Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Google Pixel bug prevented users from calling 911
- A South Korean city will test facial recognition as a way to track the virus
- Taking action against the surveillance-for-hire industry (PDF)
- Russian national sentenced for providing crypting service for Kelihos botnet
For the more technical
- Log4Shell log4j vulnerability (CVE-2021-44228 / CVE-2021-45046) – cheat-sheet reference guide
- The numbers behind Log4j vulnerability CVE-2021-44228
- Ten families of malicious samples are spreading using the Log4j2 vulnerability now
- Zero-day critical vulnerability in Log4j2 exploited in the wild
- Analysis of novel Khonsari ransomware deployed by the Log4Shell vulnerability
- Ransomware advisory: Log4Shell exploitation for initial access & lateral movement
- Log4j vulnerability: Attackers shift focus from LDAP to RMI
- Owowa: the add-on that turns your OWA into a credential stealer and remote access panel
- CVE-2021-42287/CVE-2021-42278 weaponisation
- The December 2021 security update review
- Microsoft fixes Windows AppX Installer zero-day used by Emotet
- A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
- HackerOne: Software vulnerabilities increase by 20% in 2021
- [VIDEO] mXSS in 2021 – One long solved problem?
- The definitive guide to SSH tunneling, port redirection, and bending traffic like a boss (PDF)
- Avast finds backdoor on US government commission network
- 3 new malicious packages found on PyPI
- Conti cyber attack on the HSE (PDF)
- Anubis Android malware returns to target 394 financial apps
- The dirty dozen of Latin America: From Amavaldo to Zumanek
- Staging a quack: Reverse analyzing a fileless QAKBOT stager
- PseudoManuscrypt: a mass-scale spyware attack campaign
- Phishing campaign targeting Korean to deliver Agent Tesla new variant
- APT31: Pakdoor. Technical report (PDF)
- Espionage campaign targets telecoms organizations across Middle East and Asia
- Nation state threat group targets airline with Aclip backdoor
- Tropic Trooper targets transportation and government
- Phorpiex botnet returns with new tricks making it harder to disrupt
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.