Quote for the day:
“The most important thing in communication is hearing what isn’t said.” -- Peter F. Drucker
🎧 Listen to the audio debrief on YouTube
▶ Play Audio DigestDuration: 22 mins • Perfect for listening on the go.
How MFA gets hacked — and strategies to prevent it
Multifactor authentication (MFA) is a standard security measure, but improper
implementation often leaves organizations vulnerable to sophisticated attacks.
While MFA adoption is growing, attackers continually find ways to bypass these
defenses across various platforms and devices. Common attack methods fall into
several categories. Attackers frequently use MFA fatigue, which involves
overwhelming a user with approval requests until they relent and grant access.
Social engineering tactics, such as phishing, voice phishing, and SIM swapping,
are also used to trick individuals into handing over their authentication codes.
Additionally, attackers can bypass MFA entirely by stealing authentication
cookies or targeting legacy systems and accounts that lack strong authentication
protocols. To protect against these threats, organizations must strengthen their
MFA strategies. This begins with identifying critical assets and using strong
tools like hardware keys and biometric verification. Using flexible
authentication that continuously checks for risk during a session is more
effective than relying on a single login check. Organizations should also
strictly manage user access rights to ensure individuals only have the
permissions they actually need. Regularly reviewing authentication workflows and
securing vulnerable processes, such as password resets, are essential steps.
Finally, applying the strongest security measures to important accounts, like
administrators, helps minimize the risk of severe breaches.
Former Citigroup CISO Blauner on What Makes A Great Security Leader
In a recent interview, former Citigroup executive Charles Blauner reflects on the evolution of the chief information security officer role over the past three decades. Having served as a CISO at major financial institutions since the early days of the profession, Blauner explains how the position has shifted from a purely technical job to a strategic leadership role. He credits Steve Katz, often considered the first CISO, for building a culture of collective defense and generous mentorship that still shapes the field today. Blauner advises aspiring professionals to develop a broad and diverse network of both mentors and mentees to navigate the industry. He notes that the CISO role is uniquely demanding compared to other executive positions because it is the only executive position facing an active adversary whose primary goal is to bypass the organization's defenses. To succeed in this challenging environment, modern security leaders must look beyond technology and focus on building lasting operational resilience. Furthermore, Blauner emphasizes the importance of clear communication. Rather than relying on complicated technical terms, effective CISOs must translate security risks into practical business impacts. By explaining how threats directly affect core operations and products, security leaders can better align their strategies with broader corporate goals.Why the future of network security is the convergence of SASE and firewalls
The initial excitement around Secure Access Service Edge suggested that all
physical network security hardware would soon be replaced entirely by
cloud-based solutions. However, the tech landscape is clearly moving in a
different direction. With the rapid growth of edge computing, connected
devices, and local artificial intelligence applications, physical network
locations are becoming much more complex. Processing data locally generates
significant internal traffic. Routing all of this data to the cloud for basic
security checks creates unacceptable delays and drives up bandwidth costs
unnecessarily. Because high-performance computing is increasingly happening
locally, security enforcement must be stationed right alongside it to maintain
both speed and efficiency. The industry is moving away from choosing between
legacy hardware and cloud security. Instead, the clear focus is on merging
both approaches into a unified framework. Managing separate systems for local
and cloud security creates unnecessary operational hurdles and fragmented
policies. By integrating physical firewalls and cloud security under a single
operating system, IT teams can establish a consistent defense strategy. This
sensible convergence allows for shared threat intelligence and simplified
management across the entire network. Ultimately, treating physical and cloud
security as two parts of a cohesive whole is the most practical way to protect
modern data environments.UK fintech faces tougher oversight as rules tighten
UK fintech companies are preparing for stricter regulatory oversight as
authorities expand their focus to include critical cloud infrastructure and
installment payment services. The UK government and the Financial Conduct
Authority are setting new standards that require providers to rethink their
product designs and risk management strategies. Regulators now recognize major
cloud platforms as essential financial infrastructure, ensuring better
resilience for the banks and insurers that rely on them. Experts suggest that
artificial intelligence systems could soon face similar scrutiny as they
become more embedded in financial operations. In the consumer space, new rules
for buy now, pay later products aim to deliver better shopper protections,
such as real affordability checks and limits on fees. Companies are adapting
by aligning their business models with these stricter standards, often by
operating within existing regulated credit frameworks rather than issuing new
debt. At the same time, investors are demanding much greater transparency and
robust data management from fintech firms. Securing funding now requires a
strong foundation in data analytics, moving beyond simple revenue figures to
granular transactional insights. Founders who prioritize early investment in
secure data systems will be much better positioned to answer investor
questions, integrate new technologies, and build long-term business resilience
going forward.
A major Windows 11 UI redesign is coming, Microsoft is dumping legacy code for WinUI
Microsoft is redesigning the Windows 11 interface by replacing older software
code and web applications with its native user interface framework, WinUI.
Historically, Windows 11 has struggled with visual inconsistencies, placing
modern panels alongside outdated menus and relying on web wrappers because
developers lacked faith in Microsoft's commitment to previous design tools.
Now, the company is demonstrating a clear shift by fully rebuilding
foundational elements, such as the File Explorer Properties menu and the Run
dialog, directly in WinUI instead of just applying superficial themes or dark
mode patches. Other older menus, like the file copy prompt and local account
switch screen, are also scheduled for similar updates. While initial data
shows the new Run dialog loads faster than its predecessor, the broader WinUI
framework still has notable performance challenges. Current issues include
high memory usage, slower loading times in areas like the File Explorer Home
tab, and visual tearing when resizing applications. Recognizing these
problems, Microsoft is delaying the WinUI rewrite of more complex features,
such as the Start menu, until the underlying framework becomes more efficient.
Overall, the company aims to establish a unified and responsive interface,
provided it can resolve the current speed and stability limitations of its new
system.Beyond Deadlines: CMMC As A Continuous Enterprise Risk Governance Challenge
The Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program is no longer just a compliance hurdle with a fast-approaching deadline. Instead, it represents a permanent shift in how defense contractors must manage enterprise risk. CMMC certification is a continuous requirement for doing business with the government, transforming cybersecurity from a routine IT task into a critical business continuity issue. Failure to achieve or maintain certification directly threatens revenue by limiting an organization's ability to win or keep contracts. Beyond daily operations, CMMC introduces significant financial uncertainty, as certification costs and potential delays must be factored into accurate revenue forecasting. It also exposes hidden vulnerabilities in the defense supply chain. Prime contractors rely heavily on smaller subcontractors who may struggle to meet the strict regulatory standards, potentially disrupting entire projects. Furthermore, CMMC introduces unprecedented personal legal liability. A designated senior official must personally affirm the accuracy of the company’s security posture. Inaccurate affirmations can lead to severe legal consequences under strict federal laws like the False Claims Act. Ultimately, boards of directors and risk officers must recognize CMMC as a fundamental, cross-functional governance challenge. Success requires moving these discussions directly into the boardroom, treating certification as a dynamic risk factor that affects finance, procurement, legal, and overall corporate strategy.Business transformation needs a true economic approach, not guesswork
Most organizations approach business changes by focusing heavily on cutting
costs and improving efficiency. They look at how fast a task is completed and
how much money can be saved by streamlining or automating it. While these are
valid goals, efficiency alone does not show the true worth of a process.
Improving a bad process just makes it fail faster, and finding ways to save
time does not guarantee that the task creates any real value for the company.
Because of this narrow focus on expenses, a large majority of transformation
efforts fall short of their goals. A more effective method is economic process
modeling, which examines the full picture rather than just the costs. This
approach breaks down tasks and evaluates them based on five clear factors: how
they contribute to revenue, the actual expenses involved, the risks they
carry, the future options they leave open, and the value of the information
they produce. By looking at data as a genuine asset rather than a simple
byproduct, teams can make smarter decisions about which activities truly
matter. Taking an economic approach provides a solid foundation for change,
ensuring that improvements deliver lasting and meaningful results instead of
just temporary savings.
Mythos Asks the Right Question. It Doesn't Answer It.
As artificial intelligence models like Anthropic's Mythos accelerate how
quickly vulnerabilities can be exploited, security teams are realizing that
their current methods of handling risks are no longer enough. The core issue
is not simply the speed of these new threats, but rather how organizations
decide which problems to fix first. Currently, most teams rely on traditional
severity scores to manage massive lists of software flaws. This approach lacks
important context, such as whether a vulnerable system is exposed to the
internet, who has access to it, and if it connects directly to sensitive
company data. Without understanding these practical details, teams waste time
on issues that pose no real danger while missing critical paths that attackers
could easily use. Instead of replacing existing security tools or just trying
to patch everything faster, organizations need to connect the information they
already have. By linking data about user access, cloud settings, and network
structures, teams can see exactly how an attacker might reach their most
important information. Platforms like Mesh gather these different signals into
one clear picture, allowing teams to confidently identify and fix the few
actual threats that matter, rather than getting lost in thousands of
theoretical warnings.
A recent report by ReliaQuest reveals a sophisticated DNS poisoning campaign
targeting the hospitality sector, including hotels and conference centers.
Since June 2026, threat actors have been compromising captive Wi-Fi gateways
to quietly hijack corporate accounts. By gaining initial access through
exposed management interfaces and weak administrative credentials, these
attackers bypass security measures without ever touching user endpoints or
sending phishing emails. Once in control of a gateway, they modify
configurations and use DNS poisoning to stealthily redirect legitimate web
traffic to infrastructure they control. A particularly alarming aspect of this
attack is the abuse of device-code authentication. Attackers redirect users to
legitimate-looking Microsoft authorization prompts. If approved, the attacker
receives a valid, multi-factor authentication-bypassing OAuth token. This
campaign mirrors the tactics of FrostArmada, an earlier operation linked to
the Russian threat group APT28. However, experts note a shift from surgical
targeting to non-selective redirection, capturing valuable data from any
connected user. Security professionals emphasize that compromised shared
networks turn a single breach into a massive risk, exposing hundreds of
corporate devices at once. To mitigate these risks, organizations are strongly
advised to immediately implement always-on, full-tunnel VPNs to securely route
their DNS requests before they interact with potentially vulnerable public
gateways.
DNS Poisoning Campaign Makes Hospitality Wi-Fi Spots Inhospitable
A recent report by ReliaQuest reveals a sophisticated DNS poisoning campaign
targeting the hospitality sector, including hotels and conference centers.
Since June 2026, threat actors have been compromising captive Wi-Fi gateways
to quietly hijack corporate accounts. By gaining initial access through
exposed management interfaces and weak administrative credentials, these
attackers bypass security measures without ever touching user endpoints or
sending phishing emails. Once in control of a gateway, they modify
configurations and use DNS poisoning to stealthily redirect legitimate web
traffic to infrastructure they control. A particularly alarming aspect of this
attack is the abuse of device-code authentication. Attackers redirect users to
legitimate-looking Microsoft authorization prompts. If approved, the attacker
receives a valid, multi-factor authentication-bypassing OAuth token. This
campaign mirrors the tactics of FrostArmada, an earlier operation linked to
the Russian threat group APT28. However, experts note a shift from surgical
targeting to non-selective redirection, capturing valuable data from any
connected user. Security professionals emphasize that compromised shared
networks turn a single breach into a massive risk, exposing hundreds of
corporate devices at once. To mitigate these risks, organizations are strongly
advised to immediately implement always-on, full-tunnel VPNs to securely route
their DNS requests before they interact with potentially vulnerable public
gateways.