article thumbnail

Why CISA is Warning CISOs About a Breach at Sisense

Krebs on Security

Both sources said the attackers used the S3 access to copy and exfiltrate several terabytes worth of Sisent customer data, which apparently included millions of access tokens, email account passwords, and even SSL certificates.

CISO 308
article thumbnail

Banks, Arbitrary Password Restrictions and Why They Don't Matter

Troy Hunt

Allow me to be controversial for a moment: arbitrary password restrictions on banks such as short max lengths and disallowed characters don't matter. Also, allow me to argue with myself for a moment: banks shouldn't have these restrictions in place anyway. 6 characters. for my *online banking*.

Banking 266
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

The Hidden Cost of Ransomware: Wholesale Password Theft

Krebs on Security

Organizations in the throes of cleaning up after a ransomware outbreak typically will change passwords for all user accounts that have access to any email systems, servers and desktop workstations within their network. ” WHOLESALE PASSWORD THEFT. In our Dec. If we’d had more time to prepare, it would have gone better.

Passwords 250
article thumbnail

Weekly Update 257

Troy Hunt

But what I'm most excited about is what I probably spent the least amount of time talking about, that being the work 1Password and I have been doing on our "Hello CISO" series. Sponsored by: 1Password is a secure password manager and digital wallet that keeps you safe online.

CISO 68
article thumbnail

Why CISOs change jobs

CSO Magazine

Being a CISO is a hard job. Despite this excellence, a single employee can click on a malicious web link, share a password, or misconfigure an asset, leading directly to a successful cyberattack. Yup, CISOs have heavy responsibilities. When this happens, it's your fault. How are they dealing with this burden?

CISO 125
article thumbnail

University CISOs say zero trust is the best defense against the existential threat of phishing

Tech Republic Security

Stanford has replaced logins and passwords with a digital key to improve endpoint security.

CISO 217
article thumbnail

NIST Password Guidelines 2021: Challenging Traditional Password Management

Security Boulevard

In 2017, the National Institute of Standards and Technology (NIST) released NIST Special Publication 800-63B Digital Identity Guidelines to help organizations properly comprehend and address risk as it relates to password management on the part of end users.