CIO Brief: The Hidden Cost of Keeping Exchange On-Prem
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...
Insights
Articles in CIO Briefings.
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...
The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...
The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...
The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...
The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...
The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...
The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...
The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....
The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...
The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...
The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...
The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...
The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....
The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...
The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....
The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...
The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...
The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device...
The short version: In 2019, Microsoft introduced tools to detect when employees might be taking or leaking company data — for example, downloading large...
The short version: After Capital One's 2019 breach, AWS released a setting — IMDSv2 — that blocks the technique the attacker used to steal cloud...
The short version: In 2019, Microsoft released Security Defaults: a free, one-click setting that turns on multi-factor authentication and blocks older,...
The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor...
The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...
The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...