Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- How the CIA helped foil a Russian spy ring in London
- Europol taking down over 20 000 internet domain names
- Money laundering via AirBnB
- The man who deactivated Trump’s Twitter account
- Fancy Bear using UK hosting services
- Other details of Fancy Bear activities (APT28, Pawn Storm)
- Interview with Joe Grand (AKA Kingpin)
- NSA leaker pleads guilty
- Another NSA contractor leaking data
- Brushing – unordered parcels from China
- CoinPouch security breach
- NCSC recommends not using Kaspersky AV
- Chinese men accused of stealing corporate data
- Russian carder sentenced to 14 years
- Canadian man pleads guilty to hacking for Kremlin
- Dark web threats
- [VIDEO] VoIP spying
- SWIFT hacks alert
- Europol arrested four skimmers
- Russian hackers trade British ministers passwords
- Politicians sharing passwords
- Uber paid 20 year old man to keep breach secret
- Bug bounties as anti-disclosure strategy
- OSINT used to verify Saudi missile defences
- Jail computer hacked to release a prisoner early
- Bitcoins use in darknet
- Recovering bitcoins from a damaged laptop
- Cheating TripAdvisor
- FSB crime experts and US elections
- Roofing company hacked a competitor
- Pepsi suspected of stealing documents in Russia
- Cuban sonic attacks victims might be poisoned
- Russian hacker jailed in UK
- Some funny hacker videos
For the more technical
- Three Uber security managers resign
- Dirty COW patch insufficient
- Root access without password in macOS
- More technical details on macOS root access
- RCE with 7zip
- Cryptomining with hidden browser windows
- FB image removal vulnerability
- Cobalt group using recent RTF vulnerability
- Review of exploits attacking latest Microsoft vulnerabilities
- New Mirai version
- Finding true hidden service IP
- Multiple WordPress vulnerabilities
- New Lazarus backdoor for Android
- [AUDIO] F-Secure start a new podcast
- Cisco patches critical WebEx vulnerabilities
- Telnet passwords leak from serial-to-Ethernet devices
- Tizi – Android backdoor
- ROKRAT analysis
- Hidden service OPSEC fail
- Android apps users tracking
- iOS 11 security issues
- Golden SAML to forge authentication to cloud apps
- OpenEMR flaw leaves medical records exposed
- Analysis of new Ursnif variant
- Phishing trends analysis
- Effective phishing techniques
- Terrorism fears used in a phishing campaign
- Keybase for Android could store your private keys in the Google cloud
- Chrome fighting with third party code injection
- New PacketTotal version released
- Bitcoin Gold GitHub repository compromised
- Dropbox bugs
- Simple way to perform a memory dump
- Zeus Panda spreading via Emotet
- iCloud authentication tokens analysis part 1, 2, 3
- Chicago hospital data leak
- Guessing private bitcoin keys
- Password spraying attacks
- US Army data leaks
- New Retefe version analysis
- Data exfiltration from AWS cloud environment
- Gmail on Android vulnerability
- Tool to search S3 buckets
- Fileless malware analysis
- Kaspersky’s review of 2017
- Analysis of Leakbase disappearance
- Critical vulnerability patched in Microsoft Malware Protection Engine
- Andromeda botnet eliminated
- One of Andromeda botnet admins arrested
- Tracking lateral movement with event logs
- Modifying Android apps without modifying their signature
- PayPal informs about data of 1,6 mln users compromise
- Multiple mail clients vulnerable to spoofing bug
- New tools to search WHOIS database
- Anatomy of latest Carbanak/FIN7 attacks
- TeamViewer critical vulnerability
- WhatsApp vulnerability
- Tricky PayPal phishing
- Phishing with a EV SLL certificate
- TrickBot campaign analysis
- Description of several cryptocurrency incidents
- Cybercrime pricelist
- Satori, new Mirai-style botnet
- More details on Satori botnet (PDF)
- New IoT botnet based on Huawei routers
- Analysis of Flying Kitten and Rocket Kitten APT
- Analysis of Charming Kitten APT
- Creating Windows 10 kernel exploit
- Black Hat Europe 2017: Attacks targeting financial institutions (PDF)
- Ethiopian dissidents targeted with commercial spyware
- Analysing malicious RTF files
- Spying with Amazon Echo
- Vulnerabilities in mobile banking apps (PDF)
- Accessing private Ashley Madison pictures
- Multiple WordPress pages infected with keylogging software
- Details of Intel Management Engine hack (PDF)
- VirtualBox vulnerability
- Apple HomeKit vulnerability
- Mobile location tracking without GPS
- Sandbox evasion with DDE
- Sysinternals Sysmon – suspicious activity guide
- HTTPS debugging for Android apps with Burp Proxy
- Microsoft leaks private key for cloud ERP product
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – December 10 2017”