Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Estonia arrests hacker who stole 286K ID scans from govt database
- The last refuge of the criminal: Encrypted smartphones
- Global phone hacks expose darker side of Israel’s ‘startup nation’ image
- Biden orders CISA and NIST to develop cybersecurity performance goals for critical infrastructure
- Dahua, Hikvision out of security camera industry group
- The YouTubers who blew the whistle on an anti-vax plot
- Russian cops arrest journalist who exposed spies involved in MH-17 downing
For the more technical
- Top routinely exploited vulnerabilities
- Windows “PetitPotam” network attack
- Researchers warn of unpatched Kaseya Unitrends backup vulnerabilities
- You should turn off autofill in your password manager
- Some URL shortener services distribute Android malware, including banking or SMS trojans
- Vultur, with a V for VNC
- Malicious content delivered through archive.org
- Malware increasingly targets Discord for abuse
- New attacks on Kubernetes via misconfigured Argo Workflows
- From stolen laptop to inside the company network
- Quick analysis of Haron Ransomware (feat. Avaddon and Thanos)
- BlackMatter ransomware emerges as successor to DarkSide, REvil
- DoppelPaymer continues to cause Grief through rebranding
- Unhacked: 121 tools against ransomware on a single website
- Babuk: Biting off more than they could chew by aiming to encrypt VM and *nix systems?
- When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure
- When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks
- MeteorExpress: Mysterious wiper paralyzes Iranian trains with epic troll
- APT trends report Q2 2021
- Infrastructure patterns lead to more than 30 active APT29 C2 servers
- TA456 targets defense contractor with alluring social media persona
- THOR: Previously unseen PlugX variant deployed during Microsoft Exchange server attacks by PKPLUG group
- Praying Mantis: An advanced memory-resident attack
- Kaspersky: DDoS attacks in Q2 2021
- Cloudflare: DDoS attack trends for 2021 Q2
- A controversial tool calls out thousands of hackable websites
- Here’s what that Google Drive “security update” message means
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.