Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Commission fines X €120 million under the Digital Services Act
- Password manager provider fined £1.2m by ICO for data breach affecting up to 1.6 million people in the UK
- Ransomware trends in Bank Secrecy Act data between 2022 and 2024
- Apple, Google send new round of cyber threat notifications to users around world
- 10 years of Let's Encrypt certificates
For the more technical
- December 2025 Patch Tuesday: One critical zero-day, two publicly disclosed vulnerabilities aAmong 57 CVEs
- CVE-2025-55182 (React2Shell) opportunistic exploitation in the wild: What the GreyNoise observation grid is seeing so far
- China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)
- EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks
- Fantastic OWASP: 80 minutes of a security journey
- Security-reviewing AI generated code
- PromptPwnd: Prompt injection vulnerabilities in GitHub Actions using AI agents
- Attacking browser extensions
- RolyPoly VPN: The malicious “free” VPN extension that keeps coming back
- Gogs 0-day exploited in the wild
- How I discovered a hidden microphone on a Chinese NanoKVM
- JS#SMUGGLER: Multi-stage – hidden iframes, obfuscated JavaScript, silent redirectors & NetSupport RAT delivery
- New BYOVD loader behind DeadLock ransomware attack
- Total takeover: DroidLock hijacks your device
- Spiderman phishing kit mimics top European banks with a few clicks
- Introducing GhostFrame, a new super stealthy phishing kit
- ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants
- No Name Podcast: From reactive cybersecurity to proactive threat hunting
- To catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware
- Exclusive look inside a compromised North Korean APT machine linked to the biggest heist in history
- Trouble in the air: A spree of campaigns targeting the aerospace industry in Russia
- Malicious apprentice: How two hackers went from Cisco Academy to Cisco CVEs
- UDPGangster campaigns target multiple countries
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments