Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [VIDEO] Why NSA whistleblower Edward Snowden risked his life to expose surveillance state
- Spain security firm probed ‘for spying on Assange for CIA’
- Meet Candiru – the mysterious mercenaries hacking Apple and Microsoft PCs for profit
- Legit-looking iPhone lightning cables that hack you will be mass produced and sold
- Amazon and Apple are quietly building networks that know the location of everything
- Facebook is being asked to give access to encrypted messages
- Former Yahoo engineer pleads guilty to hacking user emails in search for porn
- Zendesk breach hits 10,000 corporate accounts
- Comodo forums breached, data of over 170,000 users up for grabs
- Ransomware forces 3 hospitals to turn away all but the most critical patients
- Dutch police take down hornets’ nest of DDoS botnets
- German cops raid “Cyberbunker 2.0,” arrest 7 in child porn, dark web market sting
For the more technical
- New PDFex attack can exfiltrate data from encrypted PDF files (PDF)
- MMD-0064-2019 – Linux/AirDropBot
- New SIM attacks de-mystified, protection tools now available + more information
- WebEx, Zoom meetings exposed to snooping via enumeration attacks
- How a double-free bug in WhatsApp turns to RCE
- Attackers exploit 0-day vulnerability that gives full control of Android phones
- An exploration of apps’ circumvention of the Android permissions system
- Understanding Android VoIP security:A system-level vulnerability assessment (PDF)
- Signal: Incoming call can be connected without user interaction
- Exploiting Tinder to get paid features for free
- Webkit zero-day exploit besieges Mac and iOS users with malvertising redirects
- ‘Fleeceware’ Play store apps quietly charging up to $250
- HELO Winnti: Attack or scan?
- New ‘Gucci’ IoT botnet targets Europe
- Recent cyberattacks require us all to be vigilant
- New Adwind campaign targets US petroleum industry
- Threat landscape for industrial automation systems, H1 2019
- Avivore – hunting global aerospace through the supply chain
- Magecart Group 4: A link with Cobalt Group?
- Pulling back the curtain on a banking botnet (PDF)
- Casbaneiro: Dangerous cooking with a secret ingredient
- The eye on the Nile
- BEC actors compromise vendor accounts to target organizations via invoice wire fraud (PDF)
- Freedom Hosting 2: Forums
- Analysis and disclosure of the US Central Intelligence Agency network weapons database
- How bad actors hide their malicious code
- Four and a half Apple passwords
- How to extract screen time passcodes and voice memos from iCloud
- How to break into a Jeep when you don’t have a knife
- Cloudflare’s Warp VPN is now available to all
- Google Chrome: No more mixed messages about HTTPS
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.