Ever notice how every identity system depends on something else — and those dependencies are often invisible?
That’s the idea behind the Clean Source Principle and why it matters for the future of identity security.
specterops.io/blog/2025/10/0…
Multi-factor authentication (MFA) and single sign-on (SSO) technologies are vulnerable. Along with @CISAgov and industry partners, we’ve released a new report identifying key challenges and actionable recommendations to better secure MFA and SSO. Read now: nsa.gov/Press-Room/Pre…
“IL5 is a major milestone for CrowdStrike, giving us the ability to protect even more DoD and Intelligence customers in the community cloud through the world’s most advanced cybersecurity technology,” CrowdStrike President Michael Sentonas said
Read more: crwdstr.ke/6019Ost5z
@LightfootProd@NYIslanders Bro skates into someone. Bro gets a penalty. ‘canes will have no players after this series anyways, too soft. Nor can they skate.
@divinetechygirl Can jump from on-premises to cloud regardless if the user account is even synced in some cases; ie attacker follows the WS-FED trust (ie ADFS -> AAD Tenant).
Think the 'spy balloon' was the big SIGINT activity for China recently?
China is "endemic" at this point, drastically increasing its cyber espionage globally, especially targeting the US.
#cybersecuritynbcnews.com/news/forget-ch…
Always fun. I guess stop buying cars from China and secure your supply chain. This is why German car manufactures are pushing things like TISAX.
#cyber#espionage l inews.co.uk/news/hidden-ch…
I've been using iOS on lockdown mode for a while and it's super useable. Everything works great except some weird rendering on browers, but it's manageable.
Give it a try, I'd definitely recommand this even for standard users. support.apple.com/en-us/HT212650
I’d like to see people’s faces when they eventually find out that their MFA protected confidential data in the cloud can be accessed using a fu***** token extracted from an inconspicuous desktop app
@ConanUnofficial@x0rz I haven’t tried it. I had one person tell me it forces you to manually de-enroll the device before proceeding. I had another tell me it automatically removes the profile.
@DoD_CIO Are COAs 2 and 3 just focused on “cloud” vs applying Zero Trust everywhere including on-premises? Sunburst/SolarWinds taught us compromising on-premises becomes a back door to the cloud, and vice versa…
DoD CIO released the DoD #ZeroTrust Strategy and Roadmap today to accelerate DoD’s new approach to cybersecurity. Read more at: defense.gov/News/Releases/…