Reddit reveals breach as attacker circumvents staff’s 2FA

The company has learned the hard way that there are better ways to deliver two-factor authentication than via text messages. Reddit has announced that a hacker has broken into some of its systems and accessed some user data, including an old database backup copy containing user credentials, email addresses, and messages. Additionally, the breach affected … More Reddit reveals breach as attacker circumvents staff’s 2FA

Inmates hack prison tablets for free credits

The nature of the vulnerability hasn’t been disclosed, but is said to have already been identified and fixed. Several hundred inmates at five prisons in the northwestern US state of Idaho have exploited a software vulnerability in their “prison-specific” tablets to transfer $225,000 worth of digital credits to their virtual accounts, according to a BBC report. … More Inmates hack prison tablets for free credits

Fake banking apps on Google Play leak stolen credit card data

Fraudsters are using bogus apps to convince users of three Indian banks to divulge their personal data. Another set of fake banking apps has found its way into the official Google Play store. Claiming to increase the credit card limit for users of three Indian banks, the malicious apps phish for credit card details and … More Fake banking apps on Google Play leak stolen credit card data

Hook, line, and sinker: How to avoid looking ‘phish-y’

Top tips to help you avoid being caught receiving or sending phishing-looking emails. If you’re a regular reader of this blog, I suspect you live in a state of perpetual vigilance against targeted attacks such as phishing messages. You know that urgent sounding messages from sender addresses that don’t look right, especially if they include … More Hook, line, and sinker: How to avoid looking ‘phish-y’