Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- World's deadliest computer virus: WannaCry
- North Korea's crypto hackers have stolen over $2 billion in 2025
- Discord says 70,000 users may have had their government IDs leaked in breach
- Hackers claim Discord breach exposed data of 5.5 million users
- Salesforce refuses to pay ransom over widespread data theft attacks
- Italian businessman’s phone reportedly targeted with Paragon spyware
- noyb win: Microsoft 365 Education may not track school children
For the more technical
- CrowdStrike identifies campaign targeting Oracle E-Business Suite via zero-day vulnerability (now tracked as CVE-2025-61882)
- CVE-2025-61882 mass exploitation — Oracle E-Business Suite (EBS) under attack by Cl0p ransomware
- Another critical RCE discovered in a popular MCP server
- Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability
- RediShell: Critical remote code execution vulnerability (CVE-2025-49844) in Redis, 10 CVSS score
- A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research
- CVE-2025-59489: Arbitrary code execution in Unity Runtime
- WireTap: Breaking server SGX via DRAM bus interposition
- Your gaming mouse could eavesdrop on you, study reveals surprising vulnerability
- RondoDox: From targeting Pwn2Own vulnerabilities to shotgunning exploits
- CometJacking: How one click can turn Perplexity’s Comet AI browser against you
- Ghosts in the machine: ASCII smuggling across various LLMs
- I tested the world's first "AI ransomware"... and it was a disaster
- The evolution of Chaos ransomware: Faster, smarter, and more dangerous
- Velociraptor leveraged in ransomware attacks
- TamperedChef: Malvertising to credential theft
- Shuyal Stealer: Advanced infostealer targeting 19 browsers
- New Rust malware "ChaosBot" uses Discord for command and control
- Confucius espionage: From stealer to backdoor
- Crimson Collective: A new threat group observed operating in the cloud
- ClayRat: A new Android spyware targeting Russia
- Investigating targeted “payroll pirate” attacks affecting US universities
- Cache smuggling: When a picture isn’t a thousand words
- The ClickFix factory: First exposure of IUAM ClickFix Generator
- The crown prince, Nezha: A new tool favored by China-nexus threat actors
- An insider look at the IRGC-linked APT35 operations: Ep1 & Ep2
- Mustang Panda employ Publoader through ClaimLoader: Yes.. another DLL side-loading technique delivery via phishing
- Analyzing NotDoor: Inside APT28’s expanding arsenal
- Operation SouthNet: SideWinder expands phishing and malware operations in South Asia
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments