Skip to main content

Security

Passwords for Tens of Thousands of Dahua Devices Cached in IoT Search Engine

posted onJuly 16, 2018
by l33tdawg

Login passwords for tens of thousands of Dahua devices have been cached inside search results returned by ZoomEye, a search engine for discovering Internet-connected devices (also called an IoT search engine).

Discovered by Ankit Anubhav, Principal Researcher at NewSky Security, a cyber-security company specialized in IoT security, these passwords are for Dahua DVRs running very old firmware that is vulnerable to a five-year-old vulnerability.

Vengeful hacker exposes DomainFactory customer banking data and passwords

posted onJuly 10, 2018
by l33tdawg

A German web-hosting firm has suffered a severe data breach because one of its customers reportedly owed money to the attacker. The company only learned of the breach when the hacker announced it himself, on its support forum.

On Jan. 29, the attacker compromised customer names, company names, various addresses, telephone numbers, DomainFactory passwords, dates of birth, bank names and account numbers, and Schufa scores (German credit score).

Hacker Group Behind Ticketmaster Breach Identified

posted onJuly 10, 2018
by l33tdawg

Cybersecurity analysts RiskIQ have identified the hacker group Magecart as the origin of the skimmer code placed on Ticketmaster websites, and suggested the number impacted by their theft of payment details is likely significantly worse than first thought.

Ticketmaster is a subsidiary of Live Nation, the world’s largest entertainment ticketing sales and marketing company. Last month we reported how potentially millions of Ticketmaster customers’ payment details had been accessed by a hacker group.

Hacker Steals Customers' Text Messages from Android Spyware Company

posted onJuly 9, 2018
by l33tdawg

 It just keeps happening. A hacker has targeted a company selling Android spyware marketed to monitor children, employees, and previously romantic partners.

This data breach is the latest in an ever increasing list of vigilante hackers focusing on the consumer spyware industry, some parts of which have been linked to illegal stalking and spying by abusive partners.

Timehop Breach Impacts Personal Data of 21 Million Users

posted onJuly 9, 2018
by l33tdawg

The personal data of millions of Timehop customers has been compromised after a hacker gained access to its cloud-based backend computing environment.

Timehop, a service that plugs into users’ social media platforms and shows them memories from the past, disclosed the data breach on Sunday.  The company said that last week on July 4, a data breach resulted in hackers swiping the names, email addresses and phone numbers of millions of customers. The hackers also stole social media “access tokens,” provided to Timehop by social media services, for up to 21 million customers.

The Worst Cybersecurity Breaches of 2018 So Far

posted onJuly 9, 2018
by l33tdawg

Looking back at the first six months of 2018, there haven't been as many government leaks and global ransomware attacks as there were by this time last year, but that's pretty much where the good news ends. Corporate security isn't getting better fast enough, critical infrastructure security hangs in the balance, and state-backed hackers from around the world are getting bolder and more sophisticated.

Here are the big digital security dramas that have played out so far this year—and it's only half over.

Cellebrite's newest target: Your IoT-filled home

posted onJuly 9, 2018
by l33tdawg

Smart home devices are quickly proliferating across the the world. Millions of new devices are coming online every year, be it through an Echo or Nest or anything in between.

Each one of these devices in the ever-expanding internet of things produces huge troves of data. That information is increasingly becoming a focal point for Cellebrite, the wildly profitable Israeli firm most famous for its cracking open encrypted iPhones on behalf of law enforcement and intelligence agencies.