Advertisement
Securing SSO Environments Against Modern Credential Attacks
An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.
ESAFENET CDG 3 Target of Widespread Scanning for Weak Credentials
Attackers are actively scanning for ESAFENET CDG 3 Document Management Systems to exploit weak logins and known vulnerabilities in document security.
Chick-fil-A Data Breach: Over 13K Accounts Compromised via Credential Stuffing
Chick-fil-A confirms a data breach affecting over 13,000 customer accounts through credential stuffing, leading to drained rewards and gift cards.
23andMe $18M Settlement: Lessons in Protecting Genetic Data Privacy
23andMe agrees to an $18 million settlement with 43 attorneys general following a 2023 data breach that exposed sensitive genetic data of millions.
Nathaniel Saavedra Sentenced for 2022 DraftKings Account Takeover
21-year-old hacker 'Snoopy' sentenced to 18 months in prison for the DraftKings cyberattack that compromised 60,000 accounts via credential stuffing in 2022.
Rise of 'Search Your Target' Markets for Stolen Credentials
Explores the emerging underground market where attackers pay to precisely search stolen credential databases for specific target organizations and accounts.
Advertisement
Coordinated SSH Brute Force Attacks: Three-Month Analysis & Defenses
Analysis of coordinated SSH brute-force attacks over three months, detailing observed patterns and providing actionable strategies to protect SSH servers.
Dashlane Brute-Force Attack: Safeguarding Encrypted Password Vaults
Dashlane reports a brute-force attack resulting in the download of encrypted user vaults. Learn about the impact and remediation steps for this identity threat.
Dashlane Account Lockouts: Brute-Force Attacks Target Password Manager Users
Dashlane users are experiencing widespread account lockouts due to brute-force attacks. Learn how credential stuffing impacts password managers and mitigation strategies.
23andMe 2023 Data Breach: AG Sues Over Exposed Health Data
California AG sues 23andMe for a 2023 credential stuffing data breach exposing genetic and personal health data of 6.9 million users.
California Sues 23andMe for Failing to Protect User Genetic Data
California Attorney General files lawsuit against 23andMe (Chrome Holding Co.) for security failures leading to the massive 2023 credential stuffing breach.
Ukraine Identifies Odesa-Based Infostealer Operator
Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.
Zara Data Breach: 197,000 Customer Records Leaked on Hacking Forum
Spanish fashion retailer Zara suffers a significant data breach exposing PII for 197,000 customers, fueling concerns over targeted phishing and identity theft.
Roblox Account Hijacking: 610,000 Accounts Compromised and Sold
Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.
Rituals Cosmetics Breach: My Rituals Database PII Exposure
Rituals Cosmetics discloses a data breach affecting its My Rituals membership database. Learn about the PII exposure, risk of credential stuffing, and mitigation.
Defending Against Identity-Based Attacks and Stolen Credentials
Identity-based attacks use stolen credentials to bypass security. Learn why these attacks are the primary entry point and how to mitigate the risk.
DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense
Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.
DraftKings Credential Stuffing: Memphis Man Sentenced to 30 Months
Kamerin Stokes sentenced to 30 months for selling 60,000+ hacked DraftKings accounts. Technical analysis of the 2022 credential stuffing attack and mitigations.
Honeypot Data Analysis: Predictable Year and Season Password Patterns
SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.
Managing Recurring Credential Incident Risks in Enterprise Environments
Analyze the financial and operational impact of recurring credential incidents, beyond the $4.4 million average breach cost cited in recent industry reports.
Residential Proxies Bypass 78% of IP Reputation Checks
Residential proxies effectively bypass IP reputation systems in 78% of sessions, enabling widespread bot attacks like credential stuffing and account takeovers.
Defeating Industrialized Fraud: Identifying Standardized Attack Patterns
Analysis of the industrialized fraud ecosystem and how standardized attack infrastructure allows financial institutions to detect patterns before losses occur.
Loblaw Data Breach: Customer PII Exposed in Recent Security Incident
Loblaw confirms a data breach impacting customer names, emails, and phone numbers. Analyze the risk of phishing and credential stuffing in the retail sector.
Starbucks Data Breach: Unauthorized Access to Partner Central Accounts
Starbucks discloses a data breach affecting hundreds of employees, exposing SSNs and financial details via compromised Partner Central accounts in May 2024.