Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Changes in third-party content on European news websites after GDPR (PDF)
- On ghost users and messaging backdoors
- Indian government to intercept, monitor, and decrypt citizens’ computers
- China hacked HPE, IBM and then attacked clients
- Feds charge three in mass seizure of attack-for-hire services + more information
- European Union diplomatic communications ‘targeted by hackers’
- Potential personally identifiable information compromise of NASA servers
- Twitter’s support form hit by data breach
- Hackers deface Wall Street Journal with pro-PewDiePie message
- If you are not paying for it, you’re not the customer; you’re the product being sold
- Amazon error allowed Alexa user to eavesdrop on another home
- At Blind, a security lapse revealed private complaints from Silicon Valley employees
- Turning off Facebook location tracking doesn’t stop it from tracking your location
- This cybersecurity firm listens to the background ‘noise’ of the Internet
- Oops! EU Piracy Watchlist includes a perfectly legal site
For the more technical
- Getting an MD5 collision is is now trivial and instant
- Banking-grade credential stuffing: The futility of partial password validation
- Yet another text CAPTCHA solver (PDF)
- Researchers slam Hola VPN over absent encryption, user IP leaks
- Microsoft issues emergency update to fix critical IE flaw under active exploit
- Hacker discloses new unpatched Windows zero-day exploit on Twitter
- SQLite “Magellan” bug affects Chrome-based browsers, thousands of apps
- An inside look at two Jenkins security vulnerabilities
- Privilege escalation flaw discovered in the Cisco Adaptive Security Appliance
- $3k bug bounty – Twitter’s OAuth mistakes
- Reading ASP secrets for $17,000
- Exploiting an 18 year old bug
- Remotely controlled EV home chargers – the threats and vulnerabilities
- Remotely bricking a server
- BadUSB embedded into a USB cable
- US Ballistic Missile Defense System riddled with security flaws (PDF)
- A review of malware affecting macOS in 2018
- Android wallpaper apps found running ad fraud scheme
- Android SMS stealer
- Decrypting HiddenTear ransomware for free with HT Brute Forcer
- Inside of Danderspritz post-exploitation modules
- Cybercriminals use malicious memes that communicate with malware
- Connecting the dots between recently active cryptominers
- Sandboxed malware may control your pasteboard
- Signing phishing mails to fake trust
- Widespread Apple ID phishing attack pretends to be App Store receipts
- Large campaigns of phishing attacks in Middle East and North Africa
- With Mirai comes Miori: IoT botnet delivered via ThinkPHP remote code execution exploit
- APT33 may be behind a series of intrusions within the engineering industry
- A new method for decrypting WhatsApp backups
- Six ways to decrypt iPhone passwords from the keychain
- Android Pie à la mode: security & privacy
- Microsoft unveils Windows Sandbox
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – December 22, 2018”