I’ve Just Added 2,844 New Data Breaches With 80M Records To Have I Been Pwned

Presently sponsored by: DigiCert: IoT security can be filled with overwhelming identity challenges. One simple change can help you address nearly every one of them.

tl;dr – a collection of nearly 3k alleged data breaches has appeared with a bunch of data already proven legitimate from previous incidents, but also tens of millions of addresses that haven’t been seen in HIBP before. Those 80M records are now searchable, read on for the full story:…

Continue reading I’ve Just Added 2,844 New Data Breaches With 80M Records To Have I Been Pwned

I’ve Just Launched “Pwned Passwords” V2 With Half a Billion Passwords for Download

Presently sponsored by: Build scalable, reliable and secure cloud native applications with Tech Fabric

Last August, I launched a little feature within Have I Been Pwned (HIBP) I called Pwned Passwords. This was a list of 320 million passwords from a range of different data breaches which organisations could use to better protect their own systems. How? NIST explains:

When processing requests to establish

Continue reading I’ve Just Launched “Pwned Passwords” V2 With Half a Billion Passwords for Download

Streamlining Data Breach Disclosures: A Step-by-Step Process

Presently sponsored by: Build scalable, reliable and secure cloud native applications with Tech Fabric

I don’t know how many data breaches I’m sitting on that I’m yet to process. 100? 200? It’s hard to tell because often I’m sent collections of multiple incidents in a single archive, often there’s junk in there and often there’s redundancy across those collections. All I really know is…

Continue reading Streamlining Data Breach Disclosures: A Step-by-Step Process

Do Something Awesome with Have I Been Pwned and Win a Lenovo ThinkPad!

Presently sponsored by: Get a security solution that will keep your website up and running—and keep you sleeping soundly: Symantec Website Security. Learn how

Friends who follow what I’m up to these days will see that I’m often away from home in far-flung parts of the world. What that means is a lot of time on planes, a lot of time in airports (which is where I’m writing this now) and a lot of…

Continue reading Do Something Awesome with Have I Been Pwned and Win a Lenovo ThinkPad!

The Ethics of Running a Data Breach Search Service

Presently sponsored by: Get a security solution that will keep your website up and running—and keep you sleeping soundly: Symantec Website Security. Learn how

No matter how much anyone tries to sugar coat it, a service like Have I been pwned (HIBP) which deals with billions of records hacked out of other peoples’ systems is always going to sit in a grey area. There are degrees, of course; at one end of the spectrum…

Continue reading The Ethics of Running a Data Breach Search Service

711 million email addresses found in popular banking malware’s spambot

A trove of 711 million email accounts used by a colossal spam operation was found by a Parisian security researcher this week. The collection, hosted on a publicly accessible server in the Netherlands, includes email addresses, corresponding passwords and servers engineered to help the spam avoid inbox filters. Uncovered by a pseudonymous researcher named Benkow moʞuƎq and reported by blogger and developer Troy Hunt, the spambot known as “Onliner” marks the largest-ever data set loaded into haveibeenpwned.com, a popular breach notification service operated by Hunt. Onliner delivers Ursnif banking malware, ZDNet reported, which is responsible in more than 100,000 global infections. Ursnif is infamous years-old data-stealing malware that has been updated continuously. It’s an evolving threat that can move through numerous attack vectors. In a 2017 report, Palo Alto Networks researchers said “newer versions of the threat allow attackers to steal browsing data such as banking and credit card information, acquire passwords via screenshots and keylogging, […]

The post 711 million email addresses found in popular banking malware’s spambot appeared first on Cyberscoop.

Continue reading 711 million email addresses found in popular banking malware’s spambot