Security News

Joomla Login Page Flaw Exposes Admin Credentials
2017-09-21 11:38

Joomla 3.8 brings more than 300 improvements to the popular content management system (CMS) and patches two vulnerabilities, including one that can be exploited to obtain administrator...

Do CISOs Need IT or InfoSec Academic Credentials?
2017-09-19 11:18

In the latest edition of the ISMG Security Report: a look at the former Equifax chief information security officer and whether her lack of academic credentials in IT or IT security is relevant to...

Former Anthem Cybersecurity Exec on Protecting Credentials
2017-09-13 18:03

A former cybersecurity analytics specialist at health insurer Anthem, which experienced a massive data breach, offers insights on key steps organizations should take to avoid becoming the next...

Researchers Devise Hopeful Defense Against Credential Spear Phishing Attacks (Security Week)
2017-09-05 12:07

Security Researchers Have Proposed a New and Effective Way to Detect Credential Spearphishing Attacks in the Enterprise read more

Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials (Threatpost)
2017-08-30 16:10

Researchers accessed the Onliner spambot and found 711 million records, including email addresses, email and password combinations, and SMTP credentials and configuration files.

IoT Device Hit by Credential Attack Every Two Minutes: Experiment (Security Week)
2017-08-29 17:19

Internet of Things (IoT) botnets such as Mirai might not be in the headlines as often as they were several months ago, but the threat posed by insecure IoT devices is as high as before, a recent...

Telnet Credential Leak Reinforces Bleak State of IoT Security (Threatpost)
2017-08-29 15:22

The disclosure and recent analysis of thousands of leaked telnet credentials paints a bleak picture of the state of IoT security.

Thousands of IoT Devices Impacted by Published Credentials List (Security Week)
2017-08-28 15:52

Over 1,700 Internet of Things (IoT) devices worldwide are potentially exposed to hackers after a list containing their IPs and default login credentials emerged on Pastebin.com. read more

Race is On To Notify Owners After Public List of IoT Device Credentials Published (Threatpost)
2017-08-26 12:20

A list of device IPs and credentials has gone viral since Thursday, kicking off an effort by researchers to notify the owners of these connected devices before they're hacked.

Business Email Compromise Campaign Harvesting Credentials in Numerous Industries (Threatpost)
2017-08-23 17:02

Flashpoint warns of a new business email compromise campaign targeting organizations in various industries with the aim of harvesting credentials.