Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Server image mystery in Georgia election security case
- YouTube mystery ban on hacking videos has content creators puzzled
- GDPR Enforcement Tracker
- Four in 10 North American banks non’t use EV certificates
- Lloyd’s of London calls for cyber cover clarity in insurance policies
- Former Equifax exec gets 4 months in prison for insider trading after breach
- Utah man sentenced for computer hacking crime
- Eurofins Scientific: Forensic services firm paid ransom after cyber-attack
- Florida city fires IT employee after paying ransom demand last week
- 7-Eleven Japanese customers lose $500,000 due to mobile app flaw
- Over $800,000 stolen by scammers in Atlanta area city BEC fraud
- This Bitcoin money-laundering cartel was operating from inside a Florida prison
- China is forcing tourists to install text-stealing malware at its border
- Google’s Jigsaw was supposed to save the Internet. Behind the scenes, it became a toxic mess
- How Amazon and the cops set up an elaborate sting operation that accomplished nothing
- The simple way Apple and Google let domestic abusers stalk victims
- Which smart bulbs should you buy (from a security perspective)
- Pirates: So you want to join ‘The Scene’?
For the more technical
- How we hacked our colleague’s smart home
- Orvibo smart home devices leak billions of user records
- Android Security Bulletin—July 2019
- Tens of VMware products affected by SACK Panic and SACK Slowness flaws
- Breaking & entering with Zipato smart hubs
- Unfixable seed extraction on Trezor – a practical and reliable attack
- Centreon v19.04 remote code execution (CVE-2019-13024)
- Exploit using Microsoft Excel Power Query for remote DDE execution discovered
- Windows privilege escalation via AlwaysInstallElevated technique
- Cloudflare outage caused by bad software deploy
- Magento 2.3.1: Unauthenticated stored XSS to RCE
- A great show is now history, as is its insecure mobile app
- File-storage app 4shared caught serving invisible ads and making purchases without consent
- Cybersecurity of NATO’s space-based strategic assets
- Hackers hijacked VR chatrooms to manipulate users’ reality
- Malware development – welcome to the Dark Side [1], [2-1], [2-2], [3], [4]
- The commoditization of ATM malware in the cybercriminal underground
- Monero security flaw could’ve seen XMR stolen from cryptocurrency exchanges
- Sodin ransomware exploits Windows vulnerability and processor architecture
- First-ever malware strain spotted abusing new DoH (DNS over HTTPS) protocol
- An analysis of Godlua backdoor
- RATs and stealers rush through “Heaven’s Gate” with new loader
- A further look at the”Silentbruter” malware – Internal folder structures revealed
- New Dridex variant evading traditional antivirus
- New record in 2019: Emotet now has over 30.000 variants and counting
- New triple-threat mobile version of the malware WannaLocker targets banks in Brazil
- “Updates for Samsung” — from a blog to an Android advertisement revenue goldmine of 10,000,000+ users
- Operation Tripoli
- TA505 begins summer campaigns with a new pet malware downloader, AndroMut, in the UAE, South Korea, Singapore, and the United States
- Ratsnif – new network Vermin from OceanLotus
- ‘Silence’ hackers hit banks in Bangladesh, India, Sri Lanka, and Kyrgyzstan
- Multiple chinese threat groups exploiting CVE-2018-0798 equation editor vulnerability
- MFSocket: A Chinese surveillance tool
- A better zip bomb
- You (probably) don’t need ReCAPTCHA
- OpenID Foundation says ‘Sign In with Apple’ is not secure enough
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.