Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- OUCH! newsletter: Social media privacy (PDF)
- Signal is finally bringing its secure messaging to the masses
- How big companies spy on your emails
- Drones take to China’s skies to fight coronavirus outbreak
- Chinese military personnel charged with computer fraud, economic espionage and wire fraud for hacking into credit reporting agency Equifax (PDF)
- How the CIA used Crypto AG encryption devices to spy on countries for decades
- The war against space hackers: how the JPL works to secure its missions from nation-state adversaries
- Hackers deface Facebook’s official Twitter and Instagram accounts
- Estee Lauder exposed 440 million records online
For the more technical
- Microsoft Patch Tuesday for February 2020 + more information
- Exchange Server and SMBv1
- Windows 10 KB4532693 update bug hides user data, loads wrong profile
- Remote code execution in Microsoft SQL Server Reporting Services
- CVE-2020-0668 – A trivial privilege escalation bug in Windows Service Tracing
- Adobe releases the February 2020 security updates
- CSS data exfiltration in Firefox via a single injection point
- WordPress unzip_file path traversal
- Buffer overflow when pwfeedback is set in sudoers
- Mitigations are attack surface, too
- Unleashing Mayhem over Bluetooth Low Energy
- [VIDEO] Flare-On 2019 solutions
- Wacom drawing tablets track the name of every application that you open
- A different type of card fraud: Anatomy of a Primary Account Number (PAN) enumeration attack
- Phantom of theADAS: Phantom attacks on driver-assistance systems (PDF)
- Leaking sensitive data from air-gapped workstations via screen brightness
- Attackers abuse Bitbucket to deliver an arsenal of malware
- Malwarebytes Labs releases 2020 State of Malware Report
- Emotet evolves with new Wi-Fi spreader
- KBOT: sometimes they come back
- Security researchers partner with Chrome to take down browser extension fraud network affecting millions of users
- Android Trojan xHelper uses persistent re-infection tactics: here’s how to remove
- FBI warns about ongoing attacks against software supply chain companies
- DDoS attacks in Q4 2019
- Jenkins servers can be abused for DDoS attacks
- X-Force Threat Intelligence Index reveals Top Cybersecurity Risks of 2020
- Check Point Research’s Q4 2019 Brand Phishing Report
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.