Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Campaign “Reclaim your face” calls for a ban on biometric mass surveillance
- Surveillance disclosures show urgent need for reforms to EU aid programmes
- Zoom lied to users about end-to-end encryption for years, FTC says
- Windows 10, iOS, Chrome, and many others fall at China’s top hacking contest
- Pwn2Own Tokyo results [1] [2] [3]
- Compal, the second-largest laptop manufacturer in the world, hit by ransomware
- Steelcase furniture giant down for 2 weeks after ransomware attack
- Hotel reservation platform leaves millions of people exposed in massive data breach
- Animal Jam kids’ virtual world hit by data breach, impacts 46M accounts
- Customer data from encrypted phone company Ciphr has been dumped online
- CIA controlled global encryption company for decades, says report
- Former Microsoft software engineer sentenced to nine years in prison for stealing more than $10 million in digital value such as gift cards
- How the Pentagon is trolling Russian, Chinese hackers with cartoons
- GCHQ spies launch cyber counter-attack against anti-vaccine propaganda being spread by Russia
For the more technical
- DNS cache poisoning, the Internet attack from 2008, is back from the dead (PDF)
- Microsoft November 2020 Patch Tuesday + more information
- Microsoft fixes Windows zero-day disclosed by Google last month
- Sleep Attack: Intel Bootguard vulnerability waking from S3
- New Platypus attack can steal data from Intel CPUs
- Windows 10 Intel microcode released to fix new CPU security bugs
- New Slipstream NAT bypass attacks to be blocked by browsers
- Bitdefender: UPX unpacking featuring ten memory corruptions
- Discord.dll: successor to npm “fallguys” malware went undetected for 5 months
- Critical privilege escalation vulnerabilities affect 100k sites using Ultimate Member plugin
- Extraordinary vulnerabilities discovered in TCL Android TVs, now world’s 3rd largest TV manufacturer
- Mysterious bugs were used to hack iPhones and Android phones and no one will talk about it
- How to get root on Ubuntu 20.04 by pretending nobody’s /home
- Your computer isn’t yours
- Apple apps on macOS Big Sur bypass firewall and VPN connections
- Cyberattacks targeting health care must stop
- ICS threat activity on the rise in manufacturing sector
- The CostaRicto campaign: cyber-espionage outsourced
- Honour among thieves: the study of a cybercrime marketplace in action
- xHunt campaign: newly discovered backdoors using deleted email drafts and DNS tunneling for Command and Control
- Israeli companies targeted with new Pay2Key ransomware
- Targeted ransomware: it’s not just about encrypting your data
- Ransomware group turns to Facebook ads
- Hungry for data, ModPipe backdoor hits POS software used in hospitality sector
- Alleged source code of Cobalt Strike toolkit shared online
- Chinese-linked Muhstik botnet targets Oracle WebLogic, Drupal
- Gitpaste-12: a new worming botnet with reverse shell capability spreading via GitHub and Pastebin
- How NOT to do phishing attacks
- How did that get in my phone? Unwanted app distribution on Android devices (PDF)
- Ghimob: a Tétrade threat actor moves to infect mobile devices
- Fraudulent Minecraft apps deceive millions of Google Play users
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.