Massive breach spills credentials for thousands of sensitive networks
Summary
A massive breach exposed credentials for thousands of sensitive networks, including a NATO defense contractor, with attackers using a 45-GPU cluster to crack VPN authentication hashes and compromise Active Directory environments.
View Cached Full Text
Cached at: 06/17/26, 11:43 PM
Similar Articles
@hetmehtaa: my company got breached the attacker had access for 11 days on day 3 he emailed our IT helpdesk complained that the VPN…
A humorous yet alarming account of a company breach where the attacker, after 3 days of access, contacted IT helpdesk complaining about slow VPN, was given a password reset and upgraded access, then rated IT support 5 stars before being discovered during forensics.
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
A security researcher who infiltrated North Korean hacking systems for nearly two years reveals they breached hundreds of networks worldwide, impacting over 1,600 companies across 57 countries, with findings presented at Black Hat.
In stunning display of stupid, secret CISA credentials found in public GitHub repo
A public GitHub repository named 'Private-CISA' exposed plaintext passwords, SSH keys, and tokens belonging to CISA, allowing high-privilege access to AWS GovCloud accounts. The breach was discovered by GitGuardian and reported by Brian Krebs, following a previous incident where the acting CISA director leaked government documents via ChatGPT.
Keyv and friends compromised in active Shai-Hulud supply chain attack
Attackers compromised the GitHub account of the maintainer behind keyv and related npm caching libraries, injecting a credential-stealing worm across multiple packages with over 2 billion combined monthly installs.
Russia Hacked Routers to Steal Microsoft Office Tokens
Russian state-backed hackers (Forest Blizzard/APT28) used known vulnerabilities in old routers to hijack DNS settings and steal OAuth authentication tokens from Microsoft Office users, compromising over 200 organizations and 5,000 consumer devices without deploying malware.