Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- The US blames Russia’s GRU for sweeping cyberattacks in Georgia
- Details of 10.6 million MGM hotel guests posted on a hacking forum
- Slickwraps data breach exposes financial and customer info
- IOTA cryptocurrency shuts down entire network after wallet hack
- How Saudi Arabia infiltrated Twitter
- Pay up, or we’ll make Google ban your ads
For the more technical
- CVE-2020-0618: RCE in SQL Server Reporting Services (SSRS)
- Proof of concept for Microsoft SQL Server Reporting Services vulnerability available + PoC
- The mess behind Microsoft’s yanked UEFI patch KB 4524244
- Windows 10 KB4532693 update bug reportedly deletes user files
- Microsoft has a subdomain hijacking problem
- Hackers were inside Citrix for five months
- Cacti v1.2.8 authenticated Remote Code Execution (CVE-2020-8813)
- IMP4GT: Impersonation attacks in 4G networks
- 2019 Year End Report – Vulnerability QuickView (PDF)
- Security analysis of the Solo firmware
- The hidden dangers inside Windows & Linux computers
- AZORult spreads as a fake ProtonVPN installer
- Ransomware impacting pipeline operations
- Croatia’s largest petrol station chain impacted by cyber-attack
- Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world
- Chinese hackers have breached online betting and gambling sites
- Active C2 discovery using protocol emulation (Winnti 4.0)
- Weaponized WordPress themes & plugins
- Critical issue in ThemeGrill Demo Importer leads to database wipe and auth bypass
- Disruptive ads enforcement and our new approac
- Pokémon GO OSINT techniques
- Pen testing ships. A year in review
- What happened to DNStats.net?
- iPhone acquisition without a jailbreak (iOS 11 and 12)
- Model hacking ADAS to pave safer roads for autonomous vehicles
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.