><span> setting in Active Directory Users and Computers).</span></p>
</li>
</ul>
<p><span>To provide domain controller-side restrictions for members of the Protected Users security group, the domain functional level must be Windows Server 2012 R2 (or higher). Microsoft Security Advisory </span><a href="https://msrc-blog.microsoft.com/2014/06/05/an-overview-of-kb2871997/" rel="noopener" target="_blank"><span>KB2871997</span></a><span> adds compatibility support for the protections enforced for members of the Protected Users security group for Windows 7, Windows Server 2008 R2, and Windows Server 2012 systems.</span></p>
<p><span>Successful (Event IDs 303, 304) or failed (Event IDs 100, 104) logon events for members of the Protected Users security group can be recorded on domain controllers within the following event logs:</span></p>
<ul>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserSuccesses-DomainController.evtx</code></pre>
</li>
<li role="presentation">
<pre class="language-plain"><code>%SystemRoot%\System32\Winevt\Logs\Microsoft-Windows-Authentication%4ProtectedUserFailures-DomainController.evtx</code></pre>
</li>
</ul>
<p><span>The event logs are disabled by default and must be enabled on each domain controller. The PowerShell cmdlets referenced in Figure 35 can be leveraged to enable the event logs for the Protected Users security group on a domain controller.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>$log1 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController
$log1.IsEnabled=$true
$log1.SaveChanges()

$log2 = New-Object System.Diagnostics.Eventing.Reader.EventLogConfiguration Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController
$log2.IsEnabled=$true
$log2.SaveChanges()</code></pre>
<p><span>Figure 35: PowerShell cmdlets for enabling event logging for the Protected Users security group on domain controllers</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>Service accounts (including MSAs) should </span><strong>not</strong><span> be added to the Protected Users security group, as authentication will fail.</span></p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><span>If the Protected Users security group cannot be used, at a minimum, privileged accounts should be protected against delegation by configuring the account with the </span><span>Account is Sensitive and Cannot Be Delegated</span><span> flag in Active Directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for the Protected Users Security Group</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Removal of Account from Protected User Group</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1098/" rel="noopener" target="_blank"><span>T1098 – Account Manipulation</span></a></p>
</td>
<td>
<p><span>Search for an account that has been removed from the Protected Users group. </span></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Logon of an Account in the Protected User Group from a Nonprivileged Access Workstation</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/" rel="noopener" target="_blank"><span>T1078 – Valid Accounts</span></a></p>
</td>
<td>
<p><span>Search for logon attempts from accounts in the Protected Users group authenticating from workstations of nonprivileged users.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 25: Detection opportunities for the Protected Users security group</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Clear-Text Password Protections</span></h4>
<p><span>In addition to restricting access for privileged accounts, controls should be enforced that minimize the exposure of credentials and tokens in memory on endpoints.</span></p>
<p><span>On older Windows versions, clear-text passwords are stored in memory (LSASS) to primarily support WDigest authentication. WDigest should be explicitly disabled on all Windows endpoints where it is not disabled by default.</span></p>
<p><span>By default, WDigest authentication is disabled in Windows 8.1+ and in Windows Server 2012 R2+.</span></p>
<p><span>Beginning with Windows 7 and Windows Server 2008 R2, after installing KB2871997, WDigest authentication can be configured either by modifying the registry or by using the Microsoft Security Guide GPO template from the <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank">Microsoft Security Compliance Toolkit</a></span><span>.</span></p>
<h5><span>Registry Method</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
REG_DWORD = "0"</code></pre>
<p><span>Figure 36: Registry key and value for disabling WDigest authentication</span></p></div>
<div class="block-paragraph_advanced"><p><span>Another registry setting that should be explicitly configured is the </span><code>TokenLeakDetectDelaySecs</code><span> setting (Figure 37), which will clear credentials in memory of logged-off users after 30 seconds, mimicking the behavior of Windows 8.1 and above.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\Lsa\TokenLeakDetectDelaySecs
REG_DWORD = "30"</code></pre>
<p><span>Figure 37: Registry key and value for enforcing the TokenLeakDetectDelaySecs setting</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Method</span></h5>
<p><span>Using the Microsoft Security Guide Group Policy template, WDigest authentication can be disabled via a GPO setting (Figure 38).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; WDigest Authentication</span></p>
<ul>
<li aria-level="1"><span><span>Disabled</span></span></li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig38.max-1000x1000.png" alt="Disabling WDigest Authentication via the MS Security Guide Group Policy Template">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="11qec">Figure 38: Disabling WDigest authentication via the MS Security Guide Group Policy Template</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Additionally, an organization should verify that </span><code>Allow*</code><span> settings are not specified within the registry keys referenced in Figure 39, as this configuration would permit the </span><code>tspkgs</code><span>/CredSSP providers to store clear-text passwords in memory.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp\PolicyDefaults
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CredentialsDelegation</code></pre>
<p><span>Figure 39: Additional registry keys for hardening against clear-text password storage</span></p></div>
<div class="block-paragraph_advanced"><h5><span>Group Policy Reprocessing</span></h5>
<p><span>Threat actors can manually enable WDigest authentication on endpoints by directly modifying the registry (</span><code>UseLogonCredential</code><span> configured to a value of </span><code>1</code><span>). Even on endpoints where WDigest authentication is automatically disabled by default, it is recommended to enforce the GPO settings noted as follows, which will enforce automatic group policy reprocessing for the configured (expected) settings on an automated basis.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure security policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Group Policy &gt; Configure registry policy processing</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled - Process even if the Group Policy objects have not changed</span></p>
</li>
</ul>
</li>
</ul>
<p><strong>Note:</strong><span> </span><span>By default, Group Policy settings are only reprocessed and reapplied if the actual Group Policy was modified prior to the default refresh interval.</span></p>
<p><span>As KB2871997 is not applicable for Windows XP, Windows Server 2003, and Windows Server 2008, to disable WDigest authentication on these platforms, prior to a system reboot, WDigest needs to be removed from the listing of LSA security packages within the registry (Figure 40 and Figure 41).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\Security Packages</code></pre>
<p><span>Figure 40: Registry key to modify LSA security packages</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/destructive-attacks-guidance-fig41.max-1000x1000.png" alt="LSA security Package Registry Key Before and After Removal of WDigest Authentication from Listing of Providers">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="71ljq">Figure 41: LSA security package registry key before and after removal of WDigest authentication from listing of providers</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for WDigest Authentication Conditions</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Enable WDigest Authentication</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for evidence of WDigest being enabled in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential

REG_DWORD = "1"</code></pre>
<p><span>Figure 42: WDigest Windows Registry modification</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LSASS Memory Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1003/001/" rel="noopener" target="_blank"><span>T1003.002 - OS Credential Dumping - LSASS Memory</span></a></p>
</td>
<td>
<p><span>Monitor for processes accessing lsass.exe memory (Sysmon Event ID 10 with GrantedAccess 0x1010 or 0x1FFFFF). Alert on any non-system process opening a handle to LSASS. Deploy LSA Protection (RunAsPPL) and Credential Guard on all supported endpoints.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 26: Detection opportunities for WDigest authentication conditions</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Credential Protections When Using RDP</span></h4>
<h5><span>Restricted Admin Mode for RDP</span></h5>
<p><span>Restricted Admin mode for RDP can be enabled for all end-user systems assigned to personnel that perform Remote Desktop connections to servers or workstations with administrative credentials. This feature can limit the in-memory exposure of administrative credentials on a destination endpoint when accessed using RDP.</span></p>
<p><span>To leverage Restricted Admin RDP, the command referenced in Figure 43 can be invoked.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /RestrictedAdmin</code></pre>
<p><span>Figure 43: Command to invoke restricted admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><span>When an RDP connection uses the Restricted Admin mode, if the authenticating account is an administrator on the destination endpoint, the credentials for the user account are </span><strong>not</strong><span> stored in memory; rather, the context of the user account appears as the destination machine account (</span><code>domain\destination-computer$</code><span>).</span></p>
<p><span>To leverage Restricted Admin mode for RDP, settings must be enforced on the originating endpoint in addition to the destination endpoint.</span></p>
<h6><span>Originating Endpoint (Client Mode - Windows 7 and Windows Server 2008 R2 and above)</span></h6>
<p><span>A GPO setting must be applied to the originating endpoint initiating the remote desktop session using the </span><span>Restricted Admin</span><span> feature.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Require Restricted Admin</span><span> &gt; set to </span><span>Enabled</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Use the Following Restricted Mode</span><span> &gt; </span><span>Required Restricted Admin</span></p>
</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>Configuring this GPO setting will result in the registry keys noted in Figure 44 being configured on an endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministration
0 = Disabled
1 = Enabled

HKLM\Software\Policies\Microsoft\Windows\CredentialsDelegation\RestrictedRemoteAdministrationType
1 = Require Restricted Admin
2 = Require Remote Credential Guard
3 = Restrict Credential Delegation</code></pre>
<p><span>Figure 44: Registry settings for requiring Restricted Admin mode</span></p></div>
<div class="block-paragraph_advanced"><h6><span>Destination Endpoint (Server Mode - Windows 8.1 and Windows Server 2012 R2 and above)</span></h6>
<p><span>A registry setting will need to be configured (Figure 45).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin
0 = Enabled
1 = Disabled</code></pre>
<p><span>Figure 45: Registry setting for enabling or disabling Restricted Admin RDP</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>0</code><span> to enable Restricted Admin mode.</span></p>
<p><span>With Restricted Admin RDP, another setting that should be configured is the </span><code>DisableRestrictedAdminOutboundCreds</code><span> registry key (Figure 46).</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdminOutboundCreds
0 = default value (doesn't exist) - Admin Outbound Creds are Enabled
1 = Admin Outbound Creds are Disabled</code></pre>
<p><span>Figure 46: Registry setting for disabling admin outbound credentials</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Recommended:</strong><span> </span><span>Set the registry value to </span><code>1</code><span> to disable admin outbound credentials.</span></p>
<p><strong>Note:</strong><span> </span><span>With this setting set to </span><code>0</code><span>, any outbound authentication requests will appear as the system (</span><code>domain\destination-computer$)</code><span> that a user connected to using Restricted Admin mode. Setting this to </span><code>1</code><span> disables the ability to authenticate to any downstream network resources when attempting to authenticate outbound from a system that a user connected to using Restricted Admin mode for RDP.</span></p>
<p><span>For additional information regarding Restricted Admin mode for RDP, reference:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><a href="https://support.microsoft.com/kb/2973351" rel="noopener" target="_blank"><span>https://support.microsoft.com/kb/2973351</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><a href="https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/" rel="noopener" target="_blank"><span>https://blogs.technet.microsoft.com/kfalde/2013/08/14/restricted-admin-mode-for-rdp-in-windows-8-1-2012-r2/</span></a></p>
</li>
</ul>
<h4><span>Detection Opportunities for Restricted Admin Mode for RDP</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Restricted Admin Mode for RDP</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Restricted Admin mode for RDP in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa\DisableRestrictedAdmin 

REG_DWORD = "1"</code></pre>
<p><span>Figure 47: Restricted Admin mode for RDP being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Restricted Admin</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Restricted Admin</span><span> option being disabled within a GPO configuration. </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; System &gt; Credential Delegation &gt; Restrict delegation of credentials to remote servers

"Require Restricted Admin" &gt; set to Disabled</code></pre>
<p><span>Figure 48: Require Restricted Admin being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 27: Detection opportunities for Restricted Admin Mode for RDP</span></div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Windows Defender Remote Credential Guard</span></h4>
<p><span>For Windows 10 and Windows Server 2016 endpoints, Windows Defender Remote Credential Guard can be leveraged to reduce the exposure of privileged accounts in memory on destination endpoints when Remote Desktop is used for connectivity. With Remote Credential Guard, all credentials remain on the client (origination system) and are not directly exposed to the destination endpoint. Instead, the destination endpoint requests service tickets from the source as needed.</span></p>
<p><span>When a user logs in via RDP to an endpoint that has Remote Credential Guard enabled, none of the SSPs in memory store the account's clear-text password or password hash. Note that Kerberos tickets remain in memory to allow interactive (and single sign-on [SSO]) experiences from the destination server.</span></p>
<p><span>The Remote Desktop client (origination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1703) to be able to supply credentials</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016 to use the user's signed-in credentials (no prompt for credentials)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User's account must be able to sign into both the client (origination) and the remote (destination) endpoint</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must be running the Remote Desktop Classic Windows application</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must use Kerberos authentication to connect to the remote host</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The Remote Desktop Universal Windows Platform application does not support Windows Defender Remote Credential Guard.</span></p>
</li>
</ul>
<p><strong>Note:</strong><span> If the client cannot connect to a domain controller, then RDP attempts to fall back to NTLM. Windows Defender Remote Credential Guard does not allow NTLM fallback because this would expose credentials to risk.</span></p>
<p><span>The Remote Desktop remote (destination) host:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Must be running at least Windows 10 (v1607) or Windows Server 2016</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow Restricted Admin connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow the client's domain user to access Remote Desktop connections</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Must allow delegation of nonexportable credentials</span></p>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the client (origination) host using a GPO configuration:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</span></em>
<ul>
<li><span>To require either Restricted Admin mode or Windows Defender Remote Credential Guard, choose <em>Prefer Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, Remote Credential Guard is preferred, but it will use <em>Restricted Admin mode</em> (if supported) when Remote Credential Guard cannot be used.</span></li>
<li><span>Neither Remote Credential Guard nor Restricted Admin mode for RDP will send credentials in clear text to the Remote Desktop server.</span></li>
</ul>
</li>
<li><span>To require Remote Credential Guard, choose <em>Require Windows Defender Remote Credential Guard</em>.</span>
<ul>
<li><span>In this configuration, a Remote Desktop connection will succeed only if the remote computer meets the requirements for Remote Credential Guard.</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><span>To enable Remote Credential Guard on the remote (destination) host, see Figure 49.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa
Registry Entry: DisableRestrictedAdmin
Value: 0
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /d 0 /t REG_DWORD</code></pre>
<p><span>Figure 49: Registry key and command options to enable Remote Credential Guard on a remote (destination) host</span></p></div>
<div class="block-paragraph_advanced"><p><span>To leverage Remote Credential Guard, use the command referenced in Figure 50.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mstsc.exe /remoteguard</code></pre>
<p><span>Figure 50: Command to leverage Remote Credential Guard</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for Windows Defender Remote Credential Guard</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1112/" rel="noopener" target="_blank"><span>T1112 – Modify Registry</span></a></p>
</td>
<td>
<p><span>Search for an account disabling Remote Credential Guard in the Windows Registry.<br><br></span></p>
<pre class="language-plain"><code>HKLM\System\CurrentControlSet\Control\Lsa

Registry Entry: DisableRestrictedAdmin

Value: 1</code></pre>
<p><span>Figure 51: Remote Credential Guard being disabled in the Windows Registry on a destination endpoint</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Disable Require Remote Credential Guard</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1484/001/" rel="noopener" target="_blank"><span>T1484.001 – Domain Policy Modification: Group Policy Modification</span></a></p>
</td>
<td>
<p><span>Search for the </span><span>Require Remote Credential Guard</span><span> option being disabled within a GPO configuration.<br> </span></p>
<pre class="language-plain"><code>Computer Configuration &gt; Administrative Templates &gt; System &gt; Credentials Delegation &gt; Restrict delegation of credentials to remote servers</code></pre>
<p><span>Figure 52: Remote Credential Guard being disabled in a GPO</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div><span>Table 28: Detection opportunities for Windows Defender Remote Credential Guard</span></div>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Restrict Remote Usage of Local Accounts</span></h4>
<p><span>Local accounts that exist on endpoints are often a common avenue leveraged by threat actors to laterally move throughout an environment. This tactic is especially impactful when the password for the built-in local administrator account is configured to the same value across multiple endpoints.</span></p>
<p><span>To mitigate the impact of local accounts being leveraged for lateral movement, organizations should consider both limiting the ability of local administrator accounts to establish remote connections and creating unique and randomized passwords for local administrator accounts across the environment.</span></p>
<p><a href="https://support.microsoft.com/en-us/help/2871997/microsoft-security-advisory-update-to-improve-credentials-protection-a" rel="noopener" target="_blank"><span>KB2871997</span></a><span> introduced two well-known SIDs that can be leveraged within GPO settings to restrict the use of local accounts for lateral movement.</span></p>
<ul>
<li role="presentation"><code>S-1-5-113: NT AUTHORITY\Local account</code></li>
<li role="presentation"><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code></li>
</ul>
<p><span>Specifically, the SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> is added to an account's access token if the local account is a member of the </span><code>BUILTIN\Administrators</code><span> group. </span><strong>This is the most beneficial SID to leverage to help stop a threat actor (or ransomware variant) that propagates using credentials for any local administrative accounts.</strong></p>
<p><strong>Note:</strong><span> </span><span>For SID </span><code>S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span>, if Failover Clustering is used, this feature should leverage a nonadministrative local account (</span><code>CLIUSR</code><span>) for cluster node management. </span><strong>If this account is a member of the local Administrators group on an endpoint that is part of a cluster, blocking the network logon permissions can cause cluster services to fail.</strong><span> Be cautious and thoroughly test this configuration on servers where Failover Clustering is used.</span></p>
<h4><span>Step 1 – Option 1: S-1-5-114 SID</span></h4>
<p><span>To mitigate the use of local administrative accounts from being used for lateral movement, use the </span><code>SID S-1-5-114: NT AUTHORITY\Local account and member of Administrators group</code><span> within the following settings:</span></p>
<ul>
<li><em><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; User Rights Assignment</span></em>
<ul>
<li><span>Deny access to this computer from the network (<code>SeDenyNetworkLogonRight</code>)</span></li>
<li><span>Deny logon as a batch job (<code>SeDenyBatchLogonRight</code>)</span></li>
<li><span>Deny logon as a service (<code>SeDenyServiceLogonRight</code>)</span></li>
<li><span>Deny logon through Terminal Services (<code>SeDenyRemoteInteractiveLogonRight</code>)</span></li>
<li><span>Debug programs (<code>SeDebugPrivilege</code>: Permission used for attempted privilege escalation and process injection)</span></li>
</ul>
</li>
</ul>
<h4><span>Step 1 – Option 2: UAC Token-Filtering</span></h4>
<p><span>An additional control that can be enforced via GPO settings pertains to the usage of local accounts for remote administration and connectivity during a network logon. If the full scope of permissions (referenced previously) cannot be implemented in a short timeframe, consider applying the User Account Control (UAC) token-filtering method to local accounts for network-based logons. </span></p>
<p><span>To leverage this configuration via a GPO setting:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Download the Security Compliance Toolkit (</span><a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319" rel="noopener" target="_blank"><span>https://www.microsoft.com/en-us/download/details.aspx?id=55319</span></a><span>) to use the MS Security Guide </span><code>ADMX</code><span> file. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Once downloaded, the </span><code>SecGuide.admx</code><span> and </span><code>SecGuide.adml</code><span> files must be copied to the </span><code>\Windows\PolicyDefinitions</code><span> and </span><code>\Windows\PolicyDefinitions\en-US directories</code><span> respectively.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If a centralized GPO store is configured for the domain, copy the </span><code>PolicyDefinitions</code><span> folder to the </span><code>C:\Windows\SYSVOL\sysvol\&lt;domain&gt;\Policies</code><span> folder.</span></p>
</li>
</ol>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; Apply UAC restrictions to local accounts on network logons</span></p>
<ul>
<li aria-level="1"><span>Enabled</span></li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 53) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy

