Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- SVMetaSearch + help centre
- FTC will require Microsoft to pay $20 million over charges it illegally collected personal information from children without their parents’ consent
- BBC and British Airways affected by data breach at payroll company Zellis
- North Korea’s Lazarus group likely responsible for $35 million Atomic crypto theft
- The bizarre reality of getting online in North Korea
- Senegal continues curfew-like internet shutdown to subdue protests
- Snowden ten years later
- Scammers publish ads for hacking services on government websites
- CEO of dozens of companies and entities in Florida and New Jersey admits role in massive scheme to traffic in fraudulent and counterfeit Cisco networking equipment
- Russians charged with hacking Mt. Gox crypto exchange, running BTC-e
- Microsoft OneDrive down worldwide following claims of DDoS attacks
- This new satellite enters orbit with one mission: To get abused by hackers
For the more technical
- New MOVEit Transfer zero-day mass-exploited in data theft attacks
- Clop ransomware group behind MOVEit file transfer hacks: Microsoft
- Zero-day vulnerability in MOVEit Transfer exploited for data theft
- MOVEit Transfer and MOVEit Cloud vulnerability
- KeePass v2.54 fixes bug that leaked cleartext master password
- Chrome and Edge zero-day: “This exploit is in the wild”, so check your versions now
- Android security update fixes Mali GPU bug exploited as zero-day
- Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API
- Barracuda Email Security Gateway Appliance (ESG) vulnerability
- Modded Minecraft malware “fractureiser” – what we know
- IT threat evolution Q1 2023. Mobile & non-mobile statistics
- Tens of thousands of compromised Android apps
- Supply chain attack infiltrates Android apps with malicious SDK
- Dismantling spyware disinformation campaigns
- Stealth Soldier backdoor used in targeted espionage attacks in North Africa
- PowerDrop: A new insidious PowerShell script for command and control attacks targets U.S. aerospace defense industry
- Asylum Ambuscade: crimeware or cyberespionage?
- Carbon Black’s TrueBot detection
- Vice Society: The #1 cyberthreat to schools, colleges, and universities
- Cyclops ransomware and stealer combo: Exploring a dual threat
- ‘NoEscape’ Ransomware-as-a-Service (RaaS)
- Xollam, the latest face of TargetCompany
- New Magecart-style campaign abusing legitimate websites to attack others
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.