Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OSINT uphill – open sources of information and the spectrum of their availability
- Action against digital skimming reveals 443 compromised online merchants
- Lockbit ransomware disrupts emergency care at German hospitals
- Panasonic discloses data breach after December 2022 cyberattack
- Google settles $5 billion consumer privacy lawsuit
- NY Times sues OpenAI, Microsoft for infringing copyrighted works
For the more technical
- [VIDEO] Breaking “DRM” in Polish trains. Reverse engineering a train to analyze a suspicious malfunction
- [VIDEO] SMTP smuggling – spoofing e-mails worldwide
- Session-based vs. token-based authentication: Which is better?
- SonicWall discovers critical Apache OFBiz zero-day
- Barracuda fixes new ESG zero-day exploited by Chinese hackers
- Microsoft: Financially motivated threat actors misusing App Installer
- [VIDEO] Operation Triangulation: What you get when attack iPhones of researchers
- Operation Triangulation: The last (hardware) mystery
- [VIDEO] All cops are broadcasting. TETRA unlocked after decades in the shadows
- Annual Payment Fraud Intelligence Report: 2023
- MITRE launches critical infrastructure threat model framework
- Behind the scenes: JaskaGO’s coordinated strike on macOS and Windows
- Steam game mod breached to push password-stealing malware
- Analysis of attacks that install scanners on Linux SSH servers
- Exploiting monitoring and service mesh configurations and privileges in GKE to gain unauthorized access in Kubernetes
- MageCart WordPress plugin injects malicious user & credit card skimmer
- Stealth backdoor “Android/Xamalicious” actively infecting devices
- New malware found in analysis of Russian hacks on Ukraine, Poland
- Trend analysis on Kimsuky group’s attacks using AppleSeed
- A detailed analysis of the Menorah malware used by APT34
- Operation RusticWeb targets Indian Govt: From Rust-based malware to Web-service exfiltration
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.