Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Gmail’s new encrypted messages feature opens a door for scams
- Microsoft now pays up to $30,000 for some AI vulnerabilities
- Blue Shield of California shared the private health data of millions with Google for years
- Whistleblower: DOGE siphoned NLRB case data
- DOGE worker’s code supports NLRB whistleblower
- EU fines Apple €500M and Meta €200M for breaking Europe’s digital rules
- End of 10 campaign: Windows 10 support ends, replace it with Linux
- Why are companies lining up to buy Chrome?
- Saying ‘please’ and ‘thank you’ to ChatGPT is costing millions of dollars
- Russia attempting cyber sabotage attacks against Dutch critical infrastructure
- Russian army targeted by new Android malware hidden in mapping app
For the more technical
- VoIP penetration tests
- Case study: IOMobileFramebuffer NULL pointer dereference
- European Vulnerability Database (EUVD)
- How I made $64k from deleted files - a bug bounty story
- Github scam investigation: Thousands of "mods" and "cracks" stealing your data
- Critical Erlang/OTP SSH pre-auth RCE is 'surprisingly easy' to exploit, patch now
- io_uring is back, this time as a rootkit
- M-Trends 2025: Data, insights, and recommendations from the frontlines
- A deep dive into the latest version of Lumma infostealer with code flow obfuscation
- Detecting multi-stage infection chains madness
- SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation
- Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
- A deep dive into Strela stealer and how it targets European countries
- BrickStorm backdoor analysis. A persistent espionage threat to European industries
- Around the world in 90 days: State-sponsored actors try ClickFix
- Phishing for codes: Russian threat actors target Microsoft 365 OAuth workflows
- The data chase: Understanding Chinese espionage strategies
- Contagious Interview (DPRK) launches a new campaign creating three front companies to deliver a trio of malware: BeaverTail, InvisibleFerret, and OtterCookie
- Proton66 part 1: Mass scanning and exploit campaigns
- Proton66 part 2: Compromised WordPress pages and malware campaigns
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments