#bruteforce — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bruteforce, aggregated by home.social.
-
MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
-
MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
-
Das #internet macht auch keinen Spaß mehr.
Das sind die Top-Sperren mit fail2ban bei 2 Domains, die nicht einmal aktiv irgendwo sind. Nur der Webserver steht da rum und langweilt sich. Alles mit #fail2ban geloggt.
Hauptursache: Globale #BruteForce auf #ssh. Also sichert eure Webserver von Anfang an ab.📊 Länder-Statistik: 🇻🇳 Vietnam: 6 (54,5%) 🇷🇺 Russland: 1 (9,1%) 🇨🇴 Kolumbien: 1 (9,1%) 🇺🇿 Usbekistan: 1 (9,1%) 🇭🇰 Hongkong: 1 (9,1%) 🇩🇪 Deutschland: 1 (9,1%)
-
Das #internet macht auch keinen Spaß mehr.
Das sind die Top-Sperren mit fail2ban bei 2 Domains, die nicht einmal aktiv irgendwo sind. Nur der Webserver steht da rum und langweilt sich. Alles mit #fail2ban geloggt.
Hauptursache: Globale #BruteForce auf #ssh. Also sichert eure Webserver von Anfang an ab.📊 Länder-Statistik: 🇻🇳 Vietnam: 6 (54,5%) 🇷🇺 Russland: 1 (9,1%) 🇨🇴 Kolumbien: 1 (9,1%) 🇺🇿 Usbekistan: 1 (9,1%) 🇭🇰 Hongkong: 1 (9,1%) 🇩🇪 Deutschland: 1 (9,1%)
-
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Book Giveaway!
“So, You Think You Know the Jersey Shore” by Maryanne Christiano-Mistretta
BOOK GIVEAWAY! USA ONLY!
Happy National Give Something Away Day!
Win one of my three books!
Just comment which one you’d like to read and I’ll put your names in a hat and pick a winner at the end of the day, around 5 p.m. EST.If you win, I’ll ask for your email address so I can get your mailing address.
Totally free, all postage paid! USA ONLY!
(This contest is on Facebook and WordPress, so there will be two winners.)Here’s the books to choose from:
1. “I Don’t Want to Be Like You” — My memoir growing up in the 1970s and dealing with bullies, and how they didn’t break me. Inspirational and honest.
2. “The Gypsy Smiled” — About a young woman trying to make it in the music business. The book was inspired by Lou Christie’s song “The Gypsy Cried.” Lots of kitschy fun — Elvis tribute artists, all-girl bands inspired by Tom Jones. Fun and silly.
3. “So, You Think You Know the Jersey Shore?” — A reference guide I put together about all the nooks and crannies of The Jersey Shore. What’s cool is that I took some of the photos for the book.Apple Records legend, Brute Force, reading my book, “I Don’t Want to Be Like You”
Model: Pleasant Gehman
#antiBullying #author #bookGiveaway #books #bruteForce #bullying #fiction #indieAuthors #inspiration #jerseyShore #louChristie #maryanneChristianoMistretta #memoirs #motivation #NewJersey #pleasantGehman #reading #theGypsySmiled #traditionallyPublishedIndieAuthors -
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Microsoft 365 users and admins, beware! There's a specific IPv6 range (2a0a:d683::/32) operated by a provider called LSHIY that is engaging in password spraying / brute force login attempts against Microsoft accounts with old, previously leaked credentials that were disclosed as part of prior breaches.
The attack bypasses MFA and SSO because it uses the deprecated (but still functional) OAuth Resource Owner Password Credentials 2.0 flow. But it works because some people still use creds that were stolen years ago and were never changed. So change your passwords, people!
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
Dashlane potwierdza atak brute force, jednak dane użytkowników nie są zagrożone
31 maja 2026 do Dashlane wpłynęły zgłoszenia kilku użytkowników, którzy otrzymali e-mail informujący, że ich konto zostało zawieszone. Użytkownicy zgłaszali również problemy z logowaniem do usługi po zresetowaniu hasła (Master Password). TLDR: Zespół Dashlane ustalił, że przyczyną był atak brute force na wybrane konta użytkowników usługi. Celem ataku było pokonanie...
#WBiegu #2Fa #Atak #Awareness #Bezpieczeństwo #BruteForce #Dashlane #Hasła
https://sekurak.pl/dashlane-potwierdza-atak-brute-force-jednak-dane-uzytkownikow-nie-sa-zagrozone/
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
@sophieschmieg : *if* the second factor consist of 6 digits and regularly changes (TOTP: usually every thirty seconds), then it is typically worse than 1 in a million chance.
Because the client clock may be out of sync with the server clock, typically a time window larger than 30 seconds is used to increase fault tolerance.
I suggest you read https://www.oasis.security/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass.
I remembered that attack, but Pouyan (@i) had already referenced "AuthQuake" in an earlier toot (https://toot.pouyan.net/notice/B6xuBX6lzrGenpC74y) - but you may have missed that.
W.r.t. 2FA: if the server, after entering the user-ID and an incorrect password, responds with "wrong userID or password" - before asking for the 2FA code (or a timing difference reveals that the first factor is either wrong or correct), then the attacker's life gets a lot easier.
And if 2FA is reduced to 1FA in "device code" phishing attacks, even passkeys and FIDO2 hardware keys will not prevent account takeovers.
Also "password reset" mechanisms may have flaws (upto Instagram's AI assistent being easily convinced by fraudsters).
#TOTP #TimeWindow #RFC6238 #2FA #Weak2FA #MFA #WeakMFA #BruteForce
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
The Ferengi 14th Rule of Acquisition states "Anything stolen is pure profit"
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-41893-cwe-307-improper-restriction-of-exc-a656937b #OffSeq #infosec #vuln #bruteforce
-
Korben: #Bruteforce de #cartes #bancaires Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde. korben.info/carte-bancai...
Bruteforce de cartes bancaires... -
Korben: #Bruteforce de #cartes #bancaires Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde. korben.info/carte-bancai...
Bruteforce de cartes bancaires... -
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Korben: #Bruteforce de #cartes #bancaires
Un #chercheur en #sécurité a démontré qu'il est possible de reconstituer les chiffres manquants d'une carte bancaire par bruteforce en testant des numéros auprès de la banque, à raison d'environ 6 tentatives par seconde.
-
Des chercheurs montrent qu'on peut bruteforcer les données d'une carte bancaire en testant systématiquement les combinaisons sur différents sites marchands — sans jamais bloquer la carte. Ce n'est pas un bug isolé : c'est une limite architecturale du système de paiement en ligne. La bonne nouvelle ? On sait exactement où regarder pour améliorer ça. 🔍 #infosec #bruteforce #sécurité
https://korben.info/carte-bancaire-brute-force.html -
Credit card numbers can be brute-forced. With enough parallel requests across payment networks, the entropy melts away faster than expected. The real question isn't "is this possible?" — it's "why do the guardrails vary so much between providers?" Consistency in security controls is its own kind of vulnerability. #infosec #bruteforce #payments
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
🐱💻 Oh no! Credit cards can be hacked by brute force? Who would have thought that a string of numbers could be cracked like a safe? 🤯 I guess we'll just sit back and pretend #PCI #DSS is the Fort Knox of digital security while hackers crack open our piggy banks. 🐽🔓
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html #creditcardsecurity #digitalhacks #bruteForce #cybersecurity #HackerNews #ngated -
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities
-
Credit Cards Are Vulnerable to Brute Force Kind Attacks
https://metin.nextc.org/posts/Credit_Cards_Are_Vulnerable_To_Brute_Force_Kind_Attacks.html
#HackerNews #CreditCards #CyberSecurity #BruteForce #Attacks #Vulnerabilities