Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Cursor-Opus agent snuffs out startup’s production database
- Extension developers sell the data of at least 6.5 million users – and it’s all completely legal
- Video service Vimeo confirms Anodot breach exposed user data
- U.S. companies hit with record fines for privacy in 2025
- Turkish parliament passes bill to restrict social media access for under-15s
- Sflix, Myflixerz, HDtoday, and other pirate sites go dark as backend infrastructure fails
- Anti-DDoS firm heaped attacks on Brazilian ISPs
- Call centres dismantled and ten arrested in EUR 50 million online fraud case
- Coordinated takedown of scam centers leads to at least 276 arrests; alleged managers and recruiters charged in San Diego
For the more technical
- New Linux 'Copy Fail' vulnerability enables root access on major distributions
- Pack2TheRoot (CVE-2026-41651): Cross-distro local privilege escalation vulnerability
- We found a stable Firefox identifier linking all your private Tor identities
- CanisterSprawl: pgserve compromised on npm: malicious versions harvest credentials and exfiltrate to a decentralized ICP canister
- LOLBins – analysis of MSBuild-based attack techniques
- The Gentlemen ransomware decryptor
- VECT: Ransomware by design, wiper by accident
- Inside Vidar (2026): From infection to memory execution via JPEG and TXT payloads
- “Chaos is a ladder”: Vidar’s recent rise to the top
- Jenkins honeypot reveals emerging botnet targeting online games
- Crypto drainers as a converging threat: Insights into emerging hybrid attack ecosystems
- Hold the phone! International revenue share fraud driven by fake CAPTCHAs
- Morpheus: A new spyware linked to IPS Intelligence
- Boutique phishing kit Saiga 2FA hides behind ‘lorem ipsum’ metadata
- Deep#Door stealer: Stealthy Python backdoor and credential stealer leveraging tunneling, multi-layer persistence, and in-memory surveillance capabilities
- Firestarter backdoor infects Cisco firewall at a U.S. federal agency
- fast16: mystery ShadowBrokers reference reveals high-precision software sabotage 5 years before Stuxnet
- BlueNoroff uses ClickFix, fileless PowerShell, and AI-generated fake Zoom meetings to target Web3 sector
- Tall Tales. How Chinese actors use impersonation and stolen narratives to perpetuate digital transnational repression
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments