Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- North Carolina man pleads guilty to music streaming fraud aided by artificial intelligence
- Russian citizen sentenced to prison for hacking into U.S. companies and enabling major cybercrime groups to extort tens of millions of dollars
- Authorities disrupt world’s largest IoT DDoS botnets responsible for record breaking attacks targeting victims worldwide
- Global cybercrime crackdown: over 373 000 dark web sites shut down
- Armenian man extradited to U.S. faces charges for role in infostealing malware scheme
- FCC imposes sweeping ban on foreign-made routers, affecting all new models
- Hong Kong police can demand phone and computer passwords under amended national security law
For the more technical
- Magento PolyShell: unrestricted file upload in Magento and Adobe Commerce
- Pre-auth remote code execution via buffer overflow in telnetd LINEMODE SLC handler
- CVE-2026-3888: Important Snap flaw enables local privilege escalation to root
- Kali Linux 2026.1 release (2026 Theme & BackTrack Mode)
- Trivy compromised: Everything you need to know about the latest supply chain attack
- Tycoon2FA phishing-as-a-service platform persists following takedown
- GhostClaw expands beyond npm: GitHub repositories and AI workflows deliver macOS infostealer
- “Say my name”: How MioLab is building MacOS stealer empire
- Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka
- ClickFix campaigns targeting Windows and macOS
- RegPhantom backdoor threat analysis
- From W-2 to BYOVD: How a tax search leads to kernel-mode AV/EDR kill
- Silver Fox: The only tax audit where the fine print installs malware
- NICKEL ALLEY strategy: Fake it ‘til you make it
- Analyzing FAUX#ELEVATE: Threat actors target France with CV lures to deploy crypto miners and infostealers targeting enterprise environments
- FriendlyDealer mimics official app stores to push unvetted gambling apps
- Tracing a multi-vector malware campaign: From VBS to open infrastructure
- OpenClaw trap: AI-assisted lure factory targets developers & gamers
- When malware talks back: Real-time interaction with a threat actor during the analysis of Kiss Loader
- Torg Grabber: Anatomy of a new credential stealer
- The certificate decoding illusion: How Blank Grabber stealer hides its loader
- Pawn Storm campaign deploys PRISMEX, targets government and critical infrastructure entities
- Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER
- From phishing to exfiltration: A deep dive into PXA Stealer
- No reach, no risk: The Keitaro abuse in modern cybercrime distribution
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments