Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- UAE recruiting US personnel displaced by DOGE to work on AI for its military
- Russian hybrid threats: EU lists further 21 individuals and 6 entities and introduces sectoral measures in response to destabilising activities against the EU, its member states and international partners
- 270 arrested in global dark web crackdown targeting online drug and criminal network
- Leader of Qakbot malware conspiracy indicted for involvement in global ransomware scheme
- Oops: DanaBot malware devs infected teir own PCs
- VanHelsing ransomware builder leaked on hacking forum
- KrebsOnSecurity hit with near-record 6.3 Tbps DDoS
- Nearly 70,000 impacted by Coinbase breach involving $20 million ransom demand
For the more technical
- Anonymization in Discord unveiled
- Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin
- Passkeys for normal people
- Hidden threats of dual-function malware found in Chrome extensions
- How I ruined my vacation by reverse engineering WSC
- O2 VoLTE: locating any customer with a phone call
- 60 malicious npm packages leak network and host data in active malware campaign
- Caught in the CAPTCHA: How ClickFix is weaponizing verification fatigue to deliver RATs & infostealers
- Copyright phishing lures leading to Rhadamanthys stealer now targeting Europe
- ViciousTrap – infiltrate, control, lure: turning edge devices into honeypots en masse
- An exploration of techniques used by the obfuscator ALCATRAZ
- Danabot: Analyzing a fallen empire
- TikTok videos promise pirated Apps, deliver Vidar and StealC infostealers instead
- ESET takes part in global operation to disrupt Lumma Stealer
- From banks to battalions: SideWinder’s attacks on South Asia’s public sector
- The sting of fake Kling: Facebook malvertising lures victims to fake AI generation website
- How adversary Telegram bots help to reveal threats: Case study
- DBatLoader (ModiLoader) being distributed to Turkish users
- BlackBasta and Cactus use Skitnet for targeted ransomware operations
- Another Confluence bites the dust: Falling to ELPACO-team ransomware
- A familiar playbook with a twist: 3AM ransomware actors dropped virtual machine with vishing and Quick Assist
- UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware
- China-nexus threat actor actively exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) vulnerability
- High risk warning for Windows ecosystem: New botnet family HTTPBot is expanding
- Cloudy with a chance of hijacking forgotten DNS records enable scam actor
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments