<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Credential Stuffing</title><description>Cybersecurity articles tagged #Credential Stuffing on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Securing SSO Environments Against Modern Credential Attacks</title><link>https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</guid><description>An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.</description><pubDate>Tue, 28 Jul 2026 14:10:10 GMT</pubDate><category>Sso Security</category><category>MFA</category><category>Credential Stuffing</category><category>Identity Hardening</category><category>FIDO2</category></item><item><title>ESAFENET CDG 3 Target of Widespread Scanning for Weak Credentials</title><link>https://runtimerebel.com/blog/esafenet-cdg-3-target-of-widespread-scanning-for-weak-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/esafenet-cdg-3-target-of-widespread-scanning-for-weak-credentials</guid><description>Attackers are actively scanning for ESAFENET CDG 3 Document Management Systems to exploit weak logins and known vulnerabilities in document security.</description><pubDate>Sun, 26 Jul 2026 17:03:34 GMT</pubDate><category>ESAFENET</category><category>CDG 3</category><category>Credential Stuffing</category><category>Document Management System</category><category>Data Leakage Prevention</category></item><item><title>Chick-fil-A Data Breach: Over 13K Accounts Compromised via Credential Stuffing</title><link>https://runtimerebel.com/blog/chick-fil-a-data-breach-over-13k-accounts-compromised-via-credential-stuffing</link><guid isPermaLink="true">https://runtimerebel.com/blog/chick-fil-a-data-breach-over-13k-accounts-compromised-via-credential-stuffing</guid><description>Chick-fil-A confirms a data breach affecting over 13,000 customer accounts through credential stuffing, leading to drained rewards and gift cards.</description><pubDate>Fri, 24 Jul 2026 17:41:55 GMT</pubDate><category>Chick Fil a</category><category>Data Breach</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Customer Data</category></item><item><title>23andMe $18M Settlement: Lessons in Protecting Genetic Data Privacy</title><link>https://runtimerebel.com/blog/23andme-18m-settlement-lessons-in-protecting-genetic-data-privacy</link><guid isPermaLink="true">https://runtimerebel.com/blog/23andme-18m-settlement-lessons-in-protecting-genetic-data-privacy</guid><description>23andMe agrees to an $18 million settlement with 43 attorneys general following a 2023 data breach that exposed sensitive genetic data of millions.</description><pubDate>Thu, 16 Jul 2026 14:03:41 GMT</pubDate><category>23andMe</category><category>Data Breach</category><category>Credential Stuffing</category><category>Privacy Settlement</category></item><item><title>Nathaniel Saavedra Sentenced for 2022 DraftKings Account Takeover</title><link>https://runtimerebel.com/blog/nathaniel-saavedra-sentenced-for-2022-draftkings-account-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/nathaniel-saavedra-sentenced-for-2022-draftkings-account-takeover</guid><description>21-year-old hacker &apos;Snoopy&apos; sentenced to 18 months in prison for the DraftKings cyberattack that compromised 60,000 accounts via credential stuffing in 2022.</description><pubDate>Thu, 25 Jun 2026 00:59:20 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Cybercrime Sentencing</category><category>Snoopy</category></item><item><title>Rise of &apos;Search Your Target&apos; Markets for Stolen Credentials</title><link>https://runtimerebel.com/blog/rise-of-search-your-target-markets-for-stolen-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/rise-of-search-your-target-markets-for-stolen-credentials</guid><description>Explores the emerging underground market where attackers pay to precisely search stolen credential databases for specific target organizations and accounts.</description><pubDate>Mon, 22 Jun 2026 17:37:29 GMT</pubDate><category>Stolen Credentials</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Dark Web</category><category>Underground Market</category><category>Threat Intelligence</category></item><item><title>Coordinated SSH Brute Force Attacks: Three-Month Analysis &amp; Defenses</title><link>https://runtimerebel.com/blog/coordinated-ssh-brute-force-attacks-three-month-analysis-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/coordinated-ssh-brute-force-attacks-three-month-analysis-defenses</guid><description>Analysis of coordinated SSH brute-force attacks over three months, detailing observed patterns and providing actionable strategies to protect SSH servers.</description><pubDate>Thu, 18 Jun 2026 09:59:47 GMT</pubDate><category>SSH</category><category>Brute Force</category><category>Credential Stuffing</category><category>Threat Intelligence</category><category>Network Security</category><category>Fail2ban</category></item><item><title>Dashlane Brute-Force Attack: Safeguarding Encrypted Password Vaults</title><link>https://runtimerebel.com/blog/dashlane-brute-force-attack-safeguarding-encrypted-password-vaults</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-brute-force-attack-safeguarding-encrypted-password-vaults</guid><description>Dashlane reports a brute-force attack resulting in the download of encrypted user vaults. Learn about the impact and remediation steps for this identity threat.</description><pubDate>Tue, 02 Jun 2026 09:34:12 GMT</pubDate><category>Dashlane</category><category>Brute Force</category><category>Credential Stuffing</category><category>Password Manager</category><category>Data Exfiltration</category></item><item><title>Dashlane Account Lockouts: Brute-Force Attacks Target Password Manager Users</title><link>https://runtimerebel.com/blog/dashlane-account-lockouts-brute-force-attacks-target-password-manager-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-account-lockouts-brute-force-attacks-target-password-manager-users</guid><description>Dashlane users are experiencing widespread account lockouts due to brute-force attacks. Learn how credential stuffing impacts password managers and mitigation strategies.</description><pubDate>Mon, 01 Jun 2026 21:15:04 GMT</pubDate><category>Dashlane</category><category>Password Manager</category><category>Brute Force</category><category>Credential Stuffing</category><category>Account Lockout</category><category>MFA</category></item><item><title>23andMe 2023 Data Breach: AG Sues Over Exposed Health Data</title><link>https://runtimerebel.com/blog/23andme-2023-data-breach-ag-sues-over-exposed-health-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/23andme-2023-data-breach-ag-sues-over-exposed-health-data</guid><description>California AG sues 23andMe for a 2023 credential stuffing data breach exposing genetic and personal health data of 6.9 million users.</description><pubDate>Fri, 29 May 2026 20:54:34 GMT</pubDate><category>23andMe</category><category>Data Breach</category><category>Credential Stuffing</category><category>Genetic Data</category><category>Health Data</category><category>California AG</category><category>MFA</category></item><item><title>California Sues 23andMe for Failing to Protect User Genetic Data</title><link>https://runtimerebel.com/blog/california-sues-23andme-for-failing-to-protect-user-genetic-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/california-sues-23andme-for-failing-to-protect-user-genetic-data</guid><description>California Attorney General files lawsuit against 23andMe (Chrome Holding Co.) for security failures leading to the massive 2023 credential stuffing breach.</description><pubDate>Fri, 29 May 2026 13:19:44 GMT</pubDate><category>23andMe</category><category>California AG</category><category>Credential Stuffing</category><category>CCPA</category><category>Genetic Privacy</category></item><item><title>Ukraine Identifies Odesa-Based Infostealer Operator</title><link>https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</link><guid isPermaLink="true">https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</guid><description>Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.</description><pubDate>Thu, 21 May 2026 00:58:31 GMT</pubDate><category>Infostealer</category><category>Ukraine Cyberpolice</category><category>Data Theft</category><category>Credential Stuffing</category><category>Odesa</category></item><item><title>Zara Data Breach: 197,000 Customer Records Leaked on Hacking Forum</title><link>https://runtimerebel.com/blog/zara-data-breach-197000-customer-records-leaked-on-hacking-forum</link><guid isPermaLink="true">https://runtimerebel.com/blog/zara-data-breach-197000-customer-records-leaked-on-hacking-forum</guid><description>Spanish fashion retailer Zara suffers a significant data breach exposing PII for 197,000 customers, fueling concerns over targeted phishing and identity theft.