Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-10-07 18:44:00 UTC
ThreatPost
ThreatPost
Google Rolls Out Fixes for High-Severity Android System Flaws

The most serious bugs are elevation-of-privilege issues in the Android System component (CVE-2020-0215 and CVE-2020-0416).

Vulnerabilities Web Security (CVE-2020-0215 Android Android Security Update CVE-2020-0416 Elevation Of Privilege Framework Google Information Disclosure Kernel Media Framework October 2020 Pixel Qualcomm Samsung
2020-10-07 18:30:00 UTC
Dark Reading
Dark Reading
CISA Warns of Renewed Emotet Activity

The Emotet malware dropper is seeing an upsurge in new activity in the second half of 2020.

2020-10-07 18:00:00 UTC
Dark Reading
Dark Reading
The New War Room: Cybersecurity in the Modern Era

The introduction of the virtual war room is a new but necessary shift. To ensure its success, security teams must implement new systems and a new approach to cybersecurity.

2020-10-07 17:58:00 UTC
HackRead
HackRead
OceanLotus hackers injecting malware in Windows error report

By Waqas

OceanLotus is a Vietnamese APT32 group previously known for targeting Android and Mac devices with malware.

This is a post from HackRead.com Read the original post: OceanLotus hackers injecting malware in Windows error report

Security Hacking Macro Malware Malwarebytes OceanLotus Windows
2020-10-07 17:24:00 UTC
ThreatPost
ThreatPost
BAHAMUT Spies-for-Hire Linked to Extensive Nation-State Activity

Researchers uncovered a sophisticated, incredibly well-resourced APT that has its fingers in wide-ranging espionage and disinformation campaigns.

Hacks Bahamut BlackBerry Cyberattacks Disinformation Sites Espionage Fake News Hackers For Hire Middle East Nation State Phishing Sikhs South Asia Spies For Hire Techsprouts
2020-10-07 15:55:00 UTC
The Daily Swig
The Daily Swig
Researchers map threat actors’ use of open source offensive security tools

Malware cartographers offer their insights

2020-10-07 15:50:00 UTC
ThreatPost
ThreatPost
Google’s Chrome 86: Critical Payments Bug, Password Checker Among Security Notables

Google is rolling out 35 security fixes, and a new password feature, in Chrome 86 versions for Windows, Mac, Android and iOS users.

Vulnerabilities Web Security Android Chrome Chrome 86 Compromised Password Credential Stuffing CVE-2020-15967 CVE-2020-15969 CVE-2020-15971 CVE-2020-15972 CVE-2020-15991 Encryption Google Google Payments HTTPS Ios Linux Mac Password Check Patches Safety Check Security Fix Security Improvements Windows
2020-10-07 14:58:00 UTC
Krebs on Security
Krebs on Security
Promising Infusions of Cash, Fake Investor John Bernard Walked Away With $30M

September featured two stories on a phony tech investor named John Bernard, a pseudonym used by a convicted thief named John Clifton Davies who's fleeced dozens of technology companies out of an estimated $30 million with the promise of lucrative investments. Those stories prompted a flood of tips from Davies' victims that paint a much clearer picture of this serial con man and his cohorts, including allegations of hacking, smuggling, bank fraud and murder.

A Little Sunshine Ne'er-Do-Well News Docklands Enterprise Ltd. Ecaterina Dudorenko Inside Knowledge Solutions Ltd. Iryna Davies John Bernard John Clifton Davies Katherine Miller Organized Crime And Corruption Reporting Project Pravda SafeSwiss Secure Communication AG Secure Swiss Data Sergey Valentinov Pankov The Inside Knowledge The Private Office Of John Bernard The-private-office.ch
2020-10-07 13:25:00 UTC
ThreatPost
ThreatPost
PoetRAT Resurfaces in Attacks in Azerbaijan Amid Escalating Conflict

Spear-phishing attacks targeting VIPs and others show key malware changes and are likely linked to the current conflict with Armenia.

Government Malware Web Security Armenia Azerbaijan Cisco Talos Conflict Dostoevsky Email Espionage Government Macros Malicious Documents Malware Analysis Microsoft Word Nation State PoetRAT Public Sector Spearphishing Spyware The Brothers Karamazov Threat Actors War
2020-10-07 13:14:00 UTC
ThreatPost
ThreatPost
IRS COVID-19 Relief Payment Deadlines Anchor Convincing Phish

The upcoming deadlines for applying for coronavirus relief are the lure for a phish that gets around email security gateways by using a legitimate SharePoint page for data-harvesting.

Web Security Armorblox Campaign COVID-19 Deadlines Direct Payments Economic Impact Payment Email Security Gateway IRS Non-filers Phishing Scam Sharepoint Page

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
15 April 2024
BREACHAWARE HQ

A total of 15 breaches were found and analysed resulting in 10,110,194 leaked accounts containing a total of 23 different data types. The breaches found publicly and freely available included US Environmental Protection Agency (EPA), Stealer Log 0448, Stealer Log 0449, Believe and Carding Team