Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Alleged leader of Kelvin Security hacker gang arrested in Spain
- Microsoft: Disrupting the gateway services to cybercrime
- Spammers use Epic Games website to promote ‘piracy’ scams
- Amazon sues REKK fraud gang that stole millions in illicit refunds
- Disgruntled cloud engineer sentenced to two years in prison for intentionally damaging his former employer’s computer network
For the more technical
- Russian Foreign Intelligence Service cyber actors use JetBrains TeamCity CVE in global targeting (PDF)
- Polish hackers repaired trains the manufacturer artificially bricked. Now the train company is threatening them
- State of Log4j vulnerabilities: How much did Log4Shell change?
- Decoding CVE-2023-50164: Unveiling the Apache Struts file upload exploit
- Microsoft Patch Tuesday December 2023
- iOS 17.2 update puts an end to Flipper Zero’s iPhone shenanigans
- How worried should we be about the “AutoSpill” credential leak in Android password managers?
- Avira antivirus causes Windows computers to freeze after boot
- Critical unauthenticated remote code execution found in Backup Migration plugin
- Fake CVE-2023-45124 phishing scam tricks users into installing backdoor plugin
- Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol
- Analyzing AsyncRAT’s code injection into aspnet_compiler.exe across multiple incident response cases
- What organizations need to know about Trigona ransomware
- ActiveMQ CVE-2023-46604 exploited by Kinsing
- Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
- Curse of the Krasue: New Linux remote access trojan targets Thailand
- TA4557 targets recruiters directly via email
- New underground market comes online just in time for the holidays
- Kimsuky targets South Korean research institutes with fake import declaration
- Sandman APT: China-based adversaries embrace Lua
- Press and pressure: Ransomware gangs and the media
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.