Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- US judge finds Israel’s NSO Group liable for hacking in WhatsApp lawsuit
- Ireland fines Meta $264 million over 2018 Facebook data breach
- WIRED: The worst hacks of 2024
- Inside Operation Destabilise: How a ransomware investigation linked Russian money laundering and street-level drug dealing
- European Space Agency’s official store hacked to steal payment cards
- US adds 9th telecom company to list of known Salt Typhoon targets
- FBI links North Korean hackers to $308 million crypto heist
- Japan Airlines resumes operations after cyberattack delays flights
- Rydox cybercrime marketplace shut down and three administrators arrested
- US seeks extradition of alleged LockBit ransomware developer from Israel
- Google fights back: proposes to limit default search agreements, wants to avoid selling Chrome
For the more technical
- Apache fixed a critical SQL Injection in Apache Traffic Control
- Resolved multiple vulnerabilities in Sophos Firewall
- Hackers exploit DoS flaw to disable Palo Alto Networks firewalls
- Adobe warns of critical ColdFusion bug with PoC exploit code
- Kali Linux 2024.4 release (Python 3.12, goodbye i386, Raspberry Pi Imager & Kali NetHunter)
- Now you see me, now you don’t: Using LLMs to obfuscate malicious JavaScript
- Best-of-N jailbreaking (PDF)
- Analyzing malicious intent in Python code: A case study
- npm packages from Rspack, Vant compromised
- Getting a taste of your own medicine: Threat actor MUT-1244 targets offensive actors, leaking hundreds of thousands of credentials
- Multiple critical vulnerabilities patched in WPLMS and VibeBP plugins
- DigiEver fix that IoT thing
- Badbox botnet is back
- DrayTek routers exploited in massive ransomware campaign: Analysis and recommendations
- HiatusRAT actors targeting web cameras and DVRs
- Phishing platform Rockstar 2FA trips, and “FlowerStorm” picks up the pieces
- “DeceptionAds” — fake captcha driving infostealer infections and a glimpse to the dark side of Internet advertising
- Python-based NodeStealer version targets Facebook Ads Manager
- ESET Threat Report H2 2024
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.