Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Doxing as a new tool in Russian influence operations
- YouTube secretly tested AI video enhancement without notifying creators
- Can Flipper Zero really steal your car? (Spoiler: NO)
- U.S. government seizes online marketplaces selling fraudulent identity documents used in cybercrime schemes
- African authorities dismantle massive cybercrime and fraud networks, recover millions
- Chinese national who deployed "kill switch" code on employer's network sentenced to four years in prison
- Hundreds of Swedish municipalities impacted by suspected ransomware attack on IT supplier
- Auchan hacked: hundreds of thousands of customers exposed
For the more technical
- Reverse engineering Apple’s TCC daemon: When decompiled code
- Critical Docker Desktop flaw lets attackers hijack Windows hosts
- The one where we just steal the vulnerabilities (CrushFTP CVE-2025-54309)
- BadSuccessor is dead, long live BadSuccessor(?)
- Detecting CVE-2025-43300: A deep dive into Apple's DNG processing vulnerability
- Agentic browser security: Indirect prompt injection in Perplexity Comet
- Interesting technique to launch a shellcode
- What's new in Ghidra 11.4
- The root(ing) of all evil: Security holes that could compromise your mobile device
- AppSuite PDF Editor backdoor: A detailed technical analysis
- Chasing the Silver Fox: Cat & mouse in kernel shadows
- Storm-0501’s evolving techniques lead to cloud-based ransomware
- Examining the tactics of Bqtlock ransomware & its variants
- Cephalus ransomware: Don’t lose your head
- Hook version 3: The banking trojan with the most advanced capabilities
- Malicious Screen Connect campaign abuses AI-themed lures for Xworm delivery
- ZipLine campaign: A sophisticated phishing attack targeting US companies
- Phishing campaign targeting companies via UpCrypter
- TAG-144’s persistent grip on South American organizations
- Belarus-linked DSLRoot proxy network deploys hardware in U.S. residences, including military homes
- How Spur uncovered a Chinese proxy and VPN service used in an APT campaign
- Countering Chinese state-sponsored actors compromise of networks worldwide to feed global espionage system
- TAOTH campaign exploits end-of-support software to target traditional Chinese users and dissidents
- Deception in depth: PRC-nexus espionage campaign hijacks web traffic to target diplomats
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments