Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for February 24, 2025

THN Weekly Recap: From $1.5B Crypto Heist to AI Misuse & Apple’s Data Dilemma
https://thehackernews.com/2025/02/thn-weekly-recap-from-15b-crypto-heist.html

Becoming Ransomware Ready: Why Continuous Validation Is Your Best Defense
https://thehackernews.com/2025/02/becoming-ransomware-ready-why.html

Google Cloud KMS Adds Quantum-Safe Digital Signatures to Defend Against Future Threats
https://thehackernews.com/2025/02/google-cloud-kms-adds-quantum-safe.html

Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign
https://research.checkpoint.com/2025/large-scale-exploitation-of-legacy-driver/

Over 35,000 Websites Targeted in Full-Page Hijack Linking to a Chinese-Language Gambling Scam
https://www.reddit.com/r/netsec/comments/1ix2csa/over_35000_websites_targeted_in_fullpage_hijack/

Exposing Shadow AI Agents: How We Extracted Financial Data from Billion-Dollar Companies
https://www.reddit.com/r/netsec/comments/1ix3p40/exposing_shadow_ai_agents_how_we_extracted/

Tearing Down (Sonic)Walls: Decrypting SonicOSX Firmware
https://bishopfox.com/blog/sonicwall-decrypting-sonicosx-firmware

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for October 30, 2023

Caller ID Spoofing: The Invisible Threat to Phone Security and How to Combat It
https://www.reddit.com/r/netsec/comments/1ixpnm8/caller_id_spoofing_the_invisible_threat_to_phone/

2,500+ Truesight.sys Driver Variants Exploited to Bypass EDR and Deploy HiddenGh0st RAT
https://thehackernews.com/2025/02/2500-truesightsys-driver-variants.html

5 Active Malware Campaigns in Q1 2025
https://thehackernews.com/2025/02/5-active-malware-campaigns-in-q1-2025.html

GitVenom Malware Steals $456K in Bitcoin Using Fake GitHub Projects to Hijack Wallets
https://thehackernews.com/2025/02/gitvenom-malware-steals-456k-in-bitcoin.html

Streamlining Vulnerability Research with IDA Pro and Rust
https://www.reddit.com/r/netsec/comments/1ixoklw/streamlining_vulnerability_research_with_ida_pro/

PortSwigger and SAP Forge Strategic Partnership to Enhance Enterprise Web Security
https://portswigger.net/blog/portswigger-and-sap-forge-strategic-partnership-to-enhance-enterprise-web-security

Orange Group Confirms Breach After Hacker Posts Alleged Stolen Data
https://www.thecyberwire.com/newsletters/daily-briefing/14/36

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for February 25, 2025

The Best Security Is When We All Agree To Keep Everything Secret (Except The Secrets) - NAKIVO Backup & Replication (CVE-2024-48248)
https://www.reddit.com/r/netsec/comments/1iykzuc/the_best_security_is_when_we_all_agree_to_keep/

Malicious PyPI Package "automslc" Enables 104K+ Unauthorized Deezer Music Downloads
https://thehackernews.com/2025/02/malicious-pypi-package-automslc-enables.html

SOC 3.0 - The Evolution of the SOC and How AI is Empowering Human Talent
https://thehackernews.com/2025/02/soc-30-evolution-of-soc-and-how-ai-is.html

New Linux Malware ‘Auto-Color’ Grants Hackers Full Remote Access to Compromised Systems
https://thehackernews.com/2025/02/new-linux-malware-auto-color-grants.html

CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian Notaries
https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html

Three Password Cracking Techniques and How to Defend Against Them
https://thehackernews.com/2025/02/three-password-cracking-techniques-and.html

Kubernetes Golden Tickets
https://www.reddit.com/r/netsec/comments/1iyn5m4/kubernetes_golden_tickets/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for February 21, 2025

Malicious Chrome extensions infected over 3.2 million users worldwide.
https://www.reddit.com/r/netsec/comments/1izcoti/16_malicious_chrome_extensions_infected_over_32/

Space Pirates Targets Russian IT Firms With New LuckyStrike Agent Malware
https://thehackernews.com/2025/02/space-pirates-targets-russian-it-firms.html

New TgToxic Banking Trojan Variant Evolves with Anti-Analysis Upgrades
https://thehackernews.com/2025/02/new-tgtoxic-banking-trojan-variant.html

