Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Bypassing Detections with Command-Line Obfuscation
https://www.reddit.com/r/netsec/comments/1jimof1/bypassing_detections_with_commandline_obfuscation/

Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
https://www.reddit.com/r/netsec/comments/1jim7sp/doing_the_due_diligence_analyzing_the_nextjs/

Cross-Border Data Compliance: Navigating Public Security Regulations in a Connected World
https://www.tripwire.com/state-of-security/cross-border-data-compliance-navigating-public-security-regulations-connected

More Countries are Demanding Back-Doors to Encrypted Apps
https://www.schneier.com/blog/archives/2025/03/more-countries-are-demanding-back-doors-to-encrypted-apps.html

24th March – Threat Intelligence Report
https://research.checkpoint.com/2025/24th-march-threat-intelligence-report/

Takumi, the AI Security Engineer | GMO Flatt Security Inc.
https://www.reddit.com/r/netsec/comments/1jis8zi/takumi_the_ai_security_engineer_gmo_flatt/

Microsoft unveils Microsoft Security Copilot agents and new protections for AI
https://www.microsoft.com/en-us/security/blog/2025/03/24/microsoft-unveils-microsoft-security-copilot-agents-and-new-protections-for-ai/

Rust for Malware Development
https://bishopfox.com/blog/rust-for-malware-development

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

smugglo – Bypass Email Attachment Restrictions with HTML Smuggling
https://www.reddit.com/r/netsec/comments/1jjfq3d/smugglo_bypass_email_attachment_restrictions_with/

The Firewall Project (Application Security with Enterprise features) is now open-source
https://www.reddit.com/r/netsec/comments/1jismhn/the_firewall_project_application_security_with/

CLI tool to sandbox Linux processes using Landlock no containers, no root
https://www.reddit.com/r/netsec/comments/1jh9y1q/cli_tool_to_sandbox_linux_processes_using/

Kereva scanner: an open-source LLM security (and performance) scanner
https://www.reddit.com/r/netsec/comments/1jgtr4e/kereva_scanner_an_opensource_llm_security_and/

A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
https://www.schneier.com/blog/archives/2025/03/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations.html

Blasting Past Webp - Google Project Zero
https://www.reddit.com/r/netsec/comments/1jl2t85/blasting_past_webp_google_project_zero/

Blacklock Ransomware: A Late Holiday Gift with Intrusion into the Threat Actor's Infrastructure
https://www.reddit.com/r/netsec/comments/1jl3ig6/blacklock_ransomware_a_late_holiday_gift_with/

US Department of Labor’s journey to Zero Trust security with Microsoft Entra ID
https://www.microsoft.com/en-us/security/blog/2025/03/27/us-department-of-labors-journey-to-zero-trust-security-with-microsoft-entra-id/

When Getting Phished Puts You in Mortal Danger
https://krebsonsecurity.com/2025/03/when-getting-phished-puts-you-in-mortal-danger/

Qualys TRU Discovers Three Bypasses of Ubuntu Unprivileged User Namespace Restrictions
https://blog.qualys.com/vulnerabilities-threat-research/2025/03/27/qualys-tru-discovers-three-bypasses-of-ubuntu-unprivileged-user-namespace-restrictions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
https://www.trendmicro.com/en_us/research/25/c/the-espionage-toolkit-of-earth-alux.html

Feberis Pro: As one of the first, I had an opportunity to test new 4-in-1 Expansion Board for Flipper Zero
https://www.reddit.com/r/netsec/comments/1jo0eww/feberis_pro_as_one_of_first_i_had_and_an/

The Signal Chat Leak and the NSA
https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html

Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
https://portswigger.net/blog/welcome-to-the-next-generation-of-burp-suite-elevate-your-testing-with-burp-ai

Anatomy of an LLM RCE
https://www.reddit.com/r/netsec/comments/1jo1w9n/anatomy_of_an_llm_rce/

