RCE Vulnerability in D-Link Routers Let Hackers Access the Router Admin Page Without Credentials

Security researchers disclosed a new unauthenticated command injection vulnerability in some of the D-link routers. The vulnerability can be tracked as CVE-2019-16920 and rated as critical. Successful exploitation of the vulnerability results in Remote Code Execution, an attacker can trigger the vulnerability remotely to access the router login page without authentication. D-link Routers Affected The […]

Scotiabank source code and login credentials were hacked. Users should contact the bank to secure their money

A severe incident has been confirmed by IT system audit specialists. Scotiabank has mistakenly leaked some of its internal source code as well as confidential login credentials for its back-end systems. The bank’s security teams have spent the last twelve hours deleting repositories on GitHub that stored sensitive information, which were available to any user […]

Open-Source Spyware Spreading Via Google Play Store App to Send SMS, Steal Contacts, Files & Credentials

Researchers discovered an open-source spyware AhMyth associated with Google play store app called RB Music to intrude the Android users device to steal various sensitive information. RB Music also know as Radio Balouch, a malicious streaming radio based Android app appeared in Google play store borrowed malicious features and functionality from AhMyth to infect the Android users […]

Fileless Trojan “Astaroth” That Steals Credentials Is Back, Warns Microsoft

In a recent blog post, the Microsoft Defender ATP research team issued a warning about a harmful file-less malware campaign called Astaroth. The team got alert when they noticed a sudden huge spike in the usage of the WMIC (Windows Management Instrumentation Command-Line) tool during the month of May and June 2019. They had deployed […]

TA505 APT Hackers Launching New Malware Tools via MS Office Docs to Steal Emails & SMTP Credentials

Threat actors from TA5O5 APT groups distribute malicious spam email campaigns with a new set of malware tools via attached malicious word and excel documents. TA505 hacking group believed to reside in Russia and the threat actors from this group involved in various high profile cyber attacks including infamous Dridex, Locky ransomware, ServHelper malware, FlawedAmmyy, […]

50,000 times Downloaded Android Horror Game from GooglePlay Steals Google and Facebook Login Credentials

Android Horror game uses malicious scripts to steal the user’s login credentials and uses ad networks to drive more traffic and cause damage to the affected device. Wandera’s threat research team identified the malicious app on the Google Play Store. The app fools the Google Play Store’s rigorous security checks, “by using time-released malicious behavior, […]

Popular Android Zombie game phish users to steal Gmail credentials

The app made its way to Google Play Store was also found phishing users for Facebook credentials. Scary Granny ZOMBY Mod: The Horror Game 2019 is the latest game on Google Play Store that is condemned by the digital security fraternity for sneakily stealing personal data from unsuspecting users. The game, which has been downloaded […]

Chinese APT 10 Group Hacked Nearly 10 Telecom Networks and Stealing Users Call Records, PII, Credentials, Email Data and more

Infamous Chinese APT 10 hackers compromised over 10 Telecom networks around the world under the campaign called Operation Soft Cell and stealing various sensitive data including call records, PII, and attempting to steal all data stored in the active directory. APT 10 Threat actors known as one of the sophisticated hacking group in the world and […]

Seth – Perform a MitM Attack and Extract clear text Credentials from RDP

Seth is a tool written in Python and Bash to MitM RDP connections by attempting to downgrade the connection in order to extract clear text credentials. It was developed to raise awareness and educate about the importance of properly configured RDP connections in the context of pentests, workshops or talks. The author is Adrian Vollmer […]

GetCrypt Ransomware Encrypts Files, Brute Forces Credentials

Here’s a new ransomware that not only encrypts files and programs on a computer, but attempts to brute force credentials as well. GetCrypt, a new ransomware that’s being installed through malvertising campaigns and which redirects victims to the RIG exploit kit, encrypts all files on a computer and then demands ransom for decrypting the files. […]

Criminals Hack Forum Used for Trading Stolen Credentials

This is really interesting- a popular online forum that hackers have been using to trade stolen credentials has been hacked! Reports confirm that OGusers, a popular online form used by hackers to trade stolen account credentials, has been hacked and that this had caused sensitive personal data of many users to be exposed. Brian Krebs […]

Qakbot Malware to Steal Login Credentials & Wipe Bank Accounts

A new wave of Qakbot or Qbot banking malware campaign utilizes the advanced persistent mechanism to steal credentials and draining their bank accounts. Qbot mainly targeting the businesses with sophisticated evasion technique to remain undetected and make it harder for users to detect and remove the malware. In order to perform this evasion process and […]

Hackers steal Microsoft Outlook login credentials to steal Bitcoin

Cyber forensics course specialists report that a group of hackers have infiltrated some email accounts from Outlook users to steal several virtual assets, including Bitcoin. The total stolen amount is still unknown, although it is speculated that it could be a considerable sum. One of the victims, a Dutch engineer, claims that a threat actor […]

Juniper switch vulnerability exposes login credentials

According to cyber forensics course specialists from the International Institute of Cyber Security (IICS), Juniper Networks has launched an unexpected update after discovering that some login credentials had been left on their data centers switches. Juniper Networks is a multinational company dedicated to network and security systems and is considered the main competence of Cisco. […]

New Android Malware “BasBanke” Steal Financial Data Such as Credentials & Credit/Debit Card Numbers

Researchers discovered a new Android Malware called “BasBanke” targeting Brazilian users to steals financial related sensitive data such as credentials and credit/debit card numbers. BasBanke Malware continuously infects users since 2018 Brazilian elections using various malicious apps that downloaded over 10,000 times from Google Play Store till the date. Malware authors abusing Facebook and WhatsApp […]

Hackers using Malware that Steal Premium Users Credentials from Pornhub, XVideos to sell it in Dark Web

New Threat report revealed that Credential stealing malware were dramatically increased in 2018 that target the adult websites premium users credentials to selling it in dark web. These credentials are most wanted data in underground market place in Dark web where cybercriminals selling these stolen data for thousands. It very common that pornography website is […]

Another Aadhaar Breach: Aadhaar Operator’s Credentials Stolen And Misused

It seems like India’s unique identity number Aadhaar has become habitual of occasional security lapses as another security breach case is raising more questions regarding the security of users’ data. According to a report by HuffPost India, an Aadhaar operator named Vikram Sheokhand has fallen prey to unauthorized access of his biometrics which has been misused several times. Vikram is […]

Hackers Launching Trickbot Malware That Steals VNC, PuTTY and RDP Credentials

The new variant of infamous trickbot malware comes with the capability of grabbing remote application login credentials. Trickbot is a banking malware which steals login credentials from applications, it was discovered long back ago, the threat actors continiously adding new capabilities to the malware. Security researchers from TrendMicro observed the bew variant that bagged with […]