Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

After a decade of open source security educational tools (SecGen), we've launched a hosted platform, Hacktivity
https://www.reddit.com/r/netsec/comments/1jhvszk/after_a_decade_of_open_source_security/

VanHelsing, new RaaS in Town
https://research.checkpoint.com/2025/vanhelsing-new-raas-in-town/

Cosmos-Reason1: From Physical Common Sense To Embodied Reasoning
https://arxiv.org/abs/2503.15558

Towards Unified Latent Space for 3D Molecular Latent Diffusion Modeling
https://arxiv.org/abs/2503.15567

Privateers Reborn: Digital Letters of Marque
https://www.reddit.com/r/netsec/comments/1jibf18/privateers_reborn_digital_letters_of_marque/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected

More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html

24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/

Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/

Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/

Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
https://www.reddit.com/r/netsec/comments/1jjfq3d/smugglo_bypass_email_attachment_restrictions_with/

The Firewall Project (Application Security with Enterprise features) is now open-source
https://www.reddit.com/r/netsec/comments/1jismhn/the_firewall_project_application_security_with/

CLI tool to sandbox Linux processes using Landlock no containers, no root
https://www.reddit.com/r/netsec/comments/1jh9y1q/cli_tool_to_sandbox_linux_processes_using/

Kereva scanner: an open-source LLM security (and performance) scanner
https://www.reddit.com/r/netsec/comments/1jgtr4e/kereva_scanner_an_opensource_llm_security_and/

A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html

Blasting Past Webp - Google Project Zero
https://www.reddit.com/r/netsec/comments/1jl2t85/blasting_past_webp_google_project_zero/

Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
https://www.reddit.com/r/netsec/comments/1jl3ig6/blacklock_ransomware_a_late_holiday_gift_with/

US Department of Labor’s journey to Zero Trust security with Microsoft Entra ID
https://www.microsoft.com/en-us/security/blog/2025/03/27/us-department-of-labors-journey-to-zero-trust-security-with-microsoft-entra-id/

When Getting Phished Puts You in Mortal Danger
https://krebsonsecurity.com/2025/03/when-getting-phished-puts-you-in-mortal-danger/

Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html

Feberis Pro: As one of the first, I had an opportunity to test new 4-in-1 Expansion Board for Flipper Zero
https://www.reddit.com/r/netsec/comments/1jo0eww/feberis_pro_as_one_of_first_i_had_and_an/

The Signal Chat Leak and the NSA
https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html

Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
https://portswigger.net/blog/welcome-to-the-next-generation-of-burp-suite-elevate-your-testing-with-burp-ai

Anatomy of an LLM RCE
https://www.reddit.com/r/netsec/comments/1jo1w9n/anatomy_of_an_llm_rce/

Oracle attempt to hide serious security incident from customers in Oracle SaaS service
https://www.reddit.com/r/netsec/comments/1jo2s5g/oracle_attempt_to_hide_serious_security_incident/

New innovations in Microsoft Purview for protected, AI-ready data
https://www.microsoft.com/en-us/security/blog/2025/03/31/new-innovations-in-microsoft-purview-for-protected-ai-ready-data/

Analyzing open-source bootloaders: Finding vulnerabilities faster with AI
https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/

Epic Fails and Heist Tales: A Red Teamer’s Journey to Deadwood
https://bishopfox.com/blog/epic-fails-heist-tales-red-teamers

🛡️ DoD Sentinel Skills Challenge – compete, win, and gain access to job opportunities!
https://www.reddit.com/r/netsec/comments/1jo6yht/dod_sentinel_skills_challenge_compete_win_and/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Japan Passes Active Cyber Defense Bill
https://www.tripwire.com/state-of-security/japan-passes-active-cyber-defense-bill

Top Cybersecurity Considerations When Moving Commercial Premises
https://www.tripwire.com/state-of-security/top-cybersecurity-considerations-when-moving-commercial-premises

Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR
https://www.reddit.com/r/netsec/comments/1joqvup/reforging_sliver_how_simple_code_edits_can/

Harnessing the Power of Named Pipes
https://www.reddit.com/r/netsec/comments/1jor8nr/harnessing_the_power_of_named_pipes/

CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog
https://www.reddit.com/r/netsec/comments/1jopz93/crushftp_authentication_bypass_cve20252825/

Cell Phone OPSEC for Border Crossings
https://www.schneier.com/blog/archives/2025/04/cell-phone-opsec-for-border-crossings.html

XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1jos2z2/xss_to_rce_by_abusing_custom_file_handlers/

When Parameterization Fails: SQL Injection in Nim's db_postgres Module Using Parameterized Queries
https://www.reddit.com/r/netsec/comments/1joth41/when_parameterization_fails_sql_injection_in_nims/

Transforming Public Sector Security Operations in the AI Era
https://www.microsoft.com/en-us/security/blog/2025/04/01/transforming-public-sector-security-operations-in-the-ai-era/

Improved Detection Signature for the K8s IngressNightmare Vulnerability
https://www.reddit.com/r/netsec/comments/1jp9cmt/improved_detection_signature_for_the_k8s/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Consolidated View of Security Data: CVEs, Breaches, Ransomware & EOL Tracking
https://www.reddit.com/r/netsec/comments/1jyd734/consolidated_view_of_security_data_cves_breaches/

We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
https://www.reddit.com/r/netsec/comments/1jyihpn/we_have_a_package_for_you_a_comprehensive/

PentestGPT – AI-Powered Penetration Testing Assistant
https://www.darknet.org.uk/2025/04/pentestgpt-ai-powered-penetration-testing-assistant/

EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/

Looking for Elite Malware & Exploit Developers to Join a High-Level Development Group
https://0x00sec.org/t/looking-for-elite-malware-exploit-developers-to-join-a-high-level-development-group/43574

Article 7 of GDPR: Preserving Data Integrity in Image Publication
https://www.tripwire.com/state-of-security/article-7-gdpr-preserving-data-integrity-image-publication

Energy Under Siege: How the Industry is Fighting Against Cyber Attacks
https://www.tripwire.com/state-of-security/energy-under-siege-how-industry-fighting-against-cyber-attacks

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets
https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html

China Sort of Admits to Being Behind Volt Typhoon
https://www.schneier.com/blog/archives/2025/04/china-sort-of-admits-to-being-behind-volt-typhoon.html

Security Analysis: Potential AI Agent Hijacking via MCP and A2A Protocol Insights
https://www.reddit.com/r/netsec/comments/1jyvlzh/security_analysis_potential_ai_agent_hijacking/

14th April – Threat Intelligence Report
https://research.checkpoint.com/2025/14th-april-threat-intelligence-report/

Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking
https://research.checkpoint.com/2025/waiting-thread-hijacking/

Explore how to secure AI by attending our Learn Live Series
https://techcommunity.microsoft.com/blog/microsoft-security-blog/explore-how-to-secure-ai-by-attending-our-learn-live-series/4399703

GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs
https://arxiv.org/abs/2504.08176

The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence
https://arxiv.org/abs/2504.08264

You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager
https://arxiv.org/abs/2504.07982

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Best Practices for Transitioning from Security to Privacy
https://www.tripwire.com/state-of-security/best-practices-transitioning-security-privacy

Aiding reverse engineering with Rust and a local LLM
https://www.reddit.com/r/netsec/comments/1jzjcm9/aiding_reverse_engineering_with_rust_and_a_local/

They’re Everywhere! Why Non-Human Identities (and Their Security) Should Be Your Top Priority – Ben DH Kim
https://www.reddit.com/r/netsec/comments/1jzoxr7/theyre_everywhere_why_nonhuman_identities_and/

Renewed APT29 Phishing Campaign Against European Diplomats
https://research.checkpoint.com/2025/apt29-phishing-campaign/

Meet Burp Suite DAST: A clearer name for the industry's leading DAST solution
https://portswigger.net/blog/meet-burp-suite-dast-a-clearer-name-for-the-industrys-leading-dast-solution

Transforming security with Microsoft Security Exposure Management initiatives
https://www.microsoft.com/en-us/security/blog/2025/04/15/transforming-security-with-microsoft-security-exposure-management-initiatives/

Threat actors misuse Node.js to deliver malware and other malicious payloads
https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/

Super Bowl 2025- Behind the Scenes of the Cybersecurity Blitz
https://www.darknet.org.uk/2025/04/super-bowl-2025-behind-the-scenes-of-the-cybersecurity-blitz/

Microsoft Windows dxkrnl Untrusted Pointer Dereference Local Privilege Escalation Vulnerability | HackSys Inc
https://www.reddit.com/r/netsec/comments/1k07ee7/microsoft_windows_dxkrnl_untrusted_pointer/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New writeup: a vulnerability in PHP's extract() function allows attackers to trigger a double-free, which in turn allows arbitrary code execution (native code)
https://www.reddit.com/r/netsec/comments/1k16vep/new_writeup_a_vulnerability_in_phps_extract/

[Project] I built a tool that tracks AWS documentation changes and analyzes security implications
https://www.reddit.com/r/netsec/comments/1k17yrm/project_i_built_a_tool_that_tracks_aws/

Age Verification Using Facial Scans
https://www.schneier.com/blog/archives/2025/04/age-verification-using-facial-scans.html

Microsoft’s Secure by Design journey: One year of success
https://www.microsoft.com/en-us/security/blog/2025/04/17/microsofts-secure-by-design-journey-one-year-of-success/

Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
https://www.reddit.com/r/netsec/comments/1k1ob9c/crosssite_websocket_hijacking_exploitation_in/

Nebula – Autonomous AI Pentesting Tool
https://www.darknet.org.uk/2025/04/nebula-autonomous-ai-pentesting-tool/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Need Help Extracting Firmware from a VR Headset
https://www.reddit.com/r/netsec/comments/1k2ret4/need_help_extracting_firmware_from_a_vr_headset/

Speculative Thinking: Enhancing Small-Model Reasoning with Large Model Guidance at Inference Time
https://arxiv.org/abs/2504.12329

b3rito/b3acon: b3acon - a mail-based C2 that communicates via an in-memory C# IMAP client dynamically compiled in memory using PowerShell.
https://www.reddit.com/r/netsec/comments/1k3677a/b3ritob3acon_b3acon_a_mailbased_c2_that/

BBRadar.io - The Bug Bounty Program Aggregator - Find the latest bug bounty programs from all major platforms.
https://www.reddit.com/r/netsec/comments/1k37153/bbradario_the_bug_bounty_program_aggregator_find/

Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman