Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Federal officials recover bitcoin ransom from Colonial Pipeline attack
- Apple pays millions to end customer’s explicit images leak lawsuit
- Volkswagen says a vendor’s security lapse exposed 3.3 million drivers’ details
- Hackers steal wealth of data from game giant EA
- How hackers used Slack tobreak into EA games
- JBS paid $11 million to REvil ransomware, $22.5M first demanded
- CD Projekt: Data stolen in ransomware attack now circulating online
- Exagrid pays $2.6m to Conti ransomware attackers
- EpsilonRed ransomware group hits one of India’s financial software powerhouses
- Avaddon ransomware shuts down and releases decryption keys
- Computer memory maker ADATA hit by Ragnar Locker ransomware
- Slilpp marketplace disrupted in international cyber operation
- 800 criminals arrested in biggest ever law enforcement operation against encrypted communication
- Russian hackers breached Dutch police systems in 2017
- Call for crimes? Russian-language forum runs contest for cryptocurrency hacks
For the more technical
- A zero-day Google Chrome security flaw requires you to update now + more information
- PuzzleMaker attacks with Chrome zero-day exploit chain
- Microsoft June 2021 Patch Tuesday
- Fuzzing the Office ecosystem
- VMware fixes critical vCenter Server RCE vulnerability + PoC
- Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug
- Privacy analysis of FLoC
- ALPACA, a new type of man in the middle attack in HTTPS
- New large-scale campaign targets Kubeflow
- Siloscape: First known malware targeting Windows containers to compromise cloud environments
- Another brick in the Wall: eCrime groups leverage SonicWall VPN vulnerability
- Session Traversal Utilities for NAT (STUN) reflection/amplification
- Gootkit: the cautious Trojan
- New Evil Corp ransomware mimics PayloadBin gang to evade US sanctions
- Prometheus ransomware gang: A group of REvil?
- Gelsemium: When threat actors go gardening
- Picture this: Malware hides in Steam profile images
- Two weeks of securing Samsung devices
- BackdoorDiplomacy: Upgrading from Quarian to Turian
- Big airline heist: APT41 likely behind massive supply chain attack
- Best practices for MITRE ATT&CK mapping (PDF)
- GitHub updates policies on vulnerability research, malware, and exploits
- iOS 15: Find My network can still find your iPhone when it is powered off, or factory reset
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.