89% of Enterprise GenAI Usage Is Invisible to Organizations Exposing Critical Security Risks, New Report Reveals
https://thehackernews.com/2025/02/89-of-enterprise-genai-usage-is.html

Modern Approach to Attributing Hacktivist Groups
https://research.checkpoint.com/2025/modern-approach-to-attributing-hacktivist-groups/

Research: Using Stylometry & Topic Modeling to Attribute State-Sponsored Hacktivist Groups
https://www.reddit.com/r/netsec/comments/1izgnfx/research_using_stylometry_topic_modeling_to/

Silver Fox APT Uses Winos 4.0 Malware in Cyber Attacks Against Taiwanese Organizations
https://thehackernews.com/2025/02/silver-fox-apt-uses-winos-40-malware-in.html

FBI attributes $1.5 billion Bybit hack to DPRK hackers.
https://thecyberwire.com/newsletters/daily-briefing/14/3816

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for February 2025

Microsoft Exposes LLMjacking Cybercriminals Behind Azure AI Abuse Scheme
https://thehackernews.com/2025/02/microsoft-exposes-llmjacking.html

Cisco Fixed Command Injection and DoS Flaws in Nexus Switches
https://securityaffairs.com/174753/security/cisco-fixed-command-injection-and-dos-flaws-in-nexus-switches.html

Bypass AMSI in 2025
https://www.reddit.com/r/netsec/comments/1j07zpp/bypass_amsi_in_2025/

Behavior Models, Temperature Tweaks, and Safety Battles
https://thecyberwire.com/podcasts/the-faik-files/24/notes

5,000 Phishing PDFs on 260 Domains Distribute Lumma Stealer via Fake CAPTCHAs
https://thehackernews.com/2025/02/5000-phishing-pdfs-on-260-domains.html

RDP: a Double-Edged Sword for IT Teams – Essential Yet Exploitable
https://thehackernews.com/2025/02/rdp-double-edged-sword-for-it-teams.html

Qilin Ransomware Gang Claims Responsibility for Attack Against Lee Enterprises
https://www.reddit.com/r/netsec/comments/1j07zpp/bypass_amsi_in_2025/

Amnesty Finds Cellebrite’s Zero-Day Used to Unlock Serbian Activist’s Android Phone
https://thehackernews.com/2025/02/amnesty-finds-cellebrites-zero-day.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Why a push for encryption backdoors is a global security risk
https://www.reddit.com/r/netsec/comments/1j38aru/why_a_push_for_encryption_backdoors_is_a_global/

We Deliberately Exposed AWS Keys on Developer Forums: Attackers Exploited One in 10 Hours
https://www.reddit.com/r/netsec/comments/1j38z5p/we_deliberately_exposed_aws_keys_on_developer/

We Deliberately Exposed AWS Keys on Developer Forums: Attackers Exploited One in 10 Hours
https://www.reddit.com/r/netsec/comments/1j38z5p/we_deliberately_exposed_aws_keys_on_developer/

DISCOUNTED HOTEL DEALS ANNOUNCED FOR HOPE_16
https://www.2600.com/content/discounted-hotel-deals-announced-hope16

Securing generative AI models on Azure AI Foundry
https://www.microsoft.com/en-us/security/blog/2025/03/04/securing-generative-ai-models-on-azure-ai-foundry/

Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
https://arxiv.org/abs/2503.00061

CRFU: Compressive Representation Forgetting Against Privacy Leakage on Machine Unlearning
https://arxiv.org/abs/2503.00062

ADAGE: Active Defenses Against GNN Extraction
https://arxiv.org/abs/2503.00065

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for March 5, 2025

Silk Typhoon targeting IT supply chain
https://www.microsoft.com/en-us/security/blog/2025/03/05/silk-typhoon-targeting-it-supply-chain/

EvilLoader: Yesterday was published PoC for unpatched Vulnerability affecting Telegram for Android
https://www.reddit.com/r/netsec/comments/1j3y1kl/evilloader_yesterday_was_published_poc_for/

EvilLoader: Yesterday was published PoC for unpatched Vulnerability affecting Telegram for Android
https://www.reddit.com/r/netsec/comments/1j3y1kl/evilloader_yesterday_was_published_poc_for/

UDora: A Unified Red Teaming Framework against LLM Agents by Dynamically Hijacking Their Own Reasoning
https://arxiv.org/abs/2503.01908

Datenschutzkonformer LLM-Einsatz: Eine Open-Source-Referenzarchitektur
https://arxiv.org/abs/2503.01915

A Lightweight and Secure Deep Learning Model for Privacy-Preserving Federated Learning in Intelligent Enterprises
https://arxiv.org/abs/2503.02017

Protecting DeFi Platforms against Non-Price Flash Loan Attacks
https://arxiv.org/abs/2503.01944

Advancing Obfuscation Strategies to Counter China's Great Firewall: A Technical and Policy Perspective
https://arxiv.org/abs/2503.02018

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for October 20, 2023

The Burn Notice, Part 2/5 | How We Uncovered a Critical Vulnerability in a Leading AI Agent Framework
https://www.reddit.com/r/netsec/comments/1j4x1tp/the_burn_notice_part_25_how_we_uncovered_a/

Sleeping Beauty Vulnerability: Bypassing CrowdStrike Falcon With One Simple Trick
https://www.reddit.com/r/netsec/comments/1j4s3as/sleeping_beauty_vulnerability_bypassing/

Malvertising campaign leads to info stealers hosted on GitHub
https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/

Command Injection - Compressive Guide & Payloads | VeryLazyTech
https://www.reddit.com/r/netsec/comments/1j4yi3f/command_injection_compressive_guide_payloads/

Zen and the Art of Microcode Hacking
https://www.reddit.com/r/netsec/comments/1j4r13c/zen_and_the_art_of_microcode_hacking/

Mind the Gap: Detecting Black-box Adversarial Attacks in the Making through Query Update Analysis
https://arxiv.org/abs/2503.02986

Adopt a PET! An Exploration of PETs, Policy, and Practicalities for Industry in Canada
https://arxiv.org/abs/2503.03027

Network Anomaly Detection for IoT Using Hyperdimensional Computing on NSL-KDD
https://arxiv.org/abs/2503.03031

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for October 23, 2023

Crxplorer.com is a great free tool for blue team to check overly permissive browser extensions
https://www.reddit.com/r/netsec/comments/1j5me7r/crxplorercom_is_a_great_free_tool_for_blue_team/

Uncovering .NET Malware Obfuscated by Encryption and Virtualization
https://www.reddit.com/r/netsec/comments/1j3y26r/uncovering_net_malware_obfuscated_by_encryption/

Automatically create an operation log of your shell! Supports Linux (Bash/Zsh) and Windows (PowerShell).
https://www.reddit.com/r/netsec/comments/1j40l9q/automatically_create_an_operation_log_of_your/

gpt4free - because I ain't got cash and I need synthetic LLM response data dammit.
https://www.reddit.com/r/netsec/comments/1j37kyi/gpt4free_because_i_aint_got_cash_and_i_need/

CRAFT: Characterizing and Root-Causing Fault Injection Threats at Pre-Silicon
https://arxiv.org/abs/2503.03877

Parser Knows Best: Testing DBMS with Coverage-Guided Grammar-Rule Traversal
https://arxiv.org/abs/2503.03893

A Quantum Good Authentication Protocol
https://arxiv.org/abs/2503.03884

Cryptographic Verifiability for Voter Registration Systems
https://arxiv.org/abs/2503.03974

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

DCRat backdoor returns
https://securelist.com/new-wave-of-attacks-with-dcrat-backdoor-distributed-by-maas/115850/

Old medpy Deserialization Vulnerability
https://www.reddit.com/r/netsec/comments/1j8rx3b/old_medpy_deserialization_vulnerability/

R1-Searcher: Incentivizing the Search Capability in LLMs via Reinforcement Learning
https://arxiv.org/abs/2503.05592

MeanCache: User-Centric Semantic Caching for LLM Web Services
https://arxiv.org/abs/2403.02694

Nature-Inspired Population-Based Evolution of Large Language Models
https://arxiv.org/abs/2503.01155

Language Models Enable Simple Systems for Generating Structured Views of Heterogeneous Data Lakes
https://arxiv.org/abs/2304.09433

Npm Run Hack:Me - A Supply Chain Attack Journey
https://www.reddit.com/r/netsec/comments/1j8ugic/npm_run_hackme_a_supply_chain_attack_journey/

Alleged Co-Founder of Garantex Arrested in India
https://krebsonsecurity.com/2025/03/alleged-co-founder-of-garantex-arrested-in-india/

New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/

Microsoft Patch Tuesday, March 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/11/microsoft-patch-tuesday-march-2025-security-update-review

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
https://www.reddit.com/r/netsec/comments/1ja6lxm/sign_in_as_anyone_bypassing_saml_sso/

6 Potential Security Concerns With the Eventual Rollout of 6G
https://www.tripwire.com/state-of-security/potential-security-concerns-eventual-rollout-6g

Head Mare and Twelve join forces to attack Russian entities
https://securelist.com/head-mare-twelve-collaboration/115887/

Medusa Ransomware: FBI and CISA Urge Organizations to Act Now to Mitigate Threat
https://www.tripwire.com/state-of-security/medusa-ransomware-fbi-and-cisa-urge-organizations-act-now-mitigate-threat

Cradle.sh Open Source Threat Intelligence Hub
https://www.reddit.com/r/netsec/comments/1jad2e8/cradlesh_open_source_threat_intelligence_hub/

Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware
https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/

How MSRC coordinates vulnerability research and disclosure while building community
https://www.microsoft.com/en-us/security/blog/2025/03/13/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

TP-Link Router Botnet
https://www.schneier.com/blog/archives/2025/03/tp-link-router-botnet.html

Upcoming Speaking Engagements
https://www.schneier.com/blog/archives/2025/03/upcoming-speaking-engagements-44.html

Friday Squid Blogging: SQUID Band
https://www.schneier.com/blog/archives/2025/03/friday-squid-blogging-squid-band.html

ClickFix: How to Infect Your PC in Three Easy Steps
https://krebsonsecurity.com/2025/03/clickfix-how-to-infect-your-pc-in-three-easy-steps/

Reversing the Computing Research Workforce Shortfall: Bolstering Domestic Student Pathways to PhDs
https://arxiv.org/abs/2503.09614

Prioritizing Computing Research to Empower and Protect Vulnerable Populations
https://arxiv.org/abs/2503.09612

Factorio Learning Environment
https://arxiv.org/abs/2503.09617

Empowering the Future Workforce: Prioritizing Education for the AI-Accelerated Job Market
https://arxiv.org/abs/2503.09613

Adaptive Deadlock Avoidance for Decentralized Multi-agent Systems via CBF-inspired Risk Measurement
https://arxiv.org/abs/2503.09621

Edge AI-Powered Real-Time Decision-Making for Autonomous Vehicles in Adverse Weather Conditions
https://arxiv.org/abs/2503.09638

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Data Breach Exposes Personal Information of 3 Million Users
https://example.com/data-breach

New Ransomware Strain Targets Healthcare Institutions
https://example.com/ransomware-healthcare

Cybersecurity Firm Discovers Major Vulnerability in Cloud Services
https://example.com/cloud-vulnerability

Increase in Phishing Attacks Exploiting Remote Work Trends
https://example.com/phishing-remote-work

Critical Security Flaw Found in Popular Web Browser
https://example.com/web-browser-flaw

Government Agency Issues New Cyber Threat Advisory
https://example.com/cyber-threat-advisory

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Squid: RISC-V emulator for high-performance fuzzing with AOT instead of JIT compilation
https://www.reddit.com/r/netsec/comments/1ja8yg7/squid_riscv_emulator_for_highperformance_fuzzing/

Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis
https://www.reddit.com/r/netsec/comments/1jd0bgp/android_kernel_adventures_insights_into/

BioSerenity-E1: a self-supervised EEG model for medical applications
https://arxiv.org/abs/2503.10362

Complementarity, Augmentation, or Substitutivity? The Impact of Generative Artificial Intelligence on the U.S. Federal Workforce
https://arxiv.org/abs/2503.09637

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

CVE-2025-24016: Unsafe Deserialization Vulnerability in Wazuh Leading to Remote Code Execution
https://www.reddit.com/r/netsec/comments/1jd9oed/cve202524016_unsafe_deserialization_vulnerability/

[Tool] TruffleShow: A Client-Side Web Viewer for TruffleHog Outputs
https://www.reddit.com/r/netsec/comments/1jdcen1/tool_truffleshow_a_clientside_web_viewer_for/

17th March – Threat Intelligence Report
https://research.checkpoint.com/2025/17th-march-threat-intelligence-report/

Improvements in Brute Force Attacks
https://www.schneier.com/blog/archives/2025/03/improvements-in-brute-force-attacks.html

StilachiRAT analysis: From system reconnaissance to cryptocurrency theft
https://www.microsoft.com/en-us/security/blog/2025/03/17/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman