Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- GDPR Today - online hub for staying tuned to the (real) life of EU data protection law
- How do you fight a $12B fraud problem? One scammer at a time
- How WordPress is eliminating old versions from the Internet
- Update on British Airways cyber attack
- Cathay Pacific flags data breach affecting 9.4 million passengers
- Bombardier takes Mitsubishi to court, accuses it of ‘data’ theft
- $50 million settlement in Yahoo security breach
- Internet Solutions warns of security breach
- Government spyware vendor left customer, victim data online for everyone to see
- U.S. begins first cyberoperation against Russia aimed at protecting
- Shining a light on federal law enforcement’s use of computer hacking tools
- Millions of exposed tweets by Russian and Iranian bots
- Apple just killed the 'GrayKey' iPhone passcode hack
- Now apps can track you even after you uninstall them
- My phone is spying on me, so I decided to spy on it
- A sophisticated ad fraud scheme involving more than 125 Android apps and websites
- This SIM card forces all of your mobile data through Tor
- DNS godfather blasts DNS over HTTPS adoption
- Google mandates two years of security updates for popular phones in new Android contract
- Watch hackers steal a Tesla
For the more technical
- Investigating implausible Bloomberg Supermicro stories
- Remote code execution flaws found in FreeRTOS - popular OS for embedded systems
- An authenticated RCE vulnerability in Cisco WebEx client
- Technical rundown of WebExec
- Vulnerabilities found on WD My Book, NetGear Stora, SeaGate Home, Medion LifeCloud NAS
- Microsoft Windows zero-day disclosed on Twitter, again
- Abusing Microsoft Office Online Video
- CVE-2018–8414: A case study in responsible disclosure
- Privilege escalation and file overwrite in X.Org X server
- Zero-day in popular jQuery plugin actively exploited for at least three years
- Clickjacking in Google Docs and voice typing feature
- Multiple 0days used by Magecart
- Universal GandCrab decryption tool released for free on No More Ransom
- The No More Ransom Project - all decryption tools
- Russian government-owned lab most likely built custom intrusion tools for TRITON attackers
- Who might be responsible for Agent Tesla
- Malware distributors adopt DKIM to bypass mail filters
- Bluetooth Low Energy mobile application independent access
- Android/TimpDoor turns mobile devices into hidden proxies
- Banking trojans continue to surface on Google Play
- Chalubo botnet wants to DDoS from your server or IoT device
- Phishing for knowledge
- The hidden story of China Telecom’s BGP hijacking (PDF)
- Tracking users across the web via TLS Session Resumption (PDF)
- Two new supply-chain attacks come to light in less than a week
- How an ISP exposed administrative system credentials
- Fooling AWS CloudTrail and getting persistent access
- Three new DDE obfuscation methods
- Repairnator: a program repair bot for continuous integration
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments