Tag: password
-
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes. PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and…
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
Someone Changed the Password on a Water Utility’s PLC
More than 30 Minnesota water systems lost control of their equipment in a single weekend, and the campaign has since reached at least a dozen states. The connections attackers used were not carelessness. They were put there by people trying to keep water flowing. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/someone-changed-the-password-on-a-water-utilitys-plc/
-
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Tags: access, apple, cve, cyber, data-breach, flaw, macOS, password, rce, remote-code-execution, update, vulnerabilityApple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote attackers to execute arbitrary code and access files with root-level privileges. The flaw is especially severe on systems where Screen Sharing is exposed to the public internet. Apple’s August 6 releases macOS Tahoe 26.6.1,…
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.”…
-
Hackers grow more willing to destroy, not just disrupt, OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-destructive-cyberattacks-black-hat/827260/
-
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
-
Hackers grow more willing to destroy, not just disrupt OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-destructive-cyberattacks-black-hat/827260/
-
Why Passkeys Are Closing the Account Takeover Gap
HealthEquity’s Ajit Gaddam on Passwordless Security, Fraud Signals, Cyber Defense. Passwords remain a weak point in account security, especially when attackers can buy stolen credentials and exploit recovery workflows. Ajit Gaddam explains how passkeys, biometrics and device signals can strengthen identity assurance while reducing login friction. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/passkeys-are-closing-account-takeover-gap-a-32442
-
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
-
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python”‘based, cross”‘platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller”‘packed executable to harvest browser passwords, crypto wallet data, Discord tokens, gaming accounts, VPN configs, and sensitive documents. Vanta Stealer exemplifies the current shift toward Python for modular, easily maintainable malware, while abusing commercial protection frameworks like PyArmor…
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Stolen Greatness Tokens Provide Microsoft 365 Access More Than Two Weeks After Phishing
Stolen Greatness authentication tokens are providing sustained, MFA”‘approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay not password theft is driving the persistence in this AiTM PhaaS ecosystem. Originally documented by Cisco Talos in May 2023 and further covered by Hornet Security, […] The…
-
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection. First seen on hackread.com Jump to article: hackread.com/brazil-health-surveillance-database-exposed-records/
-
New Google Password Manager Attacks Can Hijack Synced Passkeys
Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/
-
WhatsApp Scam Hijacks Accounts via Linked Devices Feature
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
New Passkey attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
8 Best Password Managers (2026), Tested and Reviewed
Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers. First seen on wired.com Jump to article: www.wired.com/story/best-password-managers/
-
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurrency wallets. The attack begins when victims search Google for >>how to install Claude on a Mac<< and click a sponsored…
-
US authorities see ‘significant escalation’ in attacks on water system devices
Hackers have locked operators out of their own OT networks, modified passwords and changed IP addresses. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-authorities-escalation-attacks-water-system-devices/826715/
-
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
Flaw From 2002 Exposes Data Centers to Server Takeover
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to First seen on thehackernews.com Jump to article:…
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
Exposed BMCs hand out password hashes before login
An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
-
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/
-
Why Resetting Passwords No Longer Stops Attackers
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/why-resetting-passwords-no-longer-stop-attacks

