Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- ChatGPT guessing game leads to users extracting free Windows OS keys & more
- OpenAI’s own web browser could arrive within weeks
- Russian pro basketball player arrested for alleged role in ransomware attacks
- Mexico’s new probe into alleged Pegasus bribe deepens corruption scandal
For the more technical
- eSIM security
- GraphQL security from a pentester’s perspective
- Critical sudo vulnerabilities: CVE-2025-32462 and CVE-2025-32463
- How much more must we bleed? - Citrix NetScaler memory disclosure (CitrixBleed 2 CVE-2025-5777)
- CVE-2025-5777: CitrixBleed 2 write-up… Maybe?
- NOTLogon: How a low-privilege machine can DoS your domain
- Microsoft Patch Tuesday, July 2025
- A native way to remove default Microsoft Store packages
- Opossum attack: Application layer desynchronization using opportunistic TLS
- PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars + more information
- Wing FTP Server remote code execution (CVE-2025-47812) exploited in the wild
- Malvertising campaign delivers Oyster/Broomstick backdoor via SEO poisoning and trojanized tools
- Google and Microsoft trusted them. 2.3 million users installed them. They were malware
- ESET Threat Report H1 2025
- NordDragonScan: Quiet data-harvester on Windows
- macOS.ZuRu resurfaces: Modified Khepri C2 hides inside doctored Termius app
- Atomic macOS Stealer now includes a backdoor for persistent access
- Deploying NetSupport RAT via WordPress & ClickFix
- SafePay ransomware: The fast-rising threat targeting MSPs
- Detailed analysis of AiLock ransomware
- Bert ransomware group targets Asia and Europe on multiple platforms
- When installers turn evil: The Pascal script behind Inno Setup malware campaign
- IconAds conceals source of ad fraud from users
- Digging gold with a spoon – resurgence of Monero-mining malware
- Anatsa targets North America; uses proven mobile campaign process
- Technical analysis of Ducex: Packer of Triada Android malware
- GoldMelody’s hidden chords: Initial access broker in-memory IIS modules revealed
- From click to compromise: Unveiling the sophisticated attack of DoNot APT group on Southern European government entities
- Pay2Key’s resurgence: Iranian cyber warfare targets the West
- BladedFeline: Whispering in the dark
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments