Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Meta’s ad practices ruled illegal under GDPR: Key facts and implications of the decision
- Google to crack down on third-party YouTube apps that block ads
- Cops can force suspect to unlock phone with thumbprint, US court rules
- AFP traps alleged RAT developer
- Former security engineer sentenced to three years in prison for hacking two decentralized cryptocurrency exchanges
- The fall of LabHost: Law enforcement shuts down phishing service provider
- Chinese-owned semiconductor company Nexperia hit by ransomware attack
- HelloKitty ransomware rebrands, releases CD Projekt and Cisco data
For the more technical
- Palo Alto – putting the protecc in GlobalProtect (CVE-2024-3400)
- 22,500 Palo Alto firewalls “possibly vulnerable” to ongoing attacks
- PuTTY SSH client flaw allows recovery of cryptographic private keys
- [VIDEO] Request smuggling – do more than running tools! HTTP Request smuggling bug bounty case study
- Telegram fixes Windows app zero-day used to launch Python scripts
- Security advisory YSA-2024-01 YubiKey Manager privilege escalation
- Advanced cyber threats impact even the most prepared
- Botnets continue exploiting CVE-2023-1389 for wide-scale spread
- Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials
- LastPass users targeted in phishing attacks good enough to trick even the savvy
- Attackers exploiting new critical OpenMetadata vulnerabilities on Kubernetes clusters
- LLM agents can autonomously exploit one-day vulnerabilities
- Not The Hidden Wiki – the repository of links related to cybersecurity
- NCSC Cyber Threat Report 2022/2023
- Cyberthreats in the transportation industry
- SoumniBot: the new Android banker’s unique techniques
- Akira ransomware gang made $42 million from 250 attacks since March 2023
- ‘Junk gun’ ransomware: Peashooters can still pack a punch
- Unpacking the Blackjack group’s Fuxnet malware
- Russia-linked backdoor targets Eastern European networks
- Unearthing APT44: Russia’s notorious cyber sabotage unit Sandworm (PDF)
- Analysis of the APT31 indictment
- DuneQuixote campaign targets Middle Eastern entities with “CR4T” malware
- From social engineering to DMARC abuse: TA427’s art of information gathering
- Threat group FIN7 targets the U.S. automotive industry
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.