Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Italian city of Palermo shuts down all systems to fend off cyberattack
- Mandiant: “No evidence” we were hacked by LockBit ransomware
- Shields Health Care Group data breach affects 2 million patients
- SSNDOB shutdown: DOJ announces closure of darknet market selling social security numbers and other personally identifiable information
- AlphaBay is taking over the dark web – again
- How crypto giant Binance became a hub for hackers, fraudsters and drug traffickers
- Smartphones blur the line between civilian and combatant
For the more technical
- CVE-2022-30190 (Follina) vulnerability in MSDT: description and counteraction
- Free micropatches for “Follina” Microsoft Diagnostic Tool remote code execution 0day (CVE-2022-30190)
- Microsoft Diagnostic Tool “DogWalk” package path traversal gets free micropatches (0day/WontFix)
- Multiple vulnerabilities in U-Boot (CVE-2022-30790, CVE-2022-30552)
- Horde Webmail – remote code execution via email
- Router security in 2021
- Hackers can steal your Tesla by creating their own personal keys
- More mysterious DNS root query traffic from a large cloud/DNS operator
- Introduction to VirtualBox security research
- Android security bulletin – June 2022
- Top 10 Android banking trojans target apps with 1 billion downloads
- Symbiote: A new, nearly-impossible-to-detect Linux threat
- SVCReady: A new loader gets ready
- Analysis of the massive NDSW/NDSX malware campaign
- Cuba ransomware group’s new variant found using optimized infection techniques
- Bizarre ransomware sells decryptor on Roblox Game Pass store
- KELA’s ransomware victims and network access sales report (PDF)
- New Emotet variant stealing users’ credit card information from Google Chrome
- Qbot malware now uses Windows MSDT zero-day in phishing attacks
- Shining the light on Black Basta
- Black Basta ransomware goes cross-platform, now targets ESXi systems
- Phishing tactics: how a threat actor stole 1M credentials in 4 months
- Crypto stealing campaign spread via fake cracked software
- MakeMoney malvertising campaign adds fake update template
- US agencies detail the digital ‘plumbing’ used by Chinese state-sponsored hackers
- Aoqin Dragon. Newly-discovered Chinese-linked APT has been quietly spying on organizations for 10 years
- Growling bears make thunderous noise
- Lyceum .NET DNS backdoor
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.