{
  "id": 11202375,
  "title": "CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch",
  "url": "https://urgent.news/2026/10/01/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-01T13:32:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/01/ciso-thought-he-had-a-r3lg00dpw0rd-but-forgot-to-patch/5300314"
  },
  "original_language": "en",
  "account": "In a recent case of security negligence, a chief information security officer (CISO) at a law firm failed to patch critical vulnerabilities on his company's Windows systems. The security breach was compounded by the use of a weak, easily guessable password. The CISO, who is also known as \"The Blind Hacker,\" was contracted by a national law firm to perform a penetration test on one of its subsidiaries before a merger and acquisition. During the test, he discovered numerous security holes and a particularly egregious password used by the CISO himself. The password, \"r3@lg00dp@$$w0rd,\" was a hashed version of \"realgoodpassword\" with random symbols and numbers. The CISO's password was stored in plain text, making it easily accessible to anyone who gained access to the system. The CISO was unable to explain his reasoning behind choosing such a weak password, which ultimately led to his identity being revealed during the presentation to the law firm's executives. The incident serves as a stark reminder of the importance of regularly patching systems and using strong, unique passwords.",
  "summary": "Replacing letters with symbols still doesn’t make it good.",
  "key_points": [
    "CISO failed to patch critical vulnerabilities on Windows systems",
    "Used weak, easily guessable password r3@lg00dp@$$w0rd",
    "Password stored in plain text, revealing CISO's identity"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch",
        "url": "https://urgent.news/2026/10/01/ciso-thought-he-had-a-r3-lg00dp-w0rd-but-forgot-to-patch-11204778",
        "published": "2026-10-01T13:32:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}