Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Sanctions halt rewards for bug hunters in Belarus, Russia
- Fears of Russian spying prompts Germany to ditch Kaspersky
- Ukraine has started using Clearview AI’s facial recognition during war
- Powered by artificial intelligence, ‘autonomous’ border towers test Democrats’ support for surveillance technology
- Israeli government sites crash in cyberattack
- Russian defense firm Rostec shuts down website after DDoS attack
- Automotive giant DENSO hit by new Pandora ransomware gang
For the more technical
- CVE-2022-0847 aka Dirty Pipe vulnerability in Linux kernel
- About the security content of iOS 15.4 and iPadOS 15.4
- Bypassing software update package encryption – extracting the Lexmark MC3224i printer firmware
- Analyzing a PJL directory traversal vulnerability – exploiting the Lexmark MC3224i printer
- Android trojan persists on the Google Play Store since January
- AbereBot returns as Escobar
- Android malware Escobar steals your Google Authenticator MFA codes
- Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure
- Have your cake and eat it too? An overview of UNC2891
- Analysis of CaddyWiper – wiper targeting Ukraine
- CaddyWiper: New wiper malware discovered in Ukraine
- Leaks of Conti ransomware group paint picture of a surprisingly normal tech start-up… sort of
- Exposing initial access broker with ties to Conti
- SecurityScorecard discovers new botnet, ‘Zhadnost,’ responsible for Ukraine DDoS attacks
- Cyclops Blink sets sights on Asus routers
- B1txor20, a Linux backdoor using DNS tunnel
- Famous npm package deletes files to protest Ukraine war
- Threat actor UAC-0056 targeting Ukraine with fake translation software
- Government agencies in Ukraine targeted in cyber-attacks deploying MicroBackdoor malware
- Fake antivirus updates used to deploy Cobalt Strike in Ukraine
- Russian state-sponsored cyber actors gain network access by exploiting “PrintNightmare” vulnerability
- Increase in malware sightings on GoDaddy managed hosting
- CoverDrop: Securing initial contact for whistleblowers (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.