</description><pubDate>Fri, 08 May 2026 12:38:28 GMT</pubDate><category>Zara</category><category>PII</category><category>Have I Been Pwned</category><category>Credential Stuffing</category><category>Retail Security</category></item><item><title>Roblox Account Hijacking: 610,000 Accounts Compromised and Sold</title><link>https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</link><guid isPermaLink="true">https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</guid><description>Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.</description><pubDate>Wed, 29 Apr 2026 20:30:38 GMT</pubDate><category>Roblox</category><category>Account Takeover</category><category>Credential Stuffing</category><category>Cybercrime</category><category>Identity Theft</category></item><item><title>Rituals Cosmetics Breach: My Rituals Database PII Exposure</title><link>https://runtimerebel.com/blog/rituals-cosmetics-breach-my-rituals-database-pii-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/rituals-cosmetics-breach-my-rituals-database-pii-exposure</guid><description>Rituals Cosmetics discloses a data breach affecting its My Rituals membership database. Learn about the PII exposure, risk of credential stuffing, and mitigation.</description><pubDate>Thu, 23 Apr 2026 16:41:37 GMT</pubDate><category>Rituals</category><category>PII Theft</category><category>Credential Stuffing</category><category>Identity Security</category><category>Retail Cybersecurity</category></item><item><title>Defending Against Identity-Based Attacks and Stolen Credentials</title><link>https://runtimerebel.com/blog/defending-against-identity-based-attacks-and-stolen-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-identity-based-attacks-and-stolen-credentials</guid><description>Identity-based attacks use stolen credentials to bypass security. Learn why these attacks are the primary entry point and how to mitigate the risk.</description><pubDate>Tue, 21 Apr 2026 12:30:18 GMT</pubDate><category>Identity Based Attacks</category><category>Credential Stuffing</category><category>Phishing</category><category>Initial Access</category></item><item><title>DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense</title><link>https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</guid><description>Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.</description><pubDate>Fri, 17 Apr 2026 12:29:34 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Insider Threat</category><category>Identity Theft</category></item><item><title>DraftKings Credential Stuffing: Memphis Man Sentenced to 30 Months</title><link>https://runtimerebel.com/blog/draftkings-credential-stuffing-memphis-man-sentenced-to-30-months</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-credential-stuffing-memphis-man-sentenced-to-30-months</guid><description>Kamerin Stokes sentenced to 30 months for selling 60,000+ hacked DraftKings accounts. Technical analysis of the 2022 credential stuffing attack and mitigations.</description><pubDate>Fri, 17 Apr 2026 08:43:09 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Fraud</category><category>Cybercrime Sentencing</category></item><item><title>Honeypot Data Analysis: Predictable Year and Season Password Patterns</title><link>https://runtimerebel.com/blog/honeypot-data-analysis-predictable-year-and-season-password-patterns</link><guid isPermaLink="true">https://runtimerebel.com/blog/honeypot-data-analysis-predictable-year-and-season-password-patterns</guid><description>SANS ISC research reveals how attackers exploit predictable password patterns, such as years and seasons, driven by outdated rotation policies.</description><pubDate>Thu, 09 Apr 2026 08:43:49 GMT</pubDate><category>Password Security</category><category>Honeypot Analysis</category><category>Credential Stuffing</category><category>SANS ISC</category><category>Authentication</category></item><item><title>Managing Recurring Credential Incident Risks in Enterprise Environments</title><link>https://runtimerebel.com/blog/managing-recurring-credential-incident-risks-in-enterprise-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/managing-recurring-credential-incident-risks-in-enterprise-environments</guid><description>Analyze the financial and operational impact of recurring credential incidents, beyond the $4.4 million average breach cost cited in recent industry reports.</description><pubDate>Tue, 07 Apr 2026 12:27:43 GMT</pubDate><category>Credential Stuffing</category><category>Identity Security</category><category>Breach Prevention</category><category>Access Management</category></item><item><title>Residential Proxies Bypass 78% of IP Reputation Checks</title><link>https://runtimerebel.com/blog/residential-proxies-bypass-78-of-ip-reputation-checks</link><guid isPermaLink="true">https://runtimerebel.com/blog/residential-proxies-bypass-78-of-ip-reputation-checks</guid><description>Residential proxies effectively bypass IP reputation systems in 78% of sessions, enabling widespread bot attacks like credential stuffing and account takeovers.