mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

14K
active users

#passwords

22 posts15 participants1 post today

I was reading up on the biography of Fernando Corbató, the inventor of the computer password.

Corbató passed away in 2019, but he was survived by at least eight characters, including one or more uppercase letters, one or more lowercase letters, one or more numerals...


#passwords #infosec

PC World: Hackers are spreading fake password manager ransomware via Bing ads. “Using an old trick, hackers have set up new sites with ‘squatter’ URLs that look close enough to the genuine KeePass site at KeePass.info. On the fake sites, the interface mimics the genuine one to near perfection, offering downloads of the password manager. But according to an investigation by WithSecure, the […]

https://rbfirehose.com/2025/05/25/pc-world-hackers-are-spreading-fake-password-manager-ransomware-via-bing-ads/

This dumb password rule is from Really Useful Storage Boxes.

- Have a length between 8 and 20 alphanumeric characters (without accents)
- Contain at least 1 CAPITAL letter
- Contain at least 1 lowercase letter
- Contain at least 1 numeric character
- Contain at least 1 special character taken from the following list: *$@&()[]{}=#.-!?+/£€%

dumbpasswordrules.com/sites/re

dumbpasswordrules.comReally Useful Storage Boxes - Dumb Password Rules- Have a length between 8 and 20 alphanumeric characters (without accents) - Contain at least 1 CAPITAL letter - Contain at least 1 lowercase letter - Contain at least 1 numeric character - Contain at least 1 special character taken from the following list: *$@&()[]{}=#.-!?+/£€%

The simplicity of #Apple #Passwords has its benefits, however, coming from #Strongbox (and previously #1Password), there are still few things I’d love to see getting added in future releases:

• Separate email and username fields.
• Better groups or tag support.
• A keyboard shortcut to quickly reveal the password.
• Proper keyboard support in the menu bar app.

This dumb password rule is from Westpac Live Online Banking.

Password rules:
- be between 8 and 30 characters
- include at least 1 number, 1 letter and 1 special character (@#%^ etc)
- have no more than 2 repeating characters (AAB not AAA)
- not contain spaces
- not be the same as your last 3 passwords

dumbpasswordrules.com/sites/we

dumbpasswordrules.comWestpac Live Online Banking - Dumb Password RulesPassword rules: - be between 8 and 30 characters - include at least 1 number, 1 letter and 1 special character (@#%^ etc) - have no more than 2 repeating characters (AAB not AAA) - not contain spaces - not be the same as your last 3 passwords

This dumb password rule is from United Parcel Service of America.

Your password must:
- Be between 7 and 26 characters long
- Contain at least 1 lowercase character
- Contain at least 1 uppercase character
- Contain at least 1 number character
- Contain one special character (!@#$%*)
- NOT contain first or last name
- NOT contain UPS user ID
- NOT contain email...

dumbpasswordrules.com/sites/un

dumbpasswordrules.comUnited Parcel Service of America - Dumb Password RulesYour password must: - Be between 7 and 26 characters long - Contain at least 1 lowercase character - Contain at least 1 uppercase character - Contain at least 1 number character - Contain one special character (!@#$%*) - NOT contain first or last name - NOT contain UPS user ID - NOT contain email address

PupkinStealer .NET Infostealer Using Telegram for Data Theft

PupkinStealer is a newly identified .NET-based information-stealing malware that extracts sensitive data like web browser passwords and app session tokens, exfiltrating it via Telegram. It targets Chromium-based browsers, Telegram, and Discord, focusing on credential theft and session hijacking. The malware performs minimal system discovery, collects files from the desktop, and captures a screenshot. It packages stolen data into a ZIP archive and sends it to the attacker through Telegram's Bot API. PupkinStealer doesn't employ persistence mechanisms, relying on quick execution and low-profile behavior. Its primary evasion technique is leveraging legitimate Telegram infrastructure for communication.

Pulse ID: 682f21f740ee536b48e48783
Pulse Link: otx.alienvault.com/pulse/682f2
Pulse Author: AlienVault
Created: 2025-05-22 13:09:11

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.