Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for October 20, 2023

The Burn Notice, Part 2/5 | How We Uncovered a Critical Vulnerability in a Leading AI Agent Framework
https://www.reddit.com/r/netsec/comments/1j4x1tp/the_burn_notice_part_25_how_we_uncovered_a/

Sleeping Beauty Vulnerability: Bypassing CrowdStrike Falcon With One Simple Trick
https://www.reddit.com/r/netsec/comments/1j4s3as/sleeping_beauty_vulnerability_bypassing/

Malvertising campaign leads to info stealers hosted on GitHub
https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/

Command Injection - Compressive Guide & Payloads | VeryLazyTech
https://www.reddit.com/r/netsec/comments/1j4yi3f/command_injection_compressive_guide_payloads/

Zen and the Art of Microcode Hacking
https://www.reddit.com/r/netsec/comments/1j4r13c/zen_and_the_art_of_microcode_hacking/

Mind the Gap: Detecting Black-box Adversarial Attacks in the Making through Query Update Analysis
https://arxiv.org/abs/2503.02986

Adopt a PET! An Exploration of PETs, Policy, and Practicalities for Industry in Canada
https://arxiv.org/abs/2503.03027

Network Anomaly Detection for IoT Using Hyperdimensional Computing on NSL-KDD
https://arxiv.org/abs/2503.03031

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for October 23, 2023

Crxplorer.com is a great free tool for blue team to check overly permissive browser extensions
https://www.reddit.com/r/netsec/comments/1j5me7r/crxplorercom_is_a_great_free_tool_for_blue_team/

Uncovering .NET Malware Obfuscated by Encryption and Virtualization
https://www.reddit.com/r/netsec/comments/1j3y26r/uncovering_net_malware_obfuscated_by_encryption/

Automatically create an operation log of your shell! Supports Linux (Bash/Zsh) and Windows (PowerShell).
https://www.reddit.com/r/netsec/comments/1j40l9q/automatically_create_an_operation_log_of_your/

gpt4free - because I ain't got cash and I need synthetic LLM response data dammit.
https://www.reddit.com/r/netsec/comments/1j37kyi/gpt4free_because_i_aint_got_cash_and_i_need/

CRAFT: Characterizing and Root-Causing Fault Injection Threats at Pre-Silicon
https://arxiv.org/abs/2503.03877

Parser Knows Best: Testing DBMS with Coverage-Guided Grammar-Rule Traversal
https://arxiv.org/abs/2503.03893

A Quantum Good Authentication Protocol
https://arxiv.org/abs/2503.03884

Cryptographic Verifiability for Voter Registration Systems
https://arxiv.org/abs/2503.03974

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

DCRat backdoor returns
https://securelist.com/new-wave-of-attacks-with-dcrat-backdoor-distributed-by-maas/115850/

Old medpy Deserialization Vulnerability
https://www.reddit.com/r/netsec/comments/1j8rx3b/old_medpy_deserialization_vulnerability/

R1-Searcher: Incentivizing the Search Capability in LLMs via Reinforcement Learning
https://arxiv.org/abs/2503.05592

MeanCache: User-Centric Semantic Caching for LLM Web Services
https://arxiv.org/abs/2403.02694

Nature-Inspired Population-Based Evolution of Large Language Models
https://arxiv.org/abs/2503.01155

Language Models Enable Simple Systems for Generating Structured Views of Heterogeneous Data Lakes
https://arxiv.org/abs/2304.09433

Npm Run Hack:Me - A Supply Chain Attack Journey
https://www.reddit.com/r/netsec/comments/1j8ugic/npm_run_hackme_a_supply_chain_attack_journey/

Alleged Co-Founder of Garantex Arrested in India
https://krebsonsecurity.com/2025/03/alleged-co-founder-of-garantex-arrested-in-india/

New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/

Microsoft Patch Tuesday, March 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/11/microsoft-patch-tuesday-march-2025-security-update-review