Oracle attempt to hide serious security incident from customers in Oracle SaaS service
https://www.reddit.com/r/netsec/comments/1jo2s5g/oracle_attempt_to_hide_serious_security_incident/

New innovations in Microsoft Purview for protected, AI-ready data
https://www.microsoft.com/en-us/security/blog/2025/03/31/new-innovations-in-microsoft-purview-for-protected-ai-ready-data/

Analyzing open-source bootloaders: Finding vulnerabilities faster with AI
https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/

Epic Fails and Heist Tales: A Red Teamer’s Journey to Deadwood
https://bishopfox.com/blog/epic-fails-heist-tales-red-teamers

🛡️ DoD Sentinel Skills Challenge – compete, win, and gain access to job opportunities!
https://www.reddit.com/r/netsec/comments/1jo6yht/dod_sentinel_skills_challenge_compete_win_and/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Japan Passes Active Cyber Defense Bill
https://www.tripwire.com/state-of-security/japan-passes-active-cyber-defense-bill

Top Cybersecurity Considerations When Moving Commercial Premises
https://www.tripwire.com/state-of-security/top-cybersecurity-considerations-when-moving-commercial-premises

Reforging Sliver: How Simple Code Edits Can Outmaneuver EDR
https://www.reddit.com/r/netsec/comments/1joqvup/reforging_sliver_how_simple_code_edits_can/

Harnessing the Power of Named Pipes
https://www.reddit.com/r/netsec/comments/1jor8nr/harnessing_the_power_of_named_pipes/

CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog
https://www.reddit.com/r/netsec/comments/1jopz93/crushftp_authentication_bypass_cve20252825/

Cell Phone OPSEC for Border Crossings
https://www.schneier.com/blog/archives/2025/04/cell-phone-opsec-for-border-crossings.html

XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS (CVE-2025-2748) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1jos2z2/xss_to_rce_by_abusing_custom_file_handlers/

When Parameterization Fails: SQL Injection in Nim's db_postgres Module Using Parameterized Queries
https://www.reddit.com/r/netsec/comments/1joth41/when_parameterization_fails_sql_injection_in_nims/

Transforming Public Sector Security Operations in the AI Era
https://www.microsoft.com/en-us/security/blog/2025/04/01/transforming-public-sector-security-operations-in-the-ai-era/

Improved Detection Signature for the K8s IngressNightmare Vulnerability
https://www.reddit.com/r/netsec/comments/1jp9cmt/improved_detection_signature_for_the_k8s/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Consolidated View of Security Data: CVEs, Breaches, Ransomware & EOL Tracking
https://www.reddit.com/r/netsec/comments/1jyd734/consolidated_view_of_security_data_cves_breaches/

We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs
https://www.reddit.com/r/netsec/comments/1jyihpn/we_have_a_package_for_you_a_comprehensive/

PentestGPT – AI-Powered Penetration Testing Assistant
https://www.darknet.org.uk/2025/04/pentestgpt-ai-powered-penetration-testing-assistant/

EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/

Looking for Elite Malware & Exploit Developers to Join a High-Level Development Group
https://0x00sec.org/t/looking-for-elite-malware-exploit-developers-to-join-a-high-level-development-group/43574

Article 7 of GDPR: Preserving Data Integrity in Image Publication
https://www.tripwire.com/state-of-security/article-7-gdpr-preserving-data-integrity-image-publication

Energy Under Siege: How the Industry is Fighting Against Cyber Attacks
https://www.tripwire.com/state-of-security/energy-under-siege-how-industry-fighting-against-cyber-attacks

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

EDV - Endpoint Detection & Vibes - From vibe coding to vibe detections
https://www.reddit.com/r/netsec/comments/1jypjxk/edv_endpoint_detection_vibes_from_vibe_coding_to/

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets
https://www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html

China Sort of Admits to Being Behind Volt Typhoon
https://www.schneier.com/blog/archives/2025/04/china-sort-of-admits-to-being-behind-volt-typhoon.html

