Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Polish police cracks down on DDoS-for-hire service active since 2013
- Romanian operator of bulletproof hosting service sentenced to prison in US
- Russian national arrested and charged with conspiring to commit LockBit ransomware attacks against U.S. and foreign businesses
- Switzerland warns that a ransomware gang may have accessed government data
- Millions of Americans’ personal DMV data exposed in massive MOVEit hack
- Rhysida ransomware leaks documents stolen from Chilean Army
- Pink Drainer steals $3M from multiple hack events including OpenAI CTO, Orbiter Finance
- Widespread brand impersonation scam campaign targeting hundreds of the most popular apparel brands
- An anti-porn app put him in jail and his family under surveillance
- Widow of slain Saudi journalist Jamal Khashoggi files suit against Pegasus spyware maker
For the more technical
- Cryptomator – vault in cloud
- XORtigate: Pre-authentication Remote Code Execution on Fortigate VPN (CVE-2023-27997)
- Barracuda ESG zero-day Vulnerability (CVE-2023-2868) exploited globally by aggressive and skilled actor, suspected links to China
- VMware ESXi zero-day used by Chinese espionage actor to perform privileged guest operations on compromised hypervisors
- June 2023 Microsoft Patch Tuesday
- Vulnerability disclosure for Tutanota
- MOVEit discloses third critical vulnerability
- UI bug in Visual Studio lets attackers impersonate publishers
- Fake security researcher GitHub repositories deliver malicious implant
- Drone security and fault injection attacks (PDF)
- Strava heatmap feature can be abused to find home addresses
- Freaky leaky SMS: Extracting user locations by analyzing SMS timings (PDF)
- Unauthenticated IDOR to PII disclosure in WooCommerce Stripe Gateway plugin
- Hacking root EPP servers to take control of zones
- ChamelGang and ChamelDoH: A DNS-over-HTTPS implant
- Uncovering Tor hidden service with Etag
- Hardware hacking to bypass BIOS passwords
- Detecting and mitigating a multi-stage AiTM phishing and BEC campaign
- Shampoo: A new ChromeLoader campaign
- Honeypot recon: Global database threat landscape
- Cryptocurrency mining pools and money laundering: Two real world examples
- Understanding Malware-as-a-Service
- Skuld: The infostealer that speaks Golang
- Android GravityRAT goes after WhatsApp backups
- Analyzing the FUD malware obfuscation engine BatCloak
- SeroXen incorporates latest BatCloak engine iteration
- Elastic charms SpectralViper
- Understanding ransomware threat actors: LockBit
- Threat actor targets Russian gaming community with WannaCry-imitator
- RomCom resurfaces: Targeting politicians in Ukraine and U.S.-based healthcare providing aid to refugees from Ukraine
- Shuckworm: Inside Russia’s relentless cyber campaign against Ukraine
- Cadet Blizzard emerges as a novel and distinct Russian threat actor
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.