TechTarget: Amazon’s decision to abandon Active Directory proves successful

TechTarget: Amazon’s decision to abandon Active Directory proves successful

At the recent AWS re:Inforce security conference, executives highlighted Amazon’s strong security culture, developed over many years with consistent focus and investments. Amazon’s decision to build its own identity system, Midway, proved to be crucial during the SolarWinds attack of December 2020, which exploited weaknesses in Microsoft’s Active Directory and Azure environments. The SolarWinds attack, … Read more

VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

Feb 21, 2024NewsroomActive Directory / Vulnerability VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) following the discovery of a critical security flaw. Tracked as CVE-2024-22245 (CVSS score: 9.6), the vulnerability has been described as an arbitrary authentication relay bug. “A malicious actor could trick a target domain user with EAP installed … Read more