Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Polish opposition duo hacked with NSO spyware + more information
- The Worst Hacks of 2021
- The Belgian government has removed ‘backdoor requirement’ from new law after international protest
- Telehealth take-up: the risks and opportunities (PDF)
- Now DuckDuckGo is building its own desktop browser
- Google Drive could soon start locking your files
- Ubisoft confirms Just Dance data breach amid developer exodus
- The NCA shares 585 million passwords with Have I Been Pwned
- Meta (Facebook) sues operators of 39,000 phishing sites
- After Joker’s Stash shutdown, the market for stolen financial data looks a lot different
- 2easy: Logs marketplace on the rise
- Dark web marketplace ToRReZ shuts down
For the more technical
- Attacks on wireless coexistence: Exploiting cross-technology performance features for inter-chip privilege escalation (PDF)
- [VIDEO] Log4j RCE vulnerability explained with bypass for the initial fix
- Understanding the impact of Apache Log4j vulnerability
- Log4Shell – The call is coming from inside the house
- Examining Log4j vulnerabilities in connected cars and charging stations
- CISA Log4j Scanner
- CrowdStrike launches free targeted Log4j search tool
- Where’s the interpreter!? (CVE-2021-30853)
- Microsoft Teams: 1 feature, 4 vulnerabilities
- Azure App Service Linux source repository exposure
- What are attackers after on IoT devices? (PDF)
- Lenovo ImController Local Privilege Escalation (CVE-2021-3922, CVE-2021-3969)
- New Dell BIOS updates cause laptops and desktops not to boot
- Faking a positive COVID test
- Audio bugging with the Fisher Price Chatter Bluetooth Telephone
- Vulnerabilities in metal detector peripheral could allow attackers to manipulate security devices
- Spider-miner: With great power comes great problems
- New Joker malware detected on Google Play, 500.000+ users affected
- Android banking trojan spreads via fake Google Play Store page
- Log4j vulnerability now used to install Dridex banking malware
- Dridex malware trolls employees with fake job termination emails
- The continued evolution of Abcbot
- DarkWatchman: A new evolution in fileless techniques
- Stealthy BLISTER malware slips in unnoticed on Windows systems
- Avos Locker remotely accesses boxes, even running in Safe Mode
- Rook ransomware is yet another spawn of the leaked Babuk code
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.