Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-09-21 21:27:00 UTC
ThreatPost
ThreatPost
Fileless Malware Tops Critical Endpoint Threats for 1H 2020

When it comes to endpoint security, a handful of threats make up the bulk of the most serious attack tools and tactics.

Malware Most Recent ThreatLists Web Security Cisco Cobalt Strike Credential Dumping Detection Evasion Dual-use Tools Endpoint Security Fileless Malware First Half 2020 Mimikatz MITRE ATT&CK Persistence Ransomware
2020-09-21 20:25:00 UTC
Dark Reading
Dark Reading
'Dark Overlord' Cyber Extortionist Pleads Guilty

Nathan Wyatt was sentenced to five years in prison after changing a previously not guilty plea.

2020-09-21 20:07:00 UTC
ThreatPost
ThreatPost
Unsecured Microsoft Bing Server Leaks Search Queries, Location Data

Data exposed included search terms, location coordinates, and device information - but no personal data.

Hacks Web Security Cyber Blackmail Cybercriminals Data Exposed Exposed Server Hack Meow Attack Microsoft Microsoft Bing Microsoft Security Misconfiguration Phishing Scams Search Queries Security Hack Unsecured Server
2020-09-21 19:29:00 UTC
ThreatPost
ThreatPost
DHS Issues Dire Patch Warning for ‘Zerologon’

The deadline looms for U.S. Cybersecurity and Infrastructure Security Agency’s emergency directive for federal agencies to patch against the so-called ‘Zerologon’ vulnerability.

Critical Infrastructure Government Vulnerabilities Web Security Active Directory Christopher Krebs CISA ComputeNetlogonCredential CVE-2020-1472 Cybersecurity And Infrastructure Security Agency Github Microsoft Windows Netlogon Remote Protocol MS-NRPC Patch Tuesday Windows Server OS Zerologon
2020-09-21 17:03:00 UTC
The Daily Swig
The Daily Swig
Critical stored XSS vulnerability in Instagram’s Spark AR Studio nets 14-year-old researcher $25,000

Facebook triage team escalated an open redirect flaw found by the Brazilian teenager in the augmented reality tool

2020-09-21 17:01:00 UTC
ThreatPost
ThreatPost
Firefox for Android Bug Allows ‘Epic Rick-Rolling’

Anyone on the same Wi-Fi network can force websites to launch, with no user interaction.

Mobile Security Vulnerabilities Web Security
2020-09-21 16:17:00 UTC
HackRead
HackRead
Whitehat hacker bypasses SQL injection filter for Cloudflare

By Sudais Asif

This was then subsequently reported to Cloudflare who fixed it in a few days.

This is a post from HackRead.com Read the original post: Whitehat hacker bypasses SQL injection filter for Cloudflare

Security CloudFlare Hacking Security SQL Vulnerability
2020-09-21 15:59:00 UTC
ThreatPost
ThreatPost
Android Malware Bypasses 2FA And Targets Telegram, Gmail Passwords

A new Android malware strain has been uncovered, part of the Rampant Kitten threat group's widespread surveillance campaign that targets Telegram credentials and more.

Hacks Malware Mobile Security Vulnerabilities Web Security 2FA Android Malware Infostealer Iranian Threat Group Malware Password Stealer Rampant Kitten Threat Group Two Factor Authentication
2020-09-21 14:14:00 UTC
HackRead
HackRead
Critical vulnerability allowed hackers to hijack Firefox Android browser

By Waqas

Mozilla fixed a bug that could have let attackers hijack any Firefox Android browser sharing the same Wi-Fi network.

This is a post from HackRead.com Read the original post: Critical vulnerability allowed hackers to hijack Firefox Android browser

Cyber Crime Android Browser Firefox Mozilla Privacy Technology
2020-09-21 14:03:00 UTC
The Daily Swig
The Daily Swig
Online ID verification challenges heightened by coronavirus social distancing rules – Interpol

A good identification verification system should balance security, convenience, and privacy – but this is often easier said than done

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
29 April 2024
BREACHAWARE HQ

A total of 13 breaches were found and analysed resulting in 4,834,779 leaked accounts containing a total of 21 different data types. The breaches found publicly and freely available included Stealer Log 0452, Redaq, Stealer Log 0453, Kharkov and Stealer Log 0451