Happy Sunday!
I've been thinking about our industry's persistent password problem all week, and it's encouraging to see Microsoft finally making passkeys the default for new accounts. While this is a significant step forward, Ivanti's latest report reveals a concerning gap - only 22% of organizations are increasing investments in exposure management despite half of security professionals recognizing its value.
In this week's brief:
- North Korean threat actors are creating fake crypto companies to deploy triple malware threats
- The Model Context Protocol (MCP) introduces new security risks despite backing from tech giants
- Cybersecurity professionals emphasize that system administration experience is fundamental to security careers
What's your take - are we finally seeing the beginning of the end for passwords, or will they continue to haunt us for another decade?
I'd love to hear your thoughts. Reply directly to this email or share your thoughts in comments section below.

Industry News
Researchers Discover "AirBorne" Vulnerability Affecting Millions of AirPlay-Enabled Devices
-
Security firm Oligo revealed a collection of vulnerabilities in Apple's AirPlay SDK that could allow attackers on the same Wi-Fi network to hijack third-party AirPlay-enabled devices like speakers, TVs, and set-top boxes, potentially affecting tens of millions of devices.
-
While Apple has patched these flaws in their own devices, many third-party manufacturers may never update their firmware, leaving a persistent security risk that could allow attackers to maintain stealthy network access, install ransomware, or even turn devices with microphones into listening devices.
-
The vulnerabilities also affect CarPlay-enabled vehicle dashboard computers, though exploitation requires physical access via Bluetooth or USB connection, significantly limiting the threat vector in automotive applications.
Microsoft Makes Passkeys Default for New Microsoft Accounts
-
Microsoft has made new accounts "passwordless by default," enabling users to sign in with phishing-resistant passkeys instead of traditional passwords, while existing users can delete their passwords through account settings.
-
The company has simplified the sign-in experience by automatically detecting and prioritizing the best available authentication method on a user's account, representing a significant step toward industry-wide passwordless adoption.
-
Over 15 billion user accounts now support passkeys, and the FIDO Alliance is working on improving credential interoperability across providers and expanding passkey implementation to payment use cases through a new Payments Working Group.
North Korean APT "Contagious Interview" Establishes Fake Crypto Companies to Deliver Triple Malware Threat
-
Silent Push researchers uncovered three cryptocurrency front companies operated by North Korean APT group "Contagious Interview" (a subgroup of Lazarus) used to deploy BeaverTail, InvisibleFerret, and OtterCookie malware through fake job interviews targeting crypto professionals.
-
The threat actors created convincing company personas using AI-generated employee images, fake business registrations, and elaborate social media presence, while their infrastructure revealed significant operational security failures linking all three companies: BlockNovas LLC, Angeloper Agency, and SoftGlide LLC.
-
The cryptocurrency theft campaign uses a multi-stage infection process involving GitHub repositories with hidden code, fake job interviews requiring video recordings, and malware that establishes persistence across Windows, macOS, and Linux to steal wallet credentials from popular browser extensions.




