Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Trump pardoned him. Now he’s selling his cyber business for $200 million
- NSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damages
- Switzerland plans surveillance worse than US
- OpenAI slams court order to save all ChatGPT logs, including deleted chats
- Can AI therapists really be an alternative to human help?
- CrowdStrike and Microsoft unite to harmonize cyber threat attribution
- International operation takes down crypting sites used for testing malware
- U.S. Government seizes approximately 145 criminal marketplace domains
- Ross Ulbricht got a $31 million donation from a dark web dealer, crypto tracers suspect
For the more technical
- Roundcube ≤ 1.6.10 post-auth RCE via PHP object deserialization
- Threat of TCC bypasses on macOS
- Ready_ Wasn’t Ready – four critical vulnerabilities in Symfonia eDokumenty
- Bombardino Crocodilo in Poland - analysis of IKO Lokaty mobile malware campaign
- Crocodilus in the wild: Mapping the campaign in Poland
- Critical Firefox 0-interaction libvpx vulnerability let attackers execute arbitrary code
- Google fixes another actively exploited vulnerability in Chrome, so update now!
- Don't call that "Protected" method: Dissecting an N-day vBulletin RCE
- vBulletin replaceAdTemplate exploited in the wild
- Attacker exploits misconfigured AI tool to run AI-generated payload
- Cybercriminals camouflaging threats as AI tool installers
- Infostealer malware FormBook spread via phishing campaign
- Lumma infostealer – down but not out?
- Deep dive into a dumped malware without a PE header
- Unpacking ClickFix: Darktrace’s detection of a prolific social engineering tactic
- ViperSoftX stealing cryptocurrencies
- BladedFeline: Whispering in the dark
- DCRat presence growing in Latin America
- Victims risk AsyncRAT infection after being redirected to fake Booking.com sites
- Newly identified wiper malware “PathWiper” targets critical infrastructure in Ukraine
- The Bitter end: Unraveling eight years of espionage antics - part one
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments