Marcel SIneM(S)US · @simsus
211 followers · 5076 posts · Server social.tchncs.de

👋​Hey everyone!

We just released a new episode on the Shared Security Show discussing the White House's National Cybersecurity Strategy and BetterHelp's $7.8 million fine from the FTC.

We also cover credential stuffing attacks on Chick-fil-A and the importance of reading terms of service and privacy policies.

Tune in now to learn more!

Watch on YouTube: youtu.be/8u0Ht_K_gVU

Listen direct from our website:
sharedsecurity.net/2023/03/13/

#podcast #cybersecurity #sharedsecurityshow #nationalcybersecuritystrategy #ftc #BetterHelp #credentialstuffing

Last updated 2 years ago

Adam Gardner · @agardnerit
12 followers · 41 posts · Server techhub.social

When you attempt to login on a website and it confirms that the email IS registered. I’ve heard that sites SHOULDN’T do that because it’s a security risk. How? How does knowing that X email is registered present a security risk? Is it due to the potential for credential stuffing / reuse attacks on that site or just user profile (I know Adam has an account at X)?

#security #credentialreuse #credentialstuffing

Last updated 2 years ago

Marcel SIneM(S)US ☑️ · @simsus
161 followers · 2010 posts · Server social.tchncs.de
Mark Gardner ‍🤑 · @mjgardner
473 followers · 1918 posts · Server social.sdf.org

@danhon accounts on a devalued site, but phishing nonetheless. However, those who use the same elsewhere will become victims of .

#phishing #password #credentialstuffing #infosec #security #cybersecurity

Last updated 2 years ago

Marcel SIneM(S)US ☑️ · @simsus
141 followers · 1746 posts · Server social.tchncs.de
PrivacyDigest · @PrivacyDigest
193 followers · 513 posts · Server mas.to
Marcel SIneM(S)US ☑️ · @simsus
137 followers · 1663 posts · Server social.tchncs.de
Chip Kroh · @lckrohjr
138 followers · 1771 posts · Server fediverse.krohsnest.com

PayPal accounts breached in large-scale credential stuffing attack: January 19, 2023 09:47 AM

PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data.

Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites.

bleepingcomputer.com/news/secu

#hack #paypal #credentialstuffing #breach

Last updated 2 years ago

PrivacyDigest · @PrivacyDigest
193 followers · 513 posts · Server mas.to
Gᴇʀᴀʀᴅ Bᴀʀʀʏ · @gtbarry
45 followers · 248 posts · Server mastodon.social

Social Security Numbers Stolen in PayPal Cyberattack

The Social Security numbers and other personal information of about 35,000 PayPal users were stolen in a December credential-stuffing attack. In addition to Social Security numbers, usernames, addresses, dates of birth and individual tax identification numbers also may have been compromised.

cnet.com/tech/services-and-sof

#fintech #paypal #cyberattack #databreach #credentialstuffing #security #cybersecurity #ssn #infosec #hackers #hacking #hacked

Last updated 2 years ago

ThreatX · @threatx
1 followers · 1 posts · Server infosec.exchange

From the ThreatX Labs labs team: @neocoder recently published “Anatomy of a Targeted Credential Stuffing Attack.”

This paper analyzes a recent distributed, botnet-based credential stuffing attack the Labs team observed. In the paper, @neocoder highlights exactly how these attacks are carried out.

The research paper is available here (no forms or anything like that): info.threatx.com/hubfs/ug/Cred

#credentialstuffing #securityresearch #security #botnet

Last updated 2 years ago

Nicola Ferrini · @nicferr
17 followers · 122 posts · Server mastodon.uno

Just another friendly reminder to not reuse credentials - ever! I use a self hosted instance of bitwarden, but there are plenty of tools to manage credentials.

bleepingcomputer.com/news/secu

#cybersecuritynews #paypal #credentialstuffing #credentialstuffingattack

Last updated 2 years ago

Bob Carver · @cybersecboardrm
71 followers · 73 posts · Server infosec.exchange

PayPal is sending out data breach notifications to thousands of users who had their accounts accessed through credential stuffing attacks that exposed some personal data. bleepingcomputer.com/news/secu

#cybersecurity #paypal #breach #credentialstuffing

Last updated 2 years ago

Anonymous Germany · @AnonNewsDE
52377 followers · 9018 posts · Server social.tchncs.de

Vor zwei Tagen hat der Generalstaatsanwaltschaft im US-Bundesstaat Maine ein gemeldet.

Laut der Meldung führte ein Sicherheitsvorfall dazu, dass Unbefugte Zugang zu Namen, Adressen, Sozialversicherungsnummern, individuellen Steueridentifikationsnummern und Geburtsdaten erhielten [...] die Unbefugten konnten zwischen dem 6. Dezember 2022 und dem 8. Dezember 2022 auf die betroffenen Konten zugreifen".

Artikel englisch
jdsupra.com/legalnews/paypal-i

#xp #credentialstuffing #datenleck #paypal

Last updated 2 years ago

heise online · @heiseonline
40041 followers · 1687 posts · Server mastodon.social

Paypal: Datenleck nach Zugangsdaten-Durchtesten von Angreifern

Paypal hat ein Datenleck bei der Generalstaatsanwaltschaft von Maine gemeldet. Angreifer hätten Zugangsdaten durchgetestet und Zugriff auf Konten erhalten.

heise.de/news/Paypal-Datenleck

#credentialstuffing #cyberangriff #cybercrime #datenklau #paypal #security #zugriff

Last updated 2 years ago

Charles U. Farley (he/him) · @freakazoid
979 followers · 21060 posts · Server retro.social

It was a attack, meaning the attackers just tried a bunch of breached email addresses and passwords from other sites. People who don't use the same email address and password on other sites were unaffected. Which includes you, right? RIGHT?

#credentialstuffing #paypal #infosec #breach

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1829 followers · 4074 posts · Server social.tchncs.de