Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- GDPR Today – online hub for staying tuned to the (real) life of EU data protection law
- How do you fight a $12B fraud problem? One scammer at a time
- How WordPress is eliminating old versions from the Internet
- Update on British Airways cyber attack
- Cathay Pacific flags data breach affecting 9.4 million passengers
- Bombardier takes Mitsubishi to court, accuses it of ‘data’ theft
- $50 million settlement in Yahoo security breach
- Internet Solutions warns of security breach
- Government spyware vendor left customer, victim data online for everyone to see
- U.S. begins first cyberoperation against Russia aimed at protecting
- Shining a light on federal law enforcement’s use of computer hacking tools
- Millions of exposed tweets by Russian and Iranian bots
- Apple just killed the ‘GrayKey’ iPhone passcode hack
- Now apps can track you even after you uninstall them
- My phone is spying on me, so I decided to spy on it
- A sophisticated ad fraud scheme involving more than 125 Android apps and websites
- This SIM card forces all of your mobile data through Tor
- DNS godfather blasts DNS over HTTPS adoption
- Google mandates two years of security updates for popular phones in new Android contract
- Watch hackers steal a Tesla
For the more technical
- Investigating implausible Bloomberg Supermicro stories
- Remote code execution flaws found in FreeRTOS – popular OS for embedded systems
- An authenticated RCE vulnerability in Cisco WebEx client
- Technical rundown of WebExec
- Vulnerabilities found on WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS
- Microsoft Windows zero-day disclosed on Twitter, again
- Abusing Microsoft Office Online Video
- CVE-2018–8414: A case study in responsible disclosure
- Privilege escalation and file overwrite in X.Org X server
- Zero-day in popular jQuery plugin actively exploited for at least three years
- Clickjacking in Google Docs and voice typing feature
- Multiple 0days used by Magecart
- Universal GandCrab decryption tool released for free on No More Ransom
- The No More Ransom Project – all decryption tools
- Russian government-owned lab most likely built custom intrusion tools for TRITON attackers
- Who might be responsible for Agent Tesla
- Malware distributors adopt DKIM to bypass mail filters
- Bluetooth Low Energy mobile application independent access
- Android/TimpDoor turns mobile devices into hidden proxies
- Banking trojans continue to surface on Google Play
- Chalubo botnet wants to DDoS from your server or IoT device
- Phishing for knowledge
- The hidden story of China Telecom’s BGP hijacking (PDF)
- Tracking users across the web via TLS Session Resumption (PDF)
- Two new supply-chain attacks come to light in less than a week
- How an ISP exposed administrative system credentials
- Fooling AWS CloudTrail and getting persistent access
- Three new DDE obfuscation methods
- Repairnator: a program repair bot for continuous integration
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – October 27, 2018”