Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- The inside scoop on a six-figure Nigerian fraud campaign
- RSF unveils 20/2020 list of press freedom’s digital predators
- German military laptop with classified data sold on Ebay
- A UK-based security company seemed to have inadvertently exposed its ‘Leaks Database’ with 5B+ records
For the more technical
- Welcome to Pwn2Own 2020 – The schedule and live results
- Pwn2Own day two – Results and Master of Pwn
- Two Trend Micro zero-days exploited in the wild by hackers
- Deep dive: Snoop-assisted L1 Data Sampling + affected processors
- Adobe fixes nine critical vulnerabilities in Reader, Acrobat + details
- Here’s the Netflix account compromise Bugcrowd doesn’t want you to know about
- Mass account takeovers using HTTP Request Smuggling on Slack to steal session cookies
- The unexpected Google wide domain check bypass
- Vulnerabilities patched in Popup Builder plugin affecting over 100,000 sites
- Norsk Hydro outage may have been destructive state attack (PDF)
- Probing Pawn Storm: Cyberespionage campaign through scanning, credential phishing and more
- Web browser for developers leaves user data exposed
- This PIN can be easily guessed (PDF)
- Is cryptojacking dead after Coinhive shutdown? (PDF)
- MonitorMinor: vicious stalkerware?
- New TrickBot module bruteforces RDP connections, targets select telecommunication services in US and Hong Kong
- They come in the night: Ransomware deployment trends
- Security breach disrupts fintech firm Finastra
- Android – Coronavirus – related malware tracker
- CovidLock: Mobile Coronavirus tracking app coughs up ransomware
- Ransomware gangs to stop attacking health orgs during pandemic
- Covid-19 drug advice from the WHO spoofed to distribute HawkEye info-stealer
- Acunetix is offering complimentary licenses to agencies fighting COVID-19
- Full file system and keychain extraction: now with iOS 13 and iPhone 11 support
- Firefox to remove support for the FTP protocol
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.