Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-02-25 13:35:00 UTC
Naked Security | Sophos
Naked Security | Sophos
The “Cloud Snooper” malware that sneaks into your Linux servers

Fascinating research from SophosLabs into a wolf-in-sheep's-clothing malware sample.

Malware Cloud Snooper Kernel Malware Linux Malware Rootkit
2020-02-25 13:22:00 UTC
The Daily Swig
The Daily Swig
MyBB security analysis: Open source community helped squash hundreds of bugs

Forum software developers offer insight ahead of next major release

2020-02-25 11:47:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Smart speakers mistakenly eavesdrop up to 19 times a day

That smart home speaker isn't listening to everything you say, according to new research - but it is listening a lot more than it should.

Amazon Apple Google Machine Learning Microsoft Privacy Alexa Cortana Echo Dot Google Assistant Harmon Kardon Invoke HomePod Siri Smart Speakers
2020-02-25 11:22:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Google denies illegally slurping data off free student Chromebooks

Nonsense! says Google in response to a lawsuit filed by New Mexico's AG, which accuses Google of violating COPPA's child privacy laws.

Google Law & Order Privacy ChromeBook Contacts Coppa Data Collection Docs Drive Edtech Education Technology G Suite G Suite For Education Geolocation Gmail Google Education Hector Balderas Internet History Lawsuit Minors New Mexico Parental Consent Search Engine Records Sheet Student Data Students Unfair Practices Act Voice Recordings
2020-02-25 11:02:00 UTC
The Daily Swig
The Daily Swig
Let’s Encrypt deploys new domain validation technology to mitigate BGP hijacking risks

‘Multi-perspective’ assurance method reduces the risk of certs being mistakenly issued to fraudsters

2020-02-24 21:49:00 UTC
ThreatPost
ThreatPost
Apple Takes Heat Over ‘Vulnerable’ iOS Cut-and-Paste Data

Software developer builds a malicious proof-of-concept iOS app that can read data temporarily saved to the device’s clipboard.

Hacks Mobile Security Vulnerabilities Apple Apple Vulnerability Clipboard Ios IOS Flaw
2020-02-24 19:04:00 UTC
HackRead
HackRead
PayPal rejects report that exposed critical account takeover vulnerabilities

By Sudais Asif

In a shocking decision, PayPal has rejected vulnerabilities reported by researchers as part of the payment giant's bug bounty program.

This is a post from HackRead.com Read the original post: PayPal rejects report that exposed critical account takeover vulnerabilities

Security Bug Bounty Paypal Security Vulnerability
2020-02-24 17:13:00 UTC
Krebs on Security
Krebs on Security
Zyxel Fixes 0day in Network Storage Devices

Networking hardware vendor Zyxel today released an update to fix a critical flaw in many of its network attached storage (NAS) devices that can be used to remotely commandeer them. The patch comes 12 days after KrebsOnSecurity alerted the company that precise instructions for exploiting the vulnerability were being sold for $20,000 in the cybercrime underground.

Based in Taiwan, Zyxel Communications Corp. (a.k.a "ZyXEL") is a maker of networking devices, including Wi-Fi routers, NAS products and hardware firewalls. The company has roughly 1,500 employees and boasts some 100 million devices deployed worldwide. While in many respects the class of vulnerability addressed in this story is depressingly common among Internet of Things (IoT) devices, the flaw is notable because it has attracted the interest of groups specializing in deploying ransomware at scale.

Latest Warnings The Coming Storm Time To Patch 0day 500mhz Alex Holden CERT Coordination Center CERT/CC CVE-2020-9054 DHS Emotet Hold Security Ransomware Zero Day ZyXEL Communications Corp.
2020-02-24 15:44:00 UTC
The Daily Swig
The Daily Swig
Ireland’s privacy regulator handled 6,000 data breach reports in 2019

Breach reports rise sharply, but country has growing backlog of Big Tech data handling enquiries

2020-02-24 15:00:00 UTC
Dark Reading
Dark Reading
Solving the Cloud Data Security Conundrum

Trusting the cloud involves a change in mindset. You must be ready to use runtime encryption in the cloud.

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
29 April 2024
BREACHAWARE HQ

A total of 13 breaches were found and analysed resulting in 4,834,779 leaked accounts containing a total of 21 different data types. The breaches found publicly and freely available included Stealer Log 0452, Redaq, Stealer Log 0453, Kharkov and Stealer Log 0451