eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

228
active users

#credentials

0 posts0 participants0 posts today

Mysterious Database of 184 Million Records Exposes Vast Array of Login #Credentials
A trove of #breach data, which has now been taken down, includes user logins for platforms including Apple, Google, and Meta. Among the exposed accounts are ones linked to dozens of governments.
wired.com/story/mysterious-dat
archive.ph/ybk1x
#security #ITSec

WIRED · Mysterious Database of 184 Million Records Exposes Vast Array of Login CredentialsBy Matt Burgess

Mysterious Database of 184 Million Records Exposes Vast Array of #Login #Credentials | WIRED

A trove of #breached data, which has now been taken down, includes user logins for platforms including #Apple , #Google , and #Meta. Among the exposed accounts are ones linked to dozens of governments.
#security #privacy

wired.com/story/mysterious-dat

WIRED · Mysterious Database of 184 Million Records Exposes Vast Array of Login CredentialsBy Matt Burgess

Malicious #npm Packages Infect 3,200+ #Cursor Users With #Backdoor, Steal #Credentials

#Cybersecurity researchers have flagged 3 malicious npm packages that are designed to target the Apple #macOS version of Cursor

"Disguised as developer tools offering 'the cheapest Cursor API,' these packages steal user credentials, fetch an encrypted payload from threat actor-controlled infrastructure, overwrite Cursor's main.js file, & disable auto-updates to maintain persistence,"

thehackernews.com/2025/05/mali

If you use #Gmail, you need to know about this #phishing attack, as described by Malwarebytes Labs: "Cybercriminals are abusing Google’s infrastructure, creating emails that appear to come from Google ... to persuade people into handing over their Google #account #credentials." tinyurl.com/47y6pvus

Malwarebytes · All Gmail users at risk from clever replay attackAll Google accounts could end up compromised by a clever replay attack on Gmail users abusing Google infrastructure.

Who needs #phishing when your login's already in the wild?
Stolen #credentials edge out email tricks for cloud break-ins because they're so easy to get
Criminals used stolen credentials more frequently than email phishing to gain access into their victims' IT systems last year, marking the first time that compromised login details claimed the number two spot in Mandiant's list of most common initial infection vectors.
theregister.com/2025/04/23/sto
#itsec #security

The Register · Who needs phishing when your login's already in the wild?By Jessica Lyons

There are lots of #plugins/services that allow you to sync your #browser saved website #credentials across multiple devices; even #sync between ecosystems (chrome/google account <--> Microsoft acc).

But - leaving aside "password sharing is Baaaad" and "probably violates a TOS somewhere" issues - does anyone know of a plugin/service that allows you to share a saved login with a trusted other?

e.g. share an newspaper #subscription account with a partner _without_ a shared google account.

#PasswordReuse is rampant: nearly half of observed user #logins are compromised
Many users recycle #passwords, creating a ripple effect of risk when #credentials are leaked.
Based on Cloudflare's observed traffic between Sep-Nov 2024, 41% of successful logins across websites protected by Cloudflare involve compromised passwords.
When including bots 52% of all authentication requests contain leaked passwords found in our 15B record database, including Have I Been Pwned.
blog.cloudflare.com/password-r

The Cloudflare Blog · Password reuse is rampant: nearly half of observed user logins are compromisedNearly half of observed login attempts across websites protected by Cloudflare involved leaked credentials. The pervasive issue of password reuse is enabling automated bot attacks and account takeovers on a massive scale.

The @w3c Federated Identity #WorkingGroup aims to create specs for secure, #privacy friendly, and user-controlled #authentication and credential presentation
▶️ w3.org/groups/wg/fedid/

Their updated charter introduces the Digital Credentials #API, which facilitates user agents in managing access to and presenting digital #credentials, such as a driver's license, government-issued ID, or other forms of digital credentials.

🎬 Find out more about this work by @sphcow: youtu.be/GI3UTZJ0Ue4

Ah, yes, the timeless art of #B&E, now with a ✨ #tech #twist! ✨ Our hero, Eric, wields his phone like a magic wand, 🪄 casting the spell of "#default #credentials" to waltz into #apartment buildings. Who needs a life of crime when you have expired credentials and missed ferry rides? 🚢 In 2025, breaking and entering is just a casual #Sunday #hobby, right after brunch. 🥞
ericdaigle.ca/posts/breaking-i #hacking #HackerNews #ngated

www.ericdaigle.caBreaking into dozens of apartment buildings in five minutes on my phone – Eric DaigleWhat a place to use default credentials

#ElonMusk staff Have #Infiltrated Another #Government Agency - Elon Musk’s former employees are trying to use #WhiteHouse #credentials to access General Services Administration #GSA tech, giving them the potential to remote into #laptops, read #emails, and more, sources say. mass #cybercrime attack against the federal government #infosec this #cybersecurity breach by non government agents is a crime. the damage will be irreparable. wired.com/story/elon-musk-lack see also newsie.social/deck/@bespacific

WIRED · Elon Musk’s Friends Have Infiltrated the General Services AdministrationBy Makena Kelly