Security News

How one attack campaign steals and sells RDP credentials
2020-08-17 17:08

Spotted by security firm Nuspire, one campaign that has resurfaced lately grabs RDP credentials or access and then sells them on underground forums. Active on several underground forums and communities, TrueFighter specializes in the sale of compromised RDP accounts through which buyers gain remote administrative access to the networks of affected organizations.

JumpCloud App for Windows: Enabling secure credential and identity management
2020-08-12 00:30

JumpCloud announced the release of the JumpCloud App for Windows, the latest update to its patent-pending strategy for enabling secure credential and identity management from an employee's device. The JumpCloud Windows App streamlines credential management workflows and establishes the employee's workstation or laptop as a trusted device.

How to find and fix vulnerable default credentials on your network
2020-07-30 15:27

Network appliances and devices that still have their default credentials present a risk to your organization, says SecurityHQ. Think of all the routers, switches, appliances, and other devices that may be available and accessible on your network. In its blog post entitled "Notes from the Field. Don't Default on Password Security," SecurityHQ described the trap of default credentials.

Phishing attacks hiding in Google Cloud to steal Microsoft account credentials
2020-07-21 13:08

By hosting phishing pages at a legitimate cloud service, cybercriminals try to avoid arousing suspicion, says Check Point Research. The idea is that such phishing pages will better elude detection by security products and more easily ensnare unsuspecting victims.

Credential stuffing attacks on global media companies are spiking
2020-07-16 14:55

Twenty percent of the 88 billion total credential stuffing attacks observed during the reporting period targeted media companies, Akamai said. Media companies are an attractive target for criminals and saw a 63% year-over-year increase in attacks against the video media sector, the report said.

20% of credential stuffing attacks target media companies
2020-07-16 04:00

The media industry suffered 17 billion credential stuffing attacks between January 2018 and December 2019, according to a report from Akamai. The report found that 20% of the 88 billion total credential stuffing attacks observed during the reporting period targeted media companies.

Over 5 Billion Unique Credentials Offered on Cybercrime Marketplaces
2020-07-08 18:16

More than 15 billion username and password pairs have been offered on cybercrime marketplaces, including over 5 billion unique credentials, according to a report published on Wednesday by San Francisco-based risk protection solutions provider Digital Shadows. Over the past few years, Digital Shadows added to its breach repository more than 15 billion credentials shared on criminal forums, paste sites, file sharing services, and code sharing websites.

Criminals auction off stolen domain admin credentials for up to £95k. Your bank account details? Barely get £50
2020-07-08 17:26

Stolen domain admin login credentials can be resold by dark web criminals for up to £95,000 and a total of 15 billion purloined credentials are traded on illicit marketplaces. "Rick Holland, CISO and strategy veep of Digital Shadows, mused:"The sheer number of credentials available is staggering and in just over the past 1.5 years, we've identified and alerted our customers to some 27 million [leaked] credentials which could directly affect them.... "Details exposed from one breach could be re-used to compromise accounts used elsewhere. The message is simple - consumers should use different passwords for every account and organizations should stay ahead of the criminals by tracking where the details of their employees and customers could be compromised."

Phishing attack spoofs Twitter to steal account credentials
2020-07-06 16:32

A new phishing campaign spotted by Abnormal Security attempts to trick people with a phony Twitter security notification. A new phishing campaign analyzed by the security provider Abnormal Security shows how the attackers are taking advantage of Twitter users to steal account credentials.

Android Apps Stealing Facebook Credentials
2020-06-30 15:15

Before being taken down, the 25 apps were collectively downloaded more than 2.34 million times. The malicious apps were developed by the same threat group and despite offering different features, under the hood, all the apps worked the same.