Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- U.S. government disclosed 39 zero-day vulnerabilities in 2023, per first-ever report
- Internet Archive played crucial role in tracking shady CDC data removals
- DeepSeek iOS app sends data unencrypted to ByteDance-controlled servers
- New target of Paragon spyware comes forward
- Britain orders Apple to give it access to encrypted accounts
- Cybercrime websites selling hacking tools to transnational organized crime groups seized
- [VIDEO] Russian cyber-spies attack
For the more technical
- Polish IT security projects – what’s new in LKRG?
- ZeroTier – home VPN without a public IP address
- DeepSeek’s growing influence sparks a surge in frauds and phishing attacks
- Llama’s paradox – Delving deep into Llama.cpp and exploiting Llama.cpp’s heap maze, from heap-overflow to remote-code execution
- 8 million requests later, we made the SolarWinds supply chain attack look amateur
- 2024 trends in vulnerability exploitation
- Zyxel won’t patch newly exploited flaws in end-of-life routers
- 35% year-over-year decrease in ransomware payments, less than half of recorded incidents resulted in victim payments
- A comprehensive analysis of the year’s new macOS malware
- macOS FlexibleFerret: Further variants of DPRK malware family unearthed
- Let’s Encrypt: Ending support for expiration notification emails
- Cloudflare incident on February 6, 2025
- Scalable Vector Graphics files pose a novel phishing threat
- Go supply chain attack: Malicious package exploits Go module proxy caching for persistence
- Adversarial misuse of generative AI
- Lazarus group targets organizations with sophisticated LinkedIn recruiting scam
- Operation Phantom Circuit: North Korea’s global data exfiltration campaign
- Persistent threats from the Kimsuky group using RDP wrapper
- CVE-2025-0411: Ukrainian organizations targeted in zero-day campaign and homoglyph attacks
- Code injection attacks using publicly disclosed ASP.NET machine keys
- LegionLoader exposed
- The anatomy of Abyss Locker ransomware attack
- Mobile Indian cyber heist: FatBoyPanel and his massive data breach
- AsyncRAT reloaded: Using Python and TryCloudflare for malware delivery again
- Rat race: ValleyRAT malware targets organizations with new delivery techniques
- Tracing the path from SmartApeSG to NetSupport RAT
- ClickFix vs. traditional download in new DarkGate campaign
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.