Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- India bans 54 Chinese apps on security concerns
- People whose NFTs were stolen are getting wildly different refunds from OpenSea
- Jobfished: the con that tricked dozens into working for a fake design agency
- Expeditors shuts down global operations after likely ransomware attack
For the more technical
- A command injection vulnerability in the web server of some Hikvision product
- Cracking a $2 million crypto wallet + video
- Oh Snap! More lemmings: Local privilege escalation vulnerability discovered in snap-confine (CVE-2021-44731)
- Horde Webmail 5.2.22 – Account takeover via email
- Gremlin – PDF cracker with PESEL passwords
- “Zero-days” without incident – compromising Angular via expired npm publisher email domains
- New malware capable of controlling social media accounts infects 5,000+ machines
- Mobile malware evolution 2021
- Xenomorph: A newly hatched banking trojan
- Financial cyberthreats in 2021
- The TrickBot saga’s finale has aired: Spinoff is already in the works
- TrickBot gang shuts down botnet after months of inactivity
- China implicated in prolonged supply chain attack targeting Taiwan financial sector
- The Bvp47 – a top-tier backdoor of US NSA Equation Group (PDF)
- Modified CryptBot infostealer being distributed
- Detecting Karakurt – an extortion focused threat actor
- Cyclops Blink: Malware analysis report (PDF)
- New Sandworm malware Cyclops Blink replaces VPNFilter (PDF)
- Dragos’s annual ICS/OT Cybersecurity Year in Review
- (Ex)change of pace: UNC2596 observed leveraging vulnerabilities to deploy Cuba ransomware
- Cobalt Strike being distributed to vulnerable MS-SQL servers
- HermeticWiper – new destructive malware used in cyber attacks on Ukraine
- Ukraine: Disk-wiping attacks precede Russian invasion
- EvilPlayout: Attack against Iran’s state broadcaster
- Iranian government-sponsored actors conduct cyber operations against global government and commercial networks
- CISA: Free cybersecurity services and tools
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.