Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Waltz’s team set up at least 20 Signal group chats for crises across the world
- Hacking democracy: Russia’s digital war on German and European elections
- Global crackdown on Kidflix, a major child sexual exploitation platform with almost two million users
For the more technical
- Annual report from the actions of CERT Polska 2024
- About the security content of iOS 18.4 and iPadOS 18.4
- Blasting Past Webp: An analysis of the NSO BLASTPASS iMessage exploit
- IngressNightmare: CVE-2025-1974 - 9.8 critical unauthenticated remote code execution vulnerabilities in Ingress NGINX
- Bypassing authentication like it’s the ‘90s - Pre-auth RCE chain(s) in Kentico Xperience CMS
- An update on QuickShell: Sharing is caring about an RCE attack chain on Quick Share
- SpotBugs access token theft identified as root cause of GitHub supply chain attack
- Trapping misbehaving bots in an AI Labyrinth
- Multiple crypto packages hijacked, turned into info-stealers
- Hidden malware strikes again: Mu-Plugins under attack
- Analyzing new HijackLoader evasion tactics
- A phishing tale of DoH and DNS MX abuse
- Lucid PhaaS hits 169 targets in 88 countries using iMessage and RCS smishing
- New phishing campaign uses Browser-in-the-Browser attacks to target video gamers/Counter-Strike 2 players
- Exposing Crocodilus: New device takeover malware targeting Android devices
- Fast Flux: A national security threat
- Shifting the sands of RansomHub’s EDRKillShifter
- Fake Zoom ends in BlackSuit ransomware
- An old vector for new attacks: How obfuscated SVG files redirect victims
- Suspected China-nexus threat actor actively exploiting critical Ivanti Connect Secure vulnerability (CVE-2025-22457)
- The espionage toolkit of Earth Alux: A closer look at its advanced techniques
- From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic
- BeaverTail and Tropidoor malware distributed via recruitment emails
- Gamaredon campaign abuses LNK files to distribute Remcos backdoor
- Russian intelligence service-backed campaigns impersonate the CIA to target Ukraine sympathizers, Russian citizens and informants
- Operation HollowQuill: Malware delivered into Russian R&D Networks via Research Decoy PDFs
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments