Researchers have discovered attackers can take advantage of Webex Meetings API calls to enumerate Webex meeting numbers. Attackers can also launch similar "enumeration attacks" against Zoom platform for ongoing or future meetings .
LastPass released a new security update that fixes a vulnerability that exposes credentials from a previously visited website. The new version 4.33.0 was released on September 12.
Slack has reset passwords for close to 1% of overall Slack accounts in response to new information learned from 2015 security breach.
The Director of the Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about recent Iranian cybersecurity threats. The statement also included suggested tips and best practices to stay safe online.
A China-based cyber campaign dubbed "Nansh0u" has targeted tens of thousands of unsecured Windows MS-SQL and PHPMyAdmin servers worldwide.
News aggregator Flipboard warned that an unauthorized person gained access to subset of user account data and cryptographically protected passwords.
Facebook provided an update to a previously disclosed incident involving insecurely storing "tens of thousands" of Instagram users' passwords on internal servers in clear text. Facebook now says that "millions" of Instagram accounts are now impacted.
Cisco's Talos security team has observed ongoing malware distribution campaigns that use a new version of a keylogger and password stealer "HawkEye Reborn v9."
A newly discovered botnet dubbed Xwo has been scanning the internet for exposed web services and default passwords. The malware was discovered by AT&T's Alien Labs back in March and is related to malware families MongoLock and Xbash.
Mozilla has released Firefox 66 that includes many new features, such as blocking websites from automatically playing sound. Users can also use the new Firefox to add individual sites to an exceptions list or turn off the blocking feature.