Authentication sits at the heart of enterprise security, making passwords and the authentication mechanisms that use them, prime targets for cybercriminals. For more than 90% of organizations that use ...
Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.
TL;DR: Russian-linked group Midnight Blizzard (Cozy Bear) uses fake hotel Wi‑Fi "Evil Twin" networks and NTLM relay attacks to capture Windows authentication hashes and access accounts of traveling ...