Showing posts sorted by date for query passwords. Sort by relevance Show all posts
Showing posts sorted by date for query passwords. Sort by relevance Show all posts

20 February 2026

Your AI-generated password isn't random, it just looks that way

AI security company Irregular looked at Claude, ChatGPT, and Gemini, and found all three GenAI tools put forward seemingly strong passwords that were, in fact, easily guessable.

Prompting each of them to generate 16-character passwords featuring special characters, numbers, and letters in different cases, produced what appeared to be complex passphrases. When submitted to various online password strength checkers, they returned strong results. Some said they would take centuries for standard PCs to crack.

The online password checkers passed these as strong options because they are not aware of the common patterns. In reality, the time it would take to crack them is much less than it would otherwise seem.

Irregular found that all three AI chatbots produced passwords with common patterns, and if hackers understood them, they could use that knowledge to inform their brute-force strategies.

The researchers took to Claude, running the Opus 4.6 model, and prompted it 50 times, each in separate conversations and windows, to generate a password. Of the 50 returned, only 30 were unique (20 duplicates, 18 of which were the exact same string), and the vast majority started and ended with the same characters.

www.theregister.com


07 November 2025

You'll never guess what the most common passwords are. Oh, wait, yes you will

123456. admin. password. For years, the IT world has been reminding users not to rely on such predictable passwords. And yet here we are with another study finding that those sorts of quickly-guessable, universally-held-to-be-bad passwords are still the most popular ones.

Tech advice website Comparitech on Thursday published the 100 most common passwords based on a deep dive into more than two billion passwords leaked on breach forums in 2025. 

The three mentioned above all finish in the top ten, along with various variations of the numerals 1-9 in ascending sequential order. 

Puh-leaze, don't do this! Have a look here to get some useful tips on how to secure your credentials - or contact Donline.

www.theregister.com


18 July 2025

Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader


"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.

The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...

...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years.  Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.

The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack.  Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.

Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.

www.fortra.com


21 March 2025

Scam Alert: FBI ‘Increasingly Seeing’ Malware Distributed In Document Converters

Threat actors may attempt to distribute malware, including ransomware, by offering free document converters, according to a March 7 report from the FBI’s Denver office. “Agents are increasingly seeing” this type of scam. The scheme has been deployed globally, the FBI warned.

Threat actors behind the document converter scam disguise malicious software as a legitimate tool for file conversion. The software may claim to convert .doc files to .pdf files, merge multiple .jpg files into a single .pdf file, or download MP3 or MP4 audio files. In most cases, the downloaded software performs the advertised conversion. However, it also grants the attacker access to the victim’s computer.

Once installed, the malware allows threat actors to download additional malicious software or access files submitted for conversion. If these files contain identifying information —  such as dates of birth, social security numbers, or phone numbers — the threat actor may exploit them for identity theft. The attacker could scrape the submitted files for banking information, seed phrases and other information associated with cryptocurrency wallets, email addresses, and passwords.

www.techrepublic.com


19 February 2025

Hackers planted a Steam game with malware to steal gamers’ passwords

Last week, Valve removed a game from its online store Steam because the product was laced with malware

After the removal of the game, which was called PirateFi, security researchers analyzed the malware and found that whoever planted it modified an existing video game in an attempt to trick gamers into installing an info-stealer called Vidar.

Marius Genheimer, a researcher who analyzed the malware and works at SECUINFRA Falcon Team, told TechCrunch that judging by the command and control servers associated with the malware and its configuration, “we suspect that PirateFi was just one of multiple tactics used to distribute Vidar payloads en masse.”

“It is highly likely that it never was a legitimate, running game that was altered after first publication,” said Genheimer. 

In other words, PirateFi was designed to spread malware. 

Be careful out there folks - watch where you go, what you install. There are some bad people on the InterWebs. If you have installed this game please take expert advice ASAP.

www.techcrunch.com


06 June 2024

Windows Recall demands an extraordinary level of trust that Microsoft hasn’t earned


Microsoft’s Windows 11 Copilot+ PCs come with quite a few new AI and machine learning-driven features, but the tentpole is Recall. Described by Microsoft as a comprehensive record of everything you do on your PC, the feature is pitched as a way to help users remember where they’ve been and to provide Windows extra contextual information that can help it better understand requests from and meet the needs of individual users.

This, as many users in infosec communities on social media immediately pointed out, sounds like a potential security nightmare. That’s doubly true because Microsoft says that by default, Recall’s screenshots take no pains to redact sensitive information, from usernames and passwords to health care information to NSFW site visits. By default, on a PC with 256GB of storage, Recall can store a couple dozen gigabytes of data across three months of PC usage, a huge amount of personal data.

The line between potential security nightmare” and “actual security nightmare is at least partly about the implementation, and Microsoft has been saying things that are at least superficially reassuring. Copilot+ PCs are required to have a fast neural processing unit (NPU) so that processing can be performed locally rather than sending data to the cloud; local snapshots are protected at rest by Windows’ disk encryption technologies, which are generally on by default if you’ve signed into a Microsoft account; neither Microsoft nor other users on the PC are supposed to be able to access any particular user’s Recall snapshots; and users can choose to exclude apps or (in most browsers) individual websites to exclude from Recall’s snapshots.


27 June 2023

Randomly received a smartwatch (or other tech gadget)? Don’t turn it on, investigators warn.

Smartwatches capable of automatically connecting to cellphones and Wi-Fi, then gaining access to user data, are being shipped to members of the U.S. military seemingly at random, raising cybersecurity concerns.

The Department of the Army Criminal Investigation Division, or CID, in an announcement last week warned the watches may contain malware, potentially granting whoever sent the peripherals “access to saved data to include banking information, contacts, and account information such as usernames and passwords.”

A more innocuous tactic may also be to blame: so-called brushing, used in e-commerce to boost a seller’s ratings through fake orders and reviews.

The CID, an independent federal law enforcement agency consisting of thousands of personnel, did not say exactly how many smartwatches were so far distributed.

Wearable technology and downloadable applications have long clashed with the national security ecosystem, where secrecy is paramount. Smartwatches and their software log personal info and location data, can record audio, and often lack a sufficient means to validate users.

www.defensenews.com


11 April 2023

Terrifying study shows how fast AI can crack your passwords

 

Along with the positive aspects of the new generative AI services come new risks. One that’s surfaced is an advanced approach to cracking passwords called PassGAN. Using the latest AI, it was able to compromise 51% of passwords in under one minute with 71% of passwords cracked in less than a day. 

Last month, Microsoft brought attention to the security concerns that will come with the quick advancement of AI by announcing its new Security Copilot suite that will help security researchers protect against malicious use of modern technology.

Now Home Security Heroes has published a study showing how scary powerful the latest generative AI is at cracking passwords. The company used the new password cracker PassGAN (password generative adversarial network) to process a list of over 15,000,000 credentials from the Rockyou dataset and the results were wild:

51% of all common passwords were cracked in less than one minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

To stay safe: stick with at least 12 characters with a mix of upper, and lowercase letters plus numbers. Never reuse passwords - a unique one per service / account. Need help securing your accounts? Contact Donline.


02 December 2022

Intruders gain access to user data in LastPass incident

Intruders broke into a third-party cloud storage service LastPass shares with affiliate company GoTo and gained access to "certain elements" of customers' information, the pair have confirmed.

LastPass did not define what it meant by "certain elements," saying it was unsure what data was looked at: "We are working diligently to understand the scope of the incident and identify what specific information has been accessed this morning."

It did maintain, however, that services were unaffected and that customers' passwords remained "safely encrypted" – without ruling out that some of the data was stolen. The company is known to use a one-way salted hash for master passwords, with a fuller description in this technical whitepaper. The master passwords are used to lock users' password vaults, where their logins for various websites etc. can be stored, with the passphrase only ever entered by the user on their browser or app and not sent to or stored by LastPass.

www.theregister.com


25 November 2022

Guess the most common password. Hint: We just told you

NordPass has released its list of the most common passwords of 2022. Topping the list of the most common passwords was, sadly, "password," followed by "123456" and its more secure relative "123456789," "guest," "qwerty" and lots more you can definitely figure out without needing the help of a cracking tool.

Seriously, few of the passwords in this list are even words: Most are just repetitions of a single character, sequences of easy-to-guess numbers, a straight run down a row of keys, or basic combinations like "pass@123." 

Along with a depressingly basic list of common passwords and the speed it takes to crack them (most are listed as < 1 second), NordPass shared some statistics about what's trending in the password world, like the word "Oscars," which pops up especially around award season, as well as "batman," "euphoria" and "encanto" after the eponymous films and TV series that have been popular this year.

FYI: here are five things to know to pick a good password.

www.theregister.com


18 November 2022

Online security experts discuss why the future of passwords is no passwords.

 

Watch a short video featuring online security experts from CISA, FIDO Alliance, Google, and Microsoft. These experts highlight why the future of passwords is no passwords – with FIDO.

FIDO Authentication: The FIDO Alliance is involved in three areas to work towards achieving its mission to reduce the world’s reliance on passwords to better secure the web: user authentication; identity verification and binding; and the Internet of Things (IoT). The work areas address essential aspects of the digital identity lifecycle management including identity verification for initial account onboarding and account recovery, and user and device authentication.

FIDO Authentication: Passwords endure despite the growing consensus their use needs to be reduced, if not replaced. But even though effective PKI and strong authentication solutions have existed for years, barriers to widespread adoption persist. Consumers don’t like the user experience, and online service providers don’t want the cost and complexity of developing and provisioning their own dedicated solutions.

The industry’s answer to the password problem: The FIDO Alliance developed FIDO Authentication standards based on public key cryptography for authentication that is more secure than passwords and SMS OTPs, simpler for consumers to use, and easier for service providers to deploy and manage. FIDO Authentication enables password-only logins to be replaced with secure and fast login experiences across websites and apps.

www.fidoalliance.org


19 May 2022

The passwords most used by CEOs are startlingly dumb

A recent cybersecurity report shows how immensely idiotic many CEOs and business owners can be, considering the strength of their chosen account passwords. Imagine entrusting the livelihood of hundreds, even thousands of employees to someone who uses '123456' or 'qwerty' as a password.

The research comes from NordPass password manager which identified back in 2020 that the general public's most commonly used passwords were sequential numbers like '123456', 'picture1', and yep, you guessed it: 'password'.

The more recent research sample consists of 290 million cybersecurity data breaches around the globe, and denotes the job level of those affected. Turns out, when it comes to CEOs and other high-ranking businesses execs, their password choices are much the same as the general public, although many often feature names. Tiffany was spotted in 100,534 breaches; then there was Charlie with 33,699; Michael was found 10,647 times; and Jordan, 10,472 times.

The research is pretty worrying, and makes it painfully clear that most data breaches don't happen because of some profound cyber hacking initiative; around 80% are down to people choosing really poor passwords.

Read the above? Now - how to do it properly: 5 Top Tips to pick a secure password.

www.pcgamer.com


06 May 2022

Google, Apple, Microsoft promise end to passwords, courtesy of your mobile phone

A future without passwords may be closer than we think, at least when a new initiative to enlist your smartphone as a mobile authenticator gets off the ground.

On Thursday, the FIDO Alliance - announced a new type of authentication that would use passkeys stored on your phone to unlock your online accounts without requiring a password. Google, Apple and Microsoft are all on board with the new method and have promised that their respective operating systems will support this technology.

Passwords have always been a poor way to secure our accounts. We’re constantly told to create a strong, complex and unique password for each account. But that’s a difficult task, leading many people to use weak and repetitive passwords, which can easily be compromised and used in data breaches and account takeovers. Such tools as password managers have provided some relief but still chain us to this clumsy and ineffective means of authentication.

With support from Google, Apple and Microsoft, the new authentication method will store a FIDO-based passkey on your mobile phone. That key will be encrypted to protect it from compromise and will be accessible only when you unlock your phone. When you try to sign into an app or website either on the phone itself, a nearby computer or other device, that passkey will automatically log you in regardless of the operating system or browser and without you having to enroll or re-enroll your device. If you switch to a new phone, your passkey will make the trip with you.

www.techrepublic.com


08 March 2022

How an 8-character password could be cracked in less than an hour

 

Security experts keep advising us to create strong and complex passwords to protect our online accounts and data from savvy cybercriminals. And “complex” typically means using lowercase and uppercase characters, numbers and even special symbols. But complexity by itself can still open your password to cracking if it doesn’t contain enough characters, according to research by security firm Hive Systems.

As described in a recent report, Hive found that an 8-character complex password could be cracked in just 39 minutes if the attacker were to take advantage of the latest graphics processing technology. A seven-character complex password could be cracked in 31 seconds, while one with six or fewer characters could be cracked instantly. Shorter passwords with only one or two character types, such as only numbers or lowercase letters, or only numbers and letters, would take just minutes to crack.

On the plus side, even simpler passwords with a greater number of characters are less vulnerable to cracking in a short amount of time, according to Hive’s research. An 18-character password with just numbers would require three weeks to crack, but one with the same number of characters using lowercase letters would take 2 million years to crack. This piece of data shows why passphrases, which use a long string of real but random words, can be more secure than a complex but short password.

www.techrepublic.com


14 February 2022

What is a SIM swap attack?

SIM swapping is a scam in which malicious parties target cell phone carriers to gain access to victims’ bank accounts, virtual currency accounts and additional sensitive information by using social engineering, insider threat or phishing techniques. Social engineering involves a criminal to impersonate the victim’s mobile number by tricking the cell phone carrier into switching the victim’s mobile number to a SIM card that is in the criminal’s possession, allowing the malicious party to access the victim’s calls, texts and other data, but this is only one of the three methods used to steal funds from victims.

Insider threat takes place when a criminal actor pays off a mobile carrier employee to switch the victim’s SIM to a card currently in the criminal’s possession. Malicious parties can also employ phishing techniques to access victims’ sensitive data, and steal funds from the victim through their banking data or third-party services like PayPal or Venmo. This level of access to a victim’s cell data then allows a malicious party entry to everything from text message verification to SMS based two-factor authentication to exploit victims’ sensitive information.

“Service providers must move from more simplistic means of validating identity to more sophisticated ones,” Clements said. “PIN codes unique to each user’s account can be one way of adding additional security to the process, and ‘out of wallet’ questions are another alternative that works by verifying much harder to compromise information such as last three home addresses or cars. It may be more of a hassle for everyone, but it’s simply no longer viable to rely on information that has been routinely compromised to validate a person’s identity.”

The FBI encourages both cell phone users and the companies that provide service to take additional security measures in protecting their personal information. For cell phone users, the agency outlines the following tips:

Do not advertise information about financial assets, including ownership or investment of cryptocurrency, on social media websites and forums.

Do not provide your mobile number account information over the phone to representatives that request your account password or pin. Verify the call by dialing the customer service line of your mobile carrier.

Avoid posting personal information online, such as mobile phone number, address or other personal identifying information.

Use a variation of unique passwords to access online accounts.

Be aware of any changes in SMS-based connectivity.

Use strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications to access online accounts.

Do not store passwords, usernames or other information for easy login on mobile device applications.

www.techrepublic.com


26 November 2021

Huge fines and a ban on default passwords in new UK law

The government has introduced new legislation to protect smart devices in people's homes from being hacked.

Recent research from consumer watchdog Which? suggested homes filled with smart devices could be exposed to more than 12,000 attacks in a single week.

Default passwords for internet-connected devices will be banned, and firms which do not comply will face huge fines.

One expert said that it was an important "first step".

Cyber-criminals are increasingly targeting products from phones and smart TVs, to home speakers and internet-connected dishwashers. Hackers who can access one vulnerable device can then go on to access entire home networks and steal personal data.

In 2017, for example, hackers stole data from a US casino via an internet-connected fish tank. There have also been reports of people accessing home webcams and speaking to family members.

And poor security on a home wi-fi router could have been behind the uploading of illegal child abuse images from a home network that led to police accusing an innocent couple of the crime.

www.bbc.co.uk


15 September 2021

Microsoft accounts can now go fully passwordless

 

Microsoft now lets you remove passwords from Microsoft accounts to embrace a passwordless future. Starting today, the software giant will let consumers sign into Microsoft accounts with its Microsoft Authenticator app, Windows Hello, a security key, or an SMS / email verification code instead of a password.

The new option arrives just months after Microsoft started rolling out passwordless authentication for commercial users in March to help people adjust to the realities of remote work. “When I think of security, I think you’ve got to protect your whole life,” says Vasu Jakkal, corporate vice president of Microsoft security, compliance & identity, in an interview with The Verge. “It’s no longer enough just to think about work or home and anything in between.”

www.theverge.com


19 August 2021

T-Mobile says at least 47M current and former customers affected by hack

T-Mobile has confirmed that millions of current and former customers had their information stolen in a data breach, following reports of a hack over the weekend.

In a statement, T-Mobile, which has more than 100 million customers, said its preliminary analysis shows 7.8 million current postpaid T-Mobile customers had information taken in the data breach. The carrier said that some personal data was also taken, including customer names, dates of birth, Social Security numbers and driver’s license information for a “subset” of current and former postpay customers and prospective T-Mobile customers.

The company also said that 40 million records of former and prospective customers was taken, but that “no phone numbers, account numbers, PINs, passwords, or financial information were compromised.”

But the company warned that approximately 850,000 active T-Mobile customer names, phone numbers and account PINs were in fact compromised, and that customer names, phone numbers and account PINs were exposed. T-Mobile said it has reset those customer PINs. T-Mobile said it was “recommending all postpaid customers” to proactively change their account PIN, which protects their accounts from SIM-swapping attacks.

www.techcrunch.com


19 April 2021

Top 200 most common passwords of the year 2020 - top 10 on this pic!

 

Here are the worst 200 passwords of 2020. The list details how many times a password has been exposed, used, and how much time it would take to crack it. 

We also compare the most common passwords of 2019 and 2020, highlighting how their positions have changed. The green arrows indicate a rise in the position while the red ones - a fall off. 

Check if your password is on the list and strengthen it if it is.

www.nordpass.com