Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OSINT in perspective – US IC OSINT strategy 2024-2026
- North Korea hacks two South Korean chip firms to steal engineering data
- Chinese national residing in California arrested for theft of artificial intelligence-related trade secrets from Google
- Treasury sanctions members of the Intellexa commercial spyware consortium
- Germany takes down cybercrime market with over 180,000 users
- CISA forced to take two systems offline last month after Ivanti compromise
- BlackCat ransomware shuts down in exit scam, blames the “feds”
- MiTM phishing attack can let attackers unlock and steal a Tesla
For the more technical
- About the security content of iOS 17.4 and iPadOS 17.4
- VMware fixes critical sandbox escape flaws in ESXi, Workstation, and Fusion
- CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity multiple authentication bypass vulnerabilities
- QNAP warns of critical auth bypass flaw in its NAS devices
- Over 100,000 infected repos found on GitHub
- Data scientists targeted by malicious hugging face ML models with silent backdoor
- 0-click account takeover on Facebook
- From Web3 drainer to distributed WordPress brute force attack
- The art of domain deception: Bifrost’s new tactic to deceive users
- Multistage RA World ransomware uses anti-AV tactics, exploits GPO
- The anatomy of an ALPHA SPIDER ransomware attack
- WogRAT malware exploits aNotepad (Windows, Linux)
- Unboxing Snake – Python infostealer lurking through messaging services
- GTPDOOR – A novel backdoor tailored for covert access over the roaming exchange
- Spam and phishing in 2023
- Mail in the Middle – A tool to automate spear phishing campaigns
- CryptoChameleon: New phishing tactics exhibited in FCC-targeted attack
- The Predator spyware ecosystem is not dead
- Predator spyware operators rebuild multi-tier infrastructure to target mobile devices
- Evasive Panda leverages Monlam Festival to target Tibetans
- TA4903: Actor spoofs U.S. government, small businesses in phishing, BEC bids
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.