Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Your public ChatGPT queries are getting indexed by Google and other search engines
- Leaked ChatGPT conversations show people asking the bot to do some dirty work
- Wikipedia editors adopt ‘speedy deletion’ policy for AI slop articles
- Proton’s Lumo AI chatbot: not end-to-end encrypted, not open source
- noyb survey: only 7% of users want Meta to use their personal data for AI
- Google Project Zero: Policy and disclosure - 2025 edition
- Cisco discloses data breach impacting Cisco.com user accounts
- How we found an RSF military camp in the Libyan desert
- Censorship Whac-A-Mole: Google search exploited to scrub articles on San Francisco tech exec
- Hackers went looking for a backdoor in high-security safes—and now can open them in seconds
- Encryption made for police and military radios may be easily cracked
For the more technical
- Android Security Bulletin - August 2025
- Insecure credential storage in Check Point SmartConsole aka CVE-2024-24915
- ReVault! When your SoC turns against you
- Struts devmode in 2025? Critical pre-auth vulnerabilities in Adobe Experience Manager Forms
- Keeper is the only password manager that protects against infostealers
- Kali Linux & containerization (Apple's container)
- Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives
- GPT-5 under fire: Red teaming OpenAI’s latest model reveals surprising weaknesses
- CVE-2025-54136 - MCPoison Cursor IDE: Persistent code execution via MCP trust bypass
- When public prompts turn into local shells: ‘CurXecute’ – RCE in Cursor via MCP auto‑start
- How hidden prompt injections can hijack AI code assistants like Cursor
- Threat actor uses AI to create a better crypto wallet drainer
- GreedyBear: 650 attack tools, one coordinated campaign
- Arctic Wolf observes July 2025 uptick in Akira ransomware activity targeting SonicWall SSL VPN
- Huntress threat advisory: Active exploitation of SonicWall VPNs
- PlayPraetor's evolving threat: How Chinese-speaking actors globally scale an Android RAT
- Auto-Color backdoor: How Darktrace thwarted a stealthy Linux intrusion
- Plague: A newly discovered PAM-based backdoor for Linux
- Reverse engineering a Lumma infection
- Let’s be objective: A deep dive into 0bj3ctivityStealer's features
- XWorm V6: Advanced evasion and AMSI bypass capabilities revealed
- In-depth analysis of an obfuscated web shell script
- UNC2891 bank heist: Physical ATM backdoor & Linux forensic evasion evasion
- APT36: A phishing campaign targeting Indian government entities
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments