Author: admin

IndependentKrebs

Hacked Password Service Leakbase Goes Dark

Credit to Author: BrianKrebs| Date: Mon, 04 Dec 2017 05:39:53 +0000

Leakbase, a Web site that indexed and sold access to billions of usernames and passwords stolen in some of the world largest data breaches, has closed up shop. A source close to the matter says the service was taken down in a law enforcement sting that may be tied to the Dutch police raid of the Hansa dark web market earlier this year.

Read More
FortinetSecurity

PowerDNS Recursor HTML/Script Injection Vulnerability – A Walkthrough

Credit to Author: Chris Navarrete| Date: Sat, 02 Dec 2017 15:50:59 +0000

PowerDNS Recursor is a high-end, high-performance resolving name server that powers the DNS resolution of at least a hundred million subscribers. The “Recursor” is one of two name server products whose primary goal is to act as resolving DNS server. On Aug. 7, 2017, I reported an XSS (cross-site scripting) vulnerability to PowerDNS and its Security Team. They assigned it the identifier CVE-2017-15092. In this report I will explain how I was able to identify and trigger the vulnerability.

Read More
ComputerWorldIndependent

When the threats get weird, the security solutions get weirder

Credit to Author: Mike Elgan| Date: Sat, 02 Dec 2017 02:00:00 -0800

The world of security is getting super weird. And the solutions may be even weirder than the threats.

I told you last week that some of the biggest companies in technology have been caught deliberately introducing potential vulnerabilities into mobile operating systems and making no effort to inform users.

One of those was introduced into Android by Google. In that case, Android had been caught transmitting location data that didn’t require the GPS system in a phone, or even an installed SIM card. Google claimed that it never stored or used the data, and it later ended the practice.

To read this article in full, please click here

Read More
IndependentKrebs

Carding Kingpin Sentenced Again. Yahoo Hacker Pleads Guilty

Credit to Author: BrianKrebs| Date: Sat, 02 Dec 2017 01:15:15 +0000

Roman Seleznev, a Russian man who is already serving a record 27-year sentence in the United States for cybercrime charges, was handed a 14-year sentence this week by a federal judge in Atlanta for his role in a credit card and identity theft conspiracy that prosecutors say netted more than $50 million. Separately, a Canadian national has pleaded guilty to charges of helping to steal more than a billion user account credentials from Yahoo.

Read More