REG_DWORD = "0" (Enabled)</code></pre>
<p><span>Figure 53: Registry key and value for enabling UAC restrictions for local accounts</span></p></div>
<div class="block-paragraph_advanced"><p><span>When set to </span><code>0</code><span>, remote connections with high-integrity access tokens are only possible using either the plain-text credential or password hash of the RID 500 local administrator (and only then depending on the setting of </span><code>FilterAdministratorToken</code><span>, which is configurable via the GPO setting of </span><span>User Account Control: Admin Approval Mode for the built-in Administrator account</span><span>).</span></p>
<p><span>The </span><code>FilterAdministratorToken</code><span> option can either enable (1) or disable (0) (default) </span><span>Admin Approval</span><span> mode for the RID 500 local administrator. When enabled, the access token for the RID 500 local administrator account is filtered and therefore UAC is enforced for this account (which can ultimately stop attempts to leverage this account for lateral movement across endpoints).</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options &gt; User Account Control: Admin Approval Mode for the built-in Administrator account</span></p>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 54) will be configured on each endpoint.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\FilterAdministratorToken

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 54: Registry key and value for requiring Admin Approval Mode for local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>Note:</strong><span> </span><span>It is also prudent to ensure that the default setting for </span><span>User Account Control: Run all administrators in Admin Approval Mode</span><span> (</span><code>EnableLUA</code><span> option) </span><strong>is not changed</strong><span> from </span><span>Enabled</span><span> (default, as shown in Figure 55) to </span><span>Disabled</span><span>. If this setting is disabled, </span><strong>all UAC policies are also disabled</strong><span>. With this setting disabled, it is possible to perform privileged remote authentication using plain-text credentials or password hashes with any local account that is a member of the local Administrators group.</span></p>
<h5><span>GPO Setting</span></h5>
<ul>
<li aria-level="1">
<p role="presentation"><span>Computer Configuration &gt; Policies &gt; Administrative Templates &gt; MS Security Guide &gt; User Account Control: Run all administrators in Admin Approval Mode</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Enabled</span></p>
</li>
</ul>
</li>
</ul>
<p><span>Once enabled, the registry value (Figure 55) will be configured on each endpoint. This is the default setting.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA

REG_DWORD = "1" (Enabled)</code></pre>
<p><span>Figure 55: Registry key and value for requiring Admin Approval Mode for all local administrative accounts</span></p></div>
<div class="block-paragraph_advanced"><p><strong>UAC access token filtering will not affect any domain accounts in the local Administrators group on an endpoint.</strong></p>
<h4><span>Step 2: LAPS</span></h4>
<p><span>In addition to blocking the use of local administrator accounts from remote authentication to access endpoints, an organization should align a strategy to enforce password randomization for the built-in local administrator account. For many organizations, the easiest way to accomplish this task is by deploying and leveraging Microsoft's Local Administrator Password Solutions (LAPS).</span></p>
<p><span>Additional information regarding <a href="https://www.microsoft.com/en-us/download/details.aspx?id=46899" rel="noopener" target="_blank">LAPS</a>, and <a href="https://learn.microsoft.com/en-us/entra/identity/devices/howto-manage-local-admin-passwords" target="_blank">here too</a>.</span></p>
<h4><span>Detection Opportunities for Local Accounts</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Attempted Remote Logon of Local Account</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1078/003/" rel="noopener" target="_blank"><span>T1078.003 - Valid Accounts: Local Accounts</span></a></p>
</td>
<td>
<p><span>Search for remote logon attempts for local accounts on an endpoint.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 29: Detection opportunities for local accounts</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Active Directory Certificate Services (AD CS) Protections</span></h4>
<p><span>Active Directory Certificate Services (AD CS) is Microsoft's implementation of Public Key Infrastructure (PKI) and integrates directly with Active Directory forests and domains. It can be utilized for a variety of purposes, including digital signatures and user authentication. Certificate Templates are used in AD CS to issue certificates that have been preconfigured for particular tasks. They contain settings and rules that are applied to incoming certificate requests and provide instructions on how a valid certificate request is provided.</span></p>
<p><span>In June of 2021, SpecterOps published a blog post named </span><a href="https://specterops.io/blog/2021/06/17/certified-pre-owned/" rel="noopener" target="_blank"><span>Certified Pre-Owned</span></a><span>, which details their research into possible attacks against AD CS. Since that publication, Mandiant has continued to observe both threat actors and red teamers enhance targeting of AD CS in support of post-compromise objectives. Mandiant's </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/defend-ad-cs-threats/"><span>blog post</span></a> <span>and </span><a href="https://services.google.com/fh/files/misc/active-directory-certificate-services-hardening-wp-en.pdf" rel="noopener" target="_blank"><span>hardening guide</span></a><span> address the continued abuse scenarios and AD CS attack vectors identified through our frontline observations of recent security breaches.</span></p>
<h4><span>Discover Vulnerable Certificate Templates</span></h4>
<p><span>Certificate templates that have been configured and published by AD CS are stored in Active Directory as objects with an object class of </span><code>pKICertificateTemplate</code><span> and can be discovered by blue teams as well as threat actors. Any account that is authenticated to Active Directory can query LDAP directly, with the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Mandiant recommends using one of these methods to discover vulnerable certificate templates.</span></p>
<h4><span>Harden Vulnerable Certificate Templates</span></h4>
<p><span>Once discovered, vulnerable certificate templates should be hardened to prevent abuse.</span></p></div>
<div class="block-paragraph_advanced"><ol>
<li aria-level="1">
<p role="presentation"><span>Ensure that all domain controllers and Certificate Authority servers are patched with the latest updates and hotfixes.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>After installing Windows update (</span><a href="https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16" rel="noopener" target="_blank"><span>KB5014754</span></a><span>) and monitoring/remediating for Event IDs 39 and 41, configure Active Directory to support full enforcement mode to reject authentications based on weaker mappings in certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Using one of the aforementioned methods, regularly review published certificate templates, specifically for any settings related to SAN specifications configured in existing templates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review the security permissions assigned to all published certificate templates and validate the scope of enrollment and write permissions are delegated to the correct security principals.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Review published templates configured with the following Enhanced Key Usages (EKUs) that support domain authentication and verify the operational requirement for these configurations.</span></p>
</li>
</ol><ul>
<li aria-level="2">
<p role="presentation"><span>Any Purpose (2.5.29.37.0)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Subordinate CA (None)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Client Authentication (1.3.6.1.5.5.7.3.2)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>PKINIT Client Authentication (1.3.6.1.5.2.3.4)</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Smart Card Logon (1.3.6.1.4.1.311.20.2.2)</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>For templates with sensitive Enhanced Key Usage (EKU), limit enrollment permissions to predefined users or groups, as certificates with EKUs can be used for multiple purposes. Access control lists for templates should be audited to ensure that they align with the principle of least privilege.</span><span>Templates that allow for domain authentication should be carefully reviewed to verify that built-in groups that contain a large scope of accounts are not assigned enrollment permissions. Example: built-in groups that could increase the risk for abuse include:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Everyone</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>NT AUTHORITY\Authenticated Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Users</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Domain Computers</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Where possible, enforce "CA Certificate Manager approval" for any templates that include a SAN as an issuance requirement. This will require that any certificate issuance requests be manually reviewed and approved by an identity assigned the "Issue and Manage Certificates" permission on a certificate authority server.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensure that Certificate Authorities have not been configured to accept any SAN (irrelevant of the template configuration). This is a non-default configuration and should be avoided wherever possible. This abuse vector is mitigated by KB5014754, but until enforcement of strong mappings is enforced, abuse could still occur based upon historical certificates missing the new OID containing the requester's SID. For additional information, reference the following </span><a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn786426(v=ws.11)#controlling-user-added-subject-alternative-names" rel="noopener" target="_blank"><span>Microsoft article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Treat both root and subordinate certificate authorities as Tier 0 assets and enforce logon restrictions or authentication policy silos to limit the scope of accounts that have elevated access to the servers where certificate services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Audit and review the NTAuthCertificates container in AD to validate the referenced CA certificates, as this container references CA certificates that enable authentication within AD. Before authenticating a principal, AD checks the NTAuthCertificates container for the CA specified in the authenticating certificate's Issuer field to validate the authenticity of the CA. If rogue or unauthorized CA certificates are present, this could be indicative of a security event that requires further triage and investigation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To avoid the theft of a CA's private keys (e.g., via the DPAPI backup protocol), protect the private keys by leveraging a Hardware Security Module (HSM) on servers where certificate authority services are installed and configured.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce multifactor authentication (MFA) for CA and AD management and operations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keep the root CA offline and use subordinate CAs to issue certificates.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Regularly validate and identify potential misconfigurations within existing certificate templates using the built-in Windows command </span><code>certutil.exe</code><span>, or with specialized tools such as </span><a href="https://github.com/GhostPack/PSPKIAudit" rel="noopener" target="_blank"><span>PSPKIAudit</span></a><span>, </span><a href="https://github.com/ly4k/Certipy" rel="noopener" target="_blank"><span>Certipy</span></a><span>, and </span><a href="https://github.com/GhostPack/Certify" rel="noopener" target="_blank"><span>Certify</span></a><span>. Public tools (e.g., PSPKIAudit, Certipy, or Certify) may be flagged by EDR products as they are frequently used by red teams and threat actors.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>To mitigate NTLM Relay attacks in AD CS, enable Extended Protection For Authentication for Certificate Authority Web Enrollment and Certificate Enrollment Web Service. Additionally, require that AD CS accept only HTTPS connections. For additional details, reference the following </span><a href="https://support.microsoft.com/en-gb/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429" rel="noopener" target="_blank"><span>Microsoft Article</span></a><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable audit logging for Certificate Services on CA servers and Kerberos Authentication Service on Domain Controllers by using group policy. Ensure that event IDs 4886 and 4887 from CA servers and 4768 from domain controllers are aggregated in the organization's SIEM solution.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enable the audit filter on each CA server. This is a bitmask value that represents the seven different audit categories that can be enabled; if all values are enabled, the audit filter will have a value of 127.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Log and monitor events from the CA servers and domain controllers to enhance detections related to AD CS activities (steps 16 and 17 are needed to ensure the appropriate logs are generated).</span></p>
</li>
</div>
<div class="block-paragraph_advanced"><h4><span>Detection Opportunities for AD CS Abuse</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Certificate Request with Mismatched SAN (ESC1)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor event IDs 4886 (certificate request received) and 4887 (certificate issued) on CA servers. Alert when the requesting account's identity differs from the Subject Alternative Name (SAN) specified in the certificate.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NTLM Relay to AD CS Web Enrollment (ESC8)</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1557/001/" rel="noopener" target="_blank"><span>T1557.001 - LLMNR/NBT-NS Poisoning and SMB Relay</span></a></p>
<p><a href="https://attack.mitre.org/techniques/T1649/" rel="noopener" target="_blank"><span>T1649 - Steal or Forge Authentication Certificates</span></a></p>
</td>
<td>
<p><span>Monitor for NTLM authentication to AD CS HTTP enrollment endpoints from domain controllers or privileged servers. Correlate with PetitPotam coercion indicators. This attack chain provides a direct path from any domain user to Domain Admin.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 30: Detection opportunities for AD CS abuse</span></div></div>
<div class="block-paragraph_advanced"><h3><span>5. Preventing Destructive Actions in Kubernetes and CI/CD Pipelines</span></h3>
<p><span>Organizations should implement a proactive, defense-in-depth technical hardening strategy to systematically address foundational security gaps and mitigate the risk of destructive actions across their Kubernetes environments and Continuous Integration/Continuous Delivery or Deployment (CI/CD) pipelines. Adversaries increasingly target the CI/CD pipeline and the Kubernetes control plane because they serve as centralized hubs with direct access to application deployments and underlying infrastructure.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Source and Build Compromise:</strong><span> Threat actors target code repositories (e.g., GitHub, GitLab, Azure DevOps) and build environments to steal injected environment variables and secrets. Attackers can then commit malicious workflow files designed to exfiltrate repository data or deploy unauthorized infrastructure.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Container Registry Poisoning: </strong><span>By compromising developer credentials or CI/CD pipeline permissions, attackers overwrite legitimate application images in the container registry. When the Kubernetes cluster pulls the updated image, it unknowingly deploys a poisoned container embedded with backdoors, ransomware, or destructive data-wiping logic.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Cluster-Level Destruction:</strong><span> Once an attacker gains a foothold inside the Kubernetes cluster, they often abuse over-permissive role-based access control (RBAC) configurations. This provides the capability to execute destructive commands using application programming interfaces (APIs) (e.g., kubectl delete deployments), wipe persistent volumes, or delete critical namespaces, effectively causing a loss of availability and application denial of service.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secrets Extraction and Lateral Movement: </strong><span>Attackers routinely execute Kubernetes-specific attack tools to harvest secrets from compromised Kubernetes pods. These secrets often contain database passwords and cloud identity and access management (IAM) keys, allowing the attacker to pivot out of the cluster and impact cloud-based resources.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-top-10-ci-cd-security-risks/" rel="noopener" target="_blank">securing CI/CD</a>.</span></p>
<h4><span>Hardening and Mitigation Guidance</span></h4>
<p><span>To defend against CI/CD compromises and destructive actions within Kubernetes, organizations must enforce strict identity boundaries, cryptographic trust, and a least-privilege architecture.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Isolate the Kubernetes Control Plane:</strong><span> Disable unrestricted and public internet access to the Kubernetes API server. For managed services like GKE, EKS, and AKS, ensure the control plane is configured as a private endpoint or heavily restricted via authorized network IP allow-listing. Access to the API should only be permitted from trusted, designated internal management subnets or secure corporate VPNs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Secure Management Interfaces and CI/CD Pipelines:</strong><span> Enforce mandatory MFA for all access to infrastructure management platforms, including source code repositories such as GitLab/GitHub, and container registries. Utilize hardened container images (e.g., Chainguard containers, Docker Hardened Images) as base images. Implement software supply chain security frameworks (like </span><a href="https://openssf.org/projects/slsa/" rel="noopener" target="_blank"><span>SLSA</span></a><span>) by requiring image signing, provenance generation, and admission controllers (such as Binary Authorization). This ensures that the Kubernetes cluster will definitively reject and block any unverified or poisoned container images from running.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enforce Strict RBAC and Least Privilege:</strong><span> To limit the "blast radius" of a compromised pod, restrict the use of the cluster-admin role and strictly prohibit wildcard (*) permissions for standard service accounts. Workloads must run under strict security contexts—blocking containers from executing as root, preventing privilege escalation, and restricting access to the underlying worker node (e.g., disabling hostPID and hostNetwork).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Implement Immutable Cluster Backups: </strong><span>Protect the cluster's state (etcd) and stateful workload data (Persistent Volumes) by utilizing immutable backup repositories. This ensures that even if an attacker gains administrative access to the cluster or CI/CD pipeline and attempts to maliciously delete all resources, the backups cannot be destroyed or altered.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Enable Audit Logging and Threat Detection: </strong><span>Ensure Kubernetes Control Plane audit logs, node-level telemetry, and CI/CD pipeline logs are actively forwarded to a centralized SIEM. Deploy dedicated container threat detection capabilities to immediately alert on malicious exec commands, suspicious Kubernetes enumeration tools, or bulk data deletion attempts within the pods.</span></p>
</li>
</ul>
<p><span>Additional information related to <a href="https://owasp.org/www-project-kubernetes-top-ten/" rel="noopener" target="_blank">securing Kubernetes</a>.</span></p>
<h4><span>Detection Opportunities for Kubernetes and CI/CD</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Use Case</strong></p>
</td>
<td>
<p><strong>MITRE ID</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Bulk Kubernetes Resource Deletion</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1485/" rel="noopener" target="_blank"><span>T1485 - Data Destruction</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes API audit logs for bulk delete operations targeting Deployments, StatefulSets, Persistent Volume Claims, Namespaces, or ConfigMaps.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unsigned or Modified Container Image Deployed to Cluster</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1525/" rel="noopener" target="_blank"><span>T1525 - Implant Internal Image</span></a></p>
</td>
<td>
<p><span>Monitor container registries and Kubernetes admission events for deployment of images that fail signature verification, lack provenance attestation, or originate from untrusted registries.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Anomalous Kubernetes Secret Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1552/007/" rel="noopener" target="_blank"><span>T1552.007 - Unsecured Credentials: Container API</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for API calls to </span><span>/api/v1/secrets</span><span> or </span><span>/api/v1/namespaces/*/secrets</span><span> from service accounts or users that do not normally access secrets. </span></p>
<p><span>Alert on bulk secret enumeration and on access to secrets in sensitive namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Unauthorized Modification to CI/CD Pipeline Configuration</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1195/002/" rel="noopener" target="_blank"><span>T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain</span></a></p>
</td>
<td>
<p><span>Monitor source code repositories for modifications to CI/CD pipeline configuration files. </span></p>
<p><span>Alert on changes to pipeline definitions made by accounts that are not members of designated pipeline-owner groups, or changes pushed code outside of an approved pull request/merge request workflow.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Privileged Container or Host Namespace Access</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1611/" rel="noopener" target="_blank"><span>T1611 - Escape to Host</span></a></p>
</td>
<td>
<p><span>Monitor Kubernetes audit logs for pod creation or modification events requesting privileged security contexts, host namespace access, or volume mounts to sensitive host paths. These configurations allow container escape and direct access to the underlying worker node. Alert on any workload requesting these capabilities outside or pre-approved system namespaces.</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Kubernetes Audit Logging or Security Agent Tampering</span></p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1562/007/" rel="noopener" target="_blank"><span>T1562.007 - Impair Defenses: Disable or Modify Cloud Firewall</span></a></p>
</td>
<td>
<p><span>Monitor for modifications to Kubernetes API server audit policy configurations, deletion or redirection of log export sinks, and disablement or removal of container runtime security agents. Alert on changes to cluster-level logging configurations in managed services (GKE Cloud Audit Logs, EKS Control Plane Logging, AKS Diagnostic Settings) including disablement of API server, authenticator, or scheduler log streams.</span></p>
</td>
</tr>
</tbody>
</table></div></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div align="left"><span>Table 31: Detection opportunities for Kubernetes and CI/CD</span></div></div>
<div class="block-paragraph_advanced"><h3><span>Conclusion</span></h3>
<p><span>Destructive attacks, including ransomware, pose a serious threat to organizations. This blog post provides practical </span><span>guidance on protecting against common techniques used by threat actors for initial access, reconnaissance, privilege escalation, and mission objectives. This blog post should not be considered as a comprehensive defensive guide for every tactic, but it can serve as a valuable resource for organizations to prepare for such attacks. It is based on front-line expertise with helping organizations prepare, contain, eradicate, and recover from potentially destructive threat actors and incidents.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys are Your New Best Friend]]></title>
<description><![CDATA[Find out more about how passkeys, which are designed to replace passwords, work and which advantages they bring.]]></description>
<link>https://tsecurity.de/de/3501411/it-security-nachrichten/passkeys-are-your-new-best-friend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501411/it-security-nachrichten/passkeys-are-your-new-best-friend/</guid>
<pubDate>Fri, 08 May 2026 23:19:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Find out more about how passkeys, which are designed to replace passwords, work and which advantages they bring.]]></content:encoded>
</item>
<item>
<title><![CDATA[5 helpful tools from Google to keep your accounts safe]]></title>
<description><![CDATA[Sign in securely and keep your account accessible with passkeys, Recovery Contacts, Sign in with Google, Password Manager and 2-Step Verification.]]></description>
<link>https://tsecurity.de/de/3496812/it-nachrichten/5-helpful-tools-from-google-to-keep-your-accounts-safe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496812/it-nachrichten/5-helpful-tools-from-google-to-keep-your-accounts-safe/</guid>
<pubDate>Thu, 07 May 2026 18:34:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Password_Security_hero_qnsqnEK.max-600x600.format-webp.webp">Sign in securely and keep your account accessible with passkeys, Recovery Contacts, Sign in with Google, Password Manager and 2-Step Verification.]]></content:encoded>
</item>
<item>
<title><![CDATA[World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough]]></title>
<description><![CDATA[World Password Day 2026 highlights the shift toward passkeys, passwordless authentication, and Zero Trust security.
The post World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3496530/it-security-nachrichten/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496530/it-security-nachrichten/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/</guid>
<pubDate>Thu, 07 May 2026 17:12:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>World Password Day 2026 highlights the shift toward passkeys, passwordless authentication, and Zero Trust security.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/">World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough</a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough]]></title>
<description><![CDATA[World Password Day 2026 highlights the shift toward passkeys, passwordless authentication, and Zero Trust security. The post World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough appeared first on eSecurity Planet. This article has been indexed from…
Read more →
The post World ...]]></description>
<link>https://tsecurity.de/de/3496513/it-security-nachrichten/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496513/it-security-nachrichten/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/</guid>
<pubDate>Thu, 07 May 2026 17:12:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>World Password Day 2026 highlights the shift toward passkeys, passwordless authentication, and Zero Trust security. The post World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough appeared first on eSecurity Planet. This article has been indexed from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/world-password-day-2026-why-strong-passwords-alone-are-no-longer-enough/">World Password Day 2026: Why Strong Passwords Alone Are No Longer Enough</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[World Password Day (7. Mai): Wie haltet ihr es mit Passkeys und Passwörtern? - BornCity]]></title>
<description><![CDATA[Er sagt: "Jedes Jahr am Weltpassworttag geben Anbieter für IT-Sicherheit dieselben Ratschläge: Längere Passwörter! ... European Cyber Security Blogger ...]]></description>
<link>https://tsecurity.de/de/3495750/it-security-nachrichten/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495750/it-security-nachrichten/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern-borncity/</guid>
<pubDate>Thu, 07 May 2026 13:24:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Er sagt: "Jedes Jahr am Weltpassworttag geben Anbieter für <b>IT</b>-<b>Sicherheit</b> dieselben Ratschläge: Längere Passwörter! ... European <b>Cyber Security</b> Blogger ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Welt-Passwort-Tag: Passkeys, Mehr-Faktor-Authentifizierung, alles ist besser | heise online]]></title>
<description><![CDATA[Da jedoch immer wieder Einbrüche in IT-Systeme und dabei abfließende Informationen wie Zugangsdaten stattfinden, sollte das Sicherheitskonzept sich ...]]></description>
<link>https://tsecurity.de/de/3495743/it-security-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3495743/it-security-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser-heise-online/</guid>
<pubDate>Thu, 07 May 2026 13:24:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Da jedoch immer wieder Einbrüche in <b>IT</b>-Systeme und dabei abfließende Informationen wie Zugangsdaten stattfinden, sollte das Sicherheitskonzept sich ...]]></content:encoded>
</item>
<item>
<title><![CDATA[World Password Day (7. Mai): Wie haltet ihr es mit Passkeys und Passwörtern?]]></title>
<description><![CDATA[Am heutigen 7. Mai ist World Password Day, an dem an die Bedeutung des Themas erinnert werden soll. In diesem Kontext sind mir einige Meldungen zugegangen, die ich als Abriss im Beitrag spiegele. Ich verbinde es mit der Frage, wie … Weiterlesen →
Quelle]]></description>
<link>https://tsecurity.de/de/3494836/it-nachrichten/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494836/it-nachrichten/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern/</guid>
<pubDate>Thu, 07 May 2026 08:18:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Am heutigen 7. Mai ist World Password Day, an dem an die Bedeutung des Themas erinnert werden soll. In diesem Kontext sind mir einige Meldungen zugegangen, die ich als Abriss im Beitrag spiegele. Ich verbinde es mit der Frage, wie … <a href="https://borncity.com/blog/2026/05/07/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/05/07/world-password-day-7-mai-wie-haltet-ihr-es-mit-passkeys-und-passwoertern/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Welt-Passwort-Tag: Passkeys, Mehr-Faktor-Authentifizierung, alles ist besser]]></title>
<description><![CDATA[Jeden ersten Donnerstag im Mai ist der Welt-Passwort-Tag. Zeit, sich um bessere Sicherheit zu kümmern.]]></description>
<link>https://tsecurity.de/de/3494759/it-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494759/it-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser/</guid>
<pubDate>Thu, 07 May 2026 07:47:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jeden ersten Donnerstag im Mai ist der Welt-Passwort-Tag. Zeit, sich um bessere Sicherheit zu kümmern.]]></content:encoded>
</item>
<item>
<title><![CDATA[Welt-Passwort-Tag: Passkeys, Mehr-Faktor-Authentifizierung, alles ist besser]]></title>
<description><![CDATA[Jeden ersten Donnerstag im Mai ist der Welt-Passwort-Tag. Zeit, sich um bessere Sicherheit zu kümmern.]]></description>
<link>https://tsecurity.de/de/3494737/it-security-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3494737/it-security-nachrichten/welt-passwort-tag-passkeys-mehr-faktor-authentifizierung-alles-ist-besser/</guid>
<pubDate>Thu, 07 May 2026 07:36:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jeden ersten Donnerstag im Mai ist der Welt-Passwort-Tag. Zeit, sich um bessere Sicherheit zu kümmern.]]></content:encoded>
</item>
<item>
<title><![CDATA[World Passkey Day 2026 : Warum Passkeys zur wichtigen Waffe gegen KI-Hacker werden]]></title>
<description><![CDATA[Mit der zunehmenden Integration autonomer KI-Agenten verändert sich auch die Identitätssicherheit grundlegend. Unternehmen benötigen künftig eine ...]]></description>
<link>https://tsecurity.de/de/3493025/hacking/world-passkey-day-2026-warum-passkeys-zur-wichtigen-waffe-gegen-ki-hacker-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3493025/hacking/world-passkey-day-2026-warum-passkeys-zur-wichtigen-waffe-gegen-ki-hacker-werden/</guid>
<pubDate>Wed, 06 May 2026 16:24:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit der zunehmenden Integration autonomer KI-Agenten verändert sich auch die Identitätssicherheit grundlegend. Unternehmen benötigen künftig eine ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Passwörter sind im Alltag oft unsicher: Was wirklich schützt]]></title>
<description><![CDATA[Viele halten ihre Passwörter für sicher, doch nutzen kaum moderne Schutzmethoden. Warum das ein echtes Risiko ist – und wie Experten zur Passwort-Zukunft stehen.

Tags: #Cyber Security | #Passkeys | #Passwort]]></description>
<link>https://tsecurity.de/de/3491508/it-security-nachrichten/passwoerter-sind-im-alltag-oft-unsicher-was-wirklich-schuetzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3491508/it-security-nachrichten/passwoerter-sind-im-alltag-oft-unsicher-was-wirklich-schuetzt/</guid>
<pubDate>Wed, 06 May 2026 07:53:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549.jpg" class="attachment-full size-full wp-post-image" alt="Passwort-Manager" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/12/Passwort-Manager_Bildquelle_OpturaDesign_shutterstock_1196341549-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Passwörter sind im Alltag oft unsicher: Was wirklich schützt 3"></p>
    Viele halten ihre Passwörter für sicher, doch nutzen kaum moderne Schutzmethoden. Warum das ein echtes Risiko ist – und wie Experten zur Passwort-Zukunft stehen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/passkeys-en">#Passkeys</a> | <a href="https://www.it-daily.net/thema/passwort">#Passwort</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT advanced account security adds passkeys and hardware keys]]></title>
<description><![CDATA[Journalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips password-based sig...]]></description>
<link>https://tsecurity.de/de/3484506/it-security-nachrichten/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484506/it-security-nachrichten/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/</guid>
<pubDate>Mon, 04 May 2026 00:37:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Journalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips password-based sign-in from ChatGPT and Codex accounts and replaces it with passkeys or physical security keys. What enrollment changes Enrolled accounts use passkeys or hardware security keys for sign-in, with password login disabled. Email and SMS account recovery are removed, … <a href="https://www.helpnetsecurity.com/2026/05/04/openai-chatgpt-advanced-account-security/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/04/openai-chatgpt-advanced-account-security/">ChatGPT advanced account security adds passkeys and hardware keys</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT advanced account security adds passkeys and hardware keys]]></title>
<description><![CDATA[Journalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips password-based sig...]]></description>
<link>https://tsecurity.de/de/3484503/it-security-nachrichten/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3484503/it-security-nachrichten/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/</guid>
<pubDate>Mon, 04 May 2026 00:36:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Journalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips password-based sign-in from ChatGPT and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/chatgpt-advanced-account-security-adds-passkeys-and-hardware-keys/">ChatGPT advanced account security adds passkeys and hardware keys</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Introduces Password-Free Login for Millions of ChatGPT Users]]></title>
<description><![CDATA[OpenAI’s Advanced Account Security lets ChatGPT and Codex users replace passwords with passkeys or security keys, but recovery is limited. The post OpenAI Introduces Password-Free Login for Millions of ChatGPT Users appeared first on TechRepublic. This article has been indexed…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3480778/it-security-nachrichten/openai-introduces-password-free-login-for-millions-of-chatgpt-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480778/it-security-nachrichten/openai-introduces-password-free-login-for-millions-of-chatgpt-users/</guid>
<pubDate>Fri, 01 May 2026 18:06:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI’s Advanced Account Security lets ChatGPT and Codex users replace passwords with passkeys or security keys, but recovery is limited. The post OpenAI Introduces Password-Free Login for Millions of ChatGPT Users appeared first on TechRepublic. This article has been indexed…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openai-introduces-password-free-login-for-millions-of-chatgpt-users/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openai-introduces-password-free-login-for-millions-of-chatgpt-users/">OpenAI Introduces Password-Free Login for Millions of ChatGPT Users</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Introduces Password-Free Login for Millions of ChatGPT Users]]></title>
<description><![CDATA[OpenAI’s Advanced Account Security lets ChatGPT and Codex users replace passwords with passkeys or security keys, but recovery is limited.
The post OpenAI Introduces Password-Free Login for Millions of ChatGPT Users appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3480745/it-security-nachrichten/openai-introduces-password-free-login-for-millions-of-chatgpt-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480745/it-security-nachrichten/openai-introduces-password-free-login-for-millions-of-chatgpt-users/</guid>
<pubDate>Fri, 01 May 2026 17:51:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI’s Advanced Account Security lets ChatGPT and Codex users replace passwords with passkeys or security keys, but recovery is limited.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-openai-chatgpt-advanced-account-security-passkeys/">OpenAI Introduces Password-Free Login for Millions of ChatGPT Users</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hören Sie auf, Passwörter zu verwenden und nutzen Sie die klar bessere Alternative]]></title>
<description><![CDATA[Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für das Ersetzen. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys (Passkeys: So funktioniert das passwortlose Login-Verfahren).



Pas...]]></description>
<link>https://tsecurity.de/de/3477421/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-die-klar-bessere-alternative/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477421/it-nachrichten/hoeren-sie-auf-passwoerter-zu-verwenden-und-nutzen-sie-die-klar-bessere-alternative/</guid>
<pubDate>Thu, 30 Apr 2026 13:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Passwörter sind nervig und in vielen Fällen unsicher. Aber zum Teufel mit dem Aktualisieren und Verbessern der Passwörter. Entscheiden Sie sich lieber für <em>das Ersetzen</em>. Genauer gesagt: Ersetzen Sie Ihre Passwörter durch Passkeys (<a href="https://www.pcwelt.de/article/2107907/passkeys-einloggen-ohne-passwoerter.html" target="_blank" rel="noreferrer noopener">Passkeys: So funktioniert das passwortlose Login-Verfahren</a>).</p>



<p>Passkeys müssen nicht auswendig gelernt werden, können direkt auf Ihrem Smartphone gespeichert werden <em>und</em> sind sicherer als Passwörter. Ein besonderer Vorteil: Sie sind Phishing-resistent. Außerdem sollten Ihre Anmeldedaten, falls eine Website gehackt wird (was heutzutage nur allzu häufig vorkommt), weder knackbar noch für andere nutzbar sein.</p>



<p>Wenn Sie einen Passkey erstellen, werden sowohl ein öffentlicher als auch ein privater Schlüssel generiert. (Dies wird als Public-Key- oder asymmetrische Verschlüsselung bezeichnet.) Der private Schlüssel wird von Ihrem Gerät oder <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> verwahrt. Zu den unterstützten Geräten gehören Smartphones, Tablets, Hardware-Dongles wie <a href="https://www.yubico.com/products/">YubiKeys</a> und kompatible PCs. Sie können wählen, ob Sie Passkeys lokal auf Ihrem Gerät oder in der Cloud speichern möchten.</p>



<p>Diese geheimen Schlüssel werden durch die biometrische Authentifizierung Ihres Geräts (z. B. Fingerabdruck oder Gesicht) oder durch die Methode gesichert, die Ihren Passwort-Manager schützt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f340c9376b0"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2023/07/PXL_20230727_210728297-1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="YubiKey 5 on a light gray tabletop" class="wp-image-2010995" width="1200" height="800" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Hardware-Sicherheitsschlüssel wie YubiKeys können Passkeys speichern und gleichzeitig als Methode für die Zwei-Faktor-Authentifizierung dienen.</figcaption></figure><p class="imageCredit">Alaina Yee / Foundry</p></div>



<p>Der öffentliche Schlüssel wird hingegen an die Website weitergegeben, für die er generiert wurde. Sie benötigen sowohl den öffentlichen als auch den privaten Schlüssel, um sich bei dem Konto anzumelden, mit dem sie verknüpft sind. Bei jeder Anmeldung fordert die Website über die folgenden Schritte einen Nachweis an, dass Sie der Kontoinhaber sind:</p>



<ol class="wp-block-list">
<li>Eine Anfrage wird an Ihr Gerät (oder Ihren Passwort-Manager) gesendet, um den Verifizierungsprozess zu starten.</li>



<li>Ihr Fingerabdruck, ein Gesichtsscan oder eine andere Authentifizierungsmethode ist erforderlich, um die Anfrage zu autorisieren.</li>



<li>Wenn Sie zustimmen, wird Ihr privater Schlüssel (auch bekannt als geheimer Schlüssel) verwendet, um eine digitale Signatur zu erstellen, die dann an die Website gesendet wird.</li>



<li>Die Website verwendet die digitale Signatur dann, um zu versuchen, den von Ihnen angegebenen öffentlichen Schlüssel zu entschlüsseln. Ist dies erfolgreich, haben Sie Zugriff.</li>
</ol>



<p>Wenn Passkeys korrekt implementiert sind, kann niemand Ihren privaten Schlüssel anhand des öffentlichen Schlüssels ableiten – was bedeutet, dass Datenlecks und Sicherheitsverletzungen nicht so gefährlich sind. (Zumindest was die Sicherheit von Passwörtern angeht.) Passkeys funktionieren zudem nur für die spezifische Website, für die sie generiert wurden, sodass sie nicht von gefälschten, bösartigen Websites erfasst oder verwendet werden können – genau so stehlen Phishing-Betrüger normalerweise Passwörter.</p>



<p>Der einzige wirkliche Haken bei Passkeys besteht darin, dass Sie sie lokal auf einem Gerät speichern – wenn Sie das Gerät verlieren, könnten Sie aus Ihrem Konto ausgesperrt werden. Dies geschieht jedoch nur, wenn Sie sich bewusst dafür entscheiden, einen Passkey lokal zu speichern, beispielsweise auf einem Windows-PC mit einem rein lokalen Konto (was heutzutage selten ist) oder auf einem YubiKey. Sie können solche Probleme leicht vermeiden, indem Sie ein zweites Gerät oder einen Hardware-Sicherheitsschlüssel nutzen und/oder Ihrem Konto als Backup ein extrem sicheres Passwort sowie eine Zwei-Faktor-Authentifizierung (<a href="https://www.pcwelt.de/article/1206889/zwei-faktor-authentifizierung-alles-was-sie-wissen-muessen.html" target="_blank" rel="noreferrer noopener">Zwei-Faktor-Authentifizierung: Alles, was Sie wissen müssen</a>) hinzufügen.</p>



<p>Diese letzte Option macht Passwörter zwar nicht vollständig überflüssig, bringt Sie aber zumindest für den Alltag schon ein gutes Stück weiter. Ich persönlich finde das Einloggen mit einem Passkey schneller als mit Passwörtern, selbst wenn ich einen Passwort-Manager mit automatischer Ausfüllfunktion verwende. </p>



<p>Wenn Ihnen der Umstieg wie eine große Aufgabe erscheint, beginnen Sie zunächst mit den großen Diensten wie Google, Apple und Microsoft sowie mit großen Online-Shops wie Amazon. Die Umstellung Ihrer am häufigsten genutzten Apps und Websites sowie aller Dienste, die mit sensiblen Informationen (einschließlich Rechnungsdaten) umgehen, macht Ihr Online-Leben bereits sicherer und bequemer.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hybrid Authentication Environments]]></title>
<description><![CDATA[Reduce credential risk in hybrid authentication environments by securing the password layer that remains alongside passkeys. The post Hybrid Authentication Environments appeared first on Security Boulevard. This article has been indexed from Security Boulevard Read the original article: Hybrid Au...]]></description>
<link>https://tsecurity.de/de/3474585/it-security-nachrichten/hybrid-authentication-environments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474585/it-security-nachrichten/hybrid-authentication-environments/</guid>
<pubDate>Wed, 29 Apr 2026 15:23:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Reduce credential risk in hybrid authentication environments by securing the password layer that remains alongside passkeys. The post Hybrid Authentication Environments appeared first on Security Boulevard. This article has been indexed from Security Boulevard Read the original article: Hybrid Authentication…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hybrid-authentication-environments/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hybrid-authentication-environments/">Hybrid Authentication Environments</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows als Schlüssel: Entra Passkeys kommen - IT-Administrator.de]]></title>
<description><![CDATA[Die Verfügbarkeit schließt eine wichtige Lücke im passwortlosen Portfolio von Microsoft: Während Hardware-Sicherheitsschlüssel und Microsoft ...]]></description>
<link>https://tsecurity.de/de/3471612/it-security-nachrichten/windows-als-schluessel-entra-passkeys-kommen-it-administratorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471612/it-security-nachrichten/windows-als-schluessel-entra-passkeys-kommen-it-administratorde/</guid>
<pubDate>Tue, 28 Apr 2026 16:39:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Verfügbarkeit schließt eine wichtige Lücke im passwortlosen Portfolio von Microsoft: Während Hardware-Sicherheitsschlüssel und Microsoft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[WhatsApp arbeitet an eigenem Cloud-Speicher für Chat-Backups]]></title>
<description><![CDATA[WhatsApp entwickelt einen hauseigenen Cloud-Dienst für Chat-Backups. Nutzer sollen ihre Sicherungen künftig nicht nur auf iCloud bzw. Google Drive ablegen können, sondern wahlweise auch auf WhatsApp-Servern, wobei die Backups standardmäßig Ende-zu-Ende-verschlüsselt sind. Das geht aus Hinweisen i...]]></description>
<link>https://tsecurity.de/de/3471193/ios-mac-os/whatsapp-arbeitet-an-eigenem-cloud-speicher-fuer-chat-backups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471193/ios-mac-os/whatsapp-arbeitet-an-eigenem-cloud-speicher-fuer-chat-backups/</guid>
<pubDate>Tue, 28 Apr 2026 14:26:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WhatsApp entwickelt einen hauseigenen Cloud-Dienst für Chat-Backups. Nutzer sollen ihre Sicherungen künftig nicht nur auf iCloud bzw. Google Drive ablegen können, sondern wahlweise auch auf WhatsApp-Servern, wobei die Backups standardmäßig Ende-zu-Ende-verschlüsselt sind. Das geht aus Hinweisen in der aktuellen Beta-Version 2.25.24.15 für Android hervor, die WABetaInfo entdeckt hat. Passkeys als Standardverschlüsselung Bereits in einer früheren […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows als Schlüssel: Entra Passkeys kommen | IT-Administrator Magazin]]></title>
<description><![CDATA[Manfred Helber erklärt anhand von drei Beispiel-Workloads (Small, Medium, Large), welche Kriterien bei der Serverauswahl entscheidend sind – von ...]]></description>
<link>https://tsecurity.de/de/3470597/windows-server/windows-als-schluessel-entra-passkeys-kommen-it-administrator-magazin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470597/windows-server/windows-als-schluessel-entra-passkeys-kommen-it-administrator-magazin/</guid>
<pubDate>Tue, 28 Apr 2026 11:30:29 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Manfred Helber erklärt anhand von drei Beispiel-Workloads (Small, Medium, Large), welche Kriterien bei der Serverauswahl entscheidend sind – von ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Stopping AiTM attacks: The defenses that actually work after authentication succeeds]]></title>
<description><![CDATA[The security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely.



Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits between the user ...]]></description>
<link>https://tsecurity.de/de/3470528/it-security-nachrichten/stopping-aitm-attacks-the-defenses-that-actually-work-after-authentication-succeeds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470528/it-security-nachrichten/stopping-aitm-attacks-the-defenses-that-actually-work-after-authentication-succeeds/</guid>
<pubDate>Tue, 28 Apr 2026 11:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The security industry has spent years building better authentication. Longer passwords, second factors, hardware tokens. And attackers responded by moving past authentication entirely.</p>



<p>Adversary-in-the-middle (AiTM) phishing does not steal credentials and replay them. It sits between the user and the legitimate service, watches a real authentication succeed in real time, and walks away with the session token that proves it happened. The login was genuine. The MFA prompt was real. The attacker just observed — and copied the result.</p>



<p>If you have read<a href="https://www.csoonline.com/article/4147134/your-mfa-isnt-broken-its-being-bypassed-and-your-employees-cant-tell-the-difference.html"> the analysis of how these attacks work</a>, you understand the mechanism. This piece is about what comes after that understanding. Specifically: What controls reduce risk when the attack does not touch credentials at all?</p>



<h2 class="wp-block-heading"><a></a>Why most current defenses miss the point</h2>



<p>The instinct after learning about AiTM phishing is to strengthen authentication. Buy hardware keys. Deploy passkeys. Force phishing-resistant MFA for privileged accounts.</p>



<p>That instinct is correct but incomplete.</p>



<p>Phishing-resistant authentication stops the credential theft phase. FIDO2 and passkeys bind the authentication challenge cryptographically to the legitimate domain, so a proxy domain cannot complete the handshake. This works. Organizations that have deployed passkeys broadly have significantly reduced their AiTM exposure at the authentication layer.</p>



<p>But authentication is not the only layer that matters. Session tokens issued after successful authentication are the real target, and most organizations treat them as inherently trustworthy once issued. They are not.</p>



<p>A session cookie is a bearer token. Whoever holds it is authenticated. There is no cryptographic binding between the token and the device that generated it, no ongoing proof that the holder is who they claim to be, and no automatic expiry triggered by location change or device mismatch. An attacker who steals a session token in one country can replay it from another, and the identity provider will accept it as legitimate.</p>



<p>This is where most defenses currently have a gap.</p>



<h2 class="wp-block-heading"><a></a>The 3 controls that close the gap</h2>



<h3 class="wp-block-heading"><a></a>Control #1: Bind sessions to managed devices</h3>



<p>The most impactful single control for session security is requiring managed, compliant devices as a condition of accessing sensitive resources. When access policies —<a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview"> </a><a href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview">such as Microsoft Entra Conditional Access</a> — require that the device presenting a session token is enrolled, managed and meets compliance requirements, stolen tokens become significantly harder to replay.</p>



<p>An attacker who intercepts a session token cannot easily replay it from an unmanaged machine if the policy requires device compliance. The session gets terminated. The attacker needs not just the token but also a compliant device — a much higher bar.</p>



<p>This control is not foolproof. Sophisticated attackers can attempt to compromise managed devices directly. But it eliminates the easiest replay vector: Taking a stolen token and opening it in a browser on a completely different machine.</p>



<p>The practical challenge is rollout. Requiring managed devices for all users immediately creates friction for contractors, part-time workers and anyone using personal devices for work. The pragmatic approach is to start with the highest-risk access: Administrative roles, finance systems and any application handling sensitive data. Expand from there as device management coverage improves.</p>



<h3 class="wp-block-heading"><a></a>Control #2: Monitor for post-authentication anomalies</h3>



<p>AiTM attacks do not generate failed login attempts. They generate successful ones. Traditional monitoring focused on authentication failures will miss these attacks entirely.</p>



<p>The signals that matter are in what happens after authentication succeeds. Specifically:</p>



<ul class="wp-block-list">
<li><strong>Impossible travel.</strong> If a session authenticates from one location and then accesses resources from a geographically distant location minutes later, that warrants investigation. The time between events matters — a session that authenticates in New York and then accesses resources from a different continent thirty minutes later is not a normal user scenario.</li>



<li><strong>New device registration.</strong> Attackers who gain session access often immediately register a new MFA device or add a new authentication method to ensure persistent access. A new device registration occurring within minutes of a successful login is a high-fidelity signal worth alerting on.</li>



<li><strong>Inbox rule creation.</strong> A consistent post-compromise behavior across many attack campaigns is the creation of email forwarding rules or inbox filters designed to hide security alerts and forward communications to attacker-controlled addresses.<a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/"> </a><a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/malicious-oauth-applications-used-to-compromise-email-servers-and-spread-spam/">Microsoft’s own incident response teams have documented this pattern</a> repeatedly. Monitoring for inbox rule creation, particularly rules that forward externally or hide emails containing specific keywords, catches this behavior reliably.</li>



<li><strong>Privilege escalation attempts.</strong> Attackers who gain access to a standard user account typically attempt to escalate to higher-privilege roles or access administrative interfaces. Anomalous access attempts against admin portals or privilege management systems shortly after a new session authentication are worth flagging.</li>
</ul>



<p>None of these signals is conclusive on its own. But building detection rules around the combination — successful authentication followed by impossible travel followed by new device registration, for example — creates a detection capability that catches AiTM post-compromise activity that authentication monitoring misses entirely.</p>



<h3 class="wp-block-heading"><a></a>Control #3: Shorten session lifetimes for high-value access</h3>



<p>Long-lived session tokens give attackers more time to operate after a successful interception. A token that remains valid for seven days provides a much larger window than one that expires after an hour and requires reauthentication.</p>



<p>The friction of more frequent reauthentication is real. Users notice. For productivity applications used continuously throughout the day, aggressive session timeouts create a poor experience.</p>



<p>The answer is risk-based session management rather than uniform policies. Sessions accessing low-sensitivity productivity tools can have longer lifetimes. Sessions accessing financial systems, administrative interfaces, HR data or anything handling regulated information should have short lifetimes and require reauthentication before performing sensitive operations.<a href="https://pages.nist.gov/800-63-3/sp800-63b.html"> </a><a href="https://pages.nist.gov/800-63-3/sp800-63b.html">NIST’s Digital Identity Guidelines</a> provide a useful framework for thinking about session timeout thresholds by assurance level.</p>



<p>This approach concentrates the friction where the risk is highest, which makes it more defensible to users and leadership alike.</p>



<h2 class="wp-block-heading"><a></a>The training problem has not gone away</h2>



<p>Technical controls reduce risk. They do not eliminate it. Users remain part of the attack surface, and the awareness training most organizations provide does not prepare them for what AiTM phishing looks like.</p>



<p>Traditional phishing training teaches people to look for indicators of fake pages: Misspellings, suspicious URLs, unusual sender addresses. AiTM phishing pages show none of these indicators because they are not fake. They proxy the real service in real time. The URL may be suspicious, but users who click links in emails rarely check URLs carefully, even after training.</p>



<p>The one behavioral change that reduces AiTM exposure is simple and teachable: Do not start authentication flows from links in emails. Navigate directly to the service. Bookmark login pages. If you receive an email telling you to log in somewhere, open a browser tab and type the address yourself rather than clicking through.</p>



<p>This sounds obvious. It is not instinctive. Most users have spent years clicking login links in emails because it is faster and those links usually are legitimate. Changing that behavior requires explicit, repeated training that explains why the old approach is no longer safe — not just instruction to be more suspicious of phishing generally.</p>



<p>Pair this with a low-friction reporting mechanism. Users who notice something feels wrong should be able to flag it in seconds. The value of early reporting in limiting the damage from a successful session compromise is significant, and that value disappears if reporting requires effort or feels like it will generate blame rather than action.</p>



<h2 class="wp-block-heading"><a></a>The honest assessment</h2>



<p>AiTM phishing is a real and growing threat.<a href="https://www.microsoft.com/en-us/security/blog/2025/03/03/phishing-platform-tycoon-2fa-continues-to-be-a-significant-aitm-threat/"> </a><a href="https://www.microsoft.com/en-us/security/blog/2025/03/03/phishing-platform-tycoon-2fa-continues-to-be-a-significant-aitm-threat/">Phishing-as-a-Service platforms like Tycoon 2FA and FlowerStorm</a> have lowered the barrier to entry to the point where this is no longer an advanced technique requiring sophisticated threat actors. It is a commodity attack available to anyone willing to pay a subscription.</p>



<p>The organizations that reduce their exposure are those that treat session security as seriously as credential security, build detection capability around post-authentication behavior rather than just failed logins, and give users a realistic model of how modern phishing works.</p>



<p>Phishing-resistant authentication is the right long-term direction. Getting there takes time, budget and change management. In the meantime, the controls above provide meaningful risk reduction without waiting for full passkey deployment.</p>



<p>The goal is not to make AiTM attacks impossible. It is to make them expensive enough that attackers move on to easier targets.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows als Schlüssel: Entra Passkeys kommen]]></title>
<description><![CDATA[Windows als Schlüssel: Entra Passkeys kommen

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Di., 28.04.2026 - 07:00


            Passwörter haben in modernen Unternehmensumgebungen ausgedient - und Microsof...]]></description>
<link>https://tsecurity.de/de/3470385/server/windows-als-schluessel-entra-passkeys-kommen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470385/server/windows-als-schluessel-entra-passkeys-kommen/</guid>
<pubDate>Tue, 28 Apr 2026 10:15:24 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Windows als Schlüssel: Entra Passkeys kommen</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/microsoft-windows-entra-passkeys-rollout"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/7809554_m.jpg?itok=WTLdHeRO" width="480" height="319" alt="Eine Hand hält einen Schlüsselbund mit mehreren Schlüsseln und übergibt ihn an eine andere, geöffnete Hand." title="Phishing-resistent und ohne Passwort: Microsoft rollt Entra Passkeys für Windows aus. (Quelle: torring - 123RF)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-04-28T07:00:00+02:00" title="Dienstag, April 28, 2026 - 07:00" class="datetime">Di., 28.04.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Passwörter haben in modernen Unternehmensumgebungen ausgedient - und Microsoft macht jetzt Ernst: Ab Ende April 2026 können sich Nutzer an Windows-Geräten phishing-resistent per Fingerabdruck, Gesicht oder PIN anmelden, ohne dass IT-Abteilungen vorher Hand anlegen müssen.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/microsoft-windows-entra-passkeys-rollout" rel="tag" title="Windows als Schlüssel: Entra Passkeys kommen" hreflang="en">Weiterlesen<span class="visually-hidden"> über Windows als Schlüssel: Entra Passkeys kommen</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[英 NCSC, 기업에 패스키 전환 촉구 “피싱 공격 차단에 효과적”]]></title>
<description><![CDATA[영국 국가 사이버보안센터(NCSC)가 기업이 소비자에게 제공하는 기본 인증 방식으로 패스키를 채택할 것을 권고했다. 산업 전반의 기술 발전으로 패스키가 비밀번호보다 더 안전하면서도 사용자 친화적인 대안으로 자리 잡았다는 판단에서다.



NCSC는 23일 블로그를 통해 “이제 패스키를 개인과 기업 모두를 위한 주요 인증 수단으로 권장할 수 있는 수준에 도달했다”고 밝혔다. 이어 “패스키는 소비자의 첫 번째 로그인 선택지가 되어야 한다”며 “비밀번호는 현대 환경에서 더 이상 충분한 복원력을 갖추지 못했다”고 지적했다.



또 ...]]></description>
<link>https://tsecurity.de/de/3467334/it-nachrichten/ncsc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3467334/it-nachrichten/ncsc/</guid>
<pubDate>Mon, 27 Apr 2026 10:30:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>영국 국가 사이버보안센터(NCSC)가 기업이 소비자에게 제공하는 기본 인증 방식으로 패스키를 채택할 것을 권고했다. 산업 전반의 기술 발전으로 패스키가 비밀번호보다 더 안전하면서도 사용자 친화적인 대안으로 자리 잡았다는 판단에서다.</p>



<p>NCSC는 23일 <a href="https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future" target="_blank" rel="nofollow">블로그를 통해</a> “이제 패스키를 개인과 기업 모두를 위한 주요 인증 수단으로 권장할 수 있는 수준에 도달했다”고 밝혔다. 이어 “패스키는 소비자의 첫 번째 로그인 선택지가 되어야 한다”며 “비밀번호는 현대 환경에서 더 이상 충분한 복원력을 갖추지 못했다”고 지적했다.</p>



<p>또 “패스키는 온라인 계정 로그인 방식의 새로운 형태로, 사용자가 비밀번호를 입력하는 대신 승인만 하면 되도록 대부분의 과정을 자동 처리한다”며 “이로 인해 더 빠르고 간편하게 사용할 수 있고, 사이버 공격자가 침해하기도 훨씬 어렵다”고 설명했다.</p>



<p>NCSC는 패스키를 지원하는 모든 환경에서 이를 적극 활용해야 한다고 강조하며, 패스키가 피싱 공격에 강하고 비밀번호 재사용으로 인한 위험을 제거한다고 밝혔다.</p>



<h2 class="wp-block-heading">피싱에 강한 인증 방식에 초점</h2>



<p>이번 가이드라인은 실제 공격 환경에서 인증 방식이 어떻게 작동하는지를 분석한 결과를 기반으로 한다.</p>



<p>NCSC는 피싱, 자격증명 재사용, 세션 하이재킹 등 주요 공격 기법을 중심으로 인증 수단을 평가했으며, 자격증명이 생성·저장·사용되는 전 과정에서 어떻게 노출되는지를 종합적으로 분석했다고 밝혔다.</p>



<p>NCSC는 “패스키는 피싱 공격에 강하며 비밀번호 재사용에 따른 위험을 제거한다”고 재차 강조했다.</p>



<p>또한 별도의 <a href="https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use" target="_blank" rel="nofollow">기술 문서를 통해</a> 기존 인증 방식에 대해서도 평가를 내놨다. 비밀번호와 일회용 코드(OTP)를 결합한 방식조차 “본질적으로 피싱 공격에 취약하다”고 지적했다.</p>



<p>반면 FIDO2 기반 패스키는 “현실에서 발생하는 대부분의 자격증명 공격에 대해 기존 다중인증(MFA)과 동등하거나 그 이상의 보안 수준을 제공한다”고 분석했다.</p>



<p>다만 NCSC는 해당 분석이 기업 내부 인증 환경에 그대로 적용되는 것은 아니라고 설명했다. “이 문서의 상당 부분은 직원의 싱글사인온(SSO) 인증과 같은 기업 환경에도 적용될 수 있지만, 위협 모델과 사용 시나리오가 다르기 때문에 기업 리스크 평가를 위한 용도로 작성된 것은 아니다”라고 덧붙였다.</p>



<h2 class="wp-block-heading">공격 모델을 바꾸는 패스키</h2>



<p>NCSC는 패스키가 기존 인증 구조의 핵심 위험 요소인 ‘공유된 비밀(shared secret)’ 의존성을 제거함으로써 보안 위험을 낮춘다고 설명했다. 인증 정보를 특정 서비스에 강하게 결합하는 방식이기 때문에 공격자가 이를 가로채 재사용하는 것이 불가능하다는 것이다.</p>



<p>이에 따라 자격증명 재사용 공격이나 중계(릴레이) 공격을 원천적으로 차단할 수 있다. NCSC는 패스키가 사용자 기기에 저장된 암호화 키 쌍을 기반으로 작동하며, 생체인식이나 PIN과 같은 기기 기반 인증과 결합된다고 밝혔다.</p>



<h2 class="wp-block-heading">사용자 인증 방식의 구조적 전환</h2>



<p>이번 가이드라인은 고객 대상 온라인 서비스를 제공하는 기업들에게 사용자 인터페이스 수준의 인증 방식 변화를 요구하는 신호로 해석된다.</p>



<p>글로벌 시장조사업체 포레스터(Forrester)의 수석 애널리스트 마들레인 반 더 하우트는 “이번 변화는 점진적인 인증 업그레이드가 아니라 근본적인 아키텍처 전환”이라며 “비밀번호와 다중인증(MFA) 조합을 넘어, 피싱 저항성을 중심으로 한 새로운 인증 기반으로 이동하는 것”이라고 설명했다.</p>



<p>이어 “패스키는 공유된 비밀 대신 기기 기반 암호화 인증을 사용해 자격증명 탈취 위험을 제거한다”며 “이를 단순한 인증 수단 교체로 접근하면 투자 부족으로 이어질 수 있지만, 신원 관리 현대화 기회로 인식하면 경쟁력을 확보할 수 있다”고 덧붙였다.</p>



<p>NCSC는 기업이 인증 체계를 설계할 때 로그인뿐 아니라 계정 복구와 대체 인증 수단까지 포함한 전체 사용자 여정을 고려해야 한다고 강조했다. 패스키 도입으로 비밀번호 의존도는 줄어들지만, 비밀번호 재설정이나 계정 복구 절차가 취약할 경우 여전히 보안 위험이 발생할 수 있다는 지적이다.</p>



<h2 class="wp-block-heading">여전히 남아 있는 도입 과제</h2>



<p>NCSC는 패스키가 아직 모든 서비스에서 지원되는 것은 아니라고 밝혔다. 이에 따라 패스키를 사용할 수 없는 환경에서는 비밀번호 관리 도구와 다중인증을 병행할 것을 권장했다.</p>



<p>NCSC는 “특정 서비스가 패스키를 지원하지 않는 경우, 강력한 비밀번호를 생성할 수 있는 비밀번호 관리자를 활용하고 2단계 인증을 계속 사용하는 것이 바람직하다”고 설명했다.</p>



<p>반 더 하우트는 특히 다양한 플랫폼과 사용자 환경을 동시에 운영하는 기업에서 구현 난도가 높을 것으로 내다봤다. 그는 “레거시 시스템과 분산된 신원 관리 환경이 상당한 장애 요인으로 작용한다”고 분석했다.</p>



<p>또한 머신 계정 등 비인간 식별체에 대한 고려도 필요하다고 강조했다. “머신 아이덴티티 계층을 고려하지 않은 패스키 전략은 새로운 보안 공백을 만들 수 있다”고 말했다.</p>



