05/15

Red Teaming LLM Applications - DeepLearning.AI

https://www.deeplearning.ai/short-courses/red-teaming-llm-applications/
Red Teaming LLM Applications - DeepLearning.AI

Windows 11 and Red Hat Linux hacked on first day of Pwn2Own

https://www.bleepingcomputer.com/news/security/windows-11-and-red-hat-linux-virtualbox-hacked-on-first-day-of-pwn2own/
Windows 11 and Red Hat Linux hacked on first day of Pwn2Own

APT_REPORT/International Strategic/Korea/DTEX-Exposing+DPRK+Cyber+Syndicate+and+Hidden+IT+Workforce.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/International%20Strategic/Korea/DTEX-Exposing%2BDPRK%2BCyber%2BSyndicate%2Band%2BHidden%2BIT%2BWorkforce.pdf
APT_REPORT/International Strategic/Korea/DTEX-Exposing+DPRK+Cyber+Syndicate+and+Hidden+IT+Workforce.pdf at master · blackorbird/APT_REPORT · GitHub

Google fixes high severity Chrome flaw with public exploit

https://www.bleepingcomputer.com/news/security/google-fixes-high-severity-chrome-flaw-with-public-exploit/
Google fixes high severity Chrome flaw with public exploit

Operation RoundPress targeting high-value webmail servers

https://www.welivesecurity.com/en/eset-research/operation-roundpress/
Operation RoundPress targeting high-value webmail servers

Dice CTF Memory Hole: Breaking V8 Heap Sandbox

https://mem2019.github.io/jekyll/update/2022/02/06/DiceCTF-Memory-Hole.html
Dice CTF Memory Hole: Breaking V8 Heap Sandbox

FBI: US officials targeted in voice deepfake attacks since April

https://www.bleepingcomputer.com/news/security/fbi-us-officials-targeted-in-voice-deepfake-attacks-since-april/
FBI: US officials targeted in voice deepfake attacks since April

しばらくお待ちください...

https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists
しばらくお待ちください...

Nova Scotia Power confirms hackers stole customer data in cyberattack

https://www.bleepingcomputer.com/news/security/nova-scotia-power-confirms-hackers-stole-customer-data-in-cyberattack/
Nova Scotia Power confirms hackers stole customer data in cyberattack

New Tor Oniux tool anonymizes any Linux app's network traffic

https://www.bleepingcomputer.com/news/security/new-tor-oniux-tool-anonymizes-any-linux-apps-network-traffic/
New Tor Oniux tool anonymizes any Linux app's network traffic

Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

https://thehackernews.com/2025/05/russia-linked-apt28-exploited-mdaemon.html
Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

HITCON CTF 2022 - Chovid99's Blog

https://chovid99.github.io/posts/hitcon-ctf-2022/
HITCON CTF 2022 - Chovid99's Blog

Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

https://thehackernews.com/2025/05/malicious-npm-package-leverages-unicode.html
Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper

Malicious NPM package uses Unicode steganography to evade detection

https://www.bleepingcomputer.com/news/security/malicious-npm-package-using-steganography-downloaded-by-hundreds/
Malicious NPM package uses Unicode steganography to evade detection

Coinbase data breach exposes customer info and government IDs

https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/
Coinbase data breach exposes customer info and government IDs

Breachforums Boss to Pay $700k in Healthcare Breach – Krebs on Security

https://krebsonsecurity.com/2025/05/breachforums-boss-to-pay-700k-in-healthcare-breach/
Breachforums Boss to Pay $700k in Healthcare Breach – Krebs on Security

Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails

https://thehackernews.com/2025/05/coinbase-agents-bribed-data-of-1-users.html
Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails

Evolution of Tycoon 2FA Defense Evasion Mechanisms

https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/
Evolution of Tycoon 2FA Defense Evasion Mechanisms

Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit

https://thehackernews.com/2025/05/meta-to-train-ai-on-eu-user-data-from.html
Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

https://thehackernews.com/2025/05/new-chrome-vulnerability-enables-cross.html
New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

v1.4.0 - SmoothOpetator | NetExec

https://www.netexec.wiki/news/v1.4.0-smoothoperator
v1.4.0 - SmoothOpetator | NetExec

Technical Analysis of TransferLoader | ThreatLabz

https://www.zscaler.com/blogs/security-research/technical-analysis-transferloader
Technical Analysis of TransferLoader | ThreatLabz

RSA 2025: AI’s Promise vs. Security’s Past — A Reality Check | by Anton Chuvakin | Anton on Security | May, 2025 | Medium

https://medium.com/anton-on-security/rsa-2025-ais-promise-vs-security-s-past-a-reality-check-e06deb3bd579
RSA 2025: AI’s Promise vs. Security’s Past — A Reality Check | by Anton Chuvakin | Anton on Security | May, 2025 | Medium

Government webmail hacked via XSS bugs in global spy campaign

https://www.bleepingcomputer.com/news/security/government-webmail-hacked-via-xss-bugs-in-global-spy-campaign/
Government webmail hacked via XSS bugs in global spy campaign

U.S. CISA adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

https://securityaffairs.com/177856/security/u-s-cisa-adds-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html
U.S. CISA adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog