Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: authentic Clear Filter

Microsoft Will Wipe Out Your Passwords on Aug. 1. What to Do Now

Microsoft is getting rid of passwords in less than two weeks. On Aug. 1, the Microsoft Authenticator app will no longer store or manage passwords, which could be a problem for a lot of users. Microsoft Authenticator has been one of the best password managers for years. You were able to save passwords, enable two-factor authentication and auto-fill. This change means that if you're using the Authenticator app as a password manager, you'll need to look for another option soon. At the same time,

Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack

A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals. The PoisonSeed threat actors are known to employ large-volume phishing attacks for financial fraud. In the past, distributing emails containing crypto seed phrases used to drain cryptocurrency wallets. In the recent phishing attack observed by Expel, the PoisonSeed threat actors

Microsoft Will Erase Your Passwords in 2 Weeks: What to Do Now

Microsoft is axing passwords starting in August -- and if you use its Authenticator app, you'll want to be prepared. For years, Microsoft Authenticator has been a go-to for managing multifactor authentication and saved passwords. However, starting next month, it will no longer support passwords and will move to passkeys instead. That means your logins will soon rely more on things like PINs, fingerprint scans or facial recognition. Using a passkey can make your account safer, and it's a move I

UK ties GRU to stealthy Microsoft 365 credential-stealing malware

The UK National Cyber Security Centre (NCSC) has formally attributed ‘Authentic Antics’ espionage malware attacks to APT28 (Fancy Bear), a threat actor already linked to Russia’s military intelligence service (GRU). The NCSC revealed in a detailed technical analysis of the Authentic Antics malware dated May 6th that it is stealing credentials and OAuth 2.0 tokens that allow access to a target's email account. The malware was observed in use in 2023 and runs inside the Outlook process and produ

Gmail's backup codes are useless to access account

Ok, I have a work account on Gmail. Having the experience of being locked out of Gmail previously (endless loop of "You are entering the correct password but we're not sure that it is you, try again later"), I created a 2fa via Google Authenticator and set up Backup Codes and thought I'm safe from them asking me to sign in on another device or enter sms code (I don't carry that phone with me). So, one sunny day I decided to add standard iOS mail app to this account, and lo, an hour after connec

Pull Interactions from POSSEd Content

I just introduced a new feature on the website! 🎉 As usual, whenever content is POSSEd (Publish (on your) Own Site, Syndicate Elsewhere), you will find links to the syndicated content at the bottom of the page. Now, you will also see a small link to “toggle the interaction crawler”. This will open (or hide) a small form, where you can select available (and supported) social media platforms to crawl for interaction counts. This is in line with what I was discussing a few weeks ago about webmen

Forget passwords often? Android may soon let you disable Failed Authentication Lock (APK teardown)

Mishaal Rahman / Android Authority TL;DR Android 15 and newer devices include a Failed Authentication Lock feature that locks the device screen after detecting multiple failed login attempts in apps or settings. Unlike other theft protection features, this feature is enabled by default on all devices, and there’s currently no way for users to turn it off. Google may soon add a new option to the theft protection settings that will allow users to turn off Failed Authentication Lock. In additio

Microsoft Plans to Purge Passwords — Here's How to Protect Yours

Microsoft is moving closer to a password-free future, and if you're still using the Authenticator app to manage logins, big changes are coming fast. Starting Aug. 1, the app will no longer support passwords at all. This shift has already been in motion-new password creation was disabled in June, and autofill support was cut off in July. For years, Microsoft Authenticator was a go-to for managing both multi-factor authentication and saved passwords. But now, it's being refocused to support passk

How passkeys work: Going passwordless with public key cryptography

Vitalii Gulenok/Getty Images For the last five years, the FIDO Alliance -- led by Apple, Microsoft, and Google (with other companies in tow) -- has been blazing a trail toward a future where passwords are no longer necessary in order to login to our favorite websites and apps. This so-called passwordless future is based on a new form of login credential known as the passkey, which itself is largely based on another technology -- public key cryptography -- that's been around for decades. Why t

