Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Tweets on AstraZeneca have disinformation, Hyderabad-based portal among sources, claim researchers
- High-level organizer of notorious hacking group FIN7 sentenced to ten years in prison for scheme that compromised tens of millions of debit and credit cards
- Turkey launches international hunt for cryptocurrency boss
- Facebook and Gucci file joint lawsuit against persistent counterfeiter
- DigitalOcean says customer billing data accessed in data breach
- Fourth time’s a charm – OGUsers hacking forum hacked again
- Radixx announces security incident impacting Radixx Res
- FBI paid anti-child predator charity $250,000 for hacking tools
- Mass extraction: The widespread power of U.S. law enforcement to search mobile phones
- Can you fight BEC popularity in Nigeria by steering youth to legitimate IT jobs?
- I made millions selling drugs online, then it all came crashing down
For the more technical
- Cyber espionage group UNC1151 likely conducts ghostwriter influence activity (PDF)
- SonicWall Email Security zero-day vulnerabilities
- Suspected APT actors leverage authentication bypass techniques and Pulse Secure zero-day
- CISA identifies Supernova malware during incident response
- Apple AirDrop shares more than files
- Researchers say ‘massive’ macOS bug was exploited by hackers
- Shlayer malware abusing Gatekeeper bypass on macOS
- XCSSET quickly adapts to macOS 11 and M1-based Macs
- Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app’s perspective
- Security assessment of Accellion’s File Transfer Appliance (PDF)
- Positive Technologies’ key research activities in 2019–2021
- Remote code execution vulnerabilities in Cosori smart air fryer
- New vulnerabilities discovered allow access to user data and complete takeover
- Massive Qlocker ransomware attack uses 7zip to encrypt QNAP devices
- A ransomware gang made $260,000 in 5 days using the 7zip utility
- New Clubhouse security vulnerabilities could happen to any growing unicorn
- Duo two-factor authentication bypass
- Hacking 3,000,000 apps at once through CocoaPods
- PHP supply chain attack on Composer
- Remote code execution in Homebrew by compromising the official Cask repository
- Logins for 1.3 million Windows RDP servers collected from hacker market
- Hello ransomware uses updated China Chopper web shell, SharePoint vulnerability
- Breaking ABUS Secvest internet-connected alarm systems (CVE-2020-28973)
- “BadAlloc” – Memory allocation vulnerabilities could affect wide range of IoT and OT devices in industrial, medical, and enterprise networks
- What can you find in 57K AWS S3 buckets? 2021 update
- Million-dollar deposits and friends in high places: how we applied for a job with a ransomware gang
- Ransomware gang tries to extort Apple hours ahead of Spring Loaded event
- Hundreds of networks reportedly hacked in Codecov supply-chain attack
- HashiCorp is the latest victim of Codecov supply-chain attack
- Nearly half of malware now use TLS to conceal communications
- EtterSilent: the underground’s new favorite maldoc builder
- Spotting malicious Excel4 macros
- Ransomware by the numbers: Reassessing the threat’s global impact
- Babuk ransomware readies ‘shut down’ post, plans to open source malware
- UNC2447 SOMBRAT and FIVEHANDS ransomware: A sophisticated financial threat
- [VIDEO] Hunting Cobalt Strike using Sysmon and Sentinel
- Prometei botnet exploiting Microsoft Exchange vulnerabilities
- Lazarus group recruitment: Threat hunters vs head hunters
- (Are you) afreight of the dark? Watch out for Vyveva, new Lazarus backdoor
- Lazarus APT conceals malicious code within BMP image to drop its RAT
- RotaJakiro: A long live secret backdoor with 0 VT detection
- SolarWinds: Illuminating the hidden patterns that advance the story
- uBlock Origin works best on Firefox
- Edge cases in app & backend development: Dates & time
- Linux kernel team rejects University of Minnesota researchers’ apology
- Data from the Emotet malware is now searchable in Have I Been Pwned, courtesy of the FBI and NHTCU
- GitHub disables Google FLoC user tracking on its website
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.