Android Banking Trojan Asks for Selfie With Your ID
https://blogs.mcafee.com/mcafee-labs/android-banking-trojan-asks-for-selfie-with-your-id/

Malware posing as Dual Instance app steals users’ Twitter credentials
https://blog.avast.com/malware-posing-as-dual-instance-app-steals-users-twitter-credentials

EvilTwin’s Exotic Ransomware targets Executable Files
http://www.bleepingcomputer.com/news/security/eviltwins-exotic-ransomware-targets-executable-files/

DDoS on Dyn Impacts Twitter, Spotify, Reddit
https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/

Magento Credit Card Swiper Exports to Image
https://blog.sucuri.net/2016/10/magento-credit-card-swiper-exports-image.html

dr0wned - Cyber-Physical Attack with Additive Manufacturing
https://arxiv.org/abs/1609.00133
https://arxiv.org/pdf/1609.00133v1 [PDF]

Radioactive Mouse States the Obvious
https://www.syss.de/en/pentest-blog/article/2016/10/04/radioactive-mouse-states-the-obvious-1/

Hucky Ransomware: A Hungarian Locky Wannabe
https://blog.avast.com/hucky-ransomware-a-hungarian-locky-wannabe

Distrusting New WoSign and StartCom Certificates
https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/

Testing MBRFilter against Ransomware that modify the Master Boot Record
http://www.bleepingcomputer.com/news/security/testing-mbrfilter-against-ransomware-that-modify-the-master-boot-record/
https://github.com/vrtadmin/MBRFilter

AtomBombing: A Code Injection that Bypasses Current Security Solutions
http://blog.ensilo.com/atombombing-a-code-injection-that-bypasses-current-security-solutions
https://breakingmalware.com/injection-techniques/atombombing-brand-new-code-injection-for-windows/

In-Dev Ransomware forces you do to Survey before unlocking Computer
http://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/

task_t considered harmful
https://googleprojectzero.blogspot.com/2016/10/taskt-considered-harmful.html

Android Trojan GM Bot is evolving and targeting more than 50 banks worldwide
https://blog.avast.com/android-trojan-gm-bot-is-evolving-and-targeting-more-than-50-banks-worldwide

Battery Status readout as a privacy risk
https://blog.lukaszolejnik.com/battery-status-readout-as-a-privacy-risk/
http://lukaszolejnik.com/battery.pdf
https://www.fxsitecompat.com/en-CA/docs/2016/battery-status-api-has-been-removed/

Tech support scammers abuse bug in HTML5 to freeze computers
https://blog.malwarebytes.com/cybercrime/social-engineering-cybercrime/2016/11/tech-support-scammers-abuse-bug-in-html5-feature-to-freeze-computers/

Web of Trust (WOT) Add-on taken down by Google and Mozilla after reports of selling Users browsing history
http://techdows.com/2016/11/web-of-trust-add-on-removed.html

Well that’s a good and prompt response - if only they would start working through other dubious add-ons.

Malvertising on Google AdWords Targeting MacOS Users
https://blog.cylance.com/malvertising-on-google-adwords-targeting-macos-users

Vulnerability Spotlight: Remotely Exploitable Bugs in Memcached Identified and Patched
http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html