Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

DCRat backdoor returns
https://securelist.com/new-wave-of-attacks-with-dcrat-backdoor-distributed-by-maas/115850/

Old medpy Deserialization Vulnerability
https://www.reddit.com/r/netsec/comments/1j8rx3b/old_medpy_deserialization_vulnerability/

R1-Searcher: Incentivizing the Search Capability in LLMs via Reinforcement Learning
https://arxiv.org/abs/2503.05592

MeanCache: User-Centric Semantic Caching for LLM Web Services
https://arxiv.org/abs/2403.02694

Nature-Inspired Population-Based Evolution of Large Language Models
https://arxiv.org/abs/2503.01155

Language Models Enable Simple Systems for Generating Structured Views of Heterogeneous Data Lakes
https://arxiv.org/abs/2304.09433

Npm Run Hack:Me - A Supply Chain Attack Journey
https://www.reddit.com/r/netsec/comments/1j8ugic/npm_run_hackme_a_supply_chain_attack_journey/

Alleged Co-Founder of Garantex Arrested in India
https://krebsonsecurity.com/2025/03/alleged-co-founder-of-garantex-arrested-in-india/

New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects
https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/

Microsoft Patch Tuesday, March 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/11/microsoft-patch-tuesday-march-2025-security-update-review

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
https://www.reddit.com/r/netsec/comments/1ja6lxm/sign_in_as_anyone_bypassing_saml_sso/

6 Potential Security Concerns With the Eventual Rollout of 6G
https://www.tripwire.com/state-of-security/potential-security-concerns-eventual-rollout-6g

Head Mare and Twelve join forces to attack Russian entities
https://securelist.com/head-mare-twelve-collaboration/115887/

Medusa Ransomware: FBI and CISA Urge Organizations to Act Now to Mitigate Threat
https://www.tripwire.com/state-of-security/medusa-ransomware-fbi-and-cisa-urge-organizations-act-now-mitigate-threat

Cradle.sh Open Source Threat Intelligence Hub
https://www.reddit.com/r/netsec/comments/1jad2e8/cradlesh_open_source_threat_intelligence_hub/

Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware
https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/

How MSRC coordinates vulnerability research and disclosure while building community
https://www.microsoft.com/en-us/security/blog/2025/03/13/how-msrc-coordinates-vulnerability-research-and-disclosure-while-building-community/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

TP-Link Router Botnet
https://www.schneier.com/blog/archives/2025/03/tp-link-router-botnet.html

Upcoming Speaking Engagements
https://www.schneier.com/blog/archives/2025/03/upcoming-speaking-engagements-44.html

Friday Squid Blogging: SQUID Band
https://www.schneier.com/blog/archives/2025/03/friday-squid-blogging-squid-band.html

ClickFix: How to Infect Your PC in Three Easy Steps
https://krebsonsecurity.com/2025/03/clickfix-how-to-infect-your-pc-in-three-easy-steps/

Reversing the Computing Research Workforce Shortfall: Bolstering Domestic Student Pathways to PhDs
https://arxiv.org/abs/2503.09614

Prioritizing Computing Research to Empower and Protect Vulnerable Populations
https://arxiv.org/abs/2503.09612

Factorio Learning Environment
https://arxiv.org/abs/2503.09617

Empowering the Future Workforce: Prioritizing Education for the AI-Accelerated Job Market
https://arxiv.org/abs/2503.09613

Adaptive Deadlock Avoidance for Decentralized Multi-agent Systems via CBF-inspired Risk Measurement
https://arxiv.org/abs/2503.09621

Edge AI-Powered Real-Time Decision-Making for Autonomous Vehicles in Adverse Weather Conditions
https://arxiv.org/abs/2503.09638

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Data Breach Exposes Personal Information of 3 Million Users
https://example.com/data-breach

New Ransomware Strain Targets Healthcare Institutions
https://example.com/ransomware-healthcare

Cybersecurity Firm Discovers Major Vulnerability in Cloud Services
https://example.com/cloud-vulnerability

Increase in Phishing Attacks Exploiting Remote Work Trends
https://example.com/phishing-remote-work

Critical Security Flaw Found in Popular Web Browser
https://example.com/web-browser-flaw

