Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- Brave Browser and the Wayback Machine: Working together to help make the Web more useful and reliable
- Cyber attack on PM’s office, state bodies attributed to foreign spies
- Australian banks targeted by DDoS extortionists
- Former Microsoft software engineer convicted of 18 federal felonies for stealing more than $10 million in digital value such as gift cards
- Clearview’s facial recognition app has been used by the Justice Department, ICE, Macy’s, Walmart, and the NBA
- Wearing a mask won’t stop facial recognition anymore
For the more technical
- LPE and RCE in OpenSMTPD’s default install (CVE-2020-8794)
- CVE-2020-0688: Remote code execution on Microsoft Exchange Server through fixed cryptographic keys
- KrØØk: Serious vulnerability affected encryption of billion+ Wi‑Fi devices (PDF)
- Multiple vulnerabilities in Moxa AWK-3131A
- Zyxel fixes 0day in network storage devices + more information
- Ghostcat – a high-risk file read / include vulnerability in Tomcat
- A close look at 100+ patched vulnerabilities
- Google patches Chrome zero-day under active attacks
- We found 6 critical PayPal vulnerabilities – and PayPal punished us for it
- PayPal accounts are getting abused en-masse for unauthorized payments
- Active attack on recently patched Duplicator plugin vulnerability affects over 1 million sites
- Global sporting goods giant leaks Spanish employees’ data & more
- Precise location information leaking through system pasteboard
- Report identifies the most dangerous mobile app store on the internet
- Mobile malware evolution 2019
- (Ab)using bash-fu to analyze recent Aggah sample
- The Dever ransomware experience
- Sodinokibi ransomware may tip NASDAQ on attacks to hurt stock prices
- Raccoon: The story of a typical infostealer
- ‘Cloud Snooper’ attack bypasses firewall security measures
- 2020 – Year of the RAT
- Roaming Mantis: Distributed in 2019 using SMiShing and enhanced anti-researcher techniques
- Profiling of TA505 threat group
- Exploring the Genesis supply chain for fun and profit
- Fixing memory leaks in web applications
- From 0 to 1337. brief security analysis of a large service provider
- Determine a Facebook user from an email address
- DigiCert: Position on 1-year certificates
- Defeating a laptop’s BIOS password
- How to defend yourself against browser fingerprinting
- Smart vacuum security flaws may leave users exposed
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.