search
Password
Trends
- 1German tech magazine explains switching to a new password managerβMein Umzug auf einen neuen Passwort-Manager
Technology magazine c't has published a guide on migrating to a new password manager, walking readers through moving their saved credentials from one service to another. The piece covers what to consider before switching, how to export and import login data securely, and which password managers are worth choosing. German-speaking tech audiences are engaging heavily with the topic, reflecting ongoing interest in password security.
- 2
Online fashion retailer ASOS is reported to have suffered a data breach affecting millions of customer records. The exposed data reportedly includes personal customer information, though the exact scope and how the records were obtained are not yet confirmed. If accurate, the incident would add ASOS to the growing list of major retailers facing cybersecurity incidents, and customers are being advised to stay alert for phishing attempts and change their passwords.
- 3iPhone $500 voucher scam puts photos and passwords at riskβΌApple iPhone scam offering $500 voucher may give criminals your personal photos, passwords
A scam targeting iPhone users offers a fake $500 Apple voucher but may hand criminals access to personal photos and passwords. Outlets including MLive.com and Yahoo are warning recipients not to click links or enter credentials in the fraudulent offer. Users are advised to delete suspicious messages and enable security protections on their devices.
- 4AI's 'mathocalypse' could undermine the internet's securityβAI is causing a βmathocalypseβ that could break the internet
The Independent reports on warnings of a 'mathocalypse': the moment AI systems become capable of breaking the mathematical encryption that secures online communication. If advanced AI cracks public-key cryptography, passwords, banking and private messaging could all be exposed, prompting renewed debate about how urgently the internet's security infrastructure needs upgrading.
- 5FakeGit campaign returns with 17,000 malicious GitHub repos spreading StealCβπ€ FakeGit campaign is back: 17,610 malicious GitHub repos distribute SmartLoader, which drops the StealC infostealer. Re
A revived FakeGit operation has flooded GitHub with 17,610 malicious repositories posing as cracked or pirated software. Victims who download and run the fake tools receive the SmartLoader payload, which deploys the StealC infostealer to harvest passwords and other sensitive data. Security researchers warn developers and regular users alike to avoid unofficial software downloads on the platform.
- 6Teacher revives old Dynabook laptop with Linux Mint XFCEβNu heb ik een oude (hele irritante dynabook) laptop, waarop ik Linuxmint XFCE heb geinstalleerd. Het heeft 2 accounts, e
A user has installed Linux Mint XFCE on an old Dynabook laptop intended for student use, setting up two accounts: one admin with a password and one user account with an auto-filled password. Chromium launches automatically at startup, and the user is working through how to configure the machine before handing it to the first pupil.
- 7ASOS confirms data breach after shoppers receive hacked alertβΌASOS confirms data breach after "hacked" app alert reaches shoppers
ASOS has confirmed a data breach after shoppers received security alerts suggesting the app had been hacked. The online fashion retailer is notifying affected customers, though details on how many accounts were compromised and what data was accessed remain limited. Cybersecurity observers are watching how the company responds and advises customers to update passwords and monitor their accounts.
- 8Harvard Business School VPN Now Supports Single Sign-OnβΌDid You Know? HBS VPN Now Supports Single Sign-On
Harvard Business School has announced that its VPN service now supports Single Sign-On, allowing users to authenticate with their existing HBS credentials instead of separate VPN logins. The update is aimed at simplifying access to campus resources for students, faculty and staff, reducing password fatigue and streamlining the connection process for the school's remote and on-campus community.
- 9ASOS data breach: what hackers accessed from customer accountsβΌASOS data breach: What hackers accessed from customer accounts revealed
A data breach affecting ASOS customer accounts is in the news, with reports detailing what information hackers were able to access. The online fashion retailer's customers are being urged to check their accounts and secure their passwords. The full scope of the incident and the number of people affected remain unclear from initial reports.
- 10FBI warns FortiBleed attacks on FortiGate firewalls continueβπ€ FBI: FortiBleed attacks on exposed FortiGate firewalls & SSL VPN gateways are still ongoing. Attackers use leaked/info
The FBI says FortiBleed attacks against exposed FortiGate firewalls and SSL VPN gateways are still ongoing. Attackers use credentials stolen by infostealers, crack the stolen password hashes with GPU clusters running tools like Hashcat, then lock administrators out of devices. The activity is linked to INC/Lynx and Payload ransomware operations, with tens of thousands of devices reportedly affected.
- 11maxlength=20 on password fields blocks Vanguard loginsβ<input type="password" maxlength="20"> prevents me from logging into Vanguard
A developer has written about being locked out of Vanguard because its login form uses maxlength=20 on the password input, silently truncating longer passwords. The piece argues the widely copied pattern is harmful: users with longer passwords cannot log in, and password managers may fill credentials that fail without explanation. The post calls on sites to remove maxlength from password fields.
- 12
Ichikawa City Zoological and Botanical Garden in Chiba Prefecture is drawing attention for the evolving daily password it announces alongside its capybara Punch-kun. The phrase has changed over time from "Gohamo" to "Go" and now to "Pa," and fans are enjoying tracing how the greeting has developed with the animal's popularity.
- 13jshERP flaw leaks MD5 password hashes, remains unpatchedβCVE-2026-94413: jshERP through 3.6 leaks unsalted MD5 password hashes via /user/info, enabling offline cracking and auth
A newly published vulnerability, CVE-2026-94413, affects jshERP versions through 3.6. The /user/info endpoint exposes unsalted MD5 password hashes, which attackers could crack offline and replay to bypass authentication. The flaw carries a CVSS score of 6.5 and currently has no vendor patch. Security practitioners are urging administrators to restrict access to the affected endpoint as an interim measure while waiting for an official fix.
- 14Brocade SANnav vulnerability leaks passwords in log filesβπ¨ EUVD-2026-94756 π Score: 8.2/10 (CVSS v3.1) π¦ Product: Brocade SANnav, Brocade SANnav π’ Vendor: Brocade π Updated: 202
A high-severity vulnerability, tracked as EUVD-2026-94756 with a CVSS score of 8.2, has been disclosed in Brocade SANnav versions before 2.4.0b and 3.0.0. The flaw causes encoded passwords and authentication tokens to be printed in log files, potentially exposing credentials. Users are advised to update to fixed releases and review log data for sensitive information.
- 15Passkey adoption lags even among security professionalsβPasskey adoption lags as security pros still use passwords https:// fawkes.rocks/2026/10/08/passke y-adoption-lags-as-se
A new report finds that passkey adoption is falling short of expectations, with even security professionals continuing to rely on traditional passwords. The finding is raising questions about why the phishing-resistant technology has struggled to gain traction despite years of promotion from major platforms and industry groups.
- 16WeatherBug mocked for 16-character password limitβThis dumb password rule is from WeatherBug. Maximum 16 characters. https:// dumbpasswordrules.com/sites/we atherbug/ # p
WeatherBug is being criticised for capping account passwords at 16 characters, a restriction catalogued on a site that collects poor password policies. Security-minded users point out that short maximum lengths discourage long passphrases and can signal outdated or unsafe password handling behind the scenes.
Repos
- driceroland/Search A small, fast WebKit browser for macOS, by Office Commun.