Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- British govt is scanning all Internet devices hosted in UK
- AstraZeneca password lapse exposed patient data
- Danish train standstill on Saturday caused by cyber attack
- LockBit ransomware claims attack on Continental automotive giant
- Man charged for participation in LockBit global ransomware campaign (PDF)
- ALMA Observatory shuts down operations due to a cyberattack
- How Qatar hacked the World Cup
- U.S. attorney announces historic $3.36 billion cryptocurrency seizure and conviction in connection with Silk Road dark web fraud
- Ukraine arrests fraud ring members who made €200 million per year
- Nigerian scammer sentenced to 11 years in US prison
- Z-Library eBook site domains seized by U.S. Dept of Justice
- Fake books about NFT
- LinkedIn introduces new security features to combat fake accounts
- Researchers spin up terrifying hacker drone that can ‘see through walls’ with Wifi
For the more technical
- Exploring ZIP mark-of-the-web bypass vulnerability (CVE-2022-41049)
- Microsoft November 2022 Patch Tuesday
- VMware Workspace ONE Assist update addresses multiple vulnerabilities
- ‘High-severity’ vulnerability found in computers used by large oil and gas utilities
- Lenovo fixes flaws that can be used to disable UEFI Secure Boot
- The case of Cloud9 Chrome botnet
- A very powerful clipboard: Analysis of a Samsung in-the-wild exploit chain
- Accidental $70k Google Pixel lock screen bypass
- Malware on the Google Play store leads to harmful phishing sites
- Apple may keep track of everything you tap while browsing the App Store
- PayPal allows bypassing two-factor auth with a button click – claims “It’s for your protection”
- Cyber criminal adoption of IPFS for phishing, malware campaigns
- Twitter Blue Badge email scams – Don’t fall for them!
- Massive ois[.]is black hat redirect malware campaign
- Massive phishing campaigns target India banks’ clients
- PNG steganography hides backdoor
- StrelaStealer aims for mail credentials
- Microsoft Digital Defense Report 2022 (PDF)
- DDoS attacks in Q3 2022 (Kaspersky)
- Q3 2022 DDoS attacks and BGP incidents (Qrator Labs)
- Hacktivists use of DDoS activity causes minor impacts (PDF)
- Robin Banks crooks back at the table with fresh phish from Russia
- DeimosC2: What SOC analysts and incident responders need to know about this C&C framework
- Defeating Guloader anti-analysis technique
- RomCom threat actor abuses KeePass and SolarWinds to target Ukraine and potentially the United Kingdom
- New updated IceXLoader claims thousands of victims around the world
- Following APT29 by taking a deeper look at Windows credential roaming
- Hack the real box: APT41’s new subgroup Earth Longzhi
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.