Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- A flood of coronavirus apps are tracking us. Now it’s time to keep track of them
- A hacker group is selling more than 73 million user records on the dark web
- Ransomware gang asks $42m from NY law firm, threatens to leak dirt on Trump
- Hackers’ private chats leaked in stolen WeLeakData database
- How international users unwittingly build up WeChat’s Chinese censorship apparatus (PDF)
- Here’s who just voted to let the FBI seize your online search history without a warrant
For the more technical
- PrintDemon: Print spooler privilege escalation, persistence & stealth (CVE-2020-1048 & more)
- Microsoft May 2020 Patch Tuesday
- Reverse RDP – The path not taken
- Thunderbolt Flaws expose millions of PCs to hands-on hacking
- Breaking Thunderbolt 3 security
- CVE-2020-12720: vBulletin urges users to patch undisclosed security vulnerability
- Critical flaws in cybersecurity devices exposed entire networks to attack and takeover
- A mistake at Facebook broke Spotify, Venmo, TikTok, and other iPhone apps
- Top 10 routinely exploited vulnerabilities
- Two vulnerabilities in Oracle’s iPlanet Web Server (CVE-2020-9315 and CVE-2020-9314)
- Backtracking MageCart infections
- App promises news feeds, brings DDoS attacks instead
- Estimated 24,000 Android apps expose user data through Firebase blunders
- Mandrake – owning Android devices since 2016
- COMpfun authors spoof visa application with HTTP status-based trojan
- Mikroceen: Spying backdoor leveraged in high‑profile networks in Central Asia
- APT group planted backdoors targeting high profile networks in Central Asia
- Updated BackConfig malware targeting government and military organizations in South Asia
- Hackers target the air-gapped networks of the Taiwanese and Philippine military
- Tropic Trooper’s back: USBferry attack targets air-gapped environments (PDF)
- Ransomware hit ATM giant Diebold Nixdorf
- Ransomware now demands extra payment to delete stolen files
- Astaroth – Maze of obfuscation and evasion reveals dark stealer
- Cyberthreats on lockdown
- Attacks on smart manufacturing systems (PDF)
- Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks
- Drupal security guide: How to secure & protect your website
- The many kinds of creepware used for interpersonal attacks (PDF)
- Working around the iPhone USB Restricted Mode
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.