Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security related news in one place, for your reading pleasure. Enjoy!
A bit less technical
- Story of the ransomware attack on San Francisco Municipal Transportation Agency
- Quick service restoration and no ransom payed in SF
- Hacker responsible for the attack got himself hacked
- Carleton University victim of ransomware attack
- Customers of Liechtenstein bank blackmailed by hackers
- Zynga sues 2 former employees over alleged massive data heist
- Strange story around Riseup warrant canary
- Another corrupt agent might have been involved in the Silkroad case
- British National Lottery accounts hacked
- US border agents search journalist’s phone
- Apparent leak of xHamster users data
- Japanese miliatry newtorks hacked – or not
- On vulnerability disclosure
- DDoS attack on European Commission
- Cocaine Counter Intelligence
- Classified Europol files found via Shodan
- Security, cyber and elections: part 1, part 2, part 3
A bit more technical
- In-depth analysis of a huge Android malware campaign and a comment by Android chief of security
- Huge law enforcement operation against a criminal network
- New Mirai and Deutsche Telekom:
- Analysis of a large Mirai botnet
- Almost 1 mln customers in Germany suffer from Mirai – related incident
- Deutsche Telekom statement on Mirai incident
- Deutsche Telekom router firmware analysis and testing
- Mirai bot static and dynamic analysis
- Analysis of Mirai attack by Fox-IT
- Analysis of Mirai attack by Securelist
- Analysis of Mirai attack by SANS
- Analysis of Mirai attack by IBM
- Interview with alleged Mirai botmasters
- Firefox 0day
- Shamoon attacks return
- Basics of ARM/MIPS malware analysis
- MD5 collisions in malware analysis and tools
- Owning Microsoft Azure Red Hat Update Infrastructure
- Description of successful penetration testing in a casino
- About Chrome on Windows and exploit mitigation
- Real world example of 64-bit exploit development
- NetWire RAT used to steal payment card data
- Blind RCE on Facebook
- Pwning coworkers with LaTeX
- Analysis of Cerber ransomware campaign
- Gatak trojan horse delivered with keygens
- CyberChef – universal crypto convereter
- Trading in compromised remote desktop services
- Acquisition of a locked iPhone with a lockdown record
- Malicious code and the Windows integrity mechanism
- Microsoft silently fixes Windows kernel bug
- On SMS 2FA security
- Bypassing CSP using polyglot JPEGs
- Analysis of Proteus bot
- [PDF] Security analysis of implantable cardiac defibrillators
- OSS-Fuzz: continuous fuzzing for open source software
- Analysis of multiple vulnerabilities in AirDroid
- SmsSecurity Android malware analysis
- Malicious document analysis from macro to shellcode
- FreePBX 13: from XSS to RCE
- Bypassing supervisor password on ThinkPads
- Hacking Paypal OAuth tokens
- Side channel attack via sound of the fan
- Analysis of a Hancitor campaign
- [VIDEO] BSides Las Vegas
- Juniper answers to BlackNurse threat
- Rooting an appliance
- Tricky authentication bypass at ubnt.com
- Priviledge escalation in Android
If you found it useful, don’t miss next week’s edition – subscribe to one of our feeds on Twitter, Facebook or RSS.