<p>아울러 기기 요구사항과 계정 복구 절차 역시 패스키 도입 방식에 영향을 미칠 수 있다고 덧붙였다.</p>



<h2 class="wp-block-heading">전환기에는 ‘하이브리드 인증’ 불가피</h2>



<p>업계에서는 단기간 내 비밀번호를 완전히 대체하는 것은 현실적으로 어렵다는 분석이 나온다.</p>



<p>마들레인 반 더 하우트 포레스터 수석 애널리스트는 “향후 수년간은 패스키와 기존 인증 방식이 병행되는 하이브리드 모델이 지속될 것”이라며 “기업들은 패스키와 전통적인 인증 방식을 동시에 지원해야 할 것”이라고 전망했다.</p>



<p>이어 “이 기간 동안 기업은 다양한 로그인 옵션을 통합 관리해야 하며, 특히 대체 인증 수단이 전체 보안 수준을 약화시키지 않도록 설계하는 것이 중요하다”고 설명했다.</p>



<p>NCSC 역시 패스키를 사용할 수 없는 환경에서는 기존의 강력한 인증 체계를 유지할 것을 권고했다.</p>



<h2 class="wp-block-heading">비밀번호 없는 로그인 전환 가속</h2>



<p>이번 가이드라인은 소비자 인증 영역에서 비밀번호 의존도를 줄이려는 흐름을 더욱 강화하는 정책 신호로 해석된다.</p>



<p>반 더 하우트는 “이번 지침은 보안 책임자들이 벤더나 내부 이해관계자와의 논의에서 보다 강한 추진력을 확보할 수 있게 한다”고 평가했다.</p>



<p>NCSC는 “피싱 저항성을 갖춘 인증 방식으로 전환할 경우, 특히 사용자 로그인 정보에 의존하는 서비스에서 주요 사이버 침해 원인을 크게 줄일 수 있다”고 강조했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChromeOS: Sicherheitsupdate-Pflicht und Abschied vom Passwort - BornCity]]></title>
<description><![CDATA[Google schließt vierte Sicherheitslücke des Jahres – während die britische Cybersicherheitsbehörde den Umstieg auf Passkeys empfiehlt.]]></description>
<link>https://tsecurity.de/de/3464370/it-security-nachrichten/chromeos-sicherheitsupdate-pflicht-und-abschied-vom-passwort-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3464370/it-security-nachrichten/chromeos-sicherheitsupdate-pflicht-und-abschied-vom-passwort-borncity/</guid>
<pubDate>Sat, 25 Apr 2026 18:19:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google schließt vierte Sicherheitslücke des Jahres – während die britische Cybersicherheitsbehörde den Umstieg auf Passkeys empfiehlt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft wird Entra-Passkeys unter Windows einführen]]></title>
<description><![CDATA[Microsoft macht Windows ein Stück passwortloser: Entra-Passkeys bringen ab Ende April phishingsichere Logins per Gesicht, Finger­abdruck oder PIN auf deutlich mehr Geräte - auch außerhalb klassischer Firmenrechner.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3463849/it-security-nachrichten/microsoft-wird-entra-passkeys-unter-windows-einfuehren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463849/it-security-nachrichten/microsoft-wird-entra-passkeys-unter-windows-einfuehren/</guid>
<pubDate>Sat, 25 Apr 2026 12:36:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,158317.html"><img hspace="5" border="0" align="left" alt="Sicherheit, Sicherheitslücke, Hacker, Security, Malware, Angriff, Hack, Kriminalität, Linux, Server, Virus, Verschlüsselung, Schadsoftware, Cybersecurity, Exploit, Cybercrime, Hacking, Hackerangriff, Ransomware, Börse, Internetkriminalität, Erpressung, Darknet, Aktie, Hacker Angriff, Aktien, Hacker Angriffe, Hacken, Attack, Aktienkurs, Ransom, Hacks, Kurs, Crime, Cyberangriff, Schlüssel, schloss, Russische Hacker, Gehackt, Schädling, Cyberwar, China Hacker, Shell, Cyberattacke, Verschlüsselungs Software, Verschlüsselt, Auslastung, Top" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/38823.jpg"></a>
			Microsoft macht Windows ein Stück passwortloser: Entra-Passkeys bringen ab Ende April phishingsichere Logins per Gesicht, Finger­abdruck oder PIN auf deutlich mehr Geräte - auch außerhalb klassischer Firmenrechner.			(<a href="https://winfuture.de/news,158317.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[What is a passkey, how does it work and why is it better than a password?]]></title>
<description><![CDATA[Login method for apps and websites stored on users’ devices provides stronger security and is resistant to phishing and breachesThe UK’s National Cyber Security Centre has called time on the password – from now on, you should use a passkey.The NCSC said this week it would no longer recommend usin...]]></description>
<link>https://tsecurity.de/de/3463637/it-nachrichten/what-is-a-passkey-how-does-it-work-and-why-is-it-better-than-a-password/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3463637/it-nachrichten/what-is-a-passkey-how-does-it-work-and-why-is-it-better-than-a-password/</guid>
<pubDate>Sat, 25 Apr 2026 10:31:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Login method for apps and websites stored on users’ devices provides stronger security and is resistant to phishing and breaches</p><p>The UK’s National Cyber Security Centre has called time on the password – from now on, you should use a passkey.</p><p>The NCSC said this week it would no longer recommend using passwords where passkeys were available. They should be consumers’ first choice of login across all digital services because passwords were not secure enough to stand up to modern cyber threats.</p> <a href="https://www.theguardian.com/technology/2026/apr/24/what-is-a-passkey-how-does-it-work-and-why-is-it-better-than-a-password">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Users advised to drop passwords and make room for passkeys]]></title>
<description><![CDATA[In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. “Passkeys should become consumers’ first choice for logging into digital servi...]]></description>
<link>https://tsecurity.de/de/3462670/it-security-nachrichten/users-advised-to-drop-passwords-and-make-room-for-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462670/it-security-nachrichten/users-advised-to-drop-passwords-and-make-room-for-passkeys/</guid>
<pubDate>Fri, 24 Apr 2026 22:37:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. “Passkeys should become consumers’ first choice for logging into digital services,” NCSC said. Overhauling decades of security guidance, the agency will no longer recommend passwords where passkeys are available, citing their weaker resistance to current cyber threats. Since most breaches … <a href="https://www.helpnetsecurity.com/2026/04/24/ncsc-passkey-adoption-cybersecurity/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/04/24/ncsc-passkey-adoption-cybersecurity/">Users advised to drop passwords and make room for passkeys</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Users advised to drop passwords and make room for passkeys]]></title>
<description><![CDATA[In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. “Passkeys should become consumers’ first…
Read more →
The post Users advised t...]]></description>
<link>https://tsecurity.de/de/3462666/it-security-nachrichten/users-advised-to-drop-passwords-and-make-room-for-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462666/it-security-nachrichten/users-advised-to-drop-passwords-and-make-room-for-passkeys/</guid>
<pubDate>Fri, 24 Apr 2026 22:37:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. “Passkeys should become consumers’ first…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/users-advised-to-drop-passwords-and-make-room-for-passkeys/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/users-advised-to-drop-passwords-and-make-room-for-passkeys/">Users advised to drop passwords and make room for passkeys</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft to roll out Entra passkeys on Windows in late April]]></title>
<description><![CDATA[Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. [...]]]></description>
<link>https://tsecurity.de/de/3462423/it-security-nachrichten/microsoft-to-roll-out-entra-passkeys-on-windows-in-late-april/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462423/it-security-nachrichten/microsoft-to-roll-out-entra-passkeys-on-windows-in-late-april/</guid>
<pubDate>Fri, 24 Apr 2026 20:21:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Offer customers passkeys by default, UK’s NCSC tells enterprises]]></title>
<description><![CDATA[The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method for businesses to offer consumers, citing industry progress that now makes them a more secure and user-friendly alternative to passwords.



In a blog post published this week, the agency ...]]></description>
<link>https://tsecurity.de/de/3458350/ai-nachrichten/offer-customers-passkeys-by-default-uks-ncsc-tells-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458350/ai-nachrichten/offer-customers-passkeys-by-default-uks-ncsc-tells-enterprises/</guid>
<pubDate>Thu, 23 Apr 2026 16:02:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method for businesses to offer consumers, citing industry progress that now makes them a more secure and user-friendly alternative to passwords.</p>



<p>In a blog post published this week, the agency said passkeys can now be recommended to both the public and businesses as a primary authentication method.</p>



<p>“Passkeys should now be consumers’ first choice of login,” the UK cybersecurity authority <a href="https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future">said in a blog post</a>, adding that passwords are “no longer resilient enough for the contemporary world.”</p>



<p>“Passkeys are a newer method for logging into online accounts which do much of the heavy lifting for users, only requiring user approval rather than needing to input a password. This makes passkeys quicker and easier to use and harder for cyber attackers to compromise,” the NCSC added in the blog.</p>



<p>The agency said passkeys should be used wherever supported, describing them as resistant to phishing and eliminating risks associated with password reuse.</p>



<h2 class="wp-block-heading">Focus on phishing-resistant authentication</h2>



<p>The guidance is based on the agency’s assessment of how authentication methods perform against real-world attacks.</p>



<p>The NCSC said its analysis examines common techniques, including phishing, credential reuse, and session hijacking, and evaluates how credentials are exposed across their lifecycle, from creation and storage to use.</p>



<p>“Passkeys are resistant to phishing attacks and remove the risks associated with password reuse,” the agency said.</p>



<p>In its accompanying <a href="https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use" target="_blank" rel="noreferrer noopener">technical paper</a>, the NCSC said traditional authentication methods, including passwords combined with one-time codes, remain “inherently phishable.”</p>



<p>By contrast, FIDO2-based credentials such as passkeys are “as secure or more secure than traditional MFA against all common credential attacks observed in the wild,” the agency said.</p>



<p>However, NCSC cautioned in the technical paper that “while much of the analysis in this paper also applies to enterprise authentication scenarios (for example staff authenticating to a Single Sign On), the different threat model and usage scenarios mean this paper is not intended for enterprise risk assessment.”</p>



<h2 class="wp-block-heading">How passkeys change the attack model</h2>



<p>The NCSC added that passkeys reduce risk by removing reliance on shared secrets and binding authentication to the legitimate service.</p>



<p>According to the agency, this prevents credential reuse and relay attacks, as authentication cannot be intercepted and reused by an attacker.</p>



<p>Passkeys use cryptographic key pairs stored on a user’s device, with authentication tied to device-based verification such as biometrics or PINs, the agency said.</p>



<h2 class="wp-block-heading">Shift in user-level authentication</h2>



<p>For organizations that provide online services to customers, the guidance signals a shift in how authentication is implemented at the user interface level.</p>



<p>“This is a fundamental architectural change, not an incremental authentication upgrade,” said Madelein van der Hout, senior analyst at Forrester. “It moves organizations beyond the passwords-plus-MFA paradigm toward a phishing-resistant foundation.”</p>



<p>Van der Hout said passkeys eliminate risks associated with credential theft by using device-bound cryptographic authentication rather than shared secrets.</p>



<p>“Organizations that treat this as a credential swap will underinvest,” she said. “Those who treat it as a broader identity modernization opportunity will get ahead.”</p>



<p>The NCSC said organizations should also consider how authentication is implemented across the full user journey, including account recovery and fallback mechanisms.</p>



<p>While passkeys reduce reliance on passwords, the agency noted that weaker processes, such as password resets or account recovery flows, can still introduce risk if not properly secured.</p>



<h2 class="wp-block-heading">Adoption challenges remain</h2>



<p>The NCSC said passkeys are not yet universally supported and recommended password managers and multi-factor authentication where passkeys cannot be used.</p>



<p>“Where a particular service does not support passkeys, the NCSC’s advice to consumers is to use a password manager to create stronger passwords and keep using two-step verification,” NCSC noted in the blog post.</p>



<p>Van der Hout said implementation challenges are likely, particularly for organizations operating across multiple platforms and user environments.</p>



<p>“Legacy systems and fragmented identity environments present significant obstacles,” she said.</p>



<p>She added that organizations must also consider non-human identities. “Any passkey strategy that ignores the machine identity layer will create new security gaps,” she said.</p>



<p>Device requirements and account recovery processes may also affect how passkeys are deployed, she said.</p>



<h2 class="wp-block-heading">Hybrid model is expected during the transition</h2>



<p>A full transition away from passwords is unlikely in the near term, analysts believe.</p>



<p>“Expect a hybrid model lasting several years,” van der Hout said, as organizations continue to support both passkeys and traditional authentication methods.</p>



<p>During this period, organizations will need to manage authentication across multiple login options while ensuring that fallback methods do not weaken overall security, she added</p>



<p>The NCSC similarly advised maintaining strong authentication practices where passkeys are not yet available.</p>



<h2 class="wp-block-heading">Policy signal strengthens shift toward passwordless login</h2>



<p>The guidance adds to broader efforts to move away from passwords in consumer authentication.</p>



<p>“The guidance matters because it gives security leaders leverage,” van der Hout said, including in discussions with vendors and internal stakeholders.</p>



<p>The NCSC said that moving toward phishing-resistant authentication could reduce a major cause of cyber compromise, particularly in services that rely on user login credentials.</p>



<p><em>The article originally appeared in <a href="https://www.csoonline.com/article/4162596/uks-ncsc-calls-passkeys-the-default-says-passwords-are-no-longer-fit-for-the-purpose.html">CSO</a>. </em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Offer customers passkeys by default, UK’s NCSC tells enterprises]]></title>
<description><![CDATA[The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method for businesses to offer consumers, citing industry progress that now makes them a more secure and user-friendly alternative to passwords.



In a blog post published this week, the agency ...]]></description>
<link>https://tsecurity.de/de/3458295/it-security-nachrichten/offer-customers-passkeys-by-default-uks-ncsc-tells-enterprises/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458295/it-security-nachrichten/offer-customers-passkeys-by-default-uks-ncsc-tells-enterprises/</guid>
<pubDate>Thu, 23 Apr 2026 15:54:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The UK’s National Cyber Security Centre (NCSC) is recommending passkeys as the default authentication method for businesses to offer consumers, citing industry progress that now makes them a more secure and user-friendly alternative to passwords.</p>



<p>In a blog post published this week, the agency said passkeys can now be recommended to both the public and businesses as a primary authentication method.</p>



<p>“Passkeys should now be consumers’ first choice of login,” the UK cybersecurity authority <a href="https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future">said in a blog post</a>, adding that passwords are “no longer resilient enough for the contemporary world.”</p>



<p>“Passkeys are a newer method for logging into online accounts which do much of the heavy lifting for users, only requiring user approval rather than needing to input a password. This makes passkeys quicker and easier to use and harder for cyber attackers to compromise,” the NCSC added in the blog.</p>



<p>The agency said passkeys should be used wherever supported, describing them as resistant to phishing and eliminating risks associated with password reuse.</p>



<h2 class="wp-block-heading">Focus on phishing-resistant authentication</h2>



<p>The guidance is based on the agency’s assessment of how authentication methods perform against real-world attacks.</p>



<p>The NCSC said its analysis examines common techniques, including phishing, credential reuse, and session hijacking, and evaluates how credentials are exposed across their lifecycle, from creation and storage to use.</p>



<p>“Passkeys are resistant to phishing attacks and remove the risks associated with password reuse,” the agency said.</p>



<p>In its accompanying <a href="https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use" target="_blank" rel="noreferrer noopener">technical paper</a>, the NCSC said traditional authentication methods, including passwords combined with one-time codes, remain “inherently phishable.”</p>



<p>By contrast, FIDO2-based credentials such as passkeys are “as secure or more secure than traditional MFA against all common credential attacks observed in the wild,” the agency said.</p>



<p>However, NCSC cautioned in the technical paper that “while much of the analysis in this paper also applies to enterprise authentication scenarios (for example staff authenticating to a Single Sign On), the different threat model and usage scenarios mean this paper is not intended for enterprise risk assessment.”</p>



<h2 class="wp-block-heading">How passkeys change the attack model</h2>



<p>The NCSC added that passkeys reduce risk by removing reliance on shared secrets and binding authentication to the legitimate service.</p>



<p>According to the agency, this prevents credential reuse and relay attacks, as authentication cannot be intercepted and reused by an attacker.</p>



<p>Passkeys use cryptographic key pairs stored on a user’s device, with authentication tied to device-based verification such as biometrics or PINs, the agency said.</p>



<h2 class="wp-block-heading">Shift in user-level authentication</h2>



<p>For organizations that provide online services to customers, the guidance signals a shift in how authentication is implemented at the user interface level.</p>



<p>“This is a fundamental architectural change, not an incremental authentication upgrade,” said Madelein van der Hout, senior analyst at Forrester. “It moves organizations beyond the passwords-plus-MFA paradigm toward a phishing-resistant foundation.”</p>



<p>Van der Hout said passkeys eliminate risks associated with credential theft by using device-bound cryptographic authentication rather than shared secrets.</p>



<p>“Organizations that treat this as a credential swap will underinvest,” she said. “Those who treat it as a broader identity modernization opportunity will get ahead.”</p>



<p>The NCSC said organizations should also consider how authentication is implemented across the full user journey, including account recovery and fallback mechanisms.</p>



<p>While passkeys reduce reliance on passwords, the agency noted that weaker processes, such as password resets or account recovery flows, can still introduce risk if not properly secured.</p>



<h2 class="wp-block-heading">Adoption challenges remain</h2>



<p>The NCSC said passkeys are not yet universally supported and recommended password managers and multi-factor authentication where passkeys cannot be used.</p>



<p>“Where a particular service does not support passkeys, the NCSC’s advice to consumers is to use a password manager to create stronger passwords and keep using two-step verification,” NCSC noted in the blog post.</p>



<p>Van der Hout said implementation challenges are likely, particularly for organizations operating across multiple platforms and user environments.</p>



<p>“Legacy systems and fragmented identity environments present significant obstacles,” she said.</p>



<p>She added that organizations must also consider non-human identities. “Any passkey strategy that ignores the machine identity layer will create new security gaps,” she said.</p>



<p>Device requirements and account recovery processes may also affect how passkeys are deployed, she said.</p>



<h2 class="wp-block-heading">Hybrid model is expected during the transition</h2>



<p>A full transition away from passwords is unlikely in the near term, analysts believe.</p>



<p>“Expect a hybrid model lasting several years,” van der Hout said, as organizations continue to support both passkeys and traditional authentication methods.</p>



<p>During this period, organizations will need to manage authentication across multiple login options while ensuring that fallback methods do not weaken overall security, she added</p>



<p>The NCSC similarly advised maintaining strong authentication practices where passkeys are not yet available.</p>



<h2 class="wp-block-heading">Policy signal strengthens shift toward passwordless login</h2>



<p>The guidance adds to broader efforts to move away from passwords in consumer authentication.</p>



<p>“The guidance matters because it gives security leaders leverage,” van der Hout said, including in discussions with vendors and internal stakeholders.</p>



<p>The NCSC said that moving toward phishing-resistant authentication could reduce a major cause of cyber compromise, particularly in services that rely on user login credentials.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The NCSC says it’s time to switch to passkeys]]></title>
<description><![CDATA[UK security organization calls for companies to step up and offer more secure ways to login]]></description>
<link>https://tsecurity.de/de/3457903/it-security-nachrichten/the-ncsc-says-its-time-to-switch-to-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457903/it-security-nachrichten/the-ncsc-says-its-time-to-switch-to-passkeys/</guid>
<pubDate>Thu, 23 Apr 2026 13:36:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK security organization calls for companies to step up and offer more secure ways to login]]></content:encoded>
</item>
<item>
<title><![CDATA[UK security agency officially declares passkeys superior to passwords – passkeys should be the 'first choice' for authentication]]></title>
<description><![CDATA[Passkeys have come a long way in just four years and are now being recommended as the number one authentication method.]]></description>
<link>https://tsecurity.de/de/3457709/it-nachrichten/uk-security-agency-officially-declares-passkeys-superior-to-passwords-passkeys-should-be-the-first-choice-for-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457709/it-nachrichten/uk-security-agency-officially-declares-passkeys-superior-to-passwords-passkeys-should-be-the-first-choice-for-authentication/</guid>
<pubDate>Thu, 23 Apr 2026 12:46:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passkeys have come a long way in just four years and are now being recommended as the number one authentication method.]]></content:encoded>
</item>
<item>
<title><![CDATA[NCSC Backs Passkeys, Hailing a New Era of Sign-in]]></title>
<description><![CDATA[The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Backs Passkeys, Hailing a New…
Read more →
The post NCSC Backs...]]></description>
<link>https://tsecurity.de/de/3457453/it-security-nachrichten/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457453/it-security-nachrichten/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/</guid>
<pubDate>Thu, 23 Apr 2026 11:21:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Backs Passkeys, Hailing a New…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/">NCSC Backs Passkeys, Hailing a New Era of Sign-in</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NCSC Backs Passkeys, Hailing a New Era of Sign-in]]></title>
<description><![CDATA[The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS]]></description>
<link>https://tsecurity.de/de/3457358/it-security-nachrichten/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457358/it-security-nachrichten/ncsc-backs-passkeys-hailing-a-new-era-of-sign-in/</guid>
<pubDate>Thu, 23 Apr 2026 10:51:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS]]></content:encoded>
</item>
<item>
<title><![CDATA[Strengthening authentication with passkeys: A CISO playbook]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3457331/it-security-nachrichten/strengthening-authentication-with-passkeys-a-ciso-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457331/it-security-nachrichten/strengthening-authentication-with-passkeys-a-ciso-playbook/</guid>
<pubDate>Thu, 23 Apr 2026 10:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Pass the key, passwords have passed their sell-by date]]></title>
<description><![CDATA[NCSC passes judgment: passkeys pass muster, passwords fail The UK’s National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.… This…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3457282/it-security-nachrichten/pass-the-key-passwords-have-passed-their-sell-by-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457282/it-security-nachrichten/pass-the-key-passwords-have-passed-their-sell-by-date/</guid>
<pubDate>Thu, 23 Apr 2026 10:21:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NCSC passes judgment: passkeys pass muster, passwords fail The UK’s National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.… This…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/pass-the-key-passwords-have-passed-their-sell-by-date/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/pass-the-key-passwords-have-passed-their-sell-by-date/">Pass the key, passwords have passed their sell-by date</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pass the key, passwords have passed their sell-by date]]></title>
<description><![CDATA[NCSC passes judgment: passkeys pass muster, passwords fail The UK's National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.…]]></description>
<link>https://tsecurity.de/de/3457228/it-security-nachrichten/pass-the-key-passwords-have-passed-their-sell-by-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457228/it-security-nachrichten/pass-the-key-passwords-have-passed-their-sell-by-date/</guid>
<pubDate>Thu, 23 Apr 2026 10:05:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>NCSC passes judgment: passkeys pass muster, passwords fail</h4> <p>The UK's National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NCSC heralds end of passwords for consumers and pushes secure passkeys]]></title>
<description><![CDATA[UK National Cyber Security Centre is urging consumers to replace passwords and two-factor authentication with passkeys, following a technical study that shows they are more secure and easier to use]]></description>
<link>https://tsecurity.de/de/3456472/it-nachrichten/ncsc-heralds-end-of-passwords-for-consumers-and-pushes-secure-passkeys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456472/it-nachrichten/ncsc-heralds-end-of-passwords-for-consumers-and-pushes-secure-passkeys/</guid>
<pubDate>Thu, 23 Apr 2026 01:16:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK National Cyber Security Centre is urging consumers to replace passwords and two-factor authentication with passkeys, following a technical study that shows they are more secure and easier to use]]></content:encoded>
</item>
<item>
<title><![CDATA[Strengthening authentication with passkeys: A CISO playbook]]></title>
<description><![CDATA[Our passkey rollout took three tries. Here's a playbook to make your implementation smoother.Categories: Security OperationsTags: CISO, playbook, toolkit, passkeys]]></description>
<link>https://tsecurity.de/de/3456306/it-security-nachrichten/strengthening-authentication-with-passkeys-a-ciso-playbook/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3456306/it-security-nachrichten/strengthening-authentication-with-passkeys-a-ciso-playbook/</guid>
<pubDate>Wed, 22 Apr 2026 23:37:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Our passkey rollout took three tries. Here's a playbook to make your implementation smoother.</p><p><strong>Categories:</strong> Security Operations</p><p><strong>Tags:</strong> CISO, playbook, toolkit, passkeys</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond Good Faith: How AI exploits the “Authorization Gap” by shattering the illusion of human…]]></title>
<description><![CDATA[Beyond Good Faith: How AI exploits the “Authorization Gap” by shattering the illusion of human effortFrom weeks of human obsession to milliseconds of AI routine: Why we must move from identity verification to structural Intent LocksFig. 1 From weeks of human obsession to milliseconds of AI exploi...]]></description>
<link>https://tsecurity.de/de/3446494/hacking/beyond-good-faith-how-ai-exploits-the-authorization-gap-by-shattering-the-illusion-of-human/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3446494/hacking/beyond-good-faith-how-ai-exploits-the-authorization-gap-by-shattering-the-illusion-of-human/</guid>
<pubDate>Sun, 19 Apr 2026 20:23:18 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Beyond Good Faith: How AI exploits the “Authorization Gap” by shattering the illusion of human effort</h3><h4>From weeks of human obsession to milliseconds of AI routine:<br> Why we must move from identity verification to structural Intent Locks</h4><figure><img alt="" src="https://cdn-images-1.medium.com/proxy/0*rgB1ttGl-Y59erJe.png"><figcaption>Fig. 1 From weeks of human obsession to milliseconds of AI exploitation. <br>(Image generated by AI.)</figcaption></figure><blockquote><strong><em>Ethical Disclosure:</em></strong><em> <br>The technical walkthroughs and conceptual PoCs provided in this article are for </em><strong><em>educational and architectural analysis purposes only</em></strong><em>. They are designed to illustrate structural semantic vulnerabilities and do not provide functional exploit code for any specific target or service. My goal is to facilitate a constructive discussion on building more resilient authorization models.</em></blockquote><h3>Abstract</h3><p>Modern systems have significantly strengthened authentication mechanisms through biometrics, Passkeys, and hardware-backed security modules. However, many architectures still rely on an implicit assumption:</p><blockquote><em>If authentication succeeds, subsequent actions are legitimate.</em></blockquote><p>This paper examines a structural flaw I refer to as the <strong>Authorization Gap</strong> — a semantic disconnect between authenticated identity and verified intent.</p><p>We provide:</p><ul><li>A technical walkthrough of a Logic Mapping Attack</li><li>An analysis of how AI automates semantic exploit discovery</li><li>A structural defense model: <strong>Intent Lock</strong></li></ul><p>Importantly, this attack does not break encryption, bypass authentication, or escalate privileges illegally.<br> It exploits semantic misbinding within authorized flows.</p><p><a href="https://medium.com/@ryu360i/the-authorization-gap-why-identity-verification-alone-is-a-flawed-security-architecture-b5b3f068739a">The Authorization Gap: Why Identity Verification Alone is a Flawed Security Architecture</a></p><h3>1. Threat Model</h3><h3>Assumptions</h3><ul><li>Identity verification succeeds.</li><li>The attacker does not break cryptography.</li><li>The attacker does not bypass authentication.</li><li>The attacker does not exploit memory corruption.</li><li>The system operates as designed.</li></ul><p>The attacker instead exploits a semantic mismatch between:</p><ul><li>What the user believes they are authorizing</li><li>What the system actually executes</li></ul><p>We define this mismatch as:</p><blockquote><strong><em>Authorization Gap</em></strong><em><br> A structural failure to bind user-visible intent to backend authorization semantics.</em></blockquote><h3>2. Technical Walkthrough: IVR Logic Mapping Attack</h3><h3>2.1 Legitimate System Mapping</h3><p>Consider a simplified IVR backend:</p><pre>DTMF Input → Backend Mapping<br><br>1 → approve_transfer()<br>9 → cancel_transfer()</pre><p>This mapping is correct and internally consistent.</p><h3>2.2 User Interface Layer (Audio Prompt)</h3><p>The legitimate system should say:</p><blockquote><em>“Press 1 to approve the transfer. Press 9 to cancel.”</em></blockquote><h3>2.3 Attack Layer: Semantic Injection</h3><p>The attacker introduces an audio manipulation layer via:</p><ul><li>VoIP gateway interception</li><li>SIM box rerouting</li><li>Audio injection</li></ul><p>The victim instead hears:</p><blockquote><em>“Press 1 to stop the suspicious transfer.”</em></blockquote><p>The backend mapping remains unchanged.</p><h3>2.4 Execution Flow</h3><pre>User -&gt; UI (Audio Injection) -&gt; "Press 1 to STOP"<br>User -&gt; Press 1 -&gt; Backend API -&gt; approve_transfer()</pre><h4>Authentication: Valid</h4><h4>Authorization: Valid</h4><h4>Intent: Hijacked</h4><p>No encryption is broken.<br>No authentication is bypassed.<br>The system behaves exactly as designed.<br>The flaw exists at the semantic layer.</p><p><a href="https://medium.com/@ryu360i/financial-account-abuse-via-ekyc-the-hidden-design-assumptions-of-digital-identity-326fdc823a62">Financial Account Abuse via eKYC: The Hidden Design Assumptions of Digital Identity</a></p><h3>3. Why This Traditionally Required High Effort</h3><p>To perform this attack manually, an attacker historically needed to:</p><ul><li>Enumerate UI text and backend mappings</li><li>Observe workflow transitions</li><li>Reverse engineer API parameter relationships</li><li>Identify semantic inconsistencies</li><li>Test input combinations</li><li>Analyze differential responses</li></ul><p>This required:</p><ul><li>Time</li><li>Skill</li><li>Persistence</li></ul><p>The high discovery cost acted as a natural barrier.</p><h3>4. AI Acceleration of Semantic Exploit Discovery</h3><p>AI does not introduce new logic flaws. <br>It accelerates the discovery of existing ones.<br>AI does not merely automate human tasks; <br>it operates as a <strong>semantic multi-tool</strong> that can identify architectural contradictions invisible to human observers.</p><h3>4.1 Cross-Silo Semantic Correlation (Target Discovery)</h3><p>In large-scale systems, UI/UX teams, backend developers, and documentation writers often operate in silos. This fragmentation creates “Semantic Drift” — small inconsistencies between what is promised to the user and what the code executes.</p><ul><li><strong>How AI Finds It:</strong> By concurrently ingesting thousands of pages of API references, UI string files, and user manuals, an LLM can identify “islands of inconsistency”.</li><li><strong>The Exploit:</strong> AI identifies a prompt like <em>“Help protect your account”</em> mapped to a backend function authorize_third_party_access(). While a human ignores this nuance, AI marks it as a high-value <strong>Authorization Gap</strong> target.</li></ul><h3>4.2 Automated State-Space Mining</h3><p>Humans are biased toward “happy paths” — the intended user flows. AI, however, is an expert at <strong>Boundary Value Analysis</strong> on a semantic scale.</p><ul><li><strong>How AI Finds It:</strong> AI agents can perform “Fuzzing for Meaning,” where they systematically manipulate input parameters to observe how backend state transitions diverge from UI descriptions.</li><li><strong>The Exploit:</strong> AI discovers that if a specific sequence of “Cancel” and “Confirm” operations is executed in a specific timing, the system enters an <strong>Open Agency</strong> state — where authorization remains valid but user-visible context has been reset.</li></ul><h3>4.3 Detection of Logic Vulnerability Chaining</h3><p>AI excels at connecting individually “safe” logical flaws into a catastrophic sequence.</p><ul><li><strong>How AI Finds It:</strong> AI views CVEs and technical specifications not as isolated bugs, but as a <strong>Feature Catalog</strong> for building attack paths.</li><li><strong>The Exploit:</strong> It identifies that Operation A (correctly authorized) changes a metadata flag that Operation B (also authorized) fails to re-validate, ultimately allowing Operation C (high-risk) to execute without the intended user consent. This chain transforms a minor “Semantic Drift” into a <strong>Logic Mapping Attack</strong>.</li></ul><h3>4.4 Multi-Step Authorized Chaining</h3><p>AI can combine individually legitimate operations:</p><pre>Operation A (allowed)<br>Operation B (allowed)<br>Operation C (allowed)</pre><p>Into a composite high-risk outcome unintended by system designers.</p><p>Each step is authorized.<br> The final result is not.</p><p>This is Authorization Gap exploitation at scale.</p><p>This pattern is not limited to telecom or IVR systems.<br> It appears in modern hardware-backed authentication ecosystems as well.</p><h3>5. Structural Analogy: iOS Trust Model</h3><p>A similar structural pattern exists in certain device authentication architectures.</p><p>Example:</p><ul><li>Face ID → Secure Enclave-backed biometric verification</li><li>Passcode → Same privilege escalation authority</li><li>Apps cannot distinguish the authentication source</li></ul><p>In iOS LocalAuthentication:</p><p>LAPolicyDeviceOwnerAuthentication</p><p>Allows biometric authentication with automatic passcode fallback.</p><p>From the app’s perspective:</p><pre>Success == trusted</pre><p>But the source of trust may differ:</p><ul><li>Secure Enclave biometric match</li><li>6-digit passcode fallback</li></ul><p>If high-assurance operations treat these as equivalent,<br> an Authorization Gap may emerge.</p><p>The system verifies Identity.<br> It does not bind Intent to authentication modality.</p><pre>// Vulnerable: High-assurance action without source check<br>context.evaluatePolicy(<br>    .deviceOwnerAuthentication,<br>    localizedReason: "Confirm this high-risk action"<br>) { success, error in<br>    if success {<br>        // Gap: Biometric? Passcode? Unknown.<br>        // The app proceeds without knowing the "source of trust".<br>        executeHighRiskAction()<br>    }<br>}</pre><p><a href="https://medium.com/@ryu360i/proposal-to-apple-3-analysis-traces-of-structural-destruction-in-ios-how-a-stolen-passcode-c4f63bfd8e0e">A Proposal to Apple Part 3 — Analysis Traces of “Structural Destruction” in iOS : How a Stolen…</a></p><h3>6. Conceptual PoC Simulation</h3><h3>Vulnerable Pattern</h3><pre>if user_input == "1":<br>    approve_transfer()</pre><p>No binding exists between:</p><ul><li>What was shown to the user</li><li>What is executed</li></ul><h3>Improved Semantic Confirmation</h3><pre>if confirmed_intent == "STOP_TRANSFER":<br>    cancel_transfer()</pre><p>Still insufficient if confirmation layer is mutable.</p><h3>Intent Lock Pattern (Conceptual)</h3><pre>// Intent Lock Pattern: Binding Intent to Action<br>visible_prompt = "Stop suspicious transfer?"<br>backend_action = "cancel_transfer"<br><br>// Generate a cryptographic binding of the intent<br>intent_binding = sign(hash(visible_prompt + backend_action))<br><br>if verify(intent_binding) {<br>    execute(backend_action)<br>}</pre><p>The key principle:</p><p>The user-visible meaning and backend action must be cryptographically and structurally inseparable.</p><h3>7. Defense Model: Intent Lock</h3><h3>Definition</h3><p><strong>Intent Lock</strong> is a structural requirement that:</p><ul><li>Binds user-visible operation meaning</li><li>To backend authorization semantics</li><li>In a verifiable, inseparable context</li></ul><h3>Intent Lock Requires:</h3><ol><li>Prompt–Action Binding</li><li>Context Integrity Validation</li><li>Input Source Authenticity</li><li>Authorization Scope Confinement</li></ol><p>It prevents:</p><ul><li>Semantic remapping</li><li>Context rewriting</li><li>Meaning injection</li></ul><p>Even when authentication remains intact.</p><h3>8. Why This Is an AI-Scale Problem</h3><p>It is important to clarify that current AI systems may not fully automate every step of semantic exploit construction.<br> However, the structural weakness exists independently of AI capability.<br> What AI changes is not possibility, but cost.<br> As the cost of semantic enumeration and cross-layer correlation decreases, previously impractical attack paths become economically viable.</p><p>Before AI:</p><p>The Authorization Gap was difficult to discover.</p><p>After AI:</p><p>Discovery cost can decrease dramatically.<br>AI reduces:</p><ul><li>Manual enumeration barriers</li><li>Semantic mapping effort</li><li>Workflow analysis time</li></ul><p>The structural weakness was always present.<br> AI simply exposes it at scale.</p><h3>9. Conclusion</h3><p>Logic Mapping Attacks do not:</p><ul><li>Break encryption</li><li>Bypass authentication</li><li>Exploit memory corruption</li></ul><p>They exploit semantic misbinding.</p><p>As authentication grows stronger,<br> the semantic layer becomes the primary attack surface.</p><p>Security must evolve from:</p><blockquote><em>Identity Verification</em></blockquote><p>to:</p><blockquote><em>Intent Confinement</em></blockquote><p>In the AI era,<br> systems that fail to structurally bind meaning to authorization<br> will remain vulnerable — <br> even when cryptography and authentication are flawless.</p><h3>About the author</h3><p>Ryu360 is a Japan-based system architect and digital forensics specialist examining how formally correct systems fail at the structural level.</p><p>He focuses on identity architectures, adversarial design analysis, and hidden trust boundaries within digital security frameworks.</p><p>He leverages AI not as a substitute for thinking, but as an amplifier of structural reasoning across linguistic and cultural boundaries.</p><p>Consultation / Technical Inquiry:<br> 👉 <a href="https://forms.gle/btGiwS9ZRc3XhZL37">https://forms.gle/btGiwS9ZRc3XhZL37</a></p><h3>Original Japanese version (Zenn, full technical background):</h3><p><a href="https://zenn.dev/ryuzaburo/articles/723bf20a0c0c21">「手間がかかる」という最強の防壁が崩れる日：性善説に甘んじた『Authorization Gap（認可の乖離）』をAIがいかに暴くか</a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c0384469b530" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/beyond-good-faith-how-ai-exploits-the-authorization-gap-by-shattering-the-illusion-of-human-c0384469b530">Beyond Good Faith: How AI exploits the “Authorization Gap” by shattering the illusion of human…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to roll out an enterprise passkey deployment]]></title>
<description><![CDATA[CISOs know that the human element can be the weakest link in an enterprise’s cybersecurity defenses, often surfacing when end users create weak passwords that threat actors easily crack. Seeking a stronger alternative, security teams are increasingly turning to passkeys.…
Read more →
The post How...]]></description>
<link>https://tsecurity.de/de/3436700/it-security-nachrichten/how-to-roll-out-an-enterprise-passkey-deployment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436700/it-security-nachrichten/how-to-roll-out-an-enterprise-passkey-deployment/</guid>
<pubDate>Wed, 15 Apr 2026 21:37:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;CISOs know that the human element can be the weakest link in an enterprise’s cybersecurity defenses, often surfacing when end users create weak passwords that threat actors easily crack. Seeking a stronger alternative, security teams are increasingly turning to passkeys.&lt;/p&gt;…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/how-to-roll-out-an-enterprise-passkey-deployment/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/how-to-roll-out-an-enterprise-passkey-deployment/">How to roll out an enterprise passkey deployment</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to roll out an enterprise passkey deployment]]></title>
<description><![CDATA[Passkey security sidesteps many of the end-user and cybersecurity issues that plague traditional passwords. Learn how to successfully deploy passkeys in your organization.]]></description>
<link>https://tsecurity.de/de/3436683/it-security-nachrichten/how-to-roll-out-an-enterprise-passkey-deployment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3436683/it-security-nachrichten/how-to-roll-out-an-enterprise-passkey-deployment/</guid>
<pubDate>Wed, 15 Apr 2026 21:20:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passkey security sidesteps many of the end-user and cybersecurity issues that plague traditional passwords. Learn how to successfully deploy passkeys in your organization.]]></content:encoded>
</item>
<item>
<title><![CDATA[Passkeys Gaining Traction as More Secure Alternative to Passwords, Experts Say]]></title>
<description><![CDATA[  Security experts are increasingly urging users to move away from traditional passwords and adopt passkeys, a newer method of logging into accounts that aims to reduce risks such as hacking and phishing.  Passwords remain widely used, but they are…
Read more →
The post Passkeys Gaining Traction ...]]></description>
<link>https://tsecurity.de/de/3435871/it-security-nachrichten/passkeys-gaining-traction-as-more-secure-alternative-to-passwords-experts-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435871/it-security-nachrichten/passkeys-gaining-traction-as-more-secure-alternative-to-passwords-experts-say/</guid>
<pubDate>Wed, 15 Apr 2026 16:39:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Security experts are increasingly urging users to move away from traditional passwords and adopt passkeys, a newer method of logging into accounts that aims to reduce risks such as hacking and phishing.  Passwords remain widely used, but they are…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/passkeys-gaining-traction-as-more-secure-alternative-to-passwords-experts-say/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/passkeys-gaining-traction-as-more-secure-alternative-to-passwords-experts-say/">Passkeys Gaining Traction as More Secure Alternative to Passwords, Experts Say</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[privacyIDEA 3.13: Passkeys, Push-Token und neue WebUI - Security-Insider]]></title>
<description><![CDATA[Täglich die wichtigsten Infos zur IT-Sicherheit ... Mit Klick auf „Newsletter abonnieren“ erkläre ich mich mit der Verarbeitung und Nutzung meiner Daten ...]]></description>
<link>https://tsecurity.de/de/3430440/it-security-nachrichten/privacyidea-313-passkeys-push-token-und-neue-webui-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3430440/it-security-nachrichten/privacyidea-313-passkeys-push-token-und-neue-webui-security-insider/</guid>
<pubDate>Tue, 14 Apr 2026 02:21:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Täglich die wichtigsten Infos zur <b>IT</b>-<b>Sicherheit</b> ... Mit Klick auf „Newsletter abonnieren“ erkläre ich mich mit der Verarbeitung und Nutzung meiner Daten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Der große Irrglaube: Warum MFA allein nicht sicher ist und Passkeys die Zukunft dominieren]]></title>
<description><![CDATA[Die Ära der einfachen Passwörter geht zu Ende. Während Unternehmen weltweit auf Multi-Faktor-Authentifizierung (MFA) setzen, entsteht ein gefährlicher Trugschluss: Die einmalige Abfrage eines zweiten Faktors macht ein System noch lange nicht sicher im Sinne von Zero Trust.

Tags: #MFA | #Multi-Fa...]]></description>
<link>https://tsecurity.de/de/3427603/it-security-nachrichten/der-grosse-irrglaube-warum-mfa-allein-nicht-sicher-ist-und-passkeys-die-zukunft-dominieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427603/it-security-nachrichten/der-grosse-irrglaube-warum-mfa-allein-nicht-sicher-ist-und-passkeys-die-zukunft-dominieren/</guid>
<pubDate>Mon, 13 Apr 2026 05:22:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920.jpg" class="attachment-full size-full wp-post-image" alt="Authentifizierung, Multi-Faktor-Authentifizierung, mfa passkeys, passkey authentifizierung, Passwordless Authentication, Warum MFA und Zero Trust sich scheinbar widersprechen, Passkeys" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/05/MFA_Shutterstock_2480010371_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Der große Irrglaube: Warum MFA allein nicht sicher ist und Passkeys die Zukunft dominieren 1"></p>
    Die Ära der einfachen Passwörter geht zu Ende. Während Unternehmen weltweit auf Multi-Faktor-Authentifizierung (MFA) setzen, entsteht ein gefährlicher Trugschluss: Die einmalige Abfrage eines zweiten Faktors macht ein System noch lange nicht sicher im Sinne von Zero Trust.

<p>Tags: <a href="https://www.it-daily.net/thema/mfa">#MFA</a> | <a href="https://www.it-daily.net/thema/multi-faktor-authentifizierung-mfa">#Multi-Faktor-Authentifizierung (MFA)</a> | <a href="https://www.it-daily.net/thema/passkeys">#Passkeys</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungarian government email passwords exposed ahead of election]]></title>
<description><![CDATA[When voters in the forthcoming Hungarian election assess the current government, its record on internet security will not be one of its proudest achievements.



An analysis by open source investigation organization Bellingcat has revealed that the passwords for almost 800 Hungarian government em...]]></description>
<link>https://tsecurity.de/de/3423786/it-nachrichten/hungarian-government-email-passwords-exposed-ahead-of-election/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423786/it-nachrichten/hungarian-government-email-passwords-exposed-ahead-of-election/</guid>
<pubDate>Fri, 10 Apr 2026 15:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When voters in the forthcoming Hungarian election assess the current government, its record on internet security will not be one of its proudest achievements.</p>



<p>An <a href="https://www.bellingcat.com/news/2026/04/09/the-hungarian-government-passwords-exposed-online/" target="_blank" rel="noreferrer noopener">analysis by open source investigation organization Bellingcat</a> has revealed that the passwords for almost 800 Hungarian government email accounts are circulating online, many of them associated with national security. These breaches in security are not down to high-tech attacks but rather are the result of poor email hygiene among government employees. The security leaks were widespread: 12 out of 13 government departments were affected.</p>



<p>Hungarian Prime Minister Viktor Orban’s administration likes to present itself as firm protector of Hungarian borders, resisting foreign interference, but this doesn’t seem to apply to its computing prowess. Among those whose details were revealed were an officer responsible for information security and a counter-terrorism expert.</p>



<p>Bellingcat found that government officials have been using <a href="https://www.csoonline.com/article/4021827/the-10-most-common-it-security-mistakes.html#:~:text=The%20problem%3A%20Weak%20passwords">weak passwords</a> such as variations of the word “Password” or the number sequence “1234567, while another simply used his surname.</p>



<p>The Hungarian government is not alone in its laxity.  Earlier this year, <a href="https://www.pcworld.com/article/3041604/6-billion-passwords-reveal-you-should-not-use-these-login-details.html">Specops found that 6 billion logins</a> had been exposed online and found that number sequences and ‘password’ featured highly in the list of the most compromised logins.</p>



<p>The vulnerabilities inherent in the Hungarian example are a warning to all CSOs that they should be reminding their staff to tighten their security credentials. Many choose simple, short memorable passwords because they’re easy to remember but using a <a href="https://www.pcworld.com/article/2607601/memorizing-a-good-email-password-is-easy-heres-how-to-do-it.html">password manager</a> or deploying <a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html">passkeys</a> will immediately strengthen employees’ ability to protect data.</p>



<p><em>This article first appeared on <a href="https://www.csoonline.com/article/4157215/hungarian-government-email-passwords-exposed-ahead-of-election.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungarian government email passwords exposed ahead of election]]></title>
<description><![CDATA[When voters in the forthcoming Hungarian election assess the current government, its record on internet security will not be one of its proudest achievements.



An analysis by open source investigation organization Bellingcat has revealed that the passwords for almost 800 Hungarian government em...]]></description>
<link>https://tsecurity.de/de/3423744/it-security-nachrichten/hungarian-government-email-passwords-exposed-ahead-of-election/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423744/it-security-nachrichten/hungarian-government-email-passwords-exposed-ahead-of-election/</guid>
<pubDate>Fri, 10 Apr 2026 15:24:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When voters in the forthcoming Hungarian election assess the current government, its record on internet security will not be one of its proudest achievements.</p>



<p>An <a href="https://www.bellingcat.com/news/2026/04/09/the-hungarian-government-passwords-exposed-online/" target="_blank" rel="noreferrer noopener">analysis by open source investigation organization Bellingcat</a> has revealed that the passwords for almost 800 Hungarian government email accounts are circulating online, many of them associated with national security. These breaches in security are not down to high-tech attacks but rather are the result of poor email hygiene among government employees. The security leaks were widespread: 12 out of 13 government departments were affected.</p>



<p>Hungarian Prime Minister Viktor Orban’s administration likes to present itself as firm protector of Hungarian borders, resisting foreign interference, but this doesn’t seem to apply to its computing prowess. Among those whose details were revealed were an officer responsible for information security and a counter-terrorism expert.</p>



<p>Bellingcat found that government officials have been using <a href="https://www.csoonline.com/article/4021827/the-10-most-common-it-security-mistakes.html#:~:text=The%20problem%3A%20Weak%20passwords">weak passwords</a> such as variations of the word “Password” or the number sequence “1234567, while another simply used his surname.</p>



<p>The Hungarian government is not alone in its laxity.  Earlier this year, <a href="https://www.pcworld.com/article/3041604/6-billion-passwords-reveal-you-should-not-use-these-login-details.html">Specops found that 6 billion logins</a> had been exposed online and found that number sequences and ‘password’ featured highly in the list of the most compromised logins.</p>



<p>The vulnerabilities inherent in the Hungarian example are a warning to all CSOs that they should be reminding their staff to tighten their security credentials. Many choose simple, short memorable passwords because they’re easy to remember but using a <a href="https://www.pcworld.com/article/2607601/memorizing-a-good-email-password-is-easy-heres-how-to-do-it.html">password manager</a> or deploying <a href="https://www.computerworld.com/article/4009132/passkeys-how-they-work-how-to-use-them.html">passkeys</a> will immediately strengthen employees’ ability to protect data.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr]]></title>
<description><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></description>
<link>https://tsecurity.de/de/3423582/it-nachrichten/heise-angebot-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423582/it-nachrichten/heise-angebot-passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr/</guid>
<pubDate>Fri, 10 Apr 2026 14:17:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign]]></title>
<description><![CDATA[The rise of SOHO router compromise campaigns has exposed a critical weakness in global network security, particularly as threat actors like Forest Blizzard continue to exploit poorly secured home and small-office devices.  

According to security researchers, this Russia-linked group has been s...]]></description>
<link>https://tsecurity.de/de/3420331/it-security-nachrichten/russian-hackers-exploit-soho-routers-for-dns-hijacking-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420331/it-security-nachrichten/russian-hackers-exploit-soho-routers-for-dns-hijacking-campaign/</guid>
<pubDate>Thu, 09 Apr 2026 14:10:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1500" height="1000" src="https://thecyberexpress.com/wp-content/uploads/SOHO-router.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="SOHO router" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/SOHO-router.webp 1500w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/SOHO-router.webp 1500w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/SOHO-router-1140x760.webp 1140w" sizes="(max-width: 1500px) 100vw, 1500px" title="Russian Hackers Exploit SOHO Routers for DNS Hijacking Campaign 1"></p><span data-contrast="auto">The rise of SOHO router compromise campaigns has exposed a critical weakness in global network security, particularly as threat actors like Forest Blizzard continue to exploit poorly secured home and small-office devices. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to security researchers, this Russia-linked group has been systematically targeting vulnerable routers since at least August 2025, transforming them into covert infrastructure for surveillance and follow-on cyberattacks. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Forest Blizzard and the Expanding SOHO Router Compromise Campaign</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">Forest Blizzard, a <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="27577">threat actor</a> associated with Russian military intelligence and tracked in part as Storm-2754, has conducted widespread exploitation of SOHO devices. By leveraging the SOHO router compromise, the group has successfully hijacked Domain Name System (DNS) requests, allowing it to passively monitor and collect network traffic at scale.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Microsoft <a href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/" target="_blank" rel="nofollow noopener">identified</a> more than 200 organizations and over 5,000 consumer devices impacted by this malicious DNS infrastructure. Notably, telemetry showed no compromise of Microsoft-owned systems. However, the breadth of affected networks highlights the campaign’s reach and the effectiveness of targeting edge devices that often lack strong monitoring or <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="27575">security</a> controls.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">For actors like <a href="https://thecyberexpress.com/apt28-dns-hijacking-fbi/" target="_blank" rel="noopener">Forest Blizzard</a>, DNS hijacking provides persistent and low-visibility access to sensitive data flows. By positioning themselves upstream of enterprise environments, attackers can observe and potentially manipulate traffic without directly breaching corporate systems.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">How SOHO Router Compromise Leads to DNS Hijacking</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">After gaining access to vulnerable routers, Forest Blizzard alters their default configurations to use attacker-controlled DNS resolvers. This manipulation causes connected devices to unknowingly send <a href="https://thecyberexpress.com/dns-security-guidance-nist-sp-800-81r3-update/" target="_blank" rel="noopener">DNS queries</a> to malicious servers.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Most endpoint devices rely on routers for network configuration via the Dynamic Host Configuration Protocol (DHCP). Once a router is compromised, all connected devices inherit the malicious DNS settings. This makes the SOHO router a compromise, an efficient and scalable attack vector.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The group is believed to use the legitimate dnsmasq utility to handle DNS queries. While dnsmasq is commonly used in home networking for DNS forwarding and DHCP services, in this context, it enables attackers to intercept, log, and respond to DNS requests while maintaining the appearance of normal operations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Forest Blizzard’s Use of Adversary-in-the-Middle Attacks</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">Beyond passive surveillance, Forest Blizzard has extended its SOHO router compromise operations to support adversary-in-the-middle (AiTM) attacks. These attacks specifically target Transport Layer Security (TLS) connections, enabling interception of sensitive communications.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">In most cases, DNS traffic is transparently proxied, allowing users to connect to legitimate services without disruption. However, in select high-value scenarios, the attackers spoof DNS responses for targeted domains. This redirects victims to malicious infrastructure controlled by Forest Blizzard.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Once redirected, victims may encounter invalid TLS certificates mimicking legitimate services such as <a href="https://thecyberexpress.com/fancy-bear-apt28-outlook-backdoor/" target="_blank" rel="noopener">Outlook</a> on the web. If users ignore certificate warnings, attackers can intercept plaintext <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="27578">data</a> within the encrypted session. This may include emails and other sensitive cloud-hosted content.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Researchers observed two notable AiTM scenarios:</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<ul>
 	<li><span data-contrast="auto">Attacks on Microsoft 365 domains, particularly Outlook on the web. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Targeted operations against government servers in at least three African countries, where DNS interception enabled further data collection. </span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<h3 aria-level="3"><b><span data-contrast="none">Mitigation Strategies Against Forest Blizzard Threats</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":281,"335559739":281}'> </span></h3>
<span data-contrast="auto">To counter <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="27576">risks</a> associated with SOHO router compromise, researchers recommend several defensive measures. For DNS protection, organizations should enforce domain-based access controls using Zero Trust DNS (ZTDNS), block malicious domains, and maintain detailed DNS logs to detect ano</span><span data-contrast="auto">malies. Enabling network and web protection features in Microsoft Defender for Endpoint further strengthens defenses.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Equally critical is addressing identity security. Centralizing identity management, enforcing multifactor authentication (MFA), and applying Conditional Access policies can reduce the impact of credential theft from AiTM attacks. It is also advised to adopt passwordless solutions such as passkeys and restrict authentication to trusted devices and locations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Passwords syncing bug corrected by iOS 26.4.1 update]]></title>
<description><![CDATA[Apple's iOS 26.4.1 update resolves a CloudKit framework issue that prevented iCloud passwords and other data from syncing.iOS 26.4.1 includes a fix related to iCloud data syncing.Following the public release of iOS 26.4 on March 24, Apple issued a new bug fix update on Wednesday. iOS 26.4, which ...]]></description>
<link>https://tsecurity.de/de/3418672/ios-mac-os/apple-passwords-syncing-bug-corrected-by-ios-2641-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3418672/ios-mac-os/apple-passwords-syncing-bug-corrected-by-ios-2641-update/</guid>
<pubDate>Wed, 08 Apr 2026 23:35:33 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's <a href="https://appleinsider.com/inside/ios-26" title="iOS 26" data-kpt="1">iOS 26.4.1</a> update resolves a CloudKit framework issue that prevented iCloud passwords and other data from syncing.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67297-141602-Passwords-xl.jpg" alt="Close-up of an iPad screen showing a dark-mode Passwords dashboard with tiles labeled All, Passkeys, Codes, WiFi, Security, and Deleted, each displaying small colored icons and item counts"><br><span>iOS 26.4.1 includes a fix related to iCloud data syncing.</span></div><br>Following the <a href="https://appleinsider.com/articles/26/03/24/ios-264-is-here-with-playlist-playground-videos-in-podcasts-new-emoji-more">public release</a> of iOS 26.4 on March 24, Apple <a href="https://appleinsider.com/articles/26/04/08/ios-2641-ipados-2641-bug-fix-updates-have-arrived">issued</a> a new bug fix update on Wednesday. iOS 26.4, which bears the build number 23E254, delivers an important fix for apps that rely on the CloudKit framework.<br><br>To be more specific, devices running the preceding iOS 26.4 update were unable to receive <a href="https://appleinsider.com/inside/icloud" title="iCloud" data-kpt="1">iCloud</a> notifications regarding changes, causing problems for iCloud data syncing. In certain apps, changes made on one iPad or <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> would not be visible on another.<br><br><br> <a href="https://appleinsider.com/articles/26/04/08/apple-passwords-syncing-bug-corrected-by-ios-2641-update?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243984?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authentication is broken: Here’s how security leaders can actually fix it]]></title>
<description><![CDATA[Authentication keeps breaking where it matters most: On regulated front lines such as healthcare, government, aerospace and travel. The core issue is not a lack of innovation. Instead, it is a brittle and fragmented ecosystem of cards, readers, middleware and software that rarely work together un...]]></description>
<link>https://tsecurity.de/de/3410808/it-security-nachrichten/authentication-is-broken-heres-how-security-leaders-can-actually-fix-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410808/it-security-nachrichten/authentication-is-broken-heres-how-security-leaders-can-actually-fix-it/</guid>
<pubDate>Mon, 06 Apr 2026 12:07:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Authentication keeps breaking where it matters most: On regulated front lines such as healthcare, government, aerospace and travel. The core issue is not a lack of innovation. Instead, it is a brittle and fragmented ecosystem of cards, readers, middleware and software that rarely work together under real-world pressure. Even today’s “passwordless” solutions can be undermined by poor implementation, downgrades and fallback paths that attackers are quick to exploit. This article examines where these failures occur, why they persist and offers a practical blueprint for CISOs to guide their organizations and vendors toward resilient, phishing-resistant and field-ready authentication.</p>



<h2 class="wp-block-heading">The problem: Brittle by design</h2>



<p>Authentication is supposed to be the most reliable control in your security stack. Yet in many enterprises, it is often the most fragile because there are too many moving parts: Credential types, readers (contact, contactless, dual frequency), protocols, middleware, identity platforms and device operating system nuances. Any minor mismatch — such as an unexpected identifier format, a driver quirk, a browser nuance or a rushed patch — can quickly turn a mission-critical login into a service desk crisis. This is not just a theoretical risk; it is a daily reality for operations teams who must keep care units, field agents and front of house operations running smoothly.</p>



