this post was submitted on 28 Oct 2024
7 points (100.0% liked)

Cybersecurity

5927 readers
103 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
top 1 comments
sorted by: hot top controversial new old
[ā€“] [email protected] 3 points 2 months ago

Arctic Wolf notes that apart from operating unpatched endpoints, compromised organizations did not appear to have enabled multi-factor authentication on the compromised SSL VPN accounts and run their services on the default port 4433.

Y'all... It's 2024, going on 2025. You have to enable at least MFA. Running without it is like going on the internet in the 90sā€“2000s without some kind of antivirus.