How passkeys work: Let's start the passkey registration process

Photoraidz/Getty Images Previously on our passkey journey, I talked about the challenge of figuring out if a relying party -- typically, the operator of a website or app -- even offers the ability to sign in with a passkey instead of the more traditional and less secure username and password-based approach. Some of the biggest relying parties in the world -- including Apple, Google, and Microsoft -- support passkeys as a means of passwordless authentication. Together, these tech giants can int

The MFA You Trust Is Lying to You – and Here's How Attackers Exploit It

Still getting login codes via text or authenticator apps? You’re not alone—and that’s a big problem. What used to feel like a smart security layer is now one of the easiest ways for attackers to gain access to your accounts. First we were told to use SMS for MFA. Then we were told: “Don’t use SMS for MFA, use an authenticator app instead.” And while that may seem like a step forward, it’s still fundamentally flawed. Authenticator apps do improve over SMS by avoiding message interception, but t

Next month, saved passwords will no longer be in Microsoft’s Authenticator app

Starting this month, you'll no longer be able to use Microsoft Authenticator's autofill password function, a move the company is making to transition from passwords to passkeys. Last month, Microsoft stopped letting you save new passwords in the app. Next month is the biggest change, all your saved passwords will no longer be in the Authenticator app. You'll have to use passkeys instead -- such as a PIN, fingerprint or facial recognition. Attila Tomaschek, CNET's software senior writer and dig

Microsoft Will Delete Your Passwords in One Month

Starting this month, you'll no longer be able to use Microsoft Authenticator's autofill password function, a move the company is making to transition from passwords to passkeys. Last month, Microsoft stopped letting you save new passwords in the app. Next month is the biggest change, all your saved passwords will no longer be in the Authenticator app. You'll have to use passkeys instead -- such as a PIN, fingerprint or facial recognition. Attila Tomaschek, CNET's software senior writer and dig

Citrix warns of login issues after NetScaler auth bypass patch

Citrix warns that patching recently disclosed vulnerabilities that can be exploited to bypass authentication and launch denial-of-service attacks may also break login pages on NetScaler ADC and Gateway appliances. This happens because starting with NetScaler 14.1.47.46 and 13.1.59.19, the Content Security Policy (CSP) header, which mitigates risks associated with cross-site scripting (XSS), code injection, and other client-side attacks, is enabled by default. However, while it is designed to b

Microsoft Authenticator won't manage your passwords anymore - here's why and what's next

gyro/Getty Images Those of you who use Microsoft Authenticator as a password manager will have to find another option, and soon. That's because an upcoming change will pull the plug on the ability to use the Authenticator app to store and autofill passwords. In a recent support document, Microsoft revealed the timeline for Authenticator's retirement as a password manager. Starting in June, you'll no longer be able to add or import new passwords in the app, though you'll still be able to save p

If you're using Microsoft Authenticator to store your passwords, don't

Microsoft Authenticator is sunsetting its ability to store your passwords. This month, the service stopped allowing users to add or import new passwords. Beginning in July 2025, users will no longer be able to use autofill with Authenticator, and in August 2025, passwords will no longer be available at all. Payment information stored in Authenticator will be deleted after July, and after the following month, all unsaved generated passwords will be deleted. Passkeys will still be supported in Aut

Reminder: Microsoft Authenticator is dropping password autofill in July

Heads up if you’ve been using Microsoft Authenticator as a password manager: the app is phasing out support for password autofill, and all saved passwords will be deleted by August. Here’s what to do. The changes are part of Microsoft’s plan to consolidate its credential management tools under the Edge browser. Going forward, password autofill will only be available through Edge, not Authenticator. What’s changing, and when Starting June 2025, you will no longer be able to Add or Import new p

Microsoft Authenticator will soon ditch passwords for passkeys - here's what to do

ZDNET Those of you who use Microsoft Authenticator as a password manager will have to find another option, and soon. That's because an upcoming change will pull the plug on the ability to use the Authenticator app to store and autofill passwords. In a recent support document, Microsoft revealed the timeline for Authenticator's retirement as a password manager. Starting in June, you'll no longer be able to add or import new passwords in the app, though you'll still be able to save passwords thr

Microsoft Authenticator is ending support for passwords

is a news writer who covers the streaming wars, consumer tech, crypto, social media, and much more. Previously, she was a writer and editor at MUO. Microsoft will soon no longer let you use its Authenticator app to store or autofill passwords. Starting in July, you won’t be able to autofill saved passwords using Authenticator, and you’ll have to use Microsoft Edge or another password management solution instead. Microsoft also plans on deleting your saved payment information in Authenticator t

Identity theft hits 1.1M reports — and authentication fatigue is only getting worse

Join the event trusted by enterprise leaders for nearly two decades. VB Transform brings together the people building real enterprise AI strategy. Learn more From passwords to passkeys to a veritable alphabet soup of other options — second-factor authentication (2FA)/one-time passwords (OTP), multi-factor authentication (MFA), single sign-on (SSO), silent network authentication (SNA) — when it comes to a preeminent or even preferred type of identity authentication, there is little consensus amo

Microsoft Is Ditching Passwords for Passkeys: How to Switch Before the August Deadline

Did you know there's a safer alternative to passwords? Some companies are implementing passkeys, which essentially use your biometric data, like fingerprint or facial recognition to log into your account as the first step. Passkeys can cut out risky password habits that 49% of US adults have, according to a recent CNET survey. Using the same password for multiple accounts and even using personal information, like your name, as a part of your password can lead to hackers guessing it or your pass

RIP Microsoft Passwords: Here's How to Set Up a Passkey Before the August Deadline

Risky password habits can have big consequences, and some companies are making it easier to stay secure online by ditching decades-old password methods and implementing passkeys instead. Microsoft intends to do the same starting in August. Whether you have an easy-to-guess password or it's leaked in a company data breach, if hackers get hold of it, it can open the door to identity theft and fraud. A recent CNET survey found that 49% of US adults have risky password habits, like using the same p

Microsoft confirms auth issues affecting Microsoft 365 users

Microsoft is investigating an ongoing incident that is causing users to experience errors with some Microsoft 365 authentication features. As the company revealed earlier today in an incident alert published in the admin center, users may experience errors during self-service password resets, while admins may be unable to add multi-factor authentication (MFA) sign-in methods to some users. Redmond says this incident is caused by a recent change aiming to improve MFA sign-in functionality. Sinc

Trend Micro fixes critical vulnerabilities in multiple products

Trend Micro has released security updates to address multiple critical-severity remote code execution and authentication bypass vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer products. The security vendor underlines that it has seen no evidence of active exploitation in the wild for any of them. However, immediate application of the security updates is recommended to address the risks. Trend Micro Endpoint Encryption PolicyServer is a central managemen

Frequent reauth doesn't make you more secure

Frequent reauth doesn't make you more secure You're happily working away, fingers flying, deep in flow, and suddenly, boink, your session has expired. You sigh, re-enter your password (again), complete an MFA challenge (again), maybe approve an email notification (again), and finally — access restored. Until next time. This wasn't so bad when it was just passwords; we all got pretty fast at retyping our passwords. But all those MFA challenges really slow us down. And MFA fatigue attacks, a gro

Microsoft fixes Windows Server auth issues caused by April updates

Microsoft has fixed a known issue causing authentication problems on Windows Server domain controllers after installing the April 2025 security updates. Platforms affected by these problems include Windows Server 2016, Windows Server 2019, Windows Server 2022, and the latest version, Windows Server 2025. However, as Microsoft further explained when it acknowledged this known issue in early May, home users are unlikely to be impacted since domain controllers are typically used in enterprise aut