Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Human trafficking’s newest abuse: Forcing victims into cyberscamming
- Ethereum completes the “Merge,” which ends mining and cuts energy use by 99.95%
- UK provisionally approves $8.1B NortonLifeLock-Avast merger, citing competition from Microsoft
- FCC proposes cybersecurity changes to emergency alert system
- Cisco confirms Yanluowang ransomware leaked stolen company data
- Fears grow of Russian spies turning to industrial espionage
For the more technical
- Microsoft September 2022 Patch Tuesday
- Binarly finds six high severity firmware vulnerabilities in HP enterprise devices
- Contec FLEXLAN FXA2000 and FXA3000 series vulnerability report
- Yubikey madness
- Use-after-freedom: MiraclePtr
- Performance regression in Linux kernel 5.19
- TickTock: Detecting microphone status in laptops leveraging electromagnetic leakage of clock signals (PDF)
- New attack can unlock and start a Tesla Model Y in seconds (PDF)
- Say hello to crazy thin ‘deep insert’ ATM skimmers
- Record-breaking DDoS attack in Europe
- Nearly 5 million attacks blocked targeting 0-day in BackupBuddy plugin
- Hackers use the browser-in-the-browser technique to steal Steam accounts
- Magento vendor Fishpig hacked, backdoors added
- Prompt injection attacks against GPT-3
- “GIFShell” — covert attack chain and C2 utilizing Microsoft Teams GIFs
- Phishing campaign targets Greek banking users
- Undermining Microsoft Teams security by mining tokens
- It’s time to PuTTY! DPRK job opportunity phishing via WhatsApp
- Self-spreading stealer attacks gamers via YouTube
- Opsec mistakes reveal Cobalt Mirage threat actors
- Lorenz ransomware group cracks MiVoice and calls back for free
- Webworm: Espionage attackers testing and using older modified RATs
- OriginLogger: A look at Agent Tesla’s successor
- Ransomware developers turn to intermittent encryption to evade detection
- You never walk alone: The SideWalk backdoor gets a Linux variant
- TA453 uses multi-persona impersonation to capitalize on FOMO
- Pro-Palestinian hacking group compromises Berghof PLCs in Israel
- Gamaredon APT targets Ukrainian government agencies in new campaign
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.