Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- European Court of Human Rights: secret surveillance in Poland violates citizens’ privacy rights
- Google might have accidentally published docs about how Search works
- Multi-day DDoS storm batters Internet Archive
- Spyware found on US hotel check-in computers
- Ticketmaster hacked, personal data of 560 million customers leaked, ShinyHunters claim
- Largest ever operation against botnets hits dropper malware ecosystem
- Europol identifies 8 cybercriminals tied to malware loader botnets
- How researchers cracked an 11-year-old password to a $3 million crypto wallet
- 911 S5 botnet dismantled and its administrator arrested in coordinated international operation
- Trump pledges to free Silk Road creator Ross Ulbricht if re-elected
For the more technical
- Arbitrary file read in Check Point VPN gateways [CVE-2024-24919]
- Arbitrary command execution on TP-Link Archer C5400X
- Exploit released for maximum severity Fortinet RCE bug, patch now
- CISA warns of actively exploited Linux privilege elevation flaw
- [VIDEO] $203,000 bounties for 4 bugs in Azure Health Bot – 2x RCE, path traversal, memory leak
- PyPI crypto-stealer targets Windows users, revives malware campaign
- Technical analysis of Anatsa campaigns: An Android banking malware active in the Google Play store
- LightSpy: Implant for macOS
- Silent Push uses IP diversity queries to map out CryptoChameleon fast flux IOFAs. Hundreds of domains, IPs, and ASNs discovered
- Newly discovered ransomware uses BitLocker to encrypt victim data
- Threat landscape for industrial automation systems, Q1 2024
- The Pumpkin Eclipse
- By whose authority? Pegasus targeting of Russian & Belarusian-speaking opposition activists and independent media in Europe
- GRU’s BlueDelta targets key networks in Europe with multi-phase espionage campaigns
- Disrupting FlyingYeti’s campaign targeting Ukraine
- IOC extinction? China-nexus cyber espionage actors use ORB networks to raise cost on defenders
- Hellhounds: Operation Lahat
- LilacSquid: The stealthy trilogy of PurpleInk, InkBox and InkLoader
- Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks
- Decoding Water Sigbin’s latest obfuscation tricks
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.