Security News

FTCODE Ransomware Now Steals Chrome, Firefox Credentials
2020-01-21 15:02

New versions of the ransomware now sniff out saved credentials for Internet Explorer, Mozilla Firefox, Mozilla Thunderbird, Google Chrome and Microsoft Outlook. FTCODE, a PowerShell-based ransomware that targets Italian-language users, has added new capabilities, including the ability to swipe saved web browser and email client credentials from victims.

Hacker Leaks More Than 500K Telnet Credentials for IoT Devices
2020-01-21 11:57

Bad actor obtained passwords for servers, home routers, and smart devices by scanning internet for devices open to the Telnet port. A hacker has published a list of credentials for more than 515,000 servers, home routers and other Internet of Things devices online on a popular hacking forum in what's being touted as the biggest leak of Telnet passwords to date, according to a published report.

FBI seizes credentials-for-sale site WeLeakInfo.com
2020-01-20 12:21

The FBI has seized the domain for WeLeakInfo.com, a site that sold breached data records, after a multinational effort by law enforcement. The FBI and the District of Columbia explained that the site had harvested over 12 billion records from over 10,000 data breaches, including names, email addresses, usernames, phone numbers, and passwords.

Facebook users will be notified when their credentials are used for third-party app logins
2020-01-16 12:28

Facebook will explicitly tell users who use Facebook Login to log into third-party apps what information those apps are harvesting from their FB account. At the same time, users will be able to react quickly if someone managed to compromise their Facebook accounts and is using their credentials to access other apps and websites.

SSH and Digital Information Technologies help enterprises mitigate risks of privileged credential abuse
2020-01-10 00:30

SSH Communications Security, one of the world's most trusted security brands, has formed a partnership with Digital Information Technologies, an independent systems integration company operating in Japan since 1982. Adoption of multi-cloud and hybrid services creates a lot of complexity for companies and their IT admins who need to constantly onboard and offboard privileged users, such as developers and IT consultants.

Credential Harvesting Campaign Targets Government Procurement Services
2019-12-13 18:19

A credential harvesting campaign has been targeting multiple government procurement services in the United States and abroad, Anomali reveals.  read more

Google Chrome will check for leaked credentials every time you sign in anywhere
2019-12-11 13:30

Double-encrypted. That said, if you're worried about over-sharing, what are you doing on Chrome? A new feature in Google's Chrome browser will warn you if your username and password matches a...

Google Chrome will check for breached credentials every time you sign in anywhere
2019-12-11 13:30

Double-encrypted. That said, if you're worried about over-sharing, what are you doing on Chrome? A new feature in Google's Chrome browser will warn you if your username and password matches a...

Hardware-based Password Managers Store Credentials in Plaintext
2019-12-09 18:58

A security researcher has analyzed three hardware-based password vaults and discovered that credentials are stored in plaintext and survive hardware resets.  read more

Cloud Security Alliance launches credentials for auditing cloud computing systems
2019-12-06 04:15

The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, announced the...