Top Security News for Today
Threat landscape for industrial automation systems in Q4 2024
https://securelist.com/ics-cert-q4-2024-report/115944/
NCSC Releases Post-Quantum Cryptography Timeline
https://www.schneier.com/blog/archives/2025/03/ncsc-releases-post-quantum-cryptography-timeline.html
What not to do with on prem virtualization
https://www.reddit.com/r/netsec/comments/1jgfvkp/what_not_to_do_with_on_prem_virtualization/
There's a big problem with browser bookmark security.
https://www.reddit.com/r/netsec/comments/1jgij4f/theres_a_big_problem_with_browser_bookmark/
My Writings Are in the LibGen AI Training Corpus
https://www.schneier.com/blog/archives/2025/03/my-writings-are-in-the-libgen-ai-training-corpus.html
Arrests in Tap-to-Pay Scheme Powered by Phishing
https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/
Palo Alto Cortex XDR bypass (CVE-2024-8690)
https://www.reddit.com/r/netsec/comments/1jgra20/palo_alto_cortex_xdr_bypass_cve20248690/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Threat landscape for industrial automation systems in Q4 2024
https://securelist.com/ics-cert-q4-2024-report/115944/
NCSC Releases Post-Quantum Cryptography Timeline
https://www.schneier.com/blog/archives/2025/03/ncsc-releases-post-quantum-cryptography-timeline.html
What not to do with on prem virtualization
https://www.reddit.com/r/netsec/comments/1jgfvkp/what_not_to_do_with_on_prem_virtualization/
There's a big problem with browser bookmark security.
https://www.reddit.com/r/netsec/comments/1jgij4f/theres_a_big_problem_with_browser_bookmark/
My Writings Are in the LibGen AI Training Corpus
https://www.schneier.com/blog/archives/2025/03/my-writings-are-in-the-libgen-ai-training-corpus.html
Arrests in Tap-to-Pay Scheme Powered by Phishing
https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/
Palo Alto Cortex XDR bypass (CVE-2024-8690)
https://www.reddit.com/r/netsec/comments/1jgra20/palo_alto_cortex_xdr_bypass_cve20248690/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Securelist
Kaspersky industrial threat report for Q4 2024
The report contains statistics on malware, initial infection vectors and other threats to industrial automation systems in Q4 2024.
Top Security News for Today
Generalization Guarantees for Representation Learning via Data-Dependent Gaussian Mixture Priors
https://arxiv.org/abs/2502.15540
TraceFind - Email OSINT Tool - Information Gathering
https://www.reddit.com/r/netsec/comments/1jhdeb7/tracefind_email_osint_tool_information_gathering/
Secrets.tools - security tool for scanning login pages for secrets, emails, ips and urls
https://www.reddit.com/r/netsec/comments/1jhhbvs/secretstools_security_tool_for_scanning_login/
Profile Image Intel - OSINT Tool for checking when profile pictures were last changed
https://www.reddit.com/r/netsec/comments/1jhhak2/profile_image_intel_osint_tool_for_checking_when/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Generalization Guarantees for Representation Learning via Data-Dependent Gaussian Mixture Priors
https://arxiv.org/abs/2502.15540
TraceFind - Email OSINT Tool - Information Gathering
https://www.reddit.com/r/netsec/comments/1jhdeb7/tracefind_email_osint_tool_information_gathering/
Secrets.tools - security tool for scanning login pages for secrets, emails, ips and urls
https://www.reddit.com/r/netsec/comments/1jhhbvs/secretstools_security_tool_for_scanning_login/
Profile Image Intel - OSINT Tool for checking when profile pictures were last changed
https://www.reddit.com/r/netsec/comments/1jhhak2/profile_image_intel_osint_tool_for_checking_when/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
arXiv.org
Generalization Guarantees for Representation Learning via...
We establish in-expectation and tail bounds on the generalization error of representation learning type algorithms. The bounds are in terms of the relative entropy between the distribution of the...
Top Security News for Today
After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://www.reddit.com/r/netsec/comments/1jhvszk/after_a_decade_of_open_source_security/
VanHelsing, new RaaS in Town
https://research.checkpoint.com/2025/vanhelsing-new-raas-in-town/
Cosmos-Reason1: From Physical Common Sense To Embodied Reasoning
https://arxiv.org/abs/2503.15558
Towards Unified Latent Space for 3D Molecular Latent Diffusion Modeling
https://arxiv.org/abs/2503.15567
Privateers Reborn: Digital Letters of Marque
https://www.reddit.com/r/netsec/comments/1jibf18/privateers_reborn_digital_letters_of_marque/
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://www.reddit.com/r/netsec/comments/1jhvszk/after_a_decade_of_open_source_security/
VanHelsing, new RaaS in Town
https://research.checkpoint.com/2025/vanhelsing-new-raas-in-town/
Cosmos-Reason1: From Physical Common Sense To Embodied Reasoning
https://arxiv.org/abs/2503.15558
Towards Unified Latent Space for 3D Molecular Latent Diffusion Modeling
https://arxiv.org/abs/2503.15567
Privateers Reborn: Digital Letters of Marque
https://www.reddit.com/r/netsec/comments/1jibf18/privateers_reborn_digital_letters_of_marque/
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: After a decade of open source security educational tools (SecGen), we've launched a hosted…
Explore this post and more from the netsec community
Top Security News for Today
Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/
Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected
More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html
24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/
Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/
Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/
Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/
Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected
More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html
24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/
Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/
Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/
Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Bypassing Detections with Command-Line Obfuscation
Posted by Wietze- - 0 votes and 1 comment
Top Security News for Today
An Introduction to Data Masking in Privacy Engineering
https://www.tripwire.com/state-of-security/introduction-data-masking-privacy-engineering
MAS Compliance 101: Key Regulations for Financial Institutions in Singapore
https://www.tripwire.com/state-of-security/mas-compliance-key-regulations-financial-institutions-singapore
Frida 16.7.0 is out w/ brand new APIs for observing the lifecycles of threads and modules
https://www.reddit.com/r/netsec/comments/1jjg9kq/frida_1670_is_out_w_brand_new_apis_for_observing/
Report on Paragon Spyware
https://www.schneier.com/blog/archives/2025/03/report-on-paragon-spyware.html
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html
CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith
https://www.reddit.com/r/netsec/comments/1jjnjam/cve202455963_unauthenticated_rce_in/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
An Introduction to Data Masking in Privacy Engineering
https://www.tripwire.com/state-of-security/introduction-data-masking-privacy-engineering
MAS Compliance 101: Key Regulations for Financial Institutions in Singapore
https://www.tripwire.com/state-of-security/mas-compliance-key-regulations-financial-institutions-singapore
Frida 16.7.0 is out w/ brand new APIs for observing the lifecycles of threads and modules
https://www.reddit.com/r/netsec/comments/1jjg9kq/frida_1670_is_out_w_brand_new_apis_for_observing/
Report on Paragon Spyware
https://www.schneier.com/blog/archives/2025/03/report-on-paragon-spyware.html
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html
CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith
https://www.reddit.com/r/netsec/comments/1jjnjam/cve202455963_unauthenticated_rce_in/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Tripwire
An Introduction to Data Masking in Privacy Engineering
Data masking protects sensitive information by replacing it with realistic but fictitious data, ensuring compliance and reducing exposure risks.
Top Security News for Today
Implementing Privileged Access Workstations: A Step-by-Step Guide
https://www.tripwire.com/state-of-security/implementing-privileged-access-workstations-step-step-guide
How to Build a Mature Vulnerability Management Program
https://www.tripwire.com/state-of-security/build-mature-vulnerability-management-program
AI Data Poisoning
https://www.schneier.com/blog/archives/2025/03/ai-data-poisoning.html
Over 150K websites hit by full-page hijack linking to Chinese gambling sites
https://www.reddit.com/r/netsec/comments/1jkf34o/over_150k_websites_hit_by_fullpage_hijack_linking/
Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution
https://www.reddit.com/r/netsec/comments/1jkg6po/llamas_paradox_delving_deep_into_llamacpp_and/
CodeQLEAKED – Public Secrets Exposure Leads to Potential Supply Chain Attack on GitHub CodeQL
https://www.reddit.com/r/netsec/comments/1jkfjub/codeqleaked_public_secrets_exposure_leads_to/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Implementing Privileged Access Workstations: A Step-by-Step Guide
https://www.tripwire.com/state-of-security/implementing-privileged-access-workstations-step-step-guide
How to Build a Mature Vulnerability Management Program
https://www.tripwire.com/state-of-security/build-mature-vulnerability-management-program
AI Data Poisoning
https://www.schneier.com/blog/archives/2025/03/ai-data-poisoning.html
Over 150K websites hit by full-page hijack linking to Chinese gambling sites
https://www.reddit.com/r/netsec/comments/1jkf34o/over_150k_websites_hit_by_fullpage_hijack_linking/
Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution
https://www.reddit.com/r/netsec/comments/1jkg6po/llamas_paradox_delving_deep_into_llamacpp_and/
CodeQLEAKED – Public Secrets Exposure Leads to Potential Supply Chain Attack on GitHub CodeQL
https://www.reddit.com/r/netsec/comments/1jkfjub/codeqleaked_public_secrets_exposure_leads_to/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Tripwire
Implementing Privileged Access Workstations: A Step-by-Step Guide
Enhance security with Privileged Access Workstations! Discover how PAWs protect privileged accounts from cyber threats.
Top Security News for Today
smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
https://www.reddit.com/r/netsec/comments/1jjfq3d/smugglo_bypass_email_attachment_restrictions_with/
The Firewall Project (Application Security with Enterprise features) is now open-source
https://www.reddit.com/r/netsec/comments/1jismhn/the_firewall_project_application_security_with/
CLI tool to sandbox Linux processes using Landlock no containers, no root
https://www.reddit.com/r/netsec/comments/1jh9y1q/cli_tool_to_sandbox_linux_processes_using/
Kereva scanner: an open-source LLM security (and performance) scanner
https://www.reddit.com/r/netsec/comments/1jgtr4e/kereva_scanner_an_opensource_llm_security_and/
A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html
Blasting Past Webp - Google Project Zero
https://www.reddit.com/r/netsec/comments/1jl2t85/blasting_past_webp_google_project_zero/
Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
https://www.reddit.com/r/netsec/comments/1jl3ig6/blacklock_ransomware_a_late_holiday_gift_with/
US Department of Labor’s journey to Zero Trust security with Microsoft Entra ID
https://www.microsoft.com/en-us/security/blog/2025/03/27/us-department-of-labors-journey-to-zero-trust-security-with-microsoft-entra-id/
When Getting Phished Puts You in Mortal Danger
https://krebsonsecurity.com/2025/03/when-getting-phished-puts-you-in-mortal-danger/
Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
https://www.reddit.com/r/netsec/comments/1jjfq3d/smugglo_bypass_email_attachment_restrictions_with/
The Firewall Project (Application Security with Enterprise features) is now open-source
https://www.reddit.com/r/netsec/comments/1jismhn/the_firewall_project_application_security_with/
CLI tool to sandbox Linux processes using Landlock no containers, no root
https://www.reddit.com/r/netsec/comments/1jh9y1q/cli_tool_to_sandbox_linux_processes_using/
Kereva scanner: an open-source LLM security (and performance) scanner
https://www.reddit.com/r/netsec/comments/1jgtr4e/kereva_scanner_an_opensource_llm_security_and/
A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html
Blasting Past Webp - Google Project Zero
https://www.reddit.com/r/netsec/comments/1jl2t85/blasting_past_webp_google_project_zero/
Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
https://www.reddit.com/r/netsec/comments/1jl3ig6/blacklock_ransomware_a_late_holiday_gift_with/
US Department of Labor’s journey to Zero Trust security with Microsoft Entra ID
https://www.microsoft.com/en-us/security/blog/2025/03/27/us-department-of-labors-journey-to-zero-trust-security-with-microsoft-entra-id/
When Getting Phished Puts You in Mortal Danger
https://krebsonsecurity.com/2025/03/when-getting-phished-puts-you-in-mortal-danger/
Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
Explore this post and more from the netsec community
Top Security News for Today
Detect NetxJS CVE-2025-29927 efficiently and at scale
https://www.reddit.com/r/netsec/comments/1jlqota/detect_netxjs_cve202529927_efficiently_and_at/
AIs as Trusted Third Parties
https://www.schneier.com/blog/archives/2025/03/ais-as-trusted-third-parties.html
VanHelsing Ransomware: What You Need To Know
https://www.tripwire.com/state-of-security/vanhelsing-ransomware-what-you-need-know
A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
https://www.trendmicro.com/en_us/research/25/c/deep-dive-into-water-gamayun.html
Friday Squid Blogging: Squid Werewolf Hacking Group
https://www.schneier.com/blog/archives/2025/03/friday-squid-blogging-squid-werewolf-hacking-group.html
Payload-Aware Intrusion Detection with CMAE and Large Language Models
https://arxiv.org/abs/2503.20790
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Detect NetxJS CVE-2025-29927 efficiently and at scale
https://www.reddit.com/r/netsec/comments/1jlqota/detect_netxjs_cve202529927_efficiently_and_at/
AIs as Trusted Third Parties
https://www.schneier.com/blog/archives/2025/03/ais-as-trusted-third-parties.html
VanHelsing Ransomware: What You Need To Know
https://www.tripwire.com/state-of-security/vanhelsing-ransomware-what-you-need-know
A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
https://www.trendmicro.com/en_us/research/25/c/deep-dive-into-water-gamayun.html
Friday Squid Blogging: Squid Werewolf Hacking Group
https://www.schneier.com/blog/archives/2025/03/friday-squid-blogging-squid-werewolf-hacking-group.html
Payload-Aware Intrusion Detection with CMAE and Large Language Models
https://arxiv.org/abs/2503.20790
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Detect NetxJS CVE-2025-29927 efficiently and at scale
Explore this post and more from the netsec community
Top Security News for Today
Can someone please finish the work started on a UDF File System Driver?
https://www.reddit.com/r/lowlevel/comments/1jmrutp/can_someone_please_finish_the_work_started_on_a_udf_file_system_driver/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Can someone please finish the work started on a UDF File System Driver?
https://www.reddit.com/r/lowlevel/comments/1jmrutp/can_someone_please_finish_the_work_started_on_a_udf_file_system_driver/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the lowlevel community on Reddit: Can someone please finish the work started on a UDF File System Driver?
