Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! Newsletter: Creating a cyber secure home (PDF)
- Comcast, Mozilla strike privacy deal to encrypt DNS lookups in Firefox
- Microsoft Edge is stealing Chrome users’ data? I asked Microsoft if it’s true
- The secret fight for your personal information
- Republicans push bill requiring tech companies to help access encrypted data
- The Senate’s new anti-encryption bill is even worse than EARN IT, and that’s saying something
- WhatsApp, Signal privacy at risk from new anti-encryption bill
- Lawmakers propose indefinite nationwide ban on police use of facial recognition
- Wrongfully arrested because face recognition can’t tell black people apart
- ‘BlueLeaks’ exposes files from hundreds of police departments
- Twitter bans DDoSecrets account over ‘BlueLeaks’ police data dump
- Washington man sentenced for role in developing “Mirai” successor botnets
- Russian national sentenced to prison for operating websites devoted to fraud and malicious cyber activities
- WikiLeaks founder charged in superseding indictment (PDF)
For the more technical
- Google Chrome fuzzing conclusion
- Web skimming with Google Analytics
- Attacking the Golden Ring on AMD Mini-PC
- Exploiting Bitdefender antivirus: RCE from any website
- Using global honeypot networks to detect targeted ICS attacks (PDF)
- Office 365 phishing campaign exploits Samsung, Adobe and Oxford servers
- Rovnix bootkit back in business
- Magnitude exploit kit – evolution
- WastedLocker: A new ransomware variant developed by the Evil Corp group
- WastedLocker: Symantec identifies wave of attacks against U.S. organizations
- Maersk, me & notPetya
- LG Electronics allegedly hit by Maze ransomware attack
- Sodinokibi: Ransomware attackers also scanning for PoS software, leveraging Cobalt Strike
- AcidBox: Rare malware repurposing Turla group exploit targeted Russian organizations
- The Golden Tax Department and the emergence of GoldenSpy malware
- Lucifer: New cryptojacking and DDoS hybrid malware exploiting high and critical vulnerabilities to infect Windows devices
- CryptoCore: A threat actor targeting cryptocurrency exchanges (PDF)
- Attackers cryptojacking Docker images to mine for Monero
- HiddenAds up to no good again and spreading via Android gaming apps
- Largest ever recorded packet per second-based DDoS attack
- Fxmsp: “The invisible god of networks”
- Moroccan journalist targeted with network injection attacks using NSO Group’s tools
- Hacking Starbucks and accessing nearly 100 million customer records
- Weak bits floppy disc protection: an alternate origins story on 8-bit
- Announcing the PlayStation Bug Bounty Program
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.