I would assume that many companies right now are relaxing their rules on security to allow WFH capabilities for the masses.
Systems in general and VPNs in particular will have been utterly desecrated with last minute requests to enable access to systems and services they wouldn’t have had prior.
Conditional access policies will have been relaxed to allow for personal devices to connect in.
Temporary long term tokens will have been allocated in place if not having enough (RSA) dongles, or being lost.
Then there’s the social engineering aspect of exploiting the fear and naivety of the situation.
It’s gonna be a Swiss cheese covered blood bath out there in a few weeks time, if not already!!
[link] [comments]