Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [PL] Age verification means internet filtering
- [PL][VIDEO] Another VPN mishap? Not quite
- [PL] Paid disinformation takes a new turn as AI enters the game
- [PL] AI transparency in public administration must be the standard
- [PL] CRA: good practices for managing software security
- [PL] Identifying someone by their phone number under GDPR
- [PL] Arrests over false alerts about threats to life and health
- [PL] Alarm at the president’s family home. An expert debunks myths about scam tactics
- [PL] Otomoto: posting a listing can expose your data to scammers
- [PL] The bank employee scam: a call transcript and analysis
- [PL] Scammers’ “corporations”: inside the cybercrime market
- [PL] A trap for domain owners: how phishing targeting home.pl works
- [PL] Scammers working for Russia: how they impersonate well-known organizations
- Silent Ransom Group impersonating IT personnel through social engineering
- Cybercriminal VPN used by ransomware actors dismantled in global crackdown
- How we got a CISA GitHub leak taken down in under a day
- Lithuania investigates theft of 600,000 state registry records by foreign actor
- Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet
- 2026 World Cup: Discussing the world’s biggest game’s attack surface
- US law enforcement warns of “anti-tech extremism” as AI hatred grows
For the more technical
- [PL] How to set up a home flight tracking radar
- Microsoft Defender can now automatically isolate hacked endpoints
- Authenticated RCE via argument injection in Gogs
- FROST: Fingerprinting Remotely using OPFS-based SSD Timing
- FortiClient EMS exploited via CVE-2026-35616 to deliver EKZ infostealer disguised as a Fortinet patch
- From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
- Heap buffer write overflow in 7-Zip
- Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft
- Mini Shai-Hulud strikes again: TanStack + more npm packages compromised
- Megalodon: New CI/CD malware spreads across GitHub, infecting ~5,000+ repositories
- Staged publishing and new install-time controls for npm
- Malware-slop: New malicious npm package leaks its own GitHub private token
- Laravel-Lang supply chain attack: Every tag across multiple composer packages rewritten to steal CI secrets
- Ghost CMS mass compromised via CVE-2026-26980, now fueling ClickFix attacks
- Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace
- RatPressto phish kit
- SHub Reaper: macOS stealer spoofs Apple, Google, and Microsoft in a single attack chain
- From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
- Disrupting Glassworm: Inside CrowdStrike’s takedown of a developer-targeting botnet
- The Gentlemen ransomware group is scaling faster than any other group on record
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments