logo

IT service desks: The security blind spot that may put your business at risk

ID: ed01de48-1c75-5933-b4ae-073cad6a761b

STIX ID: report--ed01de48-1c75-5933-b4ae-073cad6a761b

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-10-15

Date Updated: 2026-05-01

...
...

The article warns that outsourced IT helpdesks are an expanding security blind spot: attackers use vishing, SIM‑swap, social engineering and synthetic voices to convince staff to reset credentials or disable MFA, enabling lateral movement and major breaches (citing LAPSUS$, Scattered Spider, MGM, Clorox). It recommends layered defenses—strong caller authentication, least privilege, separation of duties, comprehensive logging and monitoring, continuous agent training, technical controls for spoofing/deepfakes, and MDR services—to reduce supply‑chain/service‑provider risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.