[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjf9qE2g5gZsbN0k2087yNQklIAc-iIPXOOZ9lEg1Fgc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"1fcf85b3-ca73-47e1-bcca-0ef7c044300a","supreme-court-breach-highlights-credential-theft-and-monitoring-gaps","77a964b6-4fc6-4779-8a60-51b45263d28e","Supreme Court breach highlights credential theft and monitoring gaps","Nicholas Moore successfully breached multiple high-profile government systems including the U.S. Supreme Court's filing system using stolen credentials, demonstrating critical failures in access control and detection capabilities. The attacker was able to maintain access long enough to extract and publicly post victims' personal information on social media without detection. This incident highlights how compromised credentials can provide extensive access to sensitive government systems when proper monitoring and access controls are absent.","**Immediate actions:**\n- Implement multi-factor authentication (MFA) for all administrative and privileged accounts\n- Deploy real-time monitoring for unusual access patterns and credential usage\n- Conduct immediate audit of all user accounts and disable inactive or suspicious credentials\n\n**Long-term improvements:**\n- Establish privileged access management (PAM) solutions to control and monitor high-risk accounts\n- Implement zero-trust architecture requiring continuous verification of user identity and device status\n- Deploy user and entity behavior analytics (UEBA) to detect anomalous activities\n\n**Detection measures:**\n- Enable alerting for data exfiltration attempts and large file downloads\n- Monitor social media and dark web for leaked organizational data\n- Implement data loss prevention (DLP) tools to prevent unauthorized data sharing",[12,13,14,15,16,17],"CIS Control 6 - Access Control Management","CIS Control 8 - Audit Log Management","NIST AC-2 - Account Management","NIST AC-6 - Least Privilege","NIST AU-6 - Audit Review","NIST IA-2 - Identification and Authentication","published","2026-04-19T21:08:25.728835+00:00","2026-04-19T21:08:25.651+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Ftechcrunch.com\u002F2026\u002F04\u002F17\u002Fman-who-hacked-us-supreme-court-filing-system-sentenced-to-probation\u002F","man-who-hacked-us-supreme-court-filing-system-sentenced-to-probation-techcrunch-a2812a","Man who hacked US Supreme Court filing system sentenced to probation | TechCrunch",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]