Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Hacker who exposed some of soccer’s dirtiest secrets charged in Portugal
- Senior adviser to the operator of the Silk Road online black market sentenced to 20 years in prison
- Tracy resident charged with computer attack on discovery bay water treatment facility
- BreachForums administrator facing 30-year sentence after pleading guilty to three charges
- Revolut’s US payment flaws allowed thieves to steal $20mn
- Southwest diverted a flight after someone AirDropped a photo suggesting a bomb was on the plane
- The adtech industry tracks most of what you do on the Internet. This file shows just how much
- Wikimedia Foundation: Transparency report July to December 2022
For the more technical
- Personal safety user guide for Apple devices
- July 2023 Microsoft Patch Update
- Enhanced monitoring to detect APT activity targeting Outlook Online
- How to securely build product features using AI APIs
- Shortening the Let’s Encrypt chain of trust
- Proof of concept developed for Ghostscript CVE-2023-36664 code execution vulnerability
- Rockwell warns of new APT RCE exploit targeting critical infrastructure
- A case study on fuzzing satellite firmware
- Health threat landscape – ENISA report
- ESET Threat Report H1 2023
- Crypto crime mid-year update: Crime down 65% overall, but ransomware headed for huge year thanks to return of big game hunting
- M365 phishing email analysis – eevilcorp
- Cloudy with a chance of credentials: AWS-targeting cred stealer expands to Azure, GCP
- PyLoose: Python-based fileless malware targets cloud workloads to deliver cryptominer
- The spies who loved you: Infected USB drives to steal secrets
- Source code for BlackLotus Windows UEFI malware leaked on GitHub
- Fake Linux vulnerability exploit drops data-stealing malware
- RedEnergy: New stealer-as-a-ransomware out in the wild
- LokiBot campaign targets Microsoft Office document using vulnerabilities and macros
- A new threat targeting macOS – ‘ShadowVault’
- CustomerLoader: a new malware distributing a wide variety of payloads
- The Toitoin trojan: Analyzing a new multi-stage attack targeting LATAM region
- Letscall – new sophisticated Vishing toolset
- Malicious campaigns target government, military and civilian entities in Ukraine, Poland
- Diplomats beware: Cloaked Ursa phishing with a twist
- RomCom threat actor suspected of targeting Ukraine’s NATO membership talks at the NATO summit
- The GRU’s disruptive playbook
- Routers from the underground: Exposing AVrecon
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.