Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Which countries have the worst (and best) cybersecurity?
- Meet the amateur astronomers hunting for spy satellites
- Undercover spy exposed in NYC was 1 of many
- Hal Martin’s OPSEC audited using public DBs
- Inside the secret Facebook war for Mormon hearts and minds
- Netflix has saved every choice you’ve ever made in ‘Black Mirror: Bandersnatch’
- 617 million accounts stolen from 16 hacked websites now for sale on dark web + more information
- Russia to disconnect from the internet as part of a planned test
- Bank of Valletta resumes operations after major cyber attack
- MalwareTech loses bid to suppress damning statements made after days of partying
- Bomb threat hoaxer exposed by hacked gaming site
- Google Vulnerability Reward Program: Year in review
- A story about a feature in Windows called ASLR
For the more technical
- RunC vulnerability gives attackers root access on Docker, Kubernetes hosts
- Escape from Docker and Kubernetes containers to root on host
- Microsoft February 2019 Patch Tuesday
- Windows DHCP server remote code execution vulnerability
- If you use Skype, your contacts may now be exposed
- Spying on Safari in Mojave
- WordPress plugin ‘Simple Social Buttons’ critical security bug
- Global security update availability for smartphones
- Adobe Acrobat Reader DC text field remote code execution vulnerability
- Privilege escalation in Ubuntu Linux (dirty_sock exploit)
- Snapd flaw lets attackers gain root access on Linux systems
- Understanding Ubiquiti discovery service exposures
- Many ICS vulnerability advisories contain errors (PDF)
- Major security breach found in hospital and supermarket refrigeration systems
- Achieving remote code execution on a Chinese IP camera
- Word-based malware attack
- Practical enclave malware with Intel SGX (PDF)
- New Astaroth trojan variant exploits anti-malware software to steal info
- Windows app runs on Mac, downloads info stealer and adware
- How Google fought bad apps and malicious developers in 2018
- QNAP NAS user? You’d better check your hosts file for mystery anti-antivirus entries
- TrickBot adds remote application credential-grabbing capabilities to its repertoire
- Scarlet Widow: Nigeria-based romance scam operation (PDF)
- Weird phishing campaign uses links with almost 1,000 characters
- BEC actors exploiting Gmail “dot accounts” for fun and profit
- DNS manipulation in Venezuela in regards to the humanitarian aid campaign
- Attack at email provider wipes out almost two decades’ worth of data
- Pwning WPA/WPA2 networks with Bettercap and the PMKID client-less attack
- New zombie ‘POODLE’ attack bred from TLS flaw
- New offensive USB cable allows remote attacks over WiFi
- Data Breach QuickView Report (PDF)
- E-voting public intrusion test
- Ad IDs behaving badly
- Videos from the BlueHat IL 2019 conference
- Why is my perfectly good shellcode not working? Cache coherency on MIPS and ARM
- Xiaomi scooter hack enables dangerous accelerations and stops for unsuspecting riders
- Free cyber security training
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – February 16, 2019”