Archive
All 306 issues, newest first. Looking for something specific? Search the archive.
2026
- #306Catch-up on a bunch of news :-) 19 February 2026
2025
- #305Catching up on two weeks worth of news. 7 October 2025
- #304Takeover issue in Entra ID. New supply chain attack on npm. Malware with embedded LLMs.22 September 2025
- #303NPM attack fallout. Cursor AI default settings. CISA pledges further support for CVE.16 September 2025
- #302Popular npm packages compromised. Also other supply chain attacks. Phishing with SVG images. Misbehaving CAs.9 September 2025
- #301Salesforce-Salesloft Drift integration compromised. Antropic shares examples of AI use in malware. US private sector possibly going on the (cyber) offensive.2 September 2025
- #300Critical flaw in Docker Desktop. PyPi adds domain resurrection mitigation. Clickjacking in password managers. 26 August 2025
- #299Breach in Dutch cancer screenings. Abusing Entra OAuth. Cisco and Fortinet warn of critical issues.18 August 2025
- #298Critical issue in Exchange. DARPA selects winner in AI code review competition. Proton fixes issue in 2FA app.11 August 2025
- #297North Korean IT worker schemes on the rise. Tea app data theft. CISA open sources malware analysis tooling.4 August 2025
- #296Sharepoint servers under attack. Microsoft outsourcing DoD work to China. Several supply chain issues.25 July 2025
- #295Citrix Bleed 2. Supply chain issues with developer tools. 123456.18 July 2025
- #294Github Actions supply chain attack. Wiz acquired for $32B. Taking a short break.21 March 2025
- #293Ransomware running from a webcam. ESP32 hidden commands. Critical PHP RCE mass-exploited.13 March 2025
- #292VMware vulnerabilities. CISA will not stop monitoring Russia. North-Korea tries to launder $1.4B in crypto.6 March 2025
- #291Black Basta chatlogs leak. North Korean $1.5B heist. VSCode Material theme pulled.28 February 2025
- #290Two OpenSSH vulnerabilities. Hiding Javascript in plain sight. How not to communicate about a breach.20 February 2025
- #289Apple fixes USB Restricted Mode zero-day. Massive brute force attack from 2.8 million IP's. Manipulating AI long-term memory.14 February 2025
- #288DeepSeek concerns. Ransomware payments down 35% in 2024. US healthcare provider breach impacting 1 million.6 February 2025
- #287Subaru cars hijacked from a distance. Medical device backdoored to Chinese IP. DeepSeek database exposed.31 January 2025
- #286Record DDoS attack of 5.6 Tbps. HPE sourcecode maybe breached. Trying different format.23 January 2025
- #285Biden rolls out cybersecurity executive order. Hackers leak configs and credentials for 15,000 FortiGate devices. FTC sues GoDaddy.17 January 2025
- #284US launches cybersecurity label. 4000 webshell domains sinkholed. 10 January 2025
- #283Ninth US telecom breach confirmed. 3 million email servers without TLS. 2024 wrap-up.3 January 2025
2024
- #282$3 billion towards US ‘rip and replace’ of Chinese tech. UN approves controversial cybercrime treaty.27 December 2024
- #281Large-scale campaign targeting security people. TP-Link might get banned in the US. Jen Easterly to step down from CISA.20 December 2024
- #28027 DDoS-for-hire platforms shut down. Bypassing browser isolation with QR code based c2. A new round of MITRE vendor competition/evaluation.12 December 2024
- #279Chinese telecom hacks have been going for years. Cloudflare dev domains often abused. Arrests for DDoS features in satellite receivers.6 December 2024
- #278Nearest neighbour attack: hacking one wifi to get access to another. First of a kind Linux bootkit.29 November 2024
- #277MITRE top 25 for 2024. New Linux malware. Microsoft launches Zero Day Quest.23 November 2024
- #276Most exploited vulnerabilities of 2023. Volt Typhoon rebuilds botnet. Microsoft adopting CSAF format.16 November 2024
- #275Google Cloud MFA mandated. Hacking 700 million EA accounts ethically. Quick version.8 November 2024
- #274Infostealer infrastructure hacked by Dutch police and FBI. Second Biden executive order on cybersecurity underway. Git config files still exposed all over the place.1 November 2024
- #273Pwn2Own results. Microsoft Azure honeypots. Apple private cloud bug bounty. Another Fortinet zeroday.25 October 2024
- #272Nearly 400 US healthcare institutions hit with ransomware in the last year. New proposal for moving passkeys around. Also hacked robot vacuum cleaners turning racist.18 October 2024
- #271GoldenJackal anti-airgap malware. American Water breached. Internet Archive too. CUSP scanner.11 October 2024
- #270Linux malware perfctl uncovered. Meta fined $91 million for logging plaintext passwords. New DDoS record of 3.8 Tbps.4 October 2024
- #269Kansas water plant breached. KIA cars remotely accessible. NIST common sense password guidelines.27 September 2024
- #268Hezbollah pager explosions. 23andMe to pay 30$ million settlement. Unexplained "noise storms" on the Internet.20 September 2024
- #267Rambo and Pixhell anti-airgap attacks. Big update for the Flipper Zero. Fortinet breached.13 September 2024
- #266Yubikey 5 cloning vulnerability. MFA bypass service busted. Crappy securitycam company fined by the FTC. 6 September 2024
- #265Windows Downdate tool released. Telegram founder arrested. Ransomhub with 200+ victims since February.30 August 2024
- #264Microsoft update breaks dual boot. Solarwinds hardcoded password issue.23 August 2024
- #263Zero-click RCE against Windows IPv6. Github actions with leaked tokens. Data breach with 3 billion records.16 August 2024
- #262"0.0.0.0 Day" browser vulnerability. Windows Update downgrade attack unpatches systems. No action by the SEC against MOVEit vendor.9 August 2024
- #261Some more Crowdstrike fallout. Digicert revoking 83.000 certificates.2 August 2024
- #260Crowdstrike wrap-up. Also some other stuff.26 July 2024
- #259Crowdstrike issue taking down companies around the world. AT&T breach leaking all call logs. Kaspersky shutting down in the US.19 July 2024
- #258New kind of attack on RADIUS protocol. Linksys routers sending Wifi passwords out in plain text.11 July 2024
- #257SSH vulnerability "RegreSSHion". Cobalt Strike servers takedown. Powerful supply-chain vulnerabilities for iOS and Mac apps.5 July 2024
- #256Massive polyfill.io supply chain attack. Teamviewer breached. More MOVEit vulnerabilities.28 June 2024
- #255Complete US ban of Kaspersky products. New UEFI firmware vulnerability. Running an SSH honeypot for 30 days.21 June 2024
- #254Chinese breached 20,000 FortiGate systems worldwide. Malicious VSCode extensions. Microsoft promises better security.15 June 2024
- #253FBI obtains 7000 LockBit decryption keys. Microsoft deprecating NTLM. FCC votes to secure BGP.7 June 2024
- #252Operation Endgame takes down 2000 malware domains and 100 servers. NIST NVD backlog to be cleared by end of September. Destroying 600,000 routers in 72 hours.31 May 2024
- #251Google Cloud error wiped pension fund data. Buying expired domains to capture sensitive data. Siren maillist for open-source security.24 May 2024
- #250Large-scale backdoor malware in Linux servers. BreachForums seized again. Interesting Ethereum heist.17 May 2024
- #249Lockbit leader identified. DirtyStream and Tunnelvision vulnerabilities. Satya Nadella's memo on security at Microsoft. 9 May 2024
- #248Okta warns of unprecented credential stuffing attack. Dropbox Sign breached. DNS probing using China's Great Firewall. Quick version.2 May 2024
- #247Ransomware payments reach record low, sort of. Github and Gitlab flaw to create trustworthy URL's. Endoflife API. 26 April 2024
- #246Cisco Duo warns of third-party 2fa breach. Palo Alto firewall exploitation continues. Opinion piece on Microsoft's dominance.19 April 2024
- #245New HTTP/2 DOS attack. New Spectre v2 attack. Lastpass hack attempt with deepfake CEO. Quick version.12 April 2024
- #244xz backdoor nearly infecting everything. Report on Microsoft Exchange hack scathing. Google getting device-bound cookies.4 April 2024
- #243Most zero-days come from surveillance vendors. NVD database issues. US sanctions Chinese state-sponsored hackers.29 March 2024
- #242New type of DoS attack called Loop DoS. Github starts auto-fixing security issues in your code. Misconfigured Firebase instances leak 19 million passwords.22 March 2024
- #241Microsoft breached secrets used in ongoing attacks. Chrome's real-time phsihing protection. FCC approves cybersecurity label.15 March 2024
- #240Using visitor's browsers to perform brute-force attacks. Google engineer caught stealing AI secrets. Tesla phishing and car stealing.8 March 2024
- #239Lockbit returns. Executive order banning data sales to China, Russia and others.29 February 2024
- #238LockBit ransomware group taken down. Keytrap DNS attack.23 February 2024
- #237OpenAI blocks specific nation-state actors. New Wifi vulnerabilities. 16 February 2024
- #236More news on China intrusions in US infrastructure. The toothbrush story. Quick version.8 February 2024
- #235FBI removes Chinese malware from routers. Ransomware payments going down. 2 February 2024
- #234Microsoft corporate inboxes breached. 23andMe confirms raw genotype data leaked. Pwn2Own Automotive results.26 January 2024
- #233PixieFail issues in UEFI firmware. MOVEit vendor not financially impacted. 19 January 2024
- #232Merck settled with insurers over $700 million claim. Stuxnet planted by Dutch engineer. China claims to have cracked Airdrop privacy. 12 January 2024
- #231More info on Google OAuth token revive. Npm 'everything' package prank. 23andMe at it again.5 January 2024
2023
- #230Advanced iPhone backdoor campaign discovered. Europol warns 443 shops of skimming. Github going strong on its 2FA game.29 December 2023
- #229SSH Terrapin attack. Interpol operation arrests 3,500 cybercriminals. Quick version.21 December 2023
- #228Ukrainian military wipes Russian tax databases. Log4Shell still very much a thing. 23andMe doing great.14 December 2023
- #22723andMe breach worse than expected. New SLAM CPU and LogoFAIL UEFI attacks. Quick version.7 December 2023
- #226Okta breach broader impact than first thought. Google Drive data loss. BLUFF Bluetooth attacks. Quick version.30 November 2023
- #225Reviving expired Google tokens? Citrix Bleed still very much an issue. Thousands of secrets found on PyPi.24 November 2023
- #224Two new CPU flaws, Cachewarp and Reptar. More on passkeys. Ransomware gangs filing complaints to the SEC.17 November 2023
- #223Okta session breach root cause. Microsoft improvements on MFA policies and usage. Discord switching CDN to temporary links.10 November 2023
- #222White House issues executive order to dampen AI security risks. SEC sues Solarwinds CISO personally. 3 November 2023
- #221Okta breached. Safari iLeakage attack. Security Copilot early access.27 October 2023
- #220Ragnar ransomware site taken down. Cisco IOS XE devices actively exploited. NTLM being killed off.20 October 2023
- #219HTTP/2 exploit causes largest DDoS ever. 23andMe data leak impacting 7 million people. Passkeys are now the default for Google.12 October 2023
- #218Looney Tunables priv escalation. Exim zero-day RCE attacks. Minimal/quick issue.6 October 2023
- #217WebP vulnerability with 10/10 rating. Malicious PR's disguised as Dependabot. AI oversharing.29 September 2023
- #216Cisco buys Splunk. Microsoft exposes 38TB of sensitive data. Chromebook gets 10 years of security support.22 September 2023
- #215WiKI-Eve attack. Facebook Messenger phishing wave. 15 breaches. Minimal issue.15 September 2023
- #214Microsoft has an explanation for the Outlook hack. Apple patches two no-click zero-days.8 September 2023
- #213Qakbot network dismantled. So many breaches.1 September 2023
- #212Python in Excel. Malware that knows where you live. And more fun stuff to brighten your day.25 August 2023
- #211PowerShell Gallery vulnerable to spoofing. Industrial PLC issues. The first quantum-resilient FIDO2 key.18 August 2023
- #210Two new CPU attacks: Inception and Downfall. Stealing keystroke data through sound. TunnelCrack: widespread VPN issues.11 August 2023
- #209Collide+Power side-channel attack. Android patch gap. Minimal issue.4 August 2023
- #208Microsoft key leak more impactful than thought. OpenSSH RCE vulnerability. Ransomware leak site with an API.28 July 2023
- #207Microsoft will provide free security logs. One in twelve Docker images contains private keys. Kevin Mitnick passed away.20 July 2023
- #206Whitehouse releases detailed cybersecurity initiatives. Many patches. Azure AD becomes Entra ID.14 July 2023
- #205StackRot privilege escalation. Estimated 200 orgs impacted by MOVEit. Minimal issue.7 July 2023
- #204More MOVEit breaches. NPM manifest confusion. 6,500 arrests after Encrochat takedown. CI/CD best practices report.30 June 2023
- #203UPS discloses breach in a shitty way. Chinese state actor behind Barracude ESG issues. Killnet group somewhat threatens world banking. 23 June 2023
- #202MOVEit update. High-level breaches. BEC losses at $50B per year.16 June 2023
- #201Mass exploitation of MOVEit file transfer software. Barracuda recommends to replace e-mail gateways. 9 June 2023
- #200Issue 200! Also potential backdoor in Gigabyte motherboards. Emby shuts down infected user media servers. Security.txt now mandatory for Dutch gov website. 2 June 2023
- #199Microsoft warns of China-backed threats to US infrastructure. AI image of Pentagon explosion dips market. And much more.26 May 2023
- #198Toyota exposes car location of 2 million customers. US offers $10 million reward for Lockbit creator. Minimal issue. 18 May 2023
- #197FBI dismantles 20-year old Russian malware network. Intel firmware verification in trouble after private key leak.12 May 2023
- #196Solarwinds detected 6 months earlier. Google adds passkeys. Apple rolls out Rapid Security Response.5 May 2023
- #195Google finally releases backup for Authenticator, sort of. Apache Superset servers exposed. New DDoS vector with 2200x amplification.28 April 2023
- #194Supply-chain attack inside a supply-chain attack. Citizen Lab report on NSO activities. EU cyber cooperation in Cyber Solidarity Act. 21 April 2023
- #193Breaches, patches, and hacking cars through their headlights. 14 April 2023
- #192Genesis marketplace taken down. Nexx garage openers vulnerable. Email hacking campaign against NATO countries.7 April 2023
- #191GPT to help out in security matters. Exchange will block mail from vulnerable on-prem servers. Ultrasound control over digital assistants. 31 March 2023
- #190Breachforums marketplace down for now. Insecure image cropping. Pwn2Own in full swing.24 March 2023
- #189Back in action! Also 18 zero-days in Samsung chipsets, an easily exploitable Outlook issue, and more.17 March 2023
2021
- #188Inside the cookie stealing market. Billion records from CVS health leaked. Taking a break.21 June 2021
- #187EA breached through Slack cookie. Colonial was breached through old VPN password. 14 June 2021
- #186Ransomware to be treated almost as terrorism. Norton will let you mine crypto. Cooperation on browser extension security.7 June 2021
- #185Nuclear secrets exposed through flashcard apps. HaveIBeenPwned goes open source.31 May 2021
- #184Cyber insurance giant CNA pays out $40 million. Some new stuff in ransomware infections. Some good reads.24 May 2021
- #183Colonial pipeline news continued. Executive order on cybersecurity. FragAttacks Wifi vulnerabilities. 17 May 2021
- #182New Spectre-like attacks. Ransomware takes down pipeline. Minimal issue.10 May 2021
- #181DC police data breach. DigitalOcean billing data breach. Apple fixes actively used zero-day. 3 May 2021
- #180Passwordstate password manager hacked. Emotet removing itself since Sunday. QNAP ransomware with 7zip. 26 April 2021
- #179FBI removes Exchange web shells from hacked machines. US sanctions Russia for Solarwinds. Two zero-day Chromium issuess.19 April 2021
- #178Pwn2Own results. Rust moving into the Android OS. Microsoft cyber wargames simulator.12 April 2021
- #177533 million Facebook users' data leaked. PHP backdoor attempt. Github Actions used for coinmining. Minimal issue.5 April 2021
- #176Long list of breaches. Some important vulnerabilities. 29 March 2021
- #175Hacking group used 11 zero days in a year. FBI values US losses to cybercrime in 2020 at $4.2 billion.22 March 2021
- #174Exchange hacks everywhere. Sigstore released. Spectre PoC.15 March 2021
- #173Exchange servers under massive attack. Also other things happened. 8 March 2021
- #172VMWare vCenter vulnerable to critical exploit. Microsoft releases CodeQL queries for Solarwinds. Hiding c2 servers in Bitcoin transactions.1 March 2021
- #171Strange new Mac malware. CIS ransomware protection for hospitals. Sharing a project of mine.22 February 2021
- #170Water treatment plant hacked. Novel dependency confusion attacks. CD Projekt Red files and source code stolen. 15 February 2021
- #169Sudo issue also affects MacOS. Plex servers used is DDoS amplification. Solarwinds also exploited by China.7 February 2021
- #168Emotet and Netwalker taken down. NAT Slipstreaming 2.0. Patch your sudo and iOS.1 February 2021
- #167RDP used for DDoS amplification. Critical dnsmasq vulnerabilities. Solarwinds continued.26 January 2021
- #166Europol takes down DarkMarket. Joker's Stash carding site stops. €10 million GDPR fine for video surveillance.18 January 2021
- #165Lot's of breaches and leaks. Solarwinds continued. Ryuk income estimated at $150 million so far.11 January 2021
- #164Backdoor in Zyxel VPN's. Solarwinds continued. Ticketmaster fined $10 million. 4 January 2021
2020
- #163Solarwinds continued. Citrix-based DDoS amplification attack. Unpatched Windows priv escalation.28 December 2020
- #162Solarwinds supply-chain attack breaches several US gov departments, Microsoft, Cisco. I'm sure some other stuff happened too. 21 December 2020
- #161Amnesia33: vulnerabilities in millions of IoT devices. Pwnie awards. Minimal issue. 14 December 2020
- #160Vaccine makers heavily targeted. Ticketmaster receives GDPR fine. Ransomware gang using Facebook ads to pressure victims. 16 November 2020
- #159Maze definitely shutting down. Vulnerabilities in Github Actions. Minimal edition. 9 November 2020
- #158FBI warns of imminent large scale ransomware attack on US hospitals. Maze is shutting down. Google discloses Windows zero-day. 2 November 2020
- #157Google reports largest DDoS in history. NSA reports top 25 vulnerabilities used by Chinese hackers. Lot's of news packed in a minimal edition. 26 October 2020
- #156"Bad Neighbor" Windows issue causes BSoD. New Bluetooth issue. Good times for network access sellers. 19 October 2020
- #155Full (physical) takeover flaw in Apple T2 chips. Some malicious npm packages. Great Apple bug bounty results. 12 October 2020
- #154Windows XP leak confirmed. Ransomware everywhere. Minimal edition. 5 October 2020
- #153Lot's of breaches and leaks. Windows XP source code allegedly leaked. Please patch ZeroLogon flaw. 28 September 2020
- #152Critical Windows network vulnerability with exploits in the wild. Another Bluetooth issue. Cool new iOS security features. 21 September 2020
- #151Back in action \o/14 September 2020
2019
- #150Shutting down5 November 2019
- #149Taking a break4 October 2019
- #148Doordash breach impacting 4.9 million people. Critical RCE exploit in vBulletin. Also an RCE in Internet Explorer. 27 September 2019
- #147Data leak impacts all citizens of Ecuador. Critical issue in Harbor container registry. Hack an actual satellite. 20 September 2019
- #146New Intel CPU attack. BlueKeep exploit module in Metasploit. Cyber Peace Institute non-profit.13 September 2019
- #145Critical issues in SuperMicro motherboard controllers. Large database with Facebook phone numbers found.6 September 2019
- #144Critical Chrome issue fixed. Patch your Cisco IOS XE routers. 30 August 2019
- #143Backdoor in Ruby rest-client gem and others. Ransomware infected 22 Texas government departments.22 August 2019
- #142New attack surface in Windows CTF system. Bluetooth flaw to decrypt traffic. Minimal mode.16 August 2019
- #141Kubernetes security audit. Jira exposure. New Spectre variant. 9 August 2019
- #140Capital One breach impacting 106 million people. Several critical flaws in over 200 million devices.2 August 2019
- #139Facebook fined $5 billion. Equifax fined $700 million. VLC not affected by critical vulnerability.26 July 2019
- #138Data from all citizens of Bulgaria hacked. Google Home recordings leaked.18 July 2019
- #137Serious Zoom security issue. Record GDPR fines for British Airways and Marriot.12 July 2019
- #136D-Link forced to undergo regular security audits. US power grids going retro against cyberattacks.5 July 2019
- #135Dell SupportAssist again vulnerable to RCE. Second Firefox zero-day discovered.28 June 2019
- #134Zero-day in Firefox. Remote DoS vulnerability in Linux kernel. 21 June 2019
- #133Two Windows zero-days. Millions of Exim servers vulnerable to remote code execution. 14 June 2019
- #132BlueKeep worries rising. MacOS zero day. Sign-in with Apple feature. Minimal edition.7 June 2019
- #131Unpatched flaw in Docker. MacOS Gatekeeper bypass. BlueKeep flaw will become a problem.31 May 2019
- #130Critical Cisco vulnerabilities. Several Windows zero-days. Salesforce outage due to permissions bug. 24 May 2019
- #129Whatsapp critical vulnerability. ZombieLoad attacks against Intel CPU's. Minimal mode.17 May 2019
- #128Alpine Docker images ship root without password. Git repo's hijacked. 9 May 2019
- #127Docker Hub hacked. Dell bloatware vulnerable to remote code execution. 2 May 2019
- #126FBI reports cybercrime losses in 2018 total $2.7 billion. MalwareTech pleads guilty. Minimal mode.26 April 2019
- #125Outlook.com and Hotmail breached through helpdesk credentials. Large scale DNS hijacking going on. NoScript available on Chrome.19 April 2019
- #124Vulnerabilities in WPA3. Several router problems. Sextortion scams changing things up a bit.11 April 2019
- #123Facebook third-party data leak and other shenanigans. Backdoor in Bootstrap-sass Ruby library.5 April 2019
- #122Facebook logged passwords in plaintext. Asus software updates hijacked.29 March 2019
- #121Norsk Hydro breached. Slack allows customers to manage encryption keys. 21 March 2019
- #120Citrix breached. Postmortem on the Marriot hack. Box custom URL's need to be used with care. 15 March 2019
- #119Google warns of Chrome and Windows 7 zero days. WebAuthn now official standard. NSA releases Ghidra. 8 March 2019
- #118Backdoors in bare-metal cloud servers. Hijacking machines through Thunderbolt. Coinhive shutting down.1 March 2019
- #117Password managers leaving passwords in memory. Critical vulnerabilities in Drupal, IIS, WinRAR. Russia everywhere. 22 February 2019
- #116Critical vulnerability in Docker. Hacking electrical scooters. Google open sources ClusterFuzz.15 February 2019
- #115Facetime bug fixed. Crypto exchange lost after founder dies. Upcoming browser security features.8 February 2019
- #114Plenty of breaches. Painful FaceTime bug. Japan allows pre-emptive hacking of citizen's devices. 31 January 2019
- #113100.000 malware domains taken offline. Vulnerability in apt-get. Google fined €50M in GDPR case. 24 January 2019
- #112Systemd and SCP vulnerabilities. Lot's of breaches. Hack a Tesla. Minimal version.18 January 2019
- #111Student admits to hack of German politicians. $2 million for iOS exploits. New Lightening Yubikey.11 January 2019
- #110Thousands of Chromecasts hijacked. EU funding bug bounties for open-source projects. Let's Encrypt being awesome. 4 January 2019
2018
- #109Drones in airports. Electrum Bitcoin wallet hacked. Wannacry still a thing.28 December 2018
- #108Critical flaw in SQLite. Unlocking phones with a 3D printed head. Microsoft releases Windows Sandbox.21 December 2018
- #107Linux.org domain hijacked. Kubernetes exploits available. Australian anti-encryption law. 13 December 2018
- #106Large breaches at Quora and Marriott. Critical vulnerability in Kubernetes. Edge browser being replaced? 7 December 2018
- #105Javascript library Event-Stream hijacked. Lot's of data leaks. New vulnerabilities in Ghostscript.30 November 2018
- #104Issue 10423 November 2018
- #103Google having problems with BGP. Nginx DoS vulnerabilities. Pwn2Own results are in. 16 November 2018
- #102New CPU attack dubbed Portsmash. Cisco DoS attacks underway without patch. Many PHP plugins not using cURL right.8 November 2018
- #101New vulnerabilities in Bluetooth chips. Privilege escalation in X.org for BSD and Linux. Botnet targeting Hadoop clusters.3 November 2018
- #100Zero-day in popular jQuery File Upload plugin. Critical flaws in Drupal, FreeRTOS and more.25 October 2018
- #99Critical vulnerability in LibSSH. PHP 5.6 soon end-of-life but still widely used. TLS 1.0 and 1.1 being retired.18 October 2018
- #98Wikileaks publishes AWS datacenter locations. DoD's weapon systems vulnerable to attack. 12 October 2018
- #9750 million Facebook accounts exposed. China accused of hardware tampering. Minimal mode.5 October 2018
- #96Mac Mojave zero-day. Unwiped drives and servers for sale. Minimal mode.27 September 2018
- #95Crashing iDevices with CSS. Breaches at India's biometric database, a US Gov payment site and many more. 20 September 2018
- #94390.000 public .git directories. Best selling App Store utility stole user information. Minimal mode.15 September 2018
- #93MEGA.nz Chrome extension compromised. Thousands of MicroTik routers being targeted. 6 September 2018
- #92Breaches at T-Mobile and many more. New Struts 2 flaw. Windows zero-day published. 31 August 2018
- #91New Intel speculative execution flaw dubbed L1TF aka Foreshadow. New GhostScript/ImageMagick vulnerabilities.23 August 2018
- #90Hacking printers with a fax. Man-in-the-disk attacks on Android. Police body cams not very trustworthy.15 August 2018
- #89New method of cracking WPA2 passwords. BGP hijacking attacks on payment processors. Let's Encrypt now a trusted root.8 August 2018
- #88Reddit breached. Remote Spectre variant, but not as horrible as that sounds. IoT cameras being crappy.3 August 2018
- #87Singapore's healthcare system breached. 157 gigs of automotive data leaked. New Bluetooth vulnerability.27 July 2018
- #86Several breaches. Hacked npm package. GPS spoofing. BEC scams up to 12 billion.20 July 2018
- #85Breaches at Timehop, DomainFactory, Macy's and others. Fitness app Polar doing a Strava. Malware in Arch Linux repository.13 July 2018
- #84Breaches at Adidas, Typeform, NHS. Vulnerabilities in 4G/LTE.6 July 2018
- #83WPA3 released. Gentoo repository hacked. EFF announces STARTTLS Everywhere.29 June 2018
- #82Grabbing site content through the audio tag. 3000+ unsecured Firebase accounts. Really old PGP bug found.22 June 2018
- #81Backdoored Docker containers. Breaches and patches. And a personal Gsuite project.15 June 2018
- #80MyHeritage and TicketFly hacked, over 118 million accounts exposed. Zip Slip vulnerability. Public Google groups.7 June 2018
- #79Git remote code execution vulnerability found and fixed. Quite a few items on GDPR, data breaches and more.1 June 2018
- #78VPNFilter infects over 500.000 routers. Critical DHCP vulnerability in Redhat. New Spectre-like CPU flaw.25 May 2018
- #77eFail: PGP and S/MIME vulnerabilities. XSS vulnerability found and patched in Signal.18 May 2018
- #76Javascript added to Excel. Backdooring npm and Python packages.11 May 2018
- #75Plaintext passwords in logfiles at Twitter and Github. Europol takes down largest DDoS-for-hire service.4 May 2018
- #74New high-level Drupal vulnerability. BGP hijack to steal cryptocoins. Gmail adds self destructing emails.27 April 2018
- #73TaskRabbit hacked. Incomplete Android security patches. Malicious traffic distribution network taken down.19 April 2018
- #72Card breach at Delta, Sears and Best Buy. New password-less web authentication API approved.13 April 2018
- #71Several leaks and breaches. Cloudflare DNS service 1.1.1.1. Critical Cisco vulnerability.5 April 2018
- #70Critical Drupal vulnerability. TLS 1.3 is approved. Lot's of Google security stuff.30 March 2018
- #69Facebook data harvesting by Cambridge Analytica. AMD confirms vulnerabilities. 23 March 2018
- #68Critical AMD chip vulnerabilities disclosed. Intel announces anti-Spectre improvements. Let's Encrypt now has wildcard certificates.16 March 2018
- #67Memcached DDoS continues, but mitigations are available. Vulnerabilities in 4G LTE. Kali Linux available on Windows.9 March 2018
- #66Memcached-based DDoS attacks. Trustico SSL certificate screwup. SAML vulnerability found.2 March 2018
- #65Jenkins servers targeted to mine crypto. Tesla AWS servers too. And Bitcoin phishing through Adwords campaigns. 21 February 2018
- #64Winter Olympics hit by cyber attack. Government sites compromised to mine crypto. New iOS crashing bug.16 February 2018
- #63Wordpress auto-update broke and DoS vulnerability unpatched. Apple iBoot source code leaked. Autosploit script-kiddie heaven.9 February 2018
- #62Fitness tracking data exposes secret military bases. Several vulnerabilities fixed for Firefox, Cisco, Lenovo.2 February 2018
- #61OnePlus credit card breach. EFF reports on large-scale malware campaign. Flaw found in Electron.26 January 2018
- #60Vulnerability in torrent client Transmission. Blackwallet hacked. Bad guys getting caught.19 January 2018
- #59WPA3 announced. Backdoor found in WD NAS drives. Npm security false positive causes wide-spread issues.12 January 2018
- #58All processors are vulnerable, especially Intel's (aka Meltdown and Spectre). Also, other news.4 January 2018
2017
- #57Flaw in Lastpass Authenticator 2fa app. 300k credentials leaked by RootsWeb. Twitter adds decent 2fa option.29 December 2017
- #56Details on all American households in unsecured s3 bucket. Triton: malware aimed at causing damage to industry control systems. White House officially blames North Korea for WannaCry. 22 December 2017
- #55Creators of Mirai plead guilty. Database with 1.4 billion credentials available in the open. Nicehash mining marketplace hacked.14 December 2017
- #54Andromeda botnet dismantled. EU sponsors VLC bug bounty program. AI.type keyboard leaks info on 31 million users.7 December 2017
- #53Apple goes 'omg omg omg'. Imgur data breach from 2014 discovered. Yet another s3 bucket leak.30 November 2017
- #52Uber didn't disclose data breach of 57 million people. Intel releases several fixes for its Management Engine. Don't put credentials in Git.23 November 2017
- #51Apple's FaceID under scrutiny. 700+ apps with exposed Twilio tokens. Github introduces security alerts.17 November 2017
- #50Fake Whatsapp reached 1 million downloads before being taken offline. Malware authors doing SEO. New security features for S3.10 November 2017
- #49Domain used by Dell hijacked for a month. Severe vulnerability in Google's bug tracker fixed. Lot's of important patches to apply.3 November 2017
- #48New IoT botnet resembling Mirai. Ransomware outbreak in Russia and Ukraine. A look at Windows 10's Controlled Folder Access.27 October 2017
- #47Krack attack breaking WPA2. Serious flaw in widely used TPM encryption chip. Google offers 'advanced protection' on accounts.20 October 2017
- #46Disqus data breach of 17.5 million accounts. Embarrassing MacOS password hint bug. CSV injection is quite scary.12 October 2017
- #45Yahoo hack compromised not one but three billion accounts. Not all Mac's are getting their firmware updates. Cloudflare announces free DDoS protection for all.6 October 2017
- #44Securities and Exchange Commission (SEC) breached. Deloitte also breached. CCleaner malware was after big tech companies.27 September 2017
- #43CCleaner compromised with malware. Python malicious libraries through typosquatting. Apache Optionsbleed.21 September 2017
- #42Equifax breach digest. Serious Bluetooth vulnerabilities found in all operating systems. New wave of MongoDB ransomware attacks.14 September 2017
- #41Contact info of six million Instagram users for sale. DragonFly group targeting the energy sector. 465k patients need pacemaker updates. 7 September 2017
- #40Over 700 million e-mails found in spambot database. Google BFP misconfiguration takes part of Japan offline. $500k bounty for messaging app exploits.31 August 2017
- #39Chrome extension hacking continues. DDoS pulse wave attacks. Sony PSN's social media hacked. 24 August 2017
- #38Airbnb open-sources malware scanning framework. AWS releases data monitoring service. One vulnerability affects Git, Mercurial and SVN.16 August 2017
- #37WannaCry killswitch author arrest. Npm malicious typo-squat libraries. Changing street signs to mess up self-driving cars.11 August 2017
- #36Adobe announces end of Flash. Sweden leaks private data of millions of citizens. Chrome extension briefly taken over and turned into adware.4 August 2017
- #35More Ethereum thefts. Tor bug bounty program goes public. Large set of security updates from Apple.26 July 2017
- #34Widespread GSoap exploit in security cameras. Over $7mil stolen in Ether by hacking a website. IBM Z mainframe with massive encryption capability.20 July 2017
- #33Broadcom Wifi chip vulnerability in iOS and Android. Let's Encrypt to support wildcard certificates. 14 million Verizon records exposed.13 July 2017
- #32Let's Encrypt reaches 100 million certificates. Systemd remote code execution in Linux. Microsoft brings EMET back to Windows.6 July 2017
- #31NotPetya aka GoldenEye ransomware infection. Windows 10 builds and parts of source code leaked. 29 June 2017
- #30Stack Clash vulnerability on Linux. EU proposal to mandate encryption. 198 million US voter records public.22 June 2017
- #29Ukraine fell victim to Stuxnet-like malware. Estonia establishes data embassy. Google teaches kids about online safety.15 June 2017
- #28OneLogin data breach. Fireball malware infects 250 million pc's. Gmail adds new security features.8 June 2017
- #27Severe vulnerability found in Samba. Samsung S8 iris scanner defeated by picture of an eye. Shadow Brokers launch 0-day subscription service.31 May 2017
- #26VLC, Kodi and others affected by subtitle exploit. WannaCry follow-up. Android O's new security features.24 May 2017
- #25WannaCry. And other things. But mostly that.18 May 2017
- #24Critical flaw in Microsoft malware scanner. Intel AMT flaw worse than thought. Handbrake downloads infected.11 May 2017
- #23Intel patches chipset exploit. Wide-scale Gmail phishing attack. New NIST guidelines on passwords.4 May 2017
- #22New flaws found in Linksys routers. Hipchat passwords might have leaked. Anti-virus Webroot has a bad day.28 April 2017
- #21Domain names made to seem real with Unicode hack. Phone-based authentication for Microsoft. Master keys for fingerprints might be possible.20 April 2017
- #20Microsoft Word zero-day in the wild without macro's. Dallas tornado alarms triggered by hack. Brickerbot breaks IoT devices.13 April 2017
- #19Remote code execution through Wifi on iOS and Android. Targeted malware found called Chrysaor.7 April 2017
- #18New major Lastpass flaw. Google shames Symantec's CA capabilities. Apple releases new iOS security white paper.30 March 2017
- #17Pwn2Own results are out. Lastpass vulnerabilities found. Threats of wiping 220 million iCloud accounts.24 March 2017
- #16Digital Security Exchange to link security trainers and communities. Google releases invisible reCAPTCHA. WhatsApp and Telegram vulnerabilities patched. 16 March 2017
- #15Wikileaks releases CIA hacking tools. Malware uses DNS TXT records as C&C. HackerOne free for open-source projects.9 March 2017
- #14Dropbox open-sources security bot. Google open-sources e2email. Robot platforms found to be riddled with security holes.2 March 2017
- #13Cloudflare data leakage, the first SHA-1 collision, Netflix Stethoscope advising on mobile security.24 February 2017
- #12Up to 1.5M Wordpress sites defaced, reading your passwords through Wifi signals, call for a digital Geneva Convention.17 February 2017
- #11Wordpress exploit actively used, detecting a smartphone thieve in 14 seconds, Dutch count votes manually because of hacks.10 February 2017
- #10Wordpress exploit to edit any Wordpress site. Half of web traffic now uses HTTPS. LeakedSource has been shut down.3 February 2017
- #9Brian Krebs uncovers Mirai author, dormant Twitter botnet discovered, Heartbleed is still around.27 January 2017
- #8Whatsapp backdoor, a very convincing Gmail phishing attack, getting fingerprints from a picture.20 January 2017
- #7MongoDB attacks spiking, FTC suing D-Link, HelloKitty and ESEA hacked, pacemaker patching, and more.13 January 2017
- #6Netgear launches bug bounty program, unsecured MongoDB databases being hijacked, and more.6 January 2017
2016
- #5NIST calls for quantum-resistant encryption, PHP exploits making updates urgent, and Signal being clever as always.30 December 2016
- #4Methbot earning $3-5 million a day, Google has another security project, and more.22 December 2016
- #3One billion Yahoo accounts breached, Europol anti-ddos arrests, and more.16 December 2016
- #2Issue 29 December 2016
- #1Issue 12 December 2016