home.social

#passwordspraying — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passwordspraying, aggregated by home.social.

fetched live
  1. Leer van Laundry Bear: tips voor digitale weerbaarheid

    De AIVD en MIVD hebben op 27 mei 2025 een gezamenlijke waarschuwing uitgebracht over de Russische cybergroep Laundry Bear. Deze groep zat achter de hack op de Nederlandse politie in september 2024. Daarbij werden werkgerelateerde contactgegevens van alle agenten buitgemaakt. De publicatie gaat in op hoe de groep te werk gaat en hoe je je organisatie beschermt tegen dergelijke aanvallen.

    Laundry Bear voert sinds 2024 gerichte cyberaanvallen uit op westerse overheden en organisaties. Hun focus ligt op de overheid, defensie, defensieleveranciers, maatschappelijke organisaties en digitale dienstverleners.

    De groep gebruikt bekende aanvalsmethoden, zoals passwordspraying, het misbruiken van sessiecookies en Living-off-the-Land-technieken (gebruikmaken van bestaande software binnen een systeem).

    Tips van AIVD en MIVD

    De AIVD en MIVD adviseren organisaties in deze sectoren – en daarbuiten – om hun digitale weerbaarheid te versterken. Belangrijke aanbevelingen zijn:

    • Gebruik phishingbestendige multifactor-authenticatie (MFA);
    • Stel toegangsregels in op basis van IP-adressen en apparaten;
    • Beperk het gebruik van sessiecookies;
    • Beheer alle apparaten centraal. Vermijd Bring Your Own Device (BYOD);
    • Train medewerkers op digitale veiligheid;
    • Pas de 5 basisprincipes van het NCSC toe.

    Lees meer over de publicatie. Bekijk ook de 5 basisprincipes op de website van het NCSC.

    Dit is een automatisch geplaatst bericht. Vragen of opmerkingen kun je richten aan @[email protected]

    #bringYourOwnDevice #cyberaanvallen #cybergroep #cybersecurity #LivingOffLandTechnieken #nieuwsbrief102025 #passwordspraying #phishing #sessiecookies #weerbaarheid

  2. Leer van Laundry Bear: tips voor digitale weerbaarheid

    De AIVD en MIVD hebben op 27 mei 2025 een gezamenlijke waarschuwing uitgebracht over de Russische cybergroep Laundry Bear. Deze groep zat achter de hack op de Nederlandse politie in september 2024. Daarbij werden werkgerelateerde contactgegevens van alle agenten buitgemaakt. De publicatie gaat in op hoe de groep te werk gaat en hoe je je organisatie beschermt tegen dergelijke aanvallen.

    Laundry Bear voert sinds 2024 gerichte cyberaanvallen uit op westerse overheden en organisaties. Hun focus ligt op de overheid, defensie, defensieleveranciers, maatschappelijke organisaties en digitale dienstverleners.

    De groep gebruikt bekende aanvalsmethoden, zoals passwordspraying, het misbruiken van sessiecookies en Living-off-the-Land-technieken (gebruikmaken van bestaande software binnen een systeem).

    Tips van AIVD en MIVD

    De AIVD en MIVD adviseren organisaties in deze sectoren – en daarbuiten – om hun digitale weerbaarheid te versterken. Belangrijke aanbevelingen zijn:

    • Gebruik phishingbestendige multifactor-authenticatie (MFA);
    • Stel toegangsregels in op basis van IP-adressen en apparaten;
    • Beperk het gebruik van sessiecookies;
    • Beheer alle apparaten centraal. Vermijd Bring Your Own Device (BYOD);
    • Train medewerkers op digitale veiligheid;
    • Pas de 5 basisprincipes van het NCSC toe.

    Lees meer over de publicatie. Bekijk ook de 5 basisprincipes op de website van het NCSC.

    Dit is een automatisch geplaatst bericht. Vragen of opmerkingen kun je richten aan @[email protected]

    #bringYourOwnDevice #cyberaanvallen #cybergroep #cybersecurity #LivingOffLandTechnieken #nieuwsbrief102025 #passwordspraying #phishing #sessiecookies #weerbaarheid

  3. Thousands of hacked TP-Link routers used in years-long account takeover attacks - Hackers working on behalf of the Chinese government are using a botnet of ... - arstechnica.com/information-te #passwordspraying #microsoft #security #botnets #tp-link #biz&it

  4. Thousands of hacked TP-Link routers used in years-long account takeover attacks - Hackers working on behalf of the Chinese government are using a botnet of ... - arstechnica.com/information-te #passwordspraying #microsoft #security #botnets #tp-link #biz&it

  5. #Russia's #CozyBear (#APT29) dives into cloud environments with a new bag of tricks
    One of the ways Cozy Bear breaks into victims' cloud services is via #bruteforce and #passwordspraying attacks aimed at getting access to accounts used to manage apps and services, and to those belonging to users who no longer work at the victim org – in other words, which that aren't regularly monitored by a human. Additionally, #Kremlin's spies frequently use tokens to access accounts
    theregister.com/2024/02/27/rus

  6. #Russia's #CozyBear (#APT29) dives into cloud environments with a new bag of tricks
    One of the ways Cozy Bear breaks into victims' cloud services is via #bruteforce and #passwordspraying attacks aimed at getting access to accounts used to manage apps and services, and to those belonging to users who no longer work at the victim org – in other words, which that aren't regularly monitored by a human. Additionally, #Kremlin's spies frequently use tokens to access accounts
    theregister.com/2024/02/27/rus

  7. Among the many articles reporting that Russian hackers accessed Microsoft Execs' Emails, I found this explanation of #passwordspraying - the alleged access method - usefully clear and concise:

    "The company in its regulatory disclosure said attackers had executed a password spraying attack in late November and gained access to "a legacy non-production test tenant account." Password spraying is a technique in which hackers enter the same password guess into a number of accounts in an attempt to avoid account lockout by betting that at least one user uses a previously leaked password or has one that is easy to guess."

    databreachtoday.com/microsoft-

  8. Among the many articles reporting that Russian hackers accessed Microsoft Execs' Emails, I found this explanation of #passwordspraying - the alleged access method - usefully clear and concise:

    "The company in its regulatory disclosure said attackers had executed a password spraying attack in late November and gained access to "a legacy non-production test tenant account." Password spraying is a technique in which hackers enter the same password guess into a number of accounts in an attempt to avoid account lockout by betting that at least one user uses a previously leaked password or has one that is easy to guess."

    databreachtoday.com/microsoft-