Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- An informal review of CTF abuse
- Carbon, a new programming language from Google, aims to be C++ successor
- Bank of America hardware key implementation is basically crap
- Three charged in first ever cryptocurrency insider trading tipping scheme
- NSO Group sold spyware to 14 EU governments
- Russia is quietly ramping up its Internet censorship machine
- Hacker selling Twitter account data of 5.4 million users for $30k
- T-Mobile reaches historic $350 million settlement in 2021 data breach
- LockBit claims ransomware attack on Italian tax agency
- Breach exposes users of Microleaves proxy service
- Radioactivity monitoring and warning system hacked, disabled by attackers
- Arts organizations alarmed after WordFly ransomware attack
For the more technical
- Zyxel authentication bypass patch analysis (CVE-2022-0342)
- About Windows persistence mechanisms
- Discovery of new UEFI rootkit exposes an ugly truth: The attacks are invisible to us
- Attackers profiting from proxyware
- Malicious IIS extensions quietly open persistent backdoors into servers
- How threat actors are adapting to a post-macro world
- Attackers move quickly to exploit high-profile zero days
- Multiple vulnerabilities in Moxa NPort 5110
- FileWave patches two vulnerabilities that impacted more than 1,000 orgs
- DUCKTAIL: An infostealer malware targeting Facebook Business accounts (PDF)
- How cybercriminals are using messaging apps to launch malware schemes
- Major security vulnerability on PrestaShop websites
- Luca Stealer source code leaked on a cybercrime forum
- Examining new DawDropper banking dropper and DaaS on the dark web
- QBot phishing uses Windows Calculator DLL hijacking to infect devices
- LofyLife: malicious npm packages steal Discord tokens and bank card data
- Robin Banks might be robbing your bank
- Amid rising Magecart attacks on online ordering platforms, recent campaigns infect 311 restaurants
- Lightning Framework: New undetected “Swiss army knife” Linux malware
- LockBit ransomware group augments its latest variant, LockBit 3.0, with BlackMatter capabilities
- Attackers target Ukraine using GoMet backdoor
- APT trends report Q2 2022
- An analysis of Charming Kitten’s new tools and OPSEC errors
- STIFF#BIZON: New attack campaign observed possibly linked to Konni/APT37 (North Korea)
- Untangling KNOTWEED: European private-sector offensive actor using 0-day exploits
- Largest European DDoS attack on record
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.