Security News

Spambot Contains ‘Mind-Boggling’ Amount of Email, SMTP Credentials (Threatpost)
2017-08-30 16:10

Researchers accessed the Onliner spambot and found 711 million records, including email addresses, email and password combinations, and SMTP credentials and configuration files.

IoT Device Hit by Credential Attack Every Two Minutes: Experiment (Security Week)
2017-08-29 17:19

Internet of Things (IoT) botnets such as Mirai might not be in the headlines as often as they were several months ago, but the threat posed by insecure IoT devices is as high as before, a recent...

Telnet Credential Leak Reinforces Bleak State of IoT Security (Threatpost)
2017-08-29 15:22

The disclosure and recent analysis of thousands of leaked telnet credentials paints a bleak picture of the state of IoT security.

Thousands of IoT Devices Impacted by Published Credentials List (Security Week)
2017-08-28 15:52

Over 1,700 Internet of Things (IoT) devices worldwide are potentially exposed to hackers after a list containing their IPs and default login credentials emerged on Pastebin.com. read more

Race is On To Notify Owners After Public List of IoT Device Credentials Published (Threatpost)
2017-08-26 12:20

A list of device IPs and credentials has gone viral since Thursday, kicking off an effort by researchers to notify the owners of these connected devices before they're hacked.

Business Email Compromise Campaign Harvesting Credentials in Numerous Industries (Threatpost)
2017-08-23 17:02

Flashpoint warns of a new business email compromise campaign targeting organizations in various industries with the aim of harvesting credentials.

Facebook Awards $100K to Researchers for Credential Spearphishing Detection Method (Threatpost)
2017-08-21 18:28

Researchers who identified a real-time way to detect credential spearphishing attacks in enterprise settings won $100,000 from Facebook last week.

Patched Flash Player Sandbox Escape Leaked Windows Credentials (Threatpost)
2017-08-10 19:00

One of yesterday's Flash Player patches was a do-over after the researcher who privately reported the problem earlier this year discovered the original patch incompletely resolved the issue.

Attackers Use Typo-Squatting To Steal npm Credentials (Threatpost)
2017-08-04 21:24

Criminals used a typo-squatting technique and uploaded rogue JavaScript libraries to a popular code repository npm.

Microsoft Addresses NTLM Bugs That Facilitate Credential Relay Attacks (Threatpost)
2017-07-11 17:43

Microsoft today addressed two NTLM-related vulnerabilities privately disclosed by Preempt Security. The flaws allow for credential relay attacks.