Interesting

Tag: Office 365

Amazon postponing the implementing Microsoft’s cloud-based Office suite for its workforce due to security concerns

Matt Day, writing in Bloomberg »

Amazon paused the rollout after Microsoft discovered a Russia-linked hacker group had gained access to some of its employees’ email accounts. After conducting its own analysis of the software, Amazon asked for changes to guard against unauthorized access and create a more detailed accounting of user activity in the apps, some of which Microsoft also markets as Office 365.

It’s an unusual confluence of events: a massive commercial deal between two Seattle-area cloud-computing rivals, a state-sponsored hack, and an engineering collaboration that could improve the security of the world’s most widely used office productivity software.

“We deep-dived into O365 and all of the controls around it and we held – just as we would any of our service teams within Amazon – we held them to the same bar,” said CJ Moses, Amazon’s chief information security officer.

Security research team bypasses Microsoft Azure MFA with ease

Oasis Security’s research team has uncovered a critical vulnerability in Microsoft’s Multi-Factor Authentication (MFA) implementation, allowing cyber criminals to bypass it and gain unauthorized access to the user’s account, including Outlook emails, OneDrive files, Teams chats, and Azure Cloud, and other Office 365 services.

Oasis Security report that the bypass was simple, took around an hour to execute, required no user interaction. It did not generate any notification nor provide the account holder with any indication of trouble.

Oasis Security Research team’s full report »

Elsewhere » The Hacker News | Security Week

© 2024 Downshift

Theme by Anders NorenUp ↑