Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-08-19 20:46:00 UTC
ThreatPost
ThreatPost
FritzFrog Botnet Attacks Millions of SSH Servers

The unique, advanced worming P2P botnet drops backdoors and cryptominers, and is spreading globally.

Malware Web Security Botnet Brute Force Cryptomining Fileless Fritzfrog Guardicore Labs Malware Analysis P2P Peer To Peer SSH Server Unique Worm
2020-08-19 20:00:00 UTC
Dark Reading
Dark Reading
CISA Warns of New RAT Aimed at US Defense Contractors

Hidden Cobra, an APT group associated with the government of North Korea, is thought to be behind the campaign.

2020-08-19 18:06:00 UTC
HackRead
HackRead
Data scraping firm leaks 235m Instagram, TikTok, YouTube user records

By Sudais Asif

According to researchers, the trove of data was left for public access without any security authentication.

This is a post from HackRead.com Read the original post: Data scraping firm leaks 235m Instagram, TikTok, YouTube user records

Leaks Security Data Scraping LEAKS Security Social Media
2020-08-19 16:04:00 UTC
The Daily Swig
The Daily Swig
Google Firebase messaging vulnerability allowed attackers to send push notifications to app users

A bug bounty hunter’s casual journey through the Android ecosystem led to a $30,000 reward

2020-08-19 14:14:00 UTC
The Daily Swig
The Daily Swig
Mozilla extends bug bounty program to cover exploit mitigation bypass payouts

HTML Sanitizer check

2020-08-19 14:00:00 UTC
Dark Reading
Dark Reading
Stolen Data: The Gift That Keeps on Giving

Users regularly reuse logins and passwords, and data thieves are leveraging that reality to breach multiple accounts.

2020-08-19 13:55:00 UTC
Krebs on Security
Krebs on Security
Voice Phishers Targeting Corporate VPNs

The COVID-19 epidemic has brought a wave of email phishing attacks that try to trick work-at-home employees into giving away credentials needed to remotely access their employers' networks. But one increasingly brazen group of crooks is taking your standard phishing attack to the next level, marketing a voice phishing service that uses a combination of one-on-one phone calls and custom phishing sites to steal VPN credentials from employees.

Latest Warnings The Coming Storm Allison Nixon Domaintools Security Keys Unit 221B Urlscan.io Vishing VPN Phishing Yubico Yubikey Zack Allen ZeroFOX
2020-08-19 13:52:00 UTC
HackRead
HackRead
US Secret Service used ‘Locate X’ to track user location without warrant

By Zara Khan

Locate X collects location data from smartphone apps.

This is a post from HackRead.com Read the original post: US Secret Service used ‘Locate X’ to track user location without warrant

Privacy Surveillance Security Spying
2020-08-19 13:04:00 UTC
ThreatPost
ThreatPost
Airline DMARC Policies Lag, Opening Flyers to Email Fraud

Up to 61 percent out of the IATA (International Air Transport Association) airline members do not have a published DMARC record.

Vulnerabilities Web Security Air Transport Airlines DMARC Domain-based Message Authentication Email Fraud Email Spoofing IATA Reporting & Conformance
2020-08-19 12:58:00 UTC
ThreatPost
ThreatPost
The Sounds a Key Make Can Produce 3D-Printed Replica

Researchers reveal technology called SpiKey that can ‘listen’ to the clicks a key makes in a lock and create a duplicate from the sounds.

Hacks Attack Attackers Key National University Of Singapore Security Signal Processing SpiKey

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
22 April 2024
BREACHAWARE HQ

A total of 11 breaches were found and analysed resulting in 8,670,369 leaked accounts containing a total of 26 different data types. The breaches found publicly and freely available included A MONEY, Raychat, Bin Weevils, ZOON and Stealer Log 0450