Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Google’s plan to turn off third-party cookies in Chrome is dying
- Forget security – Google’s reCAPTCHA v2 is exploiting users for profit
- Microsoft starts campaign to make Windows security more like Mac post-CrowdStrike
- Data breach exposes US spyware maker behind Windows, Mac, Android and Chromebook malware
- BreachForums v1 database leak is an OPSEC test for hackers
- Security firm discovers remote worker is really a North Korean hacker
- Reward offer for information on North Korean malicious cyber actor targeting U.S. critical infrastructure
- Spanish police arrest three suspects linked to pro-Moscow NoName057(16) hackers
- NCA infiltrates world’s most prolific DDoS-for-hire service
For the more technical
- Oracle Critical Patch Update Advisory – July 2024
- [VIDEO] Finding criticals in mobile apps – Joel Margolis (0xteknogeek)
- Exploiting CVE-2024-21412: A stealer campaign unleashed
- PKfail: Untrusted platform keys undermine Secure Boot on UEFI ecosystem
- Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android
- CVE-2024-4879 and CVE-2024-5217 (ServiceNow RCE) exploitation in a global reconnaissance campaign
- Docker fixes critical 5-year old authentication bypass flaw
- Thread Name-Calling – using Thread Name for offense
- Binary secret scanning helped us prevent (what might have been) the worst supply chain attack you can imagine
- Stargazers Ghost Network
- Protect against the FrostyGoop ICS malware threat with OT cybersecurity basics
- SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining
- Double dipping cheat developer gets caught red-handed
- The tap-estry of threats targeting Hamster Kombat players
- Mid-year Doppelgänger information operations in Europe and the US
- Possible APT28-linked hackers target Ukraine’s scientific institutions
- Onyx Sleet uses array of malware to gather intelligence for North Korea
- Daggerfly: Espionage group makes major update to toolset
- Phishing campaign targeting mobile users in India using India Post lures
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.