Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! newsletter: Messaging / smishing attacks (PDF)
- Mozilla and Opera remove Avast extensions from their add-on stores, what will Google do?
- Facebook fired a contractor who was paid thousands in bribes to reactivate banned ad accounts
- Russian police raid NGINX Moscow office
- Two Bayrob cybercrime members sentenced to 20 and 18 years in prison
- 460,000 Turkish card details put up for sale, web skimmers suspected
- Iran banks burned, then customer accounts were exposed online
- PR software firm exposes data on nearly 500k contacts
- Ransomware at Colorado IT provider affects 100+ dental offices
For the more technical
- The Signal private group system and anonymous credentials supporting efficient verifiable encryption (PDF)
- Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpium
- From iPhone to NT AUTHORITY\SYSTEM
- Hack could allow Windows 7 to get updates for three more years
- Microsoft Patch Tuesday by Morphus Labs
- Adobe releases their December 2019 security updates
- OpenBSD multiple authentication vulnerabilities
- Chrome releases: Stable channel update for desktop
- VMware addresses ESXi issue disclosed at the Tianfu Cup hacking competition
- Binary planting with the npm CLI
- AirDoS: Remotely render any nearby iPhone or iPad unusable
- Intel’s SGX coughs up crypto keys when scientists tweak CPU voltage (PDF)
- KeyWe Smart Lock unauthorized access and traffic interception
- Blink XT2 camera system command injection flaws
- How hackers are breaking into Ring cameras
- Story of the year 2019: Cities under ransomware siege
- Ryuk Ransomware decryptor damages larger files, even if you pay
- Zeppelin: Russian ransomware targets high profile users in the U.S. and Europe
- Snatch ransomware reboots PCs into Safe Mode to bypass protection
- The quiet evolution of phishing
- Phishing campaign uses malicious Office 365 app
- A successful BEC leveraging lookalike domains
- From a TrickBot infection to the discovery of the Anchor malware
- How the TrickBot group united high-tech crimeware & APT
- GALLIUM: Targeting global telecom
- Waterbear is back, uses API hooking to evade security product detection
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.