Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- NSO – not government clients – operates its spyware, legal documents reveal
- South Korean police arrest 215 people in suspected $228m crypto scam
- Bitfinex hack launderer Heather ‘Razzlekhan’ Morgan sentenced to 18 months in prison
- Five alleged members of Scattered Spider cybercrime group charged for breaches, theft of $11 million
- US seizes PopeyeTools cybercrime marketplace, charges administrators
- Fake letters on behalf of MeteoSwiss – Instead of a ‘Severe Weather Warning App’, malware is downloaded
- Ford rejects breach allegations, says customer data not impacted
- Pokémon Go players have unwittingly trained AI to navigate the world
- Child safety org launches AI model trained on real child sex abuse images
- It’s surprisingly easy to jailbreak LLM-driven robots
For the more technical
- Issue #5 of Paged Out! magazine is now available
- 2024 CWE Top 25 Most Dangerous Software Weaknesses
- Apple confirms vulnerabilities are already being exploited
- Pots and Pans, AKA an SSLVPN – Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
- Forti-fied? Logging blind spot revealed in FortiClient VPN
- Five local privilege escalation vulnerabilities in needrestart
- 4,000,000 WordPress sites using Really Simple Security free and pro versions affected by critical authentication bypass vulnerability
- Leveling up fuzzing: Finding more vulnerabilities with AI
- Inside Water Barghest’s rapid exploit-to-market strategy for IoT devices
- Ghost Tap: New cash-out tactic with NFC Relay
- ClickFix social engineering technique floods threat landscape
- Lessons from a honeypot with US citizens’ data
- One sock fits all: The use and abuse of The NSOCKS Botnet
- New PXA Stealer targets government and education sectors for sensitive information
- Lumma Stealer on the rise: How Telegram channels are fueling malware proliferation
- Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine
- A deep-dive analysis of WezRat
- BabbleLoader, an evasive loader packed with defensive mechanisms
- Helldown Ransomware: an overview of this emerging threat
- Unraveling Raspberry Robin’s layers: Analyzing obfuscation techniques and core mechanisms
- Earth Kasha’s new LODEINFO campaign and the correlation analysis with the APT10 Umbrella
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.