Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- ProtonMail logged IP address of French activist after order by Swiss authorities
- German government admits buying Pegasus spyware, says ‘limited’ to respect privacy laws
- NSO Group affiliate circles sold equipment to Uzbekistan ‘secret police’
- UK government backs Apple, and wants to scan encrypted messages for CSAM
- Australia: Unprecedented surveillance bill rushed through parliament in 24 hours
- Texas schools are surveilling students online, often without their knowledge or consent
- How Facebook undermines privacy protections for its 2 billion WhatsApp users
- Hackers leak passwords for 500,000 Fortinet VPN accounts
- Ransomware gang threatens to leak data if victim contacts FBI, police
- Confessions of a ransomware negotiator: Well, somebody’s got to talk to the criminals holding data hostage
- The ideal ransomware victim: What attackers are looking for
- REvil ransomware is back in full attack mode and leaking data
- UN computer networks breached by hackers earlier this year
- Ukrainian cyber criminal extradited for decrypting the credentials of thousands of computers
- TrickBot gang member arrested after getting stuck in South Korea due to COVID-19 pandemic
- The operator of a Dark Web assassination site was arrested in Russia
- Hacking Team customer in Turkey was arrested for spying on police colleagues
- You don’t need to burn off your fingertips (and other biometric authentication myths)
For the more technical
- Introduction to OWASP Top 10 2021
- Microsoft shares temp fix for ongoing Office 365 zero-day attacks
- Windows MSHTML zero-day defenses bypassed as new info emerges
- Remote code execution 0-day (CVE-2021-40444) hits Windows, triggered via Office docs
- Coordinated disclosure of vulnerability in Azure Container Instances Service
- Finding Azurescape – Cross-account container takeover in Azure Container Instances
- PoC for RCE 0-day for GhostScript 9.50
- Analyzing SSL/TLS certificates used by malware
- CVE-2021-26084: Confluenza
- Demon’s Cries vulnerability (some NETGEAR smart switches)
- Draconian Fear vulnerability (some NETGEAR smart switches)
- New CPU side-channel attack takes aim at Chrome’s Site Isolation featur
- A deep-dive into the SolarWinds Serv-U SSH vulnerability
- Android Security Bulletin—September 2021
- Research shows over 10% of sampled Firebase instances open
- How a Russian mobile app developer recruited phones into a secret ad-watching robot army
- Someone could be tracking you through your headphones
- Threat landscape for industrial automation systems in H1 2021
- Meet Meris, the new 250,000-strong DDoS botnet terrorizing the internet
- Cybercrime group FIN7 using Windows 11 Alpha-themed docs to drop Javascript backdoor
- BladeHawk group: Android espionage against Kurdish ethnic group
- EGoManiac: An unscrupulous Turkish-nexus threat actor
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.