Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- What happened during ByBit heist, where $1.5 billion has been stolen from a crypto exchange
- A well-funded Moscow-based global ‘news’ network has infected Western artificial intelligence tools worldwide with Russian propaganda
- ICANN moves to retire Soviet-era .SU country domain name
- What really happened with the DDoS attacks that took down X
- ClickFix: How to infect your PC in three easy steps
- Android devices track you before you even sign in
- Cellebrite is using AI to summarize chat logs and audio from seized mobile phones
- FTC will send $25.5 million to victims of tech support scams
- Alleged co-founder of Garantex arrested in India
- Alleged Russian LockBit developer extradited from Israel, appears in New Jersey court
For the more technical
- History of NULL pointer dereferences on macOS
- Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
- Mozilla warns users to update Firefox before certificate expires
- Microsoft Patch Tuesday: March 2025
- Microsoft apologizes for removing VSCode extensions used by millions
- Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
- Sanitization and validation and escaping, oh my!
- The ESP32 "backdoor" that wasn't
- DeepSeek deep dive: Creating malware, including keyloggers and ransomware
- Ghost in the router: China-nexus espionage actor UNC3886 targets Juniper routers
- Lazarus strikes npm again with new wave of malicious packages
- Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malware
- Lookout discovers new spyware by North Korean APT37
- CISA: More than 300 critical infrastructure orgs attacked by Medusa ransomware
- SocGholish’s intrusion techniques facilitate distribution of RansomHub ransomware
- Decrypting encrypted files from Akira ransomware (Linux/ESXI variant 2024) using a bunch of GPUs
- New ransomware operator exploits Fortinet vulnerability duo
- Inside Bruted: Black Basta (RaaS) members used automated brute forcing framework to target edge network devices
- 2025 Cyber Threat Landscape for the Nordic Financial Sector
- Captain MassJacker Sparrow: Uncovering the malware’s buried treasure
- AI-assisted fake GitHub repositories fuel SmartLoader and LummaStealer distribution
- Unpatched Edimax IP camera flaw actively exploited in botnet attacks
- Ballista – new IoT botnet targeting thousands of TP-Link Archer routers
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments