CISA warns Windows users of new spear-phishing threats and security measures

forbes.com November 3, 2024, 11:00 AM UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned Windows users about new email threats, particularly a large-scale spear-phishing campaign targeting various sectors, including government and IT. CISA advises against using SMS-based multifactor authentication (MFA) due to its vulnerability to attacks. Spear-phishing is a more targeted form of phishing that can be harder to detect. CISA reports that attackers are using emails with malicious remote desktop protocol (RDP) files to gain access to networks, increasing the risk of data breaches. CISA has released a top-ten list of security measures for organizations, emphasizing the importance of enabling MFA while avoiding SMS options. Stronger alternatives, such as software authenticators or passkeys, are recommended for better protection against cyber threats.


With a significance score of 3.4, this news ranks in the top 14% of today's 17662 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 8000 minimalists.