Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Security16:37 · Jun 22

Reused Passwords Exposed in Massive Fortinet Credential Cache

By בני סולומון
Translated & summarized from Kikar HaShabbat by baba
The story · English

Cyber researchers have uncovered a huge data cache called FortiBleed containing valid login credentials for Fortinet security systems. The exposed material could give attackers direct access to 74,000 systems across 21,000 organizations worldwide. The discovery was led by security researcher Volodymyr “Bob” Diachenko and analyzed by Hudson Rock and SOCRadar.

The researchers said the breach was not the result of a new technical flaw, but of human and organizational failures in password management. The server contained usernames and passwords, along with automated attack tools that cybercriminals used to launch more than 1 billion login attempts. The attackers relied on credential stuffing, using passwords stolen in earlier breaches to try access on other systems.

According to the report, once attackers entered an organization’s network, they harvested more login details and used them to deepen the intrusion, creating a self-feeding attack chain. The core weakness was password reuse, because the same password can unlock multiple systems if it was exposed in an unrelated breach years earlier. The article warns that even a system administrator using a personal password elsewhere can place an entire organization at risk.

Security experts are urging users and organizations to stop reusing passwords, switch to unique passwords for every service, enable multi-factor authentication, keep systems updated, and regularly check whether credentials have appeared in past breaches. The article says the case shows that no sophisticated vulnerability is always needed, since one leaked password can be enough to breach sensitive networks, including government bodies, multinational companies, and financial institutions.

Read the original at Kikar HaShabbat
Open the live terminal