For years, the security advice was simple: turn on multifactor authentication.
IT people repeated it endlessly. Microsoft pushed it. Insurance companies started requiring it. Cybersecurity audits looked for it. Eventually, most businesses got the message.
Users learned the routine. Enter the password. Wait for the text message. Type in the 6-digit code. Get back to work.
Now Microsoft is changing all of that. [Read more…]
For years, companies drilled one thing into employees’ heads: don’t trust weird emails. Problem is, attackers adapted. Instead of fighting against people’s skepticism around email, they moved to platforms employees already trust without thinking twice about it. One of the biggest targets right now is Microsoft Teams
You click a link. It takes you to a site that looks exactly right. The logo matches, the name checks out, and everything feels familiar. But something’s off. And before you realize what it is, you’ve handed over your login, your credit card, or worse, your network credentials. The trick wasn’t in the layout or the content. It was in the letters.
Hackers posing as IT support are targeting employees at large companies to sneak into their Salesforce systems and steal data. They start with a phone call, pretending to help with a routine issue. The real goal? To get the employee to connect to a fake version of Salesforce’s Data Loader tool. Once that happens, the attackers can quietly grab sensitive company data.