Tuesday, 29 January 2019

Video platform Dailymotion takes steps to contain credential stuffing attack

Attackers have launched an ongoing credential stuffing campaign against the online video streaming service Dailymotion, compromising the data of an unspecified number of users in the process.

A property of French media and entertainment company Vivendi SA, Paris-based Dailymotion said in a Jan. 25 press alert that its technical teams “successfully contained” the attack “following the implementation of measures to limit its scope.” Potentially impacted users have already been contacted, as has as the CNIL, a French federal agency responsible for overseeing data protection regulations.

In a credential stuffing attack, malicious actors attempt to gain access to online websites or accounts using passwords that were previously stolen from or leaked by unrelated web services. This technique often works because many users tend to register for services with the same credentials over and over.

Video platform Dailymotion takes steps to contain credential stuffing attack

Saturday, 19 January 2019

Unprotected Government Server Exposes Years of FBI Investigations

A massive government data belonging to the Oklahoma Department of Securities (ODS) was left unsecured on a storage server for at least a week, exposing a whopping 3 terabytes of data containing millions of sensitive files.

The unsecured storage server, discovered by Greg Pollock, a researcher with cybersecurity firm UpGuard, also contained decades worth of confidential case files from the Oklahoma Securities Commission and many sensitive FBI investigations—all wide open and accessible to anyone without any password.

Other severe files exposed included emails, social security numbers, names, and addresses of 10,000 brokers, credentials for remote access to ODS workstations, and communications meant for the Oklahoma Securities Commission, along with a list of identifiable information related to AIDS patients.

Unprotected Government Server Exposes Years of FBI Investigations

Sunday, 13 January 2019

Does WhatsApp Has A Privacy Bug That Could Expose Your Messages?

In-short conclusion—Whatsapp service or its 45-days deletion policy doesn't seem to have a bug. For detailed logical explanation, please read below.

An Amazon employee earlier today tweeted details about an incident that many suggests could be a sign of a huge privacy bug in the most popular end-to-end encrypted Whatsapp messaging app that could expose some of your secret messages under certain circumstances.

According to Abby Fuller, she found some mysterious messages on WhatsApp, notably not associated with her contacts, immediately after she created a new account with the messaging app on her brand new phone using a new number for the very first time.

Does WhatsApp Has A Privacy Bug That Could Expose Your Messages?

Sunday, 23 December 2018

4 ways to spot a phishing scam

We’ve all received the classic email from a “foreign investor” promising to transfer millions of dollars into our bank account.

These fraudulent attempts to obtain sensitive information – known as phishing scams – are getting more sophisticated.

Athena Turner, brand manager at Hetzner, told MyBroadband that there are several key steps users must take to avoid becoming a victim to a scam and sharing their personal or account details.

https://mybroadband.co.za/news/security/287230-4-ways-to-spot-a-phishing-scam.html?utm_source=dlvr.it&utm_medium=twitter

Sunday, 2 December 2018

Marriott Hotel Data Breach: Ongoing Since 2014

Marriott said that a massive data breach of its guest reservation system has left up to 500 million guests’ data exposed and available for the taking. Worse, the attackers may have had access to the systems for at least four years before being discovered.

The hotel company said in a statement on its website that hackers gained access to the Starwood reservation database. Starwood, which includes hotels like St. Regis and Sheraton, was bought by Marriott in 2016.

Sunday, 18 November 2018

Instagram flaw exposes user passwords

A security flaw in Instagram’s recently released “Download Your Data” tool could have exposed some user passwords, the company reportedly told users.

The tool, revealed by Instagram right before the GDPR regulation went into effect, is designed to let users see and download the personal data that the social media platform had collected on them.

 A company spokesperson told The Information that the flaw only affected “small number” of users.

“Regardless of the number of individuals affected, this event raises major concerns about the way that Instagram is handling its users’ data,” said Bitglass CMO Rich Campagna. “In light of the fact that Facebook owns Instagram and has been experiencing a number of security debacles of its own, it should come as little surprise that Instagram is now exhibiting similar issues.

Saturday, 3 November 2018

Accused CIA Leaker Faces New Charges of Leaking Information From Prison

Joshua Adam Schulte, a 30-year-old former CIA computer programmer who was indicted over four months ago for masterminding the largest leak of classified information in the agency's history, has now been issued three new charges.

The news comes just hours after Schulte wrote a letter to the federal judge presiding over his case, accusing officials at Manhattan Metropolitan Correctional Center of interfering with his case pleading and subjecting him to "cruel and unusual punishment" in pre-trial detention.

"The shit-filled showers where you leave dirtier than when you entered; the flooding of the tiers and cages with ice-cold water; the constant blast of cold air as we are exposed to extreme cold without blankets or long-sleeve shirts; the uncontrollable lights that are always on as we are sleep deprived...No human being should ever have to experience this torture," Schulte wrote.

Accused CIA Leaker Faces New Charges of Leaking Information From Prison

Cyber Security in the Context of International Security

 Cyber security is everyone’s responsibility. What are the current trends in threats, risks, and vulnerabilities? How do threat actors explo...