Explore this post and more from the lowlevel community
Top Security News for Today
How Each Pillar of the 1st Amendment is Under Attack
https://krebsonsecurity.com/2025/03/how-each-pillar-of-the-1st-amendment-is-under-attack/
Cross-modal Information Flow in Multimodal Large Language Models
https://arxiv.org/abs/2411.18620
Federal Desktop Core Configuration (FDCC/USGCB) Compliance
https://www.tripwire.com/state-of-security/federal-desktop-core-configuration-fdccusgcb-compliance
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
How Each Pillar of the 1st Amendment is Under Attack
https://krebsonsecurity.com/2025/03/how-each-pillar-of-the-1st-amendment-is-under-attack/
Cross-modal Information Flow in Multimodal Large Language Models
https://arxiv.org/abs/2411.18620
Federal Desktop Core Configuration (FDCC/USGCB) Compliance
https://www.tripwire.com/state-of-security/federal-desktop-core-configuration-fdccusgcb-compliance
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Krebs on Security
How Each Pillar of the 1st Amendment is Under Attack
In an address to Congress this month, President Trump claimed he had "brought free speech back to America." But barely two months into his second term, the president has waged an unprecedented attack on the First Amendment rights of journalists,…
Top Security News for Today
The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html
Feberis Pro: As one of the first, I had an opportunity to test new 4-in-1 Expansion Board for Flipper Zero
https://www.reddit.com/r/netsec/comments/1jo0eww/feberis_pro_as_one_of_first_i_had_and_an/
The Signal Chat Leak and the NSA
https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html
Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
https://portswigger.net/blog/welcome-to-the-next-generation-of-burp-suite-elevate-your-testing-with-burp-ai
Anatomy of an LLM RCE
https://www.reddit.com/r/netsec/comments/1jo1w9n/anatomy_of_an_llm_rce/
Oracle attempt to hide serious security incident from customers in Oracle SaaS service
https://www.reddit.com/r/netsec/comments/1jo2s5g/oracle_attempt_to_hide_serious_security_incident/
New innovations in Microsoft Purview for protected, AI-ready data
https://www.microsoft.com/en-us/security/blog/2025/03/31/new-innovations-in-microsoft-purview-for-protected-ai-ready-data/
Analyzing open-source bootloaders: Finding vulnerabilities faster with AI
https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/
Epic Fails and Heist Tales: A Red Teamer’s Journey to Deadwood
https://bishopfox.com/blog/epic-fails-heist-tales-red-teamers
🛡️ DoD Sentinel Skills Challenge – compete, win, and gain access to job opportunities!
https://www.reddit.com/r/netsec/comments/1jo6yht/dod_sentinel_skills_challenge_compete_win_and/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html
Feberis Pro: As one of the first, I had an opportunity to test new 4-in-1 Expansion Board for Flipper Zero
https://www.reddit.com/r/netsec/comments/1jo0eww/feberis_pro_as_one_of_first_i_had_and_an/
The Signal Chat Leak and the NSA
https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html
Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
https://portswigger.net/blog/welcome-to-the-next-generation-of-burp-suite-elevate-your-testing-with-burp-ai
Anatomy of an LLM RCE
https://www.reddit.com/r/netsec/comments/1jo1w9n/anatomy_of_an_llm_rce/
Oracle attempt to hide serious security incident from customers in Oracle SaaS service
https://www.reddit.com/r/netsec/comments/1jo2s5g/oracle_attempt_to_hide_serious_security_incident/
New innovations in Microsoft Purview for protected, AI-ready data
https://www.microsoft.com/en-us/security/blog/2025/03/31/new-innovations-in-microsoft-purview-for-protected-ai-ready-data/
Analyzing open-source bootloaders: Finding vulnerabilities faster with AI
https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/
Epic Fails and Heist Tales: A Red Teamer’s Journey to Deadwood
https://bishopfox.com/blog/epic-fails-heist-tales-red-teamers
🛡️ DoD Sentinel Skills Challenge – compete, win, and gain access to job opportunities!
https://www.reddit.com/r/netsec/comments/1jo6yht/dod_sentinel_skills_challenge_compete_win_and/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Trend Micro
The Espionage Toolkit of Earth Alux A Closer Look at its Advanced Techniques
The cyberespionage techniques of Earth Alux, a China-linked APT group, are putting critical industries at risk. The attacks, aimed at the APAC and Latin American regions, leverage powerful tools and techniques to remain hidden while stealing sensitive data.
Top Security News for Today
Japan Passes Active Cyber Defense Bill
https://www.tripwire.com/state-of-security/japan-passes-active-cyber-defense-bill
Top Cybersecurity Considerations When Moving Commercial Premises
https://www.tripwire.com/state-of-security/top-cybersecurity-considerations-when-moving-commercial-premises
Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR
https://www.reddit.com/r/netsec/comments/1joqvup/reforging_sliver_how_simple_code_edits_can/
Harnessing the Power of Named Pipes
https://www.reddit.com/r/netsec/comments/1jor8nr/harnessing_the_power_of_named_pipes/
CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog
https://www.reddit.com/r/netsec/comments/1jopz93/crushftp_authentication_bypass_cve20252825/
Cell Phone OPSEC for Border Crossings
https://www.schneier.com/blog/archives/2025/04/cell-phone-opsec-for-border-crossings.html
XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1jos2z2/xss_to_rce_by_abusing_custom_file_handlers/
When Parameterization Fails: SQL Injection in Nim's db_postgres Module Using Parameterized Queries
https://www.reddit.com/r/netsec/comments/1joth41/when_parameterization_fails_sql_injection_in_nims/
Transforming Public Sector Security Operations in the AI Era
https://www.microsoft.com/en-us/security/blog/2025/04/01/transforming-public-sector-security-operations-in-the-ai-era/
Improved Detection Signature for the K8s IngressNightmare Vulnerability
https://www.reddit.com/r/netsec/comments/1jp9cmt/improved_detection_signature_for_the_k8s/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Japan Passes Active Cyber Defense Bill
https://www.tripwire.com/state-of-security/japan-passes-active-cyber-defense-bill
Top Cybersecurity Considerations When Moving Commercial Premises
https://www.tripwire.com/state-of-security/top-cybersecurity-considerations-when-moving-commercial-premises
Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR
https://www.reddit.com/r/netsec/comments/1joqvup/reforging_sliver_how_simple_code_edits_can/
Harnessing the Power of Named Pipes
https://www.reddit.com/r/netsec/comments/1jor8nr/harnessing_the_power_of_named_pipes/
CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog
https://www.reddit.com/r/netsec/comments/1jopz93/crushftp_authentication_bypass_cve20252825/
Cell Phone OPSEC for Border Crossings
https://www.schneier.com/blog/archives/2025/04/cell-phone-opsec-for-border-crossings.html
XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1jos2z2/xss_to_rce_by_abusing_custom_file_handlers/
When Parameterization Fails: SQL Injection in Nim's db_postgres Module Using Parameterized Queries
https://www.reddit.com/r/netsec/comments/1joth41/when_parameterization_fails_sql_injection_in_nims/
Transforming Public Sector Security Operations in the AI Era
https://www.microsoft.com/en-us/security/blog/2025/04/01/transforming-public-sector-security-operations-in-the-ai-era/
Improved Detection Signature for the K8s IngressNightmare Vulnerability
https://www.reddit.com/r/netsec/comments/1jp9cmt/improved_detection_signature_for_the_k8s/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Tripwire
Japan Passes Active Cyber Defense Bill
Japan's Active Cyber Defense Bill empowers military and law enforcement to take preemptive action against cyber threats, enhancing national security.
Top Security News for Today
Consolidated View of Security Data: CVEs, Breaches, Ransomware & EOL Tracking
https://www.reddit.com/r/netsec/comments/1jyd734/consolidated_view_of_security_data_cves_breaches/
We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
https://www.reddit.com/r/netsec/comments/1jyihpn/we_have_a_package_for_you_a_comprehensive/
PentestGPT – AI-Powered Penetration Testing Assistant
https://www.darknet.org.uk/2025/04/pentestgpt-ai-powered-penetration-testing-assistant/
EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/
Looking for Elite Malware & Exploit Developers to Join a High-Level Development Group
https://0x00sec.org/t/looking-for-elite-malware-exploit-developers-to-join-a-high-level-development-group/43574
Article 7 of GDPR: Preserving Data Integrity in Image Publication
https://www.tripwire.com/state-of-security/article-7-gdpr-preserving-data-integrity-image-publication
Energy Under Siege: How the Industry is Fighting Against Cyber Attacks
https://www.tripwire.com/state-of-security/energy-under-siege-how-industry-fighting-against-cyber-attacks
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Consolidated View of Security Data: CVEs, Breaches, Ransomware & EOL Tracking
https://www.reddit.com/r/netsec/comments/1jyd734/consolidated_view_of_security_data_cves_breaches/
We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
https://www.reddit.com/r/netsec/comments/1jyihpn/we_have_a_package_for_you_a_comprehensive/
PentestGPT – AI-Powered Penetration Testing Assistant
https://www.darknet.org.uk/2025/04/pentestgpt-ai-powered-penetration-testing-assistant/
EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/
Looking for Elite Malware & Exploit Developers to Join a High-Level Development Group
https://0x00sec.org/t/looking-for-elite-malware-exploit-developers-to-join-a-high-level-development-group/43574
Article 7 of GDPR: Preserving Data Integrity in Image Publication
https://www.tripwire.com/state-of-security/article-7-gdpr-preserving-data-integrity-image-publication
Energy Under Siege: How the Industry is Fighting Against Cyber Attacks
https://www.tripwire.com/state-of-security/energy-under-siege-how-industry-fighting-against-cyber-attacks
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Consolidated View of Security Data: CVEs, Breaches, Ransomware & EOL Tracking
Posted by Electrical-Wish-4221 - 13 votes and 0 comments
Top Security News for Today
EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/
BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets
https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html
China Sort of Admits to Being Behind Volt Typhoon
https://www.schneier.com/blog/archives/2025/04/china-sort-of-admits-to-being-behind-volt-typhoon.html
Security Analysis: Potential AI Agent Hijacking via MCP and A2A Protocol Insights
https://www.reddit.com/r/netsec/comments/1jyvlzh/security_analysis_potential_ai_agent_hijacking/
14th April – Threat Intelligence Report
https://research.checkpoint.com/2025/14th-april-threat-intelligence-report/
Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking
https://research.checkpoint.com/2025/waiting-thread-hijacking/
Explore how to secure AI by attending our Learn Live Series
https://techcommunity.microsoft.com/blog/microsoft-security-blog/explore-how-to-secure-ai-by-attending-our-learn-live-series/4399703
GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs
https://arxiv.org/abs/2504.08176
The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence
https://arxiv.org/abs/2504.08264
You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager
https://arxiv.org/abs/2504.07982
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/
BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets
https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html
China Sort of Admits to Being Behind Volt Typhoon
https://www.schneier.com/blog/archives/2025/04/china-sort-of-admits-to-being-behind-volt-typhoon.html
Security Analysis: Potential AI Agent Hijacking via MCP and A2A Protocol Insights
https://www.reddit.com/r/netsec/comments/1jyvlzh/security_analysis_potential_ai_agent_hijacking/
14th April – Threat Intelligence Report
https://research.checkpoint.com/2025/14th-april-threat-intelligence-report/
Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking
https://research.checkpoint.com/2025/waiting-thread-hijacking/
Explore how to secure AI by attending our Learn Live Series
https://techcommunity.microsoft.com/blog/microsoft-security-blog/explore-how-to-secure-ai-by-attending-our-learn-live-series/4399703
GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs
https://arxiv.org/abs/2504.08176
The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence
https://arxiv.org/abs/2504.08264
You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager
https://arxiv.org/abs/2504.07982
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
Explore this post and more from the netsec community
