Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Welcome to the GRU university, where Moscow turns students into spies and hackers
- Trenchant exec who sold zero days to Russian buyer ordered to pay $10 million in restitution to former employers
- Unpacking Russian-Iranian private-sector cyber connections
- Russia and U.S. amplifying Alberta separatist narratives to stoke division, distrust: report
- Anthropic’s AI chatbot is leaning more on Russian and Iranian propaganda sources, NewsGuard audit finds
- Google Chrome silently installs a 4 GB AI model on your device without consent
For the more technical
- Multi-stage malware delivery campaign using SEO poisoning and serverless infrastructure
- Dirty Frag: Universal Linux LPE
- Palo Alto PAN-OS Buffer Overflow Vulnerability (CVE-2026-0300)
- New Cisco DoS flaw requires manual reboot to revive devices
- Critical Apache HTTP/2 flaw (CVE-2026-23918) enables DoS and potential RCE
- ConsentFix v3: Analyzing a new criminal toolkit
- Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
- VENOMOUS#HELPER: Dual-RMM phishing campaign leveraging JWrapper-packaged SimpleHelp and ScreenConnect for silent remote access
- ClickFix campaign uses fake macOS utilities lures to deliver infostealers
- Supply chain campaign targets SAP npm packages with credential-stealing malware
- 8.3M downloads compromised: Lightning & Intercom-Client infected in latest Shai-Hulud attack
- Mini Shai-Hulud spreads to Packagist: Malicious Intercom PHP package follows npm compromise
- TeamPCP-linked supply chain attack hits SAP CAP and Cloud MTA npm packages
- Fake call logs, real payments: How CallPhantom tricks Android users
- TCLBANKER: Brazilian banking trojan spreading via WhatsApp and Outlook
- Malicious OpenClaw skill distributes Remcos RAT and GhostLoader
- InstallFix and Claude Code: How fake install pages lead to real compromise
- Quasar Linux (QLNX) – A silent foothold in the supply chain: Inside a full-featured Linux RAT with rootkit, PAM backdoor, credential harvesting capabilities
- Unmasking a multi-stage loader: AutoIt abuse leading to Vidar stealer command-and-control communication
- Attackers adopt JavaScript runtime Bun to spread NWHStealer
- A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
- UAT-8302 and its box full of malware
- Operation GriefLure: Dissecting an APT campaign targeting Vietnam’s military telecom & Philippine healthcare
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments