Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Rogue communication devices found in Chinese solar power inverters
- Xinbi: The $8 billion Colorado-incorporated marketplace for pig-butchering scammers and North Korean hackers
- The Internet’s biggest-ever black market just shut down amid a Telegram purge
- Introducing oniux: Kernel-level Tor isolation for any Linux app
- The most persuasive “people” on a popular subreddit turned out to be a front for a secret AI experiment
- DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains
- Breachforums boss to pay $700k in healthcare breach
- Google to pay $1.38 billion over privacy violations
For the more technical
- The May 2025 security update review
- Apple updates everything: May 2025 edition
- Branch Privilege Injection: Compromising Spectre v2 hardware mitigations by exploiting branch predictor race conditions
- One-click RCE in ASUS’s preinstalled driver software
- Printer company provided infected software downloads for half a year
- Backdooring the IDE: Malicious npm packages hijack Cursor editor on macOS
- Sophisticated NPM attack leveraging Unicode steganography and Google Calendar C2
- Stealthy .NET malware: Hiding malicious payloads as bitmap resources
- A .NET multi-stage malware delivery system
- Technical analysis of TransferLoader
- New Noodlophile stealer distributes via fake AI video generation platforms
- Evolution of Tycoon 2FA defense evasion mechanisms: Analysis and timeline
- Lumma stealer, coming and going
- Sit, fetch, steal - Chihuahua stealer: A new breed of infostealer
- DarkCloud Stealer: Comprehensive analysis of a new attack chain that employs AutoIt
- Fileless execution: PowerShell based shellcode loader executes Remcos RAT
- APT36-style ClickFix attack spoofs Indian Ministry to target Windows & Linux
- Defending against UNC3944: Cybercrime hardening guidance from the frontlines
- Operation RoundPress
- TA406 pivots to the front
- Earth Ammit disrupts drone supply chains through coordinated multi-wave attacks in Taiwan
- Unveiling Swan Vector APT targeting Taiwan and Japan with varied DLL implants
- Marbled Dust leverages zero-day in Output Messenger for regional espionage
- Analysis of APT37 attack case disguised as a think tank for national security strategy in South Korea
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments