Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Successfully countering Russian electoral interference
- In Mexico, fake news creators up their game ahead of election
- In Eastern Europe, U.S. military girds against Russian might and manipulation
- The NSA’s hidden spy hubs in eight U.S. cities
- Voices of millions of UK taxpayers stored by HMRC
- The $5 million surveillance car that hacks iPhones from 500 meters
- China takes surveillance to new heights with flock of robotic doves
- FireEye refutes claims that it hacked back a Chinese APT
- Feds pose as cryptocurrency money launderer to bust alleged dark web dealers + more information
- El Chapo’s lawyers say there’s evidence he was just a cartel middle manager
- How tech companies use dark patterns to discourage us from exercising our rights to privacy
- Paid jailbreak for Nintendo Switches includes anti-piracy code
For the more technical
- [WIDEO] Sandbox evasion techniques
- Breaking LTE on layer two
- Diameter vulnerabilities exposure report
- Practical mitigation of DMA-based Rowhammer attacks on ARM (PDF)
- Meet TLBleed: a crypto-key-leaking CPU attack that Intel reckons we shouldn’t worry about
- The state of industrial cybersecurity 2018
- Sophos privilege escalation vulnerabilities
- Cisco ASA flaw exploited in the wild
- HPE Integrated Lights-Out remote or local code execution
- VMWare Workstation DoS vulnerability
- WordPress file delete to code execution
- PoC||GTFO 18 is out (PDF)
- Inference attacks by malicious batteries on mobile devices (PDF)
- Gentoo GitHub mirror hacked and considered compromised
- Stealing passwords from McDonald’s users
- Marketing firm Exactis leaked a personal info database with 340 million records
- This popular Facebook app publicly exposed your data for years
- Hundreds of hotels affected by data breach at hotel booking software provider
- Swann home security camera sends video to wrong user
- Freenode targeted by reused password attack
- ProtonMail DDoS attacks are a case study of what happens when you mock attackers + additional information
- SSDP diffraction abused for DDoS amplification
- Tracking dog owners
- Attackers use a bag of tricks to target Greek banking customers
- Zeus Panda advanced banking trojan gets creative to scam affluent victims in Italy
- Tick group weaponized secure USB drives to target air-gapped critical systems
- MyloBot – new highly sophisticated botnet
- Noteworthy changes to Necurs’ behaviors
- Rancor: targeted attacks using PlainTee and DDKong malware families
- SamSam ransomware chooses its targets carefully (PDF)
- Talos releases ThanatosDecryptor
- Analyzing XPS files
- An empirical analysis of anonymity in Zcash
- VPN comparative test (PDF)
- Researchers release app that masks printers’ tracking dots
- Exposing the secret Office 365 forensics tool
- ‘Have I Been Pwned’ now built into Firefox, 1Password
- n6 (Network Security Incident eXchange) by CERT Polska
- Announcing STARTTLS Everywhere: securing hop-to-hop email delivery
- Wi-Fi Alliance introduces Wi-Fi CERTIFIED WPA3 security
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – June 30, 2018”