Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Agencies spending millions on ‘Crossbow’ spy tech, an upgraded Stingray
- LAPD got tech demos from Israeli phone hacking firm NSO Group
- Obscure Indian cyber firm spied on politicians, investors worldwide
- How companies are using your data against you
- Google’s indexing of WhatsApp numbers raises privacy concerns
- Fake SpaceX YouTube channels scam viewers out of $150K in bitcoin
- Man admits to “spoof” email fraud scheme + more information
- Alabama city hit with ransomware
For the more technical
- Security tests of Livecall.io web application (PDF)
- CallStranger: Data exfiltration & reflected amplified TCP DDOS & port scan via UPnP SUBSCRIBE Callback
- SMBleed: A new critical vulnerability affects Windows SMB protocol
- PoC RCE exploit for SMBGhost Windows flaw released
- Group policies going rogue
- Microsoft June 2020 Patch Tuesday
- Cmd Hijack – a command/argument confusion with path traversal in cmd.exe
- Mozilla Firefox SharedWorkerService code execution vulnerability
- SGAxe: How SGX fails in practice (PDF)
- New CrossTalk attack impacts Intel’s mobile, desktop, and server CPUs
- Arm CPUs impacted by rare side-channel attack
- CVE-2020-13777 GnuTLS audit: be scared
- The dark reality of open source (PDF)
- Legacy LVFS S3 bucket takeover and CVE-2020-10759 fwupd signature verification bypass
- Misconfigured Amazon S3 buckets continue to be a launchpad for malicious code
- Misconfigured Kubeflow workloads are a security risk
- An insider view into the increasingly complex Kingminer botnet (PDF)
- The A1 Telekom Austria hack
- Power company Enel Group suffers Snake ransomware attack
- Honda investigates possible ransomware attack, networks impacted
- Maze ransomware adds Ragnar Locker to its extortion cartel
- German task force for COVID-19 medical equipment targeted in ongoing phishing campaign
- Office 365 phishing baits remote workers with fake VPN configs
- Italian company earned up to $ 500,000 helping cybercriminals to deliver malware
- Beauty and the (fraud) beast
- Fake COVID-19 contact tracing apps used to download malware that monitors devices, steals personal data
- iCloud backups, synced data and end-to-end encryption
- Password Manager Resources
- Spies can eavesdrop by watching a light bulb’s vibrations
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.