To gain root access at this company, all an intruder had to do was ask nicely
ID: c931c141-1764-578b-ba59-37ef52e999f8
STIX ID: report--c931c141-1764-578b-ba59-37ef52e999f8
Feed Name: The Register (Security)
Threat Score
This article describes real-world social-engineering failures during penetration tests where helpdesk staff reset executive passwords and entered caller-supplied passwords, allowing account takeover; it calls out weak verification procedures and recommends challenge-response and stricter password reset workflows to mitigate human-targeted attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
