this post was submitted on 19 Feb 2024
258 points (97.4% liked)

Cybersecurity

5689 readers
102 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
 

For the first time in the history of Microsoft, a cyberattack has left hundreds of executive accounts compromised and caused a major user data leak as Microsoft Azure was attacked.

According to Proofpoint, the hackers use the malicious techniques that were discovered in November 2023. It includes credential theft through phishing methods and cloud account takeover (CTO) which helped the hackers gain access to both Microsoft365 applications as well as OfficeHome.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 14 points 9 months ago (1 children)

work on service desk.

Nobody knows their password.

If they did they wouldn't be contacting the service desk.

[–] [email protected] 10 points 9 months ago (1 children)

I often get confused at how someone could log into the computer and yet after that is done have no idea what their password is. I sometimes have them lock their computer so they can remember it again. Facepalm.

[–] [email protected] 10 points 9 months ago (1 children)

Been on both ends of this (IT support and "forget password after entering it correctly"). The secret is muscle memory/subconcious habit.

Used to have the same issue with the dial combo lock on my locker at school. If I thought about it I could never open it. If I distracted myself just enough then I'd get it open without really knowing what I did.

That said, at my place we had someone forgetting their password literally minutes after a call to have it reset, multiple times a day. Don't know what the issue was, but we had to escalate it to HR and the person was out for a good while.

[–] [email protected] 8 points 9 months ago

Totally agree about the muscle memory. I recall having access to a CO DNR database at a previous job. It was one of three alphanumeric passwords assigned to me with no option to change them. I realized one day after having my hand in the wrong place on the keyboard that I didn’t really remember it, but my subconscious did