CIO Brief: When a Dev Tool Breach Forces a Company-Wide Credential Reset
The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...
Insights
Articles in CIO Briefings.
The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...
The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...
The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...
The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...
The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....
The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....
The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release...
The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...
The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by...
The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run...
The short version: In 2022, Microsoft reorganized its identity products under a new brand, Entra — reflecting a shift the whole industry made: who you are...
The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...
The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by...
The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an...
The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...
The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a...
The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...
The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...
The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...
The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...
The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...
The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...
The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...
The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...