Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- MLAT order from Luxembourg for Signal user data
- Reward offers for information to bring DarkSide ransomware variant co-conspirators to justice
- Russian cybercriminal sentenced to 10 years in prison for digital advertising fraud scheme
- Ukrainian arrested and charged with ransomware attack on Kaseya
- Five affiliates to Sodinokibi/REvil unplugged
- MediaMarkt hit by Hive ransomware, initial $240 million ransom
- Cyber attack at MediaMarkt: hackers demand 50 million dollars
- A cyber mercenary is hacking the Google and Telegram accounts of presidential candidates, journalists and doctors
- Turkey: Hackers allegedly used streaming platform Twitch to launder $10m
- Robinhood hackers accessed internal tool for removing account security features, screenshots show
- Booking.com was reportedly hacked by a US intel agency but never told customers
For the more technical
- Microsoft November 2021 Patch Tuesday
- Windows 10 privilege-escalation zero-day gets an unofficial fix
- Zero-day disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064
- Trojan Source: Invisible vulnerabilities
- The invisible JavaScript backdoor
- Firefox vs Chromium
- BrakTooth proof of concept
- New critical vulnerabilities found on Nucleus TCP/IP stack
- Unboxing BusyBox – 14 new vulnerabilities uncovered by Claroty and JFrog
- Analyzing a watering hole campaign using macOS exploits
- OSX.CDDS – a sophisticated watering hole campaign drops a new macOS implant
- Critical security vulnerability fixed in WP Reset PRO
- FBI system hacked to email ‘urgent’ warning about fake cyberattacks
- Streaming wars continue — what about cyberthreats?
- Phishing with Google’s domain
- Spoofing calendar invites using .ics files
- Webinject panel administration: A vantage point into multiple threat actor campaigns
- BazarLoader ‘call me back’ attack abuses Windows 10 Apps mechanism
- A new Golang malware (BotenaGo) targeting millions of routers and IoT devices with more than 30 exploits
- DDoS attacks in Q3 2021
- TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
- The far-reaching attacks of the Void Balaur cybermercenary group (PDF)
- New Android malware targets Netflix, Instagram, and Twitter users
- PhoneSpy: The app-based cyberattack snooping South Korean citizens
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.