Password guessing without AI: How attackers build targeted wordlists
ID: 494f8885-a706-5ac2-b559-e70bd2333ccf
STIX ID: report--494f8885-a706-5ac2-b559-e70bd2333ccf
Feed Name: Bleeping Computer
This sponsored article outlines how attackers leverage CeWL to harvest organization-specific language from public websites, then use mutation techniques (e.g., with Hashcat) to create highly targeted password guesses that often bypass standard complexity rules. It emphasizes that context-derived passwords remain weak despite length and character variety, and recommends defenses including blocking organization-specific and known-breached passwords, enforcing long passphrases, and enabling MFA, aligning password policy with real-world attack methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
