Kicksecure includes only essential, security-enhancing software while avoiding risky or unnecessary services, providing a clean and hardened base system.

#Kicksecure #MinimalSecureInstall #SecureDefaults #TrustedSoftware #OpenSource

#WordPressOrg will be mandating MFA for plugin developers starting Oct 1, 2024

The change is made to reduce risk of unauthorized access that can impact plugins used by millions of Wordpress users

Wordpress plugin developers are advised to enable MFA, and to review their credentials for pushing code updates

#cybersecurity #securedefaults

https://www.bleepingcomputer.com/news/security/wordpressorg-to-require-2fa-for-plugin-developers-by-october/

WordPress.org to require 2FA for plugin developers by October

Starting October 1st, WordPress.org accounts that can push updates and changes to plugins and themes will be required to activate two-factor authentication (2FA) on their accounts.

BleepingComputer

Microsoft will start enforcing MFA on Azure in July 2024.

The rollout will start with Azure Portal, then make its way to CLI, PowerShell and Terraform. Token-based accounts are excluded, and Microsoft is gathering feedback regarding break glass accounts.

This is a welcome move by Microsoft as MFA has been very effective in increasing the protection of user accounts.

#cybersecurity #securedefaults #MFA #Microsoft #Azure

https://www.bleepingcomputer.com/news/microsoft/microsoft-will-start-enforcing-azure-multi-factor-authentication-MFA-in-july-2024/

Microsoft to start enforcing Azure multi-factor authentication in July

Starting in July, Microsoft will begin gradually enforcing multi-factor authentication (MFA) for all users signing into Azure to administer resources.

BleepingComputer
#OpenSSL should have made the built-in default certificate validation function always fail if tlsext_host_name is set. This way it would have been obvious that the application must implement the proper hostname validation callback. #securedefaults #infosec #cybersecurity