social.heise.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Der Mastodon-Server von und für Heise Medien und insb. die Nachrichten von heise online.

Serverstatistik:

38
aktive Profile

#smb

0 Beiträge0 Beteiligte0 Beiträge heute

Did you know a ransomware tabletop exercise can uncover gaps and failure points in your incident response plan? A recent study found it can also reduce your data breach costs by an average of $248K! If you have not planned a ransomware tabletop exercise already, it's time to put this on your schedule!

In our new blog, we share common failure points, @MDurrin's favorite ransomware tabletop exercise scenarios, and tips to help you get the most out of your next exercise.

Read the blog: lmgsecurity.com/how-a-ransomwa

LMG SecurityHow a Ransomware Tabletop Exercise Can Dramatically Reduce Your Losses If You’re Attacked | LMG SecurityA Ransomware Tabletop Exercise is one of the best ways to test your organization’s ability to handle an attack, identify process gaps, & ensure a rapid response that reduces your losses. Read our favorite scenarios and tips!

An open sourcxe AI traiing dataset lheld 12,000+ API keys & passwords! New research from Truffle Security uncovered nearly 12,000 valid API keys and passwords embedded in AI training datasets from Common Crawl—a widely used open-source web archive. These leaked secrets include AWS root keys, MailChimp API keys, and Slack webhooks, which can expose companies to data breaches, phishing, and supply chain risks.

As AI adoption grows, organizations must secure their code, scan for exposed credentials, and enforce strict key management policies to prevent unauthorized access and data leaks.

Read more details: ow.ly/Esop50V9vPT

#Cybersecurity #AISecurity #GenAI #AI #Databreach #APIsecurity #Infosec #RiskManagement #CISO #Cyberaware #SMB #CEOet/

BleepingComputer · Nearly 12,000 API keys and passwords found in AI training datasetVon Ionut Ilascu

It is insane how much faster sshfs is in #macos #finder compared to apple's native #smb implementation. Sadly, sshfs has problems handling file paths containing Umlauts.

I mean, I can browse my directory from my server containing over 200 video files without any issues on sshfs. And if I try the same via smb the finder starts to lagg and hangs. And the initial listing takes forever. With sshfs 1-2s. SMB 10-20s.

I hope the small #indie company named #apple can fix this at some point *sigh*

Härtung des Dateitransfers: Microsoft sichert das SMB-Protokoll ab

Mit zwei Maßnahmen sichert Microsoft sowohl die SMB Client- als auch die Serverseite besser ab. Wir zeigen, worauf Administratoren achten müssen.

heise.de/news/Haertung-des-Dat

Hello #Fediverse !
An #Introduction post from the scientists behind the #PolarPortal - a danish collaboration between the Danish Meteorological Institute, the Danish Technical University and GEUS with accurate near real-time #Climate data on the state of the #cryosphere in the #Arctic.
Follow us for data + visualisations of #ArcticSeaIce #Weather #GreenlandIceSheet #SMB and #GRACE / #GRACEFO mass budget as well as #permafrost +#Iceberg processes

@greenlandicesheet

polarportal.dk/en/home/

Happy #WorldPasswordDay!

I've cracked billions of #passwords from tens of thousands of #data #breaches in the past 12+ years, and because of this, I likely know at least one #password for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in #AccountTakeover and #CredentialStuffing attacks.

How can you keep your accounts safe?

- Use a #PasswordManager! I recommend @bitwarden and @1password

- Use a #Diceware style #passphrase - four or more words selected at random - for passwords you have to commit to memory, like your master password!

- Enable MFA for important online accounts, including cloud-based password managers!

- Harden your master password by tweaking your password manager's KDF settings! For #Bitwarden, use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For #1Password and other PBKDF2 based password managers, set the iteration count to at least 600,000.

- Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

- Use an ad blocker like #uBlock Origin to keep you safe from password-stealing #malware and other browser based threats!

- Don't fall for #phishing attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

- #Enterprises: require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable #NTLM authentication and disable RC4 for #Kerberos, disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory #SMB signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

Interne Apps: Warum sich Mitarbeiter-Apps auch für kleine Unternehmen lohnen

Interne Apps werden oft als Luxus großer Unternehmen angesehen. Doch gerade auch Start-Ups setzen gerne auf Custom Apps. Was sie sich davon versprechen.

heise.de/hintergrund/Interne-A

#AppStore#Apple#Apps