Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Windscribe wins legal battle in Greece due to no-logs policy
- TikTok: Covert influence operations
- APT29: Inside Russia's most dangerous hacking group
- The Signal clone the Trump admin uses was hacked
- Court clash between Meta and NSO ends in $168 million defeat for spyware firm
- Windows RDP lets you log in using revoked passwords. Microsoft is OK with that
- xAI dev leaks API key for private SpaceX, Tesla LLMs
- Yemeni man charged in federal indictment alleging he sent ‘Black Kingdom’ malware to extort businesses, schools, and medical clinics
- Santa Clarita man agrees to plead guilty to hacking Disney employee’s computer, downloading confidential data from company
For the more technical
- Android Security Bulletin—May 2025
- SQL Injection in the age of ORM: Risks, mitigations, and best practices
- Samsung MagicINFO 9 remains vulnerable to ongoing exploitation
- Using trusted protocols against you: Gmail as a C2 mechanism
- Backdoor found in popular ecommerce components
- wget to wipeout: Malicious Go modules fetch destructive payload
- Novel universal bypass for all major LLMs
- Trust me, I’m local: Chrome extensions, MCP, and the sandbox escape
- Targeted by 20.5 million DDoS attacks, up 358% year-over-year: Cloudflare’s 2025 Q1 DDoS Threat Report
- Exposing Darcula: a rare look behind the scenes of a global Phishing-as-a-Service operation
- Agenda ransomware group adds SmokeLoader and NETXLOADER to their arsenal
- IP cluster linking ransomware activity and Eye Pyramid C2
- Mamona: Technical analysis of a new ransomware strain
- Operation Deceptive Prospect: RomCom targeting UK organisations through customer feedback portals
- Multilayered email attack: How a PDF invoice and geo-fencing led to RAT malware
- CoGUI phish kit targets Japan with millions of messages
- Detailed analysis of BPFDoor targeting South Korean company
- Lampion is back with ClickFix lures
- Telegram tango: A pig butchering investigation
- COLDRIVER using new malware to steal documents from western targets and NGOs
- Pahalgam Attack themed decoys used by APT36 to target the Indian Government
- Intrusion into Middle East critical national infrastructure
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments