Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Telegram: Sign up without a SIM card
- Apple advances user security with powerful new data protections
- Android app with over 5m downloads leaked user browsing history
- Cops can extract data from 10,000 different car models’ infotainment systems
- French hospital cancels operations after cyberattack
- US Health Dept warns of Royal Ransomware targeting healthcare (PDF)
- Amnesty International Canada target of sophisticated cyber-attack linked to China
For the more technical
- Building a virtual machine inside ChatGPT
- TryHackMe: Advent of Cyber 2022
- Critical vulnerability (CVE-2021-35587) in Oracle Fusion Middleware now exploited
- Netgear router network misconfiguration
- Hackers hijack Linux devices using PRoot isolated filesystems
- Pwn2Own Toronto 2022 – Day One Results, Day Two Results, Day Three Results, Day Four Results and Master of Pwn
- Supply chain vulnerabilities put server ecosystem at risk
- COVID-bit: Keep a distance of (at least) 2m from my air-gap computer
- Main phishing and scamming trends and techniques
- Keys to the kingdom: How compromised corporate emails have become the most attractive attack vector for cybercriminals (PDF)
- Cybercriminal market in Telegram
- “In The Box” – mobile malware webinjects marketplace
- The scammers who scam scammers on cybercrime forums: Part 1
- Purpose built criminal proxy services and the malicious activity they enable
- Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers
- Technical analysis of DanaBot obfuscation techniques
- The story of a ransomware turning into an accidental wiper
- New ransomware disrupting transportation and logistics industry in Israel
- Blowing Cobalt Strike out of the water with memory analysis
- Zerobot – new Go-based botnet campaign targets multiple vulnerabilities
- Vice Society: Profiling a persistent threat to the education sector
- DEV-0139 launches targeted attacks against the cryptocurrency industry
- ₿uyer ₿eware: Fake cryptocurrency applications serving as front for AppleJeus malware
- Internet Explorer 0-day exploited by North Korean actor APT37
- New MuddyWater threat: Old kitten; new tricks
- Mustang Panda uses the Russian-Ukrainian war to attack Europe and Asia Pacific targets
- Exposing TAG-53’s credential harvesting infrastructure used for Russia-aligned espionage operations
- Russia compromises major UK and US organisations to attack Ukraine
- BackdoorDiplomacy wields new tools in fresh Middle East campaign
- Iran: State-backed hacking of activists, journalists, politicians
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.