Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! Newsletter 07/2024 – Text messaging attacks: A smishing saga
- Digital Markets Act, Google, Chrome extensions – case study
- Prominent misinformation interventions reduce misperceptions but increase scepticism
- Data breach exposes millions of mSpy spyware customers
- AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach
- Researchers claim nearly 10 billion credentials under threat — here’s what we know so far
- The stark truth behind the resurgence of Russia’s Fin7
- Russia forces Apple to remove dozens of VPN apps from App Store
- The Kremlin is rewriting Wikipedia
For the more technical
- [VIDEO] Solving Hackceler8 Teaser Task 2 by Gynvael Coldwind
- Introducing a new vulnerability class: False File Immutability
- Resurrecting Internet Explorer: Threat actors using zero-day tricks in Internet shortcut file to lure victims (CVE-2024-38112)
- Microsoft Patch Tuesday July 2024
- Signal downplays encryption key flaw, fixes it after X drama
- RADIUS/UDP vulnerable to improved MD5 collision attack
- Security flaws found in connected Traeger grill
- Netgear warns users to patch auth bypass, XSS router flaws
- CVE-2024-4577 exploits in the wild one day after disclosure
- CVE-2024-29510 – Exploiting Ghostscript using format strings
- GitLab patches critical flaw allowing unauthorized pipeline jobs
- Vulnerability in Exim MTA could allow malicious email attachments past filters [CVE-2024-39929]
- Exploring compiled V8 JavaScript usage in malware
- Hackers target WordPress calendar plugin used by 150,000 sites
- Distribution of AsyncRAT disguised as ebook
- Decrypted: DoNex ransomware and its predecessors
- Turning Jenkins into a cryptomining machine from an attacker’s perspective
- The mechanics of ViperSoftX: Exploiting AutoIt and CLR for stealthy PowerShell execution
- Turla: A master’s art of evasion
- CrystalRay: Inside the operations of a rising threat actor exploiting OSS tools
- 50 shades of bulletproof hosting – BPH landscape on russian-language cybercrime forums
- Huione Guarantee: The multi-billion dollar marketplace used by online scammers
- US disrupts AI-powered bot farm pushing Russian propaganda on X
- Houthi surveillanceware targeting Middle Eastern militaries
- APT40 advisory
- CloudSorcerer – A new APT targeting Russian government entities
- Attack activities by Kimsuky targeting Japanese organizations
- An in-depth look at crypto-crime in 2023, part 1 & part 2
- Ticket Heist: Olympic games and sporting events at risk
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.