Top Security News for Today
Best Practices for Transitioning from Security to Privacy
https://www.tripwire.com/state-of-security/best-practices-transitioning-security-privacy
Aiding reverse engineering with Rust and a local LLM
https://www.reddit.com/r/netsec/comments/1jzjcm9/aiding_reverse_engineering_with_rust_and_a_local/
They’re Everywhere! Why Non-Human Identities (and Their Security) Should Be Your Top Priority – Ben DH Kim
https://www.reddit.com/r/netsec/comments/1jzoxr7/theyre_everywhere_why_nonhuman_identities_and/
Renewed APT29 Phishing Campaign Against European Diplomats
https://research.checkpoint.com/2025/apt29-phishing-campaign/
Meet Burp Suite DAST: A clearer name for the industry's leading DAST solution
https://portswigger.net/blog/meet-burp-suite-dast-a-clearer-name-for-the-industrys-leading-dast-solution
Transforming security with Microsoft Security Exposure Management initiatives
https://www.microsoft.com/en-us/security/blog/2025/04/15/transforming-security-with-microsoft-security-exposure-management-initiatives/
Threat actors misuse Node.js to deliver malware and other malicious payloads
https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
Super Bowl 2025- Behind the Scenes of the Cybersecurity Blitz
https://www.darknet.org.uk/2025/04/super-bowl-2025-behind-the-scenes-of-the-cybersecurity-blitz/
Microsoft Windows dxkrnl Untrusted Pointer Dereference Local Privilege Escalation Vulnerability | HackSys Inc
https://www.reddit.com/r/netsec/comments/1k07ee7/microsoft_windows_dxkrnl_untrusted_pointer/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Best Practices for Transitioning from Security to Privacy
https://www.tripwire.com/state-of-security/best-practices-transitioning-security-privacy
Aiding reverse engineering with Rust and a local LLM
https://www.reddit.com/r/netsec/comments/1jzjcm9/aiding_reverse_engineering_with_rust_and_a_local/
They’re Everywhere! Why Non-Human Identities (and Their Security) Should Be Your Top Priority – Ben DH Kim
https://www.reddit.com/r/netsec/comments/1jzoxr7/theyre_everywhere_why_nonhuman_identities_and/
Renewed APT29 Phishing Campaign Against European Diplomats
https://research.checkpoint.com/2025/apt29-phishing-campaign/
Meet Burp Suite DAST: A clearer name for the industry's leading DAST solution
https://portswigger.net/blog/meet-burp-suite-dast-a-clearer-name-for-the-industrys-leading-dast-solution
Transforming security with Microsoft Security Exposure Management initiatives
https://www.microsoft.com/en-us/security/blog/2025/04/15/transforming-security-with-microsoft-security-exposure-management-initiatives/
Threat actors misuse Node.js to deliver malware and other malicious payloads
https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
Super Bowl 2025- Behind the Scenes of the Cybersecurity Blitz
https://www.darknet.org.uk/2025/04/super-bowl-2025-behind-the-scenes-of-the-cybersecurity-blitz/
Microsoft Windows dxkrnl Untrusted Pointer Dereference Local Privilege Escalation Vulnerability | HackSys Inc
https://www.reddit.com/r/netsec/comments/1k07ee7/microsoft_windows_dxkrnl_untrusted_pointer/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Tripwire
Best Practices for Transitioning from Security to Privacy
Learn key lessons for information security professionals transitioning to privacy programs, including understanding PII and collaborating with legal teams.
Top Security News for Today
SAP Emarsys SDK for Android Sensitive Data Leak (CVE-2023-6542)
https://www.reddit.com/r/netsec/comments/1k0flpj/sap_emarsys_sdk_for_android_sensitive_data_leak/
Streamlining Detection Engineering in Security Operation Centers
https://securelist.com/streamlining-detection-engineering/116186/
MITRE Support for the CVE Program is Due to Expire Today!
https://www.reddit.com/r/netsec/comments/1k0dodx/mitre_support_for_the_cve_program_is_due_to/
Cyber Signals Issue 9 | AI-Powered Deception: Emerging Fraud Threats and Countermeasures
https://www.microsoft.com/en-us/security/blog/2025/04/16/cyber-signals-issue-9-ai-powered-deception-emerging-fraud-threats-and-countermeasures/
CVE-2025-24054, NTLM Exploit in the Wild
https://research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild/
Oracle Critical Patch Update, April 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/04/16/oracle-critical-patch-update-april-2025-security-update-review
CVE Program Almost Unfunded
https://www.schneier.com/blog/archives/2025/04/cve-program-almost-unfunded.html
SPRING ISSUE OF 2600 RELEASED
https://www.2600.com/content/spring-issue-2600-released-19
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
SAP Emarsys SDK for Android Sensitive Data Leak (CVE-2023-6542)
https://www.reddit.com/r/netsec/comments/1k0flpj/sap_emarsys_sdk_for_android_sensitive_data_leak/
Streamlining Detection Engineering in Security Operation Centers
https://securelist.com/streamlining-detection-engineering/116186/
MITRE Support for the CVE Program is Due to Expire Today!
https://www.reddit.com/r/netsec/comments/1k0dodx/mitre_support_for_the_cve_program_is_due_to/
Cyber Signals Issue 9 | AI-Powered Deception: Emerging Fraud Threats and Countermeasures
https://www.microsoft.com/en-us/security/blog/2025/04/16/cyber-signals-issue-9-ai-powered-deception-emerging-fraud-threats-and-countermeasures/
CVE-2025-24054, NTLM Exploit in the Wild
https://research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild/
Oracle Critical Patch Update, April 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/04/16/oracle-critical-patch-update-april-2025-security-update-review
CVE Program Almost Unfunded
https://www.schneier.com/blog/archives/2025/04/cve-program-almost-unfunded.html
SPRING ISSUE OF 2600 RELEASED
https://www.2600.com/content/spring-issue-2600-released-19
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: SAP Emarsys SDK for Android Sensitive Data Leak (CVE-2023-6542)
Posted by MrTuxracer - 1 vote and 0 comments
Top Security News for Today
New writeup: a vulnerability in PHP's extract() function allows attackers to trigger a double-free, which in turn allows arbitrary code execution (native code)
https://www.reddit.com/r/netsec/comments/1k16vep/new_writeup_a_vulnerability_in_phps_extract/
[Project] I built a tool that tracks AWS documentation changes and analyzes security implications
https://www.reddit.com/r/netsec/comments/1k17yrm/project_i_built_a_tool_that_tracks_aws/
Age Verification Using Facial Scans
https://www.schneier.com/blog/archives/2025/04/age-verification-using-facial-scans.html
Microsoft’s Secure by Design journey: One year of success
https://www.microsoft.com/en-us/security/blog/2025/04/17/microsofts-secure-by-design-journey-one-year-of-success/
Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
https://www.reddit.com/r/netsec/comments/1k1ob9c/crosssite_websocket_hijacking_exploitation_in/
Nebula – Autonomous AI Pentesting Tool
https://www.darknet.org.uk/2025/04/nebula-autonomous-ai-pentesting-tool/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
New writeup: a vulnerability in PHP's extract() function allows attackers to trigger a double-free, which in turn allows arbitrary code execution (native code)
https://www.reddit.com/r/netsec/comments/1k16vep/new_writeup_a_vulnerability_in_phps_extract/
[Project] I built a tool that tracks AWS documentation changes and analyzes security implications
https://www.reddit.com/r/netsec/comments/1k17yrm/project_i_built_a_tool_that_tracks_aws/
Age Verification Using Facial Scans
https://www.schneier.com/blog/archives/2025/04/age-verification-using-facial-scans.html
Microsoft’s Secure by Design journey: One year of success
https://www.microsoft.com/en-us/security/blog/2025/04/17/microsofts-secure-by-design-journey-one-year-of-success/
Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
https://www.reddit.com/r/netsec/comments/1k1ob9c/crosssite_websocket_hijacking_exploitation_in/
Nebula – Autonomous AI Pentesting Tool
https://www.darknet.org.uk/2025/04/nebula-autonomous-ai-pentesting-tool/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: New writeup: a vulnerability in PHP's extract() function allows attackers to trigger a double…
Posted by SSDisclosure - 1 vote and 0 comments
Top Security News for Today
SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation | Cleafy
https://www.reddit.com/r/netsec/comments/1k21cf9/supercard_x_exposing_a_chinesespeaker_maas_for/
AES & ChaCha — A Case for Simplicity in Cryptography
https://www.reddit.com/r/netsec/comments/1k1y676/aes_chacha_a_case_for_simplicity_in_cryptography/
CVE-2025-25364: Speedify VPN MacOS privilege Escalation
https://www.reddit.com/r/netsec/comments/1k2bpp5/cve202525364_speedify_vpn_macos_privilege/
Friday Squid Blogging: Live Colossal Squid Filmed
https://www.schneier.com/blog/archives/2025/04/friday-squid-blogging-live-colossal-squid-filmed.html
A Dark Reading Panel - "The Promise and Perils of AI: Navigating Emerging Cyber Threats"
https://bishopfox.com/blog/dark-reading-panel-promise-perils-ai-navigating-emerging-cyber-threats-blog
Decentralised collaborative action: cryptoeconomics in space
https://arxiv.org/abs/2504.12465
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation | Cleafy
https://www.reddit.com/r/netsec/comments/1k21cf9/supercard_x_exposing_a_chinesespeaker_maas_for/
AES & ChaCha — A Case for Simplicity in Cryptography
https://www.reddit.com/r/netsec/comments/1k1y676/aes_chacha_a_case_for_simplicity_in_cryptography/
CVE-2025-25364: Speedify VPN MacOS privilege Escalation
https://www.reddit.com/r/netsec/comments/1k2bpp5/cve202525364_speedify_vpn_macos_privilege/
Friday Squid Blogging: Live Colossal Squid Filmed
https://www.schneier.com/blog/archives/2025/04/friday-squid-blogging-live-colossal-squid-filmed.html
A Dark Reading Panel - "The Promise and Perils of AI: Navigating Emerging Cyber Threats"
https://bishopfox.com/blog/dark-reading-panel-promise-perils-ai-navigating-emerging-cyber-threats-blog
Decentralised collaborative action: cryptoeconomics in space
https://arxiv.org/abs/2504.12465
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation | Cleafy
Explore this post and more from the netsec community
Top Security News for Today
Need Help Extracting Firmware from a VR Headset
https://www.reddit.com/r/netsec/comments/1k2ret4/need_help_extracting_firmware_from_a_vr_headset/
Speculative Thinking: Enhancing Small-Model Reasoning with Large Model Guidance at Inference Time
https://arxiv.org/abs/2504.12329
b3rito/b3acon: b3acon - a mail-based C2 that communicates via an in-memory C# IMAP client dynamically compiled in memory using PowerShell.
