Jump to content
  • Hacker finds a way to steal Windows 365 user names and passwords


    Karlston

    • 637 views
    • 1 minutes
     Share


    • 637 views
    • 1 minutes

    Microsoft touts Windows 365, Microsoft’s cloud PC solution, as being much safer than running software directly on your PC, but hackers have already found a way to exploit the remote access software to steal your user name and password credentials.

     

     

    Security researcher Benjamin Delphy achieved this feat by using a combination of tools. He used the Mimikatz tool, which can read passwords from memory, and an exploit of Windows Terminal he discovered which lets him decrypt the password to deliver the user name and password users use for Windows 365.

     

    These credentials can then be used to access other resources on a network and spread from computer to computer, likely installing ransomware in the process.

     

    Delphy notes that Windows Hello, Smartcards and other 2FA may have helped prevent this attack, but that Windows 365 relies on user names and passwords, so is not easy to protect.

     

    Read all the detail associated with the hack at BleepingComputer here.

     

     

    Hacker finds a way to steal Windows 365 user names and passwords


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...