Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- SolarWinds officials throw intern under the bus for ‘solarwinds123’ password fail
- Malaysia Airlines discloses a breach spanning 9 years of data
- Airlines warn of data breaches after SITA passenger system hack
- Three top Russian cybercrime forums hacked
- Google: Charting a course towards a more privacy-first web
For the more technical
- Operation Exchange marauder: Active exploitation of multiple zero-day Microsoft Exchange vulnerabilities
- Detection and response to exploitation of Microsoft Exchange zero-day vulnerabilities
- HAFNIUM targeting Exchange Servers with 0-day exploits
- At least 30,000 U.S. organizations newly hacked via holes in Microsoft’s email software
- ProxyLogon: The latest pre-authenticated Remote Code Execution vulnerability on Microsoft Exchange Server
- Microsoft fixes Windows 10 drive corruption bug — what you need to know
- How I might have hacked any Microsoft account
- Hijacking traffic to Microsoft’s windows.com with bitflipping + more information
- Working Windows and Linux Spectre exploits found on VirusTotal + more information
- Hunting for bugs in Windows mini-filter drivers
- Microsoft DirectWrite heap-based buffer overflow
- Anatomy of an exploit: RCE with CVE-2020-1350 SIGRed
- Google patches actively exploited Chrome browser zero-day vulnerability + more information
- Unsecured cloud configurations exposing information in thousands of mobile apps
- coding mistake prior to Gab hack came from site’s CTO
- Cybersecurity firm Qualys is the latest victim of Accellion hacks + more information
- Elite cybercrime rorum “Maza” breached by unknown attacker
- 21 million free VPN users’ data exposed
- Are Xiaomi browsers spyware? Yes, they are…
- Supermicro’s response to Trickboot vulnerability, March 2021
- GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence
- New SUNSHUTTLE second-stage backdoor uncovered targeting U.S.-based entity; possible connection to UNC2452
- FluBot: Malware analysis report (PDF)
- Centreon to Exim and back: On the trail of Sandworm
- How I hacked a nuclear power plant
- BlackBerry 2021 Threat Report (PDF)
- Windows Killed Process Canary
- Google Analytics: Stop feeding the beast
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.