HomeSecurityMicrosoft: Strengthens phishing protection in Windows 11

Microsoft: Strengthens phishing protection in Windows 11

Microsoft is testing a new feature for improved phishing in Windows 11 that warns users when they copy and paste their Windows password into websites and documents.

See also: Windows 11 version 21H2: End of support from October

Microsoft

Microsoft introduced a new security feature, Enhanced Phishing Protection, with the release of Windows 11 22H2. This feature is designed to protect Windows domain and Active Directory credentials from phishing threats.

One of the most common methods used by malicious actors to gain access to websites or corporate networks is to purchase or steal corporate credentials. The credentials are initially obtained through phishing attacks or by using malware that steals information.

Credential stealers use these credentials to log into Windows accounts, such as email, banking, or cryptocurrency trading accounts. The situation is even worse as stolen accounts can be used by hackers to gain access to corporate networks. This makes it possible to spread a lateral attack across the network and carry out BEC fraud, data theft, supply chain attacks, and ransomware.

Credential theft is a large and widespread problem, with criminal cyber selling billions of credentials and authentication cookies, as well as specialized websites selling over a million credentials for remote access.

Due to the intense abusive activity, law enforcement has aimed to enforce the law for certificate theft in businesses, arresting WT1SHOP in 2022 and recently taking down Genesis Market.

See also: Windows Copilot: Coming in September with Windows 11 23H2?

Windows 11

When Microsoft released the new Windows Enhanced Phishing, the warning was only available when users manually typed their Windows password into a document or web login page.

Although it is usually recommended that users use password managers to create strong and unique passwords for all their logins, many people copy and paste their passwords from the password manager when they log in. Because the copy and paste feature does not protect against potential threats in Windows, this feature can be a risk.

Microsoft has improved its ability to protect against Phishing in Windows 11 Insider Dev build 23506. It can now detect copying and pasting of a user's Windows password.

As this feature is not enabled by default, Windows users will need to enable it by going to Windows Security > App & Browser Control > Reputation-based Protection > Phishing and selecting all three options.

This feature will be enabled and will warn users when they type or copy and paste their Windows password into forms or website documents.

This notification will be titled “Password reuse is a security risk” and warns users to reset their Windows account password, with a link to this support document.

See also: Microsoft Teams receives an important security update

It is recommended that all Windows users enable this security option in Windows Security Settings, even though it is not supported by all applications at this time.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS