Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- ChatGPT Health lets you connect medical records to an AI that makes things up
- Google AI Overviews put people at risk of harm with misleading health advice
- Extracting books from production language models
- Australia enforces age ID checks for search engine users
- Trump pulls US out of international cyber orgs
For the more technical
- 2025 CVE data review
- The great VM escape: ESXi exploitation in the wild
- Silent takeover: How purchased Chrome extensions became remote-controlled webpage manipulation tools
- 2025 holiday scams: Docusign phishing meets loan spam
- Phishing actors exploit complex routing and misconfigurations to spoof domains
- Analyzing PHALT#BLYX: How fake BSODs and trusted build tools are used to construct a malware infection
- Malicious NPM packages deliver NodeCordRAT
- Stealth in layers: Unmasking the loader used in targeted email campaigns
- VVS Discord stealer using Pyarmor for obfuscation and detection evasion
- Predator iOS malware: Building a surveillance framework
- The ghost in the machine: Unmasking CrazyHunter's stealth tactics
- In-depth analysis report on LockBit 5.0: Operation and countermeasures
- Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp-based worm activity in Brazil
- Inside GoBruteforcer: AI-generated server defaults, weak passwords, and crypto-focused campaigns
- EmEditor supply chain incident details disclosed: Distribution of information-stealing malware sweeps through domestic government and enterprise entities
- Operation Artemis: Analysis of HWP-based DLL side loading attacks
- UAT-7290 targets high value telecommunications infrastructure in South Asia
- Reborn in Rust: Muddy Water evolves tooling with RustyWater implant
- GRU-linked BlueDelta evolves credential harvesting
- Knownsec data breach: A trove of espionage tradecraft with an insider narrative
- The intriguing Lotus: A deep dive into Sagerunex
- Analysis of StreamSpy, a new trojan using WebSocket by Patchwork (APT-Q-36)
- North Korean Kimsuky actors leverage malicious QR codes in spearphishing campaigns targeting U.S. entities
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments