Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- TikTok tells European users its staff in China get access to their data
- Amazon accidentally exposed an internal server packed with Prime Video viewing habits
- Whether you use Android or iOS, no one is 100% secured
- Liz Truss phone hack claim prompts calls for investigation
- Facebook probably has your phone number, even if you never shared it. Now it has a secret tool to let you delete it
- Accused ‘Raccoon’ malware developer fled Ukraine after Russian invasion
- World’s second largest copper producer recovering from cyberattack
- Hundreds of U.S. news sites push malware in supply-chain attack
- Mondelez and Zurich reach settlement in NotPetya cyberattack insurance suit
For the more technical
- Everything you need to know about the OpenSSL 3.0.7 Patch (CVE-2022-3602 & CVE-2022-3786)
- OpenSSL: Overview of software (un)affected by vulnerability
- Juniper SSLVPN / JunOS RCE and multiple vulnerabilities
- CosMiss: Azure Cosmos DB Notebook remote code execution vulnerability
- Microsoft mitigates vulnerability in Jupyter Notebooks for Azure Cosmos DB
- Pre-authenticated remote code execution in VMWare NSX Manager
- Black Mass Halloween 2022 by vx-underground (PDF)
- Find the needle faster with hashR data
- Dozens more PyPI packages attempting to deliver W4SP stealer in ongoing supply-chain attack
- How we handled a recent phishing incident that targeted Dropbox
- Galaxy Store applications installation/launching without user interaction
- Inside the V1 Raccoon Stealer’s den
- New Azov data wiper tries to frame researchers and BleepingComputer
- APT10: Tracking down LODEINFO 2022, part I & part II
- OPERA1ER: Playing god without permission (PDF)
- Internal chats for Yanluowang ransomware gang leaked; reveal members are Russian, not Chinese
- Black Basta ransomware: Attacks deploy custom EDR evasion tools tied to FIN7 threat actor
- APT trends report Q3 2022
- ENISA Threat Landscape 2022
- Ransomware victims and network access sales in Q3 2022
- Malware wars: the attack of the droppers
- Malware on the Google Play store leads to harmful phishing sites
- Emotet botnet starts blasting malware again after 4 month break
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.