Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Infosec News Feed

An aggregated list of cybersecurity publications
2018-12-04 11:00:00 UTC
ThreatPost
ThreatPost
Magecart Group Ups Ante: Now Goes After Admin Credentials

The group's skimmer has added some capabilities that steals credentials from admins.

Uncategorized Vulnerabilities Web Security Admin Credentials Data Breach Digital Skimmer E-commerce Group 11 Magecart Magecart Group Skimmer VisionDirect VisionDirect Data Breach
2018-12-04 00:33:00 UTC
HackRead
HackRead
Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack

By Waqas

Sotheby’s, an American multinational corporation and Auction House has become another victim of Magecart attack after hackers gained access to Sotheby’s home website and inserted a card-skimming code aiming at customers’ credit card and banking data. Although Sotheby’s detected the intrusion on 10th October 2018 the malware was present on its website and stealing personal and financial data of […]

This is a post from HackRead.com Read the original post: Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack

Hacking News Security Cyber Attack Hacking MageCart Malware Security
2018-12-03 21:30:00 UTC
ThreatPost
ThreatPost
Lawsuit Claims Pegasus Spyware Helped Saudis Spy on Khashoggi

The lawsuit alleges that NSO Group violated international law by allowing Pegasus to be used by oppressive regimes to hunt dissidents and journalists.

Government Malware Privacy Dissidents Human Rights Israel Khashoggi Lawsuit NSO Group Omar Abdulaziz Oppressive Regime Pegasus Spyware
2018-12-03 20:45:00 UTC
Dark Reading
Dark Reading
First Lawsuits Filed in Starwood Hotels' Breach

Class-action suits have been filed on behalf of guests and shareholders, with more expected.

2018-12-03 19:45:00 UTC
Dark Reading
Dark Reading
'Influence Agents' Used Twitter to Sway 2018 Midterms

About 25% of political support in Arizona and Florida was generated by influence agents using Twitter as a platform, research shows.

2018-12-03 19:01:00 UTC
HackRead
HackRead
Private data of more than 82 million US citizens left exposed

By Uzair Amir

Misconfigured ElasticSearch Servers Exposed Private Data of over 82 Million Users. A warning has been issued by Bob Diachenko, a HackenProof security researcher informing users in the US that around 73 gigabytes of data is identified in a “regular security audit” of publicly accessible servers on the Shodan IoT search engine. According to the researcher, […]

This is a post from HackRead.com Read the original post: Private data of more than 82 million US citizens left exposed

Leaks Security Breach Data ElasticSearch LEAKS Privacy Security Shodan Vulnerability
2018-12-03 17:54:00 UTC
ThreatPost
ThreatPost
Chris Vickery on the Marriott Breach and a Rash of Recent High-Profile Hacks

In this Newsmaker Interview, ‘breach hunter’ Chris Vickery explores a recent spate of breaches from Marriott, USPS and Dell EMC.

Breach Cloud Security Newsmaker Interviews Chris Vickery Dell EMC Elasticsearch ElesticDB GDPR Marriott International Merck WannaCry
2018-12-03 17:25:00 UTC
Krebs on Security
Krebs on Security
Jared, Kay Jewelers Parent Fixes Data Leak

The parent firm of bling retailers Jared and Kay Jewelers has fixed a bug in the Web sites of both companies that exposed the order information for all of their online customers.

Data Breaches Brandon Sheehy Jared Kay Jewelers Scott Lancaster Signet Jewelers
2018-12-03 17:06:00 UTC
ThreatPost
ThreatPost
U.S. Military Members Catfished and Hooked for Thousands of Dollars

Prisoners in South Carolina posed convincingly as beautiful women on social media platforms.

Mobile Security Web Security Catfish Enforcement Action Ncis Prisoners Sextortion Scam South Carolina U.S. Military
2018-12-03 15:50:00 UTC
ThreatPost
ThreatPost
Lenovo Ordered to Pay $7.3M in Superfish Fiasco

The laptop giant will settle a 32-state class-action lawsuit stemming from pre-installing vulnerable ad-targeting software.

Privacy Vulnerabilities Adware Class Action Laptop Lenovo MitM Settlement Superfish Vulnerability