Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Do better coders swear more, or does C just do that to good programmers?
- Microsoft lays off an ethical AI team as it doubles down on OpenAI
- Microsoft support ‘cracks’ Windows for customer after activation fails
- New Wi-Fi 7 cryptomining ‘TP-Link ASIC’ router scam claims to mine faster than RTX 4090
- Brazil seizing Flipper Zero shipments to prevent use in crime
- One of the darkweb’s largest cryptocurrency laundromats washed out
- ‘Nobody is safe’: In wild hacking spree, hackers accessed federal law enforcement database
- Dark web ‘BreachForums’ operator charged with computer crime
- This is the new leader of Russia’s infamous Sandworm hacking unit
- Estonian official says parliamentary elections were targeted by cyberattacks
- CISA now warns critical infrastructure of ransomware-vulnerable devices
- AT&T alerts 9 million customers of data breach after vendor hack
- LockBit brags: We’ll leak thousands of SpaceX blueprints stolen from supplier
- Royal Mail schools LockBit in leaked negotiation
- Wave of stealthy China cyberattacks hits U.S., private networks, Google says
- STALKER 2 hacker demands Ukrainian game developer reinstates Russian language support, or else…
For the more technical
- Register(ing) activity related to documents
- Kali Linux 2023.1 Release (Kali Purple & Python Changes)
- Exploiting CVE-2023-23397: Microsoft Outlook elevation of privilege vulnerability
- A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations (which is not a cyber meltdown)
- Microsoft March 2023 Patch Tuesday
- Magniber ransomware actors used a variant of Microsoft SmartScreen bypass
- Analysis of FG-IR-22-369
- Vulnerabilities in the TPM 2.0 reference implementation code
- Multiple Internet to baseband remote code execution vulnerabilities in Exynos modems
- Indirect prompt injection threats
- Threat actors abuse AI-generated Youtube videos to spread stealer malware
- Deanonymizing OpenSea NFT owners via cross-site search vulnerability
- Emotet returns, now adopts binary padding for evasion
- Thawing the permafrost of IcedID (PDF)
- First-ever Dero cryptojacking campaign targeting Kubernetes
- How sophisticated scammers and phishers are preying on customers of Silicon Valley Bank
- Business on the dark web: deals and regulatory mechanisms (PDF)
- A year of Russian hybrid warfare in Ukraine (PDF)
- Winter Vivern: Uncovering a wave of global espionage
- Nobelium uses Poland’s ambassador’s visit to the U.S. to target EU governments assisting Ukraine
- The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia
- Threat actors exploit progress Telerik vulnerability in U.S. government IIS server
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.