Government Agency Issues New Cyber Threat Advisory
https://example.com/cyber-threat-advisory

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Squid: RISC-V emulator for high-performance fuzzing with AOT instead of JIT compilation
https://www.reddit.com/r/netsec/comments/1ja8yg7/squid_riscv_emulator_for_highperformance_fuzzing/

Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis
https://www.reddit.com/r/netsec/comments/1jd0bgp/android_kernel_adventures_insights_into/

BioSerenity-E1: a self-supervised EEG model for medical applications
https://arxiv.org/abs/2503.10362

Complementarity, Augmentation, or Substitutivity? The Impact of Generative Artificial Intelligence on the U.S. Federal Workforce
https://arxiv.org/abs/2503.09637

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Jaguar Land Rover Breached by HELLCAT Ransomware Group Using Its Infostealer Playbook—Then a Second Hacker Strikes
https://www.reddit.com/r/netsec/comments/1jd7t1f/jaguar_land_rover_breached_by_hellcat_ransomware/

History of NULL Pointer Dereferences on macOS
https://www.reddit.com/r/netsec/comments/1jd7e2j/history_of_null_pointer_dereferences_on_macos/

CVE-2025-24016: Unsafe Deserialization Vulnerability in Wazuh Leading to Remote Code Execution
https://www.reddit.com/r/netsec/comments/1jd9oed/cve202524016_unsafe_deserialization_vulnerability/

[Tool] TruffleShow: A Client-Side Web Viewer for TruffleHog Outputs
https://www.reddit.com/r/netsec/comments/1jdcen1/tool_truffleshow_a_clientside_web_viewer_for/

17th March – Threat Intelligence Report
https://research.checkpoint.com/2025/17th-march-threat-intelligence-report/

Improvements in Brute Force Attacks
https://www.schneier.com/blog/archives/2025/03/improvements-in-brute-force-attacks.html

StilachiRAT analysis: From system reconnaissance to cryptocurrency theft
https://www.microsoft.com/en-us/security/blog/2025/03/17/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Auditing language models for hidden objectives
https://arxiv.org/abs/2503.10965

Combinatorial Optimization for All: Using LLMs to Aid Non-Experts in Improving Optimization Algorithms
https://arxiv.org/abs/2503.10968

Is Security Human Factors Research Skewed Towards Western Ideas and Habits?
https://www.schneier.com/blog/archives/2025/03/is-security-human-factors-research-skewed-towards-western-ideas-and-habits.html

Learn how an out-of-bounds write vulnerability in the Linux kernel can be exploited to achieve an LPE (CVE-2025-0927)
https://www.reddit.com/r/netsec/comments/1je3w9o/learn_how_an_outofbounds_write_vulnerability_in/

What is Bundesamt für Sicherheit in der Informationstechnik (BSI)?
https://www.tripwire.com/state-of-security/what-is-bundesamt-fur-sicherheit-in-der-informationstechnik-bsi

Arbitrary File Write CVE-2024-0402 in GitLab (Exploit)
https://www.reddit.com/r/netsec/comments/1je4j6r/arbitrary_file_write_cve20240402_in_gitlab_exploit/

SAML roulette: the hacker always wins
https://www.reddit.com/r/netsec/comments/1je8f1h/saml_roulette_the_hacker_always_wins/

AI innovation requires AI security: Hear what’s new at Microsoft Secure
https://techcommunity.microsoft.com/blog/microsoft-security-blog/ai-innovation-requires-ai-security-hear-what%e2%80%99s-new-at-microsoft-secure/4394130

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Arcane stealer: We want all your data
https://securelist.com/arcane-stealer/115919/

The Intersection of Public Policy and Cybersecurity: Building a Framework for 2025 and Beyond
https://www.tripwire.com/state-of-security/intersection-public-policy-and-cybersecurity-building-framework-2025-and-beyond

How to Secure Your Information on AWS: 10 Best Practices
https://www.tripwire.com/state-of-security/secure-information-aws-10-best-practices

Linux supply chain attack journey: critical vulnerabilities on multiple distribution build & packaging systems
https://www.reddit.com/r/netsec/comments/1jetbh3/linux_supply_chain_attack_journey_critical/

