Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Who cares what the public think? UK public attitudes to regulating data and data-driven technologies
- Thousands of popular websites see what you type – before you hit submit
- 10 GB database exposing VPN users dumped (for free) on Telegram
- Ukrainian sentenced to 4 years for selling hacked passwords
- Ransomware attack hits production facilities of agricultural equipment giant AGCO
- Costa Rica declares national emergency after Conti ransomware attacks
- Canadian fighter jet training company investigating ransomware attack
- Colonial Pipeline facing $1,000,000 fine for poor recovery plans
- Germany still not affected by Russia-linked cyberattacks
- Google Chrome updates failing on Android devices in Russia
- Google: Shared success in building a safer open source community
For the more technical
- F5 iControl REST endpoint authentication bypass technical deep dive
- Critical F5 BIG-IP vulnerability exploited to wipe devices
- CVE-2022-30525 (FIXED): Zyxel firewall unauthenticated remote command injection
- Microsoft May 2022 Patch Tuesday
- SMM callouts in HP products
- Hundreds of thousands of Konica printers vulnerable to hacking via physical access
- How an attacker could chain several vulnerabilities in an industrial wireless router to gain root access
- Common LinkedIn scams: Beware of phishing attacks and fake job offers
- Dirty deeds done dirt cheap: Russian RAT offers backdoor bargains
- Nerbian RAT using COVID-19 themes features sophisticated evasion techniques
- IceApple: A novel Internet Information Services (IIS) post-exploitation framework (PDF)
- New tool release: Discovering the origin host to bypass web application firewalls aplikacji
- Info-stealer campaign targets German car dealerships and manufacturers
- npm supply chain attack targets Germany-based companies with dangerous backdoor malware
- Sophos: The state of ransomware 2022 (PDF)
- Kaspersky: New ransomware trends in 2022
- Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself
- Welcome “Frappo” – The new Phishing-as-a-Service used by cybercriminals to attack customers of major financial institutions and online-retailers
- The pervasive nature of credit card skimmers
- Ukraine warns of “chemical attack” phishing pushing stealer malware
- Overview of the 9 distinct data wipers used in the Ukraine war (PDF)
- APT34 targets Jordan Government using new Saitama backdoor
- Please confirm you received our APT
- Cobalt Mirage conducts ransomware operations in U.S.
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.