</description><pubDate>Thu, 02 Apr 2026 16:26:17 GMT</pubDate><category>Residential Proxies</category><category>IP Reputation</category><category>Bot Attacks</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Netacea</category><category>Cybercrime</category></item><item><title>Defeating Industrialized Fraud: Identifying Standardized Attack Patterns</title><link>https://runtimerebel.com/blog/defeating-industrialized-fraud-identifying-standardized-attack-patterns</link><guid isPermaLink="true">https://runtimerebel.com/blog/defeating-industrialized-fraud-identifying-standardized-attack-patterns</guid><description>Analysis of the industrialized fraud ecosystem and how standardized attack infrastructure allows financial institutions to detect patterns before losses occur.</description><pubDate>Thu, 02 Apr 2026 08:35:16 GMT</pubDate><category>Payment Fraud</category><category>Credential Stuffing</category><category>Fraud Shops</category><category>Botnets</category></item><item><title>Loblaw Data Breach: Customer PII Exposed in Recent Security Incident</title><link>https://runtimerebel.com/blog/loblaw-data-breach-customer-pii-exposed-in-recent-security-incident</link><guid isPermaLink="true">https://runtimerebel.com/blog/loblaw-data-breach-customer-pii-exposed-in-recent-security-incident</guid><description>Loblaw confirms a data breach impacting customer names, emails, and phone numbers. Analyze the risk of phishing and credential stuffing in the retail sector.</description><pubDate>Sun, 15 Mar 2026 12:15:31 GMT</pubDate><category>Loblaw</category><category>PII Exposure</category><category>Retail Security</category><category>Credential Stuffing</category></item><item><title>Starbucks Data Breach: Unauthorized Access to Partner Central Accounts</title><link>https://runtimerebel.com/blog/starbucks-data-breach-unauthorized-access-to-partner-central-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/starbucks-data-breach-unauthorized-access-to-partner-central-accounts</guid><description>Starbucks discloses a data breach affecting hundreds of employees, exposing SSNs and financial details via compromised Partner Central accounts in May 2024.</description><pubDate>Fri, 13 Mar 2026 12:20:01 GMT</pubDate><category>Starbucks</category><category>Partner Central</category><category>PII Exposure</category><category>Credential Stuffing</category><category>Identity Theft</category></item><item><title>Loblaw Data Breach: Analyzing the PC Optimum Account Resets</title><link>https://runtimerebel.com/blog/loblaw-data-breach-analyzing-the-pc-optimum-account-resets</link><guid isPermaLink="true">https://runtimerebel.com/blog/loblaw-data-breach-analyzing-the-pc-optimum-account-resets</guid><description>Canadian retail giant Loblaw notifies customers of a security breach affecting PC Optimum accounts, prompting a mandatory session reset for all users.</description><pubDate>Fri, 13 Mar 2026 00:34:33 GMT</pubDate><category>Loblaw</category><category>Credential Stuffing</category><category>Retail Security</category><category>Pc Optimum</category><category>Account Takeover</category></item><item><title>Automated AI-Driven Exploitation of FortiGate Management Interfaces in AWS Environments</title><link>https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</guid><description>Threat actors are utilizing artificial intelligence to automate credential stuffing and exploit exposed administrative ports on Fortinet devices within AWS…</description><pubDate>Mon, 23 Feb 2026 12:21:29 GMT</pubDate><category>FortiGate</category><category>AWS</category><category>Credential Stuffing</category><category>AI</category><category>Network Security</category></item><item><title>AI-Automated Campaign Targets Global FortiGate Edge Infrastructure</title><link>https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</guid><description>A Russian-speaking threat actor leveraged generative AI to automate the compromise of over 600 FortiGate devices across 55 countries between January and February 2026.</description><pubDate>Mon, 23 Feb 2026 04:05:57 GMT</pubDate><category>FortiGate</category><category>GenAI</category><category>Credential Stuffing</category><category>Threat Intelligence</category><category>Network Security</category></item></channel></rss>