Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Mark Zuckerberg has been added to a DC lawsuit over the Cambridge Analytica scandal
- Fake YouTube Apple event stream draws 30k viewers before turning into crypto scam
- Hacker steals government ID database for Argentina’s entire population
- Fraudsters cloned company director’s voice in $35 million bank heist, police find
- Hacker defaces Donald Trump’s website
- Acer hacked twice in a week by the same threat actor
- Zerodium wants zero-day exploits for Windows VPN clients
- Two individuals sentenced for providing “bulletproof hosting” for cybercriminals
- Facebook sues Ukrainian who scraped the data of 178 million users
- Governments turn tables on ransomware gang REvil by pushing it offline
- Hospital attack ‘purely financial,’ likely by Chinese group
For the more technical
- Exploit kit adds rare Chrome browser attack chain
- Windows 10, iOS 15, Ubuntu, Chrome fall at China’s Tianfu hacking contest
- CVE-2021-42299: TPM Carte Blanche
- Disabling JavaScript won’t save you from fingerprinting
- Gummy Browsers: Targeted browser spoofing against state-of-the-art fingerprinting techniques (PDF)
- Credit card PINs can be guessed even when covering the ATM pad
- New SmashEx attack breaks Intel SGX enclaves
- Evaluating physical-layer BLE location tracking attacks on mobile devices (PDF)
- Cobalt Strike: Using known private keys to decrypt traffic
- Digitally-signed rootkits are back – A look at FiveSys and companions
- Trickbot rising — Gang doubles down on infection efforts to amass network footholds
- Trickbot module descriptions
- A decryptor for the ransomware BlackByte
- Karma ransomware – An emerging threat with a hint of Nemty pedigree
- TA505 ramps up activity, delivers new FlawedGrace variant
- Newly found npm malware mines cryptocurrency on Windows, Linux, macOS devices
- Shining a light on RedLine Stealer malware and identity data found in criminal shops
- Phishing campaign targets YouTube creators with cookie theft malware
- LightBasin: A roaming threat to telecommunications companies
- Russian-speaking cybercrime evolution: What changed from 2016 to 2021
- New espionage campaign targets South East Asia
- FIN7 recruits talent for push into ransomware
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.