Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- How kids are using Google Docs to bully each other
- Facial recognition’s ‘dirty little secret’: Millions of online photos scraped without consent
- Debit card with built-in fingerprint reader begins trial in the UK
- Insert skimmer & camera cover PIN stealer
- Two-thirds of secondhand USB drives still contain previous owners’ data
- The Intercept shuts down access to Snowden trove
- China database lists ‘breedready’ status of 1.8 million women
- Sydney man charged with selling personal details of customers online
- Columbia Surgical Specialists pays almost $15k ransom following ransomware attack
- Crypto exec arrested for “multibillion-dollar pyramid scheme”
- North Korea stole cryptocurrency via hacking
- Inside the August plot to kill Maduro with drones
For the more technical
- Microsoft March 2019 Patch Tuesday
- The fourth horseman: CVE-2019-0797 vulnerability
- Root cause of the kernel privilege escalation vulnerabilities CVE-2019-0808
- Windows 10 to automatically remove updates that cause problems
- Adobe releases patches for critical flaws in Photoshop CC and Digital Edition
- Attackers exploiting WinRAR UNACEV2.DLL vulnerability (CVE-2018-20250)
- A saga of code executions on Zimbra
- UPnP-enabled connected devices in the home and unpatched known vulnerabilities
- WordPress 5.1 CSRF to remote code execution
- WordPress WooCommerce XSS vulnerability
- Pandora’s Box: Another new way to leak all your sensitive data
- TLS: 64bit-ish serial numbers & mass revocation
- Extracting BitLocker keys from a TPM
- Researchers find critical backdoor in Swiss online voting system
- Gaming industry still in the scope of attackers in Asia
- Analyzing sophisticated PowerShell targeting Japan
- Study of the Belonard Trojan, exploiting zero-day vulnerabilities in Counter-Strike 1.6
- Inside the Emotet banking trojan and malware distributor
- DanaBot control panel revealed
- ‘DMSniff’ POS malware actively leveraged to target small-, medium-sized businesses
- Inserting malware into anyone’s Google Earth Projects Archive
- Threat actors leverage credential dumps to breach cloud accounts worldwide
- From RCE to LDAP access
- Penetration testing Active Directory – privilege escalation & reconnaissance
- Spam and phishing in 2018
- Two-thirds of all Android antivirus apps are frauds
- SimBad: A rogue adware campaign on Google Play
- A password-storage field study with freelance developers (PDF)
- Google Chrome to add drive-by-download protection
- Firefox Send – a free, encrypted file sharing service
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – March 16, 2019”