A Traefik Shortcut Could Let a Stranger Inherit Your Login

A specific Traefik HTTP/3 and NTLM configuration could let one client reuse a backend connection authenticated as someone else. Fixed releases and a public test are available.

A specific Traefik HTTP/3 and NTLM configuration could let one client reuse a backend connection authenticated as someone else. Fixed releases and a public test are available.

A fraudulent request from a genuine government email domain persuaded Revolut to disclose sensitive customer records. The failure was in verifying who had authority to ask.

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

Florida identified one compromised police login, improperly stored on an employee's personal device, as the route into its systems. The claimed scale of exposure remains unconfirmed.

One compromised contractor session opened cloud applications, patient systems and external health-record portals. HHS says the AdaptHealth breach affected 4,115,802 people.

The attacker did not need broad network access. Veradigm says credentials stolen from a third-party vendor were enough to copy patient data through one customer-service API.

The passkey was only the pretext. Microsoft says attackers are calling personal phones, capturing cloud sessions and quietly collecting files and email for hours or days.

The attacker did not need to host a conventional phishing page. Microsoft redirects, a blob URL and a service worker assembled the fake login inside the victim’s browser.

Separate social-engineering breaches at Quinn Emanuel and McDermott show how one compromised identity can expose exceptionally sensitive legal records.

Hasbro says a compromised employee account exposed personal and financial information. Massachusetts records identify 436 affected residents, while the worldwide total remains undisclosed.