Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Google pulls the plug on Privacy Sandbox, leaving cookies in place
- Evilginx’s creator reckons with the dark side of red-team tools
- Cybercrime-as-a-service takedown: 7 arrested
- Half of 2025 ransomware attacks hit critical sectors as manufacturing, healthcare, and energy top global targets
- JFL lost up to $800,000 weekly after cyberattack, CEO says no patient or staff data was compromised
- NSO permanently barred from targeting WhatsApp users with Pegasus spyware
For the more technical
- Pwn2Own Ireland 2025: Day One Results, Day Two Results, Day Three and Master of Pwn
- apis.google.com - Insecure redirect via __lu parameter (exploited in the wild)
- TARmageddon (CVE-2025-62518): RCE vulnerability highlights the challenges of open source abandonware
- Key IOCs for Pegasus and Predator spyware cleaned with iOS 26 update
- The security paradox of local LLMs
- Malicious activity surrounding Perplexity’s Comet browser launch
- Attack technique: Abuse of the UWP lifecycle and Windows job objects
- Beyond credentials: weaponizing OAuth applications for persistent cloud access
- Tykit analysis: New phishing kit stealing hundreds of Microsoft accounts in finance
- Fast, broad, and elusive: How Vidar Stealer 2.0 upgrades infostealer capabilities
- GlassWorm: First self-propagating worm using invisible code hits OpenVSX marketplace
- Dissecting YouTube’s malware distribution network
- Operation MotorBeacon : Threat actor targets Russian automotive sector using .NET implant
- To be (a robot) or not to be: New malware attributed to Russia state-sponsored COLDRIVER
- Dark Covenant 3.0: Controlled impunity and Russia’s cybercriminals
- PhantomCaptcha: Multi-stage WebSocket RAT targets Ukraine in single-day spearphishing operation
- New group on the block: UNC5142 leverages EtherHiding to distribute malware
- TOLLBOOTH: What's yours, IIS mine
- Gotta fly: Lazarus targets the UAV sector
- Help wanted: Vietnamese actors using fake job posting campaigns to deliver malware and steal credentials
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments