Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Medal count: OSINT analysis of real Russian losses for the first week of hostilities in Ukraine
- Ukraine dismantles 5 disinformation bot farms, seizes 10,000 SIM cards
- EU Parliament passes privacy-busting crypto rules despite industry criticism
- Investigating influencer VPN ads on YouTube (PDF)
- Okta apologizes for waiting two months to notify customers of Lapsus$ breach
- Lapsus$ found a spreadsheet of accounts as they breached Okta, documents show
- UK police charge 2 teenagers in connection with Lapsus$ hacks
- Iberdrola suffers a hack that exposes the data of 1.3 million customers
For the more technical
- Behold, a password phishing site that can trick even savvy users
- Tracking cyber activity in Eastern Europe
- Spring4Shell: Zero-day vulnerability in Spring framework (CVE-2022-22965)
- Spring4Shell: Security analysis of the latest Java RCE ‘0-day’ vulnerabilities in Spring + more information
- Resolved RCE in Sophos Firewall (CVE-2022-1040)
- Vulnerabilities identified in Wyze Cam IoT device
- Spy in the GPU-box: Covert and side channel attacks on multi-GPU systems (PDF)
- The old switcheroo: Hiding code on Rockwell Automation PLCs
- BROKENWIRE: Wireless disruption of CCS electric vehicle charging (PDF)
- Arbitrary file read via the bulk imports UploadsPipeline
- A beautiful factory for malicious packages
- Microsoft is adding a new driver-blocklist feature to Windows Defender on Windows 10 and 11
- URL rendering trick enabled WhatsApp, Signal, iMessage phishing
- Honda bug lets a hacker unlock and start your car via replay attack
- An EFF investigation: Mystery GPS tracker on a supporter’s car
- An in-depth look at ICS vulnerabilities
- Triton malware remains threat to global critical infrastructure Industrial Control Systems (PDF)
- Russian-linked Android malware records audio, tracks your location
- Analysis of BlackGuard – a new info stealer malware being sold in a Russian hacking forum
- Mars Stealer: Oski refactoring
- Spoofed invoice used to drop IcedID
- Hive ransomware deploys novel IPfuscation technique to avoid detection
- First Python ransomware attack targeting Jupyter Notebooks
- KA-SAT Network cyber attack overview
- Chinese threat actor Scarab targeting Ukraine
- New milestones for Deep Panda: Log4Shell and digitally signed Fire Chili rootkits
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.