Security News

Race is On To Notify Owners After Public List of IoT Device Credentials Published (Threatpost)
2017-08-26 12:20

A list of device IPs and credentials has gone viral since Thursday, kicking off an effort by researchers to notify the owners of these connected devices before they're hacked.

Business Email Compromise Campaign Harvesting Credentials in Numerous Industries (Threatpost)
2017-08-23 17:02

Flashpoint warns of a new business email compromise campaign targeting organizations in various industries with the aim of harvesting credentials.

Facebook Awards $100K to Researchers for Credential Spearphishing Detection Method (Threatpost)
2017-08-21 18:28

Researchers who identified a real-time way to detect credential spearphishing attacks in enterprise settings won $100,000 from Facebook last week.

Patched Flash Player Sandbox Escape Leaked Windows Credentials (Threatpost)
2017-08-10 19:00

One of yesterday's Flash Player patches was a do-over after the researcher who privately reported the problem earlier this year discovered the original patch incompletely resolved the issue.

Attackers Use Typo-Squatting To Steal npm Credentials (Threatpost)
2017-08-04 21:24

Criminals used a typo-squatting technique and uploaded rogue JavaScript libraries to a popular code repository npm.

Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks (Threatpost)
2017-07-11 17:43

Microsoft today addressed two NTLM-related vulnerabilities privately disclosed by Preempt Security. The flaws allow for credential relay attacks.

CIA Tools for Stealing SSH Credentials Exposed by WikiLeaks (Security Week)
2017-07-07 09:17

WikiLeaks has published documents detailing BothanSpy and Gyrfalcon, tools allegedly used by the U.S. Central Intelligence Agency (CIA) to steal SSH credentials from Windows and Linux systems. read more

NotPetya Operators Accessed M.E.Doc Server Using Stolen Credentials: Cisco (Security Week)
2017-07-06 15:43

The group behind last week’s destructive NotPetya attack was able to access M.E.Doc’s update server and use it for their nefarious purposes courtesy of stolen credentials, Cisco has discovered. read more

Sabre Says Stolen Credentials Led to Breach (InfoRiskToday)
2017-07-06 13:33

Travel Giant Declined to Release Number of VictimsTravel industry giant Sabre said Wednesday an intruder using stolen account credentials for its widely used reservations software had access to...

Wikileaks Unveils CIA Implants that Steal SSH Credentials from Windows & Linux PCs (The Hackers News)
2017-07-06 11:41

WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell)...