#password — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #password, aggregated by home.social.
-
Was just idly typing sample #password formations into https://passcheck.io to see what it thought. This one is the initials of the first line of a famous English novel and I was surprised at how many other people had apparently used it. Can you guess what it was? I asked my wife the same question and she got it right first time...
#security #literature #books -
Distinct Clusters Target Individuals of Interest to Russia
Three distinct suspected Russian cyber espionage threat clusters—UNC6293, UNC7005, and UNC5976—are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, governments, and think tanks across Europe and the United States. These groups conduct sophisticated phishing campaigns using app password phishing, OAuth phishing, device code phishing, and malware deployment. UNC6293 and UNC7005 are assessed with moderate confidence to be initial access clusters linked to ICE RELIC (formerly APT29), while UNC5976 appears distinct. Operations leverage social engineering through fake diplomatic invitations, conference registrations, and file sharing pages. UNC7005 was tied to hospitality captive portal redirects and deployed MaaS infostealers including VIDAR and ATOMIC. These actors abuse legitimate authentication mechanisms including Google OAuth, Microsoft device codes, and WhatsApp device linking to compromise personal accounts, making detection challenging for organizations.
Pulse ID: 6a8734bac622f3c7b2d9a633
Pulse Link: https://otx.alienvault.com/pulse/6a8734bac622f3c7b2d9a633
Pulse Author: AlienVault
Created: 2026-08-20 17:09:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT29 #CyberSecurity #Espionage #Europe #FileSharing #Google #Government #Hospital #InfoSec #InfoStealer #MaaS #Malware #Microsoft #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SMS #SocialEngineering #UnitedStates #Vidar #WhatsApp #Word #bot #AlienVault
-
Arthur Fry, born OTD in 1931, invented the adhesive used to create Post-it Notes https://cromwell-intl.com/cybersecurity/root-password.html?s=mb #cybersecurity #password
-
Arthur Fry, born OTD in 1931, invented the adhesive used to create Post-it Notes https://cromwell-intl.com/cybersecurity/hacker-passwords.html?s=mb #cybersecurity #password
-
Arthur Fry, born OTD in 1931, invented the adhesive used to create Post-it Notes https://cromwell-intl.com/cybersecurity/password.html?s=mb #cybersecurity #password
-
Arthur Fry, born OTD in 1931, invented the adhesive used to create Post-it Notes https://cromwell-intl.com/cybersecurity/password-breaking.html?s=mb #cybersecurity #password
-
Hey @bitwarden care to explain your surrender to a venture capital firm? You're treading awfully close to the precipice that #Lastpass tripped and fell into.
Otherwise a lot of us, me included will be consulting articles like these for our next password manager
https://www.passwordmanager.com/best-password-managers/
-
Arthur Fry, born OTD in 1931, invented the adhesive used to create Post-it Notes https://cromwell-intl.com/cybersecurity/basics/04-passwords.html?s=mb #cybersecurity #password
-
If you ever are stuck on updating a password because it requires you to add a special character, just end it with &Knuckles.
There is no character more special Knuckles.
-
Token is a mostly misunderstood term in IT technology:
Some think to know how expensive their AI use is, others expect to receive profits via cryptocurrencies, but we all use it to enter the password / passkeys for authentication after every click on the web.
It’s all true, but one thing isn’t marketing propaganda.
#token #ai #cryptogrpahy #myopinion #cryptocurrency #itsecurity #web #opinion #internet #authenticate #password #passkeys #marketing #propaganda
-
MacSync Stealer: C2 Infrastructure Rotation
On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs.
Pulse ID: 6a84bafb3c129cc2f9de2762
Pulse Link: https://otx.alienvault.com/pulse/6a84bafb3c129cc2f9de2762
Pulse Author: AlienVault
Created: 2026-08-18 20:05:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #Browser #CyberSecurity #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #Password #Proxy #RAT #TLS #Word #bot #cryptocurrency #AlienVault
-
MacSync Stealer Hides Behind 30+ Domains While Stealing Passwords and Sensitive Mac Data
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/macsync-stealer/
Pulse ID: 6a85b5fcbb36128c50223b08
Pulse Link: https://otx.alienvault.com/pulse/6a85b5fcbb36128c50223b08
Pulse Author: CyberHunter_NL
Created: 2026-08-19 13:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #Password #Passwords #RCE #Word #bot #CyberHunter_NL
-
Clop Returns with Custom Implant in Mass-Extortion Campaign
The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Pulse ID: 6a85530dde3c55da4658c63b
Pulse Link: https://otx.alienvault.com/pulse/6a85530dde3c55da4658c63b
Pulse Author: AlienVault
Created: 2026-08-19 06:54:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DataTheft #Extortion #ICS #InfoSec #Java #Manufacturing #OTX #OpenThreatExchange #Password #Passwords #RAT #SSL #Word #bot #AlienVault
-
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA is an active phishing-as-a-service toolkit built to steal Microsoft 365 credentials and authenticated sessions through Adversary-in-the-Middle attacks. Analysis shows 63.7% of identified victims are in the US, with Technology, Manufacturing, and Education among the most targeted industries. The operation generated thousands of compromise events between 2024 and 2026, including stolen session cookies, passwords, and SSO access. Once a Microsoft 365 session is hijacked, attackers gain access to corporate email, sensitive data, and trusted business accounts. The toolkit uses browser-based delivery through .htm, .xhtml, and .svg stagers, QR codes, JavaScript obfuscation, and WebSocket-based AiTM activity. Of 9,426 unique targeted email addresses, 4,532 were potentially compromised, representing approximately 48% success rate.
Pulse ID: 6a84c514863d37cbadb72833
Pulse Link: https://otx.alienvault.com/pulse/6a84c514863d37cbadb72833
Pulse Author: AlienVault
Created: 2026-08-18 20:48:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #AdversaryInTheMiddle #AitM #Browser #Cookies #CyberSecurity #Education #Email #HTML #InfoSec #Java #JavaScript #Manufacturing #Microsoft #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #Rust #SVG #Word #bot #AlienVault
-
Cl0p Hackers Exploit PTC Windchill Flaw to Steal Passwords and Sensitive Company Data
Indicators extracted from public reporting. Source: https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
Pulse ID: 6a854563c1a89b92936e12c9
Pulse Link: https://otx.alienvault.com/pulse/6a854563c1a89b92936e12c9
Pulse Author: CyberHunter_NL
Created: 2026-08-19 05:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cl0p #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Word #bot #CyberHunter_NL
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846abfbc588c465571b8cb
Pulse Link: https://otx.alienvault.com/pulse/6a846abfbc588c465571b8cb
Pulse Author: cryptocti
Created: 2026-08-18 14:22:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti
-
DCRat Campaign Targeting Users via SVG-Based HTML Smuggling
Trellix uncovered a DCRat phishing campaign using a Colombian judicial lure. A malicious SVG uses HTML smuggling to deliver a password protected archive, followed by DLL sideloading and process hollowing to run DCRat inside a legitimate Windows process and establish encrypted C2 communication.
Pulse ID: 6a846ac500763a217460eb4b
Pulse Link: https://otx.alienvault.com/pulse/6a846ac500763a217460eb4b
Pulse Author: cryptocti
Created: 2026-08-18 14:23:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #InfoSec #OTX #OpenThreatExchange #Password #Phishing #RAT #SVG #SideLoading #Trellix #Windows #Word #bot #cryptocti