Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! Newsletter: Virtual Private Networks (PDF)
- German banks are moving away from SMS one-time passcodes
- Ransomware, BEC attacks strike government offices in the US Virgin Islands
- They paid nearly a half million in ransom. Where’s the data?
- Should governments pay extortion payments after a ransomware attack?
- Hackers breached Greece’s top-level domain registrar
- Bitpoint cryptocurrency exchange hacked for $32 million
- ICO statement: Intention to fine British Airways £183.39m under GDPR for data breach + more information
- UK watchdog plans to fine Marriott £99m
- A massive international email scam netted $3 million worth of top-secret US military equipment
- Banned Chinese security cameras are almost impossible to remove
- Hong Kong’s protesters put AirDrop to ingenious use to breach China’s Firewall
- Fugitive U.S. tech guru: Cryptocurrency is next Cuban revolution
- ‘Drugs in the mail’: Three in court over alleged Melbourne syndicate
- “Stranger Things” leaks suggest Netflix 4K may have been breached
- The Scene: Pirates ripping content from Amazon & Netflix
- The women who win hundreds of sweepstakes per year
For the more technical
- Zoom zero day: 4+ million webcams & maybe an RCE? Just get them to visit your website + more information
- Microsoft’s July 2019 Patch Tuesday + more information
- Microsoft stirs suspicions by adding telemetry files to security-only update
- Windows zero‑day CVE‑2019‑1132 exploited in targeted attacks
- Authentication bypass and arbitrary file upload on Cisco Data Center Network Manager
- Canonical GitHub account hacked, Ubuntu source code safe
- Archive cerver of Pale Moon open source browser hacked
- Two pentesters, one glitch: Firefox browser menaced by ancient file-snaffling bug, er, feature
- Nation-state hackers exploiting Outlook to deliver malware
- NewsBeef delivers Christmas presence
- Buhtrap group uses zero‑day in latest espionage campaigns
- Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques
- Router Exploit Kits: An overview of RouterCSRF attacks and DNS hijacking in Brazil
- Backdoored torrents infect movie, TV fans with GoBot2 malware
- Backdoor found in Ruby library for checking for strong passwords + more information
- Hardcoded credentials in Uniguest kiosk software lead to API compromise
- New vulnerability in Schneider Electric Modicon PLCs
- How we seized 15 active ransomware campaigns targeting Linux file storage servers
- Who’s behind the GandCrab ransomware?
- Keeping the ‘kill switch’ alive is the only thing preventing another WannaCry outbreak
- Dismantling a fileless campaign: Microsoft Defender ATP next-gen protection exposes Astaroth attack + more information
- New Miori variant uses unique protocol to communicate with C&C
- Magecart campaign breaches websites en masse via misconfigured Amazon S3 buckets
- Magento Killer: Malicious operations used to steal payment info
- Double duty: Dridex banking malware delivered with RMS RAT
- UK banking phish targets 2-factor information
- iOS URL scheme susceptible to hijacking
- Apple disables Walkie Talkie app due to vulnerability that could allow iPhone eavesdropping
- Investigating some subscription scam iOS apps
- New FinSpy iOS and Android implants revealed ITW
- More than 1,000 Android apps harvest data even after you deny permissions (PDF)
- Anubis Android malware returns with over 17,000 samples
- Hidden VPN owners unveiled: 97 VPN products run by just 23 companies
- Details of the Cloudflare outage on July 2, 2019
- Tor Project to fix bug used for DDoS attacks on Onion sites for years
- Bug bounty: how to win the race against black-hat hackers?
- Inside the MSRC – anatomy of a SSIRP incident
- The art of iPhone acquisition
- Grizzly browser fuzzing framework
- Seriously, stop using RSA
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.