Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! newsletter: Email oops, and how to avoid them (PDF)
- Sales engagement startup Apollo says its massive contacts database was stolen in a data breach
- Open-source crypto is no better than closed-source crypto
- Voice phishing scams are getting more clever
- How companies use fake websites and backdated articles to censor Google’s search results
- How a hapless Bitcoin entrepreneur started a multimillion-dollar Ponzi scheme
- FBI solves mystery surrounding 15-year-old Fruitfly Mac malware
- Travellers refusing digital search now face $5000 Customs fine
- CEO pleads guilty to selling encrypted phones to organized crime
- French police officer caught selling confidential police data on the dark web
- FSB agents leaked secret data to the FBI for 10 million dollars
- Russian envoy rejects reports of cybercrimes
- Saudi-linked cyber espionage against Canadian victim discovered
- A Russian-speaking journalist visits China’s dystopian police state
- In El Chapo’s trial, extraordinary steps to keep witnesses alive
For the more technical
- Windows 10 October 2018 Update is deleting user data
- Intel ME Manufacturing Mode – obscured dangers
- Intel Q1’18 – security review cumulative update
- Critical vulnerabilities in Emerson AMS Device Manager
- An interesting Google vulnerability that got me 3133.7 reward
- A new vulnerability in Google PDFium’s JBIG2 library
- Telegram leaks IP addresses by default when initiating calls
- Recent wave of hijacked WhatsApp accounts traced back to voicemail hacking
- Multiple vulnerabilities in Fuji Electric industrial products
- Auditing KRACKs in Wi-Fi (PDF)
- Cyber actors increasingly exploit the Remote Desktop Protocol to conduct malicious activity
- Threat actors customize URLs to avoid detection
- Hackers can stealthily avoid traps set to defend the cloud
- A staggering amount of stolen data is heading to Zoho domains
- Identifying a phisher
- Someone used my IPFS gateway for phishing
- When security researchers pose as cybercrooks, who can tell the difference?
- MageCart: now with tripwire
- Gigantic 100,000-strong botnet used to hijack traffic meant for Brazilian banks + additional information
- Researchers analyzed a stealthy malware family named Stegoloader
- Fileless malware: part deux
- New Betabot campaign under the microscope
- Roaming Mantis: iOS crypto-mining and spreading via malicious content delivery system
- Hidden Cobra – FASTCash campaign
- Shedding skin – Turla’s fresh faces
- Details of Qatar’s cyber espionage campaign in the United States
- APT38: Details on new North Korean regime-backed threat group
- APT37: Final1stspy reaping the FreeMilk + technical description
- Video analysis of Android SMS worm spying on victims
- Mini pwning with GL-iNet AR150
- How to spot good fuzzing research
- Deployment of Microsoft 365 security solutions
- Trustworthy Chrome extensions, by default
- Everything you wanted to know about Activation Lock and iCloud Lock
- Recipe for the Apple Wireless Direct Link ad hoc protocol
- Jailbreaks demystified
- Violating your personal space with Webex
- Penetration testing dropbox – [1] [2] [3]
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – October 7, 2018”