Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Maps that care about user privacy
- FBI hacker dropped stolen Airbus data on 9/11
- Hackers claim MGM cyberattack as outage drags into fourth day
- MGM casino’s ESXi servers allegedly encrypted in ransomware attack
- Royal Dutch Football Association confirms it paid ransom for hacked employee data
- Hacking Meduza: Pegasus spyware used to target Putin’s critic
- Phineas Fisher, hacktivism, and magic tricks
- When MFA isn’t actually MFA
- TikTok hit with €345 million fine over privacy settings for children
- The new Have I Been Pwned domain search subscription service
- Intel confirms Thunderbolt 5 name, 120Gbps tech arrives in 2024
For the more technical
- Microsoft September 2023 Patch Tuesday
- With 0-days hitting Chrome, iOS, and dozens more this month, is no software safe?
- Google fixes another Chrome zero-day bug exploited in attacks
- Mozilla patches Firefox, Thunderbird against zero-day exploited in attacks
- Adobe warns of critical Acrobat and Reader zero-day exploited in attacks
- Uncursing the ncurses: Memory corruption vulnerabilities found in library
- The GitHub Actions worm: Compromising GitHub repositories through the actions dependency tree
- Password-stealing without hacking: Wi-Fi enabled practical keystroke eavesdropping (PDF)
- Container escape techniques
- Can’t be contained: Finding a command injection vulnerability in Kubernetes
- Threat landscape for industrial automation systems. Statistics for H1 2023
- Password-stealing Linux malware served for 3 years and no one noticed
- macOS MetaStealer: New family of obfuscated go infostealers spread in targeted attacks
- From ERMAC to Hook: Investigating the technical differences between two Android malware variants
- Ongoing Webex malvertising campaign drops BatLoader
- OriginBotnet spreads via malicious Word document
- RedLine/Vidar abuses EV certificates, shifts to ransomware
- From Caribbean shores to your devices: analyzing Cuba ransomware
- 3AM: New ransomware family used as fallback in failed LockBit attack
- Redfly: Espionage actors continue to target critical infrastructure
- Digital threats from East Asia increase in breadth and effectiveness
- Sponsor with batch-filed whiskers: Ballistic Bobcat’s scan and strike backdoor
- Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.