okr765
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
shish_mish@lemmy.world to Technology@lemmy.worldEnglish · 19 hours ago

16 Billion Apple, Facebook, Google And Other Passwords Leaked — Act Now

www.forbes.com

external-link
message-square
30
fedilink
138
external-link

16 Billion Apple, Facebook, Google And Other Passwords Leaked — Act Now

www.forbes.com

shish_mish@lemmy.world to Technology@lemmy.worldEnglish · 19 hours ago
message-square
30
fedilink
  • drspod@lemmy.ml
    link
    fedilink
    English
    arrow-up
    21
    ·
    17 hours ago

    This article is about credentials that are stolen directly from users’ devices that are compromised with malware. So they will be that user’s passwords for whatever services they were using while infected with the malware. This is why the dumps contain passwords for just about every online service that exists.

    This isn’t an actual database breach of the major providers.

    • A_norny_mousse@feddit.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      17 hours ago

      Thanks for clarifying. Still, does this affect every “device” user out there? There must be some sort of explanation here, what’s the attack vector etc. I couldn’t find it even on that Lithuanian guy’s website.

      • drspod@lemmy.ml
        link
        fedilink
        English
        arrow-up
        5
        ·
        16 hours ago

        This forbes blog is about this article:

        https://cybernews.com/security/billions-credentials-exposed-infostealers-data-leak/

        The only silver lining here is that all of the datasets were exposed only briefly: long enough for researchers to uncover them, but not long enough to find who was controlling vast amounts of data. Most of the datasets were temporarily accessible through unsecured Elasticsearch or object storage instances.

        So there isn’t really an explanation other than “somebody collected these somehow and left the data unsecured.”

        The attack vector for infostealer malware is usually social engineering, getting unwary users to download infected trojanized software via phishing and malvertising etc.

        If you follow security news, you will see articles about infostealer malware campaigns all the time.

        https://www.theregister.com/2025/06/18/minecraft_mod_malware/

        https://thehackernews.com/2025/06/malicious-pypi-package-masquerades-as.html

        https://thehackernews.com/2025/06/rust-based-myth-stealer-malware-spread.html

        https://thehackernews.com/2025/05/eddiestealer-malware-uses-clickfix.html

        • Geodad@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          14 hours ago

          Oh, so I’m probably safe.

          I don’t do mainstream social media, and I don’t answer phone calls, texts, or emails from unknown sources.

          Mama told me not to talk to strangers, and I took that into the digital age.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.78K users / day
  • 9.99K users / week
  • 17.8K users / month
  • 38.2K users / 6 months
  • 1 local subscriber
  • 71.6K subscribers
  • 10.1K Posts
  • 341K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org