Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Dutch man sabotaged Iranian nuclear program without Dutch government’s knowledge
- AirDrop ‘cracked’ by chinese authorities to identify senders
- Video piracy visits rose to 141 billion in 2023, report shows
- Member of notorious international hacking crew sentenced to prison
For the more technical
- Microsoft January 2024 Patch Tuesday
- Microsoft shares script to update Windows 10 WinRE with BitLocker fixes
- CVE-2023-36025 exploited for defense evasion in Phemedrone stealer campaign
- Vulnerabilities on Bosch Rexroth nutrunners may be abused to stop production lines, tamper with safety-critical tightenings
- Active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN
- Cutting Edge: Suspected APT targets Ivanti Connect Secure VPN in new zero-day exploitation
- Cisco Unity Connection unauthenticated arbitrary file upload vulnerability
- New RE#TURGENCE attack campaign: Turkish hackers target MSSQL servers to deliver domain-wide MIMIC ransomware
- Juniper warns of critical RCE bug in its firewalls and switches
- Google: Malware abusing API is standard token theft, not an API issue
- Type juggling leads to two vulnerabilities in POST SMTP Mailer WordPress plugin
- Thousands of sites with Popup Builder compromised by Balada Injector
- Joomla! vulnerability is being actively exploited
- New Year with new PE-bear, release 0.6.7 is ready
- AsyncRAT loader: Obfuscation, DGAs, decoys and Govno
- From gamer to malware developer: Exploring Silver RAT and its Syrian roots
- Deceptive cracked software spreads Lumma variant on YouTube
- Atomic Stealer rings in the new year with updated version
- Black Basta-affiliated Water Curupira’s Pikabot spam campaign
- New decryptor for Babuk Tortilla ransomware variant released
- Follow-on extortion campaign targeting victims of Akira and Royal ransomware
- Exploring FBot: Python-based malware targeting cloud and payment services
- Hundreds of thousands of dollars worth of Solana cryptocurrency assets stolen in recent CLINKSINK drainer campaigns
- Russian language cybercriminal forums – an excursion into the core of the underground ecosystem
- Russian language cybercriminal forums – steep investments and hefty profits
- You had me at hi — Mirai-based NoaBot makes an appearance
- Turkish espionage campaigns in the Netherlands
- “Homeland Justice” targets Albanian organizations with “No-justice” wiper
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.