Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Journalists sent exploding flash drives
- Ferrari discloses data breach after receiving ransom demand
- Tracking the fake GitHub star black market with Dagster, dbt and BigQuery
- RAT developer arrested for infecting 10,000 PCs with malware
- Breached hacking forum shuts down, fears it’s not ‘safe’ from FBI
For the more technical
- Exploiting aCropalypse: Recovering truncated PNGs
- Microsoft fixes aCropalypse privacy bug in Windows 11 Snipping Tool
- Move, patch, get out the way: 2022 zero-day exploitation continues at an elevated pace
- General Bytes Bitcoin ATMs hacked using zero-day, $1.5M stolen
- WooCommerce credit card skimmer reveals tampered plugin
- Critical authentication bypass in WooCommerce Payments allows site takeover
- Over-the-air: How we remotely compromised the gateway, BCM, and autopilot ECUs of Tesla cars (PDF)
- Pwn2Own Vancouver 2023 – Day one results
- Pwn2Own Vancouver 2023 – Day two results
- Pwn2Own Vancouver 2023 – Day three results
- Netgear Orbi router vulnerable to arbitrary command execution
- GitHub: We updated our RSA SSH host key
- [VIDEO] Linus Tech Tips explains how YouTube channel got hacked for crypto scam streams
- [VIDEO] 4Developers 2022: Cloud hacking scenarios
- [VIDEO] 4Developers 2022: Proactive API security
- March 20 ChatGPT outage: Here’s what happened
- “FakeGPT” #2: Open-source turned malicious in another variant of the Facebook account-stealer Chrome extension
- Past KyberSwap frontend exploit
- Red Canary 2023 Threat Detection Report (PDF)
- Adobe Acrobat Sign abused to push Redline info-stealing malware
- Attackers are starting to target .NET developers with malicious-code NuGet packages
- Nexus: a new Android botnet?
- BianLian ransomware gang continues to evolve
- LockBit 3.0: Technical details
- KillNet and affiliate hacktivist groups targeting healthcare with DDoS attacks
- Uncovering HinataBot: A deep dive into a Go-based threat
- Fortinet zero-day and custom malware used by suspected Chinese actor in espionage operation
- Operation Tainted Love: Chinese APTs target telcos in new attacks
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.