Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- NIST updates NVD operations to address record CVE growth
- Seiko USA website defaced as hacker claims customer data theft
- Anthropic investigates report of rogue access to hack-enabling Mythos AI
- Korean rights holders behind takedown of manga piracy giant TuMangaOnline
- Ukraine busts ‘bot farm’ supplying thousands of fake Telegram accounts to Russian spies
- Meta to start capturing employee mouse movements, keystrokes for AI training data
- UK intelligence: 100 nations have spyware that can hack Britain
For the more technical
- Oracle Critical Patch Update Advisory - April 2026
- CVE-2025-29635: Mirai campaign targets D-Link devices
- QR code phishing evolves: How to keep up
- Malicious trading website drops malware that hands your browser to attackers
- Void Dokkaebi uses fake job interview lure to spread malware via code repositories
- Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
- Bissa scanner exposed: AI-assisted mass exploitation and credential harvesting
- Nightmare-Eclipse tooling moves from public PoC to real-world intrusion
- New NGate variant hides in a trojanized NFC payment app
- Uptick in Bomgar RMM exploitation
- The Gentlemen & SystemBC: A sneak peek behind the proxy
- Mystery around Venezuelan cyberattack deepens, with new discovery of "highly destructive" wiper
- Not just annoying ads: Adware bundles delivering Gh0st RAT
- PureRAT: A multi-stage, fileless RAT utilizing image steganography and process hollowing
- macOS ClickFix campaign: AppleScript stealers & new terminal protections
- Bad Apples: Weaponizing native macOS primitives for movement and execution
- Fake document, real access: Foxit impersonation enables stealth VNC control
- "Hello? I can’t hear you": Investigating UNC1069’s fake meeting tactics
- Snow Flurries: How UNC6692 employed social engineering to deploy a custom malware suite
- Bad connection: Uncovering global telecom exploitation by covert surveillance actors
- MOIS-aligned cyber influence ecosystem
- Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics
- Inside Lazarus: How North Korea uses AI to industrialize attacks on developers
- GopherWhisper: A burrow full of malware
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments