Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Foreign hacker in 2023 compromised Epstein files held by FBI, source and documents show
- Authorities dismantle global malicious proxy service that deployed malware and defrauded thousands of U.S. persons, businesses, and financial institutions of millions of dollars in losses
- Iranian hacktivists strike medical device maker Stryker in "severe" attack that wiped systems
- Russia targets Signal and WhatsApp accounts in cyber campaign
- Italian prosecutors confirm journalist was hacked with Paragon spyware
- Meta lied about its smart glasses protecting user privacy, new class action lawsuit claims
For the more technical
- March 2026 Patch Tuesday: Eight critical vulnerabilities and two publicly disclosed among 82 CVEs patched
- Fixing request smuggling vulnerabilities in Pingora OSS deployments
- Can’t hide your stride: Inferring car movement patterns from passive TPMS measurements
- Silence of the hops: The KadNap botnet
- New 'Zombie ZIP' technique lets malware slip past security tools
- Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets
- Evil evolution: ClickFix and macOS infostealers
- InstallFix: How attackers are weaponizing malvertised install guides
- CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security
- Through the lens of MDR: Analysis of KongTuke’s ClickFix abuse of compromised WordPress sites
- One click on this fake Google Meet update can give attackers control of your PC
- Abusing .arpa: The TLD that isn’t supposed to host anything
- Fileless multi-stage Remcos RAT: From phishing to memory-resident execution
- MAAS VIP_Keylogger campaign
- Endgame harvesting: Inside ACRStealer’s modern infrastructure
- MicroStealer analysis: A fast-spreading infostealer with limited detection
- PDF-borne living-off-the-land attacks with RMM abuse
- Daisy-chaining rogue RMM tools: How threat actors abuse remote management software for initial access
- Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
- APT36: A nightmare of vibeware
- Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
- Iran conflict drives heightened espionage activity against Middle East targets
- China-nexus activity against Qatar observed amid expanding regional tensions
- Iranian MOIS actors & the cyber crime connection
- Clearing the water: Unmasking an attack chain of MuddyWater
- North Korean APT malware analysis: DEV#POPPER RAT and OmniStealer
- An investigation into years of undetected operations targeting high-value sectors
- Sednit reloaded: Back in the trenches
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments