News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Box: MFA via SMS could also be bypassed by attackers
Box: MFA via SMS could also be bypassed by attackers

Varonis security researchers have discovered a way to bypass multi-factor authentication (MFA) via SMS for Box accounts. Attackers with stolen credentials were able to compromise an organization's Box account and exfiltrate sensitive data without having to access the victim's phone. Security researchers reported this vulnerability to Box on November 3, 2021 via HackerOne, which prompted it to be closed. Just last month, Varonis Thread Labs demonstrated how to bypass Box's TOTP-based MFA. Both gaps make it clear that cloud security, even when using seemingly secure technologies, is never...

Read more

Good outlook for cybersecurity professionals

What can we expect in 2022? Are we past the worst or are we just at the beginning of a worrying development? Cyber ​​security professionals are in demand like never before. Michael Scheffler, Country Manager DACH of the data security specialist Varonis Systems, dares four predictions. And again, a turbulent year lies behind us, which intensified many of the previous year's trends: We saw supply chain attacks on IT service providers with far-reaching consequences. Ransomware attacks also seemed to know no boundaries, be it with regard to the quantity and quality of the victims or the sums required, which reached new highs….

Read more

BOX.com: Multi-factor authentication has been canceled
B2B Cyber ​​Security ShortNews

The multi-factor authentication of Box.com could be bypassed by attackers. The Varonis research team discovered a way to replace MFA with classic one-factor authentication for box accounts. Box.com joins the long list of cloud providers where MFA vulnerabilities were recently uncovered: The Varonis research team discovered a way to replace MFA with classic one-factor authentication for Box accounts, the authentication -Use apps like Google Authenticator. Attackers with stolen credentials could compromise a company's box account and exfiltrate sensitive data without having to use a one-time password. Box.com vulnerability closed in the meantime Security researchers identified this vulnerability in Box on ...

Read more

How to prevent or reduce the impact of ransomware attacks
How to prevent or reduce the impact of ransomware attacks

The latest victims, such as Media Markt and Saturn, the medical service provider Medatixx and the US broker Robinhood, show the range of goals of ransomware attackers: Ultimately, every industry and every company is at risk. But: ransomware attacks can be prevented or their effects can be reduced. But even if ransomware acts like an inevitable evil, there are a number of measures that companies can take to prevent an attack and data loss in your business. Michael Scheffler, Country Manager DACH of the data security specialist Varonis Systems, recommends companies to observe and implement the following points in particular: Make the right preparations Sensitize your ...

Read more