Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- OUCH! November 2025: ‘Tis the season to be skeptical - shopping online securely
- CrowdStrike catches insider feeding information to hackers
- Founders of Samourai Wallet cryptocurrency mixing service sentenced to five and four years in prison
- Ransomware attack disrupts local emergency alert system across US
- OpenAI: What to know about a recent Mixpanel security incident
For the more technical
- How macOS file metadata exposes authentication tokens
- Thick client penetration testing guide 2025
- Desktop application security testing checklist 2025
- Counter Galois Onion: Improved encryption for Tor circuit traffic
- The unpowered SSDs in your drawer are slowly losing your data
- When updates backfire: RCE in Windows Update Health Tools
- Grafana warns of max severity admin spoofing vulnerability
- Critical vulnerabilities in FluentBit expose cloud environments to remote takeover
- Stop putting your passwords into random websites (yes, seriously, you are the problem)
- HashJack – novel indirect prompt injection against AI browser assistants
- The dual-use dilemma of AI: Malicious LLMs
- Analyzing the latest Sneaky2FA Browser-in-the-Browser phishing page
- ClickFix gets creative: Malware buried in images
- Russian-linked StealC V2 campaign targeting Blender users via malicious .blend files
- Fake Battlefield 6 pirated versions and game trainers used to deploy stealers and C2 agents
- WhatsApp compromise leads to Astaroth deployment
- Brazilian campaign: Spreading the malware via WhatsApp
- FlexibleFerret malware continues to strike
- Shai-Hulud 2.0 supply chain attack: 25K+ repos exposing secrets
- ShadowV2 casts a shadow over IoT devices
- Beyond the watering hole: APT24's pivot to multi-vector attacks
- Kimsuky’s ongoing evolution of KimJongRAT and expanding threats
- APT35 internal leak of hacking campaigns against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and domestic Iranian targets
- A sophisticated Water Gamayun APT group attack
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments