search
Password
Trends
- 1New Android malware RatHat records screen touches to steal passwords●RatHat is a new Android malware that records your screen touches to steal passwords
A new Android threat called RatHat has been reported by Mashable. The malware records screen touches, allowing attackers to capture passwords and other credentials as users type them. It adds to growing concern over Android security and mobile malware capable of harvesting login details directly from infected devices.
- 2
Online fashion retailer Asos is facing reports of a hack after customers using its app received alerts suggesting their data may have been breached. The story, first reported by The Times, is spreading rapidly across search trends in the UK, US, France, Italy, Germany, Australia, Sweden and the Netherlands. Shoppers are reacting with concern over what customer information may have been exposed and whether they should change their passwords.
- 3
Online fashion retailer ASOS is facing questions after customers reported receiving notifications suggesting their accounts had been hacked, with messages warning company bosses of a possible data leak. Users took to social media and news comments to compare alerts and seek reassurance. The company has not yet fully explained the scope of any breach, and shoppers are being urged to change their passwords as a precaution.
- 4Old-school forum launched on open protocol with keypair identity▼Show HN: An old school forum on an open protocol – your identity is a keypair
A developer has launched a new old school-style forum built on Nostr, an open social protocol. Instead of accounts and passwords, users' identities are cryptographic keypairs, meaning no central authority controls logins. The project revives classic forum formats on decentralised infrastructure, drawing interest among Hacker News readers curious about alternatives to corporate social platforms.
- 5Password field limit locks users out of Vanguard logins●<input type="password" maxlength="20"> prevents me from logging into Vanguard
A developer has written about being unable to log into Vanguard because the brokerage's login form caps passwords at 20 characters using an input maxlength attribute, silently truncating longer passwords. The post argues this practice is harmful, since users with longer passwords may be locked out or misled about what credentials are valid, and it has drawn attention on Hacker News.
- 6c't columnist describes switching to a new password manager▼Mein Umzug auf einen neuen Passwort-Manager
German tech magazine c't has published a personal account of moving from one password manager to another, walking through what prompted the switch and how the migration was carried out. Readers are discussing which password managers are worth trusting, how to export and import vaults safely, and what the move says about the state of the tools many people rely on for their most sensitive logins.
- 7Digital Independence Day: volunteers help users switch to open source●Hier wird das Internet repariert! Morgen ist digitaler Unabhängigkeitstag. Viele Freiwillige helfen euch beim Umstieg au
German-speaking internet users are promoting a Digital Independence Day, a day when volunteers help others move away from big-tech services to open-source alternatives. The initiative covers messengers, search engines, browsers, smartphone operating systems, cloud storage, password managers and online shopping, with helpers offering guidance for people making the switch to freer, more independent software.
- 8Remembering Nipsey Russell, Beloved Game Show Panelist●Julius "Nipsey" Russell (September 15, 1918 – October 2, 2005) was an American entertainer best known for his appearance
Julius "Nipsey" Russell (1918–2005) is being remembered as an American entertainer best known as a panelist on classic game shows from the 1960s through the 1990s, including Match Game, Password, Hollywood Squares and To Tell the Truth. Posts recounting his career are circulating among fans of vintage American television.
- 9Security messaging: hashed passwords, encrypted data●Concerned about what happens to your information? * User passwords are hashed. * Sensitive information is encrypted at r
A security-focused account is highlighting how user information is protected: passwords are hashed, sensitive information is encrypted at rest, and data is not shared with any AI model. The message stresses that security is not only about tools but about how information is handled, and invites readers to learn more and sign up.
- 10
Austrian daily Die Presse is drawing attention to how easily guessable passwords such as "Superman" or "Metallica" make users targets for attackers, prompting renewed discussion in Germany and Austria about password security. Commenters and readers are weighing whether password managers offer a practical solution for people juggling dozens of online accounts.
- 11K4I Street app organizes daily life in one place●K4I Street K4I Street is a personal productivity and information management application designed to help users organize
K4I Street is a personal productivity and information management application designed to help users organize important parts of their daily life in a single private space. The app brings together tools for managing passwords, plans, schedules and training, positioning itself as an all-in-one solution for personal organization. Details on pricing, availability and developer background remain limited.
- 12Scam losses from hijacked UK social media accounts up 400%▼Money stolen by scammers hijacking UK social media accounts rises 400% https://www.theguardian.com/money/2026/oct/05/sca
Fraudsters hijacking people's social media accounts to swindle their friends and followers have taken 400% more money from UK victims, according to a Guardian report. The scammers take over accounts, then pose as the owner to ask contacts for money or exploit trusted profiles for cons. The steep rise is being flagged as a warning to users to secure accounts with strong passwords and two-factor authentication.
- 13Mortgage servicer Rushmore criticised for password rules blocking quotes▼This dumb password rule is from Rushmore Loan Management Services. Hmmm.. why are they afraid of double and single quote
Security-conscious users are mocking Rushmore Loan Management Services for a password policy that rejects single and double quote characters. Poorly designed password restrictions are a recurring target of ridicule among information security professionals, who argue arbitrary character bans suggest bad handling of user input and weaker overall security practices.
- 14Switching to a new open-source password manager●Mein Umzug auf einen neuen Passwort-Manager (Open Source)
The German tech publication c't describes its move to a new open-source password manager, walking through the reasons for switching and what the changeover involves. The piece has drawn strong engagement from readers interested in practical alternatives to mainstream or proprietary password tools.
- 15Hotels Urged to Strengthen Defenses Against Password Attacks▼How Hotels Can Prevent Password Attacks and Protect Guest Information |
Hotel Technology News reports that hotels face growing risk from password attacks that can expose guest information such as payment details and identity records. The piece outlines steps hospitality operators can take, including stronger password policies, multi-factor authentication and staff training, to protect guest data and avoid breaches that damage reputation and trigger regulatory penalties.
- 16Debate over whether passkeys' lack of backup makes them phishing resistant●@ steveriggins @ agowa338 @ vineethkuruvath @ monkeydom @ iamkonstantin @ acdha @ farseen On a related note, I saw someo
A technical discussion is underway about passkeys, the passwordless login credentials promoted as a phishing-resistant replacement for passwords. One participant noted a Reddit argument that the inability to back up passkeys is precisely what makes them phishing resistant, since secrets that cannot be exported cannot be handed over to attackers. Commenters are weighing whether that trade-off justifies the lack of portability across devices.
- 17c't writer switches to an open source password manager●Mein Umzug auf einen neuen Passwort-Manager (Open Source) Das Passwort-Chaos aufzuräumen, kann überfordern. Passwort-Man
A German technology journalist describes moving all saved passwords to a new open source password manager. The article argues that cleaning up scattered, reused passwords can feel overwhelming, and that password managers bring order across operating systems, with the option of choosing an open source tool. The piece doubles as practical guidance for readers considering the same switch amid ongoing concern about password security.
- 18CISO's 'clever' password mocked as weak security practice●CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch Replacing letters with symbols still doesn’t make it good.
A chief information security officer is being ridiculed after it emerged he relied on a password that only swapped letters for symbols and numbers, spelling out 'really good password' in leetspeak, while neglecting to apply an available patch. Security commentators note that character substitution is a well-known trick that attackers' cracking tools handle easily, and that skipping patches is a more basic failure than any password choice.
- 19How to make SSH use a password instead of a key●Need to test password-based SSH login, or connect to a host without offering your usual key? You can... # programming #
A technical guide is circulating explaining how to force SSH to use password authentication instead of your default SSH key, useful when testing password-based logins or connecting to hosts where your usual key should not be offered. Readers in programming and devops circles are sharing it as a handy tip, particularly for beginners working with remote servers and authentication troubleshooting.
- 20Keycloak flaw lets stolen passwords bypass mandatory MFA●CVE-2026-105305 affects Red Hat build of Keycloak. The OIDC Device Authorization Grant flow does not enforce a client's
A vulnerability tracked as CVE-2026-105305 affects the Red Hat build of Keycloak. The OIDC Device Authorization Grant flow fails to enforce a client's minimum authentication level, meaning a stolen password could bypass mandatory multi-factor authentication and gain access to the Admin REST API. No exploitation has been confirmed, and Red Hat has a fix available. Security practitioners are sharing the advisory and urging admins to patch promptly.
- 21EU survey finds cybersecurity awareness high but habits lag▼EU Cybersecurity awareness high but everyday practices lag, Eurobarometer shows
A new Eurobarometer survey shows that people across the European Union are highly aware of cybersecurity threats, but their everyday online practices do not match that awareness. The findings highlight a gap between knowing about risks such as phishing or weak passwords and actually taking protective steps, prompting calls in Brussels for better practical guidance and consumer education on digital safety.
- 22MetLife mocked over restrictive password rules●This dumb password rule is from MetLife. Max length of 20 characters, no special characters allowed. Pasting into the se
MetLife is being criticised online for requiring account passwords of no more than 20 characters, banning special characters, and blocking pasting into its password confirmation field. Security commentators say such rules push users toward weaker passwords and discourage password managers, running contrary to widely accepted guidance from standards bodies like NIST.
- 23
German technology magazine c't is highlighting its pick for the best password manager, in a piece that has drawn tens of thousands of likes. The recommendation is striking a chord with readers weighing how to store login credentials securely, a topic that keeps resurfacing as data breaches and phishing attempts make password hygiene a priority for everyday users.
- 24Security experts vent over yet another default-password breach●Another breach writeup, another root cause that turns out to be a default password. Every single time. # infosec
Information security professionals are once again discussing a breach whose root cause was a device or account left running with its default password, expressing frustration that the same basic mistake keeps recurring across incident writeups. Commenters echo the sentiment that default credentials remain one of the most common and preventable causes of major security incidents, renewing calls for mandatory password changes and hardened defaults from vendors.
- 25Security researcher flags fake Facebook login page●Possible Phishing 🎣 on: ⚠️hxxp[:]//facebooksecure[.]blogspot[.]com 🧬 Analysis at: https:// urldna.io/scan/6ac312f23b7750
Cybersecurity researchers are warning about a suspected phishing site operating at facebooksecure.blogspot.com, which imitates Facebook to steal login credentials. The domain, hosted on Blogspot, has been submitted for analysis on UrlDNA, where its scan results are being shared across infosec communities. Experts advise users to check web addresses carefully before entering Facebook passwords, as attackers frequently use free hosting services for such scams.
- 26New CloudSyncD macOS malware hides in fake Zoom installer●Discover how the new CloudSyncD macOS malware disguises itself as a fake Zoom installer to bypass Gatekeeper and steal y
Security researchers are warning about CloudSyncD, a new macOS malware that poses as a Zoom installer to slip past Apple's Gatekeeper protection. Once installed, it steals users' administrator passwords, putting Mac users at risk of account compromise. The report urges caution when downloading Zoom or other apps outside official sources.
- 27Experts question whether web authentication is sustainable▼Does anyone else get the feeling that the way the world authenticates to thousands of services on the Web, and the curre
A cybersecurity commentator is asking whether the way the world authenticates to thousands of online services is sustainable, arguing that current login systems outpace the technical literacy of users across generations. The remark has struck a chord among information security professionals, who regularly point to passwords, phishing, and inconsistent security standards as growing problems. It feeds into a wider debate over passkeys, multi-factor authentication, and how to design account security that ordinary people can actually manage.
- 28Password field maxlength of 20 blocks Vanguard logins●prevents me from logging into Vanguard Article URL: https:// tanin.nanakorn.com/input-type- password-maxlength-20-is-con
A developer writes that Riot's Vanguard anti-cheat system prevents them from logging in because the login form's password field has a maxlength of 20 characters, truncating longer passwords and rejecting legitimate credentials. The writeup argues that limiting password input length in this way is harmful practice, and the story has drawn discussion among developers criticizing the form design.
- 29Chrome on Android may require biometrics for password autofill●Chrome on Android’s password autofill could soon require a biometric test Revisiting an old idea. https://www. androidau
Google is reportedly revisiting a plan to require a biometric check before Chrome on Android fills in saved passwords. The feature, spotted in development coverage by Android Authority, would add a fingerprint or face scan step before credentials are autofilled, aiming to stop anyone with access to an unlocked phone from retrieving stored passwords.
- 30Password chaos: dealing with ignored account security●Ich ignoriere es schon zu lange (Passwort-Chaos)
The German tech magazine c't is drawing attention to password chaos - the mess of forgotten, reused or outdated login credentials many people put off dealing with. The piece urges viewers to finally sort out their password management, a long-running topic in IT security as data leaks and weak or recycled passwords keep putting accounts at risk.
- 31French tax office hacked via stolen staff passwords●France's tax office got hacked via stolen staff passwords and didn't even notice. Their security team caught red flags b
France's tax authority was breached by attackers using stolen employee passwords. Security teams reportedly noticed red flags but failed to connect them, leaving the intrusion undetected. Commenters are highlighting the episode as a textbook failure of basic credential security and internal alert monitoring, with criticism of how overlooked warning signs can let a serious breach of a major government institution go unnoticed.
- 32PCPartPicker criticised for having no password rules●This dumb password rule is from PCPartPicker. There are no rules for passwords. Passwords can be any length (including o
PCPartPicker has been flagged in cybersecurity discussions for allowing passwords of any length and complexity, including single-character passwords, with no confirmation emails sent on password changes. Security-minded users argue the lack of minimum requirements leaves accounts unnecessarily vulnerable to trivially weak credentials, and the site has been added to a running catalogue of questionable password policies.
- 33South Korean Banks Hit by Wave of Data Breaches▼South Korean Banks Hit by String of Data Breaches — AhnLab Says Stop Password Reuse First
A series of data breaches has hit South Korean banks, prompting security firm AhnLab to urge customers to stop reusing passwords as a first protective step. The advice highlights that credential reuse allows attackers who obtain login details from one breach to access accounts at multiple institutions. Customers are being advised to use unique passwords and stronger authentication across banking services.
- 34Polish invoicing platform Fakturownia discloses database breach●Fakturownia, a Polish invoicing platform with over 600,000 business users, says an attacker spent about 38 hours inside
Fakturownia, a Polish invoicing platform used by more than 600,000 businesses, says an attacker spent roughly 38 hours inside its servers on 27-28 September and copied a large part of its database. Exposed data reportedly includes account details, password hashes, bank account numbers and integration tokens. Security professionals are sharing the disclosure and urging affected users to change passwords and review integrations.
- 35New portfolio tracker encrypts all user financial data on-device●We built a portfolio and spending tracker that can't read your numbers. Your key is made on your device from your passwo
A developer has launched a portfolio and spending tracker designed so the company cannot view users' financial figures. Encryption keys are generated on the user's device from their password, meaning portfolio and wallet data reach the servers already encrypted. The maker openly acknowledges the main limitation: users must still trust the code being served, since the app is not open source.
- 36
A guide is circulating explaining how iPhone and Android users can check whether their saved passwords have been compromised in data breaches. On iPhone, users can access password security recommendations in Settings, while Android offers a password checkup tool through Google settings or the Password Manager. The advice comes amid ongoing concern about account security and repeated large-scale data leaks.
- 37
Cybersecurity experts are warning that hackers are increasingly using AI to craft convincing phishing messages and crack passwords, putting everyday accounts at risk. Advice circulating includes using strong, unique passwords, enabling two-factor authentication, staying alert to suspicious messages, and keeping software updated. The guidance reflects growing concern that AI tools have made scams faster, more personalized, and harder for ordinary users to spot.
- 38US Department of War promotes 'Brilliant at the Basics' for Cybersecurity Awareness Month▼Department of War Champions 'Brilliant at the Basics' for Cybersecurity Awareness Month
The US Department of War is marking Cybersecurity Awareness Month by promoting its 'Brilliant at the Basics' campaign, urging staff and the wider public to follow fundamental cyber hygiene such as strong passwords, phishing awareness and multi-factor authentication. The initiative highlights how basic defensive practices remain the department's core message against growing digital threats.
- 39Scattered Spider's MGM hack retold with low-poly potatoes▼How Scattered Spider shut down Las Vegas with one phone call, retold with low-poly potatoes 🥔 LinkedIn recon → help-desk
Scattered Spider's 2023 attack on MGM Resorts is being retold in a quirky animated explainer, with low-poly potato characters. The story shows how a single phone call, LinkedIn research and help-desk impersonation led to a password and MFA reset, ransomware across 100+ MGM servers and the shutdown of Las Vegas operations. The campaign later hit Caesars, M&S, Salesforce clients and TfL, where two members were arrested.
- 40YesWiki hit by nine vulnerabilities including SQL injection flaw●🚨 YesWiki 9 CVEs — CVE-2026-104457 (CVSS 8.6) unauthenticated SQL injection dumps admin password hashes. No login requir
Nine security vulnerabilities have been disclosed in YesWiki, a French open-source wiki platform. The most severe, CVE-2026-104457 with a CVSS score of 8.6, is an unauthenticated SQL injection that can dump administrator password hashes without any login. Other reported flaws include three SSRF issues, blind and second-order SQL injection, CSRF and page overwrite. Fixes are available in YesWiki 4.6.7, and users are urged to patch immediately.
Repos
- driceroland/Search A small, fast WebKit browser for macOS, by Office Commun.