Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- HackerOne employee stole data from bug bounty reports for financial gain
- Hackers claim theft of police info in China’s largest data leak
- Marriott hacked again? Yes. Here’s what we know
- Google allowed a sanctioned Russian ad company to harvest user data for months
- More and more, artificial intelligence is keeping the world under watch
- Algorithm claims to predict crime in US cities before it happens
- Apple expands industry-leading commitment to protect users from highly targeted mercenary spyware
- Microsoft rolls back decision to block Office macros by default
For the more technical
- Microsoft quietly fixes ShadowCoerce Windows NTLM Relay bug
- 2022 0-day In-the-Wild Exploitation…so far
- Security advisory accidentally exposes vulnerable systems
- Attack on Titan M: Vulnerability research on a modern security chip
- Ledger HW.1 & Nano security keycard bypass + more information
- Django fixes SQL Injection vulnerability in new releases
- CVE-2022-28219: Unauthenticated XXE to RCE and domain compromise in ManageEngine ADAudit Plus
- Dynamic analysis of firmware components in IoT devices
- Police can trace cameras thanks to sensor imperfection ‘fingerprints’
- “CuteBoi” detected preparing a large-scale crypto mining campaign on NPM users
- IconBurst NPM software supply chain attack grabs data from apps and websites
- Fake copyright complaints push IcedID malware using Yandex Forms
- Unprecedented shift: The Trickbot group is systematically attacking Ukraine
- Threat report: Maui ransomware (PDF)
- North Korean state-sponsored cyber actors use Maui ransomware to target the healthcare and public health sector
- New RedAlert ransomware targets Windows, Linux VMware ESXi servers
- AstraLocker ransomware shuts down and releases decryptors
- Brand-new HavanaCrypt ransomware poses as Google software update app, uses Microsoft hosting service IP address as C&C server
- When pentest tools go brutal: Red-teaming tool being abused by malicious actors
- Microsoft finds Raspberry Robin worm in hundreds of Windows networks
- PennyWise stealer: An evasive infostealer leveraging YouTube to infect users
- Russian organizations increasingly under attack by Chinese APTs
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.