Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- T-Mobile confirms hack that may have compromised 100 million users
- T‑Mobile shares additional information regarding ongoing cyberattack investigation
- Ford bug exposed customer and employee records from internal systems
- Colonial Pipeline reports data breach after May ransomware attack
- America’s secret terrorist watchlist exposed on the web without a password
- The Taliban have seized U.S. military biometrics devices
- Emails from Lithuanian Ministry of Foreign Affairs for sale on data-trading forum
- German parliament pens letter to Tim Cook with concerns over CSAM detection system
- New York man sentenced to 3 years for stealing students’ nude photos after hacking their accounts
- Messenger updates end-to-end encrypted chats with new features
- New Russian ad stars Bruce Willis… without Bruce Willis
- This $500 million Russian cyber mogul planned to take his company public—then America accused it of Hacking for Putin’s spies
For the more technical
- Why TLS is better without STARTTLS. A security analysis of STARTTLS in the email context
- New unofficial Windows patch fixes more PetitPotam attack vectors
- CVE-2021-21166: Chrome object lifecycle issue in audio
- [VIDEO] DEF CON 29 main stage presentations
- How to contact Google SRE: Dropping a shell in cloud SQL
- Multiple issues in Realtek SDK affects hundreds of thousands of devices down the supply chain
- Fortinet FortiWeb OS command injection
- Critical vulnerability affecting millions of IoT devices
- CVE-2021-1905: Qualcomm Adreno GPU memory mapping use-after-free
- Modify in-flight data to payment provider Smart2Pay
- Weaponizing middleboxes for TCP reflected amplification (PDF)
- Windows Hello bypassed using infrared image
- Microsoft Exchange servers are getting hacked via ProxyShell exploits
- Linux glibc security fix created a nastier Linux bug
- Crack Me If You Can 2021. Team write-up (PDF)
- HTTP/2: The sequel is always worse
- SynAck ransomware gang releases decryption keys for old victims
- DeepBlueMagic – new ransomware, new method
- RansomClave: Ransomware key management using SGX (PDF)
- Analysis of Diavol ransomware reveals possible link to TrickBot gang
- Malware dev infects own PC and data ends up on intel platform
- How to proactively defend against Mozi IoT botnet
- Malware campaign uses clever ‘captcha’ to bypass browser warning
- Operation Secondary Infektion continues targeting democratic institutions and regional geopolitics (PDF)
- Indra – hackers behind recent attacks on Iran
- Hackers breached US Census Bureau in January 2020 via Citrix vulnerability
- Uncovering Tetris – a full surveillance kit running in your browser
- North Korean APT InkySquid infects victims using browser exploits
- Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
- Apple Watch forensics: The adapters
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.