Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Apple, Google, and Mozilla block Kazakhstan’s HTTPS intercepting certificate
- Google wants to reduce lifespan for HTTPS certificates to one year
- Announcing the Microsoft Edge Insider Bounty
- Microsoft contractors listened to Xbox owners in their homes
- Man sued for using bogus YouTube takedowns to get address for swatting
- The rise of “bulletproof” residential networks
- Ransomware strike takes down 23 Texas local government agencies
- Employees connect nuclear plant to the internet so they can mine cryptocurrency
- Breach at Hy-Vee supermarket chain tied to sale of 5 million stolen credit, debit cards
For the more technical
- Backdoor code found in Ruby libraries
- npm pulls malicious package that stole login passwords
- Removing profile pictures for any Facebook user
- Webmin 0day remote code execution
- CVE-2019-12527: Code execution on Squid proxy through a buffer overflow
- Kubernetes vulnerable to DoS attacks
- Hacker releases first public jailbreak for up-to-date iPhones in years
- Multiple bugs in OpenWeave and Nest Labs Nest Cam IQ indoor camera
- Cisco warns of public exploit code for critical switch flaws
- Cross-router covert channels (PDF)
- Multiple critical vulnerabilities in Adobe Photoshop
- Multiple vulnerabilities found in VLC Media Player
- Researcher publishes second Steam zero day after getting banned on Valve’s bug bounty program
- BitDefender Antivirus Free 2020 found vulnerable
- State of application security at top 100 global fintech startups
- IT threat evolution Q2 2019 + statistics
- Finding Neutrino: A large malware campaign ongoing since 2013
- Uncovering a MyKings variant with bootloader persistence
- Open source ransomware targets Fortnite users
- Asruex backdoor variant infects Word documents and PDFs through old MS Office and Adobe vulnerabilities
- First‑of‑its‑kind spyware sneaks into Google Play
- Banking trojan Bolik spreads disguised as the NordVPN app
- Damage from Silence APT operations increases fivefold. The gang deploys new tools on its “worldwide tour”
- [VIDEO] hacker:HUNTER – a free documentary about the hunt for the Carbanak group
- Magecart criminals caught stealing with their poker face on
- New phishing campaign bypasses Microsoft ATP to deliver Adwind to utilities industry
- Evolving phishing attacks targeting journalists and human rights defenders from the Middle-East and North Africa
- Microsoft warns of phishing attacks using custom 404 pages
- How attackers can harvest users’ Microsoft 365 credentials with new phishing campaign
- A study of bandwidth denial-of-service attacks against Tor (PDF)
- Hunting the public cloud for exposed hosts and misconfigurations
- Coinbase: A closer look at a password storage issue affecting 3,420 customers
- Data breach in adult site compromises privacy of all users
- Newly registered domains: Malicious abuse by bad actors
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.