Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT
- noyb win: Microsoft ordered to stop tracking school children
- French MPs approve social media ban for children under 15
- Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts
- Site catering to online criminals has been seized by the FBI
- Microsoft gave FBI keys to unlock encrypted data, exposing major privacy flaw
- Chinese language money laundering networks emerge as major facilitators of the illicit crypto economy, now driving 20% of laundering activity
For the more technical
- Energy sector incident report - 29 December 2025 (PDF)
- SpyNote: Comprehensive analysis of an Android Remote Access Trojan
- Diverse threat actors exploiting critical WinRAR vulnerability CVE-2025-8088
- Attackers with decompilers strike again (SmarterTools SmarterMail WT-2026-0001 auth bypass)
- Ivanti warns of two EPMM flaws exploited in zero-day attacks
- Critical eScan supply chain compromise
- When zero‑width isn’t zero: How I found and fixed a vulnerability
- Top 10 web hacking techniques of 2025: call for nominations
- Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic
- No place like home network: Disrupting the world's largest residential proxy network
- Stanley — A $6,000 Russian malware toolkit with Chrome Web Store guarantee
- Hacking an AI children's toy: Remote access to every conversation
- Analysis of ClawDBot malware hidden in VSCode extensions
- The rise of Arsink RAT
- When malware talks back
- Interlock ransomware: New techniques, same old tricks
- Pivoting from PayTool: Tracking various frauds and e-crime targeting Canada
- Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
- RedKitten: AI-accelerated campaign targeting Iranian protests
- APT attacks target Indian government using Gogitter, Gitshellpad, and Goshell | Part 1
- APT attacks target Indian government using Sheetcreep, Firepower, and Mailcreep | Part 2
- PeckBirdy: A versatile script framework for LOLBins exploitation used by China-aligned threat groups
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments