During a penetration test, login credentials are a highly sought-after item. While it is common to harvest that information via email scams (phishing attacks), it is not always the most practical or effective tactic to gain unauthorized access. That access, however, still requires a valid set of credentials. This poses a challenge. How does an attacker find valid accounts without social engineering? There are two main options: breached credentials and password spraying.
When in doubt, try "Password123" - How I guessed your password
Topics: Cybersecurity, Network Security, Data Protection, Personal Data Protection, Security Awareness Training, Passwords, Monitoring
Topics: Information Security, Data Protection, Personal Data Protection
Security Measures to Implement in 30-Seconds or Less on your Phone & Computer
As ProCircular’s resident young person without a background in security, I have learned an extraordinary amount of information about the importance of cybersecurity since starting at this company. I now think about how often my generation tends to overlook basic security features on our phones and computers which leaves us open to disastrous consequences in our personal or professional lives.
Topics: Cybersecurity, Personal Privacy, Personal Data Protection
At this point, everyone has probably heard a speech about how important it is to have a strong password. It is true that a strong password is extremely important in preventing an attacker from guessing or cracking it. However, it does not help against those annoying and ever-present phishing attacks when a user unknowingly hands over their password. And unfortunately, it’s almost inevitable that this will happen. This means that there will always be a question about the security of a password.
Topics: Cybersecurity, Information Security, Personal Data Protection, Passwords
Personal Privacy in the Wake of Reoccurring Data Breaches
It seems like every other week there is a new data breach in the news. Some notable incursions of 2016 were LinkedIn, Yahoo, and a new one as of December 5th, DailyMotion (a video hosting service).
Topics: Data Breach, Data Security, Personal Privacy, Personal Data Protection