Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Approach to mainframe penetration testing on z/OS. Deep dive into RACF
https://securelist.com/zos-mainframe-pentesting-resource-access-control-facility/116873/

Lateral Movement with code execution in the context of active user sessions
https://www.reddit.com/r/netsec/comments/1lunnbw/lateral_movement_with_code_execution_in_the/

Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
https://www.reddit.com/r/netsec/comments/1luix11/abusing_windows_net_quirks_and_unicode/

[CVE-2025-32461] Tiki Wiki CMS Groupware <= 28.3 Two SSTI Vulnerabilities
https://www.reddit.com/r/netsec/comments/1lukohx/cve202532461_tiki_wiki_cms_groupware_283_two_ssti/

New Attack on TLS: Opossum attack
https://www.reddit.com/r/netsec/comments/1lunm8t/new_attack_on_tls_opossum_attack/

New spyware strain steals data from Russian industrial companies
https://therecord.media/spyware-strain-steals-data-russian-industrial-sector

Bitchat MITM Flaw
https://www.reddit.com/r/netsec/comments/1lus5jg/bitchat_mitm_flaw/

Iranian ransomware group offers bigger payouts for attacks on Israel, US
https://therecord.media/iran-ransomware-group-pay2keyi2p-israel-us-targets

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Yet Another Strava Privacy Leak
https://www.schneier.com/blog/archives/2025/07/yet-another-strava-privacy-leak.html

Fake CNN and BBC sites used to push investment scams
https://therecord.media/news-websites-faked-to-spread-investment-scams

Jack Dorsey Unveils Offline Messaging App ‘Bitchat’ with No Internet, Servers, or Accounts
https://www.reddit.com/r/netsec/comments/1lvk3j9/jack_dorsey_unveils_offline_messaging_app_bitchat/

French intel chief warns of evolving Russian hybrid operations, ‘existential threat’ to Europe
https://therecord.media/french-intelligence-chief-russia-threat

Uncovering Privilege Escalation Bugs in Lenovo Vantage — Atredis Partners
https://www.reddit.com/r/netsec/comments/1lvmj5p/uncovering_privilege_escalation_bugs_in_lenovo/

Microsoft expands Zero Trust workshop to cover network, SecOps, and more
https://www.microsoft.com/en-us/security/blog/2025/07/09/microsoft-expands-zero-trust-workshop-to-cover-network-secops-and-more/

More than $40 million stolen from GMX crypto platform
https://therecord.media/gmx-exchange-cryptocurrency-stolen

Driver's license numbers, addresses leaked in 2024 bitcoin ATM company breach
https://therecord.media/bitcoin-depot-cryptocurrency-atm-company-data-breach

German court rules Meta tracking technology violates European privacy laws
https://www.reddit.com/r/netsec/comments/1lvmj5p/uncovering_privilege_escalation_bugs_in_lenovo/

You’re Pen Testing AI Wrong: Why Prompt Engineering Isn’t Enough
https://bishopfox.com/blog/youre-pen-testing-ai-wrong-why-prompt-engineering-isnt-enough

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The GPS Leak No One Talked About: Uffizio’s Silent Exposure
https://reporter.deepspecter.com/the-gps-leak-no-one-talked-about-uffizios-silent-exposure-03b5dfb23556

Four arrested by UK police over ransomware attacks on M&S, Co-op and Harrods
https://therecord.media/uk-arrests-four-ransomware-ms-harrods-co-op

Code highlighting with Cursor AI for $500,000
https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/

Using Signal Groups for Activism
https://www.schneier.com/blog/archives/2025/07/using-signal-groups-for-activism.html

Iranian APTs increased activity against US industries in late spring, researchers say
https://therecord.media/iran-state-backed-hackers-industrial-attacks-spring-2025

Qantas says 5.7 million affected by breach, leaked info not enough to access frequent flyer accounts
https://therecord.media/qantas-airline-data-breach-frequent-flyer-numbers

