Comment on 16 Billion Apple, Facebook, Google And Other Passwords Leaked — Act Now

<- View Parent
drspod@lemmy.ml ⁨2⁩ ⁨weeks⁩ ago

This forbes blog is about this article:

cybernews.com/…/billions-credentials-exposed-info…

The only silver lining here is that all of the datasets were exposed only briefly: long enough for researchers to uncover them, but not long enough to find who was controlling vast amounts of data. Most of the datasets were temporarily accessible through unsecured Elasticsearch or object storage instances.

So there isn’t really an explanation other than “somebody collected these somehow and left the data unsecured.”

The attack vector for infostealer malware is usually social engineering, getting unwary users to download infected trojanized software via phishing and malvertising etc.

If you follow security news, you will see articles about infostealer malware campaigns all the time.

www.theregister.com/…/minecraft_mod_malware/

thehackernews.com/…/malicious-pypi-package-masque…

thehackernews.com/…/rust-based-myth-stealer-malwa…

thehackernews.com/…/eddiestealer-malware-uses-cli…

source
Sort:hotnewtop