https://www.reddit.com/r/netsec/comments/1k3677a/b3ritob3acon_b3acon_a_mailbased_c2_that/
BBRadar.io - The Bug Bounty Program Aggregator - Find the latest bug bounty programs from all major platforms.
https://www.reddit.com/r/netsec/comments/1k37153/bbradario_the_bug_bounty_program_aggregator_find/
Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Need Help Extracting Firmware from a VR Headset
https://www.reddit.com/r/netsec/comments/1k2ret4/need_help_extracting_firmware_from_a_vr_headset/
Speculative Thinking: Enhancing Small-Model Reasoning with Large Model Guidance at Inference Time
https://arxiv.org/abs/2504.12329
b3rito/b3acon: b3acon - a mail-based C2 that communicates via an in-memory C# IMAP client dynamically compiled in memory using PowerShell.
https://www.reddit.com/r/netsec/comments/1k3677a/b3ritob3acon_b3acon_a_mailbased_c2_that/
BBRadar.io - The Bug Bounty Program Aggregator - Find the latest bug bounty programs from all major platforms.
https://www.reddit.com/r/netsec/comments/1k37153/bbradario_the_bug_bounty_program_aggregator_find/
Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: need help extracting firmware from a vr headset in a working state
Posted by Shot_Morning2815 - 0 votes and 4 comments
Top Security News for Today
Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/
Elkeid – A Modern, Scalable HIDS for Cloud-Native Infrastructure
https://www.darknet.org.uk/2025/04/elkeid-a-modern-scalable-hids-for-cloud-native-infrastructure/
FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE
https://www.trendmicro.com/en_us/research/25/d/fog-ransomware-concealed-within-binary-loaders-linking-themselve.html
Assessing LLMs in Art Contexts: Critique Generation and Theory of Mind Evaluation
https://arxiv.org/abs/2504.12805
Understanding the Limits of Vision Language Models Through the Lens of the Binding Problem
https://arxiv.org/abs/2411.00238
Phishing attacks leveraging HTML code inside SVG files
https://securelist.com/svg-phishing/116256/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/
Elkeid – A Modern, Scalable HIDS for Cloud-Native Infrastructure
https://www.darknet.org.uk/2025/04/elkeid-a-modern-scalable-hids-for-cloud-native-infrastructure/
FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE
https://www.trendmicro.com/en_us/research/25/d/fog-ransomware-concealed-within-binary-loaders-linking-themselve.html
Assessing LLMs in Art Contexts: Critique Generation and Theory of Mind Evaluation
https://arxiv.org/abs/2504.12805
Understanding the Limits of Vision Language Models Through the Lens of the Binding Problem
https://arxiv.org/abs/2411.00238
Phishing attacks leveraging HTML code inside SVG files
https://securelist.com/svg-phishing/116256/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
Everything You Need to Know About VPNs—Without the "affiliates" : r/netsec
531K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers…
Top Security News for Today
21st April – Threat Intelligence Report
https://research.checkpoint.com/2025/21st-april-threat-intelligence-report/
IoT Network Security: Analyzing Decrypted Zigbee Traffic Data
https://www.reddit.com/r/netsec/comments/1k4awln/iot_network_security_analyzing_decrypted_zigbee/
Lumma Stealer – Tracking distribution channels
https://securelist.com/lumma-fake-captcha-attacks-analysis/116274/
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative
https://www.microsoft.com/en-us/security/blog/2025/04/21/securing-our-future-april-2025-progress-report-on-microsofts-secure-future-initiative/
Investigating cybersecurity incidents using large language models in latest-generation wireless networks
https://arxiv.org/abs/2504.13196
Whistleblower: DOGE Siphoned NLRB Case Data
https://krebsonsecurity.com/2025/04/whistleblower-doge-siphoned-nlrb-case-data/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
21st April – Threat Intelligence Report
https://research.checkpoint.com/2025/21st-april-threat-intelligence-report/
IoT Network Security: Analyzing Decrypted Zigbee Traffic Data
https://www.reddit.com/r/netsec/comments/1k4awln/iot_network_security_analyzing_decrypted_zigbee/
Lumma Stealer – Tracking distribution channels
https://securelist.com/lumma-fake-captcha-attacks-analysis/116274/
Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative
https://www.microsoft.com/en-us/security/blog/2025/04/21/securing-our-future-april-2025-progress-report-on-microsofts-secure-future-initiative/
Investigating cybersecurity incidents using large language models in latest-generation wireless networks
https://arxiv.org/abs/2504.13196
Whistleblower: DOGE Siphoned NLRB Case Data
https://krebsonsecurity.com/2025/04/whistleblower-doge-siphoned-nlrb-case-data/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Check Point Research
21st April – Threat Intelligence Report - Check Point Research
For the latest discoveries in cyber research for the week of 21st April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Retail giant Ahold Delhaize has suffered a cyber-attack resulting in data theft of customer information from…