Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Iranian hacking group targeted satellite industry nerds
- How a BlackBerry wiretap helped crack a multimillion-dollar cocaine cartel
- Inside the phone company secretly run by drug traffickers
- Major German manufacturer still down a week after getting hit by ransomware
- Japanese hotel chain sorry that hackers may have watched guests through bedside robots
- Vatican’s wearable rosary gets fix for app flaw allowing easy hacks
- Norwegian newspaper website taken offline after content hack
- Open database leaked 179GB in customer, US government, and military records
- 7 million Adobe Creative Cloud accounts exposed to the public
- Prolific business email scam takedown leads to arrests in Spain
For the more technical
- Many nginx + php-fpm configurations vulnerable (exploit)
- PHP remote code execution 0-day discovered in real world CTF exercise
- Trend Micro Anti-Threat Toolkit remote code execution 0-day
- Multiple vulnerabilities in Schneider Electric ProClima
- CVE-2019-16278 – Unauthenticated remote code execution in Nostromo web server
- Maxthon Browser for Windows – Unquoted search path and potential abuses (CVE-2019-16647)
- Your cache has fallen: Cache-Poisoned Denial-of-Service attack (PDF)
- Shikata Ga Nai encoder still going strong
- Alexa and Google Home expose users to vishing and eavesdropping
- Mercedes-Benz app glitch exposed car owners’ information to other users
- Trojan malware infecting 17 apps on the App Store
- Tracking down the developer of Android adware affecting millions of users
- Gustuff return, new features for victims
- Hunting Raccoon: The new masked bandit on the block
- Discord turned into an info-stealing backdoor by new malware
- Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor
- Exploring a link between Magecart Group 5 and the Carbanak APT
- Turla group exploits Iranian APT to expand coverage of victims
- A DDoS gang is extorting businesses posing as Russian government hackers
- Phishing attack targeting United Nations and humanitarian organizations
- AutoIT-compiled Negasteal/Agent Tesla, Ave Maria Delivered via malspam
- Joker’s Stash upgrades with large SSN offering and support infrastructure
- iOS platform security & anti-tampering Swift library
- Threat Intelligence Portal: We need to go deeper
- The Tor Project releases Tor Browser 9.0
- Weaponizing and gamifying AI for WiFi hacking: Presenting Pwnagotchi 1.0.0
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.