Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Propaganda for export
- Trump signs memorandum revoking security clearance of former CISA director Chris Krebs
- Towards an accurate description of cyber operations
- How security teams fail
- Tuta launches post quantum cryptography for email
- Gmail unveils end-to-end encrypted messages. Only thing is: It’s not true E2EE
- Apple just won a bid to stop its UK privacy case from being held completely in secret
- Fintech founder charged with fraud after ‘AI’ shopping app found to be powered by humans in the Philippines
- Unmasking EncryptHub: Help from ChatGPT & OPSEC blunders
- Operation Endgame follow-up leads to five detentions and interrogations as well as server takedowns
- Dog-like robot jams home networks and disables devices during police raids — DHS develops NEO robot for walking denial of service attacks
For the more technical
- Vulnerability in FortiSwitch allows unauthenticated attackers to change admin passwords
- Microsoft April 2025 Patch Tuesday
- Windows Remote Desktop Protocol: Remote to rogue
- Google fixes Android zero-days exploited in attacks, 60 other flaws
- Malicious PyPI package targets WooCommerce stores with automated carding attacks
- RolandSkimmer: Silent credit card thief uncovered
- Smishing Triad is now targeting toll payment services in a massive fraud campaign expansion
- Hacking the call records of millions of Americans
- Analysis of Konni RAT: Stealth, persistence, and anti-analysis techniques
- Grandoreiro trojan distributed via Contabo-hosted servers in phishing campaigns
- New evasive campaign delivers LegionLoader via fake CAPTCHA & CloudFlare Turnstile
- ViperSoftX malware distributed by Arabic-speaking threat actor
- Vidar stealer: Revealing a new deception strategy
- ClearFake’s new wdespread variant: Increased Web3 exploitation for malware delivery
- Researcher uncovers network of risky Chrome extensions with over 4 million installs
- AkiraBot: AI-powered bot bypasses CAPTCHAs, spams websites at scale
- BadBazaar and Moonshine: Spyware targeting Uyghur, Taiwanese and Tibetan groups and civil society actors
- State-sponsored tactics: How Gamaredon and ShadowPad operate and rotate their infrastructure
- Goodbye HTA, hello MSI: New TTPs and clusters of an APT driven by multi-platform attacks
- The ever-evolving threat of the Russian-speaking cybercriminal underground
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments