Tag: password
-
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data.The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file impersonating Maccy, a legitimate open-source clipboard manager. It has been codenamed PamStealer owing to its ability…
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
Why a Windows Hello PIN Beats a Password for Enterprise Security
As phishing campaigns, AI-driven identity attacks, and Windows migration planning raise authentication stakes, IT teams should recheck how Windows Hello PIN security works. The post Why a Windows Hello PIN Beats a Password for Enterprise Security appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-hello-pin-security/
-
Angriffe auf Azure-CLI: Millionen Passwort-Angriffe auf Microsoft-Konten
Ein massiver Password-Spray-Angriff auf das Azure-CLI kompromittierte 78 Microsoft-Konten. Angreifer nutzten ein veraltetes OAuth-Verfahren als Bypass. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/angriffe-auf-azure-cli
-
BioShocking-Angriff hebelt KI-Schutzfilter aus
Der Prompt-Injection-Angriff BioShocking bringt KI-Browser dazu, Sicherheitsfilter zu ignorieren und sensible Nutzerdaten wie Passwörter zu stehlen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/bioshocking-angriff-ki-schutzfilter
-
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker…
-
ADN erweitert Security-Portfolio um Specops Software
Zero Trust Workforce Access und Active-Directory-Schutz. Die ADN Distribution GmbH baut ihr Cybersecurity-Portfolio strategisch weiter aus: Ab sofort vertreibt der Value-Added Distributor die führenden Identitäts- und Gerätesicherheitslösungen von Specops Software, die Teil der Outpost24-Gruppe sind. Damit adressiert ADN die zwei kritischsten Einfallstore moderner Unternehmens-Infrastrukturen: schwache Passwörter im Active Directory sowie kompromittierte Endgeräte beim mobilen… First…
-
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June 12 and June 26, 2026. According to researchers from Huntress, the activity primarily originates from…
-
Azure Password-Spraying Attack Bypasses MFA Defenses
Threat Actor Uses Deprecated OAuth 2.0 Authentication Flow. Attackers behind a password-spraying campaign targeting Microsoft Office 365 accounts have amassed dozens of victims by abusing a deprecated feature in OAuth 2.0 to generate access tokens, in some cases sidestepping multifactor authentication controls, warn researchers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/azure-password-spraying-attack-bypasses-mfa-defenses-a-32128
-
Hackers target Microsoft 365 accounts with 81 million login attempts
An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-microsoft-365-accounts-with-81-million-login-attempts/
-
Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs
81 Million Login Attempts, 78 Compromised Accounts: The LSHIY Password Spray Hitting Azure CLI Huntress researchers have been tracking a massive automated password spray campaign against Microsoft Azure CLI environments since June 12, 2026. A password spray attack is when attackers try a small number of common passwords across many accounts instead of many passwords…
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE…
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts
KDDI says a breach may have exposed email addresses and passwords for up to 14.2 million ISP accounts across six providers. The post Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-kddi-breach-isp-email-accounts-apac-japan/
-
Iran, Russia, China Target Water Systems for Sabotage
Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation, not sophisticated malware. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotage
-
Neue ClickFix-Kampagne infiziert macOS-Geräte von Apple
Eine neue macOS-ClickFix-Kampagne nutzt Terminal-Befehle, um Schadsoftware unbemerkt aus DMG-Dateien zu laden und Passwörter sowie Krypto-Daten zu stehlen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/apple-neue-clickfix-kampagne
-
Nathan Austad Pleads Guilty in DraftKings Hacking Scheme, Gets 18 Months
Third DraftKings hacker gets 18 months in prison for a 2022 credential-stuffing attack that compromised 1,600 accounts and stole $600,000. Nathan Austad, the third person sentenced over the 2022 DraftKings credential-stuffing attack, received 18 months in prison. The group used usernames and passwords stolen from other breaches to access about 1,600 accounts and steal roughly…
-
Experts Warn: Passwords Still Winning Despite Passwordless Push
Today marks International Passwordless Day, an annual observance held on 23 June, the birthday of mathematician Alan Turing, whose foundational work in computing underpins the cryptographic principles that enable modern passwordless authentication. Created to raise awareness and accelerate the shift away from traditional passwords, the day arrives at a moment of genuine but uneven progress.…
-
New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector
Researchers warn GhostShell is using fake drone documents to target Ukrainian defence teams, stealing passwords and sensitive data in a new cyber campaign. First seen on hackread.com Jump to article: hackread.com/ghostshell-hacking-group-ukraine-drone-defense-sector/
-
He Thought He Was Secure; His Phone Number Was Stolen Anyway
Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/how-a-sim-swap-attack-led-to-a-near-account-takeover
-
Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route. First seen on hackread.com Jump to article: hackread.com/fake-npm-packages-postcss-tool-steal-chrome-password/
-
KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials
Customers of the affected Japanese email services are “strongly advised” to change their email passwords First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/kddi-breach-japanese-telcos/
-
Google Workspace expands password reset alerts to all admins
Google’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/google-workspace-admin-password-reset-alerts/
-
KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts
Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan. First seen on…
-
Neuer Schadsoftware-Loader OXLOADER nutzt Google-Anzeigen
Ein neuer Malware-Loader namens OXLOADER verbreitet den Passwort-Dieb CastleStealer über gefälschte Google Ads. Die Erkennungsrate ist bislang sehr gering. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/google-ads-schadsoftware-loader
-
Your AI agent can’t be authenticated by a password reset email
First seen on scworld.com Jump to article: www.scworld.com/perspective/your-ai-agent-cant-be-authenticated-by-a-password-reset-email
-
Majority of users still store passwords in browsers, survey finds
Tags: passwordFirst seen on scworld.com Jump to article: www.scworld.com/brief/majority-of-users-still-store-passwords-in-browsers-survey-finds
-
Password manager maker LastPass says hackers stole customer support case data during Klue breach
This is the second data breach to affect LastPass customers in recent years, after one of the password manager’s tech partners was recently breached. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/

