Security News

LastPass Patches Bug Leaking Last-Used Credentials
2019-09-16 14:40

A vulnerability recently addressed in LastPass could be abused by attackers to expose the last site credentials filled by LastPass. A freemium password manager, LastPass stores encrypted passwords...

For Sale: Admin Access Credentials to Healthcare Systems
2019-09-13 19:18

Cybercriminals are "upping their game" by stealing and then auctioning off on the dark web administrative access credentials to healthcare organizations' clinician and patient portals, says Etay...

Credential Leaking Vulnerabilities Impact Comba, D-Link Routers
2019-09-12 08:33

Trustwave security researchers have discovered five new credential leaking vulnerabilities, two in a D-Link DSL modem and three in multiple Comba Telecom WiFi devices. read more

Vulnerabilities in D-Link, Comba Routers Can Leak Credentials
2019-09-10 12:00

Flaws can potentially affect every device and user on the network by directing them to malicious websites or blocking their access to important data or resources.

Zyxel Devices Can Be Hacked via DNS Requests, Hardcoded Credentials
2019-09-03 18:16

Multiple security vulnerabilities have been discovered by SEC Consult in various Zyxel devices, including flaws that involve sending unauthenticated DNS requests and hardcoded FTP credentials. read more

A ransomware revival leads to 2.2 billion stolen credentials on the dark web in Q1
2019-08-28 13:12

In a new report, McAfee Labs said cybercriminals were focusing in on attacking weak IoT devices and extracting huge troves of data from large companies.

Backdoored Ruby gems stole credentials, injected cryptomining code
2019-08-21 11:52

The compromise of several older versions of a popular Ruby software package (aka a Ruby “gem”) has led to the discovery of a more widespread effort to inject malware and mining software through...

Credential Stuffing Attacks vs. Brute Force Attacks
2019-08-19 16:33

What They Are and How to Handle ThemTo explore how credential stuffing attacks and brute force attacks differ, we need to understand what they are and how they operate. Here is a quick summary.

A New Credential for Healthcare Security Leaders
2019-08-12 19:03

A new professional credential aims to help healthcare organizations bolster their security leadership bench strength, says William Brad Marsh, co-chair of a committee that developed the certification.

State Farm Falls Victim to Credential-Stuffing Attack
2019-08-08 21:03

The insurance giant serves at least 83 million U.S. households.