Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! newsletter: Got backups? (PDF)
- The risk of weak online banking passwords
- Monzo urges 480,000 customers to change their pin numbers
- Researchers show how Europe’s data protection laws can dox people
- Binance KYC data leak — crypto exchange sets $290,000 bounty on blackmailer
- Microsoft contractors are listening to some Skype calls
- Instagram ad partner secretly sucked up and tracked millions of users’ locations and stories
- 8chan refugees blow their anonymity
- Hundreds of exposed Amazon cloud backups found leaking sensitive data
- Amazon allegedly scammed out of $370K by 22-year-old’s return shipments of dirt
- AT&T employees took bribes to plant malware on the company’s network
- How AT&T insiders were bribed to ‘unlock’ millions of phones
- Iranian hackers suspected of cyberattacks on Bahrain
For the more technical
- With warshipping, hackers ship their exploits directly to their target’s mail room
- Google Project Zero: Vulnerability disclosure FAQ
- Apple gives hackers a special iPhone—and a bigger bug bounty
- Dangerous get-task-allow entitlement on iExplorer example
- Avaya VoIP phones harbored 10-year old vulnerability
- QualPwn – exploiting Qualcomm WLAN and modem over the air
- Security bugs in popular Cisco switch brand allow hackers to take over devices
- Unpatched KDE vulnerability disclosed on Twitter
- Steam Windows client local privilege escalation 0day
- Responding to Firefox 0-days in the wild
- Hackers can break into an iPhone just by sending a text
- WhatsApp protocol decryption for chat manipulation and more
- Basic Electron framework exploitation
- Reverse RDP attack: The Hyper-V connection
- Multiple vulnerabilities in NVIDIA Windows GPU Display Driver, VMware ESXi, Workstation and Fusion
- A Boeing code leak exposes security flaws deep in a 787’s guts
- SWAPGS attack: New side-channel attack bypasses Spectre and Meltdown defenses
- HTTP desync attacks: Request Smuggling reborn
- A technical analysis of the Capital One cloud misconfiguration breach
- iNSYNQ ransom attack began with phishing email
- New Echobot botnet variant uses over 50 exploits to propagate
- Some Fiberhome routers are being utilized as SSH tunneling proxy nodes
- The PDF invoice that phished you
- Varenyky: Spambot à la Française
- GermanWiper ransomware hits Germany hard, destroys files, asks for ransom
- Unmasking AVE_MARIA
- Corporate IoT – a path to intrusion
- DDoS attacks in Q2 2019
- APT41: A dual espionage and cyber crime operation
- Sharpening the Machete
- Canva security incident
- From the depths of counterfeit smartphones
- The Advanced Protection Program expands to Chrome
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.