#password

anonymiss@despora.de

Second Factor #SMS: Worse Than Its Reputation

Source: https://www.ccc.de/en/updates/2024/2fa-sms

IdentifyMobile, a provider of 2FA-SMS, shared the sent one-time passwords in real-time on the internet. The #CCC happened to be in the right place at the right time and accessed the data. It was sufficient to guess the subdomain "idmdatastore". Besides SMS content, recipients' phone numbers, sender names, and sometimes other account information were visible.

#news #security #internet #2fa #mobile #cybersecurity #problem #password

anonymiss@despora.de

#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.

#fail #password #leak #problem #news

anonymiss@despora.de

Git-Rotate: Leveraging #GitHub Actions to Bypass #Microsoft Entra Smart lockout

Source: https://research.aurainfosec.io/pentest/git-rotate/

Despite advancements in #cybersecurity, #password #spraying attacks remain a prevalent and effective technique for attackers attempting to gain unauthorised access to #cloud - based infrastructure and web applications by targeting their login portals. Password spraying involves attempting a small number of common passwords against a large number of usernames. This makes it difficult for #security systems to detect and mitigate as they often avoid common protections such as #account lockout policies by avoiding rapid or repeated login attempts for a single account. Attackers can easily obtain lists of commonly used passwords or use automated tools to generate potential passwords, increasing the likelihood of success.

#news #hack #hacker #login #attack #problem

anonymiss@despora.de

Cybercriminals crave cookies, not passwords

source: https://cybernews.com/security/cybercriminals-crave-cookies-not-passwords/

Authentication #cookies establish an expiration time for your sessions with services. The token expires after some time, which may take minutes to months, and the user needs to re-authenticate. Malicious actors, having access to cookies and device information, no longer need to know passwords and security passphrases or have access to account recovery options.

#password #cooky #security #web #internet #browser #cybercrime #news #malware