Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Google illegally spied on workers before firing them, US labor board alleges
- DHS plans to start collecting eye scans and DNA — with the help of defense contractors
- Hacker collective member who made online threats against schools and airline sentenced to nearly 8 years in federal prison
- California hacker who stole proprietary information from Nintendo sentenced to three years in prison
- Ransomware attack cripples Vancouver public transportation agency
- CBS Last.fm fixes admin password leakage via Symfony profiler
For the more technical
- Vulnerability in Google Play Core Library remains unpatched in Google Play applications
- An iOS zero-click radio proximity exploit odyssey
- Bug or feature: Privilege escalation in Windows Autopilot
- GitHub: Securing the world’s software (PDF)
- Industry’s first dynamic analysis of 4 million publicly available Docker hub container images (PDF)
- Blackrota, a heavily obfuscated backdoor written in Go
- Remote code execution on Basecamp.com
- There’s a RAT in my code: new npm malware with Bladabindi trojan spotted
- Etherify 3 – the PI 4’s dirty little secret
- Etherify 4 – back to earth with “normal” ethernet hardware
- Forensically sound cold system analysis
- ESET’s Cybersecurity Trends 2021 (PDF)
- The chronicles of Emotet
- German users targeted with Gootkit banker or REvil ransomware
- Turla Crutch: Keeping the “back door” open
- Bandook: Signed & delivered
- TrickBot now offers ‘TrickBoot’: Persist, brick, profit
- What did DeathStalker hide between two ferns?
- Evilginx-ing into the cloud: How we detected a red team attack in AWS
- DarkIRC bot exploits recent Oracle WebLogic vulnerability
- Global phishing campaign targeting the COVID-19 vaccine cold chain
- Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them
- APT annual review: What the world’s threat actors got up to in 2020
- Uncovering the clients of cyberespionage firm Circles
- Dox, steal, reveal. Where does your personal data end up?
- Covid is causing shipping issues, but natural competitive forces are causing darknet market consolidatio
- Deep dive into an obfuscation-as-a-service for Android malware
- Payment skimmer hides in social media buttons
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.