Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Meet Window Snyder, the trailblazer who helped secure the internet and billions of devices
- Fake FlipperZero sites promise free devices after completing offer
- Clop ransomware now uses torrents to leak data and evade takedowns
- Kazakhstan refuses to extradite detained Russian cyber expert to US
- Astronomical observations at the International Gemini Observatory suspended
- Hacktivists fund their operations using common cybercrime tactics
- Operation Narsil disrupts network of child abuse websites designed to generate profits from advertising
For the more technical
- The many vulnerabilities Talos discovered in SOHO and industrial wireless routers post-VPNFilter
- 2022 top routinely exploited vulnerabilities
- Google AMP – The newest of evasive phishing tactic
- Universal and transferable adversarial attacks on aligned language models
- Collide+Power. Leaking inaccessible data with software-based power side channels
- Emerging attacker exploit: Microsoft cross-tenant synchronization
- Multiple high severity vulnerabilities in Ninja Forms plugin
- Security hole in Minecraft mods lets hackers execute code remotely
- Unsafe deserialization vulnerability in many Minecraft mods
- Use native pointer of function to bypass the latest Chrome v8 sandbox
- New acoustic attack steals data from keystrokes with 95% accuracy
- Tesla jailbreak unlocks theft of in-car paid features
- Midnight Blizzard conducts targeted social engineering over Microsoft Teams
- Fake blockchain games deliver RedLine Stealer & Realst Stealer – A new macOS infostealer malware
- What’s happening in the world of crimeware: Emotet, DarkGate and LokiBot
- Pikabot deep analysis
- Inside the IcedID BackConnect protocol
- WikiLoader digs sophisticated evasion
- New Rilide stealer version targets banking data and works around Google Chrome Manifest V3
- NodeStealer 2.0 – The Python version: Stealing Facebook business accounts
- Related CherryBlos and FakeTrade Android malware involved in scam campaigns
- APT Bahamut targets individuals with Android malware using spear messaging
- CISA releases malware analysis reports on Barracuda backdoors
- Linux version of Abyss Locker ransomware targets VMware ESXi servers
- Common TTPs of attacks against industrial organizations. Implants for gathering data
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.