Goto

Collaborating Authors

 credential


Hackers want your nudes. Here's how to keep your privates, private

PCWorld

Here's how to keep your privates, private Sexortion is an old concept, but the FBI's latest warning about it is new. Long before the internet, people blackmailed others over sexually explicit photos or videos. But this week, the US Federal Bureau of Investigation released a fresh warning around hackers and sexortion--an alert aimed at both adults and children. In its public service announcement, the FBI says sexual exploitation actors have been breaking into "social media and personal accounts" to download any saved explicit content. The stolen images and video then gets spread to criminal forums and marketplaces, often with personal details like name, email, phone number, social media username, and date of birth also shared.


You're being lazy with passwords the wrong way

PCWorld

When you purchase through links in our articles, we may earn a small commission. Reusing passwords is the risky kind of shortcut. A password manager lets you do less work while keeping every account better protected. I have a hot take: You're probably lazy with passwords in the wrong way. You plug the same password into every single app, website, and service you don't care about.


Hackers didn't break into Chick-fil-A. They just logged in

PCWorld

Chick-fil-A customers in 10 states and D.C. experienced a data breach where hackers accessed accounts using stolen credentials from other sites through "credential stuffing." The attack exposed names, email addresses, and partial payment details, but wasn't due to Chick-fil-A's security being compromised directly. PCWorld recommends affected users change passwords immediately and use password managers to create unique, strong passwords for preventing future credential stuffing attacks. Sometimes you want a quick bite to eat. So you hop online, create an account for your favorite joint, and get to ordering. But a lot of people make a major mistake while doing this--which some Chick-fil-A customers just found out the hard way. On Wednesday, news broke about a Chick-fil-A data breach, with customers in ten states and the District of Columbia affected.


A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots

WIRED

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots A new type of malware can worm deep into AI coding systems to steal data and logins--and can flip a "death switch" to destroy files and keep out real users. As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems--all while finding new ways to cover their tracks. Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as "Altered Spider") and North Korean groups are targeting the AI software supply chain. "This is one of the campaigns that we've seen showing that this is an emerging attack class," Meyers tells WIRED.


Claude did my FreshDirect shopping, with help from 1Password

PCWorld

PCWorld reports that Claude AI's new 1Password integration allows secure automation of online tasks like grocery shopping without exposing user passwords. The connector uses separate channels to maintain security, with 1Password handling login credentials while Claude performs website interactions on desktop Mac. Testing showed successful FreshDirect order completion, demonstrating potential for streamlining routine online chores, though social logins and passkeys aren't currently supported.


You can now grant Claude access to your 1Password credentials

Engadget

If you like putting Claude's AI agents to work on personal chores but are concerned about giving them access to your credentials, there's a new solution available. Users can now authorize Claude to complete real-world tasks like booking travel and managing accounts securely with credentials injected directly to the target system on their behalf, 1Password explains. Security has emerged as a big issue when using agents to complete tasks on your behalf. Sharing credentials directly with an agent exposes them to the model, its memory and the systems behind it, which can pose a risk if the model gets hacked . To solve that problem, 1Password built a zero-exposure security framework that allows agents to use stored credentials from your 1Password vault without them reaching the model.


124 million passwords added to breach database. Yours may be in there, too

PCWorld

PCWorld reports that Have I Been Pwned added 56 million email addresses and 124 million passwords from infostealer malware targeting Windows PCs. These credentials were stolen directly from infected devices rather than corporate breaches, with users often unaware of the ongoing data theft. Immediate password changes, two-factor authentication, and unique passwords for each service are essential to protect against these prevalent cybercriminal tools. The data breach notification service Have I Been Pwned (HIBP) has added a large number of compromised login credentials to its database. In total, 56.3 million email addresses and 124 million passwords have been added. What makes this dataset notable is its origin. Unlike many previous entries, it does not stem from a single cyberattack on an online service. Instead, HIBP says the information was extracted directly from infected computers and devices.


Robot mower flaw could open your home network

FOX News

Yarbo robot mowers reportedly contain serious security flaws that could expose owners to remote access, live camera viewing and Wi-Fi credential theft, a new report says.


149 Million Usernames and Passwords Exposed by Unsecured Database

WIRED

This "dream wish list for criminals" includes millions of Gmail, Facebook, banking logins, and more. The researcher who discovered it suspects they were collected using infostealing malware. A database containing 149 million account usernames and passwords--including 48 million for Gmail, 17 million for Facebook, and 420,000 for the cryptocurrency platform Binance --has been removed after a researcher reported the exposure to the hosting provider. The longtime security analyst who discovered the database, Jeremiah Fowler, could not find indications of who owned or operated it, so he worked to notify the host, which took down the trove because it violated a terms of service agreement. In addition to email and social media logins for a number of platforms, Fowler also observed credentials for government systems from multiple countries as well as consumer banking and credit card logins and media streaming platforms.


Comparing AI Agents to Cybersecurity Professionals in Real-World Penetration Testing

arXiv.org Artificial Intelligence

We present the first comprehensive evaluation of AI agents against human cybersecurity professionals in a live enterprise environment. We evaluate ten cybersecurity professionals alongside six existing AI agents and ARTEMIS, our new agent scaffold, on a large university network consisting of ~8,000 hosts across 12 subnets. ARTEMIS is a multi-agent framework featuring dynamic prompt generation, arbitrary sub-agents, and automatic vulnerability triaging. In our comparative study, ARTEMIS placed second overall, discovering 9 valid vulnerabilities with an 82% valid submission rate and outperforming 9 of 10 human participants. While existing scaffolds such as Codex and CyAgent underperformed relative to most human participants, ARTEMIS demonstrated technical sophistication and submission quality comparable to the strongest participants. We observe that AI agents offer advantages in systematic enumeration, parallel exploitation, and cost -- certain ARTEMIS variants cost $18/hour versus $60/hour for professional penetration testers. We also identify key capability gaps: AI agents exhibit higher false-positive rates and struggle with GUI-based tasks.