Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Zoom launches post-quantum encryption to secure user data
- New Windows AI feature records everything you’ve done on your PC
- When online content disappears
- Cencora data breach exposes US patient info from 8 drug companies
- Eventbrite promoted illegal opioid sales to people searching for addiction recovery help
- Owner of Incognito dark web drugs market arrested in New York
- UK to propose mandatory reporting for ransomware attacks and licensing regime for all payments
- Two Santa Cruz students uncover security bug that let anyone do their laundry for free
For the more technical
- QNAP QTS – QNAPping at the wheel (CVE-2024-27130 and friends)
- D-Link DIR-X4860 security vulnerabilities – technical analysis
- Rockwell Automation warns admins to take ICS devices offline
- New ‘Siren’ mailing list aims to share threat intelligence for open source projects
- Linguistic Lumberjack: Attacking cloud services via logging endpoints (Fluent Bit – CVE-2024-4323)
- CVE-2024-4978: Backdoored Justice AV Solutions Viewer software used in apparent supply chain attack
- Supply-chain attacks in LLMs: From GGUF model format metadata RCE, to state-of-the-art NLP project RCEs
- Reverse engineering Electron apps to discover APIs
- Surveilling the masses with Wi-Fi-based positioning systems
- DNSBomb pulsing DoS attack
- Stealers, stealers and more stealers
- Spring cleaning with Latrodectus: A potential replacement for IcedID
- Grandoreiro banking trojan unleashed
- Corporate users targeted via malicious ads and modals
- Ongoing malvertising campaign leads to ransomware
- ShrinkLocker: Turning BitLocker into ransomware
- Invisible miners: unveiling GhostEngine’s crypto mining operations
- Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign
- Void Manticore destructive activities in Israel
- Transparent Tribe targets Indian government, defense, and aerospace sectors leveraging cross-platform programming languages
- Operation Diplomatic Specter: An active Chinese cyberespionage campaign leverages rare tool set to target governmental entities in the Middle East, Africa and Asia
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.