Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Chrome removing third-party cookies or not?
- X begins training Grok AI with your posts, here’s how to disable
- Pro-Ukrainian hackers claim attack on Russian cyber company
- NCA shuts down major fraud platform responsible for 1.8 million scam calls
- Leader of tech support fraud scheme sentenced to seven years in prison
- U.S. trades cybercriminals to Russia in prisoner swap
For the more technical
- CrowdStrike’s final post-incident report
- WhatsApp for Windows lets Python, PHP scripts execute with no warning
- Wrong Check Point (CVE-2024-24919)
- The tragedy of low-level exploitation
- Improving the security of Chrome cookies on Windows
- SLUBStick: Arbitrary memory writes through practical software cross-cache attacks within the Linux kernel (PDF)
- PKfail. Supply-chain failures in Secure Boot key management (PDF)
- Ransomware operators exploit ESXi hypervisor vulnerability for mass encryption
- “EchoSpoofing” — A massive phishing campaign exploiting Proofpoint’s email protection to dispatch millions of perfectly spoofed emails
- Phishing targeting Polish SMBs continues via ModiLoader
- Social media malvertising campaign promotes fake AI editor website for credential theft
- Threat actor impersonates Google via fake ad for Authenticator
- Mandrake spyware sneaks onto Google Play again, flying under the radar for two years
- BingoMod: The new android RAT that steals money and wipes data
- Unmasking the SMS stealer: Targeting several countries with deceptive apps
- StackExchange abused to spread malicious Python package that drains victims’ crypto wallets
- Introducing Gh0stGambit: A dropper for deploying Gh0st RAT
- Unveiling the latest banking trojan threats in LATAM
- Threat actor abuses Cloudflare Tunnels to deliver RATs
- Surge in Magniber ransomware attacks impact home users worldwide
- IR Trends: Ransomware on the rise, while technology becomes most targeted sector
- ThreatLabz 2024 Ransomware Report (PDF)
- Ducks Now Sitting (DNS): Internet infrastructure insecurity
- Who knew? Domain hijacking is so easy
- UNC4393 goes gently into the SILENTNIGHT
- APT45: North Korea’s digital military machine
- APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike
- SideWinder utilizes new infrastructure to target ports and maritime facilities in the Mediterranean Sea
- StormBamboo compromises ISP to abuse insecure software update mechanisms
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.