Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Two Iranian men indicted for deploying SamSam ransomware
- Malware companies are finding new ways to spy on iPhones
- DriveSavers claims it has a way to break into locked iPhones
- Israeli cyber firm negotiated advanced attack capabilities sale with Saudis
- Google shut out privacy and security teams from secret China project
- Half of all phishing sites now have the padlock
- Marriott announces data breach of 500 million customers + more information
- Dell announces security breach
- New breakthroughs in combatting tech support scams
For the more technical
- Test of web browser extensions for protection against malicious software
- Using AWS Lambda for privilege escalation and exploring a LightSail service
- Details about the event-stream incident + more information
- Zoom message spoofing
- Cisco Prime License Manager SQL injection vulnerability
- Cisco Webex Meetings Desktop App command injection vulnerability
- Obfuscated bash script targeting QNap boxes
- Siemens patches major firewall flaw, other vulnerabilities
- Smart bulb offers light, color, music, and… data exfiltration
- Stealing webpages rendered on your browser by exploiting GPU vulnerabilities (PDF)
- Why AutoCAD malware keeps chugging on + more information
- Kaspersky says 2018 in malware was mostly a miner story
- KingMiner malware hijacks the full power of Windows Server CPUs
- Brazilian financial malware targets bank customers in Latin America and Europe
- Ukraine detects new Pterodo backdoor malware, warns of Russian cyberattack
- Analyzing the GreyEnergy malware: from maldoc to backdoor
- New strain of Olympic Destroyer droppers
- Demystifying obfuscation used in the Thanksgiving spam campaign
- Malvertising attack hijacks 300 million sessions over 48 hours
- Two apps that installed root certificates then leaked the private keys (PDF)
- UPnProxy: EternalSilence
- Hiding through a maze of IoT devices
- A look into the connection between XLoader and FakeSpy
- AutoIt-compiled worm delivers fileless version of njRAT backdoor
- Global “Pied Piper” campaign
- DNSpionage campaign targets Middle East
- FBI takes down ad fraud botnets Kovter and Boaxxe (PDF)
- Requirements for a secure broadband router (PDF)
- Apple Health is the next big thing: Health, cloud and security
- Clickstream tracking of users of the Tor browser
- Robust website fingerprinting through the cache occupancy channel
- Hunting with ꓘamerka 2.0 aka FIST (Flickr, Instagram, Shodan, Twitter)
- Jailbreaking Subaru StarLink
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – November 30, 2018”