home.social

#credential — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credential, aggregated by home.social.

fetched live
  1. The LiteLLM attack's true reach: terabytes of credentials tied to 434,000 pipelines

    Follow us and never miss a story.

    1ban.news/litellm-credential-l

    #1ban #litellm #credential #leak #434000 #tech

  2. Need to securely pass secrets to shell scripts in Jenkins? Use `withCredentials` in Declarative Pipelines. This snippet binds a Secret text credential to `SECRET_API_KEY`, masking it in console logs. Jenkins 2.176+ with Credentials Binding Plugin 1.24+ required. #jenkins #declarative-pipeline #credential-binding

    valtersit.com/vault/secure-cre

  3. DCSync attack: Extract all user password hashes from a Domain Controller by simulating replication via MS-DRSR. Requires Replication-Get-Changes-All privileges. Works on Windows Server 2008 R2+ DCs. #credential-access #dcsync #ValtersIT

    valtersit.com/vault/extract-pa

  4. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  5. For the 2nd time in weeks, #Microsoft packages laced with #credential stealer

    Dozens of #cryptographically verified #opensource packages from Microsoft were #compromised late last week to add advanced credential-stealing code that was triggered when #developers opened them in #AI coding #agents.

    In all, multiple researchers said, 73 packages were flagged as #malicious when automated systems on #GitHub blocked them on the platform. Rather than noting they are malicious—and that developers who used #AIagents to work with them should assume their systems are compromised—the Microsoft-owned GitHub said it disabled the packages “due to a violation of GitHub's terms of service.” The text went on to encourage the package owner to contact GitHub.
    #security

    arstechnica.com/security/2026/

  6. 黒き太陽 Чорне сонце
    黒き太陽、突如世を夜に染め
    Чорне сонце раптом забарвлює світ у ніч

    note.com/poison_raika/n/n5ae31

    <>

    #black #sun #suddenly #dyes #world #night #display #royal #credential #make #greatness #known #world #leave #like #shoot #star

  7. CVE-2026-34474: Pre-auth #credential disclosure in #ZTE #H298A / #H108N via #ETHCheat...The short version: an ETHCheat branch returns credential-bearing #HTML before #authentication. The captured fields include the #admin #password, WLAN PSK, and ESSID, and a companion wizard #endpoint #exposes serial data.

    #cybersecurity #cybersec #security #exploited

  8. 黒き太陽 Чорне сонце
    黒き太陽、突如世を夜に染め
    Чорне сонце раптом забарвлює світ у ніч

    note.com/poison_raika/n/n5ae31

    <>

    #black #sun #suddenly #dyes #world #night #display #royal #credential #make #greatness #known #world #leave #like #shoot #star

  9. Thousands of consumer #routers hacked by Russia's #military

    The Russian military is once again #hacking home and small office routers in widespread operations that send unwitting users to sites that harvest #passwords and #credential tokens for use in #espionage campaigns, researchers said Tuesday.
    #russia #security #privacy #gru

    arstechnica.com/security/2026/

  10. Thousands of consumer #routers hacked by Russia's #military

    The Russian military is once again #hacking home and small office routers in widespread operations that send unwitting users to sites that harvest #passwords and #credential tokens for use in #espionage campaigns, researchers said Tuesday.
    #russia #security #privacy #gru

    arstechnica.com/security/2026/

  11. 🚨 Oh look, another day, another #PyPI disaster! 🎉 This time it's 'litellm', because who doesn't love their credentials being "borrowed"? 🤦‍♂️ Maybe they should've named it litell-uh-oh instead. 🙄
    github.com/BerriAI/litellm/iss #Litellm #Security #Disaster #Credential #Theft #OpenSource #Drama #HackerNews #ngated

  12. 🚨 Oh look, another day, another #PyPI disaster! 🎉 This time it's 'litellm', because who doesn't love their credentials being "borrowed"? 🤦‍♂️ Maybe they should've named it litell-uh-oh instead. 🙄
    github.com/BerriAI/litellm/iss #Litellm #Security #Disaster #Credential #Theft #OpenSource #Drama #HackerNews #ngated

  13. 黒き太陽 Чорне сонце
    黒き太陽、突如世を夜に染め
    Чорне сонце раптом забарвлює світ у ніч

    note.com/poison_raika/n/n5ae31

    <>

    #black #sun #suddenly #dyes #world #night #display #royal #credential #make #greatness #known #world #leave #like #shoot #star

  14. 🚨🚀 Breaking News: #Microsoft can't tell a #fake domain from a real one, so they've been sending your imaginary emails to Japan! 🎌🤖 Apparently, Outlook's idea of "autodiscover" is to discover how to #leak your credentials like a sieve. 🤦‍♂️
    tinyapps.org/blog/microsoft-mi #Outlook #Security #Issues #Domains #Credential #Japan #HackerNews #ngated

  15. 🚨🚀 Breaking News: #Microsoft can't tell a #fake domain from a real one, so they've been sending your imaginary emails to Japan! 🎌🤖 Apparently, Outlook's idea of "autodiscover" is to discover how to #leak your credentials like a sieve. 🤦‍♂️
    tinyapps.org/blog/microsoft-mi #Outlook #Security #Issues #Domains #Credential #Japan #HackerNews #ngated

  16. #Pentagon Introduces New Restrictions on #Reporter Access

    The #DepartmentofDefense will force reporters to pledge not to gather or use any information that had not been formally authorized for release, or risk losing their #credential to cover the #military.
    #Trump #journalism #journalist #dod

    nytimes.com/2025/09/20/busines