IT Security Weekend Catch Up – January 18, 2025

Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!

For the less technical

  1. TikTok, AliExpress, SHEIN & Co surrender Europeans’ data to authoritarian China
  2. Meta is blocking links to decentralized Instagram competitor Pixelfed
  3. Telegram shuts down Z-Library & Anna’s Archive channels over copyright infringement
  4. FBI forces Chinese malware to delete itself from thousands of US computers
  5. Russia’s largest platform for state procurement hit by cyberattack from pro-Ukraine group
  6. Latest Doom port runs inside a PDF document, but performance is limited
  7. Tetris has been crammed into a tiny 60KB PDF, works in any browser

For the more technical

  1. [VIDEO] BlinkenCity: Radio-controlling street lamps and power plants
  2. Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
  3. Microsoft January 2025 Patch Tuesday
  4. FastHTTP used in new bruteforce campaign
  5. Millions of accounts vulnerable due to Google’s OAuth flaw
  6. Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions
  7. How cracks and installers bring malware to your device
  8. How a simple DNS misconfiguration enables malware delivery by a Russian botnet
  9. The great Google Ads heist: criminals ransack advertiser accounts via fake Google ads
  10. Deep dive into a Linux rootkit malware
  11. Gootloader inside out
  12. Meduza stealer analysis: A closer look at its techniques and attack vector
  13. Sneaky 2FA: exposing a new AiTM phishing-as-a-service
  14. Double-Tap campaign: Russia-nexus APT possibly related to APT28 conducts cyber espionage on Central Asia and Kazakhstan diplomatic relations
  15. Weaponized software targets Chinese-speaking organizations

Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.

Leave a Reply

Your email address will not be published. Required fields are marked *