Security Analysis: Potential AI Agent Hijacking via MCP and A2A Protocol Insights
https://www.reddit.com/r/netsec/comments/1jyvlzh/security_analysis_potential_ai_agent_hijacking/

14th April – Threat Intelligence Report
https://research.checkpoint.com/2025/14th-april-threat-intelligence-report/

Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking
https://research.checkpoint.com/2025/waiting-thread-hijacking/

Explore how to secure AI by attending our Learn Live Series
https://techcommunity.microsoft.com/blog/microsoft-security-blog/explore-how-to-secure-ai-by-attending-our-learn-live-series/4399703

GenXSS: an AI-Driven Framework for Automated Detection of XSS Attacks in WAFs
https://arxiv.org/abs/2504.08176

The AI Risk Repository: A Comprehensive Meta-Review, Database, and Taxonomy of Risks From Artificial Intelligence
https://arxiv.org/abs/2504.08264

You Can't Trust Your Tag Neither: Privacy Leaks and Potential Legal Violations within the Google Tag Manager
https://arxiv.org/abs/2504.07982

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Best Practices for Transitioning from Security to Privacy
https://www.tripwire.com/state-of-security/best-practices-transitioning-security-privacy

Aiding reverse engineering with Rust and a local LLM
https://www.reddit.com/r/netsec/comments/1jzjcm9/aiding_reverse_engineering_with_rust_and_a_local/

They’re Everywhere! Why Non-Human Identities (and Their Security) Should Be Your Top Priority – Ben DH Kim
https://www.reddit.com/r/netsec/comments/1jzoxr7/theyre_everywhere_why_nonhuman_identities_and/

Renewed APT29 Phishing Campaign Against European Diplomats
https://research.checkpoint.com/2025/apt29-phishing-campaign/

Meet Burp Suite DAST: A clearer name for the industry's leading DAST solution
https://portswigger.net/blog/meet-burp-suite-dast-a-clearer-name-for-the-industrys-leading-dast-solution

Transforming security with Microsoft Security Exposure Management initiatives
https://www.microsoft.com/en-us/security/blog/2025/04/15/transforming-security-with-microsoft-security-exposure-management-initiatives/

Threat actors misuse Node.js to deliver malware and other malicious payloads
https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/

Super Bowl 2025- Behind the Scenes of the Cybersecurity Blitz
https://www.darknet.org.uk/2025/04/super-bowl-2025-behind-the-scenes-of-the-cybersecurity-blitz/

Microsoft Windows dxkrnl Untrusted Pointer Dereference Local Privilege Escalation Vulnerability | HackSys Inc
https://www.reddit.com/r/netsec/comments/1k07ee7/microsoft_windows_dxkrnl_untrusted_pointer/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New writeup: a vulnerability in PHP's extract() function allows attackers to trigger a double-free, which in turn allows arbitrary code execution (native code)
https://www.reddit.com/r/netsec/comments/1k16vep/new_writeup_a_vulnerability_in_phps_extract/

[Project] I built a tool that tracks AWS documentation changes and analyzes security implications
https://www.reddit.com/r/netsec/comments/1k17yrm/project_i_built_a_tool_that_tracks_aws/

Age Verification Using Facial Scans
https://www.schneier.com/blog/archives/2025/04/age-verification-using-facial-scans.html

Microsoft’s Secure by Design journey: One year of success
https://www.microsoft.com/en-us/security/blog/2025/04/17/microsofts-secure-by-design-journey-one-year-of-success/

Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
https://www.reddit.com/r/netsec/comments/1k1ob9c/crosssite_websocket_hijacking_exploitation_in/

Nebula – Autonomous AI Pentesting Tool
https://www.darknet.org.uk/2025/04/nebula-autonomous-ai-pentesting-tool/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Need Help Extracting Firmware from a VR Headset
https://www.reddit.com/r/netsec/comments/1k2ret4/need_help_extracting_firmware_from_a_vr_headset/

Speculative Thinking: Enhancing Small-Model Reasoning with Large Model Guidance at Inference Time
https://arxiv.org/abs/2504.12329

b3rito/b3acon: b3acon - a mail-based C2 that communicates via an in-memory C# IMAP client dynamically compiled in memory using PowerShell.
https://www.reddit.com/r/netsec/comments/1k3677a/b3ritob3acon_b3acon_a_mailbased_c2_that/

BBRadar.io - The Bug Bounty Program Aggregator - Find the latest bug bounty programs from all major platforms.
https://www.reddit.com/r/netsec/comments/1k37153/bbradario_the_bug_bounty_program_aggregator_find/

Everything You Need to Know About VPNs—Without the "affiliates"
https://www.reddit.com/r/netsec/comments/1k3fuyo/everything_you_need_to_know_about_vpnswithout_the/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Local privilege escalation on Zyxel USG FLEX H Series (CVE-2025-1731)
https://www.reddit.com/r/netsec/comments/1k5roqe/local_privilege_escalation_on_zyxel_usg_flex_h/

Regulating AI Behavior with a Hypervisor
https://www.schneier.com/blog/archives/2025/04/regulating-ai-behavior-with-a-hypervisor.html

Understanding the threat landscape for Kubernetes and containerized assets
https://www.microsoft.com/en-us/security/blog/2025/04/23/understanding-the-threat-landscape-for-kubernetes-and-containerized-assets/

XRP Supplychain attack: Official NPM package infected with crypto stealing backdoor
https://www.reddit.com/r/netsec/comments/1k54dna/xrp_supplychain_attack_official_npm_package/

DOGE Worker’s Code Supports NLRB Whistleblower
https://krebsonsecurity.com/2025/04/doge-workers-code-supports-nlrb-whistleblower/

Authenticated Remote Code Execution on USG FLEX H Series (CVE-2025-1731 / CVE-2025-1732)
https://www.reddit.com/r/netsec/comments/1k6f52p/authenticated_remote_code_execution_on_usg_flex_h/

Operation SyncHole: Lazarus APT goes back to the well
https://securelist.com/operation-synchole-watering-hole-attacks-by-lazarus/116326/

Scams 2.0: How Technology Is Powering the Next Generation of Fraud
https://www.tripwire.com/state-of-security/scams-how-technology-powering-next-generation-fraud

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Certifying Knowledge Comprehension in LLMs
https://arxiv.org/abs/2402.15929

Fire In The Hole, We’re Breaching The Vault - Commvault Remote Code Execution (CVE-2025-34028) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1k6ogjy/fire_in_the_hole_were_breaching_the_vault/

GitHub potential leaking of private emails and Hacker One
https://www.reddit.com/r/netsec/comments/1k6owdl/github_potential_leaking_of_private_emails_and/

SonicWall Sonicos Versions 7.1.x and 8.0.x
https://bishopfox.com/blog/sonicwall-sonicos-versions-7-1-x-and-8-0-x

New whitepaper outlines the taxonomy of failure modes in AI agents
https://www.microsoft.com/en-us/security/blog/2025/04/24/new-whitepaper-outlines-the-taxonomy-of-failure-modes-in-ai-agents/

2 New UAF Vulnerabilities in Chrome
https://www.reddit.com/r/netsec/comments/1k6r7r8/2_new_uaf_vulnerabilities_in_chrome/

New Linux Rootkit
https://www.schneier.com/blog/archives/2025/04/new-linux-rootkit.html

io_uring Is Back, This Time as a Rootkit
https://www.reddit.com/r/netsec/comments/1k73fcr/io_uring_is_back_this_time_as_a_rootkit/

Tyton – Kernel-Mode Rootkit Hunter for Linux
https://www.darknet.org.uk/2025/04/tyton-kernel-mode-rootkit-hunter-for-linux/

Addressing a Large-Scale Data Breach: Seeking Network Security Expertise
https://www.reddit.com/r/netsec/comments/1k77q6j/addressing_a_largescale_data_breach_seeking/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman