Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Microsoft SharePoint Zero-Day
https://www.schneier.com/blog/archives/2025/07/microsoft-sharepoint-zero-day.html

Social engineering attack obtains data on ‘majority’ of Allianz Life customers
https://therecord.media/allianz-life-social-engineering-data-breach

BadSuccessor – Purple Team
https://www.reddit.com/r/netsec/comments/1mben1v/badsuccessor_purple_team/

An inside look into how a coalition of state legislators plan to take on data brokers
https://therecord.media/state-coalition-lawmakers-data-broker-rules

28th July – Threat Intelligence Report
https://research.checkpoint.com/2025/28th-july-threat-intelligence-report/

Tea app data theft scandal worsens as stolen IDs leaked to cybercriminal forum
https://therecord.media/tea-app-data-breach-stolen-ids-leaked

Cyberattack on Aeroflot causing mass flight disruptions, Russia says
https://therecord.media/cyberattack-aeroflot-russia-delays

Sploitlight: Analyzing a Spotlight-based macOS TCC vulnerability
https://www.microsoft.com/en-us/security/blog/2025/07/28/sploitlight-analyzing-a-spotlight-based-macos-tcc-vulnerability/

Argus – Ultimate Reconnaissance Toolkit for Offensive Recon Operations
https://www.darknet.org.uk/2025/07/argus-ultimate-reconnaissance-toolkit-for-offensive-recon-operations/

Revisiting UNC3886 Tactics to Defend Against Present Risk
https://www.trendmicro.com/en_us/research/25/g/revisiting-unc3886-tactics-to-defend-against-present-risk.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!
https://security.humanativaspa.it/attacking-genai-applications-and-llms-sometimes-all-it-takes-is-to-ask-nicely/

Gunra Ransomware Group Unveils Efficient Linux Variant
https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html

Aeroflot Hacked
https://www.schneier.com/blog/archives/2025/07/aeroflot-hacked.html

Google Gemini AI CLI Hijack - Code Execution Through Deception
https://www.reddit.com/r/netsec/comments/1mc5pdm/google_gemini_ai_cli_hijack_code_execution/

Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms
https://www.reddit.com/r/netsec/comments/1mc5t7b/struts_devmode_in_2025_critical_preauth/

Orange, France’s largest telecoms company, hit by cyberattack
https://therecord.media/orange-telecom-france-cyberattack

Scattered Spider is targeting victims' Snowflake data storage for quick exfiltration
https://therecord.media/scattered-spider-targeting-snowflake-access-data-exfiltration

Minnesota governor activates National Guard after cyberattack on state capital
https://therecord.media/minnesota-governor-activates-national-guard-st-paul-cyber-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Leveraging OSINT from the Dark Web – A Practical How-To
https://www.darknet.org.uk/2025/07/leveraging-osint-from-the-dark-web-a-practical-how-to/

Decryptor released for FunkSec ransomware; Avast works with law enforcement to help victims
https://therecord.media/funksec-ransomware-decryptor-avast

Palo Alto Networks to acquire identity security provider CyberArk in $25 billion deal
https://therecord.media/palo-alto-networks-cyberark-acquisition

Cyberattack shuts down hundreds of Russian pharmacies, disrupts healthcare services
https://therecord.media/cyberattack-shuts-down-russian-pharmacies

IBM: Average cost of a data breach in US shoots to record $10 million
https://therecord.media/ibm-data-breach-report-us-losses

Russia blocks popular US-made internet speed test tool over national security concerns
https://therecord.media/russia-bans-speedtest-ookla

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Engineered to Fail: The DNA of Negligent Cyber Defenses
https://reporter.deepspecter.com/engineered-to-fail-the-dna-of-negligent-cyber-defenses-22466a034b28

Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats
https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/

CISA unveils free Thorium malware analysis platform
https://therecord.media/cisa-unveils-free-malware-analysis-tool

Espionage costing Australia $8 billion each year, warns intelligence chief
https://therecord.media/espionage-costing-australia-8-billion

North Korean hackers targeting open-source repositories in new espionage campaign
https://therecord.media/north-korean-hackers-targeting-open-source-repositories

The State of Ransomware – Q2 2025
https://research.checkpoint.com/2025/the-state-of-ransomware-q2-2025/

Cheating on Quantum Computing Benchmarks
https://www.schneier.com/blog/archives/2025/07/cheating-on-quantum-computing-benchmarks.html

Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations
https://research.checkpoint.com/2025/before-toolshell-exploring-storm-2603s-previous-ransomware-operations/

Biotech contractor settles for $9.8 million with DOJ over alleged cybersecurity lapses
https://therecord.media/illumina-false-claims-act-doj-cybersecurity-settlement

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Luxembourg probes reported attack on Huawei tech that caused nationwide telecoms outage
https://therecord.media/luxembourg-telecom-outage-reported-cyberattack-huawei-tech

Russia’s mobile internet shutdowns hit record high amid Ukrainian drone attacks
https://therecord.media/russia-mobile-internet-shutdowns-record

Spying on People Through Airportr Luggage Delivery Service
https://www.schneier.com/blog/archives/2025/08/spying-on-people-through-airportr-luggage-delivery-service.html

Flo settles class action lawsuit alleging improper data sharing
https://therecord.media/flo-app-settlement-class-action-suit-data-sharing-meta

Hackers leak purported Aeroflot data as Russia denies breach
https://therecord.media/hackers-leak-purported-aeroflot-data

EU preps biometric checks for foreign visitors
https://therecord.media/eu-preps-biometric-checks-travel

It opened the free, online, practical 'Introduction to Security' class from the Czech Technical University.
https://www.reddit.com/r/netsec/comments/1mf29r9/it_opened_the_free_online_practical_introduction/

What the Top 20 OSS Vulnerabilities Reveal About the Real Challenges in Security Governance
https://www.reddit.com/r/netsec/comments/1mfh9ol/what_the_top_20_oss_vulnerabilities_reveal_about/

Friday Squid Blogging: A Case of Squid Fossil Misidentification
https://www.schneier.com/blog/archives/2025/08/friday-squid-blogging-a-case-of-squid-fossil-misidentification.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

4th August – Threat Intelligence Report
https://research.checkpoint.com/2025/4th-august-threat-intelligence-report/

[Need Feedback] Bootloader → Long Mode in pure NASM (15 y.o self-taught dev, 370+ lines so far)
https://www.reddit.com/r/lowlevel/comments/1mghva6/need_feedback_bootloader_long_mode_in_pure_nasm/

PyRIT – AI-Powered Reconnaissance for Cloud Red Teaming
https://www.darknet.org.uk/2025/08/pyrit/

I designed a constant-free cryptographic hash function where entropy fully emerges from the input: Kaoru Hash (public blueprint with code and spec)
https://www.reddit.com/r/netsec/comments/1mh1j25/i_designed_a_constantfree_cryptographic_hash/

Building Bigraphs of the real world
https://arxiv.org/abs/2508.00003

Reasoning under uncertainty in the game of Cops and Robbers
https://arxiv.org/abs/2508.00004

ReVise: A Human-AI Interface for Incremental Algorithmic Recourse
https://arxiv.org/abs/2508.00002

Modelling Program Spaces in Program Synthesis with Constraints
https://arxiv.org/abs/2508.00005

Agent Network Protocol Technical White Paper
https://arxiv.org/abs/2508.00007

Git Context Controller: Manage the Context of LLM-based Agents like Git
https://arxiv.org/abs/2508.00031

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Panel to create roadmap for establishing US Cyber Force
https://therecord.media/panel-to-create-roadmap-cyber-force

First Sentencing in Scheme to Help North Koreans Infiltrate US Companies
https://www.schneier.com/blog/archives/2025/08/first-sentencing-in-scheme-to-help-north-koreans-infiltrate-us-companies.html

Sean Cairncross confirmed as national cyber director
https://therecord.media/sean-cairncross-confirmed-oncd

