#cis

6 posts· Last used 2d

How average folks don't stand a chance against phishing, example #80,144,963: "Security" "Professionals" "Warning! Your account is about to be deactivated." Log in soon or terrible things will happen. Consider clicking on a link in this email. BUTTON [Click it... Click it... Click it...] Grey on grey because accessibility is for losers. Click the password manager plugin icon on a browser tab, start typing "cis...", click to open and autofill credentials and login (in one step), click the (old) password field to autofill, click to accept the suggested very long and random password suggestion which autofills both the new password field and the one to check that the autofill typed it correctly the first time then automatically submit, log out, and wait for the next email from Compliance Isn't Security inviting me to the next dance. For the historians: this is during the current wave of phishing campaigns claiming that your service is being shut down, retired, updated or otherwise changed in a way which requires you to click urgently before all that you love is lost. PS. "This email was sent with love from" PPS. NIST SP 800-63B §3.1.1.2 #6 - https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #InfoSec #InformationSecurity #CyberSecurity
1
1
1
0
Replying to @AJCxZ0@infosec.exchange
Not only is Center for Internet Security, Inc. (CIS) still sending these, but they still have no multi-factor authentication for accounts. From https://www.cisecurity.org/about-us The CIS Vision Leading the global community to secure our ever-changing connected world. The CIS Mission Our mission is to make the connected world a safer place by developing, validating, and promoting timely best practice solutions that help people, businesses, and governments protect themselves against pervasive cyber threats. https://www.youtube.com/watch?v=51gf648nRyE&t=118s #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #MFA #2FA #InfoSec #InformationSecurity #CyberSecurity
1
1
1
0
Replying to @AJCxZ0@infosec.exchange
While it may have taken them a moment, with the new CIS Portal for CIS Workbench, they have announced that, "When your account is ready, you'll be guided through a brief process to choose a primary verification method, .." Hardware tokens and/or passkeys, right? "..like SMS ..." When your account is updated, be sure to visit the Portal for "CIS-curated thought leadership and cybersecurity resources to help you put best practices into action" #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #MFA #2FA #InfoSec #InformationSecurity #CyberSecurity
0
1
0
0
Chairwoman of Russia's Federation Council Valentina Matviyenko congratulated the Heads of a number of parliaments and international organisations on International Day of Parliamentarism. In her letters to the heads of parliamentary chambers of #CIS and #BRICS countries, as well as friendly states, Chairwoman of Russia's Federation Council emphasised the commitment to expanding ties and deepening interparliamentary cooperation in both https://www.un.org/en/observances/parliamentarism-day
0
0
0
0
You've seen all posts