Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Office 365 Missed 34,000 Phishing Emails Last Month
Newest First  |  Oldest First  |  Threaded View
marklas1
100%
0%
marklas1,
User Rank: Apprentice
11/2/2017 | 3:08:11 PM
Re: Very low on usable and/or verifiable details
My first thought was regarding ATP and whether or not it was being used.  No email system offers anything beyond some basic features.  You will need to add an additional service to actually get ahead of the problem.
cdansbee
50%
50%
cdansbee,
User Rank: Apprentice
11/2/2017 | 11:33:21 AM
Re: Very low on usable and/or verifiable details
Agree completely! This article fails to produce any actual findings from any sources other than Microsoft's competition. Unfortunately, people will read the headline and jump to the conclusion that EOL is not a good option, which seems to be what the author is after. 

It seems Dark Reading may be chasing headlines on this one.
dmstork
100%
0%
dmstork,
User Rank: Strategist
11/1/2017 | 9:18:32 AM
Very low on usable and/or verifiable details
Unfortunatly the research paper is very low on details, which exact settings where used in Office 365 (default settings tend to change for new tenants) and whether or not Office 365 Advanced Threat Protection was added. Also, the exact setup is a little bit questionable as there are multiple layers of scanning (even down to mailbox level) that scanning takes place (also after the mail landed in the mailbox).

But looking at their website, it becomes clear that Exchange Online Protection is actually a direct competitor of theirs. That is a clear conflict of interest and IMHO should've been mentioned in this article otherwise this is just an elaborate ad...


Look Beyond the 'Big 5' in Cyberattacks
Robert Lemos, Contributing Writer,  11/25/2020
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I think the boss is bing watching '70s TV shows again!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26250
PUBLISHED: 2020-12-01
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authenticator.allowed_users` with a warning, is instead ignored by ...
CVE-2020-28576
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
CVE-2020-28577
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
CVE-2020-28582
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
CVE-2020-28583
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.