Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [VIDEO] Hacker breaks down 26 hacking scenes from movies & TV
- US suspects St. Petersburg hacker arrested in Bulgaria of cyber fraud at $7mln
- Hacking Team hacker Phineas Fisher has gotten away with it
- How hackers sell luxury hotel rooms for next to nothing
- Shady data brokers are selling online dating profiles by the millions
- Hacker say they compromised ProtonMail. ProtonMail says it’s BS
- A leaky database of SMS text messages exposed password resets and two-factor codes
- That domain you forgot to renew? Yeah, it’s now stealing credit cards
- Dark side of Nintendo Switch piracy
- Up to three million kids’ GPS watches can be tracked by parents… and any miscreant
- Impact assessment shows privacy risks Microsoft Office ProPlus Enterprise
- Meeting Kosovo’s clickbait merchants
- Man pleads guilty in fatal swatting case, faces 20+ years in prison
- Support wouldn’t change his password, so he mailed them a bomb
For the more technical
- November 2018 Microsoft Patch Tuesday
- The evolution of Microsoft Threat Protection, November update
- What’s new in Windows Defender ATP
- A new exploit for zero-day vulnerability CVE-2018-8589
- UAC bypass by mocking trusted directories
- Inserted malicious URLs within Office documents’ embedded videos
- SUSE SMT: A tale of three CVEs
- WordPress GDPR plugin inadvertently exposed sites to hackers
- Patched Facebook vulnerability could have exposed private information
- Old school ‘sniffing’ attacks can still reveal your browsing history
- Tracking and snooping on a million kids
- Spectre, Meltdown researchers unveil 7 more speculative execution attacks (PDF)
- DJI drone vulnerability
- The Intel Microcode Boot Loader protects older CPUs from Spectre
- Web vulnerabilities in Siemens SIMATIC operator panels
- Vulnerabilities in Siemens industrial products
- Authentication bypass vulnerability in D-Link DIR-850L wireless router
- Botnet pwns 100,000 routers using ancient security flaw + more information
- FASTCash: How the Lazarus group is emptying millions from ATMs
- Inside Magecart: Comprehensive report on the assault on e-commerce
- Merchants struggle with MageCart reinfections
- Examining Emotet’s activities, infrastructure
- Emotet infection with IcedID banking trojan
- What’s new in TrickBot? Deobfuscating elements
- Cryptocurrency-mining malware targets Linux systems, uses rootkit for stealth
- Targeted ransomware attacks – SophosLabs 2019 Threat Report
- tRat: New modular RAT appears in multiple email campaigns
- The White Company: Inside the Operation Shaheen espionage campaign
- Chinese threat actor targets UK-based engineering company using Russian APT techniques
- Europol report on Internet organised crime threat assessment (in brief)
- Spear phishing attack on GOV in Poland
- Phishing emails with .COM extensions are hitting finance departments
- Hacking Gmail’s UX with from fields
- Clickjacking on Google MyAccount worth 7,500$
- How a Nigerian ISP accidentally knocked Google offline
- The rise of multivector DDoS attacks
- The Big List of Naughty Strings
- Recent flow watermarking techniques for detection of Tor hidden services
- Bitwarden completes third-party security audit
- Combating potentially harmful applications with machine learning at Google
- iMessage security, encryption and attachments
- Messages in iCloud: How to extract full content
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.