Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Telegram now shares users’ IP and phone number on legal requests
- Firefox tracks you with “privacy preserving” feature
- EU privacy regulator fines Meta 91 million euros over password storage
- Disney to ditch Slack following July data breach
- Uniting for Internet freedom: Tor Project & Tails join forces
- macOS Sequoia change breaks networking for VPN, antivirus software
- “Bad Romance”: How Kaspersky Lab failed to conquer the Western cybersecurity market
- Mystery profile linked to Hungarian firm implicated in exploding pagers
- Web tracking report: who monitored users’ online activities in 2023–2024 the most
For the more technical
- Attacking UNIX Systems via CUPS, Part I
- Critical exploit in MediaTek Wi-Fi chipsets: Zero-click vulnerability (CVE-2024-20017) threatens routers and smartphones
- Critical NVIDIA AI vulnerability affecting containers using NVIDIA GPUs, including over 35% of cloud environments
- CVE-2024-28987: SolarWinds Web Help Desk hardcoded credential vulnerability deep-dive + PoC
- Threat landscape for industrial automation systems, Q2 2024
- Hacking Kia: Remotely controlling cars with just a license plate
- Wallet scam: A case study in crypto drainer tactics
- Octo2: European banks already under attack by new malware variant
- Gleaming Pisces poisoned Python packages campaign delivers PondRAT Linux and MacOS backdoors
- HTML Smuggling: How blob URLs are abused to deliver phishing content
- 10 years of DLL Hijacking, and what we can do to prevent 10 more
- Infostealer malware bypasses Chrome’s new cookie-theft defenses
- LummaC2: Obfuscation through indirect control flow
- BBTok targeting Brazil: Deobfuscating the .NET loader with dnlib and PowerShell
- SilentSelfie: Uncovering a major watering hole campaign against Kurdish websites
- Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023
- Storm-0501: Ransomware attacks expanding to hybrid cloud environments
- Examining mobile threats from Russia
- The Iranian cyber capability
- Iran steps up efforts in U.S. election meddling
- Kryptina RaaS: From unsellable cast-off to enterprise ransomware
- Inside SnipBot: The latest RomCom malware variant
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.