Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Silicon Valley’s vast data collection should worry you more than TikTok
- Google ‘accidentally’ enabled smart speakers to listen passive sounds
- Privacy problems are widespread for Alexa and Google Assistant voice apps, according to researchers
- Google just revealed how many people use its Privacy Checkup tool. It’s not good news
- Australian QR codes used for COVID-19 contact tracing redirect to websites that will disclose your personal information to adv companies
- How cops can secretly track your phone
- DHS had access to messages from Portland protesters, document shows
- China is now blocking all encrypted HTTPS traffic that uses TLS 1.3 and ESNI
- Have I Been Pwned’s code base will be open sourced
- Intel investigating breach after 20GB of internal documents leak online
- Bulgarian police arrest hacker Instakilla
- GandCrab ransomware operator arrested in Belarus
- Garmin received decryptor for WastedLocker ransomware
- Ransomware gang publishes tens of GBs of internal data from LG and Xerox
- Canon confirms ransomware attack in internal memo
For the more technical
- Black Hat USA 2020 – materials
- TikTok: Logs, logs, logs
- Windows 10: HOSTS file blocking telemetry is now flagged as a risk
- Microsoft Teams Updater living off the land
- EtherOops – bypassing firewalls and NATs by exploiting packet-in-packet attacks in Ethernet (PDF)
- New ‘unpatchable’ exploit allegedly found on Apple’s Secure Enclave chip, here’s what it could mean
- Vulnerability in new TouchID feature put iCloud accounts at risk of being breached
- Over 400 vulnerabilities on Qualcomm’s Snapdragon chip threaten mobile phones’ usability worldwide
- If you own one of these 45 Netgear devices, replace it: Kit maker won’t patch vulnerable gear despite live proof-of-concept code
- Researcher demos hacking of 3D printer firmware that can trigger a fire
- Mirai botnet exploit weaponized to attack IoT devices via CVE-2020-5902
- Hacker leaks passwords for 900+ enterprise VPN servers
- Cybersecurity vulnerability at major cosmetics brand leads to 7 gigabytes+ data leak
- Privilege escalation on Meetup.com enabled redirection of payments
- How malicious Tor relays are exploiting users in 2020
- Chinese hackers have pillaged Taiwan’s semiconductor industry
- Baking and boiling botnets could drive energy market swings and damage
- Iranian hacker group becomes first known APT to weaponize DNS-over-HTTPS (DoH)
- Take a “NetWalk” on the wild side
- WastedLocker’s techniques point to a familiar heritage
- Inter skimming kit used in homoglyph attacks
- Over 80 million users scammed by Chrome fake ad blockers
- Hacking the traffic light of the future
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.