Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- CD Projekt Red source code reportedly sells for millions in dark Web auction
- Yandex suffers data breach after sysadmin sold access to user emails
- Largest commercial bank in Ukraine has 40 million user records sold online
- More than 100 financial services firms hit with DDoS extortion attacks
- Emsisoft: Incident report
- That Slack email you just got asking to reset your password is legit, not a scam
- $1 million is just the beginning: Q4 2020 in network access sales
- Feds traced Bitcoin transactions to a drug dealer’s apartment
- Ten hackers arrested for string of SIM-swapping attacks against celebrities
- How the US military used a creepy island to test cyberattacks on the grid — in the middle of a pandemic
For the more technical
- NUMBER:JACK – Forescout research labs finds nine ISN generation vulnerabilities affecting TCP/IP stacks
- Multiple security updates affecting TCP/IP: CVE-2021-24074, CVE-2021-24094, and CVE-2021-24086
- Microsoft February 2021 Patch Tuesday
- Internet Explorer 11 zero-day vulnerability gets a free micropatch
- Google Chrome vulnerability: CVE-2021-21117
- The Great Suspender Chrome extension’s fall from grace
- Launching OSV – Better vulnerability triage for open source
- Apple puts additional walls between your browsing data and Google on iOS 14.5
- Hacking Chess.com and accessing 50 million customer records
- New research reveals who’s targeted by email attacks
- New phishing attack uses Morse code to hide malicious URLs
- What’s most interesting about the Florida water system hack? That we heard about it at all
- Supercookie uses favicons to assign a unique identifier to website visitors
- How I hacked into Apple, Microsoft and dozens of other companies
- Sonatype spots 150+ malicious npm packages copying recent software supply chain attacks that hit 35 organizations
- Web shell attacks continue to rise
- PyPI, GitLab dealing with spam attacks
- Discord CDN: A popular choice for hosting malicious payloads
- Breached water plant employees used the same TeamViewer password and no firewall
- Domestic Kitten – An inside look at the Iranian surveillance operations
- ScreenConnect remote access tool utilizing Ministry of Foreign affairs-themed EXEs and URLs
- Reverse engineering Emotet
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.