Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Prague airport reports failed cyberattacks
- Cyber criminals don’t ‘brake’ for pandemics
- About recent Uniswap and Lendf.Me reentrancy attacks
- IT services giant Cognizant suffers Maze Ransomware cyber attack
- Nintendo accounts are getting hacked and used to buy Fortnite currency
- Valve says it’s safe to play CS:GO and TF2 after source code leaked online
- Energy company in Poland exposed data of its customers
- Details of 20 million Aptoide app store users leaked on hacking forum
- Firefox’s Bug Bounty in 2019 and into the future
- COVID-19’s impact on Tor
For the more technical
- You’ve got (0-click) mail! Multiple vulnerabilities in MobileMail/Maild
- Apple says iOS Mail vulnerabilities do not pose immediate threat, patch coming
- New iOS exploit discovered being used to spy on China’s Uyghur minority
- New iPhone text-bomb bug: Just receiving this Sindhi character notification crashes iPhones
- CVE-2020-0022 an Android 8.0-9.0 Bluetooth zero-click RCE – BlueFrag
- Zoom Communications user enumeration
- You won’t believe what this one line change did to the Chrome sandbox
- Cleanly escaping the Chrome sandbox
- Multiple vulnerabilities in IBM Data Risk Manager
- The unpatchable silicon: A full break of the bitstream encryption ofXilinx 7-Series FPGAs (PDF)
- Serious flaws found in multiple smart home hubs: Is your device among them?
- Microsoft releases OOB security updates for Microsoft Office
- SMBGhost pre-auth RCE abusing Direct Memory Access structs
- Detect and prevent web shell malware (PDF)
- New stealth Magecart attack bypasses payment services ising iframes
- Trickbot to Ryuk in two hours
- BazarBackdoor: TrickBot gang’s new stealthy network-hacking malware
- Exploiting (almost) every antivirus software
- COVID-19 has awakened Faketoken — the trojan is out to steal money again
- Oil & gas spearphishing campaigns drop Agent Tesla spyware in advance of historic OPEC+ deal
- Newly uncovered DNS tunnelling technique, and new campaign against South Korean gaming company
- Following ESET’s discovery, a Monero mining botnet is disrupted
- Evolution of Hoaxcalls
- Sawfish phishing campaign targets GitHub users
- The malvertiser that hacks revive ad servers, redirects victims to malware
- Mining for malicious Ruby gems
- Nazar: A lost amulet
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.