Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Lurk: an exemplary Cybercrime Inc.
- The elite hackers of the FSB
- A network of fake test answer sites is trying to incriminate students
- AI-synthesized faces are indistinguishable from real faces and more trustworthy
- Mexican businessman admits to brokering spyware used to monitor political and business rivals
- How Roblox ‘beamers’ get rich stealing from children
- BlackCat (ALPHV) claims Swissport ransomware attack, leaks data
For the more technical
- A technique to semi-automatically discover new vulnerabilities in WordPress plugins
- Vulnerability in UpdraftPlus allowed subscribers to download sensitive backups
- Emergency Magento update fixes zero-day bug exploited in attacks
- Researchers create exploit for critical Magento bug, Adobe updates advisory
- Hacker could’ve printed unlimited ‘Ether’ but chose $2M bug bounty instead
- How everything we’re told about website identity assurance is wrong
- Never, ever, ever use pixelation for redacting text
- Mozilla warns Chrome, Firefox ‘100’ user agents may break sites
- A walk through Project Zero metrics
- Introducing the Privacy Sandbox on Android
- SMS PVA services’ use of infected Android phones reveals flaws in SMS verification
- Attackers increasingly adopting regsvr32 utility execution via Office documents
- A method for decrypting data infected with Hive ransomware (PDF)
- ESET Threat Report T3 2021 (PDF)
- Threat Horizons. Cloud Threat Intelligence. February 2022 (PDF)
- Evasive Trickbot attacks customers of 60 high-profile companies
- Meet Kraken: A new Golang botnet in development
- Charting TA2541’s flight
- Cyber-attack on ICRC: What we know
- Moses Staff campaigns against Israeli organizations span several months
- Iranian-aligned threat actor “TunnelVision” actively exploiting VMware Horizon
- Russian state-sponsored cyber actors target cleared defense contractor networks
- Russian cybercriminals drive significant ransomware and cryptocurrency-based money laundering activity
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.