Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-09-22 12:56:00 UTC
The Daily Swig
The Daily Swig
Growing ‘cultural divide’ between DevOps and AppSec workers could lead to less secure software – report

Survey warns that working relationships must improve among developers

2020-09-22 12:21:00 UTC
The Daily Swig
The Daily Swig
Youth unemployment risks fueling Indian cybercrime boom

Many young Indians are turning to the dark side to generate additional income, a new report claims

2020-09-21 21:27:00 UTC
ThreatPost
ThreatPost
Fileless Malware Tops Critical Endpoint Threats for 1H 2020

When it comes to endpoint security, a handful of threats make up the bulk of the most serious attack tools and tactics.

Malware Most Recent ThreatLists Web Security Cisco Cobalt Strike Credential Dumping Detection Evasion Dual-use Tools Endpoint Security Fileless Malware First Half 2020 Mimikatz MITRE ATT&CK Persistence Ransomware
2020-09-21 20:25:00 UTC
Dark Reading
Dark Reading
'Dark Overlord' Cyber Extortionist Pleads Guilty

Nathan Wyatt was sentenced to five years in prison after changing a previously not guilty plea.

2020-09-21 20:07:00 UTC
ThreatPost
ThreatPost
Unsecured Microsoft Bing Server Leaks Search Queries, Location Data

Data exposed included search terms, location coordinates, and device information - but no personal data.

Hacks Web Security Cyber Blackmail Cybercriminals Data Exposed Exposed Server Hack Meow Attack Microsoft Microsoft Bing Microsoft Security Misconfiguration Phishing Scams Search Queries Security Hack Unsecured Server
2020-09-21 19:29:00 UTC
ThreatPost
ThreatPost
DHS Issues Dire Patch Warning for ‘Zerologon’

The deadline looms for U.S. Cybersecurity and Infrastructure Security Agency’s emergency directive for federal agencies to patch against the so-called ‘Zerologon’ vulnerability.

Critical Infrastructure Government Vulnerabilities Web Security Active Directory Christopher Krebs CISA ComputeNetlogonCredential CVE-2020-1472 Cybersecurity And Infrastructure Security Agency Github Microsoft Windows Netlogon Remote Protocol MS-NRPC Patch Tuesday Windows Server OS Zerologon
2020-09-21 17:03:00 UTC
The Daily Swig
The Daily Swig
Critical stored XSS vulnerability in Instagram’s Spark AR Studio nets 14-year-old researcher $25,000

Facebook triage team escalated an open redirect flaw found by the Brazilian teenager in the augmented reality tool

2020-09-21 17:01:00 UTC
ThreatPost
ThreatPost
Firefox for Android Bug Allows ‘Epic Rick-Rolling’

Anyone on the same Wi-Fi network can force websites to launch, with no user interaction.

Mobile Security Vulnerabilities Web Security
2020-09-21 16:17:00 UTC
HackRead
HackRead
Whitehat hacker bypasses SQL injection filter for Cloudflare

By Sudais Asif

This was then subsequently reported to Cloudflare who fixed it in a few days.

This is a post from HackRead.com Read the original post: Whitehat hacker bypasses SQL injection filter for Cloudflare

Security CloudFlare Hacking Security SQL Vulnerability
2020-09-21 15:59:00 UTC
ThreatPost
ThreatPost
Android Malware Bypasses 2FA And Targets Telegram, Gmail Passwords

A new Android malware strain has been uncovered, part of the Rampant Kitten threat group's widespread surveillance campaign that targets Telegram credentials and more.

Hacks Malware Mobile Security Vulnerabilities Web Security 2FA Android Malware Infostealer Iranian Threat Group Malware Password Stealer Rampant Kitten Threat Group Two Factor Authentication

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
22 April 2024
BREACHAWARE HQ

A total of 11 breaches were found and analysed resulting in 8,670,369 leaked accounts containing a total of 26 different data types. The breaches found publicly and freely available included A MONEY, Raychat, Bin Weevils, ZOON and Stealer Log 0450