<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>credentials &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/credentials/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Tue, 28 Oct 2025 19:18:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Cybercriminals Targeting Payroll Sites</title>
		<link>https://noise.getoto.net/2025/11/04/cybercriminals-targeting-payroll-sites/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 04 Nov 2025 12:05:54 +0000</pubDate>
				<category><![CDATA[banking]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71056</guid>

					<description><![CDATA[Microsoft is warning of a scam involving online payroll systems. Criminals use social engineering to steal people&#8217;s credentials, and then divert direct deposits into accounts that they control. Sometimes they do other things to make it harder for...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Automate the Creation &#038; Rotation of Amazon Simple Email Service SMTP Credentials</title>
		<link>https://noise.getoto.net/2025/03/11/automate-the-creation-rotation-of-amazon-simple-email-service-smtp-credentials/</link>
		
		<dc:creator><![CDATA[Zip Zieper]]></dc:creator>
		<pubDate>Tue, 11 Mar 2025 05:47:00 +0000</pubDate>
				<category><![CDATA[*Post Types]]></category>
		<category><![CDATA[Amazon SES]]></category>
		<category><![CDATA[Amazon Simple Email Service (SES)]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[AWS Secrets Manager]]></category>
		<category><![CDATA[Best practices]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[email best practices]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[messaging]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[SES]]></category>
		<category><![CDATA[SMTP]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=1e2091e103b4ce0411bd41057fcc24ed</guid>

					<description><![CDATA[[Amazon Simple Email Service] provides a secure email solution that scales with your business needs. Unfortunately, all email systems, including Amazon SES, remain the primary target for spammers and bad actors due to email’s widespread use and accessibility. While SES offers powerful features for application-based email sending, its SMTP credentials require careful management to prevent […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Trojaned AI Tool Leads to Disney Hack</title>
		<link>https://noise.getoto.net/2025/03/04/trojaned-ai-tool-leads-to-disney-hack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 04 Mar 2025 12:08:31 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69973</guid>

					<description><![CDATA[This is a sad story of someone who downloaded a Trojaned AI tool that resulted in hackers taking over his computer and, ultimately, costing him his job.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>New Windows Malware Locks Computer in Kiosk Mode</title>
		<link>https://noise.getoto.net/2024/09/25/new-windows-malware-locks-computer-in-kiosk-mode/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 25 Sep 2024 11:00:29 +0000</pubDate>
				<category><![CDATA[browsers]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69419</guid>

					<description><![CDATA[<p><a href="https://www.bleepingcomputer.com/news/security/malware-locks-browser-in-kiosk-mode-to-steal-google-credentials/">Clever</a>:</p>
<blockquote><p>A malware campaign uses the unusual method of locking users in their browser’s kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware.</p>
<p>Specifically, the malware “locks” the user’s browser on Google’s login page with no obvious way to close the window, as the malware also blocks the “ESC” and “F11” keyboard keys. The goal is to frustrate the user enough that they enter and save their Google credentials in the browser to “unlock” the computer.</p>
<p>Once credentials are saved, the StealC information-stealing malware steals them from the credential store and sends them back to the attacker...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Security Analysis of the EU’s Digital Wallet</title>
		<link>https://noise.getoto.net/2024/06/27/security-analysis-of-the-eus-digital-wallet/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 27 Jun 2024 11:06:32 +0000</pubDate>
				<category><![CDATA[credentials]]></category>
		<category><![CDATA[cryptanalysis]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[identification]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69102</guid>

					<description><![CDATA[A group of cryptographers have analyzed the eiDAS 2.0 regulation (electronic identification and trust services) that defines the new EU Digital Identity Wallet.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Detect Stripe keys in S3 buckets with Amazon Macie</title>
		<link>https://noise.getoto.net/2024/02/19/detect-stripe-keys-in-s3-buckets-with-amazon-macie/</link>
		
		<dc:creator><![CDATA[Koulick Ghosh]]></dc:creator>
		<pubDate>Mon, 19 Feb 2024 18:58:35 +0000</pubDate>
				<category><![CDATA[Amazon Macie]]></category>
		<category><![CDATA[Amazon S3]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[keys]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Sensitive Data Discovery]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0d810cdc630619e00104441c1b089084</guid>

					<description><![CDATA[Many customers building applications on Amazon Web Services (AWS) use Stripe global payment services to help get their product out faster and grow revenue, especially in the internet economy. It’s critical for customers to securely and properly handle the credentials used to authenticate with Stripe services. Much like your AWS API keys, which enable access […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Leaving Authentication Credentials in Public Code</title>
		<link>https://noise.getoto.net/2023/11/16/leaving-authentication-credentials-in-public-code/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 16 Nov 2023 12:10:04 +0000</pubDate>
				<category><![CDATA[credentials]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68107</guid>

