Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Tales from the Crypto: How the Baltic states became the hub of money laundering and fraud
- UK passport images database could be used to catch shoplifters
- Amazon made $1B with secret algorithm for spiking prices Internet-wide
- Sony confirms data breach impacting thousands in the U.S.
- Group attacking Apple encryption linked to dark-money network
- Red Cross lays down hacktivism law as Ukraine war rages on
- People exploited YouTube bug to upload “undeletable” porn videos
- A closer look at the Snatch data ransom group
- Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts
- The SiegedSec crew claimed it broke into six NATO web portals
For the more technical
- CVE-2023-4911: Looney Tunables – local privilege escalation in the glibc’s ld.so
- Microsoft’s response to open-source vulnerabilities – CVE-2023-4863 and CVE-2023-5217
- Cisco Emergency Responder static credentials vulnerability
- Behind the screens: An overview of hidden attack surfaces in powerful BMC chip infrastructure
- ShellTorch: Multiple critical vulnerabilities in PyTorch model server (TorchServe) threatens countless AI users
- NSA and CISA advise on top ten cybersecurity misconfigurations
- Cloudflare DDoS protections ironically bypassed using Cloudflare
- Thousands of GitHub comments leak live API keys
- Exposing infection techniques across supply chains and codebases
- Analyzing Lu0Bot: A Node.js malware with near-unlimited capabilities
- BunnyLoader, the newest malware-as-a-service
- Let’s dig deeper: dissecting the new Android trojan GoldDigger
- LightSpy mAPT mobile payment system attack
- Typosquatting campaign delivers r77 rootkit via npm
- Malicious packages hidden in npm
- Introducing the REF5961 intrusion set
- Qakbot-affiliated actors distribute Ransom Knight malware despite infrastructure takedown
- Operation Jacana: Foundling hobbits in Guyana
- Chinese state-sponsored cyber espionage activity targeting semiconductor industry in East Asia
- Active Lycantrox infrastructure illumination
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.