#passwordspraying — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #passwordspraying, aggregated by home.social.
-
TeamFiltration was built to safeguard systems, but now it's fueling attacks on over 80,000 accounts. How did a trusted tool flip sides and empower hackers? Discover the twist behind this dual-use dilemma.
#teamfiltration
#cybersecurity
#cyberattacks
#penetrationtesting
#passwordspraying -
Leer van Laundry Bear: tips voor digitale weerbaarheid
De AIVD en MIVD hebben op 27 mei 2025 een gezamenlijke waarschuwing uitgebracht over de Russische cybergroep Laundry Bear. Deze groep zat achter de hack op de Nederlandse politie in september 2024. Daarbij werden werkgerelateerde contactgegevens van alle agenten buitgemaakt. De publicatie gaat in op hoe de groep te werk gaat en hoe je je organisatie beschermt tegen dergelijke aanvallen.
Laundry Bear voert sinds 2024 gerichte cyberaanvallen uit op westerse overheden en organisaties. Hun focus ligt op de overheid, defensie, defensieleveranciers, maatschappelijke organisaties en digitale dienstverleners.
De groep gebruikt bekende aanvalsmethoden, zoals passwordspraying, het misbruiken van sessiecookies en Living-off-the-Land-technieken (gebruikmaken van bestaande software binnen een systeem).
Tips van AIVD en MIVD
De AIVD en MIVD adviseren organisaties in deze sectoren – en daarbuiten – om hun digitale weerbaarheid te versterken. Belangrijke aanbevelingen zijn:
- Gebruik phishingbestendige multifactor-authenticatie (MFA);
- Stel toegangsregels in op basis van IP-adressen en apparaten;
- Beperk het gebruik van sessiecookies;
- Beheer alle apparaten centraal. Vermijd Bring Your Own Device (BYOD);
- Train medewerkers op digitale veiligheid;
- Pas de 5 basisprincipes van het NCSC toe.
Lees meer over de publicatie. Bekijk ook de 5 basisprincipes op de website van het NCSC.
Dit is een automatisch geplaatst bericht. Vragen of opmerkingen kun je richten aan @[email protected]
#bringYourOwnDevice #cyberaanvallen #cybergroep #cybersecurity #LivingOffLandTechnieken #nieuwsbrief102025 #passwordspraying #phishing #sessiecookies #weerbaarheid
-
Leer van Laundry Bear: tips voor digitale weerbaarheid
De AIVD en MIVD hebben op 27 mei 2025 een gezamenlijke waarschuwing uitgebracht over de Russische cybergroep Laundry Bear. Deze groep zat achter de hack op de Nederlandse politie in september 2024. Daarbij werden werkgerelateerde contactgegevens van alle agenten buitgemaakt. De publicatie gaat in op hoe de groep te werk gaat en hoe je je organisatie beschermt tegen dergelijke aanvallen.
Laundry Bear voert sinds 2024 gerichte cyberaanvallen uit op westerse overheden en organisaties. Hun focus ligt op de overheid, defensie, defensieleveranciers, maatschappelijke organisaties en digitale dienstverleners.
De groep gebruikt bekende aanvalsmethoden, zoals passwordspraying, het misbruiken van sessiecookies en Living-off-the-Land-technieken (gebruikmaken van bestaande software binnen een systeem).
Tips van AIVD en MIVD
De AIVD en MIVD adviseren organisaties in deze sectoren – en daarbuiten – om hun digitale weerbaarheid te versterken. Belangrijke aanbevelingen zijn:
- Gebruik phishingbestendige multifactor-authenticatie (MFA);
- Stel toegangsregels in op basis van IP-adressen en apparaten;
- Beperk het gebruik van sessiecookies;
- Beheer alle apparaten centraal. Vermijd Bring Your Own Device (BYOD);
- Train medewerkers op digitale veiligheid;
- Pas de 5 basisprincipes van het NCSC toe.
Lees meer over de publicatie. Bekijk ook de 5 basisprincipes op de website van het NCSC.
Dit is een automatisch geplaatst bericht. Vragen of opmerkingen kun je richten aan @[email protected]
#bringYourOwnDevice #cyberaanvallen #cybergroep #cybersecurity #LivingOffLandTechnieken #nieuwsbrief102025 #passwordspraying #phishing #sessiecookies #weerbaarheid
-
De Russische cyberactor Laundry Bear is een nieuwe, maar alarmerende speler op het wereldtoneel van cyberdreigingen.
