Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- AI, cybersecurity and the European perspective
- Pegasus spyware infections found on several private sector phones
- Criminal group forging over 12 000 official documents halted in Poland
- Black Basta ransomware gang's internal chat logs leak online
- Crypto exchange Bybit says it was hacked and lost around $1.4B
- Apple removes its highest level data security tool in the UK
- X now blocks Signal contact links, flags them as malicious
For the more technical
- CVE-2025-26788: Passkey authentication bypass in StrongKey FIDO server
- CVE-2025-21420: Windows Disk Cleanup Tool elevation of privilege vulnerability
- CVE-2025-1094: PostgreSQL psql SQL injection
- Nginx/Apache path confusion to auth bypass in PAN-OS (CVE-2025-0108)
- GymTok: Breaking TLS using the Alt-Svc header
- Invisible obfuscation technique used in PAC attack
- An update on fake updates: Two new actors, and new Mac malware
- Technical analysis of Xloader versions 6 and 7 - Part 1 & Part 2
- The bleeding edge of phishing: darcula-suite 3.0 enables DIY phishing of any brand
- Don’t ghost the SocGholish: GhostWeaver backdoor
- Updated Shadowpad malware leads to ransomware deployment
- Meet NailaoLocker: a ransomware distributed in Europe by ShadowPad and PlugX backdoors
- Lumma stealer chronicles: PDF-themed campaign using compromised educational institutions' infrastructure
- GhostSocks - Lumma's partner in proxy
- DPRK DriverEasy & ChromeUpdate deep dive
- Signals of trouble: Multiple Russia-aligned threat actors actively targeting Signal messenger
- Earth Preta mixes legitimate and malicious components to sidestep detection
- Unraveling the many stages and techniques used by RedCurl/EarthKapre APT
- Cyber threats impacting the financial sector in 2024 – focus on the main actors
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments