Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- FAA meltdown injected uncertainty, including for military pilots
- PayPal accounts breached in large-scale credential stuffing attack
- NortonLifeLock warns that hackers breached Password Manager accounts
- Mailchimp says it was hacked — again
- Founder and majority owner of cryptocurrency exchange charged with processing over $700 million of illicit funds
- It looked like a nice family home. Cops suspect it was a secret drone airport for MDMA dropoffs
- Industrial espionage: How China sneaks out America’s technology secrets
- The FBI won’t say whether it hacked dark web ISIS site
- College kid swarmed by cops with tasers after falling for pizza scam on Twitter
- Hacker Guccifer launched Clinton email scandal out of prison
For the more technical
- MSI accidentally breaks Secure Boot for hundreds of motherboards
- ManageEngine CVE-2022-47966 technical deep dive + PoC
- Oracle Critical Patch Update Advisory – January 2023
- Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2
- Netcomm – Unauthenticated Remote Code Execution
- Assessing potential exploitation of Sophos Firewall and CVE-2022-3236
- CVE-2022-3236: Sophos Firewall User Portal and Web Admin code injection
- Suspected Chinese threat actors exploiting FortiOS vulnerability (CVE-2022-42475)
- AWS CloudTrail vulnerability: Undocumented API allows CloudTrail bypass
- Vendors defeat Magento security patch (+ simple check)
- Scattered Spider exploits Windows security deficiencies with bring-your-own-vulnerable-driver tactic in attempt to bypass endpoint security
- Illegal Solaris darknet market hijacked by competitor Kraken
- Solaris – Russian drug platform exposed
- Talos Year in Review 2022
- Abusing a GitHub Codespaces feature for malware delivery
- Hook: a new Ermac fork with RAT capabilities
- Ransomware Diaries: Volume 1
- Batloader malware abuses legitimate tools, uses obfuscated JavaScript files in Q4 2022 attacks
- Heads up! Xdr33, A variant of CIA’s HIVE attack kit emerges
- Uncovering Iran’s mobile legal intercept system
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.