Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Predicting dementia from spontaneous speech using large language models
- Deployment dashboards for key Internet standards in the EU
- Twitter rival Mastodon rejects funding to preserve nonprofit status
- Microsoft fined $64 million in France over advertising cookies
- North Korea hacked almost 900 South Korean foreign policy experts, sought ransom
- Hackers stole data from multiple electric utilities in recent ransomware attack
- Port of Lisbon website still down as LockBit gang claims cyberattack
- Personal data from 270,000 patients was leaked in Louisiana hospital cyberattack
- Canada’s largest children’s hospital struggles to recover from pre-Christmas ransomware attack
- How biometric devices are putting Afghans in danger
- Police in China can track protests by enabling ‘alarms’ on Hikvision software
- They called 911 for help. Police and prosecutors used a new junk science to decide they were liars
For the more technical
- CVE-2022-27510, CVE-2022-27518 – Measuring Citrix ADC & Gateway version adoption on the Internet
- ENLBufferPwn (CVE-2022-47949)
- Netgear warns users to patch recently fixed WiFi router bug
- Malware, ransomware analysis and a lot of fun with reverse engineering
- XLLing in Excel – threat actors using malicious add-ins
- Password managers by Tavis Ormandy
- Turning Google smart speakers into wiretaps for $100k
- EarSpy: Spying Caller Speech and Identity through Tiny Vibrations of Smartphone Ear Speakers (PDF)
- OpwnAI: AI that can save the day or HACK it away
- “MasquerAds” — Google’s Ad-Words massively abused by threat actors, targeting organizations, GPUs and crypto wallets
- IcedID botnet distributors abuse Google PPC to distribute malware
- New ransomware strains emerging from leaked Conti’s source code
- New stealer variants in burgeoning PyPI supply chain attack
- New RisePro Stealer distributed by the prominent PrivateLoader
- GuLoader dissection reveals new anti-analysis techniques and code injection redundancy
- Cybersecurity threatscape: Q3 2022
- Hackers steal $8 million from users running trojanized BitKeep apps
- The scammers who scam scammers on cybercrime forums: Part 1, Part 2, Part 3, Part 4
- Inside Roblox’s criminal underworld, where kids are scamming kids
- New Steppy#Kavach attack campaign likely targeting Indian government
- BlueNoroff introduces new methods bypassing MoTW
- Fin7 Unveiled: A deep dive into notorious cybercrime gang (PDF)
- Investigation of North Korean APT’s large-scale phishing attack on NFT users
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.