Introducing WEBCAT: Web-based Code Assurance and Transparency
https://www.reddit.com/r/netsec/comments/1jf1zwq/introducing_webcat_webbased_code_assurance_and/

DOGE to Fired CISA Staff: Email Us Your Personal Data
https://krebsonsecurity.com/2025/03/doge-to-fired-cisa-staff-email-us-your-personal-data/

By Executive Order, We Are Banning Blacklists - Domain-Level RCE in Veeam Backup & Replication (CVE-2025-23120)
https://www.reddit.com/r/netsec/comments/1jff8u9/by_executive_order_we_are_banning_blacklists/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://www.reddit.com/r/netsec/comments/1jhvszk/after_a_decade_of_open_source_security/

VanHelsing, new RaaS in Town
https://research.checkpoint.com/2025/vanhelsing-new-raas-in-town/

Cosmos-Reason1: From Physical Common Sense To Embodied Reasoning
https://arxiv.org/abs/2503.15558

Towards Unified Latent Space for 3D Molecular Latent Diffusion Modeling
https://arxiv.org/abs/2503.15567

Privateers Reborn: Digital Letters of Marque
https://www.reddit.com/r/netsec/comments/1jibf18/privateers_reborn_digital_letters_of_marque/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected

More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html

24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/

Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/

Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/

Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
https://www.reddit.com/r/netsec/comments/1jjfq3d/smugglo_bypass_email_attachment_restrictions_with/

The Firewall Project (Application Security with Enterprise features) is now open-source
https://www.reddit.com/r/netsec/comments/1jismhn/the_firewall_project_application_security_with/

CLI tool to sandbox Linux processes using Landlock no containers, no root
https://www.reddit.com/r/netsec/comments/1jh9y1q/cli_tool_to_sandbox_linux_processes_using/

Kereva scanner: an open-source LLM security (and performance) scanner
https://www.reddit.com/r/netsec/comments/1jgtr4e/kereva_scanner_an_opensource_llm_security_and/

A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html

Blasting Past Webp - Google Project Zero
https://www.reddit.com/r/netsec/comments/1jl2t85/blasting_past_webp_google_project_zero/

Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
https://www.reddit.com/r/netsec/comments/1jl3ig6/blacklock_ransomware_a_late_holiday_gift_with/

US Department of Labor’s journey to Zero Trust security with Microsoft Entra ID
https://www.microsoft.com/en-us/security/blog/2025/03/27/us-department-of-labors-journey-to-zero-trust-security-with-microsoft-entra-id/

When Getting Phished Puts You in Mortal Danger
https://krebsonsecurity.com/2025/03/when-getting-phished-puts-you-in-mortal-danger/

Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html

Feberis Pro: As one of the first, I had an opportunity to test new 4-in-1 Expansion Board for Flipper Zero
https://www.reddit.com/r/netsec/comments/1jo0eww/feberis_pro_as_one_of_first_i_had_and_an/

The Signal Chat Leak and the NSA
https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html

Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
https://portswigger.net/blog/welcome-to-the-next-generation-of-burp-suite-elevate-your-testing-with-burp-ai

Anatomy of an LLM RCE
https://www.reddit.com/r/netsec/comments/1jo1w9n/anatomy_of_an_llm_rce/

Oracle attempt to hide serious security incident from customers in Oracle SaaS service
https://www.reddit.com/r/netsec/comments/1jo2s5g/oracle_attempt_to_hide_serious_security_incident/

New innovations in Microsoft Purview for protected, AI-ready data
https://www.microsoft.com/en-us/security/blog/2025/03/31/new-innovations-in-microsoft-purview-for-protected-ai-ready-data/

Analyzing open-source bootloaders: Finding vulnerabilities faster with AI
https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/

Epic Fails and Heist Tales: A Red Teamer’s Journey to Deadwood
https://bishopfox.com/blog/epic-fails-heist-tales-red-teamers

🛡️ DoD Sentinel Skills Challenge – compete, win, and gain access to job opportunities!
https://www.reddit.com/r/netsec/comments/1jo6yht/dod_sentinel_skills_challenge_compete_win_and/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman