Employee onboarding often involves sharing temporary passwords via email or SMS, creating security risks if intercepted or never changed. Attackers exploit weak or default credentials to access corporate systems, as seen in incidents like the Cyber Av3ngers attack on a water utility using default PLC passwords and the McHire platform breach via a legacy admin account. Solutions like Specops First Day Password allow new hires to set their own passwords securely, reducing reliance on temporary credentials. Organizations must enforce password resets and adopt secure onboarding practices to mitigate these risks.
CVEs: CVE-2026-11645
Attack groups: Cyber Av3ngers
Companies: Specops, Paradox.ai, McDonald's
Products: Specops First Day Password, Specops uReset, McHire
Original source: thehackernews.com