Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Save the Children Foundation duped by hackers into paying out $1 million
- Hacker banner ads are totally wild
- Fraudster convicted of online banking thefts using a bizarre homemade device
- Spammed bomb threat hoax demands Bitcoin
- We broke into a bunch of Android phones with a 3D-printed head
- Facebook, under scrutiny, pays out largest bug bounty yet
- Over 40,000 credentials for government portals found online
- Widespread blurring of satellite images reveals secret facilities
- Super Micro says review found no malicious chips in motherboards
- What’s actually in Australia’s encryption laws? Everything you need to know
- Signal says it can’t allow government access to users’ chats
- The truth about Black Friday and Cyber Monday
For the more technical
- 50 CVEs in 50 days: Fuzzing Adobe Reader
- Adobe’s year-end update patches 87 flaws in Acrobat software
- The December 2018 security update review
- Zero-day in Windows Kernel Transaction Manager
- A bug in Microsoft’s login system made it easy to hijack anyone’s Office account
- Google will shut down Google+ four months early after second data leak
- How I could have stolen your photos from Google
- Facebook Photo API bug exposed pics of up to 6.8 million users
- WordPress plugs bug that led to Google indexing some user passwords
- Samsung bug allowed full takeover of user accounts
- Remote code execution vulnerability in SQLite
- Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
- Tildeb: Analyzing the 18-year-old implant from the Shadow Brokers’ leak
- How side-channel attacks can compromise privacy in WhatsApp, Telegram, and Signal
- Vulnerability in Logitech Options
- New exploit kit “Novidade” found targeting home and SOHO routers
- Demystifying Kubernetes CVE-2018-1002105 (and a dead simple exploit)
- FreeRTOS TCP/IP stack vulnerabilities – the details
- Serious vulnerability in Rockwell Automation PLCs
- Critical vulnerabilities in Siemens SINUMERIK controllers
- Owning the Virgin Media Hub 3.0: The perfect place for a backdoor
- How to steal private information from a mobile device using a powerbank
- The guidelines on cyber security onboard ships (PDF)
- IoT Security in the ‘Smart Manufacturing’ world: a new study by ENISA
- Abandoned Globelmposter TOR site leaves ransomware victims without options
- MHT file inside a ZIP file
- Shamoon 3 targets oil and gas organization + more information
- Operation Sharpshooter – campaign targets global defense, critical infrastructure (PDF)
- The latest wave of organized phishing attacks by Iranian state-backed hackers + additional information
- Dear Joohn: The Sofacy group’s global campaign
- The Dark Side of the ForSSHe: A landscape of OpenSSH backdoors (PDF)
- Emotet trojan is back with a vengeance
- Android malware steals money from PayPal accounts
- The evolution of Microsoft Threat Protection, December update
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – December 15, 2018”