Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Instagram accidentally exposed some users’ passwords in plaintext
- PI System software maker, OSIsoft, announced breach
- Amazon customers’ names and email addresses disclosed by website error
- Taking down an insider threat
- NordVPN shares results of ‘no-log’ audit
- Inside the British Army’s secret information warfare machine
- Saudi dissidents hit with stealth iPhone spyware before Khashoggi’s murder
- Man spoofs GPS to fake shop visits for profit, gets caught
- The recently arrested “redandwhite”: one of Silk Road’s greatest nemeses
- New Yorker accused of stealing $1m from Silicon Valley executive via SIM swap
- Inside the hunt for the world’s most dangerous terrorist
For the more technical
- Ghost emails: Hacking Gmail’s UX to hide the sender
- XSS injection campaign exploits WordPress AMP plugin
- Why you should patch Skype for Business immediately
- Security updates available for Flash Player + more information
- Spoof all domains containing ‘d’ in Apple products
- This JavaScript can snoop on other browser tabs to work out what you’re visiting (PDF)
- Intel Management Engine JTAG proof of concept
- ECCploit: ECC memory vulnerable to Rowhammer attacks after all (PDF)
- DirtyCOW bug drives attackers to a backdoor in vulnerable Drupal web servers
- Multiple remote vulnerabilities in TP-Link TL-R600VPN
- VMware affected by Dell EMC Avamar vulnerability
- Critical vulnerability in Modicon M221 PLC
- New wave of malware spreads via ISO file email attachments
- The Rotexy mobile Trojan – banker and ransomware
- TrickBot’s bigger bag of tricks
- Lazy passwords become rocket fuel for Emotet SMB spreader
- Mirai: Not just for IoT anymore
- CozyBear – in from the cold? + technical description
- Sednit: What’s going on with Zebrocy?
- FIN7 not finished – Morphisec spots new campaign
- Lazarus mounts attacks on financial organizations in Latin America
- Advanced sabotage among competing Magecart factions + more information
- True identity of notorious hacker tessa88 revealed
- An OSINT analysis of the Elon Musk Bitcoin scam
- ATMs can be hacked in minutes
- Free VPN apps: Chinese ownership, secretive companies & weak privacy
- German eID card system vulnerable to online identity spoofing
- Popular Dark Web hosting provider got hacked, 6,500 sites down
- How Azure AD could be vulnerable to brute-force and DOS attacks
- AWS rolls out new security feature to prevent accidental S3 data leaks
- Evilginx 2.2 – Jolly Winter Update
- Fake fingerprints can imitate real ones in biometric systems (PDF)
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – November 25, 2018”