Network Security News | Ingalls Information Security

Articles of interest from the week of November 29, 2021

Written by John Frasier | Nov 29, 2021 5:00:00 AM

MFA Lulls Businesses Into A False Sense Of Security

Despite the technology’s generally sound design and widespread takeup, however, ongoing reports of MFA hacks confirm that it is far from invulnerable — and that security executives mustn’t rest on their laurels by treating the technology as a cure-all. (By David Braue, Cybercrime Magazine)


Sideloading Attacks: How a Malicious App Can Bring Down a Business

A new sideloading malware campaign targeting Windows uses phishing and social engineering tactics that can be difficult for users to spot. (By Michael Hill, CSO)


How Phishing Kits Are Enabling a New Legion of Pro Phishers

Phishing approaches are continually evolving to counter email security solutions, but even non-technical criminals can also easily take advantage of new techniques thanks to phishing kits. Mirroring out-of-the-box software bundles used by legitimate businesses, these kits provide a collection of tools that enable would-be criminals to quickly create and launch their own phishing campaigns. (By Magni Sigurðsson, Help Net Security


150+ HP Multifunction Printers Open To Attack 

Over 150 HP multifunction printers (MFPs) are open to attack via two exposed physical access port vulnerabilities (CVE-2021-39237) and two different font parsing vulnerabilities (CVE-2021-39238). (By Help Net Security


WFH Security: How To Protect Your Remote Endpoints 

Many organizations lack an effective patch management program, especially when it comes to patching remote systems, says Action1. (By Lance Whitney, TechRepublic