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
https://www.reddit.com/r/netsec/comments/1ja6lxm/sign_in_as_anyone_bypassing_saml_sso/

6 Potential Security Concerns With the Eventual Rollout of 6G
https://www.tripwire.com/state-of-security/potential-security-concerns-eventual-rollout-6g

Head Mare and Twelve join forces to attack Russian entities
https://securelist.com/head-mare-twelve-collaboration/115887/

Medusa Ransomware: FBI and CISA Urge Organizations to Act Now to Mitigate Threat
https://www.tripwire.com/state-of-security/medusa-ransomware-fbi-and-cisa-urge-organizations-act-now-mitigate-threat

Cradle.sh Open Source Threat Intelligence Hub
https://www.reddit.com/r/netsec/comments/1jad2e8/cradlesh_open_source_threat_intelligence_hub/

Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware
https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/

How MSRC coordinates vulnerability research and disclosure while building community
https://www.microsoft.com/en-us/security/blog/2025/03/13/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

TP-Link Router Botnet
https://www.schneier.com/blog/archives/2025/03/tp-link-router-botnet.html

Upcoming Speaking Engagements
https://www.schneier.com/blog/archives/2025/03/upcoming-speaking-engagements-44.html

Friday Squid Blogging: SQUID Band
https://www.schneier.com/blog/archives/2025/03/friday-squid-blogging-squid-band.html

ClickFix: How to Infect Your PC in Three Easy Steps
https://krebsonsecurity.com/2025/03/clickfix-how-to-infect-your-pc-in-three-easy-steps/

Reversing the Computing Research Workforce Shortfall: Bolstering Domestic Student Pathways to PhDs
https://arxiv.org/abs/2503.09614

Prioritizing Computing Research to Empower and Protect Vulnerable Populations
https://arxiv.org/abs/2503.09612

Factorio Learning Environment
https://arxiv.org/abs/2503.09617

Empowering the Future Workforce: Prioritizing Education for the AI-Accelerated Job Market
https://arxiv.org/abs/2503.09613

Adaptive Deadlock Avoidance for Decentralized Multi-agent Systems via CBF-inspired Risk Measurement
https://arxiv.org/abs/2503.09621

Edge AI-Powered Real-Time Decision-Making for Autonomous Vehicles in Adverse Weather Conditions
https://arxiv.org/abs/2503.09638

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Data Breach Exposes Personal Information of 3 Million Users
https://example.com/data-breach

New Ransomware Strain Targets Healthcare Institutions
https://example.com/ransomware-healthcare

Cybersecurity Firm Discovers Major Vulnerability in Cloud Services
https://example.com/cloud-vulnerability

Increase in Phishing Attacks Exploiting Remote Work Trends
https://example.com/phishing-remote-work

Critical Security Flaw Found in Popular Web Browser
https://example.com/web-browser-flaw

Government Agency Issues New Cyber Threat Advisory
https://example.com/cyber-threat-advisory

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Squid: RISC-V emulator for high-performance fuzzing with AOT instead of JIT compilation
https://www.reddit.com/r/netsec/comments/1ja8yg7/squid_riscv_emulator_for_highperformance_fuzzing/

Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis
https://www.reddit.com/r/netsec/comments/1jd0bgp/android_kernel_adventures_insights_into/

BioSerenity-E1: a self-supervised EEG model for medical applications
https://arxiv.org/abs/2503.10362

Complementarity, Augmentation, or Substitutivity? The Impact of Generative Artificial Intelligence on the U.S. Federal Workforce
https://arxiv.org/abs/2503.09637

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

CVE-2025-24016: Unsafe Deserialization Vulnerability in Wazuh Leading to Remote Code Execution
https://www.reddit.com/r/netsec/comments/1jd9oed/cve202524016_unsafe_deserialization_vulnerability/

[Tool] TruffleShow: A Client-Side Web Viewer for TruffleHog Outputs
https://www.reddit.com/r/netsec/comments/1jdcen1/tool_truffleshow_a_clientside_web_viewer_for/

