Researchers fish out Fortune 500 companies' passwords from Dark Web. Guess the common one!
Thursday, October 31, 2019
"Cyber-criminals are smart and pragmatic. They focus on the shortest, cheapest and safest way to get your crown jewels. The great wealth of stolen credentials accessible on the Dark Web is a modern-day Klondike for mushrooming threat actors who don’t even need to invest in expensive 0day or time-consuming APTs," commented Ilia Kolochenko, CEO and founder of ImmuniWeb.
"With some persistence, they easily break-in being unnoticed by security systems and grab what they want. Worse, many such intrusions are technically non-investigable due to lack of logs or control over the breached [third-party] systems," he said.
The lax attitude on password management makes things easier for cyber-criminals. Approximately 42 percent of the stolen passwords were somehow related either to the victim’s company name or to the breached resource in question. On an average, 11 percent of the stolen passwords from one breach are identical. The most common password? Password! Read Full Article
Threatpost: Murky Details Surround Bed, Bath and Beyond Breach
Bleeping Computer: 21 Million Logins for Top 500 Firms Offered on the Dark Web