Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Edward Snowden’s book profits must go to the government, judge rules
- Are you one of Avast’s 400 million users? This is why it collects and sells your web habits
- More than 38,000 people will stand in line this week to get a new password
- ‘Inconsistent and misleading’ – research suggests password meters could increase risk of cyber attacks
- Apple opens public bug bounty program, publishes official rules
- Thief stole payroll data of 29,000 Facebook employees
- Report: 267 million Facebook users IDs and phone numbers exposed online
- What do “password” and President Trump have in common? Both lost ranking on SplashData’s Annual Worst Passwords List
- Removing coordinated inauthentic behavior from Georgia, Vietnam and the US
- British hacker accused of blackmailing healthcare firms extradited to U.S.
- The dark world of online murder markets
- Meet the mad scientist who wrote the book on how to hunt hackers
For the more technical
- Vulnerability related to processing of archive files patched in Drupal
- Privilege escalation flaws found in preinstalled Acer, ASUS software
- Multiple vulnerabilities in SPPA-T3000 components
- TP-Link Archer router vulnerability voids admin password, can allow remote takeover
- Multiple vulnerabilities in WAGO PFC200
- BreakingApp – WhatsApp crash & data loss bug
- Microsoft SharePoint Server information disclosure vulnerability
- Multiple vulnerabilities in Barco ClickShare
- Abusing feature to steal your tokens
- Hacking GitHub with Unicode’s dotless ‘i’
- Your workmates might still be reading that ‘unshared’ Slack document
- It’s time to disconnect RDP from the internet
- Seasons greetings: Now install my malware…
- Untangling Legion Loader’s hornet nest of malware
- Buer Loader, new Russian loader on the market with interesting persistence
- Lazarus hackers target Linux, Windows with new Dacls malware
- Dacls, the Dual platform RAT
- Say hello to Bottle Exploit Kit targeting Japan
- New Echobot variant exploits 77 remote code execution flaws
- The year of the phish
- APT campaign targets Korean industrial companies
- Shining a light on one of China’s hidden hacking groups (PDF)
- One in every 172 active RSA certificates are vulnerable to attack
- BFU extraction: Forensic analysis of locked and disabled iPhones
- Apple platform security guide (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.