Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Massive database with 24 billion credentials found exposed online

A massive, unsecured Elasticsearch database containing approximately 24 billion plaintext credentials and login URLs was discovered exposed online, compiled from 36 sources including infostealer logs and previous breaches. This exposure creates a severe credential-stuffing risk, particularly for accounts lacking multi-factor authentication, and the database appears to be actively updated. No specific software vulnerability, CVSS score, affected versions, patch, or workaround is detailed in the report, as the threat stems from the exposure of the aggregated data collection itself.
Read Full Article →

Identity Massive database with 24 billion credentials found exposed online June 17, 2026 Share By SC Staff (Adobe Stock) A colossal database containing 24 billion records, including usernames, passwords, and login URLs in plaintext, was discovered exposed on the internet. Security researchers from Cybernews found the Elasticsearch database, which is believed to be a compilation of various infostealer logs, according to a recent report by Tech Radar. The exposed database, weighing approximately 8 terabytes, was compiled from 36 different sources, including Telegram channels, previous data breach collections, and data exported from live servers. While the exact number of unique entries is unknown, the sheer volume of data poses a significant risk of account takeovers for billions of users, especially those without multi-factor authentication. The owner of the database remains unidentified, with sources indicating a mix of English and Russian origins. Notably, around 260 million records are linked to Telegram channels associated with the defunct ransomware group "Darkside." The database appears to be regularly updated, suggesting active monitoring of the cybersecurity landscape. Source: Tech Radar SC Staff Related Privacy Apple to change Hide My Email domain, potentially impacting anonymous sign-ups SC Staff June 17, 2026 The change, announced to developers, will move anonymously generated email addresses to a new domain, @private.icloud.com. Identity Beyond Identity launches Ceros to secure enterprise AI agents SC Staff June 16, 2026 Ceros aims to provide visibility and control over AI agents by logging every session, including the user and device involved. Privacy UK government to ban social media for under-16s SC Staff June 16, 2026 To enforce the ban, social media platforms will be required to implement age verification for new users, likely through ID uploads or facial age scans. Related Events Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Cybercast The industrialization of identity compromise On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article