Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Breaches at NetworkSolutions, Register.com, and Web.com
- TrendMicro employee sold customer info to tech support scammers
- How a scammer stole 500$ from me and in the end begged me not to tell his parents
- Aventura charged for flogging Chinese spy equipment to US gov’t with security vulnerabilities
- Inside the Microsoft team tracking the world’s most dangerous hackers
- Two former Twitter employees and a Saudi national charged as acting as illegal agents of Saudi Arabia
- Chinese police arrest operators of 200,000-strong DDoS botnet
- Facebook: Changes to groups API access
For the more technical
- The App Defense Alliance: Bringing the security industry together to fight bad apps
- Welcome to Pwn2Own Tokyo 2019 – schedule and day one results
- Pwn2Own Tokyo 2019 – day two final results
- Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium
- Actively exploited bug in fully updated Firefox is sending users into a tizzy
- Android Security Bulletin—November 2019
- The first BlueKeep mass hacking is finally here—but don’t panic
- BlueKeep exploitation activity seen in the wild + more information
- Microsoft works with researchers to detect and protect against new RDP exploits
- NVIDIA fixes security flaws in GPU Driver, GeForce Experience
- Thousands of QNAP NAS devices have been infected with the QSnatch malware + security advisory
- An online database of default passwords used by ICS/SCADA devices
- Libarchive vulnerability impacts multiple Linux distributions
- ClamAV zero-day lands but don’t panic
- rConfig v3.9.2 authenticated and unauthenticated RCE (CVE-2019-16663) and (CVE-2019-16662)
- Bypassing GitHub’s OAuth flow
- How I hacked Volkswagen and Skoda
- Researchers hack Siri, Alexa, and Google Home by shining lasers at them
- Amazon’s Ring Video Doorbell lets attackers steal your Wi-Fi password
- Trick or treating Android Emoji keyboard app makes millions of unauthorized purchases
- Asus router app leaks customer data and exposes Alexa users
- WP-VCD: The malware you installed on your own site
- DarkUniverse – the mysterious APT framework #27
- Double loaded ZIP file delivers Nanocore
- New Megacortex ransomware changes Windows passwords, threatens to publish data
- Fake ransomware named after Donald Trump tries to trick victims out of a buck
- Titanium: the Platinum group strikes again
- Uncovering the secret world of malware-like cheats in video games
- Phishing detection via analytic networks
- Google is helping design an open source, ultra-secure chip
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.