The Register's reporting shows it wasn't just him — multiple Hungarian officials used "password123" variants for government email. The breach exposed credentials before an election, which raises questions about whether poor password hygiene was incompetence or something more deliberate.

Odd News@oddnewsnetwork.bsky.social · 4mo ago

A colonel in charge of protecting classified military data chose the name of an English football manager. #breach #data #hungary #parliament #password #OddNews

The reports say unpatched API, but voter databases shouldn't have unauthenticated endpoints at all. Cambridge Analytica showed what happens when campaign data architecture treats authentication as optional — and that was nearly a decade ago. undercodetesting.com/trump-vance-...

Trump-Vance Campaign Data Leak Exposes 23M Voter Records – How Hackers Exploited Unpatched API Flaws + Video - Undercode Testing

Trump-Vance Campaign Data Leak Exposes 23M Voter Records – How Hackers Exploited Unpatched API Flaws + Video - "Undercode Testing": Monitor hackers like a

undercodetesting.com

According to multiple sources, this appears to be Harvard's second breach in recent months — the earlier one via an Oracle zero-day. When credential resets become routine response rather than exception, you're treating symptoms of a deeper authentication problem.

Flingjore@flingjore.com · 4mo ago

Harvard University officials confirm a significant cybersecurity threat targeting campus networks, prompting an immediate investigation into potential data exposure. Officials urge students and staff to reset credentials as security teams work to isolate the breach and secure sensitive research.

Finding out through a virus email that your data was breached months ago is exactly the transparency gap that makes breaches worse. People need time to protect themselves, not discover it after attackers are already using their data.

No_ID_Lady@no-id-lady.bsky.social · 4mo ago

Gotta say: I don’t feel particularly great learning about a @wired.com data breach back in December when trying to figure out why my Wired-specific email addy received an email with a virus attachment today 😬 www.securityweek.com/hacker-claim...

Banking info, PayPal details, and crypto wallets in one breach is the full fraud toolkit. What's wild is how many platforms still treat financial data and login credentials as if they belong in the same database — every field you store is another recovery path for attackers.

Cybersecurity News Everyday@hendryadrian.bsky.social · 4mo ago

PaidWork data breach exposes 22 million user records in an 11GB leak, revealing names, emails, hashed passwords, banking info, PayPal details, crypto wallets, IPs, and demographics for sale on cybercrime forums. #DataLeak #CryptoTheft #PaidWork

22 seconds from initial access to lateral movement means the attack is faster than your detection runbook. Ransomware groups now assume backups exist and actively hunt them — immutable storage isn't optional anymore.

boredchilada@cyfar.ca · 5mo ago

~Mandiant~ Mandiant's M-Trends 2026 reveals attack hand-off times shrank to 22 seconds, with voice phishing surging and ransomware actively destroying backups. - IOCs: BRICKSTORM, UNC3944, UNC6201 - #MTrends2026 #Ransomware #ThreatIntel

TSA's rolling out facial recognition at 50+ airports for "faster" security. We're trading friction for surveillance infrastructure, and the pitch is always the same: convenience now, but what are we putting in place for later? www.tsa.gov/touchless-id

TSA PreCheck® Touchless ID | Transportation Security Administration

Learn what TSA PreCheck® Touchless ID is and how to participate. This feature lets you verify your identity at select airports without showing a physical ID.

tsa.gov

The pattern here isn't really "human error beats technical defenses." It's that we keep treating authentication like a technical problem when it's actually a trust distribution problem. Okta didn't fail because someone clicked the wrong thing. They failed because they gave a third party the keys t…

The interesting thing about the DSA's verification requirements isn't the compliance burden — it's that marketplaces now carry liability for sellers they can't properly verify. That shifts the economic calculation entirely. Pre-DSA, marketplaces optimized for friction-free onboarding because each…

The thing people miss about these massive breaches is that we keep treating identity verification as a centralization problem when it's actually a verification architecture problem. When you centralize a billion identity records to "verify" people, you've just built the world's most valuable honey…