Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Finland, Germany, Ireland, Japan, Poland, South Korea added to US-led spyware agreement
- Microsoft to shut down 50 cloud services for Russian businesses
- Flipper Zero makers respond to Canada’s ‘harmful’ ban proposal
- AT&T says leaked data of 70 million people is not from its systems
- Fujitsu says it discovered malware on ‘multiple work computers’ that may expose customer data
- 19 million plaintext passwords exposed by incorrectly configured Firebase instances
- International Monetary Fund email accounts hacked in cyberattack
- Darknet marketplace Nemesis Market seized by German police
- Moldovan national sentenced to federal prison for operating websites involved in the illicit sale of compromised computer credentials
For the more technical
- Loop DoS: New Denial-of-Service attack targets application-layer protocols
- [VIDEO] CSRF – how to find it in 2024? CSRF bug bounty case study
- Google Vulnerability Reward Program: 2023 year in review
- Pwn2Own Vancouver 2024 – day one results & day two results
- Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own
- Threat landscape for industrial automation systems. H2 2023
- A series of serious security vulnerabilities in dormakaba’s Saflok electronic RFID locks
- GoFetch: Breaking constant-time cryptographic implementations using data memory-dependent prefetchers
- Apple chip flaw lets hackers steal encryption keys
- ShadowSyndicate Group’s possible exploitation of aiohttp vulnerability (CVE-2024-23334)
- ArtPrompt: ASCII art-based jailbreak attacks against aligned LLMs (PDF)
- VexTrio’s browser fingerprinting
- Sign1 malware: Analysis, campaign history & indicators of compromise
- TeamCity vulnerability exploits lead to Jasmin ransomware, other malware types
- WhiteSnake stealer: Unveiling the latest version – less obfuscated, more dangerous
- Inside the rabbit hole: BunnyLoader 3.0 unveiled
- LockBit attempts to stay afloat with a new version
- New Go loader pushes Rhadamanthys stealer
- Rescoms rides waves of AceCryptor spam
- AcidPour: New embedded wiper variant of AcidRain appears in Ukraine
- New details on TinyTurla’s post-compromise activity reveal full kill chain
- SmokeLoader delivery: UAC-0006 attack analysis (PDF)
- Initial access brokers exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect
- Curious Serpens’ FalseFont backdoor: Technical analysis, detection and prevention
- Andariel group exploiting Korean asset management solutions (MeshAgent)
- Earth Krahang exploits intergovernmental trust to launch cross-government attacks
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.