					<description><![CDATA[<p>Interesting <a href="https://arstechnica.com/security/2023/11/developers-cant-seem-to-stop-exposing-credentials-in-publicly-accessible-code/">article</a> about a surprisingly common vulnerability: programmers leaving authentication credentials and other secrets in publicly accessible software code:</p>
<blockquote><p>Researchers from security firm GitGuardian this week <a href="https://blog.gitguardian.com/uncovering-thousands-of-unique-secrets-in-pypi-packages/">reported</a> finding almost 4,000 unique secrets stashed inside a total of 450,000 projects submitted to PyPI, the official code repository for the Python programming language. Nearly 3,000 projects contained at least one unique secret. Many secrets were leaked more than once, bringing the total number of exposed secrets to almost 57,000...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>FBI (and Others) Shut Down Genesis Market</title>
		<link>https://noise.getoto.net/2023/04/05/fbi-and-others-shut-down-genesis-market/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 05 Apr 2023 15:55:02 +0000</pubDate>
				<category><![CDATA[botnets]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67156</guid>

					<description><![CDATA[<p>Genesis Market is <a href="https://krebsonsecurity.com/2023/04/fbi-seizes-bot-shop-genesis-market-amid-arrests-targeting-operators-suppliers/">shut down</a>:</p>
<blockquote><p>Active since 2018, Genesis Market’s slogan was, “Our store sells bots with logs, cookies, and their real fingerprints.” Customers could search for infected systems with a variety of options, including by Internet address or by specific domain names associated with stolen credentials.</p>
<p>But earlier today, multiple domains associated with Genesis had their homepages replaced with a seizure notice from the FBI, which said the domains were seized pursuant to a warrant issued by the U.S. District Court for the Eastern District of Wisconsin...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>You can now assign multiple MFA devices in IAM</title>
		<link>https://noise.getoto.net/2022/11/17/you-can-now-assign-multiple-mfa-devices-in-iam/</link>
		
		<dc:creator><![CDATA[Liam Wadman]]></dc:creator>
		<pubDate>Wed, 16 Nov 2022 23:17:05 +0000</pubDate>
				<category><![CDATA[credentials]]></category>
		<category><![CDATA[FIDO]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[Google Authenticator]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<category><![CDATA[TOTP]]></category>
		<category><![CDATA[U2F]]></category>
		<category><![CDATA[WebAuthn]]></category>
		<category><![CDATA[YubiKey]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=f3ec1a2d688114faff189e48e848bf22</guid>

					<description><![CDATA[At Amazon Web Services (AWS), security is our top priority, and configuring multi-factor authentication (MFA) on accounts is an important step in securing your organization. Now, you can add multiple MFA devices to AWS account root users and AWS Identity and Access Management (IAM) users in your AWS accounts. This helps you to raise the […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NSA on Authentication Hacks (Related to SolarWinds Breach)</title>
		<link>https://noise.getoto.net/2020/12/18/nsa-on-authentication-hacks-related-to-solarwinds-breach/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 18 Dec 2020 16:35:38 +0000</pubDate>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[trust]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=60621</guid>

					<description><![CDATA[<p>The NSA has published an <a href="https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2451159/nsa-cybersecurity-advisory-malicious-actors-abuse-authentication-mechanisms-to/">advisory</a> outlining how &#8220;malicious cyber actors&#8221; are &#8220;are manipulating trust in federated authentication environments to access protected data in the cloud.&#8221; This is related to the SolarWinds hack I have <a href="https://www.schneier.com/blog/archives/2020/12/another-massive-russian-hack-of-us-government-networks.html">previously</a> <a href="https://www.schneier.com/blog/archives/2020/12/how-the-solarwinds-hackers-bypassed-duo-multi-factor-authentication.html">written</a> <a href="https://www.schneier.com/blog/archives/2020/12/more-on-the-solarwinds-breach.html">about</a>, and represents one of the techniques the SVR is using once it has gained access to target networks.</p>
<p>From the <a href="https://media.defense.gov/2020/Dec/17/2002554125/-1/-1/0/AUTHENTICATION_MECHANISMS_CSA_U_OO_198854_20.PDF">summary</a>:</p>
<blockquote><p>Malicious cyberactors are abusing trust in federated authentication environments to access protected data. The exploitation occurs after the actors have gained initial access to a victim&#8217;s on-premises network. The actors leverage privileged access in the on-premises environment to subvert the mechanisms that the organization uses to grant access to cloud and on-premises resources and/or to compromise administrator credentials with the ability to manage cloud resources. The actors demonstrate two sets of tactics, techniques,and procedures (TTP) for gaining access to the victim network&#8217;s cloud resources, often with a particular focus on organizational email...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 46/247 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-08 14:35:33 by W3 Total Cache
-->