Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Phatic function in practice: How ChatGPT's conversation maintenance generates millions in losses
- Google is going to let kids use its Gemini AI
- Wikipedia says it will use AI, but not to replace human volunteers
- Perplexity wants to know more about you than Google
- Those who can’t do: Russia’s RT launches ‘journalism courses’ on ‘how to detect fakes’
- The problem with browser bookmark security
- Hitachi Vantara takes servers offline after Akira ransomware attack
- FBI's 2024 Internet Crime Complaint Center Report
- Alleged ‘Scattered Spider’ member extradited to U.S.
- FBI offers $10 million for information about Salt Typhoon members
For the more technical
- Hello 0-days, my old friend: A 2024 zero-day exploitation analysis
- Wormable zero-click remote code execution (RCE) in AirPlay protocol puts Apple & IoT devices at risk
- Critical SAP NetWeaver vulnerability fixed: actively exploited in the wild
- Microsoft’s patch for CVE-2025–21204 symlink vulnerability introduces another symlink vulnerability
- CVE-2025-24054, NTLM exploit in the wild
- Investigating an in-the-wild campaign using RCE in CraftCMS
- Fake security vulnerability phishing campaign targets WooCommerce users
- Scallywag extensions monetize piracy
- Cookie-Bite: How your digital crumbs let threat actors bypass MFA and maintain access to cloud environments
- The rapid rise of bots and the unseen risk for business
- Yet another NodeJS backdoor (YaNB): A modern challenge
- Navigating through the Fog
- DragonForce and Anubis introduced innovative approaches to expand their operations
- Gremlin stealer: New stealer on sale in underground forum
- Pentagon Stealer: Go and Python malware targeting crypto
- Threat actors are rargeting US tax-session with new tactics of Stealerium-infostealer
- I StealC you: Tracking the rapid changes to StealC
- TerraStealerV2 and TerraLogger: Golden Chickens' new malware families discovered
- Uncovering MintsLoader, a malicious loader deployed through multiple infection vectors
- Weaponized words. Uyghur language software hijacked to deliver malware
- Billbug: Intrusion campaign against Southeast Asia continues
- TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks
- Russian cyber operations. Analysis for the second half of 2024 from CERT-UA
- Earth Kasha updates TTPs in latest campaign targeting Taiwan and Japan
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments