IT Security Weekend Catch Up – August 15, 2025

Comments

15.08.2025 | 17:32

IT Security Weekend Catch Up – August 15, 2025
avatar

badcyber

comments

IT Security Weekend Catch Up – August 15, 2025

Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!

For the less technical

  1. Reddit will block the Internet Archive
  2. Securing the supply chain at scale: Starting with 71 important open source projects
  3. US embeds trackers in AI chip shipments to catch diversions to China, sources say
  4. Microsoft helping Israel spy on millions of Palestinians since 2021: Report
  5. Google confirms data breach exposed potential Google Ads customers' info
  6. The dark web economy for compromised government and police email accounts
  7. BtcTurk suspends operations amid alleged $49M hot wallet heist
  8. Pwnie Awards 2025: Documented keys, exploit chains and a SignalGate T-shirt

For the more technical

  1. A mouse move that crashed the system – stack buffer overflow in display driver on macOS
  2. August 2025 Patch Tuesday: One publicly disclosed zero-day and 13 critical vulnerabilities among 107 CVEs
  3. MadeYouReset technical details - how (and why) it works? + more information
  4. MadeYouReset: Turning HTTP/2 server against itself
  5. Malicious packages across open-source registries: Detection statistics and trends (Q2 2025)
  6. Persistent risk: XZ Utils backdoor still lurking in Docker images
  7. 60 malicious Ruby Gems used in targeted credential theft campaign
  8. Invitation is all you need: Invoking Gemini for workspace agents with a simple Google Calendar invite
  9. BadCam: Now weaponizing Linux webcams
  10. CrossC2 expanding Cobalt Strike Beacon to cross-platform attacks
  11. Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability
  12. Malvertising campaign leads to PS1Bot, a multi-stage malware framework
  13. Fire in the woods – A new variant of FireWood
  14. Exposing PathWiper: A deep dive into DCOM abuse and network erasure with Trellix NDR
  15. VexTrio unmasked: A legacy of spam and homegrown scams
  16. Inside the robot: Deconstructing VexTrio’s affiliate advertising platform
  17. Rapid breach: Social engineering to remote access in 300 seconds
  18. New ransomware Charon uses Earth Baxia APT techniques to target enterprises
  19. Picture paints a thousand codes: Dissecting image-based steganography in a .NET (Quasar) RAT loader
  20. Ghost in the Zip: New PXA stealer and its Telegram-powered ecosystem
  21. From Hidden Bee to Rhadamanthys – the evolution of custom executable formats
  22. Odyssey stealer: ClickFix malware attacks macOS users for credentials and crypto wallet details
  23. Dissecting the CastleBot malware-as-a-service operation
  24. Unveiling a new variant of the DarkCloud campaign
  25. New infection chain and ConfuserEx-based obfuscation for DarkCloud stealer
  26. Unmasking SocGholish: Silent push untangles the malware web behind the “pioneer of fake updates” and its operator, TA569
  27. Tracking Candiru’s DevilsTongue spyware in multiple countries
  28. Revisiting UNC3886 tactics to defend against present risk
  29. Curly COMrades: A new threat actor targeting geopolitical hotbeds
  30. The covert operator's playbook: Infiltration of global telecom networks
  31. GenAI used for phishing websites impersonating Brazil’s government
  32. Unmasking Interlock group's evolving malware arsenal

Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.


Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy! For the less technical Reddit will block the Internet Archive Securing the supply chain at scale: Starting with 71 impor 2025-08-15T17:32:45+02:00

Comments