Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Tor Project appeals Russian court’s decision to block access to Tor
- Let’s Encrypt is revoking lots of SSL certificates in two days
- Google kills FLoC & will stick with cookies because of privacy complaints
- Apple’s AirTag uncovers a secret German intelligence agency
- Finland says it found NSO’s Pegasus spyware on diplomats’ phones
- Searching for Susy Thunder
- DeepDotWeb administrator sentenced for money laundering scheme
- Conti ransomware hits Apple, Tesla supplier
- Hacktivist group shares details related to Belarusian Railways hack
For the more technical
- Attacking RDP from Inside: How we abused named pipes for smart-card hijacking, unauthorized file system access to client machines and more
- Hacking the Apple Webcam (again)
- Apple: Personal Safety User Guide (PDF)
- A bug lurking for 12 years gives attackers root on most major Linux distros
- PwnKit: Local privilege escalation vulnerability discovered in polkit’s pkexec (CVE-2021-4034)
- Backdoor found in themes and plugins from AccessPress Themes
- Dark Souls servers taken down to prevent hacks using critical bug
- How I hacked my friend’s PayPal account
- How I got access to 25+ Tesla’s around the world
- Azure DDoS protection—2021 Q3 and Q4 DDoS attack trends
- QNAP force-installs update after DeadBolt ransomware hits 3,600 devices
- Analysis and impact of LockBit ransomware’s first Linux and VMware ESXi variant
- Watering hole deploys new macOS malware, DazzleSpy, in Asia
- Chasing Chaes kill chain
- TrickBot bolsters layered defenses to prevent injection research
- How BRATA is monitoring your bank account
- New FluBot and TeaBot campaigns target Android devices worldwide
- Malicious app on Google Play drops banking malware on users’ devices
- Financially motivated mobile scamware exceeds 100M installations
- Observations from the StellarParticle campaign
- North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign
- Investigating APT36 or Earth Karkaddan’s attack chain and malware arsenal
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.