Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [PL] Criminal code amendment makes patostreaming a criminal offence
- [PL] Minors offered DDoS attack services online, with the youngest aged just 12
- [PL] Apple strengthens parental controls in iOS. What’s changing?
- [PL] Achievement unlocked: Steam account hijacked
- [PL] Fake parking fee used as a phishing lure
- [PL][VIDEO] DevOps in the crosshairs: social engineering that slips through the pipeline
- [PL][VIDEO] Fake reviews, fake experts and the real internet
- [PL] Publishing the names of athletes sanctioned for doping under GDPR
- [PL][VIDEO] What is the EU’s new QWAC mechanism?
- [PL][VIDEO] How YouTube creators can manipulate their metrics
- [PL] It’s dumber than you think: how your chatbot is being manipulated
- [PL] AI search: convenient answers, uncertain sources
- [PL] Chat Control rises from the grave: an ineffective and dangerous tool
- [PL] The Middle Kingdom watches from the shadows: China’s quiet expansion into Europe
- [PL][VIDEO] How the Kremlin is building an alternative financial system
- [PL] How Russian influence operations seek to delegitimise NATO
- [PL] Pro-Russian propaganda racks up more than a million views on TikTok
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
- Hack reveals Suno AI music generator scraped YouTube, Deezer, and Genius
- Law enforcement takes down Kratos/Sneaky2FA phishing service
For the more technical
- [PL][VIDEO] Recordings from the Oh My Hack 2025 conference
- [PL] The graveyard of code-signing certificates
- INC Ransom: Infrastructure analysis, operational tradecraft, and detection opportunities
- Next chapter: Restructuring GitHub’s bug bounty program
- WP2Shell: Pre authentication RCE in WordPress core
- Exploitation in the wild of wp2shell
- wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
- Tenda W18E security research
- Email threat landscape: Q2 2026 trends and insights
- From a single alert to 1,000 files: Inside an exposed WebDAV malware delivery lab
- Miasma worm hits Microsoft again: Azure Functions Action and 72 other repositories disabled after supply chain attack targeting AI coding agents
- ClickLock stealer: Paste once, lose everything
- Abusing trusted business workflows: A multi-stage Phantom stealer campaign
- The TTF trap: A global campaign of a low-detection Lua loader
- Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
- Unpacking “Cruciferra”: An analysis of a sophisticated crypter service
- TA488 targets Zimbra mailservers with half-click exploits
- Lampion's Portugal-focused phishing campaign delivers multistage malware
- DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's evolving tradecraft
- The procurement trap: Inside an AiTM campaign targeting global institutions
- Analysis of Kimsuky's attack on a South Korean groupware vendor using a new Gomir family variant
- Who needs a job? DPRK ClickFake Interview campaign drops PylangGhost and GolangGhost RATs
- New North Korean campaign uses fake coding interviews to steal developer credentials
- Execution-level analysis of a Russian-speaking multi-operator intrusion campaign: Operation STANDOFF
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
- Targeted attack on government entities in the Middle East
- GTIG: Updated cyber threat actor naming system
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.


Comments