Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- I verified my LinkedIn identity. Here's what I actually handed over
- TikTok won't protect DMs with controversial privacy tech, saying it would put users at risk
- Europol coordinated Project Compass against the The Com network
- Defending the gates: How a global coalition disrupted Tycoon 2FA, a major driver of initial access and large-scale online impersonation
- Russia-linked cryptocurrency services and sanctions evasion
- The post-RAMP era: Allegations, fragmentation, and the rebuilding of the ransomware underground
For the more technical
- Look what you made us patch: 2025 zero-days in review
- FreeScout RCE enables full system takeover
- Coruna: The mysterious journey of a powerful iOS exploit kit
- Taming agentic browsers: Vulnerability in Chrome allowed extensions to hijack new Gemini panel
- OpenClaw vulnerability: Website-to-local agent takeover
- “Malware, from the outside!”: How a threat actor used fake OpenClaw installers to infect systems with GhostSocks and information stealers
- Caught in the hook: RCE and API token exfiltration through Claude Code project files
- Tracking CyberStrikeAI usage
- A fake FileZilla site hosts a malicious download
- OAuth redirection abuse enables phishing and malware delivery
- CISA details how RESURGE hides on Ivanti systems after zero-day attacks
- Viruses 101: How a classic file-infecting virus worked in Windows
- Hooked on Linux: Rootkit taxonomy, hooking techniques and tradecraft
- Analysis of AuraStealer, an emerging infostealer
- New BoryptGrab stealer targets Windows users via deceptive GitHub pages
- Signed malware impersonating workplace apps deploys RMM backdoors
- Funnull resurfaces: Exposing RingH23 arsenal and MacCMS supply chain attacks
- APT37 adds new capabilities for air-gapped networks
- UAT-9244 targets South American telecommunication providers with three new malware implants
- Silver Dragon targets organizations in Southeast Asia and Europe
- SloppyLemming deploys BurrowShell and Rust-Based RAT to target Pakistan and Bangladesh
- Threat brief: March 2026 escalation of cyber risk related to Iran
- Interplay between Iranian targeting of IP cameras and physical warfare in the Middle East
- RedAlert trojan campaign: Fake emergency alert app spread via SMS spoofing Israeli Home Front Command
- Doppelgänger / RRN disinformation infrastructure ecosystem 2026
- Exposing a Russian campaign targeting Ukraine using new malware duo: BadPaw and MeowMeow
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments