Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- The best stories on hacking and information security of 2018
- The bleak picture of two-factor authentication adoption in the wild
- In January, the EU starts running bug bounties on free and open source software
- Hot tub hack reveals washed-up security protection
- Doxxing pirates or even anti-pirates is no way to solve disputes
- Selling pirate movies & putting the money in a personal PayPal account is insane
- Serial swatter and stalker Mir Islam arrested for allegedly dumping body in river
For the more technical
- ZeroNights 2018 – materials
- Windows zero-day PoC lets you read any file with System level access
- Detecting use of SandboxEscaper’s “MsiAdvertiseProduct” 0-day PoC
- Cisco Prime License Manager SQL injection vulnerability
- Hacking the Twinkly IoT Christmas lights
- Hackers make a fake hand to beat vein authentication
- Remote firmware attack renders servers unbootable
- Major flaws in Guardzilla cameras allow remote hijack of the security device
- Over 19,000 Orange Livebox ADSL modems are leaking their WiFi credentials
- Wormable stored XSS on WordPress.org
- ‘Serious’ Twitter flaw allows hackers to post on other people’s accounts
- Four months after its debut, sneaky Mac malware went undetected by AV providers
- There’s a fake Amazon Alexa ‘Setup’ app climbing App Store charts
- Shamoon attackers employ new tool kit to wipe infected systems
- Modified open-source wiper contains verse from the Quran
- JungleSec ransomware infects victims through IPMI remote consoles
- Sofacy creates new ‘Go’ variant of Zebrocy tool
- Progression of APT28/Sofacy Golang Zebrocy loader ‘Project2.Go’: WMIC & hex decode
- Analysis of the latest Emotet propagation campaign
- Season’s greetings from Ursnif
- Dissecting the Danabot paylaod targeting Italy
- Matryoshka phish
- Threats of terror pervade recent extortion phishing campaigns
- Three-year campaign targets Russian critical infrastructure
- Hacking group “Charming Kitten” targets nuclear experts and Treasury officials
- Chinese malicious cyber activity
- The MITRE ATT&CK framework
- Head-to-head evaluation of six password managers
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – December 29, 2018”