Glossary
Credential Stuffing
An automated attack that tries username and password pairs leaked from one breach against other websites, exploiting the fact that many people reuse passwords across services. It is highly effective at scale and is a primary reason security guidance discourages password reuse and recommends MFA.
Recent coverage mentioning Credential Stuffing
IDScan Sued Over Alleged Breach Impacting 153 Million Drivers
IDScan faces lawsuits after a dark-web service allegedly offered to sell 153 million driver's licenses and millions of other identity documents.
French Hospital Fined €500K for GDPR Data Breach
France's CNIL fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive medical data of 727,000 patients.
Entra Log Analysis: Detecting Password Spray Attacks with PowerShell
Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.
Sakura Internet Breach Exposes 1.36 Million Accounts
Japanese cloud provider Sakura Internet discloses a data breach exposing customer contract and membership data for up to 1.36 million accounts.
US Charges Iranian Hackers in $3.4B Intellectual Property Theft
US charges 17 Iranian hackers from Mabna Institute for a state-sponsored campaign stealing 31.5 TB of academic and corporate intellectual property since 2013.
Mitigating Large-Scale Credential Attacks and Password Spraying
Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.
Advertisement