Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2020-03-03 22:29:00 UTC
HackRead
HackRead
Hackers are using Word documents to drop NetSupport Manager RAT

By Sudais Asif

Before dropping NetSupport Manager RAT, attackers trick users into opening a malicious MS Word document by entering a password.

This is a post from HackRead.com Read the original post: Hackers are using Word documents to drop NetSupport Manager RAT

News Cyber Attack Cyber Crime Fraud Malware Phishing Privacy RAT Security TROJAN
2020-03-03 21:50:00 UTC
ThreatPost
ThreatPost
Cobalt Ulster Strikes Again With New ForeLord Malware

Threatpost talks to Alex Tilley, senior security researcher with Dell SecureWorks' Counter Threat Unit Research Team, about a recently discovered campaign linked to an Iranian APT.

Malware RSAC Videos Advanced Persistent Threat Actor Cobalt Ulster Credential Theft Forelord Irán Iran APT Malware Muddywater APT
2020-03-03 21:30:00 UTC
Dark Reading
Dark Reading
Gotta Patch 'Em All? Not Necessarily, Experts Say

When it's impossible to remediate all vulnerabilities in an organization, data can indicate which bugs should be prioritized.

2020-03-03 20:13:00 UTC
ThreatPost
ThreatPost
Let’s Encrypt to Revoke Millions of TLS Certs

On Wednesday millions of Transport Layer Security certificates will be revoked because of a Certificate Authority Authorization bug.

Cryptography Web Security Bug Caa Certificate Authority Authorization Certificates Let's Encrypt Revoke TLC Transport Layer Security Vulnerability
2020-03-03 19:02:00 UTC
ThreatPost
ThreatPost
MediaTek Bug Actively Exploited, Affects Millions of Android Devices

An exploit published by a developer is easy to use and has already been used to build malicious apps that gain root access on Android devices.

Mobile Security Vulnerabilities Android Critical Flaw CVE-2020-0032 CVE-2020-0069 March 2020 Android Update MediaTek Root Access Security Vulnerability Xda-developer
2020-03-03 17:56:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Why ‘free’ Wi-Fi isn’t really free

How much data is too much to give away to get online while you're waiting at the train station? In the airport? A shopping mall?

Data Loss Data Breach Free Wi-Fi Wi-fi
2020-03-03 17:15:00 UTC
Dark Reading
Dark Reading
Former Microsoft Software Engineer Convicted of Fraud

The 25-year-old was convicted of 18 charges stemming from illegal access to money stored in online gift cards.

2020-03-03 16:32:00 UTC
The Daily Swig
The Daily Swig
Data rights in Canada: Quebec to modernize its privacy law with a GDPR-style flair

Canadian province may set country’s future privacy standard

2020-03-03 16:28:00 UTC
ThreatPost
ThreatPost
Have I Been Pwned No Longer For Sale

Troy Hunt said the popular HIBP will continue to be run as an independent service.

Breach Vulnerabilities Breach Alert Data Breach Have I Been Pwned HIBP HIBP Sale Password Troy Hunt
2020-03-03 15:39:00 UTC
Krebs on Security
Krebs on Security
The Case for Limiting Your Browser Extensions

Last week, KrebsOnSecurity reported to health insurance provider Blue Shield of California that its Web site was flagged by multiple security products as serving malicious content. Blue Shield quickly removed the unauthorized code. An investigation determined it was injected by a browser extension installed on the computer of a Blue Shield employee who'd edited the Web site in the past month.

The incident is a reminder that browser extensions -- however useful or fun they may seem when you install them -- typically have a great deal of power and can effectively read and/or write all data in your browsing sessions. And as we'll see, it's not uncommon for extension makers to sell or lease their user base to shady advertising firms, or in some cases abandon them to outright cybercriminals.

Breadcrumbs 212b3d4039ab5319ec.js Blue Shield Of California Cndpps DomainTools.com Frankomedison1020@gmail.com Icontent Linkojager Metrext Monetizus Page Ruler Extension Peter Newnham Thisadsfor

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Point of View

OUR TAKE ON TRENDING STORIES
March 2024
By SUE DENIM
TikTok Ban, Discord Bot Community Attack, and Telecom Company's Breach Resurgence.
Ah, the dramatic saga of TikTok in the United States! Picture this: a ban looming over TikTok, akin to a dark cloud threatening to rain on our digital parade. Congress is all up in arms, waving their "think of the children" banners while TikTok nervously checks its watch, wondering if it should start packing its bags for a forced sale. Meanwhile, nobody bats an eye at the plethora of Chinese gadge...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
22 April 2024
BREACHAWARE HQ

A total of 11 breaches were found and analysed resulting in 8,670,369 leaked accounts containing a total of 26 different data types. The breaches found publicly and freely available included A MONEY, Raychat, Bin Weevils, ZOON and Stealer Log 0450