Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! newsletter: Am I hacked? (PDF)
- Here’s why [insert thing here] is not a password killer
- FIFA admits hack and braces for new leaks
- Fake Elon Musk Twitter Bitcoin scam earned 180K in one day
- Thieves are combining SMS-based phishing attacks with new “cardless” ATMs
- The aftermaths of Operation Bayonet and the migration of vendors to Dream Market
- Alleged admin of a child abuse forum on the Darkweb arrested in France
- Chloe Ayling to testify in second “Black Death Group” kidnapping case in Italy
- Swedish ISP protests ‘site blocking’ by blocking rightsholders website too
- US Cyber Command starts uploading foreign APT malware to VirusTotal
- Giant ransomware bundle threatens to make malware attacks easier for crooks
- Police decrypt 258,000 messages after breaking pricey IronChat crypto app
- The CIA’s communications suffered a catastrophic compromise. It started in Iran
- China is exporting its digital surveillance methods to African governments
For the more technical
- VirtualBox 0day dumped on GitHub
- Security bug in Icecast puts online radio stations at risk + more information
- Cisco small business switches privileged access vulnerability
- Cisco accidentally released Dirty Cow exploit code in software
- RCE via EL injection in JBoss
- Evernote for Windows read local file and command execute vulnerabilities
- WordPress design flaw leads to WooCommerce RCE
- Erealitatea[.]net hack corrupts websites with WP GDPR Compliance plugin vulnerability
- Struts 2.3 vulnerable to two year old file upload flaw
- DJI drone vulnerability
- Critical vulnerabilities in AVEVA industrial software
- FaceTime: Heap corruption in RTP video processing
- Adobe ColdFusion servers under attack from APT group + technical description
- Stealing Chrome cookies without a password
- Bug bounty hunter ran ISP doxing service
- Build interactive map of cameras from Shodan
- Persian stalker pillages Iranian users of Instagram and Telegram
- Attack uses malicious InPage document and outdated VLC media player
- Busting SIM swappers and SIM swap myths
- Who’s in your online shopping cart?
- Fake banking app found on Google Play used in SMiShing scheme
- Metamorfo banking trojan keeps its sights on Brazil
- Deep analysis of TrickBot new module pwgrab
- Spam and phishing in Q3 2018
- U.S. Secret Service warns ID Thieves are abusing USPS’s mail scanning service
- Supply-chain attack on cryptocurrency exchange gate.io
- Reversing Retefe
- Decoding Hancitor malware with Suricata and Lua
- Arecibo: an OOB exfiltration tool (DNS & HTTP)
- Tunneling scanners (or really anything) over SSH
- A new chapter for OSS-Fuzz
- Introducing the Android Ecosystem Security Transparency Report
- Space Data Link Protocols – summary of concept and rationale (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – November 11, 2018”