Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Russian hacker “Wazawaka” indicted for ransomware
- Russian IT worker jailed for participating in pro-Ukraine DDoS attacks
- 18-year-old charged with hacking 60,000 DraftKings betting accounts
- Anti-money laundering: Council adopts rules which will make crypto-asset transfers traceable
- [VIDEO] How iPhone thieves lock you out of your Apple account
- [VIDEO] Apple’s iPhone passcode problem: Thieves can ruin your entire digital life in minutes
- Knocking down Hive: How the FBI ran its own ransomware decryption operation
For the more technical
- Bug bounties are broken – the story of “i915” bug, ChromeOS + Intel bounty programs, and beyond
- CVE-2023-26818 – Bypass TCC with Telegram in macOS
- KeePass 2.X Master Password Dumper (CVE-2023-32784)
- Bitwarden Passwordless.dev hits general availability
- Testing a new encrypted messaging app’s extraordinary claims
- The dangers of Google’s .zip TLD
- The .zip gTLD: Risks and opportunities
- Dangerous functionalities in Microsoft Teams enable phishing and malware delivery by attackers
- The growing threat from infostealers
- Overview of the Russian-speaking infostealer ecosystem: the logs
- New phishing-as-a-service tool “Greatness” already seen in the wild
- Ongoing MEME#4CHAN attack/phishing campaign uses meme-filled code to drop XWorm payloads
- Water Orthrus’s new campaigns deliver rootkit and phishing modules
- “FleeceGPT” mobile apps target AI-curious to rake in cash
- Lemon Group’s cybercriminal businesses built on preinfected devices
- Apple blocked 1.7 million apps for privacy, security issues in 2022
- Geacon brings Cobalt Strike capabilities to macOS threat actors
- MalasLocker ransomware targets Zimbra servers, demands charity donation
- Researchers tie FIN7 cybercrime family to Clop ransomware
- You’ve been kept in the dark (web): exposing Qilin’s RaaS program
- RATs found hiding in the npm attic
- Malspam campaign delivering PowerDash – a tiny PowerShell backdoor
- The dragon who sold his camaro: Analyzing custom router implant
- Crime finds a way: The evolution and experimentation of the cybercrime ecosystem
- CloudWizard APT: the bad magic story goes on
- Lancefly: Group uses custom backdoor to target orgs in government, aviation, other sectors
- APT28 leverages multiple phishing techniques to target Ukrainian civil society
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.