Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
https://threatpost.com/twitter-whistleblower-tldr-version/180472/
Researcher shows how Instagram and Facebook’s use of an in-app browser within both its iOS apps can track interactions with external websites.
Four newly discovered attack paths could lead to PII exposure, account takeover, even organizational data destruction.
A developer appears to have divulged credentials to a police database on a popular developer forum, leading to a breach and subsequent bid to sell 23 terabytes of personal data on the dark web.
Hackers with Amazon users’ authentication tokens could’ve stolen or encrypted personal photos and documents.
The company is warning victims in Italy and Kazakhstan that they have been targeted by the malware from Italian firm RCS Labs.
https://threatpost.com/google-hermit-spyware-android-ios/180062/
One well crafted phishing message sent via Facebook Messenger ensnared 10 million Facebook users and counting.
Attackers gained access to private account details through an email compromise incident that occurred in April.