Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2019-10-23 13:46:00 UTC
The Daily Swig
The Daily Swig
Healthcare CISO: ‘Throwing money at security doesn’t make a company secure’

Security specialist Tom August on how to protect the healthcare industry despite pressure from budget cuts

2019-10-23 12:43:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Alexa and Google Home phishing apps demonstrated by researchers

The researchers' "Smart Spies" apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.

Amazon Google Phishing Privacy Actions Alexa Amazon Echo Eavesdropping Google Home Karsten Nohl Passwords Security Research Labs Skills Smart Spies Spying Apps SRL Vishing
2019-10-23 12:41:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Hacker breached servers used by NordVPN

NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.

Privacy Security Threats Vulnerability Data Breach Data Hack Data Leak Hacker NordVPN TorGuard Virtual Private Network Vpn
2019-10-23 12:02:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Facebook pulls fake news networks linked to Russia and Iran

It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.

Facebook Fake News Instagram Social Networks 2020 US Presidential Elections BLMNews Compromised Accounts Fake Accounts Graphika Internet Research Agency IRA Iraq Liberty Front Press Nathaniel Gleicher Political Ads Russia Russian Troll Army Russian Trolls
2019-10-23 12:00:00 UTC
ThreatPost
ThreatPost
15 Years Later, Metasploit Still Manages to be a Menace

A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves, even against modern defenses.

Hacks Malware Web Security APT41 Backdoors Metasploit Shikata Ga Nai Ta505 Turla UNC902
2019-10-23 11:46:00 UTC
The Daily Swig
The Daily Swig
Firefox 70: Browser revamp bundles password manager and multiple security fixes

Mozilla improves privacy by clamping down on social media cross-site tracking cookies

2019-10-23 10:32:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Travel database exposed PII on US government employees

A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.

Amazon Data Loss Privacy Security Threats AWS Best Western Best Western Hotel & Resorts Group Data Breach Data Loss Department Of Homeland Security Elasticsearch Pii
2019-10-22 20:05:00 UTC
ThreatPost
ThreatPost
FTC Cracks Down on Stalkerware With Retina-X App Bans

The FTC has banned the sale of three apps - marketed to monitor children and employees - unless the developers can prove that the apps will be used for legitimate purposes.

Breach Mobile Security Privacy App Ban Data Breach FTC Retina-x Spyware Stalkerware
2019-10-22 19:44:00 UTC
ThreatPost
ThreatPost
Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing

The Qode Instagram Widget and Qode Twitter Feed both have bugs that could allow redirects to malicious sites.

Vulnerabilities Bridge Open Redirect Patch Plugins Qode Instagram Widget Qode Twitter Feed Vulnerabilities Wordpress Theme
2019-10-22 19:04:00 UTC
Krebs on Security
Krebs on Security
Ransomware Hits B2B Payments Firm Billtrust

Business-to-business payments provider Billtrust is still recovering from a ransomware attack that began last week.  The company said it is in the final stages of bringing all of its systems back online from backups.

Data Breaches Billtrust Ransomware Attack Steven Pinado

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE
BreachAware Podcast

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Amazon Music Apple Podcasts Spotify Podcast BreachAware YouTube Channel

Point of View

OUR TAKE ON TRENDING STORIES
June 2024
By SUE DENIM
Dark-Web Forum Collapse, Lockbit’s Misdirection, and Europol’s Botnet Crackdown.
In the ever-dramatic world of cybercrime, a small dark-web forum has found itself in a downward spiral, now up for sale. As covered in our weekly insight, the forum was breached by an unknown threat actor, prompting the admin to panic and shut it down. This came just days after the admin had taken to Telegram to badmouth the threat actor community and insult Shiny Hunters, the admin of Breach Foru...

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
22 July 2024
BREACHAWARE HQ

A total of 9 breaches were found and analysed resulting in 2,948,750 leaked accounts containing a total of 14 different data types. The breaches found publicly and freely available included Avito, Lulu Hypermarket, The Cellula, Boutique Curly and NATO Wiki