Cloudflare employees were recently targeted by a “sophisticated” cyberattack, and even though some fell for the scheme, the DDoS protection company managed to successfully defend itself. 

In a blog post(opens in new tab), Cloudflare co-founder Matthew Prince, together with team members Daniel Stinson-Diess and Sourov Zaman, explained how the attack happened and what made the difference between success and failure.

The threat actor made a couple of key preparations ahead of the attack: they registered a domain that looked legitimate and would fool many victims: cloudflare-okta.com. Okta is Cloudflare’s identity provider. They also managed to somehow obtain the phone numbers of almost 80 Cloudflare employees, as well as family members for some.


More

TechCrunch: FIDO Alliance adds a biometrics certification program to help fight spoofing

The FIDO Alliance has launched a certification program for biometrics systems in a move aimed…

Read More →

Engadget: Biometric security now has an industry-wide testing standard

Engadget reports that FIDO Alliance has launched a first-of-its-kind Biometric Component Certification Program that will…

Read More →

VentureBeat: Hands-on with Google’s Titan Security Key, a $50 FIDO fob that secures your online accounts

VentureBeat reports that Google has launched its FIDO-based Titan Security Key for more secure user…

Read More →