<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Ashetrace Blog</title>
    <link>https://ashetrace.com/blog</link>
    <description>Field notes on infostealer exposure, session hijacking and defensible incident response, for the teams that have to contain it.</description>
    <language>en</language>
    <atom:link href="https://ashetrace.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How to Check Your Computer for an Infostealer</title>
      <link>https://ashetrace.com/blog/how-to-check-computer-for-infostealer</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/how-to-check-computer-for-infostealer</guid>
      <description>Check for an infostealer before you change any passwords. Flashpoint tracked 11.1 million infected devices in 2025. Here is a safe, ordered way to check.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Can a Hacker Bypass Two-Factor Authentication?</title>
      <link>https://ashetrace.com/blog/can-hackers-bypass-two-factor-authentication</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/can-hackers-bypass-two-factor-authentication</guid>
      <description>Yes, attackers can bypass 2FA by stealing the session after login. SpyCloud recaptured 17.3 billion stolen cookies in 2024. Here is how, and how to stay safe.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Signs your computer has an infostealer</title>
      <link>https://ashetrace.com/blog/signs-of-infostealer-infection</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/signs-of-infostealer-infection</guid>
      <description>The signs of infostealer infection are often invisible: the malware runs once and exfiltrates in seconds. 80% of breaches now involve stolen credentials.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>My Passwords Keep Getting Leaked After I Change Them</title>
      <link>https://ashetrace.com/blog/passwords-keep-getting-leaked-after-changing</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/passwords-keep-getting-leaked-after-changing</guid>
      <description>If your password keeps getting compromised after you change it, the cause was never removed. 40% of infostealer infections hit devices that ran antivirus.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>My password appeared in a data leak: what does it mean?</title>
      <link>https://ashetrace.com/blog/password-appeared-in-data-leak</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/password-appeared-in-data-leak</guid>
      <description>A Chrome or Apple alert that your password appeared in a data leak means it was found in a known breach corpus. SpyCloud recaptured 3.1B passwords in 2024.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to log out of all devices after a password leak</title>
      <link>https://ashetrace.com/blog/how-to-log-out-all-devices-after-password-leak</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/how-to-log-out-all-devices-after-password-leak</guid>
      <description>After a leak, sign out of all devices to kill stolen sessions a reset leaves alive. Steps for Google, Microsoft, GitHub and AWS. 17.3B cookies stolen in 2024.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How do I know if someone is logged into my account?</title>
      <link>https://ashetrace.com/blog/how-to-know-if-someone-logged-into-account</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/how-to-know-if-someone-logged-into-account</guid>
      <description>Check your account&apos;s active-sessions list, then watch for forwarding rules and unknown OAuth apps. SpyCloud found 17.3B stolen session cookies in 2024.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How do I know if my credentials were leaked?</title>
      <link>https://ashetrace.com/blog/how-to-know-if-credentials-leaked</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/how-to-know-if-credentials-leaked</guid>
      <description>How to know if your credentials were leaked, why a clean checker result is not proof, and the five exposure types tools miss. HIBP indexes 17.6B pwned accounts.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How do I know if my browser cookies were stolen?</title>
      <link>https://ashetrace.com/blog/how-to-know-if-browser-cookies-stolen</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/how-to-know-if-browser-cookies-stolen</guid>
      <description>You rarely get an alert when browser cookies are stolen. SpyCloud recaptured 17.3 billion stolen session cookies in 2024. Here are the signs to watch.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Have I Been Pwned says I was breached: what should I do?</title>
      <link>https://ashetrace.com/blog/have-i-been-pwned-what-to-do</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/have-i-been-pwned-what-to-do</guid>
      <description>Have I Been Pwned flagged your email? Here&apos;s what to do next: check what leaked, reset reused passwords, and revoke live sessions. HIBP tracks 17.6B accounts.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>My email was found in a data breach, but my password wasn&apos;t</title>
      <link>https://ashetrace.com/blog/email-in-data-breach-but-not-password</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/email-in-data-breach-but-not-password</guid>
      <description>An email in a breach without your password is the lowest-risk exposure, not zero: 70% of breach victims reused a leaked password. What each case means.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>I changed my password after a breach. Am I safe now?</title>
      <link>https://ashetrace.com/blog/changed-password-after-breach-am-i-safe</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/changed-password-after-breach-am-i-safe</guid>
      <description>Changed your password after a breach? You may still be exposed: stolen session cookies bypass the reset. SpyCloud recaptured ~17 billion stolen cookies in 2024.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Can hackers access my account without knowing my password?</title>
      <link>https://ashetrace.com/blog/can-hackers-access-account-without-password</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/can-hackers-access-account-without-password</guid>
      <description>Yes. Attackers replay stolen session cookies, tokens and hijacked phone numbers to skip your password. SpyCloud recaptured 17.3B stolen cookies in 2024 alone.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Identity exposure management: what it is and how it works</title>
      <link>https://ashetrace.com/blog/identity-exposure-management</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/identity-exposure-management</guid>
      <description>Identity exposure management finds, revokes and rotates leaked credentials before attackers log in. SpyCloud recaptured 17.3B stolen session cookies in 2024.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to check whether your company credentials have been exposed</title>
      <link>https://ashetrace.com/blog/check-company-credentials-exposed</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/check-company-credentials-exposed</guid>
      <description>A practical method for security teams to check for exposed company credentials across breach data and stealer logs. HIBP alone indexes 17.6B pwned accounts.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Dark web monitoring vs. infostealer monitoring: what each one detects and misses</title>
      <link>https://ashetrace.com/blog/dark-web-monitoring-vs-infostealer-monitoring</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/dark-web-monitoring-vs-infostealer-monitoring</guid>
      <description>Dark web monitoring catches breach dumps and forum listings; infostealer monitoring surfaces fresh device logs and live cookies. SpyCloud logged 17.3B cookies.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is compromised credential monitoring? A guide for security teams</title>
      <link>https://ashetrace.com/blog/compromised-credential-monitoring</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/compromised-credential-monitoring</guid>
      <description>Compromised credential monitoring finds users in breaches and stealer logs before attackers log in. Stolen credentials drove 22% of 2025 breaches (Verizon).</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Why a password reset is not enough after an infostealer infection</title>
      <link>https://ashetrace.com/blog/password-reset-after-infostealer</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/password-reset-after-infostealer</guid>
      <description>A password reset won&apos;t contain an infostealer: stolen session cookies stay valid until revoked. SpyCloud recaptured 17 billion malware-stolen cookies in 2024.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Infostealer incident response: a step-by-step containment checklist</title>
      <link>https://ashetrace.com/blog/infostealer-incident-response</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/infostealer-incident-response</guid>
      <description>Infostealer incident response checklist: isolate, revoke live sessions, rotate credentials, scope the blast radius. 276M 2025 creds carried active cookies.</description>
      <category>Incident Response</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Employee credentials found on the dark web: what security teams should do next</title>
      <link>https://ashetrace.com/blog/employee-credentials-dark-web</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/employee-credentials-dark-web</guid>
      <description>Employee credentials on the dark web signal a live compromise. Here is how to triage in hours: Verizon ties 22% of all breaches to stolen credentials.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Stolen session cookies: how attackers bypass MFA and how to revoke access</title>
      <link>https://ashetrace.com/blog/stolen-session-cookies-mfa-bypass</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/stolen-session-cookies-mfa-bypass</guid>
      <description>Stolen session cookies let attackers replay an authenticated session and skip MFA. SpyCloud recaptured 17.3 billion of them from infected devices in 2024.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Stealer Logs vs. Data Breaches vs. Combolists: What Is the Difference?</title>
      <link>https://ashetrace.com/blog/stealer-logs-vs-data-breach-vs-combolists</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/stealer-logs-vs-data-breach-vs-combolists</guid>
      <description>Stealer logs, data breaches and combolists are not one threat. Stealer logs are the freshest: 276M carried live session cookies in 2025 (Recorded Future).</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What are stealer logs, what they contain and how to respond</title>
      <link>https://ashetrace.com/blog/what-are-stealer-logs</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/what-are-stealer-logs</guid>
      <description>A stealer log is everything an infostealer siphons from one infected device: passwords, cookies, tokens. Russian Market listed over 180,000 logs in H1 2025.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is infostealer malware, and how it steals corporate credentials</title>
      <link>https://ashetrace.com/blog/what-is-infostealer-malware</link>
      <guid isPermaLink="true">https://ashetrace.com/blog/what-is-infostealer-malware</guid>
      <description>Infostealer malware harvests passwords, cookies and tokens from a device, then feeds corporate breaches. SpyCloud recaptured 17.3B stolen cookies in 2024.</description>
      <category>Threat Intelligence</category>
      <dc:creator>Cassiano Assumpção</dc:creator>
      <pubDate>Fri, 17 Jul 2026 12:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
