Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
Looking for sponsors
Over 3 year of weekly delivery of fresh IT security news, thousands of links and happy readers. You can become part of IT Security Weekly Catch Up by becoming a sponsor. Interested? Get in touch at badcybercom[at]gmail.com (and please, no VPNs/crypto/poker etc.)
For the less technical
- Facebook has a new tool to spot spammers, and it’s already taken down billions of accounts
- Black market white washing: Why you shouldn’t take legal advice from criminals
- Through apps, not warrants, ‘Locate X’ allows federal law enforcement to track phones
- How information on the coronavirus is managed on Chinese social media
- Visser, a parts manufacturer for Tesla and SpaceX, confirms data breach
- Walgreens mobile app leaks prescription data
- Meet the white-hat group fighting Emotet, the world’s most dangerous malware
- Let’s Encrypt pushes back deadline to revoke some TLS certificates
For the more technical
- Intel CSME bug is worse than previously thought + more information
- Intel fixed 236 bugs in 2019 and only 5% (11 bugs) were CPU vulnerabilities (PDF)
- New AMD side channel attacks discovered, impacts Zen architecture
- Serious security flaws uncovered in Cacagoo IP cameras
- Ghostcat bug impacts all Apache Tomcat versions released in the last 13 years
- Facebook OAuth framework vulnerability
- CVE-2019-1458: Going from ‘in the wild report’ to POC
- CVE-2020-8597: Buffer overflow vulnerability in Point-to-Point Protocol Daemon (pppd)
- SurfingAttack: Interactive hidden attack on voice assistants using ultrasonic guided wave
- How one person is exploiting your WiFi router
- Serverless (in)security
- FUSE: Finding file upload bugs via penetration testing (PDF)
- Trickbot delivery method gets a new upgrade focusing on Windows 10
- Nemty ransomware punishes victims by posting theirstolen data
- Critical MediaTek rootkit affecting millions of Android devices has been out in the open for months
- Malware Evasion Encyclopedia
- The worst mistakes in iOS forensics
- OWASP Threat Dragon – a free, open-source, cross-platform threat modeling application
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.