The head of the California Privacy Protection Agency on the future of data privacy regulation
https://therecord.media/california-privacy-protection-agency-tom-kemp-interview

Russian basketball player arrested in France over alleged ransomware ties
https://therecord.media/russian-basketball-player-arrested-in-france-ransomware

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Spain awards Huawei contracts to manage intelligence agency wiretaps
https://therecord.media/spain-awards-contracts-huawei-intelligence-agency-wiretaps

DeepSeek a threat to national security, warns Czech cyber agency
https://therecord.media/deepseek-security-czech-cyber-agency-warning

Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1lx360q/preauth_sql_injection_to_rce_fortinet_fortiweb/

Indonesia extradites Russian accused of selling personal data on Telegram
https://therecord.media/indonesia-extradites-russian-telegram-sale

CISA orders agencies to immediately patch Citrix Bleed 2, saying bug poses ‘unacceptable risk’
https://therecord.media/cisa-orders-agencies-patch-citrix-bleed-2

Hacker returns cryptocurrency stolen from GMX exchange after $5 million bounty payment
https://therecord.media/hacker-returns-stolen-gmx-bounty

Airline executive agrees to dismiss litigation around alleged hack-for-hire scheme
https://therecord.media/airline-exec-agrees-to-dismiss-hack-for-hire-lawsuit

Albemarle latest Virginia county hit with ransomware
https://therecord.media/albemarle-virginia-ransomware-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Revisiting automating MS-RPC vulnerability research and making the tool open source
https://www.reddit.com/r/netsec/comments/1lzh1t5/revisiting_automating_msrpc_vulnerability/

Forensic journey: Breaking down the UserAssist artifact structure
https://securelist.com/userassist-artifact-forensic-value-for-incident-response/116911/

Securing Against Phishing Beyond Email
https://www.tripwire.com/state-of-security/securing-against-phishing-beyond-email

Fooling the Sandbox: A Chrome-atic Escape
https://www.reddit.com/r/netsec/comments/1lzj3jt/fooling_the_sandbox_a_chromeatic_escape/

Romanian police arrest 13 scammers targeting UK’s tax authority
https://therecord.media/romania-arrests-tax-fraud-ring-britain-hmrc

14th July – Threat Intelligence Report
https://research.checkpoint.com/2025/14th-july-threat-intelligence-report/

[CVE-2024-58258] SugarCRM <= 14.0.0 (css/preview) LESS Code Injection Vulnerability
https://www.reddit.com/r/netsec/comments/1lzgkiv/cve202458258_sugarcrm_1400_csspreview_less_code/

Watch the on-demand webinar: Shift left without the strain
https://portswigger.net/blog/watch-the-on-demand-webinar-shift-left-without-the-strain

Improving IT efficiency with Microsoft Security Copilot in Microsoft Intune and Microsoft Entra
https://www.microsoft.com/en-us/security/blog/2025/07/14/improving-it-efficiency-with-microsoft-security-copilot-in-microsoft-intune-and-microsoft-entra/

CVE-2025-5333 - CVSS 9.5: Remote Code Execution in Broadcom Symantec Endpoint Management Suite (Altiris)
https://www.reddit.com/r/netsec/comments/1lzo9wz/cve20255333_cvss_95_remote_code_execution_in/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-5333 - CVSS 9.5: Remote Code Execution in Broadcom Symantec Endpoint Management Suite (Altiris)
https://www.reddit.com/r/netsec/comments/1lzo9wz/cve20255333_cvss_95_remote_code_execution_in/

Louis Vuitton says customers in Turkey, South Korea and UK impacted by data breaches
https://therecord.media/louis-vuitton-says-customers-impacted-by-data-breaches

CISA's NIMBUS 2000 Initiative: Understanding Key Findings and Strengthening Cloud Identity Security
https://www.trendmicro.com/en_us/research/25/g/nimbus-2000-initiative-findings.html

