Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [VIDEO] Conti: Inside the billion dollar hacking empire
- Stolen Rockstar Games analytics data leaked by extortion gang
- Booking.com warns reservation data may have checked out with intruders
- FBI takedown of W3LL phishing service leads to developer arrest
- Europol-supported global operation targets over 75 000 users engaged in DDoS attacks
- Russia-linked hackers compromised scores of Ukrainian prosecutors’ email accounts, data shows
- How the Kremlin turned a MAGA influencer trip into an influence operation
- Pushpaganda manipulates Google Discovery feeds with AI-generated content to spread malicious notifications
- News outlets are blocking Wayback Machine from archiving their pages — 23 outlets concerned AI companies might abuse fair use and use it to train their models
For the more technical
- April 2026 Patch Tuesday: Two zero-days and eight critical vulnerabilities among 164 CVEs
- A 32-year-old bug walks into a Telnet server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
- 10 minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)
- MCPwn: A CVSS 9.8 one-Line MCP bug that hands over your Nginx to anyone on the network – actively exploited in the wild
- Protecting cookies with Device Bound Session Credentials
- 108 Chrome extensions linked to data exfiltration and session theft via shared C2 infrastructure
- Someone bought 30 WordPress plugins and planted a backdoor in all of them
- The most commonly used domain extensions for fraud in 2025
- Fake Claude site installs malware that gives attackers access to your computer
- HasAIbeenPwned - security incidents affecting major AI models
- Inside Predator's kernel engine
- Uncovering Webloc. An analysis of Penlink’s ad-based geolocation surveillance tech
- Orbán’s spying kit revealed: Israeli surveillance tool combined with Hungarian technology
- APT37’s pretexting-based targeted intrusion: Analysis of Facebook reconnaissance and software tampering attacks
- Masjesu rising: The commercial IoT botnet built for stealth, DDoS, and IoT evasion
- Exposing Russian malicious infrastructure: 1,250+ C2 servers mapped across 165 providers
- Inside ZionSiphon: Analysis of OT malware targeting Israeli water systems
- Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments