Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Hive claims ransomware attack on Tata Power, begins leaking data
- Iran’s atomic energy agency confirms hack after stolen data leaked online
- Hacker and Dark Market operator arraigned on federal charges
- Elon Musk closes Twitter deal, immediately fires top executives
- Chrome won’t support Windows 7 or Windows 8.1 in 2023
For the more technical
- Stranger Strings: An exploitable flaw in SQLite
- Critical OpenSSL fix due Nov 1—what you need to know
- Upcoming critical OpenSSL vulnerability: What will be affected?
- Google fixes seventh Chrome zero-day exploited in attacks this year
- How an attacker can achieve persistence in Google Cloud Platform (GCP) with cloud shell
- A bug in Apple MacOS Ventura breaks third-party security tools
- Hope of delivery: Extracting user locations from mobile instant messengers (PDF)
- Ring0VBA – Getting Ring0 using a goddamn Word document
- How security professionals are being attacked: A study of malicious CVE proof of concept exploits in GitHub (PDF)
- Sysdig TRT uncovers massive cryptomining operation leveraging GitHub Actions
- Hackers use Microsoft IIS web server logs to control malware
- Mirai, RAR1Ransom, and GuardMiner – multiple malware campaigns target VMware vulnerability
- Fodcha DDoS botnet reaches 1Tbps in power, injects ransoms in packets
- “Dormant Colors”: Live campaign with over 1M data stealing extensions installed
- From Gozi to ISFB: The history of a mythical malware family
- ERMAC Android malware increasingly active
- Where is the origin?: Qakbot uses valid code signing
- Archive sidestepping: Self-unlocking password-protected RAR
- Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
- Exbyte: BlackByte ransomware attackers deploy new exfiltration tool
- DEV-0832 (Vice Society) opportunistic ransomware campaigns impacting US education sector
- Pro-PRC DragonBridge influence campaign leverages new TTPs to aggressively target U.S. interests, including midterm elections
- APT27 – One year to exfiltrate them all: Intrusion in-depth analysis
- Gremlins’ prey, secrets, and dirty tricks: the ransomware gang OldGremlin set new records
- Unattributed RomCom threat actor spoofing popular apps now hits Ukrainian militaries
- WarHawk: the new backdoor in the arsenal of the SideWinder APT group
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.