Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Facebook took down a China-linked COVID-19 disinformation campaign
- Hackers steal $119M from ‘Web3’ crypto project with old school attack
- When Russia helped the U.S. nab cybercriminals
- The fall of a Russian cyberexecutive who went against the Kremlin
- U.S. State Department phones hacked with Israeli company spyware
- FBI document shows what data can be obtained from encrypted messaging apps
- Former Ubiquiti employee charged with hacking and extorting company
- European Money Mule Action leads to 1 803 arrests
- Russian man sentenced for providing ‘bulletproof hosting’ for cybercriminals
- FBI says the Cuba ransomware gang made $43.9 million from ransom payments
- Russian internet watchdog announces ban of six more VPN products
For the more technical
- This shouldn’t have happened: A vulnerability postmortem
- Micropatching unpatched local privilege escalation in Mobile Device Management Service (CVE-2021-24084 / 0day)
- Multiple security vulnerabilities fixed in Hide My WP by wpWave
- Researchers discover 14 new data-stealing web browser attacks
- Concluding Project Memoria – Lessons learned after 18 Months of vulnerability research (PDF)
- DNS cache poisoning attack: Resurrections with side channels (PDF)
- Hackers welcome: Major security test uncovers vulnerabilities in all common Wi-Fi routers
- 8-year-old HP printer vulnerability affects 150 printer models
- A mysterious threat actor is running hundreds of malicious Tor relays
- Microsoft Defender scares admins with Emotet false positives
- EwDoor botnet is attacking AT&T customers
- Smishing botnets going viral in Iran
- 300.000+ infections via droppers on Google Play store
- Scammers exploit Omicron fears in new COVID‑19 phishing campaign
- ProxyShell exploitation leads to BlackByte ransomware
- ScarCruft surveilling North Korean defectors and human rights activists
- APT expands attack on ManageEngine with active campaign against ServiceDesk Plus
- NginRAT parasite targets Nginx
- Injection is the New Black: Novel RTF Template Inject technique poised for widespread adoption beyond APT actors
- Triple threat: North Korea-aligned TA406 scams, spies, and steals (PDF)
- APT annual review 2021
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.