Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [VIDEO] AI and hacking – opportunities and threats – Joseph “rez0” Thacker
- This new data poisoning tool lets artists fight back against generative AI
- Who’s behind Israel-Gaza disinformation and hate online?
- Are social media giants censoring pro-Palestine voices amid Israel’s war?
- Spanish police arrest 34 alleged cybercriminals for scamming operation
- Brave appears to install VPN Services without user consent
- CCleaner says hackers stole users’ personal data during MOVEit mass-hack
- 1Password detects “suspicious activity” in its internal Okta account
- QNAP takes down server behind widespread brute-force attacks
- They cracked the code to a locked USB drive worth $235 million in Bitcoin. Then it got weird
For the more technical
- iLeakage: Browser-based timerless speculative execution attacks on Apple devices
- Citrix Bleed: Leaking session tokens with CVE-2023-4966
- Putting censorship circumvention to the test: Security audit findings
- Pwn2Own Toronto 2023 – day one results
- Pwn2Own Toronto 2023 – day two results
- Pwn2Own Toronto 2023 – day three results
- Pwn2Own Toronto 2023 – day four results
- Phishing guidance: Stopping the attack cycle at phase one
- Malware stories: Deworming the XWorm
- Mystic Stealer revisited
- Rhysida ransomware technical analysis
- Measuring the potential impact of Pipedream malware OPC UA module, Mousehole
- Leveraging a hooking framework to expand malware detection coverage on the Android platform
- From Copacabana to Barcelona: The cross-continental threat of Brazilian banking malware
- Sophisticated StripedFly spy platform masqueraded for years as crypto miner
- How to catch a wild triangle
- The outstanding stealth of Operation Triangulation
- IPinside: Korea’s mandatory spyware
- ENISA Threat Landscape 2023 report
- Cloud and threat report: Top adversary tactics and techniques
- ESET APT Activity Report Q2–Q3 2023
- Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers
- Technical writeup: Malware campaigns targeting Armenian infrastructure and users
- A cascade of compromise: unveiling Lazarus’ new campaign
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.