Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- Hacker leaks passwords for more than 500,000 servers, routers, and IoT devices
- Study says Grindr, OkCupid, and Tinder breach GDPR
- PolicyLint: Investigating internal privacy policy contradictions on Google Play (PDF)
- Mitsubishi Electric discloses information leak
- Russian national pleads guilty to running online criminal marketplace
- Glenn Greenwald charged with cybercrimes in Brazil
- Top Secret documents show Cyber Command’s growing pains in its mission against ISIS
- Revealed: the Saudi heir and the alleged plot to undermine Jeff Bezos
- Ubisoft sues operators of four DDoS-for-hire services
- What are deepfakes – and how can you spot them?
- Apple dropped plan for encrypting backups after FBI complained
- Apple Transparency Report: Government and private party requests (PDF)
For the more technical
- Citrix patches CVE-2019-19781 flaw in ADC, Gateway and SD-WAN WANOP
- FireEye and Citrix tool scans for indicators of compromise related to CVE-2019-19781
- RDP to RCE: When fragmentation goes wrong
- Micropatching a workaround for CVE-2020-0674
- Easily exploitable vulnerabilities patched in WP Database Reset plugin
- “Like” at your own risk
- Netgear signed TLS cert private key disclosure
- Fortinet FortiSIEM hardcoded SSH key
- Live cyber threat maps:
- Muhstik botnet attacks Tomato routers to harvest new IoT devices
- Someone is uninstalling the Phorpiex malware from infected PCs and telling users to install an antivirus
- Fake company, real threats
- Inside the world’s highest-stakes industrial hacking contest
- Ryuk ransomware hit multiple oil & gas facilities, ICS security expert says
- EFS ransomware
- WOOF locker: Unmasking the browser locker behind a stealthy tech support scam operation
- Shlayer trojan attacks one in ten macOS users
- Yet another [almost] non-removable trojan for Android
- 250 million Microsoft customer service and support records exposed on the web
- Cannabis users’ sensitive data exposed in data breach
- LastPass is in the midst of a major outage
- A comprehensive guide on securing your system, archives and documents
- OWASP API Security Top 10 2019 (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.