Key security articles for week ending 22-7-22
Daniel Aldam
Award-Winning CISO | Strategic Leadership in Cybersecurity | Security Programs Architect | GRC & Security Operations Expert | Proven Team Leader | Mentor
I had a need to analyse the week's security news today, so thought I would share. If anyone is interested, I may repeat it in the future, but for now this is all about me :)
21-7-22
The @GCHQ and @NCSC proposals for child safety surrounding end-to-end encryption, all amount to a single premise: that messenger software should [be forced to] lie to its users regarding the privacy that it provides.
Heatwave forced Google and Oracle to shut down computers
Continued cyber activity in Eastern Europe observed by TAG
iOS 16 Lockdown Mode will significantly enhance the security of the devices if turned on
A crack in the Linux firewall/ Billions of Linux devices will never be patched for a new netfilter vulnerability
NFT collector loses 100 ETH (~$150,000) in a joke gone wrong
Confluence has another critical bug, with hard-coded credentials
20-7-22
TeamViewer installs suspicious font only useful for web fingerprinting
Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware
In no joking:), I discovered like 17 RCE bugs all in a SINGLE attack surface in Windows, which proved one point I've been talking about for a while. Thread.
Justice Department Seizes and Forfeits Approximately $500,000 from North Korean Ransomware Actors and their Conspirators
19-7-22
SATAn: Air-Gap Exfiltration Attack via Radio Signals From SATA Cables
Busting browser fails: What attackers see when they hack your employees’ browser
领英推荐
New security research: #PassBleed: How to get @okta master passwords in clear text for all employees
‘Zero Trust’ security is a poor choice of words
A wide range of routers are under attack by new, unusually sophisticated malware
Lock Screen Bypass Exploit of Android Devices (CVE-2022–20006)
Google Play hides app permissions in favor of developer-written descriptions
China faces its first truly mega-leak (1 billion user’s records exposed)
Denmark bans Google Workspace:
Digium Phones Under Attack: Insight Into the Web Shell Implant
Software advertised on social media as a password-recovery and password brute-forcing tool for programmable logic controllers (PLCs) also contains a version of the Sality malware.
Attack vector for GitHub projects
New vulnerabilities in fingerprint sensors and cryptocurrency wallets
Experts concerned about ransomware groups creating searchable databases of victim data
Ongoing phishing campaign can hack you even when you’re protected with MFA
Are blockchains decentralized?
Source articles unashamedly stolen from https://risky.biz/ and https://substack.com/profile/11790324-the-grugq , comments are mine.
General Manager | Enterprise Architect | IT Strategist
2 年Well I feel less secure now! But seriously, that is a lot of interesting and informed views shared on very current cybersec topics. Thanks for taking the time to summarise and share.