Podcast Spotify: https://open.spotify.com/episode/4Mtg8ieEiANP2D9engr4F7?si=GvOX_uqMSgOnuLDPWF3jIg
Podcast Youtube: https://youtu.be/TIfFZ3RfOq8?si=JP-RIwSvnSsQLVZK
Artikel Cybercrimeinfo: https://www.ccinfo.nl/menu-onderwijs-ontwikkeling/cybercrime/cyberoorlog/2532381_laundry-bear-de-russische-cyberdreiging-die-nederland-en-de-politie-raakt
#LaundryBear #RussischeCyberdreiging #Cybercrime #Cyberoorlog #AIVD #MIVD #Nederland #Politie #GeopolitiekeDreiging #Cybersecurity #Phishing #PasswordSpraying #Cyberaanvallen #Spionage
-
Storm-1977 targets education sector with password spraying, Microsoft warns – Source: securityaffairs.com https://ciso2ciso.com/storm-1977-targets-education-sector-with-password-spraying-microsoft-warns-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #cryptominingmalware #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #passwordspraying #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime
-
Storm-1977 targets education sector with password spraying, Microsoft warns – Source: securityaffairs.com https://ciso2ciso.com/storm-1977-targets-education-sector-with-password-spraying-microsoft-warns-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #cryptominingmalware #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #passwordspraying #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime
-
Top 10 Passwords Hackers Use to Breach RDP – Is Yours at Risk? https://hackread.com/top-10-passwords-hackers-use-to-breach-rdp/ #PasswordSpraying #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #Microsoft #Security #Password #RDP
-
Top 10 Passwords Hackers Use to Breach RDP – Is Yours at Risk? https://hackread.com/top-10-passwords-hackers-use-to-breach-rdp/ #PasswordSpraying #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #Microsoft #Security #Password #RDP
-
Top 10 Passwords Hackers Use to Breach RDP – Is Yours at Risk? – Source:hackread.com https://ciso2ciso.com/top-10-passwords-hackers-use-to-breach-rdp-is-yours-at-risk-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #PasswordSpraying #cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #Microsoft #Hackread #Password #security #RDP
-
Top 10 Passwords Hackers Use to Breach RDP – Is Yours at Risk? – Source:hackread.com https://ciso2ciso.com/top-10-passwords-hackers-use-to-breach-rdp-is-yours-at-risk-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #PasswordSpraying #cybersecurity #Vulnerability #CyberAttacks #CyberAttack #BruteForce #Microsoft #Hackread #Password #security #RDP
-
#PasswordSpraying-Angriff auf #M365-Konten von #Botnet mit über 130.000 Drohnen | Security https://www.heise.de/news/Password-Spraying-Angriff-auf-M365-Konten-von-Botnet-mit-ueber-130-000-Drohnen-10294301.html
-
Botnet of 130K Devices Targets Microsoft 365 in Password-Spraying Attack – Source:hackread.com https://ciso2ciso.com/botnet-of-130k-devices-targets-microsoft-365-in-password-spraying-attack-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #PasswordSpraying #cybersecurity #CyberAttacks #Microsoft365 #CyberAttack #Microsoft #Hackread #security #malware #botnet #IoT
-
Botnet of 130K Devices Targets Microsoft 365 in Password-Spraying Attack – Source:hackread.com https://ciso2ciso.com/botnet-of-130k-devices-targets-microsoft-365-in-password-spraying-attack-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #PasswordSpraying #cybersecurity #CyberAttacks #Microsoft365 #CyberAttack #Microsoft #Hackread #security #malware #botnet #IoT
-
🚨 A botnet of 130,000 hacked devices is launching a massive Password-Spraying attack on Microsoft 365 and bypassing MFA 🔓⚠️
Read: https://hackread.com/botnet-devices-microsoft-365-password-spraying-attack/
-
🚨 A botnet of 130,000 hacked devices is launching a massive Password-Spraying attack on Microsoft 365 and bypassing MFA 🔓⚠️
Read: https://hackread.com/botnet-devices-microsoft-365-password-spraying-attack/
-
Chinese threat actors use Quad7 botnet in password-spray attacks – Source: securityaffairs.com https://ciso2ciso.com/chinese-threat-actors-use-quad7-botnet-in-password-spray-attacks-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #passwordspraying #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #Quad7botnet #CyberCrime #hacking #Malware
-
Chinese threat actors use Quad7 botnet in password-spray attacks – Source: securityaffairs.com https://ciso2ciso.com/chinese-threat-actors-use-quad7-botnet-in-password-spray-attacks-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #passwordspraying #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #Quad7botnet #CyberCrime #hacking #Malware
-
Thousands of hacked TP-Link routers used in years-long account takeover attacks - Hackers working on behalf of the Chinese government are using a botnet of ... - https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/ #passwordspraying #microsoft #security #botnets #tp-link #biz&it
-
Thousands of hacked TP-Link routers used in years-long account takeover attacks - Hackers working on behalf of the Chinese government are using a botnet of ... - https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/ #passwordspraying #microsoft #security #botnets #tp-link #biz&it
-
‘Unprecedented Scale’ of Credential Stuffing Attacks Observed: Okta https://thecyberexpress.com/credential-stuffing-attacks-surge-okta/ #credentialstuffingattacks #TheCyberExpressNews #credentialstuffing #CybersecurityNews #passwordspraying #CyberEssentials #TheCyberExpress #DataBreachNews #passwordspray #bruteforce #CiscoTalso #dataleaks #Okta
-
‘Unprecedented Scale’ of Credential Stuffing Attacks Observed: Okta https://thecyberexpress.com/credential-stuffing-attacks-surge-okta/ #credentialstuffingattacks #TheCyberExpressNews #credentialstuffing #CybersecurityNews #passwordspraying #CyberEssentials #TheCyberExpress #DataBreachNews #passwordspray #bruteforce #CiscoTalso #dataleaks #Okta
-
#Russia's #CozyBear (#APT29) dives into cloud environments with a new bag of tricks
One of the ways Cozy Bear breaks into victims' cloud services is via #bruteforce and #passwordspraying attacks aimed at getting access to accounts used to manage apps and services, and to those belonging to users who no longer work at the victim org – in other words, which that aren't regularly monitored by a human. Additionally, #Kremlin's spies frequently use tokens to access accounts
https://www.theregister.com/2024/02/27/russia_cozy_bear_new_ttps/ -
#Russia's #CozyBear (#APT29) dives into cloud environments with a new bag of tricks
One of the ways Cozy Bear breaks into victims' cloud services is via #bruteforce and #passwordspraying attacks aimed at getting access to accounts used to manage apps and services, and to those belonging to users who no longer work at the victim org – in other words, which that aren't regularly monitored by a human. Additionally, #Kremlin's spies frequently use tokens to access accounts
https://www.theregister.com/2024/02/27/russia_cozy_bear_new_ttps/ -
Among the many articles reporting that Russian hackers accessed Microsoft Execs' Emails, I found this explanation of #passwordspraying - the alleged access method - usefully clear and concise:
"The company in its regulatory disclosure said attackers had executed a password spraying attack in late November and gained access to "a legacy non-production test tenant account." Password spraying is a technique in which hackers enter the same password guess into a number of accounts in an attempt to avoid account lockout by betting that at least one user uses a previously leaked password or has one that is easy to guess."
https://www.databreachtoday.com/microsoft-russian-hackers-had-access-to-executives-emails-a-24152
-
Among the many articles reporting that Russian hackers accessed Microsoft Execs' Emails, I found this explanation of #passwordspraying - the alleged access method - usefully clear and concise:
"The company in its regulatory disclosure said attackers had executed a password spraying attack in late November and gained access to "a legacy non-production test tenant account." Password spraying is a technique in which hackers enter the same password guess into a number of accounts in an attempt to avoid account lockout by betting that at least one user uses a previously leaked password or has one that is easy to guess."
https://www.databreachtoday.com/microsoft-russian-hackers-had-access-to-executives-emails-a-24152
-
SecurityAffairs: Iranian Peach Sandstorm group behind recent password spray attacks https://securityaffairs.com/150868/intelligence/iranian-peach-sandstorm-password-spray.html #informationsecuritynews #ITInformationSecurity #PierluigiPaganini #passwordspraying #SecurityAffairs #PasswordSpreay #PeachSandstorm #BreakingNews #Cyberwarfare #Intelligence #SecurityNews #hackingnews #Hacking #Iran #APT