Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2019-11-13 12:06:00 UTC
Naked Security | Sophos
Naked Security | Sophos
US-CERT warns of critical flaws in Medtronic equipment

Medtronic's latest problem is in their Valleylab electrosurgical generators used by surgeons things like cauterisation during operations.

Vulnerability Insulin Pumps Medical Medtronic Valleylab
2019-11-13 11:45:00 UTC
ThreatPost
ThreatPost
Federal Court: Suspicionless Search of Traveler Devices by Border Agents Is Unconstitutional

U.S. Customs agents now must have reasonable cause and suspicion to search traveler devices at points of entry.

Government Privacy American Civil LIberties Union Borders Courts Edward Snowden Electronic Devices Electronic Frontier Foundation Smartphones U.S. Customs And Border Protection
2019-11-13 11:31:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Microsoft says it will honor California’s new privacy law across US

Microsoft said CCPA is good news, given the failure of Congress to pass a comprehensive privacy protection law at the federal level.

Law & Order Microsoft Privacy California Consumer Privacy Act CCPA Chief Privacy Officer GDPR
2019-11-13 11:23:00 UTC
Naked Security | Sophos
Naked Security | Sophos
No, YouTube isn’t planning to jettison your unprofitable channel

Or your small/new channel, or to shut you down if you use an ad blocker, though a clause in its new ToS is leading people to fear the worst.

Google Social Networks Account Termination Ad Blockers Clause TOS Videos YouTube
2019-11-12 22:10:00 UTC
ThreatPost
ThreatPost
Insider Threats, a Cybercriminal Favorite, Not Easy to Mitigate

Rogue employees -- not just external threat groups -- pose a formidable threat to incident response teams.

Hacks Web Security Breach Incident Response Insider Threat Mitigation OpenText Enfuse Rogue Employee
2019-11-12 22:04:00 UTC
Krebs on Security
Krebs on Security
Patch Tuesday, November 2019 Edition

Microsoft today released updates to plug security holes in its software, including patches to fix at least 74 weaknesses in various flavors of Windows and in software that runs on top of it. The November updates include patches for a zero-day flaw in Internet Explorer that is currently being exploited in the wild, as well as a sneaky bug in certain versions of Office for Mac that bypasses security protections and was detailed publicly prior to today's patches.

Time To Patch Adobe CVE-2019-1429 CVE-2019-1457 Internet Explorer Zero-day Macros Microsoft Office For Mac Windows 7 End-of-life
2019-11-12 21:35:00 UTC
ThreatPost
ThreatPost
Microsoft Patches RCE Bug Actively Under Attack

Microsoft tackles 74 bugs as part of its November Patch Tuesday security bulletin.

Vulnerabilities Additional Critical Microsoft Patch Tuesday November Patch Tuesday Office Document Remote Code Execution SYLK SYmbolic Vulnerabilities
2019-11-12 21:11:00 UTC
ThreatPost
ThreatPost
Plugging the Data Leak in Manufacturing

IIoT-generated data – calibrations, measurements and other parameters – still need to be stored, managed and shared securely.

Critical Infrastructure InfoSec Insider IoT Data Security Digital Guardian IIoT Industrial Infosec Insiders Internet Of Things Manufacturing Security Concerns Tim Bandos
2019-11-12 21:00:00 UTC
Dark Reading
Dark Reading
New DDoS Attacks Leverage TCP Amplification

Attackers over the past month have been using a rarely seen approach to disrupt services at large organizations in several countries.

2019-11-12 19:07:00 UTC
ThreatPost
ThreatPost
Intel Warns of Critical Info-Disclosure Bug in Security Engine

The issue is in an Intel chip used for remote management.

Vulnerabilities Critical Flaw CVE-2019-0169 Information Disclosure Intel November 2019 Patch Tuesday Patches

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
April 2024
By SUE DENIM
Cyber Warfare: Breaches, Alerts, and Cybersecurity Policy
In cyber warfare, it seems no sector is safe from the relentless clutches of threat actors. Take, for instance, a Russian food manufacturing giant finding itself in the crosshairs of a Ukrainian hacker collective. With a flair for the dramatic, the group proudly proclaimed their conquest in a channel dedicated to airing their digital conquests. Their loot? A whopping 6TB of sensitive data, includi...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
29 April 2024
BREACHAWARE HQ

A total of 13 breaches were found and analysed resulting in 4,834,779 leaked accounts containing a total of 21 different data types. The breaches found publicly and freely available included Stealer Log 0452, Redaq, Stealer Log 0453, Kharkov and Stealer Log 0451