cybersecurity
Sam Curry's work investigating a phishing website from his own IP address saw events escalate rapidly...
"DevSecOps shouldn't mean that developers have to be security experts. They won't be, they can't be and it is a very bad idea to even have this expectation."
"I think our biggest challenge was, and this is something we learned the hard way, was the password reset..."
Microsoft itself warns that it is "not possible to audit the generation of SAS tokens"
Social engineering allegedly led to MGM attack: $13 billion firm's cybersecurity "defeated by a 10-minute conversation"?
From SAP, an "update that only became necessary because the Security Note was accidentally previously deleted" and from Microsoft, some strange assessments.
"We also notified law enforcement and took prompt action to protect our systems and data, including shutting down certain systems."
An attacker could have been forging access tokens to Microsoft services for up to two years, unnoticed