17th March – Threat Intelligence Report
https://research.checkpoint.com/2025/17th-march-threat-intelligence-report/

Improvements in Brute Force Attacks
https://www.schneier.com/blog/archives/2025/03/improvements-in-brute-force-attacks.html

StilachiRAT analysis: From system reconnaissance to cryptocurrency theft
https://www.microsoft.com/en-us/security/blog/2025/03/17/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Auditing language models for hidden objectives
https://arxiv.org/abs/2503.10965

Combinatorial Optimization for All: Using LLMs to Aid Non-Experts in Improving Optimization Algorithms
https://arxiv.org/abs/2503.10968

Is Security Human Factors Research Skewed Towards Western Ideas and Habits?
https://www.schneier.com/blog/archives/2025/03/is-security-human-factors-research-skewed-towards-western-ideas-and-habits.html

Learn how an out-of-bounds write vulnerability in the Linux kernel can be exploited to achieve an LPE (CVE-2025-0927)
https://www.reddit.com/r/netsec/comments/1je3w9o/learn_how_an_outofbounds_write_vulnerability_in/

What is Bundesamt für Sicherheit in der Informationstechnik (BSI)?
https://www.tripwire.com/state-of-security/what-is-bundesamt-fur-sicherheit-in-der-informationstechnik-bsi

Arbitrary File Write CVE-2024-0402 in GitLab (Exploit)
https://www.reddit.com/r/netsec/comments/1je4j6r/arbitrary_file_write_cve20240402_in_gitlab_exploit/

SAML roulette: the hacker always wins
https://www.reddit.com/r/netsec/comments/1je8f1h/saml_roulette_the_hacker_always_wins/

AI innovation requires AI security: Hear what’s new at Microsoft Secure
https://techcommunity.microsoft.com/blog/microsoft-security-blog/ai-innovation-requires-ai-security-hear-what%e2%80%99s-new-at-microsoft-secure/4394130

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Arcane stealer: We want all your data
https://securelist.com/arcane-stealer/115919/

The Intersection of Public Policy and Cybersecurity: Building a Framework for 2025 and Beyond
https://www.tripwire.com/state-of-security/intersection-public-policy-and-cybersecurity-building-framework-2025-and-beyond

How to Secure Your Information on AWS: 10 Best Practices
https://www.tripwire.com/state-of-security/secure-information-aws-10-best-practices

Linux supply chain attack journey: critical vulnerabilities on multiple distribution build & packaging systems
https://www.reddit.com/r/netsec/comments/1jetbh3/linux_supply_chain_attack_journey_critical/

Introducing WEBCAT: Web-based Code Assurance and Transparency
https://www.reddit.com/r/netsec/comments/1jf1zwq/introducing_webcat_webbased_code_assurance_and/

DOGE to Fired CISA Staff: Email Us Your Personal Data
https://krebsonsecurity.com/2025/03/doge-to-fired-cisa-staff-email-us-your-personal-data/

By Executive Order, We Are Banning Blacklists - Domain-Level RCE in Veeam Backup & Replication (CVE-2025-23120)
https://www.reddit.com/r/netsec/comments/1jff8u9/by_executive_order_we_are_banning_blacklists/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://www.reddit.com/r/netsec/comments/1jhvszk/after_a_decade_of_open_source_security/

VanHelsing, new RaaS in Town
https://research.checkpoint.com/2025/vanhelsing-new-raas-in-town/

Cosmos-Reason1: From Physical Common Sense To Embodied Reasoning
https://arxiv.org/abs/2503.15558

Towards Unified Latent Space for 3D Molecular Latent Diffusion Modeling
https://arxiv.org/abs/2503.15567

Privateers Reborn: Digital Letters of Marque
https://www.reddit.com/r/netsec/comments/1jibf18/privateers_reborn_digital_letters_of_marque/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected

More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html

24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/

Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/

Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/

Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman