Tag: credentials
-
Chrome for Android tests feature that securely verifies your ID with sites
Google is testing a new feature called Digital Credential API for Chrome on Android that will allow websites to request identity information from mobi… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/chrome-for-android-tests-feature-that-securely-verifies-your-id-with-sites/
-
Guide to mitigating credential stuffing attacks
We have a collective unaddressed weakness when it comes to basic cybersecurity. Out of the many reports circulating in the news today, many statistics… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/25/mitigating-credential-stuffing-attacks-whitepaper/
-
Hunting for Credential Theft Identify When an InfoStealer May be Stealing Sensitive Access
Threat Overview Hunting for Credential Theft Identify When an InfoStealer May be Stealing Sensitive Access The recent SnowFlake incident has brought t… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/hunting-for-credential-theft-identify-when-an-infostealer-may-be-stealing-sensitive-access/
-
165 Snowflake Customers ‘Potentially Exposed’ in Campaign
Researchers with Mandiant said that since at least April 14, the threat group behind the attack has used stolen credentials to access over 100 custome… First seen on duo.com Jump to article: duo.com/decipher/mandiant-165-snowflake-customers-potentially-exposed-in-wider-campaign
-
Why Devs Aren’t Responsible for Non-Human Credential Hygiene
Tags: credentials3 min read… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/why-devs-arent-responsible-for-non-human-credential-hygiene/
-
Medibank breach: Security failures revealed (lack of MFA among them)
The 2022 Medibank data breach / extortion attack perpetrated by the REvil ransomware group started by the attackers leveraging login credentials stole… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/18/medibank-breach-security-failures/
-
Amtrak Says Guest Rewards Accounts Hacked in Credential Stuffing Attacks
National passenger railroad company Amtrak is notifying customers that hackers have breached their Guest Rewards Accounts. The post passenger railroad… First seen on securityweek.com Jump to article: www.securityweek.com/amtrak-says-guest-rewards-accounts-hacked-in-credential-stuffing-attacks/
-
Internet Computer Protocol Launches Walletless Verified Credentials for Public Trust
ernet Computer Protocol (ICP) introduces Verified Credentials (VCs), a walletless solution enhancing data sharing privacy. Unveiled at DICE 2024, VCs … First seen on hackread.com Jump to article: hackread.com/internet-computer-protocol-walletless-verified-credentials/
-
Mozilla Firefox can now secure access to passwords with device credentials
Mozilla Firefox finally allows you to further protect local access to stored credentials in the browser’s password manager using your device’s login, … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-firefox-can-now-secure-access-to-passwords-with-device-credentials/
-
Australian Regulators Detail Medibank Hack: VPN Lacked MFA
Court Filing: Threat Actor Stole Admin Credentials From IT Service Desk Contractor. Medibank’s lack of MFA on its global VPN allowed a hacker to use c… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/australian-regulators-detail-medibank-hack-vpn-lacked-mfa-a-25539
-
Snowflake Cloud Accounts Felled by Rampant Credential Issues
A threat actor has accessed data belonging to at least 165 organizations using valid credentials to their Snowflake accounts, thanks to no MFA and poo… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/snowflake-cloud-accounts-rampant-credential-issues
-
‘Sticky Werewolf’ APT Stalks Aviation Sector
The pro-Ukranian group has upgraded its infection chain, with credentials, strategic info on commercial pilots, or billion-dollar designs as the possi… First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/sticky-werewolf-apt-stalks-aviation-sector
-
New phishing toolkit uses PWAs to steal login credentials
A new phishing kit has been released that allows red teamers and cybercriminals to create progressive web Apps (PWAs) that display convincing corporat… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-phishing-toolkit-uses-pwas-to-steal-login-credentials/
-
Snowflake Warns: Targeted Credential Theft Campaign Hits Cloud Customers
Cloud computing and analytics company Snowflake said a limited number of its customers have been singled out as part of a targeted campaign.We have no… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/snowflake-warns-targeted-credential.html
-
Russian Hackers Target Europe with HeadLace Malware and Credential Harvesting
The Russian GRU-backed threat actor APT28 has been attributed as behind a series of campaigns targeting networks across Europe with the HeadLace malwa… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/russian-hackers-target-europe-with.html
-
Privacy Regulators Probe Impact of 23andMe’s Mega Breach
6.9 Million Individuals’ Genetic Details Stolen via 2023 Credential Stuffing Attack. Privacy regulators in the U.K. and Canada have launched a joint i… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/privacy-regulators-probe-impact-23andmes-mega-breach-a-25480
-
Privacy Regulators Probe Impact of 23andMe’s Mega-Breach
6.9 Million Individuals’ Genetic Details Stolen via 2023 Credential-Stuffing Attack. Privacy regulators in the U.K. and Canada have launched a joint i… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/privacy-regulators-probe-impact-23andmes-mega-breach-a-25480
-
Okta Warns of Credential Stuffing Attacks Targeting Customer Identity Cloud
Okta is warning that a cross-origin authentication feature in Customer Identity Cloud (CIC) is susceptible to credential stuffing attacks orchestrated… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/okta-warns-of-credential-stuffing.html
-
Okta Says Customer Identity Cloud Prone To Credential Stuffing Attacks
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35950/Okta-Says-Customer-Identity-Cloud-Prone-To-Credential-Stuffing-Attacks.html
-
New Fog ransomware targets US education sector via breached VPNs
A new ransomware operation named ‘Fog’ launched in early May 2024, using compromised VPN credentials to breach the networks of educational organizatio… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-fog-ransomware-targets-us-education-sector-via-breached-vpns/
-
Okta Warns Once Again of Credential-Stuffing Attacks
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/okta-warns-once-again-of-credential-stuffing-attacks
-
361 Million Unique Email Credentials Leaked On Telegram Channels
Last week, a security researcher sent me 122GB of data scraped out of thousands of Telegram channels. It contained 1.7k files with 2B lines and 361M u… First seen on gbhackers.com Jump to article: gbhackers.com/email-credentials-leaked/
-
361 million account credentials leaked on Telegram: Are yours among them?
A new trove of 361 million email addresses has been added to Have I Been Pwned? (HIBP), the free online service through which users can check whether … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/04/check-account-credentials-compromised/
-
APT28 targets key networks in Europe with HeadLace malware
Russia-linked APT28 used the HeadLace malware and credential-harvesting web pages in attacks against networks across Europe. Researchers at Insikt Gro… First seen on securityaffairs.com Jump to article: securityaffairs.com/164061/apt/apt28-headlace-malware-europe.html
-
Vulnerabilities in employee management system could lead to remote code execution, login credential theft
Talos also recently helped to responsibly disclose and patch other vulnerabilities in the Foxit PDF Reader and two open-source libraries that support … First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/vulnerability-roundup-may-1-2024/
-
#Infosec2024: Why Credential-Based Attacks Need Modern Solutions
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/credential-attacks-modern-solutions/
-
CarnavalHeist Weaponizing Word Documents To Steal Login Credentials
Hackers take advantage of Word documents as weapons due to their widespread use and trust. This is facilitated by the ease with which users can be dec… First seen on gbhackers.com Jump to article: gbhackers.com/carnavalheist-weaponizing-word-documents-credentials/
-
Snowflake compromised? Attackers exploit stolen credentials
Have attackers compromised Snowflake or just their customers’ accounts and databases? Conflicting claims muddy the situation. What is Snowflake? Snowf… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/31/snowflake-compromised-data-theft/
-
361 million stolen accounts leaked on Telegram added to HIBP
A massive trove of 361 million email addresses from credentials stolen by password-stealing malware, in credential stuffing attacks, and from data bre… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/

