Friday Squid Blogging: Squid Are ColorblindSchneier on Security·Jan 27, 14:13 UTC · Jan 27, 2020Malware155
Lazarus APT steals cryptocurrency and user data via a decoy MOBA gameKaspersky Securelist·Oct 23, 11:00 UTC · Oct 23, 2024Threat actorCVE-2024-494760
Equation: The Death Star of Malware GalaxyKaspersky Securelist·Feb 16, 18:55 UTC · Feb 16, 2015Malware55
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementationCisco Talos·Jul 13, 16:00 UTC · Jul 13, 2023Vulnerability55
New variant for Mac Malware XCSSET compiled for M1 ChipsSecurity Affairs·Mar 13, 10:13 UTC · Mar 13, 2021Malware55
Last week, the source code for MS Windows XP and Windows Server 2003 OS were leaked online, now a developer successfully compiled them.Security Affairs·Sep 30, 20:41 UTC · Sep 30, 2020Exploit / PoC160
What the food and building industry can teach us about securing embedded systemsHelp Net Security·Aug 16, 14:01 UTC · Aug 16, 2023Vulnerability55
‘Trojan Source’ Bug Threatens the Security of All CodeKrebs on Security·Nov 1, 05:21 UTC · Nov 1, 2021Malware55
2016 Updates to Shifu Banking TrojanPalo Alto Unit 42·Jan 6, 20:00 UTC · Jan 6, 2017MalwareCVE-2016-0167CVE-2015-0003160
Sofacy APT hits high profile targets with updated toolsetKaspersky Securelist·Dec 4, 10:59 UTC · Dec 4, 2015Data breachCVE-2015-259060
Friday Squid Blogging: The Far Side Squid ComicSchneier on Security·Dec 10, 22:05 UTC · Dec 10, 2021Exploit / PoCCVE-2021-44228160
Trojan Source bugs may lead to extensive supply-chain attacks on source codeHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2021MalwareCVE-2021-42574CVE-2021-42694160
Symantec confirms that Longhorn group is tied to CIA operators detailed in Vault 7Security Affairs·Apr 29, 10:24 UTC · Apr 29, 2021Exploit / PoC60
AutoHotkey-Based credential stealer targets bank in the US and CanadaSecurity Affairs·Jan 2, 10:45 UTC · Jan 2, 2021Malware55
Unraveling the Lamberts ToolkitKaspersky Securelist·Apr 11, 09:59 UTC · Apr 11, 2017Exploit / PoCCVE-2014-414860
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
Threat Brief: CVE-2022-3786 and CVE-2022Palo Alto Unit 42·Jun 5, 17:45 UTC · Jun 5, 2024VulnerabilityCVE-2022-3786CVE-2022-3602160
Hacked Cellebrite and MSAB Software ReleasedSchneier on Security·Jan 15, 00:00 UTC · Jan 15, 2023Exploit / PoC160
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
Internet Explorer and Windows zeroKaspersky Securelist·Aug 12, 07:00 UTC · Aug 12, 2020Exploit / PoCCVE-2020-0986CVE-2020-1380CVE-2020-0674+3 CVEs60
Chinese database exposes 42.5 million records compiled from multiple dating appsCyberScoop·May 29, 14:20 UTC · May 29, 2019Exploit / PoC in the wild160
Symantec Connects 40 Cyber Attacks to CIA Hacking Tools Exposed by WikileaksThe Hacker News·Apr 10, 18:37 UTC · Apr 10, 2017Exploit / PoC60
Equation Group: from Houston with loveKaspersky Securelist·Feb 19, 09:00 UTC · Feb 19, 2015Vulnerability55
The Epic Turla OperationKaspersky Securelist·Aug 7, 13:55 UTC · Aug 7, 2014Threat actorCVE-2013-5065CVE-2013-3346CVE-2012-172360
Prototyping Mitigations with DBI FrameworksCisco Talos·Apr 18, 03:35 UTC · Apr 18, 2012Vulnerability55
Chinese APT Group Exploits Dell ZeroInfosecurity Magazine·Feb 18, 10:10 UTC · Feb 18, 2026Threat actorCVE-2026-2276960
The dual reality of AI-augmented development: innovation and riskCyberScoop·Jul 7, 11:00 UTC · Jul 7, 2025Data breach in the wild160
Researchers discovered the largest data breach ever, exposing 16 billion login credentialsSecurity Affairs·Jun 20, 22:18 UTC · Jun 20, 2025Data breach in the wild60
Old certificate, new signature: Open-source tools forge signature timestamps on Windows driversCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
Microsoft silently enables ‘Super Duper Secure Mode’ for EdgeThe Record·Dec 19, 00:00 UTC · Dec 19, 2022Vulnerability55
Enhancing cyber resilience: What your team needs to knowHelp Net Security·Jun 9, 00:00 UTC · Jun 9, 2021Ransomware60
Google underwrites two full-time maintainers for Linux kernel security developmentHelp Net Security·Feb 25, 00:00 UTC · Feb 25, 2021Vulnerability55
A Fanny Equation: “I am your father, Stuxnet”Kaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2015Exploit / PoCCVE-2010-256860
State of play: network devices facing bullsKaspersky Securelist·Nov 26, 09:00 UTC · Nov 26, 2014Exploit / PoCCVE-2014-271960
Monthly Malware Statistics: August 2009Kaspersky Securelist·Sep 4, 12:00 UTC · Sep 4, 2009Malware in the wild60