-
1. What does GitHub’s security team even do? (orchidfiles.com) ▲ -
2. Pope's official prayer app commits cardinal sin, leaks 700K+ users' info (theregister.com) ▲ -
3. The hacker who humiliated spyware makers and was never caught (techcrunch.com) ▲ -
4. Hacker wipes Romania's land registry database (news.risky.biz) ▲ -
5. [post] How to maintain best practice in CS? ▲ -
6. Two critical SQLi vulnerabilities in WordPress (wordpress.org) ▲ -
7. Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes (theregister.com) ▲ -
8. Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package (theregister.com) ▲ -
9. North Korean Hackers Compromise Go and PHP Packages (opensourcemalware.com) ▲ -
10. PRC-linked spies hid inside medical and military networks for more than a year (theregister.com) ▲ -
11. Nearly Half of LG Smart TV Apps Are Laced with Proxies (spur.us) ▲ -
12. Anonymous GitHub account mass-dropping undisclosed 0-days (github.com) ▲ -
13. Cybersecurity in the post-mythos era: Keep calm and carry on! (cephalosec.com) ▲ -
14. Apple's Hide My Email could be exposing your real email address (easyoptouts.com) ▲ -
15. Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher (theregister.com) ▲ -
16. Humanity Protocol hacked for $36m (x.com) ▲ -
17. OptinMonster supply chain attack hits 1.2 million sites (sansec.io) ▲ -
18. Council of Europe hacked in ShinyHunters' PeopleSoft heist (theregister.com) ▲ -
19. Typosquatting: When Your Domain Is Used Against You (truesec.com) ▲ -
20. 10 year old critical vulnerability in phpBB affecting tens of millions of users (aikido.dev) ▲ -
21. ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw (cyberscoop.com) ▲ -
22. Malware developers added nuclear and biological weapons text to to their spyware (x.com) ▲ -
23. Who Runs the Ransomware Group 'The Gentlemen'? (krebsonsecurity.com) ▲ -
24. Infostealers Turn Millions of Devices Into Credential Theft Machines (securityweek.com) ▲ -
25. Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the year (theregister.com) ▲ -
26. A Botnet Accidentally Destroyed I2P (sambent.com) ▲ -
27. Microsoft Hacked to Deliver Malware to Claude and Gemini Users (404media.co) ▲ -
28. From cause to cash: a cross-border look at hacktivist activity (securelist.com) ▲ -
29. Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix (theregister.com) ▲ -
30. Anthropic: Measuring LLMs’ impact on N-day exploits (red.anthropic.com) ▲