Google Workspace Log Extraction

Google Workspace Log Extraction

In this blog post, we reviewed the methods through which we can extract logs from Google Workspace. One option is to query the logs in the Admin Console, although there are several limitations that result in this not being the most ideal method. The best option to obtain the most thorough and easily parsable data is to use the Reports API in the Admin SDK. We also mentioned the use of forwarding logs to Google Cloud for a subset of audit logs to be available via Google Cloud Logging. In the last two blog posts in this series, we’ll look at how to extract logs from Microsoft 365 and Azure.

Read More

BreachForums Clone – 4,204 breached accounts

In June 2023, a clone of the previously shuttered popular hacking forum “BreachForums” suffered a data breach that exposed over 4k records. The breach was due to an exposed backup of the MyBB database which included email and IP addresses, usernames and Argon2 password hashes.

Read More

Zacks – 8,929,503 breached accounts

In December 2022, the investment research company Zacks announced a data breach. The following month, reports emerged of the incident impacting 820k customers. However, in June 2023, a corpus of data with almost 9M Zacks customers appeared before being broadly circulated on a popular hacking forum. The most recent data was dated May 2020 and included names, usernames, email and physical addresses, phone numbers and passwords stored as unsalted SHA-256 hashes. On disclosure of the larger breach, Zacks advised that in addition to their original report “the unauthorised third parties also gained access to encrypted [sic] passwords of zacks.com customers, but only in the encrypted [sic] format”.

Read More
X