Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Singapore to order Meta to curb impersonation scams or face fines of up to S$1 million
- Google hit with $425 million verdict in privacy class action suit
- Apple is teaching its AI to adapt to the Trump era
- 400 scientists speak out against chat control
- Introducing Signal secure backups
- The Tor Project has released an official VPN
- PromptLock ransomware is just a research project, but it's still disturbing
For the more technical
- September 2025 Patch Tuesday: Two publicly disclosed zero-days and eight critical vulnerabilities among 84 CVEs
- Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1
- DNS4EU – a bit EU, a bit secure, a bit pointless
- The Rise of RatOn: From NFC heists to remote control and ATS
- Technical report: AgeGO age verification on pornographic platforms
- The history of AppSuite: the certs of the BaoLoader developer
- Behind the mask of Madgicx Plus: A Chrome extension campaign targeting Meta advertisers
- Fancy Bear GonePostal – espionage tool provides backdoor access to Microsoft Outlook
- ChillyHell: A deep dive into a modular macOS backdoor
- ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT
- Technical analysis of kkRAT
- MostereRAT deployed AnyDesk/TightVNC for covert full access
- AdaptixC2: A new open-source framework leveraged in real-world attacks
- SafePay ransomware: How a non-RaaS group executes rapid fire attacks
- Trigona rebranding suspicions and global threats, and BlackNevas ransomware analysis
- Unmasking the Gentlemen ransomware: Tactics, techniques, and procedures revealed
- CyberVolk ransomware: Analysis of double encryption structure and disguised decryption logic
- Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm
- Frankenstein variant of the ToneShell backdoor targeting Myanmar
- APT37 targets Windows with Rust backdoor and Python loader
- Inside the 2025 energy phishing wave: Chevron, Conoco, PBF, Phillips 66
- Inside the Kimsuky leak: How the “Kim” dump exposed North Korea’s credential theft playbook
- Kimsuky’s use of GitHub for malware delivery and exfiltration
- Salt Typhoon and UNC4841: Silent Push discovers new domains; urges defenders to check telemetry and log data
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments