Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Double-double tracking: How Tim Hortons knows where you sleep, work and vacation
- Dating apps exposed 845 GB of explicit photos, chats, and more
- South African bank to replace 12m cards after employees stole master key
- Amazon’s enforcement failures leave open a back door to banned goods—some sold and shipped by Amazon itself
- Coder-turned-kingpin Paul Le Roux gets his comeuppance
- Former eBay execs allegedly made life hell for critics
- How @YourAnonCentral hijacked the news with fake stories
- How I accidentally hijacked someone’s WhatsApp
- Introducing Firefox Private Network VPN’s official product – the Mozilla VPN
- Mexico’s biggest telecommunications operator is blocking Tor network
- GitHub to replace “master” with alternative term to avoid slavery references
For the more technical
- The Curious Case of Copy & Paste – on risks of pasting arbitrary content in browsers
- Firefox & Chrome privacy leakage: search term is sent to ISP without user’s consent
- A survey of recent iOS kernel exploits
- SOHO device exploitation
- 6 new vulnerabilities found on D-Link home routers
- BraveStarr – A Fedora 31 netkit telnetd remote exploit
- Ripple20: 19 zero-day vulnerabilities amplified by the supply chain
- A vulnerability in IBM Maximo was fixed
- A click from the backyard | Analysis of CVE-2020-9332, a vulnerable USB redirection software
- Threat vector: GTP. Vulnerabilities in LTE and 5G networks 2020
- VLC Media Player 3.0.11 fixes severe remote code execution flaw
- Adobe patches 18 critical flaws in out-of-band update
- Massive spying on users of Google’s Chrome shows new security weakness
- Explicit content and cyberthreats: 2019 report
- Privnotes.com is phishing bitcoin from users of private messaging service Privnote.com
- Global COVID 19-related phishing campaign by North Korean operatives Lazarus group
- Vendetta group and the COVID-19 phishing emails
- India: Human rights defenders targeted by a coordinated spyware operation
- Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies
- Copy-paste compromises – tactics, techniques and procedures used to target multiple Australian networks
- Digging up InvisiMole’s hidden arsenal
- ‘Work pressure’ sees Maze ransomware gang demand payoff from wrong company
- Hackers for hire: An overview of the unethical services offered on the Darknet
- AWS said it mitigated a 2.3 Tbps DDoS attack, the largest ever (PDF)
- AvaMaria RAT analysis
- Black Kingdom ransomware (TTPs & IOC)
- Stalkerware Test 2020 (PDF)
- Hashcat 6.0.0 released
- Zoom: End-to-end encryption update
- The secret life of GPS trackers
- Week in OSINT
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.