Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- The EDPB data protection guide for small business
- The DOJ detected the SolarWinds hack 6 months earlier than first disclosed
- Capita admits customer data may have been breached during cyber-attack
- Ukrainian arrested for selling data of 300M people to Russians
- Cybersecurity company Group-IB says it’s fully exited Russia
For the more technical
- Attackers in the bottleneck – lateral movements and threat hunting
- New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP)
- CVE-2023-29552 Service Location Protocol-denial of service amplification attack
- TP-Link WAN-side vulnerability CVE-2023-1389 added to the Mirai botnet arsenal
- GhostToken – exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts
- Critical vulnerabilities in PaperCut print management software
- Do NOT remove curl.exe from your Windows System32 folder
- Multiple security vulnerabilities in VMware Workstation and Fusion
- Smartphones with popular Qualcomm chip secretly share private information with US chip-maker
- BlackBerry Global Threat Intelligence Report – April 2023 (PDF)
- How I (could) have stolen your corporate secrets for $100 (PDF)
- Google: How we fought bad apps and bad actors in 2022
- HiddenAds spread via Android gaming apps on Google Play
- Magecart threat actor rolls out convincing modal forms
- First-ever attack leveraging Kubernetes RBAC to backdoor clusters
- NSO Group’s Pegasus spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains
- EvilExtractor – all-in-one stealer
- Threat actor selling new Atomic macOS (AMOS) Stealer on Telegram
- Bumblebee malware distributed via trojanized installer downloads
- Rapture, a ransomware family with similarities to Paradise
- APT trends report Q1 2023
- Hacktivism unveiled, April 2023 insights into the footprints of hacktivists
- Nomadic Octopus’ Paperbug campaign (PDF)
- Unpacking BellaCiao: A closer look at Iran’s latest malware
- Evasive Panda APT group delivers malware via updates for popular Chinese software
- FIN7 tradecraft seen in attacks against Veeam backup servers
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.