Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- How law enforcement gets around your smartphone’s encryption
- U.S. schools are buying phone-hacking tech that the FBI uses to investigate terrorists
- Malware found on laptops given out by government
- Massive blackouts have hit Iran. The government is blaming bitcoin mining
- Last Dash for Joker’s Stash: Carding forum may close in 30 days
- OpenWRT reports data breach after hacker gained access to forum admin account
- Hacker leaks full database of 77 million Nitro PDF user records
- UK police warn of sextortion attempts in intimate online dating chats
- Hacker posts 1.9 million Pixlr user records for free on forum
- Brave browser takes step toward enabling a decentralized web
For the more technical
- Write-up of DOMPurify 2.0.0 bypass using mutation XSS
- Mutation XSS via namespace confusion – DOMPurify < 2.0.17 bypass
- KindleDrip – from your Kindle’s email address to using your credit card
- Windows 10 bug crashes your PC when you access this location
- Multiple vulnerabilities found in FiberHome HG6245D routers
- Take action to secure your QNAP NAS
- Microsoft Remote Desktop Protocol (RDP) reflection/amplification DDoS attack mitigation recommendations
- DNSpooq – Kaminsky attack is back
- New SAP exploit published online
- Signal, Google Duo, FB Messenger vulnerabilities allowed eavesdropping
- VPNFilter two years later: Routers still compromised
- A Chinese hacking group is stealing airline passenger details
- Abusing cloud services to fly under the radar
- What you should know before leaking a Zoom meeting
- IObit forums hacked to spread ransomware to its members
- Cyber criminals leave stolen phishing credentials in plain sight
- Raindrop: New malware discovered in SolarWinds investigation
- Deep dive into the Solorigate second-stage activation: From Sunburst to Teardrop and Raindrop
- Malwarebytes targeted by Nation State Actor implicated in SolarWinds breach
- Chaining multiple bugs for unauthenticated RCE in the SolarWinds Orion platform
- FreakOut – leveraging newest vulnerabilities for creating a botnet
- Iranian cyber actors continue to threaten US election officials
- New website launched to document vulnerabilities in malware strains
- MrbMiner: Cryptojacking to bypass international sanctions
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.