HackDig : Dig high-quality web security articles for hackers

Ubiquiti breach, and other IoT security problems

Networking equipment manufacturer Ubiquiti sent out an email to warn users about a possible data breach. The email stated there had been unauthorized access to its IT systems that are hosted with a third-party cloud provider. Ubiquiti Networks sells networking devices and IoT devices. It did not specify which products were affected but pointed at UI.com,
Publish At:2021-01-12 16:00 | Read:178 | Comments:0 | Tags:IoT 2fa chastity belt IoT security passwords traffic lights

Get a head start on defending against tax scams

It may not be tax season in your part of the world right now but you’ll no doubt be pleased to know a prolific tax scammer is on their way to jail for 20 years. If you’re annoyed by tax scam missives, or had the misfortune to hand money over, this is probably satisfying news. Between 2013 and 2016, Hitesh Patel ran a particularly sophisticated operation.
Publish At:2020-12-08 17:30 | Read:143 | Comments:0 | Tags:Social engineering 2fa HMRC money laundering phish phishing

Spotify resets some user logins after hacker database found floating online

A team of researchers working for vpnMentor has found a treasure trove in the form of an unsecured Elasticsearch database containing over 380 million records. The trove contained login credentials and other data belonging to Spotify users. So what’s Spotify doing leaving its user data hanging around on an unsecured database? Answer: It’s not.
Publish At:2020-11-25 13:36 | Read:183 | Comments:0 | Tags:Reports 2fa credential stuffing database Elasticsearch mfa P

2FA bypass in cPanel potentially exposes tens of millions of websites to hack

2FA bypass discovered in web hosting software cPanel More than 70 million sites are managed via cPanel software, according to the company. Researchers discovered a major issue in cPanel that could be exploited by attackers to bypass two-factor authentication for cPanel accounts. Security researchers from Digital Defense have discovered a major secur
Publish At:2020-11-24 20:07 | Read:319 | Comments:0 | Tags:Breaking News Hacking 2FA hacking news information security

Scammers are spoofing bank phone numbers to rob victims

It can be a very convincing trick… “You can check the number in your display online sir. You’ll see I’m really calling from your bank.” That is, of course, if you are unaware that phone numbers can be spoofed. Then again, they wouldn’t be successful scammers if they weren’t convincing. If you suggest calling them back, they’ll tell you it’s
Publish At:2020-10-28 10:53 | Read:250 | Comments:0 | Tags:Social engineering 2fa caller id cold callers fake banksites

Brute force attacks increase due to more open RDP ports

While leaving your back door open while you are working from home may be something you do without giving it a second thought, having unnecessary ports open on your computer is a security risk that is sometimes underestimated. That’s because an open port can be subject to brute force attacks. What are brute force attacks? A brute force attack is w
Publish At:2020-10-20 11:47 | Read:428 | Comments:0 | Tags:Exploits and vulnerabilities Web threats 2fa attacks brute f

Rampant Kitten ‘s arsenal includes Android malware that bypasses 2FA

Security researchers discovered Android malware capable of bypassing 2FA that was developed by an Iran-linked group dubbed Rampant Kitten Security researchers from Check Point discovered an Android malware, developed by an Iran-linked group dubbed Rampant Kitten, that is able to bypass 2FA. Rampant Kitten has been active at least since 2014 and was inv
Publish At:2020-09-18 16:30 | Read:475 | Comments:0 | Tags:Breaking News Hacking Malware Mobile 2FA Android information

Great news, now you can protect your Zoom account with 2FA

Zoom has implemented two-factor authentication (2FA) to protect all user accounts against security breaches and other cyber attacks. Zoom has announced finally implemented the two-factor authentication (2FA) to protect all user accounts from unauthorized accesses. This is a great news due to the spike in the popularity of the communication software dur
Publish At:2020-09-11 11:00 | Read:434 | Comments:0 | Tags:Breaking News Security 2FA authentication Hacking Identity T

Report: Pandemic caused significant shift in buyer appetite in the dark web

Last year, credentials for PayPal, Facebook, and Airbnb were among the top goods on high demand in the dark web, aka the Internet’s underground market. But due to the COVID-19 outbreak, with most of the worldwide population sheltering, working, and studying indoors, many facets of life have made a full 180-degree turn—including the criminal world.
Publish At:2020-09-10 19:18 | Read:526 | Comments:0 | Tags:Cybercrime 2fa airbnb Cash App covid-19 Dark Web Dark Web Ma

US tax service says, “2FA is a must!”

byPaul DucklinThe Beatles famously sang about The Taxman back in 1966, when Britain had much higher taxes on the rich than it does now: Let me tell you how it will be There's one for you, nineteen for me 'Cause I'm the taxman, yeah, I'm the taxman Should five per cent appear too small Be thankful I don't take it all 'Cause I'm the tax
Publish At:2020-07-29 13:37 | Read:582 | Comments:0 | Tags:2-factor Authentication 2FA IRS refund fraud scams tax scams

Coordinated Twitter attack rakes in 100 grand

“I’m feeling generous because of Covid-19. I’ll double any BTC payment sent to my BTC address for the next hour. Good luck, and stay safe out there!” This and similar Tweets asking readers to send US$1,000 to a Bitcoin address with the promise of a double return payment went out yesterday. Too good to be true? Once again,
Publish At:2020-07-16 14:35 | Read:574 | Comments:0 | Tags:Social engineering 2fa bitcoin Social Engineering tweets twi

What to do when you receive an extortion email

In the last few weeks, there has been an upswing in people receiving threatening, extortion email messages, demanding payment to avoid release of sensitive information. Most of the time, these emails are what we call “sextortion” emails, as they claim that malware on your computer has captured embarrassing photos of you through the webcam, but th
Publish At:2020-05-03 14:39 | Read:1149 | Comments:0 | Tags:Malwarebytes news 2fa Bitcoin sextortion extortion online ex

Europol busts up two SIM-swapping hacking rings

byLisa VaasAfter months-long, cross-border investigations, Europol announced on Friday that it’s arrested more than two dozen people suspected of draining bank accounts by hijacking victims’ phone numbers via SIM-swap fraud.Following a ramp-up in SIM-jacking over recent months, police across Europe have been gearing up to dismantle criminal netwo
Publish At:2020-03-17 07:39 | Read:1281 | Comments:0 | Tags:2-factor Authentication Law & order Malware Security threats

99% of compromised Microsoft enterprise accounts lack MFA

byJohn E DunnCybercriminals compromise 0.5% of all Microsoft enterprise accounts every month because too few customers are using multi-factor authentication (MFA), the company has revealed.In a presentation uploaded to YouTube from the recent RSA Security Conference, director of Identity Security Alex Weinert said 1.2 million accounts were compromised in Jan
Publish At:2020-03-09 08:17 | Read:1021 | Comments:0 | Tags:2-factor Authentication Microsoft Privacy Security threats W

Boots yanks loyalty card payouts after 150K accounts get stuffed

byLisa VaasBoots, a UK pharmacy chain, has suspended payments on the loyalty cards of 14.4 million active customers after its security team spotted “unusual” activity on a number of Boots Advantage Card accounts.It wasn’t hacked, the company said in a statement, and this isn’t what you’d classify as a breach. Intruders didn’t get into
Publish At:2020-03-06 08:12 | Read:1083 | Comments:0 | Tags:2-factor Authentication Security threats 2FA Advantage Card

Tools

Tag Cloud