Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! Security Awareness Newsletter: Phone call attacks & scams (PDF)
- Hamas created dating apps and fake Facebook profiles to try to lure Israeli soldiers
- Europe is using smartphone data as a weapon to deport refugees
- The great firewall of China: Xi Jinping’s internet shutdown
- The state of Internet censorship in Egypt
- Danske Bank money laundering allegations
- How to get away with financial fraud
- UK banks told to show their backup plans for tech shutdowns
- Did Satoshi Nakamoto write this book excerpt?
- D.B. Cooper: investigators claim they’ve discovered skyjacker’s identity
- Poland’s surveillance law targets personal data of environmental advocates, threatening U.N. climate talks
- The app developers sifting through your Gmail
- Google says it doesn’t get paid for giving third-party apps access to Gmail
- Key Brexit documents left on Eurostar train in embarrassing security bungle
- Superyacht cybercrime: the next big thing?
- Data from open-source ancestry site GEDMatch has led to more arrests
- Brazil’s PCC has become a multinational criminal enterprise
For the more technical
- Malicious macro hijacks desktop shortcuts to deliver backdoor
- Two new zero-day exploits in the same PDF
- A look into recent exploit kit activities
- A virus infecting tens of thousands of Fortnite players
- Downloader with a twist (PDF)
- GandCrab v4.1 in the wild - first Windows XP and Server 2003 impacting ransomware SMB worm
- Why VPNFilter is like a Moonlight Maze
- Check your router for VPNFilter
- Smoke Loader learned new tricks
- A new campaign involving the FormBook malware
- Even more Fake Santander Bank invoices delivering Trickbot
- Obfuscated Coinhive shortlink reveals larger mining operation + more information
- CoinImp cryptominer and fully qualified domain names
- Rakhni ransomware adds coinminer component
- Nozelesn ransomware reportedly using spam to target Poland
- Gentoo publishes incident report after GitHub hack
- Hacking a massive Steam scamming and phishing operation for fun and profit
- Con artists are fleecing Uber drivers + additional information
- Reading hotel key cards with a credit card magstripe reader
- Two-thirds of second-hand memory cards contain data from previous owners
- Thermanator: thermal residue-based post factum attacks on keyboard password entry
- Canon DSLR Bluetooth Remote Protocol reverse engineered
- Google CTF 2018 Quals – BBS
- Distinguishing attacks from legitimate traffic at an authentication server (PDF)
- Download bomb trick returns in Chrome – also affects Firefox, Opera, Vivaldi and Brave
- “Stylish” browser extension steals all your internet history
- These academics spent the last year testing whether your phone is secretly listening to you
- How Smart TVs in millions of U.S. homes track more than what’s on tonight
- The $12,000 intersection between clickjacking, XSS, and denial of service
- RCE by uploading a web.config
- Vulnerabilities patched in VMware ESXi, Workstation, Fusion
- WordPress 4.9.7 update fixes pair of security vulnerabilities
- Zerodium offers up to $500,000 for Linux zero-day exploits
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – July 7, 2018”