Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Google’s adding the app permissions section back to the Play Store after removing it
- How Meta and the security industry collaborate to secure the internet
- Hacked Ukrainian radio stations broadcast fakes about Zelensky’s health
- Justice Department seizes and forfeits approximately $500,000 from North Korean ransomware actors and their conspirators
- Building materials giant Knauf hit by Black Basta ransomware gang
- Russian hackers behind SolarWinds breach continue to scour US and European organizations for intel, researchers say
For the more technical
- CVE-2022-30136: Microsoft Windows Network File System v4 remote code execution vulnerability
- [CVE-2022-34918] A crack in the Linux firewall
- Critical vulnerabilities discovered in popular automotive GPS tracking device (PDF)
- The return of Candiru: Zero-days in the Middle East
- Javascript obfuscation techniques by example
- DNS-over-HTTP/3 in Android
- React debug.keystore key was trusted by Meta(Facebook) which caused to Instagram account takeover by malicious apps
- How attackers use exposed Prometheus server to exploit Kubernetes clusters
- SATAn: Air-gap exfiltration attack via radio signals from SATA cables (PDF)
- Fortinet: Cybersecurity in water management facilities (PDF)
- The kit that wants it all: Scam mimics PayPal’s known security measures
- Tracing state-aligned activity targeting journalists, media
- Continued cyber activity in Eastern Europe observed by TAG
- Russian APT29 hackers use online storage services, DropBox and Google Drive
- APT41: A case study
- Buy, sell, steal, EvilNum targets cryptocurrency, Forex, commodities
- Anatomy of attack: Truth behind the Costa Rica government ransomware 5-day intrusion
- Luna and Black Basta — new ransomware for Windows, Linux and ESXi
- Joker, Facestealer and Coper banking malwares on Google Play store
- I see what you did there: A look at the CloudMensis macOS spyware
- The trojan horse malware & password “cracking” ecosystem targeting industrial operators
- 8220 gang massively expands cloud botnet to 30,000 infected hosts
- Over thirty thousand DMCA notices reveal an organized attempt to abuse copyright law
- Google ads lead to major malvertising campaign
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.