Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Cyberinsurance company refuses to pay out full amount to bank after hacking
- Theft of customer data at British Airways
- Alleged ‘Satori’ IoT botnet operator sought media spotlight, got indicted
- U.S. accuses North Korea of plot to hurt economy as spy is charged in Sony hack + more information
- Leader of DDoS-for-hire gang pleads guilty to bomb threats
- Google notifies people targeted by secret FBI investigation
- Riding with the diplomatic couriers who deliver America’s secret mail
- The women code breakers who unmasked Soviet spies
For the more technical
- Drupal Cache Poisoning SA-CORE-2018-005
- Bypassing latest Avast AV on Windows 10 x86_64
- Multi-provider VPN client privilege escalation vulnerabilities
- Keybase browser extension could allow sites to see messages
- Rogue MEGA Chrome extension stole passwords and crypto keys + more information
- Oracle products affected by exploited Apache Struts flaw
- Active exploitation of new Apache Struts vulnerability deploys cryptocurrency miner
- Schneider Electric shipped USB drives loaded with malware
- Malicious MDM: Let’s hide this app
- Popular Mac anti-adware app steals your browsing history + more information
- Thousands of compromised MikroTik routers send traffic to attackers
- PowerPool malware exploits ALPC LPE zero-day vulnerability
- New Chainshot malware found by cracking 512-bit RSA key
- Threat actors peddling weaponized IQY files via Necurs botnet
- Small businesses targeted by highly localized Ursnif campaign
- MagentoCore skimmer most aggressive to date
- CamuBot: New financial malware targets Brazilian banking customers
- White-hats go rogue, attack financial institutions
- FIN6 returns to attack retailer point of sale systems in US, Europe + more information
- Advanced deception with BEC fraud attacks
- Business email compromise via altered invoices
- For 2nd time in 3 years, mobile spyware maker mSpy leaks millions of sensitive records
- Global scan – exposed .git repos
- Threat landscape for industrial automation systems: H1 2018
- BADFET: Defeating modern secure boot using second-order pulsed electromagnetic fault injection (PDF)
- Researchers used sonar signal from a smartphone speaker to steal unlock passwords (PDF)
- Let’s trade: You read my email, I’ll read your password
- A story about a penetration test, where it was not possible to get a shell
- Reverse engineering Medium app (and making all stories in it free)
- Finding the real origin IPs hiding behind CloudFlare or TOR
- Mozilla to block Firefox ad-tracking by default
- Protecting user identities
- Cloud forensics: Why, what and how to extract evidence
- Google’s doors hacked wide open by own employee
- Inside MSRC: Sharing our story & customer tips
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.