Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- WormGPT – The generative AI tool cybercriminals are using to launch business email compromise attacks
- Google exposes intelligence and defense employee names in VirusTotal leak
- Social engineering campaign targets technology industry employees
- Estée Lauder beauty giant breached by two ransomware gangs
- Fake passports, real bank accounts: How TheTruthSpy stalkerware made its millions
- How a Nintendo Switch helped locate a missing girl 2,000 miles from home
- Kevin Mitnick, hacker and fugitive turned security consultant, dies at 59
For the more technical
- The quarterly Oracle security updates are out
- New critical Citrix ADC and Gateway flaw exploited as zero-day
- Active exploitation of multiple Adobe ColdFusion vulnerabilities
- Attackers could have shut down your WhatsApp account with one simple email
- Unpacking the MOVEit breach: Statistics and analysis
- CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent
- Patch diffing CVE-2023-28121 to compromise a WooCommerce
- [VIDEO] How to operate patch management when you have more then 3000 servers
- Critical AMI MegaRAC bugs can let hackers brick vulnerable servers
- Comprehensive analysis of initial attack samples exploiting CVE-2023-23397 vulnerability
- Analysis of Storm-0558 techniques for unauthorized email access
- Secrets revealed in container images: An Internet-wide study on occurrence and impact (PDF)
- Bad.Build: A critical privilege escalation design flaw in Google Cloud Build enables a supply chain attack
- An uptick in Mallox ransomware activities exploiting MS-SQL servers
- BYOS – bundle your own stealer
- Analyzing a New .NET variant of LaplasClipper: retrieving the config
- P2PInfect: The rusty peer-to-peer self-replicating worm
- HotRat: The risks of illegal software downloads and hidden AutoHotkey script within
- FakeSG enters the ‘FakeUpdates’ arena to deliver NetSupport RAT
- Cybercriminals evolve antidetect tooling for mobile OS-based fraud
- Lookout attributes advanced Android surveillanceware to Chinese espionage group APT41
- Chinese cyber espionage actors continue to evolve tactics to avoid detection
- FIN8 uses revamped Sardonic backdoor to deliver Noberus ransomware
- New invitation from APT29 to use CCleaner
- KillNet showcases new capabilities while repeating older tactics
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.