For years, the security advice was simple: turn on multifactor authentication.
IT people repeated it endlessly. Microsoft pushed it. Insurance companies started requiring it. Cybersecurity audits looked for it. Eventually, most businesses got the message.
Users learned the routine. Enter the password. Wait for the text message. Type in the 6-digit code. Get back to work.
Now Microsoft is changing all of that. [Read more…]
I’ve said from the beginning that the biggest risk with AI isn’t that it writes bad code. It’s that people are starting to trust it to make decisions it has no business making.
Back in the fall, I said Microsoft was going to have to extend Windows 10 support again. The numbers made it obvious. There were simply too many machines still running it, and not enough realistic paths to Windows 11 for a huge chunk of users. Now here we are.
For years, companies drilled one thing into employees’ heads: don’t trust weird emails. Problem is, attackers adapted. Instead of fighting against people’s skepticism around email, they moved to platforms employees already trust without thinking twice about it. One of the biggest targets right now is Microsoft Teams
A new attack called Pixnapping can steal sensitive data from Android devices, without needing a single permission. The exploit targets visual data on-screen, including two-factor authentication codes, private messages, and location histories. It works by quietly measuring how long it takes to render specific pixels. If that sounds like science fiction, it’s not. Researchers have already tested it on Pixel and Samsung devices with unsettling results.