Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Scottish beer firm becomes victim of sophisticated ransomware attack
- Microsoft automatically installs six bloatware apps onto every Windows 10 PC
- How much are stolen frequent flyer miles worth on the dark web?
- United Nations accidentally exposed passwords and sensitive information to the whole Internet
- COI on SingHealth cyber attack: Hackers searched for PM Lee’s records using his NRIC number
- NSA coder jailed for smuggling secrets that wound up in Russian hands
- Hacker linked to Target data breach gets 14 years in prison
- When a refugee camp becomes an innovation incubator
For the more technical
- New CVE-2018-8373 exploit spotted
- Facebook discovered ‘security issue’ affecting 50 million accounts
- Credential leak flaws in Windows PureVPN client
- Bypassing Duo two-factor authentication
- The latest Bitcoin bug was so bad, developers kept its full details a secret
- A cache invalidation bug in Linux memory management
- Outrunning attackers on the Jet Database Engine 0day
- The known_hosts file can help Red Teams
- Password managers can be tricked into believing that malicious Android apps are legitimate
- Banking trojan found on Google Play stole 10,000 Euros from victims
- Cryptojacking apps return to Google Play Market
- USB threats from malware to miners
- One Emotet infection leads to three follow-up malware infections
- VPNFilter: More tools for the Swiss army knife of malware
- First UEFI rootkit found in the wild, courtesy of the Sednit group
- Defeating fileless malware with behavior monitoring, AMSI, and next-gen AV
- Deep analysis of a driver-based MITM malware: iTranslator
- The ‘Gazorp’ Dark Web Azorult builder
- How the Dridex gang makes millions from bespoke ransomware
- Adwind dodges AV via DDE
- Hide and Seek IoT botnet uses ADB over Internet to exploit thousands of Android devices
- Torii botnet – not another Mirai variant
- Cyber attacks on colleges and universities: who, when and why?
- Ghostbuster: Detecting the presence of hidden eavesdroppers (PDF)
- Secret Service warns of surge in ATM ‘wiretapping’ attacks
- How to protect your data from Magecart and other e-commerce attacks
- Release 2.1.1 Mimikatz
- Introducing the Librem Key
- Mozilla rolls out recovery key option for Firefox accounts
- Password tips from a pen tester
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
One thought on “IT Security Weekend Catch Up – September 29, 2018”