Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- New evidence of hacked Supermicro hardware found in U.S. telecom + additional information
- Supply chain security: An expert’s view
- Czech counterintelligence helps uncover Hezbollah hacking scheme
- The long, weird story explaining why I bid $700 for a stolen PSN account
- How an amateur rap crew stole surveillance tech that tracks almost every American
- How a fraudster got $12 million out of a Canadian university
- Pentagon discloses card breach
- Silk Road admin pleads guilty – could face up to 20 years in prison
- Mozilla: Delaying further Symantec TLS certificate distrust
For the more technical
- Derbycon 2018 Videos
- Microsoft October Patch Tuesday summary
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- Microsoft Edge RCE write-up
- Windows 10 ransomware protection bypassed using DLL injection
- Trusting the delivery of Firefox Updates
- Adobe releases October 2018 Security Updates
- WhatsApp fixes bug that let hackers take over app when answering a video call + more information
- Multiple vulnerabilities discovered in MikroTik's RouterOS
- A mysterious grey-hat is patching people's outdated MikroTik routers
- Naming & shaming web polluters: Xiongmai
- Siemens fixes new vulnerabilities in its products
- Cisco Prime Infrastructure (CPI) contains two vulnerabilities + more information
- What makes OS drivers dangerous for BIOS?
- How to bypass application whitelisting and Constrained Powershell
- Advanced attacks on Microsoft Active Directory: detection and mitigation
- Threat actors prey on Drupalgeddon vulnerability
- Facebook: An update on the security issue
- Google+ to shut down after coverup of data-exposing bug + more information
- FitMetrix exposed millions of customers' records in a passwordless database
- Phishing campaign uses hijacked emails to deliver Ursnif
- Police phishing attack targets bank credentials
- Card-skimming group executes scaled supply chain attack on Shopper Approved
- GPlayed trojan - .NET playing with Google Market
- Fake Flash updaters push cryptocurrency miners
- Obfuscated JavaScript cryptominer
- The many faces of Necurs: How the botnet spewed millions of spam emails for cyber extortion
- New TeleBots backdoor: First evidence linking Industroyer to NotPetya
- Thieves and geeks: Russian and Chinese hacking communities
- APT28: New espionage operations target military and government organizations
- Cobalt Group 2.0
- Full discloser of Andariel, a subgroup of Lazarus threat group (PDF)
- Weapon systems cybersecurity: DOD just beginning to grapple with scale of vulnerabilities (PDF)
- How I hacked modern Vending Machines
- How STACKLEAK improves Linux kernel security
- Control Flow Integrity in the Android kernel
- Google and Android have your back by protecting your backups
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments