Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- Apple engineers have a proposal to standardize two-factor authentication messages, and Google is on board
- Protecting SMS messages used in critical business processes
- Indian airline breach impacts 1.2m passengers
- AdultFriendFinder network hack exposes 412 million accounts
- Researchers found a list of Electronic Arts’ Slack channels
- Dutch university paid $220,000 ransom to hackers after Christmas attack
- Sodinokibi ransomware threatens to publish data of Automotive Group
- China, desperate to stop coronavirus, turns neighbor against neighbor
- Facebook’s ‘Clear History’ tool doesn’t clear shit
- I asked Tinder for my data. It sent me 800 pages of my deepest, darkest secrets
- Some Google Photos videos in ‘Takeout’ backups were sent to strangers last November
For the more technical
- Direct memory access attacks – a walk down memory lane
- Cisco patches critical CDP flaws affecting millions of devices (PDF)
- LPE and RCE in OpenSMTPD (CVE-2020-7247)
- Remote cloud execution – critical vulnerabilities in Azure cloud infrastructure – part I & II
- Leaked code from Docker Registries
- Critical security flaw found in WhatsApp desktop platform allowing cybercriminals read From the file system access
- A critical flaw in Trezor hardware wallets
- Critical Bluetooth vulnerability in Android (CVE-2020-0022) – BlueFrag
- Android Security Bulletin – February 2020
- The dark side of smart lighting
- Full disclosure: 0day vulnerability (backdoor) in firmware for HiSilicon-based DVRs, NVRs and IP cameras
- A critical vulnerability in TeamViewer
- Dropbox bug bounty program has paid out over $1,000,000
- Genesis market 2020 overview, a bazaar for buying data out of compromised computers
- Forging SWIFT MT Payment Messages for fun and pr… research
- Linear eMerge E3 access controller actively being exploited
- Windows app runs on Mac, downloads info stealer and adware
- Malicious optimizer and utility Android apps on Google Play communicate with trojans that install malware, perform mobile ad fraud
- STOMP 2 DIS: Brilliance in the (Visual) Basics
- Mysterious new ransomware targets industrial control systems
- Ransomware borrows vulnerable driver to remove security software
- New EmoCheck tool checks if you’re infected with Emotet
- Winnti Group targeting universities in Hong Kong
- Reverse engineering my router’s firmware with binwalk
- Kali Linux 2020.1 release
- Deanonymizing Tor circuits
- Apple vs law enforcement: Cloudy times
- Protecting users from insecure downloads in Google Chrome
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.