Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Self Rewarding Self Improving
https://arxiv.org/abs/2505.08827

Communications Backdoor in Chinese Power Inverters
https://www.schneier.com/blog/archives/2025/05/communications-backdoor-in-chinese-power-inverters.html

Announcing the Official Parity Release of Volatility 3!
https://www.reddit.com/r/netsec/comments/1ko3uye/announcing_the_official_parity_release_of/

Skitnet(Bossnet) Malware Analysis
https://www.reddit.com/r/netsec/comments/1ko59nn/skitnetbossnet_malware_analysis/

Automated Alert Classification and Triage (AACT): An Intelligent System for the Prioritisation of Cybersecurity Alerts
https://arxiv.org/abs/2505.09616

Guardian Positioning System (GPS) for Location Based Services
https://arxiv.org/abs/2505.09628

Correlating Account on Ethereum Mixing Service via Domain-Invariant feature learning
https://arxiv.org/abs/2505.09743

PIG: Privacy Jailbreak Attack on LLMs via Gradient-based Iterative In-Context Optimization
https://arxiv.org/abs/2505.09639

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Large Language Models Are More Persuasive Than Incentivized Human Persuaders
https://arxiv.org/abs/2505.09662

$XX^{t}$ Can Be Faster
https://arxiv.org/abs/2505.09814

Analog Foundation Models
https://arxiv.org/abs/2505.09663

Frame by Frame, Kernel Streaming Keeps Giving Vulnerabilities
https://devco.re/blog/2025/05/17/frame-by-frame-kernel-streaming-keeps-giving-vulnerabilities-en/

Stateful Connection With Spoofed Source IP — NetImpostor
https://www.reddit.com/r/netsec/comments/1kp4n2r/stateful_connection_with_spoofed_source_ip/

Translating Electrocardiograms to Cardiac Magnetic Resonance Imaging Useful for Cardiac Assessment and Disease Screening: A Multi-Center Study AI for ECG to CMR Translation Study
https://arxiv.org/abs/2411.13602

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The NSA’s “Fifty Years of Mathematical Cryptanalysis (1937–1987)”
https://www.schneier.com/blog/archives/2025/05/the-nsas-fifty-years-of-mathematical-cryptanalysis-1937-1987.html

Introducing EntraFalcon – A Tool to Enumerate Entra ID Objects and Assignments
https://www.reddit.com/r/netsec/comments/1kq4oie/introducing_entrafalcon_a_tool_to_enumerate_entra/

Cache poisoning via race-condition in Next.js
https://www.reddit.com/r/netsec/comments/1kq64ta/cache_poisoning_via_racecondition_in_nextjs/

19th May – Threat Intelligence Report
https://research.checkpoint.com/2025/19th-may-threat-intelligence-report/

Microsoft extends Zero Trust to secure the agentic workforce
https://www.microsoft.com/en-us/security/blog/2025/05/19/microsoft-extends-zero-trust-to-secure-the-agentic-workforce/

SafeTrans: LLM-assisted Transpilation from C to Rust
https://arxiv.org/abs/2505.10708

Agent Name Service (ANS): A Universal Directory for Secure AI Agent Discovery and Interoperability
https://arxiv.org/abs/2505.10609

Neural-Inspired Advances in Integral Cryptanalysis
https://arxiv.org/abs/2505.10790

RAN Tester UE: An Automated Declarative UE Centric Security Testing Platform
https://arxiv.org/abs/2505.10812

Automating Security Audit Using Large Language Model based Agent: An Exploration Experiment
https://arxiv.org/abs/2505.10732

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Government Organizations Lose Nearly a Month in Downtime for Every Ransomware Attack
https://www.tripwire.com/state-of-security/government-organizations-lose-nearly-month-downtime-every-ransomware-attack

How IoT Security Cameras Are Susceptible to Cyber Attacks
https://www.tripwire.com/state-of-security/how-iot-security-cameras-are-susceptible-cyber-attacks

DoorDash Hack
https://www.schneier.com/blog/archives/2025/05/doordash-hack.html

New Vulnerabilities in Foscam X5
https://www.reddit.com/r/netsec/comments/1kr32cs/new_vulnerabilities_in_foscam_x5/

The Sting of Fake Kling: Facebook Malvertising Lures Victims to Fake AI Generation Website
https://research.checkpoint.com/2025/impersonated-kling-ai-site-installs-malware/

How to Extract Useful Info from Microsoft Deployment Toolkit (MDT) Shares on Red Teams
https://www.reddit.com/r/netsec/comments/1kr5uiu/how_to_extract_useful_info_from_microsoft/

Varonis' Data Security Report Reveals 99% of Orgs Have Sensitive Information Exposed to AI
https://www.reddit.com/r/netsec/comments/1kr5uee/varonis_data_security_report_reveals_99_of_orgs/

Malvertising's New Threat: Exploiting Trusted Google Domains
https://www.reddit.com/r/netsec/comments/1krgc39/malvertisings_new_threat_exploiting_trusted/

KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS
https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Dero miner zombies biting through Docker APIs to build a cryptojacking horde
https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/

EvilWorker: a new AiTM attack framework leveraging service workers — much more effective, autonomous, and adaptable than Evilginx2? 🎣
https://www.reddit.com/r/netsec/comments/1krtrht/evilworker_a_new_aitm_attack_framework_leveraging/

Humans are Insecure Password Generators
https://www.reddit.com/r/netsec/comments/1krqom1/humans_are_insecure_password_generators/

BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
https://www.reddit.com/r/netsec/comments/1ks1i9g/badsuccessor_abusing_dmsa_to_escalate_privileges/

Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/

AI-Powered Malware – The Next Evolution in Cyber Threats
https://www.darknet.org.uk/2025/05/ai-powered-malware-the-next-evolution-in-cyber-threats/

CVE-2024-45332 brings back branch target injection attacks on Intel
https://www.reddit.com/r/netsec/comments/1ksc31c/cve202445332_brings_back_branch_target_injection/

ZathuraDbg: Open-Source GUI tool for learning assembly
https://www.reddit.com/r/lowlevel/comments/1ks4em6/zathuradbg_opensource_gui_tool_for_learning/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Authenticated Remote Code Execution in Netwrix Password Secure (CVE-2025-26817)
https://www.reddit.com/r/netsec/comments/1kslcpa/authenticated_remote_code_execution_in_netwrix/

EXP-401 (OSEE):用五天課程訓練通透十年的知識體
https://devco.re/blog/2025/05/22/exp-401-osee-five-days-to-master-a-decade-of-knowledge/

The Voter Experience
https://www.schneier.com/blog/archives/2025/05/the-voter-experience.html

How to Enumerate and Exploit CefSharp Thick Clients Using CefEnum
https://www.reddit.com/r/netsec/comments/1kskq0k/how_to_enumerate_and_exploit_cefsharp_thick/

Automating MS-RPC vulnerability research
https://www.reddit.com/r/netsec/comments/1ksp4m2/automating_msrpc_vulnerability_research/

Live Forensic Collection from Ivanti EPMM Appliances (CVE-2025-4427 & CVE-2025-4428)
https://www.reddit.com/r/netsec/comments/1ksufxv/live_forensic_collection_from_ivanti_epmm/

Oops: DanaBot Malware Devs Infected Their Own PCs
https://krebsonsecurity.com/2025/05/oops-danabot-malware-devs-infected-their-own-pcs/

CVE-2025-32756: Write-Up of a Buffer Overflow in Various Fortinet Products
https://www.reddit.com/r/netsec/comments/1kszzx6/cve202532756_writeup_of_a_buffer_overflow_in/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Signal Blocks Windows Recall
https://www.schneier.com/blog/archives/2025/05/signal-blocks-windows-recall.html

3AM Ransomware Attackers Pose as IT Support to Compromise Networks
https://www.tripwire.com/state-of-security/3am-ransomware-attackers-pose-it-support-compromise-networks

Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE
https://www.reddit.com/r/netsec/comments/1ktjoa8/dont_call_that_protected_method_dissecting_an/

Prime Path Coverage in the GNU Compiler Collection
https://arxiv.org/abs/2505.14694

RoboCulture: A Robotics Platform for Automated Biological Experimentation
https://arxiv.org/abs/2505.14941

Diffusion vs. Autoregressive Language Models: A Text Embedding Perspective
https://arxiv.org/abs/2505.15045

Text Generation Beyond Discrete Token Sampling
https://arxiv.org/abs/2505.14827

One-Layer Transformers are Provably Optimal for In-context Reasoning and Distributional Association Learning in Next-Token Prediction Tasks
https://arxiv.org/abs/2505.15009

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Threat of TCC Bypasses on macOS
https://www.reddit.com/r/netsec/comments/1kvr057/threat_of_tcc_bypasses_on_macos/

26th May – Threat Intelligence Report
https://research.checkpoint.com/2025/26th-may-threat-intelligence-report/

Unauthenticated RCE on Smartbedded MeteoBridge (CVE-2025-4008)
https://www.reddit.com/r/netsec/comments/1kvtr2i/unauthenticated_rce_on_smartbedded_meteobridge/

Windows namespace traversal
https://www.reddit.com/r/lowlevel/comments/1kvtv22/windows_namespace_traversal/

Preparing for the Post Quantum Era: Quantum Ready Architecture for Security and Risk Management (QUASAR) -- A Strategic Framework for Cybersecurity
https://arxiv.org/abs/2505.17084

Improving LLM Outputs Against Jailbreak Attacks with Expert Model Integration
https://arxiv.org/abs/2505.17066

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

PortSwigger Honored with the King's Award for Enterprise in International Trade
https://portswigger.net/blog/portswigger-honored-with-the-kings-award-for-enterprise-in-international-trade

Finding SSRFs in Azure DevOps - Part 2
https://www.reddit.com/r/netsec/comments/1kz0nci/finding_ssrfs_in_azure_devops_part_2/

A detailed guide to Stealth syscall and EDR Bypass
https://www.reddit.com/r/netsec/comments/1kz06v8/a_detailed_guide_to_stealth_syscall_and_edr_bypass/

Why Take9 Won’t Improve Cybersecurity
https://www.schneier.com/blog/archives/2025/05/why-take9-wont-improve-cybersecurity.html

Exploits and vulnerabilities in Q1 2025
https://securelist.com/vulnerabilities-and-exploits-in-q1-2025/116624/

B-XAIC Dataset: Benchmarking Explainable AI for Graph Neural Networks Using Chemical Data
https://arxiv.org/abs/2505.22252

TensorShield: Safeguarding On-Device Inference by Shielding Critical DNN Tensors with TEE
https://arxiv.org/abs/2505.22843

Azure Arc - C2aaS
https://www.reddit.com/r/netsec/comments/1kzfqty/azure_arc_c2aas/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Wireless Pivots: How Trusted Networks Become Invisible Threat Vectors
https://www.reddit.com/r/netsec/comments/1kzttw0/wireless_pivots_how_trusted_networks_become/

Experimenting with USB-Based Attacks: Can a Standard USB Become a Bad USB? (Write-up)
https://www.reddit.com/r/netsec/comments/1l02exx/experimenting_with_usbbased_attacks_can_a/

Beyond HTTP: InterceptSuite for TCP/TLS Traffic Interception in Windows
https://www.reddit.com/r/netsec/comments/1l02jra/beyond_http_interceptsuite_for_tcptls_traffic/

Thought netsec people might enjoy this read - the ultimate guide to different types of wireless signals and what they are used for.
https://www.reddit.com/r/netsec/comments/1l06tm8/thought_netsec_people_might_enjoy_this_read_the/

Reverse Engineer Android Apps for API Key
https://www.reddit.com/r/netsec/comments/1l09vab/reverse_engineer_android_apps_for_api_key/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Certification Roadmap Please
https://www.reddit.com/r/netsec/comments/1l1bsrz/certification_roadmap_please/

Australia Requires Ransomware Victims to Declare Payments
https://www.schneier.com/blog/archives/2025/06/australia-requires-ransomware-victims-to-declare-payments.html

Vulnerabilities Found in Preinstalled Apps on Android Smartphones Could Perform Factory Reset of Device, Exfiltrate PIN Code or Inject an Arbitrary Intent with System-Level Privileges
https://www.reddit.com/r/netsec/comments/1l1fh52/vulnerabilities_found_in_preinstalled_apps_on/

Seeking Insights from Network Security Leaders at Large Companies on Vendor Selection and Challenges
https://www.reddit.com/r/netsec/comments/1l1io63/seeking_insights_from_network_security_leaders_at/

2nd June – Threat Intelligence Report
https://research.checkpoint.com/2025/2nd-june-threat-intelligence-report/

Announcing a New Strategic Collaboration to Bring Clarity to Threat Actor Naming
https://www.microsoft.com/en-us/security/blog/2025/06/02/announcing-a-new-strategic-collaboration-to-bring-clarity-to-threat-actor-naming/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Ramifications of Ukraine’s Drone Attack
https://www.schneier.com/blog/archives/2025/06/the-ramifications-of-ukraines-drone-attack.html

So you want to rapidly run a BOF? Let's look at this 'cli4bofs' thing then
https://www.reddit.com/r/netsec/comments/1l33fxt/so_you_want_to_rapidly_run_a_bof_lets_look_at/

The Ultimate Guide to Windows Coercion Techniques in 2025
https://www.reddit.com/r/netsec/comments/1l3079i/the_ultimate_guide_to_windows_coercion_techniques/

Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities
https://www.reddit.com/r/netsec/comments/1l39v5s/multiple_cves_in_infoblox_netmri_rce_auth_bypass/

2025 Red Team Tools – C2 Frameworks, Active Directory & Network Exploitation
https://bishopfox.com/blog/2025-red-team-tools-c2-frameworks-active-directory-network-exploitation

Detailed research for Roundcube ≤ 1.6.10 Post-Auth RCE is out
https://www.reddit.com/r/netsec/comments/1l3o04q/detailed_research_for_roundcube_1610_postauth_rce/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

IT threat evolution in Q1 2025. Non-mobile statistics
https://securelist.com/malware-report-q1-2025-pc-iot-statistics/116686/

IT threat evolution in Q1 2025. Mobile statistics
https://securelist.com/malware-report-q1-2025-mobile-statistics/116676/

Analysis of Spyware That Helped to Compromise a Syrian Army from Within
https://www.reddit.com/r/netsec/comments/1l3trgn/analysis_of_spyware_that_helped_to_compromise_a/

Meet the Deputy CISOs who help shape Microsoft’s approach to cybersecurity: Part 3
https://www.microsoft.com/en-us/security/blog/2025/06/05/meet-the-deputy-cisos-who-help-shape-microsofts-approach-to-cybersecurity-part-3/

Tnok - Next Generation Port Security
https://www.reddit.com/r/netsec/comments/1l466co/tnok_next_generation_port_security/

Vulnerabilities in Anthropic’s MCP: Full-Schema Poisoning + Secret-Leaking Tool Attacks (PoC Inside)
https://www.reddit.com/r/netsec/comments/1l43aqc/vulnerabilities_in_anthropics_mcp_fullschema/

Proxy Services Feast on Ukraine’s IP Address Exodus
https://krebsonsecurity.com/2025/06/proxy-services-feast-on-ukraines-ip-address-exodus/

DroidGround: Elevate your Android CTF Challenges
https://www.reddit.com/r/netsec/comments/1l4am2x/droidground_elevate_your_android_ctf_challenges/

Cards Are Still the Weakest Link
https://www.reddit.com/r/netsec/comments/1l4brpy/cards_are_still_the_weakest_link/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman