Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Cloudflare turns AI against itself with endless maze of irrelevant facts
- People are using Google’s new AI model to remove watermarks from images
- EU mandates Apple to open up iPhone, iOS to competitors under Digital Markets Act
- A win for encryption: France rejects backdoor mandate
- The Citizen Lab’s director dissects spyware and the ‘proliferating’ market for it
- Social media platforms face huge fines under UK’s new digital safety laws
- TikTok will be blocked in Albania for one year
- Microsoft wouldn't look at a bug report without a video. Researcher maliciously complied
- Banned Russian channel RT secretly pays video bloggers who promote Kremlin narratives
- Ukrainian military targeted in new Signal spear-phishing attacks
- Warning over free online file converters that actually install malware
For the more technical
- GitHub Action tj-actions/changed-files supply chain attack: everything you need to know
- New GitHub Action supply chain attack: reviewdog/action-setup
- Kali Linux 2025.1a release (2025 Theme, & Raspberry Pi)
- Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
- Microsoft fixes Windows update bug that uninstalled Copilot
- Windows shortcut exploit abused as zero-day in widespread APT campaigns
- Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts
- BitM up! Session stealing in seconds using the browser-in-the-middle technique
- Hijacking a Python upload server: writeup from Insomni'hack CTF 2025
- One PUT request to own Tomcat: CVE-2025-24813 RCE is in the wild
- In-depth technical analysis of the Bybit hack
- Virtue or vice? A first look at Paragon’s proliferating spyware operations
- WhatsApp patched zero-click flaw exploited in Paragon spyware attacks
- State of WordPress security in 2025
- Hundreds of malicious Google Play-hosted apps bypassed Android 13 security with ease
- AMOS and Lumma stealers actively spread to Reddit users
- StilachiRAT analysis: From system reconnaissance to cryptocurrency theft
- Albabat ransomware group potentially expands targets to multiple OS, uses GitHub to streamline operations
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments