On this week's episode, Andy and Adam talk about the 23andMe and Okta breach that happened recently along with some recommendations on how organizations can try and prevent similar attacks in the future. They also talk about a revolutionary new feature in Microsoft Defender for Endpoint called Automatic Attack Disruption. They talk about how it works and how organizations can take advantage of it even if MDE is not your incumbent or primary EDR/XDR.
Youtube Video Link: https://youtu.be/2gUn1ZszQ-w
Documentation:
https://techcrunch.com/2023/10/10/23andme-resets-user-passwords-after-genetic-data-posted-online/
https://www.wired.com/story/okta-support-system-breach-disclosure/
https://blog.1password.com/files/okta-incident/okta-incident-report.pdf
https://www.microsoft.com/en-us/security/blog/2023/10/11/microsoft-defender-for-endpoint-now-stops-human-operated-attacks-on-its-own/
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/automate-the-boring-for-your-soc-with-automatic-investigation/ba-p/1381038
Contact Us:
Website: https://bluesecuritypod.com
Twitter: https://twitter.com/bluesecuritypod
Threads: https://www.threads.net/@bluesecuritypodcast
Linkedin: https://www.linkedin.com/company/bluesecpod
Youtube: https://www.youtube.com/c/BlueSecurityPodcast
Twitch: https://www.twitch.tv/bluesecuritypod
Andy Jaw
Mastodon: https://infosec.exchange/@ajawzero
Twitter: https://twitter.com/ajawzero
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email: andy@bluesecuritypod.com
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email: adam@bluesecuritypod.com
--- Send in a voice message: https://podcasters.spotify.com/pod/show/blue-security-podcast/message