Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- UK government secretly paid foreign YouTube stars for ‘propaganda’
- Facebook rigorously removes news articles mentioning pirate service “MagisTV”
- Tea app leak worsens with second database exposing user chats
- Proton: Introducing Lumo, the AI where every conversation is confidential
- OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test
- A bar? A church? China? A stolen iPhone's baffling journey around the globe
- How bad is Afghan data breach for MI6 and SAS?
- French submarine-maker targeted by hackers
- Operation Grayskull culminates in lengthy sentences for managers of dark web site dedicated to sexual abuse of children
- Law enforcement operations seized BlackSuit ransomware gang’s darknet sites
- Cybercrime forum XSS returns on mirror and dark web 1 day after seizure
For the more technical
- In-the-wild exploitation of CVE-2025-53770 and CVE-2025-53771: Technical details and mitigation strategies
- Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations
- Cisco Identity Services Engine unauthenticated remote code execution vulnerabilities
- Stack overflows, heap overflows, and existential dread (SonicWall SMA100 CVE-2025-40596, CVE-2025-40597 and CVE-2025-40598)
- Vulnerabilities identified in Dahua Hero C1 smart cameras
- Thorium: A scalable platform for automated file analysis and result aggregation
- Understanding current CastleLoader campaigns
- Gold Blade remote DLL sideloading attack deploys RedLoader
- Email-delivered RMM: Abusing PDFs for silent initial access
- Exploiting Direct Send: Attackers abuse Microsoft 365 to deliver internal phishing attacks
- Sealed chain of deception: Actors leveraging Node.JS to launch JSCeal
- MaaS appeal: An infostealer rises from the ashes
- ToxicPanda: The Android banking trojan targeting Europe
- AI-generated malware in panda image hides persistent Linux threat
- Gunra ransomware group unveils efficient Linux variant
- Fire Ant: A deep-dive into hypervisor-level espionage
- LARVA-208’s new campaign targets Web3 developers
- Muddled Libra threat assessment: Further-reaching, faster, more impactful
- Dropping Elephant APT group targets Turkish defense industry with new campaign and capabilities: LOLBAS, VLC Player, and encrypted Shellcode
- Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments