Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Decoding secrets through symbols: How military insignia revealed Russia’s hidden SIGINT network
- From dirty crypto to clean money – the laundering playbook of Russophone cybercriminals
- Ukraine-aligned hackers claim cyberattack on major Russian drone supplier
- Dell confirms breach of test lab platform by World Leaks extortion group
- Hungary: Police arrest suspect behind DDoS cyberattacks on IPI and independent media websites
- ATM fraudsters halted in Europol-supported operation led by Romanian and British authorities
- Ukraine arrests suspected admin of XSS Russian hacking forum
- After a tip, ExpressVPN updates its Windows app to strengthen protections
- Brave blocks Microsoft Recall by default
For the more technical
- DLL Hijacking in Check Point SmartConsole installer aka CVE-2024-24916
- SharePoint 0-day uncovered (CVE-2025-53770)
- Active exploitation of Microsoft SharePoint vulnerabilities
- SharePoint ToolShell: Zero-day exploited in-the-wild targets enterprise servers
- Disrupting active exploitation of on-premises SharePoint vulnerabilities
- NVIDIAScape - Critical NVIDIA AI vulnerability: A three-line container escape in NVIDIA Container Toolkit (CVE-2025-23266)
- Uncovering a stealthy WordPress backdoor in mu-plugins
- Google releases critical Chrome update for CVE-2025-6558 exploit active in the wild
- Copy-paste pitfalls: Revealing the AppLocker bypass risks in the suggested block-list policy
- Fake CAPTCHA led to LUMMA
- Back to business: Lumma stealer returns with stealthier methods
- Dissecting the ClickFix user-execution attack and its sophisticated persistence via ADS
- New variant of ACRStealer actively distributed with modifications
- Malware in DNS
- Ghost Crypt powers PureRAT with hypnosis
- NailaoLocker ransomware’s “cheese”
- Coyote in the wild: First-ever malware that abuses UI Automation
- DeedRAT backdoor enhanced by Chinese APTs with advanced capabilities
- Lookout Discovers Iranian APT MuddyWater leveraging DCHSpy during Israel-Iran conflict
- MaaS operation using Emmenhtal and Amadey linked to threats against Ukrainian entities
- Hive0156 continues Remcos campaigns against Ukraine
- Illusory wishes: China-nexus APT targets the Tibetan community
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments