Important: BreachAware does not operate under any other brand name and will never provide unauthorised access to compromised credentials. We ask our users to beware of illegitimate websites imitating BreachAware.

Global News Feed

POPULAR CYBERSECURITY PUBLICATIONS
2019-03-21 15:17:00 UTC
Krebs on Security
Krebs on Security
Facebook Stored Hundreds of Millions of User Passwords in Plain Text for Years

Hundreds of millions of Facebook users had their account passwords stored in plain text and searchable by thousands of Facebook employees -- in some cases going back to 2012, KrebsOnSecurity has learned. Facebook says an ongoing investigation has so far found no indication that employees have abused access to this data.

A Little Sunshine The Coming Storm Facebook Plaintext Passwords Scott Renfro
2019-03-21 15:00:00 UTC
The Daily Swig
The Daily Swig
FIRST for security: Non-profit looks ahead to another 15 years of CVSS ratings

Behind the scenes at the world’s most popular vulnerability scoring system

2019-03-21 12:57:00 UTC
The Daily Swig
The Daily Swig
New XS-Leak techniques reveal fresh ways to expose user information

‘This should be in the OWASP Top 10 in 2025’

2019-03-21 12:31:00 UTC
ThreatPost
ThreatPost
Cisco Patches High-Severity Flaws in IP Phones

The most serious vulnerabilities in Cisco's 8800 Series IP Phones could allow unauthenticated, remote attackers to conduct a cross-site request forgery attack or write arbitrary files to the filesystem.

Mobile Security Vulnerabilities Cisco Cisco IP Phone 7800 Series Cisco IP Phone Series 8800 Cisco Patch Denial Of Service High Severity Flaw Path Traversal Flaw Remote Code Execution
2019-03-21 12:09:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Researcher finds new way to sniff Windows BitLocker encryption keys

A researcher has published a new and relatively simple way that Windows BitLocker encryption keys can be sniffed in less secure configurations as they travel from Trusted Platform Modules (TPMs) during boot.

2-factor Authentication Cryptography Microsoft Organisations Security Threats Vulnerability BitLocker Tpm Trusted Platform Modules Windows Windows 10
2019-03-21 12:02:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Flaw in popular PDF creation library enabled remote code execution

A researcher has discovered a high-severity bug in a popular PHP library used for creating PDFs.

Security Threats Cross-site Scripting Deserialization PHP PHP Library Polict Rce Remote Code Execution TCPDF XSS
2019-03-21 11:41:00 UTC
Naked Security | Sophos
Naked Security | Sophos
Opera brings back free VPN service to its Android browser

Opera lost its Android browser's VPN after it was sold to a Chinese consortium, but now it's back.

Android Mobile Opera Privacy Web Browsers Browser Privacy Mobile Browsers Opera Vpn Web Browser Privacy
2019-03-21 11:13:00 UTC
The Daily Swig
The Daily Swig
UPnP harnessed to map potentially vulnerable IPv6 hosts

Peek-a-boo ping

2019-03-21 10:42:00 UTC
Naked Security | Sophos
Naked Security | Sophos
FBI crackdown on DDoS-for-hire sites led to 85% slash in attack sizes

According to a new report, average and maximum DDoS attack sizes decreased by 85.36% and 23.91%.

Denial Of Service IoT Security Threats Booters China DDoS DDoS-for-hire FBI Lizard Squad NexusGuard US
2019-03-20 21:20:00 UTC
ThreatPost
ThreatPost
Mac-Focused Malvertising Campaign Abuses Google Firebase DBs

Researchers said 1 million user sessions could have been exposed to the campaign, which downloads the Shlayer trojan.

Malware Web Security Confiant Google Firebase Mac Malvertising Obfuscation Shlayer Trojan Steganography Verymal

BreachAware Insight

THE LATEST CURATED INTEL FROM OUR RESEARCH CENTRE
BreachAware Podcast

Listen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.

Amazon Music Apple Podcasts Spotify Podcast BreachAware YouTube Channel

Point of View

OUR TAKE ON TRENDING STORIES

Weekly Summary

SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
21 October 2024
BREACHAWARE HQ
Island Breach Exposure Monitoring