#password

anonymiss@despora.de

#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.

#fail #password #leak #problem #news

anonymiss@despora.de

Git-Rotate: Leveraging #GitHub Actions to Bypass #Microsoft Entra Smart lockout

Source: https://research.aurainfosec.io/pentest/git-rotate/

Despite advancements in #cybersecurity, #password #spraying attacks remain a prevalent and effective technique for attackers attempting to gain unauthorised access to #cloud - based infrastructure and web applications by targeting their login portals. Password spraying involves attempting a small number of common passwords against a large number of usernames. This makes it difficult for #security systems to detect and mitigate as they often avoid common protections such as #account lockout policies by avoiding rapid or repeated login attempts for a single account. Attackers can easily obtain lists of commonly used passwords or use automated tools to generate potential passwords, increasing the likelihood of success.

#news #hack #hacker #login #attack #problem

anonymiss@despora.de

Cybercriminals crave cookies, not passwords

source: https://cybernews.com/security/cybercriminals-crave-cookies-not-passwords/

Authentication #cookies establish an expiration time for your sessions with services. The token expires after some time, which may take minutes to months, and the user needs to re-authenticate. Malicious actors, having access to cookies and device information, no longer need to know passwords and security passphrases or have access to account recovery options.

#password #cooky #security #web #internet #browser #cybercrime #news #malware

christophs@diaspora.glasswings.com

Gandalf | Lakera – Test your prompting skills to make Gandalf reveal secret information.

Your goal is to make Gandalf reveal the secret password for each level. However, Gandalf will level up each time you guess the password, and will try harder not to give it away. Can you beat level 7? (There is a bonus level 8)

Haven't tried it yet but sounds fun!
#security #password

https://gandalf.lakera.ai/

anonymiss@despora.de

'The #Wallet Event': #Crypto #Startup #Bankrupt After Losing #Password to $38.9 Million Physical Crypto Wallet

Source: https://www.404media.co/crypto-startup-prime-trust-files-for-bankruptcy-after-losing-password-to-38-9-million-crypto-wallet/

Rather than write down the seed phrases, Prime Trust opted to laser etch them into a piece of steel called “Cryptosteel Hardware,” which are called “Wallet Access Devices” in the court filings. According to the filing, it lost these devices, which is why it can’t get back into the wallet.

#problem #technology #cryptocurrency #finance #economy #news

anonymiss@despora.de

#LG, Whirlpool Target Customers Disconnected From ‘Smart’ Appliances

The appliance makers continue to invest in efforts to drum up revenue through internet-connected devices, but many customers aren’t logging on

Source: https://www.wsj.com/articles/lg-whirlpool-target-customers-disconnected-from-smart-appliances-11674232811

If a #customer changes their service provider or router or even their #password, that could cause the device to disconnect, he said.

No shit, Sherlock đŸ€”

Stay offline; stay secured; don't let them steal your data. Don't buy things, which don't need to be online but must be online.

#capitalism #internet #bigdata #online #security #smart #iot #problem #economy #news #service