NSA: Volt Typhoon was ‘not successful’ at persisting in critical infrastructure
https://therecord.media/china-typhoon-hackers-nsa-fbi-response

Google says ‘Big Sleep’ AI tool found bug hackers planned to use
https://therecord.media/google-big-sleep-ai-tool-found-bug

Homebrew Malware Campaign
https://www.reddit.com/r/netsec/comments/1m0i0cw/homebrew_malware_campaign/

Weaponizing Windows Drivers: A Hacker's Guide for Beginners
https://www.reddit.com/r/netsec/comments/1m0h8np/weaponizing_windows_drivers_a_hackers_guide_for/

RAG Safety: Exploring Knowledge Poisoning Attacks to Retrieval-Augmented Generation
https://arxiv.org/abs/2507.08862

Tangma: A Tanh-Guided Activation Function with Learnable Parameters
https://arxiv.org/abs/2507.10560

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Code Execution Through Email: How I Used Claude to Hack Itself
https://www.reddit.com/r/netsec/comments/1m17ec3/code_execution_through_email_how_i_used_claude_to/

Does Your Organization Need Deepfake Defenses?
https://www.tripwire.com/state-of-security/does-your-organization-need-deepfake-defenses

Enterprise RAID Data Recovery Solution – Comprehensive Technical Evaluation
https://www.reddit.com/r/netsec/comments/1m17ent/enterprise_raid_data_recovery_solution/

21-year-old former US soldier pleads guilty to hacking, extorting telecoms
https://therecord.media/cameron-john-wagenius-former-us-soldier-guilty-plea-hacking

Ukraine-aligned hackers claim cyberattack on major Russian drone supplier
https://therecord.media/ukraine-hackers-claim-attack-russia-gaskar-group-drone-maker

Senate panel passes Intelligence Authorization Act that takes aim at telecom hacks
https://therecord.media/senate-panel-passes-intel-act-salt-typhoon-china

PSA: CrystalDiskInfo & CrystalDiskMark now embeds adwares /!\
https://www.reddit.com/r/netsec/comments/1m19cp1/psa_crystaldiskinfo_crystaldiskmark_now_embeds/

New MITRE framework takes aim at crypto threats
https://www.reddit.com/r/netsec/comments/1m1b46y/new_mitre_framework_takes_aim_at_crypto_threats/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Security Vulnerabilities in ICEBlock
https://www.schneier.com/blog/archives/2025/07/security-vulnerabilities-in-iceblock.html

Chainalysis: $2.17 billion in crypto stolen in first half of 2025, driven by North Korean hacks
https://therecord.media/chainalysis-crypto-stolen-billions

Automated Function ID Database Generation in Ghidra on Windows
https://www.reddit.com/r/netsec/comments/1m254kt/automated_function_id_database_generation_in/

FCC wants to ban Chinese tech from undersea cables
https://therecord.media/fcc-plans-to-ban-chinese-tech-undersea-cables

Bypassing root detection and RASP in sensitive Android apps
https://www.reddit.com/r/netsec/comments/1m26i6a/bypassing_root_detection_and_rasp_in_sensitive/

Elite Russian university launches degree program on sanctions evasion
https://therecord.media/russian-university-sanctions-evasion-degree

UK NCA officer jailed for stealing bitcoin from darknet criminal he previously helped investigate
https://therecord.media/former-uk-nca-officer-jailed-stealing-bitcoin-from-criminal

Roblox introduces age estimation technology for unfiltered chats
https://therecord.media/roblox-age-verification-technology-unfiltered-chats

Transparency on Microsoft Defender for Office 365 email security effectiveness
https://www.microsoft.com/en-us/security/blog/2025/07/17/transparency-on-microsoft-defender-for-office-365-email-security-effectiveness/

Real-time CVE feed with filters, summaries, and email alerts
https://www.reddit.com/r/netsec/comments/1m296mp/realtime_cve_feed_with_filters_summaries_and/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Breaking: UK sanctions Russian cyber spies accused of facilitating murders
https://therecord.media/uk-sanctions-gru-personnel-accused-murder-civilians-ukraine

New Mobile Phone Forensics Tool
https://www.schneier.com/blog/archives/2025/07/new-mobile-phone-forensics-tool.html

Microsoft at Black Hat USA 2025: A unified approach to modern cyber defense
https://techcommunity.microsoft.com/blog/microsoft-security-blog/%e2%80%8b%e2%80%8bmicrosoft-at-black-hat-usa-2025-a-unified-approach-to-modern-cyber-defense%e2%80%8b%e2%80%8b/4434292

Japanese police release decryptor for Phobos ransomware after February takedown
https://therecord.media/decryptor-phobos-8base-ransomware-japan-national-police

Singapore accuses Chinese state-backed hackers of attacking critical infrastructure networks
https://therecord.media/singapore-accuses-chinese-backed-hackers-critical-infrastructure-attacks

Securing Tomorrow: An Interview with Trend Micro VP of Product Management Michael Habibi
https://www.trendmicro.com/en_us/research/25/g/endpoint-protection-epp-gartner-magic-quadrant-july-2025.html

Friday Squid Blogging: The Giant Squid Nebula
https://www.schneier.com/blog/archives/2025/07/friday-squid-blogging-the-giant-squid-nebula.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Looking for a C and x64 NASM asm (linux) study buddy. Complete beginners welcome, I also included all the steps for setting up Debian 12 in a VM for accessibility. malware analysis after foundations learned
https://www.reddit.com/r/lowlevel/comments/1m48nv2/looking_for_a_c_and_x64_nasm_asm_linux_study/

Legless: IPv6 Penetration Testing – Real Attacks via RA, RDNSS, and DHCPv6 Spoofing
https://www.reddit.com/r/netsec/comments/1m4jllp/legless_ipv6_penetration_testing_real_attacks_via/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Internet Red Button: a 2016 Bug Still Lets Anyone Kill Solar Farms in 3 Clicks
https://reporter.deepspecter.com/the-internet-red-button-a-2016-bug-still-lets-anyone-kill-solar-farms-in-3-clicks-042eeca7df33

Warnings issued as hackers actively exploit critical zero-day in Microsoft SharePoint
https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally

Another Supply Chain Vulnerability
https://www.schneier.com/blog/archives/2025/07/another-supply-chain-vulnerability.html

A Novel Technique for SQL Injection in PDO’s Prepared Statements
https://arxiv.org/abs/2507.14139

The Internet Red Button: a 2016 Bug Still Lets Anyone Kill Solar Farms in 3 Clicks
https://www.reddit.com/r/netsec/comments/1m5g4ok/the_internet_red_button_a_2016_bug_still_lets/

Understanding the Impact of Scattered Spider on the Airline & Transportation Industry
https://blog.qualys.com/product-tech/2025/07/21/understanding-the-impact-of-scattered-spider-on-the-airline-transportation-industry

New malware samples exfiltrate WhatsApp data to target Iran regime’s enemies
https://therecord.media/malware-exfiltrates-whatsapp-iran-muddywater

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New York unveils new cyber regulations, $2.5 million grant program for water systems
https://therecord.media/new-york-cyber-regulations-water-grants

Google Sues the Badbox Botnet Operators
https://www.schneier.com/blog/archives/2025/07/google-sues-the-badbox-botnet-operators.html

[CVE-2025-48932] Invision Community <= 4.7.20 (calendar/view.php) SQL Injection Vulnerability
https://www.reddit.com/r/netsec/comments/1m757kw/cve202548932_invision_community_4720/

The Guest Who Could: Exploiting LPE in VMWare Tools
https://www.reddit.com/r/netsec/comments/1m77439/the_guest_who_could_exploiting_lpe_in_vmware_tools/

Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack
https://therecord.media/clorox-cyberattack-lawsuit-cognizant-it-contractor

Suspected admin of major dark web cybercrime forum arrested in Ukraine
https://therecord.media/suspected-xss-cybercrime-marketplace-admin-arrested

Active Exploitation of Microsoft SharePoint Vulnerabilities
https://www.reddit.com/r/netsec/comments/1m7bv48/active_exploitation_of_microsoft_sharepoint/

Hijacking Cursor’s Agent: How We Took Over an EC2 Instance
https://www.reddit.com/r/netsec/comments/1m7dbjp/hijacking_cursors_agent_how_we_took_over_an_ec2/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Solid Protocol Restores Digital Agency
https://www.schneier.com/blog/archives/2025/07/how-solid-protocol-restores-digital-agency.html

SharePoint ToolShell – One Request PreAuth RCE Chain
https://www.reddit.com/r/netsec/comments/1m826b7/sharepoint_toolshell_one_request_preauth_rce_chain/

FBI: Thousands of people involved in 'The Com' targeting victims with ransomware, swatting
https://therecord.media/fbi-the-com-ransomware-swatting-alert

Stealthy cyber spies linked to China compromising virtualization software globally
https://therecord.media/stealthy-china-spies-fire-ant-virtualization-software

Ukraine's deputy defense minister for digital affairs steps down
https://therecord.media/ukraine-deputy-defense-minister-digital-affairs-kateryna-chernohorenko-steps-down

Microsoft says Warlock ransomware deployed in SharePoint attacks as governments scramble
https://therecord.media/microsoft-says-warlock-ransomware-deployed-in-sharepoint-attacks

Phishers Target Aviation Execs to Scam Customers
https://krebsonsecurity.com/2025/07/phishers-target-aviation-execs-to-scam-customers/

Fortifying Your Cloud Against Cross-Service Confused Deputy Attacks
https://blog.qualys.com/vulnerabilities-threat-research/2025/07/24/fortifying-your-cloud-against-cross-service-confused-deputy-attacks

CastleLoader Malware: Fake GitHub and Phishing Attack Hits 469 Devices
https://www.reddit.com/r/netsec/comments/1m8fw3d/castleloader_malware_fake_github_and_phishing/

Proactive Email Security: The Power of AI
https://www.trendmicro.com/en_us/research/25/g/proactive-email-security.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

BlackSuit ransomware gang’s darknet websites seized by police
https://therecord.media/blacksuit-ransomware-gang-website-takedown

Subliminal Learning in AIs
https://www.schneier.com/blog/archives/2025/07/subliminal-learning-in-ais.html

How we Rooted Copilot
https://www.reddit.com/r/netsec/comments/1m8wqdd/how_we_rooted_copilot/

Arizona woman sentenced to 8.5 years for running North Korean laptop farm
https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm

Despite changes, crisis pregnancy centers still attract scrutiny over HIPAA promises
https://therecord.media/crisis-pregnancy-centers-hipaa-data-privacy

How We Gained Full Access to a $100M Zero-Trust Startup
https://www.reddit.com/r/netsec/comments/1m908uy/how_we_gained_full_access_to_a_100m_zerotrust/

NASCAR confirms data breach after March cyberattack
https://therecord.media/nascar-confirms-data-breach

Friday Squid Blogging: Stable Quasi-Isodynamic Designs
https://www.schneier.com/blog/archives/2025/07/friday-squid-blogging-stable-quasi-isodynamic-designs.html

The average ransomware attack payment increased nearly 500% from 2023 to 2024.
https://www.reddit.com/r/netsec/comments/1m9bhd5/the_average_ransomware_attack_payment_increased/

Admin Emails & Passwords Exposed via HTTP Method Change
https://www.reddit.com/r/netsec/comments/1m9gwr0/admin_emails_passwords_exposed_via_http_method/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman