Skip to content
tag — credential-theft

grep -rl "credential-theft" ./articles

#credential-theft

10 articles

France's tax agency learned of the theft from the thief, seven weeks after it started

2026-10-01Security

ANSSI's incident report on the DGFiP, published on 29 September, describes several dozen agent passwords stolen from machines the agency does not manage, sensitive portals with no multi-factor authentication, and a messaging tool scraped on three days in June and July. Nobody noticed until the attacker posted about it on a forum on 12 August.

The print server held the LDAP bind credentials. That is what they came for

2026-09-07Security

Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.