Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- The scammer is always right - how Facebook protects scammers
- Behind the scenes of Paged Out! magazine – interview with Gynvael Coldwind
- U.S. spy agencies get one-stop shop to buy highly sensitive personal data
- Hacker who breached communications app used by Trump aide stole data from across US government
- Cetus Protocol hacked for more than $200 million
- U.S. sanctions cloud provider ‘Funnull’ as top source of ‘pig butchering’ scams
For the more technical
- By default, Signal doesn't Recall
- Microsoft closes 9-year-old feature request, open-sources Windows Subsystem for Linux
- BadSuccessor: Abusing dMSA to escalate privileges in Active Directory
- OneDrive File Picker flaw provides ChatGPT and other web apps full read access to users’ entire OneDrive
- Expression payloads meet mayhem - Ivanti EPMM Unauth RCE chain (CVE-2025-4427 and CVE-2025-4428)
- Thousands of Asus routers are being hit with stealthy, persistent backdoors
- PumaBot: Novel botnet targeting IoT surveillance devices
- Unpatched critical vulnerability in TI WooCommerce Wishlist plugin
- PhaaS the secrets: The hidden ties between Tycoon2FA and Dadsec's operations
- Text-to-Malware: How cybercriminals weaponize fake AI-themed websites
- Chasing Eddies: New Rust- based InfoStealer used in CAPTCHA campaigns
- PureHVNC RAT using fake high-level job offers from fashion and beauty brands
- A flyby on the CFO's inbox: Spear-phishing campaign targeting financial executives with NetBird deployment
- Katz stealer threat analysis
- Dissecting the macOS AppleProcessHub stealer: Technical analysis of a multi-stage attack
- DarkCloud stealer: Comprehensive analysis of a new attack chain that employs AutoIt
- The sharp taste of Mimo’lette: Analyzing Mimo’s latest campaign targeting Craft CMS
- NSIS abuse and sRDI shellcode: Anatomy of the Winos 4.0 campaign
- Pakistan Telecommunication Company (PTCL) targeted by Bitter APT during heightened regional conflict
- Operation Sindoor – anatomy of a digital siege
- Mark your calendar: APT41 innovative tactics
- Earth Lamia develops custom arsenal to target multiple industries
- New Russia-affiliated actor Void Blizzard targets critical sectors for espionage
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments