Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Cyber cheat dupes Mumbai businessman of Rs 15.5 lakh with credit card scam, cops recover Rs 7.5 lakh
- Darkweb market BidenCash gives away 1.2 million credit cards for free
- Report: Big U.S. banks are stiffing account takeover victims
- Celsius exchange data dump is a gift to crypto sleuths—and thieves
- Toyota discloses data leak after access key exposed on GitHub
- Intel confirms Alder Lake BIOS source code leak, new details emerge
- US airports’ sites taken down in DDoS attacks by pro-Russian hackers
- How Wi-Fi spy drones snooped on financial firm
- Indian energy company Tata Power announces cyberattack affecting IT infrastructure
For the more technical
- Microsoft October 2022 Patch Tuesday fixes zero-day used in attacks, 84 flaws
- Microsoft Office 365 attacked over feeble encryption
- Ongoing exploitation of CVE-2022-41352 (Zimbra 0-day)
- FortiOS, FortiProxy, and FortiSwitchManager authentication bypass technical deep dive (CVE-2022-40684)
- The race to native code execution in PLCs: Using RCE to uncover Siemens SIMATIC S7-1200/1500 hardcoded cryptographic keys
- Hacking TMNF: Part 1 – Fuzzing the game server
- Hacking TMNF: Part 2 – Exploiting a blind format string
- Analysing LastPass
- Signal will remove support for SMS text messages on Android
- Malicious WhatsApp mod distributed through legitimate apps
- Facebook: Protecting people from malicious account compromise apps
- Truth behind the Celer Network cBridge cross-chain bridge incident: BGP hijacking
- Cloudflare DDoS threat report 2022 Q3
- Project DDOSIA Russia’s answer to disBalancer
- The fresh phish market: Behind the scenes of the Caffeine phishing-as-a-service platform
- Alchimist: A new attack framework in Chinese for Mac, Linux and Windows
- TOAD attacks: Vishing combined with Android banking malware now targeting Italian banks
- A visualizza into recent IcedID
- Fake ransomware infection under widespread
- Magniber ransomware adopts JavaScript, targeting home users with fake software updates
- Black Basta ransomware gang infiltrates networks via QAKBOT, Brute Ratel, and Cobalt Strike
- New “Prestige” ransomware impacts organizations in Ukraine and Poland
- Polonium targets Israel with Creepy malware
- Tracking Earth Aughisky’s malware and changes
- LofyGang – software supply chain attackers; organized, persistent, and operating for over a year
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.