Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Israeli spyware firm NSO Group drags researchers to court
- Proton Mail discloses user data leading to arrest in Spain
- The Post Millennial hack leaked data impacting 26 million people
- Feds seize BreachForums platform, Telegram page
- Two brothers arrested for attacking Ethereum blockchain and stealing $25M in cryptocurrency
- Developer of Tornado Cash gets jail sentence for laundering billions of dollars in cryptocurrency
- INC ransomware source code selling on hacking forums for $300,000
- I/O 2024: What’s new in Android security and privacy
- Apple and Google join forces to stop unwanted tracking
- Intel’s Thunderbolt Share lets two PCs control each other over a USB cable
- VMware Fusion, Workstation now free for home use, subscription-only for businesses
For the more technical
- Microsoft May 2024 Patch Tuesday
- QakBot attacks with Windows zero-day (CVE-2024-30051)
- Apple patches everything: macOS, iOS, iPadOS, watchOS, tvOS updated
- Google Chrome emergency update fixes 6th zero-day exploited in 2024
- Detecting compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect devices
- Send()-ing myself belated Christmas gifts – GitHub.com’s environment variables & GHES shell
- New WiFi vulnerability: The SSID Confusion attack
- Lethal Injection: How we hacked Microsoft’s healthcare chat bot
- Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
- Invisible optical adversarial stripes on traffic sign against autonomous vehicles
- GoTo Meeting loads Remcos RAT via Rust shellcode loader
- GitCaught: Threat actor leverages GitHub repository for malicious infrastructure
- Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
- Foxit PDF “flawed design” exploitation
- CISA: Black Basta ransomware breached over 500 orgs worldwide
- State of ransomware in 2024
- ESET APT Activity Report Q4 2023–Q1 2024
- To the Moon and back(doors): Lunar landing in diplomatic missions
- Waterbear and Deuterbear – two of the tools in Earth Hundun’s arsenal
- Springtail: New Linux backdoor added to toolkit
- FIN7 uses trusted brands and sponsored Google Ads to distribute MSIX payloads
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.