Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- The Ghostwriter scenario
- La Puente man steals 620,000 iCloud photos in plot to find images of nude women
- Nigerian ransomware: An inside look at soliciting employees to deploy DemonWare
- Liquid exchange hacked – $97 million stolen
- One disruption at a bank, a long legal battle and the case of a missing $9 million
- Apple photo-scanning plan faces global backlash from 90 rights groups
- Apple’s spy in the jailbreak community
For the more technical
- AWS privilege escalation: exploring odd features of the Trust Policy
- Razer bug lets you become a Windows 10 admin by plugging in a mouse
- Trend Micro: Linux Threat Report 2021 1H
- Kaspersky: Gaming-related cyberthreats in 2020 and 2021
- Academics bypass PINs for Mastercard and Maestro contactless payments
- From Pearl to Pegasus. Bahraini government hacks activists with NSO Group zero-click iPhone exploits
- Almost 2,000 Exchange servers hacked using ProxyShell exploit
- Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities
- Vulnerability in Bumble dating app reveals any user’s exact location
- CISA releases five Pulse Secure-related MARs
- Realtek SDK vulnerabilities weaponized for Mirai distribution
- LockFile: Ransomware uses PetitPotam exploit to compromise Windows domain controllers
- Indicators of compromise associated with OnePercent group ransomware (PDF)
- Ragnarok ransomware releases master decryptor after shutdown
- FortiGuard Labs Threat Landscape Report highlights tenfold increase in ransomware
- Ransomware groups to watch: Emerging threats
- New campaign sees LokiBot delivered via multiple methods
- FIN8 threat actor spotted once again with new “Sardonic” backdoor
- PRISM attacks fly under the radar
- Triada trojan in WhatsApp mod
- ShadowPad: A masterpiece of privately sold malware in Chinese espionage
- The SideWalk may be as dangerous as the CROSSWALK
- Cloudflare thwarts 17.2M rps DDoS attack — the largest ever reported
- How default permissions on Microsoft Power Apps exposed millions
- Microsoft warns thousands of cloud customers of exposed databases
- Confucius uses Pegasus spyware-related lures to target Pakistani military
- Here’s how to guard your enterprise against ShinyHunters
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.