Cybercriminals have been busy this summer, and many of the attacks have targeted Active Directory. In the month of July alone, attackers exploited Microsoft vulnerabilities that led to the PrintNightmare and PetitPotam attacks, in addition to other flaws that were not directly related to Active Directory. The REvil ransomware group…
Organizations are gravitating toward a hybrid identity management model: As cloud adoption increases, the ability to manage both on-premises and cloud access is a business requirement. For most companies, leveraging the cloud means integrating with Azure Active Directory (AAD). But integrating on-premises Active Directory with AAD authentication requires a different…
Après une compromission, comment limiter le temps d’indisponibilité de l’AD, pour redémarrer les activités au plus vite ?
Active Directory exploitation is the common thread in recent high-profile attacks. Colonial Pipeline, SolarWinds, Hafnium – every day we hear about a new attack, a new vulnerability, and devastating consequences. Almost every attack is centered on finding a foothold in Active Directory, escalating privileges, and wreaking havoc. The exposure is…
AD est une cible préférée des attaquants. C’est pourquoi, un audit régulier est nécessaire pour identifier et corriger les vulnérabilités avant que les pirates ne le fassent.
For more than two decades, Microsoft Active Directory (AD) has been the de facto method organizations use to authenticate and authorize users so they can access computers, devices, and applications within a network. AD is celebrated for its ease of management. But that ease of use comes with security downsides.…
Is Your Core Identity System Ready for Today's Threats? Active Directory is used for identity management by 90% of businesses. But this 20-year-old technology is increasingly under attack by cyber-criminals who use AD to gain access to your network — and your data. Recent incidents like the Hafnium attack on…
Disaster Recovery (DR) strategies have traditionally focused on natural disasters, then expanded into other physical events such as terrorism. Today, cyber weaponization is everywhere, and the "extinction event" is a genuine threat with no respect for geographic boundaries. Presented by 15-time Microsoft MVP and identity security expert Sean Deuby (Semperis…
As cyber-attacks increasingly target Active Directory as an initial entry point, the role of AD engineers and architects is rapidly expanding to include security responsibilities. At the same time that AD engineers must secure access to cloud applications, they must also guard against attackers that take advantage of AD configuration…
Nous présentons un récapitulatif des cyberattaques en France ainsi que des pistes d'améliorations de la sécurité de votre Active Directory avant, pendant et après une cyberattaque.