🦞🌯 Lobster Roll

Thread

Weak Password Used to Access Hypervisor, Deface OpenSSL Site (threatpost.com)
There was some speculation that a compromise of the hypervisor code itself was the way the OpenSSL site was defaced, but it now appears to just be a weak password.

Stories related to "Weak Password Used to Access Hypervisor, Deface OpenSSL Site" across the full archive.

Weak Password Used to Access Hypervisor, Deface OpenSSL Site (threatpost.com)
There was some speculation that a compromise of the hypervisor code itself was the way the OpenSSL site was defaced, but it now appears to just be a weak password.
Tulsi Gabbard Reused the Same Weak Password on Multiple Accounts for Years (wired.com)
453,491 cleartext Yahoo passwords released; 59% of users used the same password at Sony (troyhunt.com)
Cisco switches to weaker hashing scheme, passwords cracked wide open (arstechnica.com)
‘Password’ and ‘123456’ Still Commonly Used Passwords: Survey (sitepronews.com)
How hackers can access iPhone contacts and photos without a password (arstechnica.com)
iOS 10: Security Weakness Discovered, Backup Passwords Much Easier to Break (blog.elcomsoft.com)
Can or has NSA used legal powers to force weakened security of US goods? (schneier.com)
Cops used dead man’s finger in attempt to access his phone. It’s legal, but is it okay? (tampabay.com)
Oxy - A Security Focused Remote Access Tool (oxy-secure.app)
freenode Security Update: Reused Password Attack (freenode.net)
Over 1400 Western Australian government officials used 'Password123' as their password (nzherald.co.nz)
Weak default passwords for internet-connected devices banned in California from 2020 (bbc.com)
CBS All Access orders two seasons of "Star Trek: Lower Decks", a half-hour animated comedy series focused on the support crew (variety.com)
Bomb threat, sextortion spammers abused weakness at GoDaddy.com (krebsonsecurity.com)
How I abused 2FA to maintain persistence after a password change on multiple services (medium.com)
How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc) (medium.com)
Snapchat employees abused data access to spy on users (vice.com)
Security researcher successfully used false GDPR "right of access" requests to obtain extensive personal information about someone else (bbc.com)
Swedish police can use spyware to hunt criminal gangs – police to use the latest technology to access everyday encrypted apps used by criminals (sverigesradio.se)
Apps that access Google G Suite services using a username and password (as opposed to OAuth) will be restricted in June 2020, and blocked in February 2021 (gsuiteupdates.googleblog.com)
Encoding your WiFi access point password into a QR code (feeding.cloud.geek.nz)
How we abused Slack's TURN servers to gain access to internal services (rtcsec.com)
Nearly 11,000,000 kilograms of strawberries might get thrown in the trash in California each week due to weakened demand caused by coronavirus (laist.com)
Dutch researcher claims that he accessed US President Donald Trump's Twitter account by guessing password (theguardian.com)
Password generator in Kaspersky Password Manager used biased non-cryptographic PRNG (donjon.ledger.com)
Workarounds to Computer Access in Healthcare Organizations: You Want My Password or a Dead Patient? (cs.dartmouth.edu)
Workarounds to computer access in healthcare are sufficiently common that they often go unnoticed. Clinicians focus on patient care, not cybersecurity. We argue and demonstrate that understanding workarounds to healthcare workers’ computer access requires not only analyses of computer rules, but als...
Pre-hashing large password files used with PBKDFs (notes.volution.ro)
Are Redis ACL password protections weak? (blog.ovalerio.net)
Unanimous US Supreme Court preserves access to widely used abortion medication (apnews.com)