#password


New Spectre v2 attack variant leaks Linux root password hash in minutes

Sep 29, 2026 // 20:17

A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few […]

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Sep 23, 2026 // 19:07

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The […]

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Sep 3, 2026 // 16:57

Infostealer logs have evolved from an underground commodity into an operational security problem. For defenders, finding an exposed credential is only the beginning. In today’s […]

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Aug 24, 2026 // 15:03

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could […]

Password spraying attacks surge 155x as hackers exploit MFA gaps

Aug 19, 2026 // 17:17

Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving […]

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Aug 7, 2026 // 01:17

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. […]

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Aug 4, 2026 // 00:57

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at […]

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Aug 4, 2026 // 00:37

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at […]

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Aug 4, 2026 // 00:18

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at […]

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Jul 28, 2026 // 17:51

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to […]

1 2 3 Next