Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Facebook says it ‘unintentionally uploaded’ 1.5 million people’s email contacts without their consent
- Facebook now says its password leak affected ‘millions’ of Instagram users
- Russia fines Facebook $50 for failing to comply with local data privacy law
- Hackers could read your Hotmail, MSN, and Outlook emails by abusing Microsoft support
- Microsoft loses control over Windows Tiles subdomain
- A hacker has dumped nearly one billion user records over the past two months
- India’s Wipro investigating potential breach of some employee accounts + more information
- Cyber-security firm Verint hit by ransomware
- Former student destroys 59 university computers using USB Killer device
- ‘Flash Boys’ trading bots are running wild on crypto exchanges
- Hackers steal more than $50 million in cryptocurrency in 15 months
- Moscow server hosted WikiLeaks and Iran’s hackers weeks apart
- Demonoid founder ‘Deimos’ is believed to have passed away
For the more technical
- Oracle Critical Patch Update Advisory – April 2019
- New zero-day vulnerability CVE-2019-0859 in win32k.sys
- Internet Explorer browser flaw threatens all Windows users
- Security flaw in EA’s Origin client exposed gamers to hackers
- Linux: Privilege escalation by injecting process possessing sudo tokens
- Apache Tomcat patches important remote code execution flaw
- Adblock Plus filter lists may execute arbitrary code in web pages
- Reverse-engineering Broadcom wireless chipsets
- DNS hijacking abuses trust in core internet service
- DNS tunneling in the wild: Overview of OilRig’s DNS tunneling
- ‘Land Lordz’ service powers Airbnb scams
- Potential targeted attack uses AutoHotkey and malicious script embedded in Excel file to avoid detection
- Source code of Iranian cyber-espionage tools leaked on Telegram
- Pirates of Brazil: Integrating the strengths of Russian and Chinese hacking communities
- Spear phishing campaign targets Ukraine government and military
- Massive eGobbler malvertising campaign leverages Chrome vulnerability to target iOS users
- Chamois: The big botnet you didn’t hear about
- Electrum Bitcoin wallets under siege
- Miner malware spreads beyond China, uses multiple propagation methods
- Account with admin privileges abused to install BitPaymer ransomware via PsExec
- ‘NamPoHyu Virus’ ransomware targets remote Samba servers
- The Qrypter payload malware has been finally decrypted
- New HawkEye Reborn variant emerges following ownership change
- Inside Scranos – a cross platform, rootkit-enabled spyware operation
- Tchap: The super (not) secure app of the French government
- Tic Toc pwned – child tracking smartwatch API flaws
- FLASHMINGO: The FireEye open source automatic analysis tool for Flash
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – April 19, 2019”