Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Philly hunger relief group Philabundance lost nearly $1 million in cyberattack
- Shirbit hackers release more data as company refuses to pay ransom
- Payment processing giant TSYS: Ransomware incident “immaterial” to company
- Ransomware forces hosting provider Netgain to take down data centers
- Ransomware gangs are now cold-calling victims if they restore from backups without paying
- Pfizer/BioNTech vaccine docs hacked from European Medicines Agency + Statement regarding cyber attack on European Medicines Agency
- Hackers leak data from Embraer, world’s third-largest airplane maker
- Hackers are selling more than 85,000 MySQL databases on a dark web portal
- More than 20,000 arrests in year-long global crackdown on phone and Internet scams
- Kazakhstan government is intercepting HTTPS traffic in its capital
- New cross-border online terrorist content rules sparks rights concerns
- New York City Council votes to prohibit businesses from using facial recognition without public notice
- Endangered Firefox: The state of Mozilla
- Manifest V3 now available on M88 Beta
- Google and Apple are banning technology for sharing users’ location data
For the more technical
- December 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing
- PsExec local privilege escalation + PoC
- Android Security Bulletin – December 2020
- “Important, Spoofing” – zero-click, wormable, cross-platform remote code execution in Microsoft Teams
- CVE-2020-17049: Kerberos Bronze Bit attack – theory & practical exploitation
- OpenSSL Security Advisory: EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971)
- Vulnerability in GE LightSpeed, Revolution, and other CT, MRI, and X-Ray imaging systems
- Russian state-sponsored malicious cyber actors exploit known vulnerability in virtual workspaces (PDF)
- Pwnie Awards 2020 winners include Zerologon, CurveBall, Checkm8, BraveStarr attacks
- Depix – a tool for recovering passwords from pixelized screenshots
- Oblivious DNS over HTTPS (ODoH): A practical privacy enhancement to DNS (PDF)
- WAF evasion techniques
- Etherify 5 – switching the switches
- Tactics, techniques and procedures (TTPs) utilized by FireEye’s Red Team tools
- Evading link scanning security services with passive fingerprinting
- Hackers hide web skimmer inside a website’s CSS files
- Facebook: Taking action against hackers in Bangladesh and Vietnam
- Operation StealthyTrident: corporate software under attack
- Cyber actors target K-12 distance learning education to cause disruptions and steal data (PDF)
- Qbot malware switched to stealthy new Windows autostart method
- Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers
- njRAT spreading through active Pastebin command and control tunnel
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.