Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Trump Administration's Cyber Command and CISA and Russian Operations
- NoviSpy: Cheap Pegasus spyware for everyone
- You knew it was coming: Google begins testing AI-only search results
- Research finds 12,000 ‘live’ API keys and passwords in DeepSeek's training data
- Vulnerability Reward Program: 2024 in review
- Doors Wide Open: hundreds of thousands of employees exposed; thousands of organisations physically vulnerable
- Spyzie stalkerware is spying on thousands of Android and iPhone users
- Garantex cryptocurrency exchange disrupted in international operation
- Fake BianLian ransom notes mailed to US CEOs in postal mail scam
- Cybercrime 'crew' stole $635,000 in Taylor Swift concert tickets
- Massive botnet that appeared overnight is delivering record-size DDoSes
- US charges Chinese nationals in cyberattacks on Treasury, dissidents and more
- Feds link $150m cyberheist to 2022 LastPass hacks
- Data breach at Japanese telecom giant NTT hits 18,000 companies
- Two decades of visitor data at the Toronto Zoo stolen in cyberattack
For the more technical
- Understanding and mitigating TOCTOU vulnerabilities in C# applications
- Bypassing spam filtering mechanism in Outlook
- JTAG & Flipper Zero: To repair the Proxmark3
- A hidden feature in the mass-market ESP32 chip that could infect millions of IoT devices
- Paragon Partition Manager contains five memory vulnerabilities within its BioNTdrv.sys driver
- Over 37,000 VMware ESXi servers vulnerable to ongoing attacks
- The tools that real hackers use
- Cellebrite zero-day exploit used to target phone of Serbian student activist
- Meet Rayhunter: A new open source tool from EFF to detect cellular spying
- New PyPI malware ‘set-utils’ exfiltrates Ethereum private keys through blockchain transactions
- Camera off: Akira deploys ransomware via webcam
- Havoc: SharePoint with Microsoft Graph API turns into FUD C2
- BadBox 2.0 targets consumer devices with multiple fraud schemes
- Malvertising campaign leads to info stealers hosted on GitHub
- Silk Typhoon targeting IT supply chain
- Call it what you want: Threat actor delivers highly targeted multistage polyglot malware
- Unmasking the new persistent attacks on Japan
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments