Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Rise of cryptocurrency loans in Australia spark concerns about financial 'contagion'
- Oracle billionaire encourages world leaders to funnel all of their data to AI (and maybe his data centers)
- 20 million OpenAI accounts offered for sale
- No, OpenAI wasn’t breached—The real threat comes from infostealers
- Trolling scammers trend could be 'dangerous'
- An Italian journalist speaks about being targeted with Paragon spyware
- Dutch Police seizes 127 XHost servers, dismantles bulletproof hoster
- Key figures behind Phobos and 8Base ransomware arrested in international cybercrime crackdown + more information
- US reportedly releases Russian cybercrime figure Alexander Vinnik in prisoner swap
For the more technical
- NFC Relay = Criminal “commercialization” of the NFCGate research project
- Microsoft February 2025 Patch Tuesday
- First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)
- More than 1,000 GitHub repositories at risk: how to detect RepoJacking vulnerabilities
- Nginx/Apache path confusion to auth bypass in PAN-OS (CVE-2025-0108)
- Leaking the email of any YouTube user for $10,000
- Everyone knows your location: tracking myself down through in-app ads
- Smuggling arbitrary data through an emoji
- RATatouille: Cooking up chaos in the I2P kitchen
- Further insights into Ivanti CSA 4.6 vulnerabilities exploitation
- Malicious ML models discovered on Hugging Face platform
- whoAMI: A cloud image name confusion attack
- Xelera ransomware campaign: Fake food corporation of India job offers targeting tech aspirants
- Storm-2372 conducts device code phishing campaign
- Multiple Russian threat actors targeting Microsoft device code authentication
- Sandworm APT targets Ukrainian users with trojanized Microsoft KMS activation tools in cyber espionage campaigns
- Cybercrime: A multifaceted national security threat
- RedMike (Salt Typhoon) exploits vulnerable Cisco devices of global telecommunications providers
- From South America to Southeast Asia: The fragile web of REF7707
- You've got malware: Finaldraft hides in your drafts
- The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation
- XE group: From credit card skimming to exploiting zero-days
- Chinese-speaking group manipulates SEO with BadIIS
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments