Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-08-13 12:34:00 UTC
ThreatPost
ThreatPost
High-Severity TinyMCE Cross-Site Scripting Flaw Fixed

The cross-site scripting flaw could enable arbitrary code execution, information disclosure - and even account takeover.

Vulnerabilities Web Security App Code Cross Site Scripting CVE-2020-12648 Flaw HTML Javascript Poc Security TinyMCE XSS
2020-08-13 12:33:00 UTC
The Daily Swig
The Daily Swig
TinyMCE suffers big XSS flaw

Inadequate sanitization checks result in web security flaw in HTML text editor

2020-08-13 11:18:00 UTC
The Daily Swig
The Daily Swig
US DoJ to shut down 300 fraudulent websites exploiting coronavirus

Move comes following joint investigation between US and Vietnam

2020-08-13 10:00:00 UTC
ThreatPost
ThreatPost
Amazon Alexa ‘One-Click’ Attack Can Divulge Personal Data

Researchers disclosed flaws in Amazon Alexa that could allow attackers to access personal data and install skills on Echo devices.

IoT Privacy Vulnerabilities Amazon Amazon Alexa Data Privacy Flaw Personal Data Vulnerability
2020-08-12 22:32:00 UTC
HackRead
HackRead
TikTok collected MAC addresses for Android phones against Google’s ToS

By Zara Khan

TikTok also collected unique identifiers and sent them to Byte Dance, its parent company.

This is a post from HackRead.com Read the original post: TikTok collected MAC addresses for Android phones against Google’s ToS

Surveillance Android China Data Google Privacy Security Spying TikTok
2020-08-12 18:26:00 UTC
HackRead
HackRead
SANS InfoSec institute loses 28,000 records in phishing attack

By Waqas

SANS is known for providing high-profile and expensive training on InfoSec and cyber security. Oh, the irony.

This is a post from HackRead.com Read the original post: SANS InfoSec institute loses 28,000 records in phishing attack

Cyber Crime Phishing Scam Breach Cyber Security Data Hacking Infosec Phishing Security
2020-08-12 16:45:00 UTC
Dark Reading
Dark Reading
SANS Security Training Firm Hit with Data Breach

A phishing email allowed an attacker to compromise a SANS employee's email environment, the organization reports.

2020-08-12 16:32:00 UTC
The Daily Swig
The Daily Swig
California Privacy Rights Act: State poised to raise privacy bar with ‘CCPA 2.0’

New law would provide California residents with an expanded set of digital rights

2020-08-12 15:51:00 UTC
HackRead
HackRead
23% of Tor browser relays found to be stealing Bitcoin

By Sudais Asif

The threat actor was able to see the user's transmitted data on the Tor browser and tamper with it for their own ill-motives.

This is a post from HackRead.com Read the original post: 23% of Tor browser relays found to be stealing Bitcoin

Security Anonymity Anonymous Dark Web Privacy Tor VPN Vulnerability
2020-08-12 15:17:00 UTC
ThreatPost
ThreatPost
Citrix Warns of Critical Flaws in XenMobile Server

Citrix said that it anticipates malicious actors "will move quickly to exploit" two critical flaws in its mobile device management software.

Vulnerabilities Citrix Critical Flaw CVE-2020-8208 CVE-2020-8209 Flaw Patch Tuesday Patches Vulnerabilities XenMobile Server

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
April 2024
By SUE DENIM
Cyber Warfare: Breaches, Alerts, and Cybersecurity Policy
In cyber warfare, it seems no sector is safe from the relentless clutches of threat actors. Take, for instance, a Russian food manufacturing giant finding itself in the crosshairs of a Ukrainian hacker collective. With a flair for the dramatic, the group proudly proclaimed their conquest in a channel dedicated to airing their digital conquests. Their loot? A whopping 6TB of sensitive data, includi...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
29 April 2024
BREACHAWARE HQ

A total of 13 breaches were found and analysed resulting in 4,834,779 leaked accounts containing a total of 21 different data types. The breaches found publicly and freely available included Stealer Log 0452, Redaq, Stealer Log 0453, Kharkov and Stealer Log 0451