Topic: credential exposure

  • Stolen Credentials Give Attackers a Head Start Most Firms Miss

    Stolen Credentials Give Attackers a Head Start Most Firms Miss

    73% of organizations found employee credentials in breach databases or infostealer logs in the past year, yet nearly one in five have no visibility into their own leaks, and over 70% faced an authentication-related incident, with attackers using valid credentials in two-thirds of cases. Infosteal...

    Read More »
  • Massive supply-chain breach exposes terabytes of credentials

    Massive supply-chain breach exposes terabytes of credentials

    A supply-chain attack on LiteLLM, an open-source AI platform, exposed credentials from major organizations like Microsoft, Amazon, and Cisco, with data pulled from the official Python Package Index during a 40-minute window in March. The stolen data includes cloud keys, SSH keys, Kubernetes secre...

    Read More »
  • Massive breach exposes credentials for thousands of sensitive networks

    Massive breach exposes credentials for thousands of sensitive networks

    A Russian-speaking threat actor breached nearly 74,000 Fortinet devices from over 21,000 IP addresses across 194 countries, exposing plaintext credentials of major organizations including Oracle, Chevron, Lenovo, and Fortinet itself. The attackers gained near-total access by compromising firewall...

    Read More »
  • Dark Web Holds Early Clues to Supply-Chain Attacks

    Dark Web Holds Early Clues to Supply-Chain Attacks

    Early warning signs of software supply-chain attacks often appear on the dark web as posts advertising GitHub access, source code, API keys, and OAuth tokens, with the real danger lying in the trust relationships these exposures touch. A recent Flare investigation highlights that GitHub-related a...

    Read More »
  • 149 Million Login Credentials Leaked in Database Breach

    149 Million Login Credentials Leaked in Database Breach

    A massive, publicly accessible database containing nearly 149 million stolen login credentials—including 48 million for Gmail—was discovered and taken offline, highlighting the persistent threat of unsecured data troves. The database, found by a security researcher, was highly organized and conta...

    Read More »
  • Microsoft 365 faces 81 million hacker login attempts

    Microsoft 365 faces 81 million hacker login attempts

    A password-spraying campaign generated over 81 million login attempts on Microsoft 365 environments in two weeks, using credentials from past breaches to authenticate via Azure CLI. The threat actor exploited the ROPC OAuth mechanism to bypass multi-factor authentication (MFA) due to insecure Con...

    Read More »
  • Cyber Theory vs. Practice: Are Your Tools Failing You?

    Cyber Theory vs. Practice: Are Your Tools Failing You?

    Traditional security measures often fail due to inaccurate data and manual processes, leaving organizations vulnerable as they operate with flawed information. Many organizations face critical weaknesses in asset discovery, vulnerability management, threat intelligence, and endpoint enforcement, ...

    Read More »
  • Microsoft Empowers Security Teams with AI Investigations

    Microsoft Empowers Security Teams with AI Investigations

    Microsoft has launched **Purview Data Security Investigations**, a new AI-powered tool that dramatically speeds up complex data investigations, turning processes that took weeks into operations completed in hours. The platform aggregates and analyzes data from across Microsoft 365 (including emai...

    Read More »
  • US, South Korea warn of Gunra ransomware hitting govt agencies

    US, South Korea warn of Gunra ransomware hitting govt agencies

    U.S. and South Korean agencies issued a joint advisory urging global critical infrastructure to defend against Gunra, a double-extortion ransomware built on leaked Conti source code, first appearing in April 2025 and targeting healthcare, finance, and government sectors. Gunra exploits Fortinet f...

    Read More »