Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! Newsletter: Dark Web (PDF)
- Baltimore ransomware perp pinky-swears he didn’t use NSA exploit
- Eurofins Scientific detects ransomware in some of its IT systems
- Ransomware attack costs Norsk Hydro tens of millions of dollars
- NordVPN sued by TorGuard for trying to disclose their own vulnerability to them (PDF)
- For two hours, a large chunk of European mobile traffic was rerouted through China
- The EU’s embassy in Russia was hacked but the EU kept it a secret
- Software vendor may have opened a gap for hackers in 2016 swing state
- Hackers steal 19 years’ worth of data from a top Australian university
- The aftermath of a data breach: A personal story
- Should failing phish tests be a fireable offense?
- Canada uses civil anti-spam law in bid to fine malware purveyors
- Assange won’t face charges over role in devastating CIA leak
- Four international hacking suspects charged with racketeering
- 18 arrested in the UK and Romania for €20 million fake train ticket scam
For the more technical
- Millions of Exim mail servers exposed to local, remote attacks
- VMware patches vulnerabilities in Tools, Workstation
- Update your Fortigates if you use SSLVPN
- Stopping SharePoint’s CVE-2019-0604
- CVE-2019-0725: An analysis of its exploitability
- Export corrupts Windows Event Log files
- Diebold Nixdorf warns customers of RCE bug in older ATMs
- Plot to steal cryptocurrency foiled by the npm security team + more information
- Bypassing CSP with policy injection
- We decide what you see: Remote code execution on a major IPTV platform
- Germany: Backdoor found in four smartphone models; 20,000 users infected
- How Ledger hacked an HSM
- How a quantum computer could break 2048-bit RSA encryption in 8 hours
- How to attack Kerberos?
- Investigating an attack against Recorded Future in real time
- Infected cryptocurrency-mining containers target Docker hosts with exposed APIs
- BlackSquid slithers into servers and drives with 8 notorious exploits to drop XMRig miner
- Monero-mining malware PCASTLE zeroes back in on China
- How a remote tech writing gig proved to be an old-school scam
- New phishing attacks use PDF docs to slither past the gateway
- PHA family highlights: Triada
- Hollywood lie: Bank hacks take months, not seconds (PDF)
- Platinum APT group is back
- Threat actors cobble together open-source pieces into monstrous Frankenstein campaign
- Actors in support of Iranian interests used impersonation of real individuals on social media
- Twitterbots: Anatomy of a propaganda campaign
- Government sector in Central Asia targeted with new HAWKBALL backdoor
- Google Cloud networking incident
- Using a HackRF to reverse engineer and control restaurant pagers
- Windows boot from UEFI to kernel
- The clever cryptography behind Apple’s ‘Find My’ feature
- How does Apple (privately) find your offline devices?
- Step by step guide to iOS jailbreaking and physical acquisition
- Firefox starts blocking third-party cookies by default
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.