CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Member of The Com sent to prison for blackmail, sextortion

Today's briefing covers passkey security vulnerabilities, LexisNexis service disruptions, and supply chain breaches impacting Valve and Steam hardware customers.

Authentication and supply chain resilience take center stage today. Security researchers demonstrated new methods to bypass passkey protections and extract synced private keys without breaking underlying cryptography. Meanwhile, third-party vendor incidents continue to impact major enterprises, forcing LexisNexis to take core services offline and compromising customer data for Valve's Steam hardware operations.

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Researchers revealed attacks against passkey implementations that recover synced private keys or bypass phishing-resistant MFA without cracking underlying cryptography, affecting Windows Hello for Business and Google Password Manager in Chrome.

Why it matters
Organizations using passkeys or Windows Hello for Business may face MFA bypass or key recovery if endpoints or user sessions are compromised.
  • passkeys
  • mfa
  • windows
  • chrome
Read the original

Member of The Com sent to prison for blackmail, sextortion

A member of 'The Com,' an online cybercrime collective targeting children and teenagers, has been sentenced to two years in prison for blackmail and sextortion involving nearly 120 victims worldwide.

  • cybercrime
  • extortion
Read the original

LexisNexis shuts down services after suspicious activity on servers

LexisNexis shut down its Diligence, Metabase API, and Newsdesk services after detecting unusual activity on servers managed by an unnamed third-party hosting vendor.

Why it matters
Third-party vendor incidents can compromise hosted environments and force operational service disruptions across reliant business applications.
  • lexisnexis
Read the original

Valve notifies Steam hardware customers of a data breach

Valve is notifying Steam hardware customers in Europe that their data was stolen following a cyberattack on its logistics and shipping partner, CEVA Logistics.

Why it matters
Third-party logistics breaches expose customer order and contact details, increasing susceptibility to phishing and fraud.
  • valve
Read the original

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster.

  • devsecops
  • ai
Read the original

Key takeaways

  • Security researchers demonstrated passkey attacks that bypass MFA and recover private keys without breaking the underlying cryptography.
  • LexisNexis took Diligence, Metabase API, and Newsdesk services offline following suspicious activity on a third-party vendor's servers.
  • A cybercrime actor involved in The Com collective was sentenced to two years in prison for extortion and blackmail offenses against nearly 120 victims.
  • TheCom
  • sextortion
  • PasskeyAttacks
  • MFA
  • SpecterOps