Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [VIDEO] Hack.lu 2023: Introduction to cyberwarfare: Theory and practice – Lukasz Olejnik
- Ragnar Locker ransomware’s dark web extortion sites seized by police
- Moldovan charged, arrested, and extradited for administration of site involved in the illicit sale of compromised computer credentials
- U.S. DoJ cracks down on North Korean IT scammers defrauding global businesses
- Apple’s compliance with China app rules plugs censorship loophole, creates new obstacles for developers
- Fraudsters target Booking.com customers claiming hotel stay could be cancelled
- 530K people’s info feared stolen from cloud PC gaming biz Shadow
- Casio discloses data breach impacting customers in 149 countries
- Hacker leaks millions more 23andMe user records on cybercrime forum
- IT admins are just as culpable for weak password use
- Hackers stole access tokens from Okta’s support unit
- How Cloudflare mitigated yet another Okta compromise
For the more technical
- Signal says there is no evidence rumored zero-day bug is real
- CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
- Active exploitation of Cisco IOS XE software web management user interface vulnerability
- Widespread Cisco IOS XE implants in the wild + Cisco IOS XE implant scanner
- Looking for CVE-2023-43261 in the real world
- Updated MATA attacks industrial companies in Eastern Europe
- 55 vulnerabilities in Squid Caching Proxy and 35 0days
- Government-backed actors exploiting WinRAR vulnerability
- Google-hosted malvertising leads to fake Keepass site that looks genuine
- No one is Prefect – is your MLOps infrastructure leaking secrets?
- Encrypted traffic interception on Hetzner and Linode targeting the largest Russian XMPP (Jabber) messaging service
- Critical unauthenticated arbitrary file upload vulnerability in Royal Elementor Addons and Templates being actively exploited
- Void Rabisu targets female political leaders with new slimmed-down Romcom variant
- US cybersecurity agencies have published an update on their StopRansomware guide (PDF)
- In-depth analysis of a worldwide Linux XorDDoS campaign
- Take a note of SpyNote
- Lumma Stealer distributed via Discord CDN
- DarkGate opens organizations for attack via Skype, Teams
- APT trends report Q3 2023
- “EtherHiding” — Hiding Web2 malicious code in Web3 smart contracts
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.