Afraid of missing important security news during the week? We’re here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone number
- Scania confirms insurance claim data breach in extortion attempt
- Iranian crypto exchange Nobitex hacked for over $90 million by pro-Israel group
- Europe-wide takedown hits longest-standing dark web drug market
For the more technical
- Null Pointer Exceptions: From Java’s pitfalls to Kotlin’s solutions
- GreyNoise observes exploit attempts targeting Zyxel CVE-2023-28771
- Asus Armoury Crate AsIO3.sys authorization bypass vulnerability
- Kali Linux 2025.2 release (Kali menu refresh, BloodHound CE & CARsenal)
- “The Grafana Ghost” exposes 36% of public-facing instances to malicious account takeover
- SmartAttack: Air-gap attack via smartwatches
- Breaking down ‘EchoLeak’, the first zero-click AI vulnerability enabling data exfiltration from Microsoft 365 Copilot
- How I hacked accounts using host header injection in password reset link
- Critical Langflow vulnerability (CVE-2025-3248) actively exploited to deliver Flodrix botnet
- Fake Minecraft mods distributed by the Stargazers Ghost Network to steal gamers’ data
- Mocha Manakin delivers custom NodeJS backdoor via paste and run
- Clone, compile, compromise: Water Curse’s open-source malware trap on GitHub
- A Wretch Client: From ClickFix deception to information stealer deployment
- Your mobile app, their playground: The dark side of the virtualization
- Vexing and vicious: The eerie relationship between WordPress hackers and an adtech Cabal
- Exploring a new KimJongRAT stealer variant and its PowerShell implementation
- DanaBleed: DanaBot C2 server memory leak bug
- GrayAlpha uses diverse infection vectors to deploy PowerNet Loader and NetSupport RAT
- Don’t get caught in the headlights – DeerStealer analysis
- Amatera stealer: Rebranded ACR stealer with improved evasion, sophistication
- Anubis: A closer look at an emerging ransomware with built-in wiper
- Defending the Internet: how Cloudflare blocked a monumental 7.3 Tbps DDoS attack
- Threat actor Banana Squad exploits GitHub repos in new campaign
- Uncovering a Tor-enabled Docker exploit
- Analyzing SerpentineCloud: Threat actors abuse Cloudflare Tunnels to infect systems with stealthy Python-based malware
- Same sea, new phish: Russian government-linked social engineering targets app-specific passwords
- Follow the smoke: China-nexus threat actors hammer at the doors of top tier targets
- Famous Chollima deploying Python version of GolangGhost RAT
- Feeling Blue(Noroff): Inside a sophisticated DPRK Web3 intrusion
- From SambaSpy to Sorillus: Dancing through a multi-language phishing campaign in Europe
- Threat group targets companies in Taiwan
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.