Panel

Noticias Financieras

Google AdSenseNews Headernews_header
Mandiant pushes organizations to dump insecure NTLMv1 by releasing a way to crack it
computerworld_nzhace 21d

Mandiant pushes organizations to dump insecure NTLMv1 by releasing a way to crack it

Google’s Mandiant security division has come up with an unusual tactic to persuade organizations to stop using the aged and hugely insecure NTLMv1 authentication protocol: publish a data lookup that makes cracking NTLMv1 credentials trivial for attackers.The intention, Mandiant explained, is to draw attention to the fact that, despite decades of evidence that NTLMv1 (NT LAN Manager version 1) is insecure, organizations continue to use it. Anyone can use Mandiant’s Net-NTLMv1 pre-computed rainbow table lookup, downloadable from the Google Cloud Research Dataset portal, to map a given server response to reconstruct a real NT hash.Hashes, of course, are mathematical representations of real passwords, but are just as useful to criminals when exploited using techniques such as pass-the-hash. The benefit is time and money saved: Mandiant reckons its rainbow table allows the recovery of an NTLMv1 key in 12 hours using a computer costing $600, rather than relying on third party services or expensive hardware to brute-force the keys.None of this makes NTLMv1 less secure or easier to target than it already is. Mandiant’s hope is that the release of the table will serve as a reminder that the problem exists, prompting organizations to finally rip out NTLMv1 from their networks.“This legacy protocol leaves organizations vulnerable to trivial credential theft, yet it remains prevalent due to inertia and a lack of demonstrated immediate risk,” the company said in its announcement. “By releasing these tables, Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1.”Long fallbackNTLMv1 is a 1990s challenge-response protocol used to authenticate Windows NT users to Active Directory (AD). Based on 1980’s Data Encryption Standard (DES) encryption, it was updated to the more secure NTLMv2 in 1996 before being completely replaced by Kerberos. Unfortunately, legacy protocols like NTLMv1 don’t just disappear, and are retained as a fallback in case they are needed by older applications. That fallback has turned out to last decades.What evidence does Mandiant have that organizations are still using NTLMv1? The first is anecdotal: “Mandiant consultants continue to identify its use in active environments,” the company noted in last week’s announcement.Secondly, cyberattackers regularly target it. For example, a 2024 campaign by the TA577 threat group targeted NTLM hashes by using booby-trapped emails to send challenge-response authentication requests to internal SMB resources such as legacy printers. A more recent incident involved an authentication relay attack aimed at a specific NTLM vulnerability, CVE-2025-54918, which came only weeks after Microsoft announced that it was finally removing NTLMv1 support from Windows Server 2025 and Windows 11.Primary hurdle: Knowing it’s still thereAccording to Rob Finn, International vice president at supply chain security company Chainguard, even security-aware organizations could be caught out by NTLMv1.“Legacy protocols like NTLMv1 are buried deep within third-party firmware. A security team might deprecate NTLMv1 at the OS level, only to have a legacy printer driver or industrial sensor reintroduce it via an unpatched, decades-old library,” he said. “For most companies, the primary hurdle isn’t just knowing NTLMv1 is insecure, it’s knowing that it’s still there.”Because resources such as printers are not externally exposed, it is tempting to assume they are beyond the reach of attackers. Despite this, NTLMv1 can still be targeted from outside the network using relay or coercion techniques, by, for example, triggering authentication via a phishing attack.“Attackers don’t need to know you’re using it. They just have to poke the system to find out. Fundamentally, organizations keep legacy protocols active not because they want to, but because they fear breaking a mission-critical legacy app,” said Finn.Despite Microsoft recommending that organizations upgrade to NTLMv2 and Kerberos for more than two decades, it appears not everyone got the memo. “In crypto terms, NTLMv1 isn’t just old, it’s archaeological,” said Rob Anderson, head of reactive consulting services at Reliance Cyber. “NTLMv1 is still enabled, not because it is needed today, but because it was needed once, and nobody is quite brave enough to turn it off and see what breaks.”Despite those fears, organizations need to take action. “Scan for its use, find out why it is in use, register it as a high risk and get to work removing it, with achievable deadlines,” he advised.This article originally appeared on CSOonline.

#CRYPTO
wallst_247hace 21d

3 AI Stocks That May Be The Biggest Winners In 2026

Artificial intelligence stocks have been some of the best investments over the past year. Many stocks in this industry beat the S&P 500 in 2025, and some of those same stocks are poised to extend their runs into 2026 and beyond. These AI stocks might become some of the biggest winners in 2026. IREN IREN ... 3 AI Stocks That May Be The Biggest Winners In 2026The post 3 AI Stocks That May Be The Biggest Winners In 2026 appeared first on 24/7 Wall St..

#CRYPTO
echo_auhace 21d

Circular economy report released – what’s inside?

On Friday last week, the Productivity Commission’s (PC) final report on the circular economy was released, which outlines Australia’s ‘opportunities to lift materials productivity and reduce waste’.The post Circular economy report released – what’s inside? appeared first on The Echo.

#ECONOMY
Bitzero Holdings Inc. Acquires NVIDIA Blackwell B300 GPU Servers to Launch AI Compute Pilot with Hydra Host
benzingahace 21d

Bitzero Holdings Inc. Acquires NVIDIA Blackwell B300 GPU Servers to Launch AI Compute Pilot with Hydra Host

Company Deploys 64 Next-Generation GPUs at Norway Site, Marking Entry into Neocloud OperationsVANCOUVER, BC, Jan. 19, 2026 /PRNewswire/ -- Bitzero Holdings Inc., (CSE:BITZ) (OTC:BTZRF) (FSE: 000) ("Bitzero" or the "Company"), a provider of sustainable blockchain and high-performance compute (HPC) data center infrastructure, today announced the acquisition of eight NVIDIA Blackwell B300 servers, totaling 64 GPUs, to be deployed at its Namsskogan, Norway facility in partnership with Hydra Host. The deployment, expected to be completed in Q1 2026, represents Bitzero's first direct investment in GPU compute hardware and marks the Company's entry into neocloud operations. The servers will be leased as bare metal infrastructure for AI workloads through Hydra Host's Brokkr platform.Pilot Program DetailsBitzero has funded the initial deposit for the following hardware:8 air-cooled NVIDIA Blackwell B300 servers64 total GPUs featuring NVIDIA's latest Blackwell architectureDeployment at the Company's low-carbon Namsskogan, Norway data centerThe pilot is designed to validate GPU operations on Bitzero's existing infrastructure and establish the operational framework for potential future expansion.Hydra Host as Platform and Distribution PartnerHydra Host's Brokkr platform will provide Bitzero with GPU lifecycle management capabilities, including provisioning, monitoring, and access ...Full story available on Benzinga.com

#CRYPTO#TECH
Trump’s Iran Tariff Puts Friends and Foes on the Same Hook
oilpricehace 21d

Trump’s Iran Tariff Puts Friends and Foes on the Same Hook

On 12 January 2026, U.S. President Donald Trump announced, “Effective immediately, any Country doing business with the Islamic Republic of Iran will pay a Tariff of 25% on any and all business being done with the United States of America.” Trump’s announcement aims to weaken the government of the Islamic Republic in the wake of weeks of protests against the government, sparked by a weak economy. Trump told the protesters to keep fighting their government and that “help is on the way.” Who is “doing business”...

#CRYPTO#ECONOMY
Retail’s next customer may be a bot, says Althaf
gulftimeshace 21d

Retail’s next customer may be a bot, says Althaf

Retailers must prepare for a paradigm shift in commerce, where autonomous agents act as customers rather than mere tools, according to a top official of a major full-line retailer across the Gulf Co-o...

#CRYPTO#ECONOMY
Outlook for Air Canada Stock in 2026
fool_cahace 21d

Outlook for Air Canada Stock in 2026

With Air Canada stock still trading below $20 to start the year, is it one of the best value stocks to buy in 2026?The post Outlook for Air Canada Stock in 2026 appeared first on The Motley Fool Canada.

#STOCKS
Google AdSenseNews Footernews_footer