<h2 class="wp-block-heading">Sector snapshots: Where it breaks (and why that matters)</h2>



<ul class="wp-block-list">
<li><strong>Healthcare.</strong> Clinicians need tap and go speed with zero tolerance for downtime. One large hospital attempted to pair advanced HID SEOS credentials, which use privacy-preserving randomized IDs, with a clinical SSO platform that expects static IDs for user recognition. This architectural mismatch forced a choice between stronger privacy and reliable workflows. The project stalled until the team reverted to technology compatible with static IDs. In healthcare, even a minor glitch can quickly escalate into a patient safety incident.</li>



<li><strong>State &amp; local government.</strong> Agencies rolled out unified FIDO2 credentials to cover both door access and laptop logons. However, they soon discovered that many rugged laptops did not include the low-frequency antenna needed for physical access. Teams either split credentials, which defeated the purpose or added external readers, which increased cost and complexity. Field users ended up carrying multiple badges and dongles, which is the opposite of resilience.</li>



<li><strong>Aerospace and Travel.</strong> Aerospace organizations that adopted proprietary card ecosystems, such as LEGIC encountered licensing constraints that limited which readers they could purchase and how quickly they could scale globally. In the travel sector, a cruise line’s shift to wristband credentials faced challenges with FIPS 201 requirements, which were designed for cards rather than wearables. This forced the company into custom engineering solutions. In these cases, innovation moved faster than standards and operational teams had to manage the consequences.</li>
</ul>



<h2 class="wp-block-heading">Root causes: Why the ecosystem is stuck</h2>



<ul class="wp-block-list">
<li><strong>Fragmentation across layers.</strong> Cards like SEOS, LEGIC, DESFire and FIDO2, mixed with contact, contactless and dual‑frequency readers and identity stacks such as Imprivata, Windows Hello, Okta and Ping rarely interoperate cleanly. A change in any layer can trigger unexpected failures across the system.</li>



<li><strong>Downgrades and fallback weaknesses.</strong> Authentication remains only as strong as its weakest backup path. Adversary‑in‑the‑middle and downgrade attacks routinely bypass phish‑resistant flows, as shown in <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">CSO reporting on FIDO passkey downgrade</a> exploits and ongoing <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html">MFA‑fatigue attacks</a>. These gaps quietly reintroduce risk despite modern authentication advances.</li>



<li><strong>Patch fragility.</strong> Platform updates often break authentication flows, with CSO documenting cases where Windows updates disrupted smart card logons and Windows Hello for Business. These incidents, including the ones covered in Microsoft updates, knock out key enterprise functions. And <a href="https://www.csoonline.com/article/3980320/security-update-causes-new-problem-for-windows-hello-for-business-authentication.html">Windows Hello for Business authentication issue</a>s, show how sensitive authentication stacks are to version drift.</li>



<li><strong>Vendor lock‑in and standards gaps.</strong> Proprietary licensing and uneven SDKs limit flexibility and slow upgrades. Progress toward interoperability profiles is emerging, but only when customers demand it. <a href="https://www.csoonline.com/article/3566344/oktas-new-security-standard-to-be-adopted-by-google-microsoft.html">Okta’s IPSIE standard</a> is one example, though broad adoption still depends on pressure from buyers.</li>
</ul>



<h2 class="wp-block-heading">The path forward: 3 architectural shifts that can help</h2>



<p>Three architectural shifts can significantly improve reliability and reduce unexpected failures. These approaches are not mutually exclusive and can be combined for maximum effectiveness on a single platform.</p>



<h3 class="wp-block-heading">1) Modular secure elements (SEs) embedded or in SIM form</h3>



<p>Device-bound cryptography, tamper resistance, ultra-low-power states and tighter OEM control over firmware and BIOS all raise the baseline for security and reliability. This is especially valuable in rugged or clinical environments, where device identity and offline resilience matter. Embedded secure elements help here by removing dependence on external readers and unstable drivers, though they introduce their own tradeoffs such as vendor lock‑in, added board and firmware complexity and reliance on specialized parts that can create yet another integration challenge if no common profile exists. The most effective way to adopt them is to start with a narrow, high‑value fleet like emergency carts, field supervisors or flight line tablets, pairing the secure element with a hardened, signed image and an offline‑ready authentication posture so it can serve as the root of trust for both login and data at rest.</p>



<h3 class="wp-block-heading">2) Middleware standardization (make the reader/credential layer pluggable)</h3>



<p>Middleware becomes the universal bridge that smooths out card and reader quirks, giving you a stable way to integrate with identity platforms like Entra, Okta, Ping or Imprivata while normalizing identifiers, enforcing anti‑downgrade logic and capturing every strange edge case for rapid incident response. It comes with its own hurdles, including unclear ownership, upfront integration work and competing SDKs, yet once it’s in place you separate authentication behavior from device idiosyncrasies and vendor swaps, which is a major win for operations. The cleanest path is to stand up a credential abstraction layer with clear policies that block legacy fallbacks on high‑risk apps, enforce phishing‑resistant flows and log any downgrade decisions as security events sent to the SOC, while also applying session‑protection controls that blunt adversary‑in‑the‑middle attacks.</p>



<h3 class="wp-block-heading">3) Unified credential ecosystem (the “USB‑C moment” for authentication)</h3>



<p>Standard behavior across readers, middleware and identity providers creates a calmer edge environment, cutting down on surprise failures and the weekend firefighting that follows patch cycles. The model isn’t free—you need industry coordination, legacy bridges and steady change management—but the direction is already set toward credential abstraction with multiprotocol support and reference integrations that vendors certify together. The cleanest way to land this is through RFP requirements that demand multiprotocol credential handling, verified reader and IdP compatibility, documented anti‑downgrade behavior and clear runbooks for regression handling after OS or IdP updates, with payments and renewals tied directly to meeting those standards.</p>



<h2 class="wp-block-heading">CISO action plan: 5 moves that change outcomes this quarter</h2>



<ol start="1" class="wp-block-list">
<li><strong>Kill the weakest link: Remove silent fallbacks.</strong> Identify where passwordless flows still revert to legacy prompts such as SMS, voice, OTP or simple approval pushes. On systems handling money, PHI or privileged access, disable or tightly control these paths. If a fallback is unavoidable, require identity verification and alert the SOC for review. Downgrade paths and MFA fatigue attacks often succeed because weak backups are left in place, as detailed <a href="https://www.csoonline.com/article/570795/how-to-hack-2fa.html">here</a>.</li>



<li><strong>Demand downgrade transparency in your tooling.</strong> Require your IdP or middleware to log every downgrade event and block scripted browser or agent spoofing that drives users into fake “unsupported browser” flows. Downgrade bypasses in passkey and FIDO flows have been demonstrated in the wild, so your stack should make these attempts easy to detect and simple to shut down. A clear example is outlined <a href="https://www.csoonline.com/article/4040128/fido-undermined.html">here</a>.</li>



<li><strong>Harden for patch turbulence (assume authentication regressions).</strong> Create a pre‑prod integration gauntlet that exercises smart cards, passkeys, Windows Hello key trust and your clinical or field SSO flows. Hold broad deployment until the gauntlet passes and keep a one‑click rollback and a ready‑to‑send communications script. <a href="https://www.csoonline.com/article/4076016/security-patch-or-self-inflicted-ddos-microsoft-update-knocks-out-key-enterprise-functions-2.html">Recent Windows updates</a> have shown how quickly authentication can break at scale, so build muscle‑memory playbooks before Patch Tuesday. Examples include</li>



<li><strong>Write interoperability into contracts.</strong> RFPs should call out multi‑protocol credential abstraction, certified reader and IdP pairings, FIDO2 and passkey support without insecure fallbacks and alignment with emerging interoperability profiles. Vendors are already moving in this direction and Okta’s IPSIE standard is one example worth <a href="https://www.csoonline.com/article/3566344/oktas-new-security-standard-to-be-adopted-by-google-microsoft.html">citing</a>.</li>



<li><strong>Pick the right pilot: Constrained, high‑value and visible.</strong> Start where downtime is costly and users are already trained, such as ICU stations, air‑side operations or revenue desks. Pair embedded secure‑element devices with reader‑agnostic middleware and strict anti‑downgrade policies. Track MTTR for authentication incidents, downgrade frequency and help‑desk volume, then publish the results to justify a broader rollout.</li>
</ol>



<h2 class="wp-block-heading">The long view: Resilience over fashion</h2>



<p>Passkeys and FIDO2 move authentication in the right direction when they are deployed without porous fallbacks and with integrations that behave consistently under pressure. Their security and usability advantages are <a href="https://www.csoonline.com/article/574369/how-passkeys-are-changing-authentication.html">clear</a>, yet real‑world usage has also shown how adversary‑in‑the‑middle techniques and weak backup paths can <a href="https://www.csoonline.com/article/574369/how-passkeys-are-changing-authentication.html">undermine</a> those gains. These issues are not reasons to slow adoption but reminders to approach implementation with discipline.</p>



<p>To build authentication that remains stable even as systems evolve, we need interoperability, anti‑downgrade behavior as the default and graceful failure modes. That means using modular hardware where it fits, relying on reader‑agnostic middleware with enforceable policy and pushing for a unified credential experience that vendors certify and customers insist on. Components exist today; what’s missing is the resolve to wire them together.</p>



<p>Do not invest in another point solution until your contracts, runbooks and pilots reflect these principles. Authentication should be the calmest, most predictable part of your stack, not the source of your next incident. The building blocks for resilient, interoperable authentication already exist. What’s missing is resolve. Now is the time for security leaders to set the standard and demand better. Make authentication work for you, not against you.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Battling payment fraud with tokenization and executive interviews from RSAC 2026 - Jimmy White, Thyaga Vasudevan, Brian Oh, Mickey Bresman, Ashish Jain - ESW #453]]></title>
<description><![CDATA[Interview with Brian Oh from FIS Global Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders' desks. In this episode, Brian Oh from ...]]></description>
<link>https://tsecurity.de/de/3410711/it-security-nachrichten/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-jimmy-white-thyaga-vasudevan-brian-oh-mickey-bresman-ashish-jain-esw-453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410711/it-security-nachrichten/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-jimmy-white-thyaga-vasudevan-brian-oh-mickey-bresman-ashish-jain-esw-453/</guid>
<pubDate>Mon, 06 Apr 2026 11:21:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with Brian Oh from FIS Global</h3> <p><strong>Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant</strong></p> <p>Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders' desks. In this episode, Brian Oh from FIS Global explains how merchant-specific tokenization and virtual cards work, why embedded finance raises the stakes, and how approaches like behavioral biometrics and tokenized payments can reduce fraud while keeping checkout experiences fast and seamless.</p> <p>Segment Resources:</p> <ul> <li>FIS Global - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/insights/the-future-of-embedded-finance"> The Future of Embedded Finance</a></li> <li>PYMNTS Article - <a rel="noopener" target="_blank" href="https://www.pymnts.com/news/regulation/2025/fdic-support-clears-path-tokenized-deposits-scale/"> FDIC Support Clears a Path for Tokenized Deposits to Scale</a></li> <li>FIS Global Blog - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/blog?p=how-behavioral-biometrics-are-leading-the-way-in-secure-banking-and-fraud-defense-for-digital-one-flex-clients&amp;ap=digital-one&amp;c=digital-one"> How behavioral biometrics are leading the way in secure banking and fraud defense for Digital One™ Flex clients</a></li> <li>FIS Global Blog - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/blog?p=inside-flexs-advanced-fraud-defense-what-tech-leaders-need-to-know&amp;ap=digital-one&amp;c=digital-one"> Inside Flex's Advanced Fraud Defense: What Tech Leaders Need to Know</a></li> </ul> <h3>Interviews with Mickey Bresman from Semperis and Ashish Jain from OneSpan</h3> <p><strong>The Making of Midnight in the War Room</strong></p> <p>Semperis is producing <a rel="noopener" target="_blank" href="https://www.semperis.com/midnight-in-the-war-room/">Midnight in the War Room</a>, a full length feature film on cyberwar and CISO heroism and their work defending their companies against the onslaught of cyberattacks. Midnight in the War Room puts a human face on the front lines of cyber defense and will reveal the weight carried by defenders every day and why resilience must be built not only into systems, but into people and institutions.</p> <p>This segment is sponsored by Semperis! Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/semperisrsac">https://securityweekly.com/semperisrsac</a> to learn more.</p> <p><strong>Why Passkeys Are Ready for Prime Time in Modern Banking</strong></p> <p>Authentication has long required an uneasy tradeoff between strong security and smooth user experience. This interview segment explores why passkeys are ready now for even the highest risk banking use cases, why banks should be moving quickly to adopt them, and how OneSpan delivers the most complete, secure, and enterprise ready passkey solution on the market.</p> <p>This segment is sponsored by OneSpan. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/onespanrsac">https://securityweekly.com/onespanrsac</a> to learn more about them!</p> <h3>Interviews with Jimmy White from F5 and Thyaga Vasudevan from SkyHigh Security</h3> <p><strong>Securing AI Agents: Managing Runtime Risk in Enterprise AI Systems</strong></p> <p>As organizations deploy AI agents and automated workflows, security challenges are increasingly emerging once these systems interact with APIs, enterprise data, and business processes in production.</p> <p>For more information about F5, please visit <a rel="noopener" target="_blank" href="https://securityweekly.com/f5rsac">https://securityweekly.com/f5rsac</a>.</p> <p><strong>AI's Security Inflection Point: Hybrid, Browser Security, and Data Compliance</strong></p> <p>The rapid adoption of AI applications is reshaping enterprise security architectures. As organizations integrate AI copilots, agentic workflows, and cloud-native platforms, traditional network-centric security models are proving insufficient.</p> <p>This segment is sponsored by Skyhigh Security. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/skyhighrsac">https://securityweekly.com/skyhighrsac</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-453">https://securityweekly.com/esw-453</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Battling payment fraud with tokenization and executive interviews from RSAC 2026 - ESW #453]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Interview with Brian Oh from FIS Global

Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant

Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that incre...]]></description>
<link>https://tsecurity.de/de/3410707/it-security-video/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-esw-453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410707/it-security-video/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-esw-453/</guid>
<pubDate>Mon, 06 Apr 2026 11:17:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zxV7Wdjx2vI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with Brian Oh from FIS Global<br />
<br />
Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant<br />
<br />
Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders’ desks. In this episode, Brian Oh from FIS Global explains how merchant-specific tokenization and virtual cards work, why embedded finance raises the stakes, and how approaches like behavioral biometrics and tokenized payments can reduce fraud while keeping checkout experiences fast and seamless.<br />
<br />
Segment Resources:<br />
<br />
- FIS Global - The Future of Embedded Finance: https://www.fisglobal.com/insights/the-future-of-embedded-finance<br />
- PYMNTS Article - FDIC Support Clears a Path for Tokenized Deposits to Scale: https://www.pymnts.com/news/regulation/2025/fdic-support-clears-path-tokenized-deposits-scale/<br />
- FIS Global Blog - How behavioral biometrics are leading the way in secure banking and fraud defense for Digital One™ Flex clients: https://www.fisglobal.com/blog?p=how-behavioral-biometrics-are-leading-the-way-in-secure-banking-and-fraud-defense-for-digital-one-flex-clients&ap=digital-one&c=digital-one<br />
- FIS Global Blog - Inside Flex's Advanced Fraud Defense: What Tech Leaders Need to Know: https://www.fisglobal.com/blog?p=inside-flexs-advanced-fraud-defense-what-tech-leaders-need-to-know&ap=digital-one&c=digital-one<br />
<br />
Interviews with Mickey Bresman from Semperis and Ashish Jain from OneSpan<br />
<br />
The Making of Midnight in the War Room<br />
<br />
Semperis is producing Midnight in the War Room (https://www.semperis.com/midnight-in-the-war-room/), a full length feature film on cyberwar and CISO heroism and their work defending their companies against the onslaught of cyberattacks. Midnight in the War Room puts a human face on the front lines of cyber defense and will reveal the weight carried by defenders every day and why resilience must be built not only into systems, but into people and institutions.<br />
<br />
This segment is sponsored by Semperis! Visit https://securityweekly.com/semperisrsac to learn more.<br />
<br />
Why Passkeys Are Ready for Prime Time in Modern Banking<br />
<br />
Authentication has long required an uneasy tradeoff between strong security and smooth user experience. This interview segment explores why passkeys are ready now for even the highest risk banking use cases, why banks should be moving quickly to adopt them, and how OneSpan delivers the most complete, secure, and enterprise ready passkey solution on the market.<br />
<br />
This segment is sponsored by OneSpan. Visit https://securityweekly.com/onespanrsac to learn more about them!<br />
<br />
Interviews with Jimmy White from F5 and Thyaga Vasudevan from SkyHigh Security<br />
<br />
Securing AI Agents: Managing Runtime Risk in Enterprise AI Systems<br />
<br />
As organizations deploy AI agents and automated workflows, security challenges are increasingly emerging once these systems interact with APIs, enterprise data, and business processes in production.<br />
<br />
For more information about F5, please visit https://securityweekly.com/f5rsac.<br />
<br />
AI’s Security Inflection Point: Hybrid, Browser Security, and Data Compliance<br />
<br />
The rapid adoption of AI applications is reshaping enterprise security architectures. As organizations integrate AI copilots, agentic workflows, and cloud-native platforms, traditional network-centric security models are proving insufficient.<br />
<br />
This segment is sponsored by Skyhigh Security. Visit https://securityweekly.com/skyhighrsac to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-453<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr | heise online]]></title>
<description><![CDATA[Special: Zusammen das Datacenter weiterentwickelnSecure IT für Unternehmen ... Als Security Researcher bei der Neodyme AG ist er Experte für Code ...]]></description>
<link>https://tsecurity.de/de/3402316/it-security-nachrichten/passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402316/it-security-nachrichten/passwortlose-authentifizierung-mit-passkeys-fido-sso-und-mehr-heise-online/</guid>
<pubDate>Thu, 02 Apr 2026 12:36:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Special: Zusammen das Datacenter weiterentwickelnSecure <b>IT</b> für Unternehmen ... Als <b>Security</b> Researcher bei der Neodyme AG ist er Experte für Code ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Bank Negara Malaysia RMiT Update: New Authentication Rules for Fintech and Banks]]></title>
<description><![CDATA[Bank Negara Malaysia’s updated RMiT framework introduces stricter authentication rules for banks and fintech apps. Learn how passkeys, adaptive MFA, device binding, and risk-based authentication help meet compliance. The post Bank Negara Malaysia RMiT Update: New Authentication Rules for Fintech…...]]></description>
<link>https://tsecurity.de/de/3401635/it-security-nachrichten/bank-negara-malaysia-rmit-update-new-authentication-rules-for-fintech-and-banks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401635/it-security-nachrichten/bank-negara-malaysia-rmit-update-new-authentication-rules-for-fintech-and-banks/</guid>
<pubDate>Thu, 02 Apr 2026 08:36:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bank Negara Malaysia’s updated RMiT framework introduces stricter authentication rules for banks and fintech apps. Learn how passkeys, adaptive MFA, device binding, and risk-based authentication help meet compliance. The post Bank Negara Malaysia RMiT Update: New Authentication Rules for Fintech…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/bank-negara-malaysia-rmit-update-new-authentication-rules-for-fintech-and-banks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/bank-negara-malaysia-rmit-update-new-authentication-rules-for-fintech-and-banks/">Bank Negara Malaysia RMiT Update: New Authentication Rules for Fintech and Banks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,09ms -->