Afraid of missing important security news during the week? We’re here to help! Every week we put all important security related news in one place, for your reading pleasure. Enjoy!
A bit less technical
- Russian propaganda influence on american elections
- Interview with stock hacker photos author
- Microsoft shares Windows 10 telemetry data with FireEye
- Darknet drug vendors opsec fails
- Bankers in Philippines charged for involvement in SWIFT fraud
- 178 money mules arrested
- ATMs in Europe targetted by hackers
- Bank phishing results in USD 2,6 mln theft
- The FBI Hacked Over 8,000 Computers In 120 Countries
- EU’s new approach to regulating cryptography
- Twitter Fighting with Sexualised Images of Children
- Probably a second breach at NSA
- London Tube users tracked by WiFi device MAC address
- UK’s ThreeMobile customers database incident
- Popular Twitter accounts compromised by spammers
A bit more technical
- All videos from Black Hat USA 2016
- A Russian Trump fan is celebrating by hacking Google Analytics
- KeePass security audit results
- [PDF] curl audit report
- Securing domain controllers
- gstreamer FLIC decode vulnerability
- Incorrect fix for gstreamer FLIC decoder vulnerability
- New method for distributing malware through images
- Hacking Tesla with a malicious Android app: part 1, part 2
- Detailed analysis of Android N encryption
- Pixel security improvements
- Analysis of recent DDoS attacks on Russian banks
- Analysis of Ursnif campaign
- Soltra threat intelligence sharing tool saved by new owner
- 0day in specific regional software used in attacks in Asia
- Tropic Trooper APT campaign
- Forensic resources lists
- Exploit and malware in .HWP files
- 4 fatal flaws in deterministic password managers
- [PDF] Solid comparison of password managers
- [PDF] SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit
- TeleCrypt ransomware defeated
- Crysis ransomware decryption analysis
- Cerber ransomware encrypts databases
- Signal protocol specs now public domain
- Syscall Auditing at Scale
- NIST’s new password rules
- Interesting vulnerability in WordPress update server
- TP-link Device Debug Protocol (TDDP) Vulnerabilities
- Elevating privileges by environment variables expansion
- [PDF] Many Android VPNs are malicious
- Exfiltration of User Credentials using WLAN SSID
- Android malware analysis with Radare
- Sending Valid Phishing E-mails From Microsoft.com
- Windows 10 vs EMET analysis
- Flokibot analysis
- Gathering .onion addresses
- Tracking drivers with Bluetooth
- TimThumb vulnerability author’s confession
- Useful email obfuscation technique
- Ways to Brute Force WordPress
- Generic VBA Instrumentation for Microsoft Office Documents
- [PDF] Reverse engineering Fitbit firmware
- CVE-2016-0176 analysis (Edge)
- [PDF] Classification of Side-Channel Attacks on Mobile Devices
- Major update – Sysmon 5.0
- Malware spreading on Facebook
- Analysis of Android banking malware app: part 1, part 2
- Next-gen vs traditional AV products – tests and comments
- [PDF] Analysis of secure external hard drives
- [PDF] Akamai State of the Internet Q3 report
- Uber bug bounty finds
- Fareit spam campaign analysis
- Wget Access List Bypass
- Research on unsecured Wi-Fi networks across the world
- Forensic Implications of iOS Lockdown (Pairing) Records
If you enjoyed this list and find it useful, subscribe to our feeds (RSS, Twitter, Facebook available) to find out when the new edition is posted next week.
One thought on “IT Security Weekend Catch Up – November 26, 2016”