Hackers Attack Aviation Industry With AsyncRAT to Steal Login Credentials

Cisco Talos has detected and published a series of malicious campaigns recently along with many other security researchers that are continuously targeting the aviation industry.  This campaign is continuously targeting the aerospace and travel sectors along with spear-phishing emails that spread an actively exploited loader, and later it also delivers RevengeRAT or AsyncRAT. The threat […]

Hackers dump login credentials of Fortinet VPN users in plain-text

Fortinet VPN users are urged to reset their passwords as the company has acknowledged the data to be legitimate. Popular network security solutions provider, Fortinet, has confirmed that a cybercriminal gang managed to gain unauthorized access to VPN login IDs and passwords linked with 87,000 FortiGate SSL-VPN devices. Hackread.com can confirm the gang has dumped […]

Nameless malware stole 26m login credentials from 3.25m computers

The total amount of data collected by the malware includes nearly 26 million login credentials holding 1.1 million unique email addresses, 2 billion+ cookies and 6.6 million files. In recent news, a malware study performed by NordLocker, a subsidiary of NordVPN, along with a third-party company that specialises in data breach analysis, revealed that a […]

Fortinet VPN users need to reset their credentials. Massive Fortinet data leak

A hacking group exposed around 500,000 Fortinet VPN service usernames and passwords allegedly obtained from vulnerable devices via exploiting a dangerous vulnerability. Although the hackers mention that the flaw has already been addressed, they assure that many of the compromised credentials are still active. If you have Fortinet VPN, please go force reset all your […]

BigBasket security leak also impacted thousands of Flipkart users; access credentials exposed

Security incidents sometimes transcend affected organizations, reaching levels of impact that IT security teams cannot foresee. This is the case with the data breach in BigBasket, which resulted in the leaking of sensitive information belonging to Flipkart users nearly seven months after the initial incident. As some users will remember, BigBasket suffered a data breach […]

Experts warn of a new Android banking trojan stealing users’ credentials

Cybersecurity researchers on Monday disclosed a new Android trojan that hijacks users’ credentials and SMS messages to facilitate fraudulent activities against banks in Spain, Germany, Italy, Belgium, and the Netherlands. Called “TeaBot” (or Anatsa), the malware is said to be in its early stages of development, with malicious attacks targeting financial apps commencing in late […]

Git-Wild-Hunt – A Tool To Hunt For Credentials In Github Wild AKA Git*Hunt

  A tool to hunt for credentials in the GitHub wild AKA git*hunt Getting started Install the tool Configure your GitHub token Search for credentials See results cat results.json | jq Installation requirements: virtualenv, python3 git clone https://github.com/d1vious/git-wild-hunt && cd git-wild-hunt clone project and cd into the project dir pip install virtualenv && virtualenv -p […]

VMware vRealize Operations critical vulnerability allows hackers to steal credentials

VMware security teams announced the release of some security patches to fix a severe flaw in vRealize Operations whose exploit would allow threat actors to steal administrator credentials on vulnerable servers. It should be remembered that vRealize Operations is an IT operations management platform, powered by artificial intelligence for private, hybrid, and cloud environments. The […]

Over 500,000 Credentials of two Dozen Leading Gaming Firms Leaked Online

Tel Aviv-based threat intelligence firm Kela has warned gaming companies to improve their cybersecurity posture after discovering 500,000 breached employee credentials and a million compromised internal accounts on the dark web. With the rise of gamers and purchases, the online gaming industry is estimated to reach $196 billion in revenue by 2022. On the other hand, the […]

FTCODE Ransomware Attack Windows To Encrypt Files & Steals Stored Login Credentials From Browsers

Researchers discovered a new wave of FTCODE ransomware campaign that steal browsers login credentials and Encrypt files in Windows systems. FTCODE ransomware was first observed in 2013, it uses the Windows PowerShell program to perform file encryption. The ransomware resurfaced again starting from last year September, according to Certego analysis of the FTCODE ransomware, it […]

21 Million Stolen Fortune 500 Dark Web Purchase Credentials

Many studies and investigations have been conducted into the number of stolen credentials on the dark web. Nonetheless, a new report recently issued is a little different: it relies on credentials from international Fortune 500 companies and uses machine learning (ML) approaches to clean and validate the information gathered. The findings are more alarming than […]

21 million login credentials of Fortune 500 Companies found on dark web

The top 5 passwords used by the Technology industry among Fortune 500 Companies were “passw0rd,” and “abc123.” The dark web is one of those places that is either underestimated or highly exaggerated by many but when it comes to hackers and cybercriminals dark web marketplaces are a safe haven.  Recently, ImmuniWeb, an IT security company […]

Avast Hacked – Hackers Gained Network Access Via Avast Own VPN With Compromised Credentials

Leading Anti-Virus software maker Avast hacked by unknown cyber-espionage groups using compromised credentials and gained the internal network access over their own VPN in earlier March 2019. Avast is one of the well-known cybersecurity company that making various internet security software including Anti-virus, VPN, Endpoint Security, content filtering software for Microsoft Windows, macOS, Android, and iOS. Experts from Avast […]

RCE Vulnerability in D-Link Routers Let Hackers Access the Router Admin Page Without Credentials

Security researchers disclosed a new unauthenticated command injection vulnerability in some of the D-link routers. The vulnerability can be tracked as CVE-2019-16920 and rated as critical. Successful exploitation of the vulnerability results in Remote Code Execution, an attacker can trigger the vulnerability remotely to access the router login page without authentication. D-link Routers Affected The […]

Scotiabank source code and login credentials were hacked. Users should contact the bank to secure their money

A severe incident has been confirmed by IT system audit specialists. Scotiabank has mistakenly leaked some of its internal source code as well as confidential login credentials for its back-end systems. The bank’s security teams have spent the last twelve hours deleting repositories on GitHub that stored sensitive information, which were available to any user […]

Open-Source Spyware Spreading Via Google Play Store App to Send SMS, Steal Contacts, Files & Credentials

Researchers discovered an open-source spyware AhMyth associated with Google play store app called RB Music to intrude the Android users device to steal various sensitive information. RB Music also know as Radio Balouch, a malicious streaming radio based Android app appeared in Google play store borrowed malicious features and functionality from AhMyth to infect the Android users […]