Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- New OpenAI tool renews fears that “AI slop” will overwhelm scientific research
- Former Google engineer found guilty of economic espionage and theft of confidential AI technology
- “Incognito Market” owner sentenced to 30 years for operating one of the world’s largest online narcotics marketplaces
- Inside a sophisticated recovery scam network: Evidence from a live investigation into legal services impersonation
- Rublevka team: Anatomy of a Russian crypto drainer operation
- Russia’s Matryoshka bots begin Epstein-themed disinfo campaign, focusing false claims against Ukraine and France
- Spain becomes first country in Europe to ban social media for under-16s
For the more technical
- Attributive questions in high profile incidents
- APT28’s stealthy multi-stage campaign leveraging CVE‑2026‑21509 and cloud C2 infrastructure
- APT28 leverages CVE-2026-21509 in operation Neusploit
- Someone knows bash far too well, and we love it (Ivanti EPMM pre-auth RCEs CVE-2026-1281 & CVE-2026-1340)
- n8n sandbox escape: Critical vulnerabilities in n8n exposes hundreds of thousands of enterprise AI systems to complete takeover
- CVE-2026-25049 expression escape vulnerability leading to RCE in n8n
- A deep dive into CVE-2026-25049: n8n remote code execution
- Metro4Shell: Exploitation of React Native’s Metro server in the wild
- Notepad++ hijacked by state-sponsored hackers
- The Chrysalis backdoor: A deep dive into Lotus Blossom’s toolkit
- The Notepad++ supply chain attack - unnoticed execution chains and new IoCs
- Web traffic hijacking: When your Nginx configuration turns malicious
- Technical analysis of Marco stealer
- Novel fake CAPTCHA chain delivering Amatera stealer
- New Clickfix variant ‘CrashFix’ deploying Python remote access trojan
- Android trojan campaign uses Hugging Face hosting for RAT payload delivery
- GlassWorm loader hits Open VSX via developer account compromise
- Strengthening supply-chain security in Open VSX
- Nitrogen Ransomware: ESXi malware has a bug
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments