Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Group-IB discovers 100K+ compromised ChatGPT accounts on dark web marketplaces
- Most invasive AI apps
- From “heavy purchasers” of pregnancy tests to the depression-prone: We found 650,000 ways advertisers label you
- DuckDuckGo Windows browser now available in public beta
- Bloodied Macbooks and stacks of cash: Inside the increasingly violent Discord servers where kids flaunt their crimes
- Identity of mole who sold Russia secrets from within Australia’s spy agency uncovered
- European Investment Bank attacked, hackers claiming to “impose sanctions on EU”
- SMS phishers harvested phone numbers, shipment data from UPS tracking tool
- Reddit hackers threaten to leak data stolen in February breach
- BreachForums seized by FBI three months after arrest of alleged admin
- American Airlines, Southwest Airlines disclose data breaches affecting pilots
For the more technical
- PoC exploit published for Cisco AnyConnect Secure vulnerability
- nOAuth: How Microsoft OAuth misconfiguration can lead to full account takeover
- VMware warns of critical vRealize flaw exploited in attacks
- Zyxel warns of critical command injection flaw in NAS devices
- ASUS urges customers to patch critical router vulnerabilities
- GitHub dataset research reveals millions potentially vulnerable to RepoJacking
- CISA orders agencies to patch iPhone bugs abused in spyware attacks
- Dissecting TriangleDB, a Triangulation spyware implant
- Fortinet reverses Flutter-based Android malware “Fluhorse”
- NSA releases guide to mitigate BlackLotus threat
- Fragments of cross-platform backdoor hint at larger Mac OS attack
- Condi DDoS botnet spreads via TP-Link’s CVE-2023-1389
- The anatomy of the latest Mirai campaign leveraging multiple IoT exploits
- Mystic Stealer: The new kid on the block
- Mystic Stealer – Evolving “stealth” malware
- LockBit Green and phishing that targets organizations
- An overview of the different versions of the Trigona ransomware
- RedEyes group wiretapping individuals (APT37)
- BlueDelta exploits Ukrainian government roundcube mail servers to support espionage activities
- Graphican: Flea uses new backdoor in attacks targeting foreign ministries
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.