Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- New evidence of hacked Supermicro hardware found in U.S. telecom + additional information
- Supply chain security: An expert’s view
- Czech counterintelligence helps uncover Hezbollah hacking scheme
- The long, weird story explaining why I bid $700 for a stolen PSN account
- How an amateur rap crew stole surveillance tech that tracks almost every American
- How a fraudster got $12 million out of a Canadian university
- Pentagon discloses card breach
- Silk Road admin pleads guilty – could face up to 20 years in prison
- Mozilla: Delaying further Symantec TLS certificate distrust
For the more technical
- Derbycon 2018 Videos
- Microsoft October Patch Tuesday summary
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- Microsoft Edge RCE write-up
- Windows 10 ransomware protection bypassed using DLL injection
- Trusting the delivery of Firefox Updates
- Adobe releases October 2018 Security Updates
- WhatsApp fixes bug that let hackers take over app when answering a video call + more information
- Multiple vulnerabilities discovered in MikroTik’s RouterOS
- A mysterious grey-hat is patching people’s outdated MikroTik routers
- Naming & shaming web polluters: Xiongmai
- Siemens fixes new vulnerabilities in its products
- Cisco Prime Infrastructure (CPI) contains two vulnerabilities + more information
- What makes OS drivers dangerous for BIOS?
- How to bypass application whitelisting and Constrained Powershell
- Advanced attacks on Microsoft Active Directory: detection and mitigation
- Threat actors prey on Drupalgeddon vulnerability
- Facebook: An update on the security issue
- Google+ to shut down after coverup of data-exposing bug + more information
- FitMetrix exposed millions of customers’ records in a passwordless database
- Phishing campaign uses hijacked emails to deliver Ursnif
- Police phishing attack targets bank credentials
- Card-skimming group executes scaled supply chain attack on Shopper Approved
- GPlayed trojan – .NET playing with Google Market
- Fake Flash updaters push cryptocurrency miners
- Obfuscated JavaScript cryptominer
- The many faces of Necurs: How the botnet spewed millions of spam emails for cyber extortion
- New TeleBots backdoor: First evidence linking Industroyer to NotPetya
- Thieves and geeks: Russian and Chinese hacking communities
- APT28: New espionage operations target military and government organizations
- Cobalt Group 2.0
- Full discloser of Andariel, a subgroup of Lazarus threat group (PDF)
- Weapon systems cybersecurity: DOD just beginning to grapple with scale of vulnerabilities (PDF)
- How I hacked modern Vending Machines
- How STACKLEAK improves Linux kernel security
- Control Flow Integrity in the Android kernel
- Google and Android have your back by protecting your backups
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – October 14, 2018”