Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
19 résultats taggé Password  ✕
Cisco warns that Unified CM has hardcoded root SSH credentials https://www.bleepingcomputer.com/news/security/cisco-removes-unified-cm-callManager-backdoor-root-account/
02/07/2025 19:48:39
QRCode
archive.org
thumbnail

Cisco has removed a backdoor account from its Unified Communications Manager (Unified CM), which would have allowed remote attackers to log in to unpatched devices with root privileges.

Cisco Unified Communications Manager (CUCM), formerly known as Cisco CallManager, serves as the central control system for Cisco's IP telephony systems, handling call routing, device management, and telephony features.

The vulnerability (tracked as CVE-2025-20309) was rated as maximum severity, and it is caused by static user credentials for the root account, which were intended for use during development and testing.

bleepingcomputer EN CVE-2025-20309 2025 CUCM CallManager Unified Security Password Root Hardcoded Communications Cisco
NIST proposes barring some of the most nonsensical password rules https://arstechnica.com/security/2024/09/nist-proposes-barring-some-of-the-most-nonsensical-password-rules/?is=09685296f9ea1fb2ee0963f2febaeb3a55d8fb1eddbb11ed4bd2da49d711f2c7
28/09/2024 10:08:00
QRCode
archive.org
thumbnail

The National Institute of Standards and Technology (NIST), the federal body that sets technology standards for governmental agencies, standards organizations, and private companies, has proposed barring some of the most vexing and nonsensical password requirements. Chief among them: mandatory resets, required or restricted use of certain characters, and the use of security questions.

arstechnica EN 2024 NIST password rules best-practices standard rules
How Researchers Cracked an 11-Year-Old Password to a $3 Million Crypto Wallet | WIRED https://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/
29/05/2024 18:16:15
QRCode
archive.org
thumbnail

Thanks to a flaw in a decade-old version of the RoboForm password manager and a bit of luck, researchers were able to unearth the password to a crypto wallet containing a fortune.

wired EN 2024 RoboForm cryptocurrency bitcoin cracked password wallet
Google shares update on passkeys and new ways to protect accounts https://blog.google/technology/safety-security/google-passkeys-update-april-2024/
03/05/2024 09:07:42
QRCode
archive.org
thumbnail

For World Password Day, we’re sharing updates to passkeys across our products and sharing more ways we’re keeping people safe online.

google EN 2024 passkeys Password
Recent ‘MFA Bombing’ Attacks Targeting Apple Users – Krebs on Security https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/
27/03/2024 09:56:52
QRCode
archive.org

Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple's password reset feature. In this scenario, a target's Apple devices are forced to display dozens of system-level prompts that…

krebsonsecurity EN 2024 MFA-fatigue attack Apple MFA-bombing password
How a mistakenly published password exposed Mercedes-Benz source code https://techcrunch.com/2024/01/26/mercedez-benz-token-exposed-source-code-github/?guccounter=1
29/01/2024 07:12:21
QRCode
archive.org
thumbnail

Mercedes accidentally exposed a trove of sensitive data after a leaked security key gave “unrestricted access” to company’s source code.

techcrunch EN 2024 Mercedes exposed password Mercedes-Benz Source-Code GitHub
LastPass to enforce a 12-character requirement for master passwords https://www.scmagazine.com/news/lastpass-to-enforce-a-12-character-requirement-for-master-passwords?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
08/01/2024 11:01:45
QRCode
archive.org
thumbnail

Security pros say while the 12-character requirement by LastPass is a step in the right direction, teams still need to enforce multi-factor authentication and practice continuous monitoring.

scmagazine EN 2023 LastPass requirement password change
Bitwarden Heist - How to Break Into Password Vaults Without Using Passwords https://blog.redteam-pentesting.de/2024/bitwarden-heist/
05/01/2024 14:06:49
QRCode
archive.org
thumbnail

Sometimes, making particular security design decisions can have unexpected consequences. For security-critical software, such as password managers, this can easily lead to catastrophic failure: In this blog post, we show how Bitwarden’s Windows Hello …

redteam-pentesting.de 2024 Bitwarden Password Vaults Windows Hello
Weak password and infostealer blamed for Orange Spain outage https://www.theregister.com/2024/01/04/orange_spain_outage_breach/
05/01/2024 08:36:11
QRCode
archive.org
thumbnail

No 2FA or special characters to prevent database takeover and BGP hijack

theregister EN 2023 Orange Spain Weak password RIPE
High school changes every student’s password to ‘Ch@ngeme!’ https://techcrunch.com/2023/06/29/high-school-changes-every-students-password-to-chngeme/
02/07/2023 11:01:01
QRCode
archive.org
thumbnail

After a cybersecurity audit mistakenly reset everyone’s password, a high school changed every student’s password to “Ch@ngeme!” giving every student the chance to hack into any other student’s account, according to emails obtained by TechCrunch.

techcrunch EN 023 password Ch@ngeme! reset school
KeePass flaw allows retrieval of master password, PoC is public (CVE-2023-32784) https://www.helpnetsecurity.com/2023/05/17/cve-2023-32784/
17/05/2023 15:31:56
QRCode
archive.org
thumbnail

A vulnerability (CVE-2023-32784) in KeePass can be exploited to retrieve the master password from the software's memory.

helpnetsecurity EN 2023 CVE-2023-32784 password KeePass retrieve
GitHub - vdohney/keepass-password-dumper https://github.com/vdohney/keepass-password-dumper
17/05/2023 15:30:10
QRCode
archive.org
thumbnail

The vulnerability was assigned CVE-2023-32784. It should be fixed in KeePass 2.54, which should come out in ~July 2023. Thanks again to Dominik Reichl for his fast response and creative fix!

vdohney EN 2023 PoC KeePass dumper password CVE-2023-32784
PSA: upgrade your LUKS key derivation function https://mjg59.dreamwidth.org/66429.html
23/04/2023 11:23:25
QRCode
archive.org

Here's an article from a French anarchist describing how his (encrypted) laptop was seized after he was arrested, and material from the encrypted partition has since been entered as evidence against him. His encryption password was supposedly greater than 20 characters and included a mixture of cases, numbers, and punctuation, so in the absence of any sort of opsec failures this implies that even relatively complex passwords can now be brute forced, and we should be transitioning to even more secure passphrases.

Or does it? Let's go into what LUKS is doing in the first place. The actual data is typically encrypted with AES, an extremely popular and well-tested encryption algorithm. AES has no known major weaknesses and is not considered to be practically brute-forceable - at least, assuming you have a random key. Unfortunately it's not really practical to ask a user to type in 128 bits of binary every time they want to unlock their drive, so another approach has to be taken.

mjg59 EN Linux LUKS KDF cracked police encryption password AES
NortonLifeLock warns that hackers breached Password Manager accounts https://www.bleepingcomputer.com/news/security/nortonlifelock-warns-that-hackers-breached-password-manager-accounts/
16/01/2023 20:03:14
QRCode
archive.org
thumbnail

Gen Digital, formerly Symantec Corporation and NortonLifeLock, is sending data breach notifications to customers, informing them that hackers have successfully breached Norton Password Manager accounts in credential-stuffing attacks.

bleepingcomputer EN 2023 Password-manager NortonLifeLock breach Norton Password Manager credential-stuffing attack
DigitalOcean says customer email addresses were exposed after latest Mailchimp breach – TechCrunch https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/
17/08/2022 12:45:34
QRCode
archive.org
thumbnail

Cloud giant DigitalOcean says that some customers’ email addresses were exposed because of a recent “security incident” at email marketing company Mailchimp. In a scant blog post dated August 12, just two days after the company’s co-founder and long-time CEO Ben Chestnut stepped down, Mailchimp said a recent but undated attack saw threat actors targeting […]

techcrunch EN 2022 digitalocean mailchimp password phishing sms twilio
Comprehensive Threat Intelligence: Cisco Talos shares insights related to recent cyber attack on Cisco https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html?m=1
11/08/2022 20:22:21
QRCode
archive.org
thumbnail
  • On May 24, 2022, Cisco became aware of a potential compromise. Since that point, Cisco Security Incident Response (CSIRT) and Cisco Talos have been working to remediate.
  • During the investigation, it was determined that a Cisco employee’s credentials were compromised after an attacker gained control of a personal Google account where credentials saved in the victim’s browser were being synchronized.
talosintelligence EN 2022 Cisco attack Google sync password insights
Password policies of most top websites fail to follow best practices https://passwordpolicies.cs.princeton.edu/
17/06/2022 07:07:02
QRCode
archive.org

We examined the password policies of 120 of the most popular English-language websites in the world.

princeton paper en 2022 password passwords policies websites bestpractices
Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/
06/05/2022 16:19:39
QRCode
archive.org
thumbnail

Faster, easier and more secure sign-ins will be available to consumers across leading devices and platforms  Mountain View, California, MAY 5, 2022  – In a joint effort to make the web […]

FIDO fidoalliance EN 2022 Google Apple Microsoft Passwordless password Standard
Behold, a password phishing site that can trick even savvy users https://arstechnica.com/information-technology/2022/03/behold-a-password-phishing-site-that-can-trick-even-savvy-users/
27/03/2022 21:13:38
QRCode
archive.org
thumbnail

Just when you thought you'd seen every phishing trick out there, BitB comes along.

Behold password arstechnica EN 2022 phishing BitB
4521 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio