CISA Faces Scrutiny Over Leaked Credentials

The US Cybersecurity and Infrastructure Security Agency (CISA) is under fire after dozens of its internal credentials were accidentally exposed on a public GitHub account, sparking concerns over potential security breaches. Despite the agency's assurance that no sensitive data was compromised, lawmakers and experts are demanding answers on how this incident…

https://osintsights.com/cisa-faces-scrutiny-over-leaked-credentials?utm_source=mastodon&utm_medium=social

#Cisa #CredentialLeak #Github #EmergingThreats #GovernmentAgencies

CISA Faces Scrutiny Over Leaked Credentials

Learn how CISA credentials were leaked and what was exposed, read the full report now and stay updated on the incident and its implications for cybersecurity.

OSINTSights

Grafana Labs Discloses Source Code Theft by Hackers

Hackers recently breached Grafana Labs' security, gaining unauthorized access to a GitHub token that allowed them to download the company's source code, and subsequently attempting to extort payment to keep it under wraps. The incident was swiftly investigated, and the compromised token was promptly invalidated.

https://osintsights.com/grafana-labs-discloses-source-code-theft-by-hackers?utm_source=mastodon&utm_medium=social

#SourceCodeTheft #Github #CredentialLeak #Extortion #EmergingThreats

Grafana Labs Discloses Source Code Theft by Hackers

Learn how Grafana Labs disclosed a source code theft by hackers and what steps they took to address the breach - read the full incident report now.

OSINTSights

Zero-Click NTLM Patch Bypass (CVE-2025-50154)

A zero-click NTLM credential leak exploit bypasses Microsoft’s patch, exposing NTLM hashes and silently staging binaries on patched systems.

https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/

#NTLM #credentialleak

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154) 

Learn about CVE-2025-50154 and its risk of NTLM attacks and RCE even after Microsoft’s fix for CVE-2025-24054.

Cymulate

16 billion credentials exposed—from your favorite tech giants to government sites. This isn’t just another hack; it’s a wake-up call that proves our digital defenses may be outdated. How secure are you really?

https://thedefendopsdiaries.com/understanding-the-16-billion-credentials-leak-causes-and-consequences/

#credentialleak
#cybersecurity
#databreach
#infostealer
#passwordsecurity

Prometheus Security Breach 300K Instances Expose Credentials and API Keys
Today, we're diving into the alarming news of a massive security breach involving Prometheus, a popular monitoring and alerting tool used by countless organizations worldwide
#PrometheusSecurity #DataBreach #CyberSecurity #APIKeys #CredentialLeak #InformationSecurity #DataProtection #SecurityIncident #CyberThreat #TechNews #hack #security #news #privacy #leaks
https://cloudhosting.evostrix.eu/prometheus-security-breach-300k-instances-expose-credentials-and-api-keys/
New York Times source code stolen using exposed GitHub token

Internal source code and data belonging to The New York Times was leaked on the 4chan message board after being stolen from the company's GitHub repositories in January 2024, The Times confirmed to BleepingComputer.

BleepingComputer
Containerd Bug Exposes Cloud Account Credentials - The flaw (CVE-2020-15157) is located in the container image-pulling process. https://threatpost.com/containerd-bug-cloud-account-credentials/160546/ #containerimage-pulling #googlecomputeplatform #securityvulnerability #vulnerabilities #credentialleak #cve-2020-15157 #cloudsecurity #cloudaccounts #hostregistry #containerd #bug
Containerd Bug Exposes Cloud Account Credentials

The flaw (CVE-2020-15157) is located in the container image-pulling process.

Threatpost - English - Global - threatpost.com