Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Expanding Play’s target level API requirements to strengthen user security
- Hacker accessed 319 crypto- and finance-related Mailchimp accounts, company said
- Hackers gaining power of subpoena via fake “Emergency Data Requests”
- Wtch this: Unravelling the mystery behind a secret YouTube URL
- Darkweb researcher warns of possible cyberattack against Indonesian energy company Perushaan Gas Negare
- Wind turbine giant Nordex shuts down IT systems in response to cyberattack
- Justice Department announces court-authorized disruption of botnet controlled by the Russian Federation’s main intelligence directorate (GRU)
- Disrupting cyberattacks targeting Ukraine
- The alleged scammers behind the most notorious murder-for-hire site have been arrested
- Shutdown of Russia’s Hydra Market disrupts a crypto-crime ATM
- Member of hacking group sentenced for scheme that compromised tens of millions of debit and credit cards
For the more technical
- Android security bulletin – April 2022
- CVE-2022-22965: Analyzing the exploitation of Spring4Shell vulnerability in weaponizing and executing the Mirai botnet malware
- PHP supply chain attack on PEAR
- Vulnerability in Rockwell Automation ISaGRAF
- An in-depth look at ICS vulnerabilities – part 2 & part 3
- Server-side request forgery on FinTech platform enabled administrative account takeover
- How we secure Monzo’s banking platform
- Parrot TDS takes over web servers and threatens millions
- European industrial infrastructure cyber threat perspective (PDF)
- VIASAT incident: from speculation to technical details
- Deep dive analysis – Borat RAT
- A bad luck BlackCat
- Denonia: The first malware specifically targeting Lambda
- Google is on guard: sharks shall not pass!
- Fake e‑shops on the prowl for banking credentials using Android malware
- Leave your message after the beep: WhatsApp voicemail phishing attack from Russia
- FFDroider stealer targeting social media platform users
- Scammers are exploiting Ukraine donations
- Chinese hackers abuse VLC Media Player to launch malware loader
- Suspected China-backed hackers target 7 Indian electricity grid centers
- Operation Bearded Barbie: APT-C-23 campaign targeting Israeli officials
- FIN7 power hour: Adversary archaeology and the evolution of FIN7
- Fresh Totolink vulnerabilities picked up by Beastmode Mirai campaign
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.