Hacked Crimean servers reveal information about abducted children, Ukraine says
https://therecord.media/hacked-crimean-servers-abducted-children

Microsoft Entra Suite delivers 131% ROI by unifying identity and network access
https://www.microsoft.com/en-us/security/blog/2025/08/04/microsoft-entra-suite-delivers-131-roi-by-unifying-identity-and-network-access/

Jury ‘sends a message’ on app privacy in ruling against Meta
https://therecord.media/jury-verdict-meta-flo-app-data-privacy-case

SonicWall urges customers to take VPN devices offline after ransomware campaign
https://therecord.media/sonicwall-possible-zero-day-gen-7-firewalls-ssl-vpn

Crypto ATMs fueling criminal activity, Treasury warns
https://therecord.media/crypto-atms-fueling-cybercrime

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Surveilling Your Children with AirTags
https://www.schneier.com/blog/archives/2025/08/surveilling_your_children_with_airtags.html

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle
https://portswigger.net/blog/http-request-smuggling-explained-with-seasoned-bug-bounty-hunter-nahamsec-and-world-class-researcher-james-kettle

3 Custom VT-x Hypervisors in C – EPT Cloaking, CPUID/MSR Spoofing & VMX Control
https://www.reddit.com/r/lowlevel/comments/1mi5txt/3_custom_vtx_hypervisors_in_c_ept_cloaking/

Dutch Caribbean islands respond to cyberattacks on courts, tax departments
https://therecord.media/aruba-curacao-governments-cyberattacks

CVE-2025-54136 – MCPoison Cursor IDE: Persistent Code Execution via MCP Trust Bypass
https://research.checkpoint.com/2025/cursor-vulnerability-mcpoison/

Taiwan’s TSMC fires engineers over suspected theft of semiconductor secrets
https://therecord.media/tsmc-fires-engineers-over-semiconductor-secrets-theft

Vietnamese-speaking hackers appear to be running global data theft operation through Telegram
https://therecord.media/pxa-infostealer-telegram-bots-vietnamese-speaking-hackers

OdooMap - A Pentesting Tool for Odoo Applications
https://www.reddit.com/r/netsec/comments/1micsmu/odoomap_a_pentesting_tool_for_odoo_applications/

Elevate your protection with expanded Microsoft Defender Experts coverage
https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/elevate-your-protection-with-expanded-microsoft-defender-experts-coverage/4439134

Bipartisan Senate duo wants answers from UnitedHealth over Episource data breach
https://therecord.media/episource-data-breach-questions-senators-cassidy-hassan

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Driver of destruction: How a legitimate driver is being used to take down AV processes
https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/

Who Got Arrested in the Raid on the XSS Crime Forum?
https://krebsonsecurity.com/2025/08/who-got-arrested-in-the-raid-on-the-xss-crime-forum/

British intelligence warns cyber threat to critical infrastructure is increasing
https://therecord.media/british-intel-cyber-threat-infrastructure

Hackers using fake summonses in attacks on Ukraine's defense sector
https://therecord.media/hackers-using-fake-summonses-ukraine

Ransomware-as-a-Service Economy – Trends, Targets & Takedowns
https://www.darknet.org.uk/2025/08/ransomware-as-a-service-economy-trends-targets-takedowns/

Sharing practical guidance: Launching Microsoft Secure Future Initiative (SFI) patterns and practices
https://www.microsoft.com/en-us/security/blog/2025/08/06/sharing-practical-guidance-launching-microsoft-secure-future-initiative-sfi-patterns-and-practices/

Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
https://therecord.media/tornado-cash-money-laundering-conviction

Strong regulation can nudge automakers to improve customers’ privacy, research suggests
https://therecord.media/automakers-data-privacy-ratings-websites-customer-portals

HTTP/1.1 Must Die: What This Means for AppSec Leadership
https://portswigger.net/blog/http-1-1-must-die-what-this-means-for-appsec-leadership

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

China Accuses Nvidia of Putting Backdoors into Their Chips
https://www.schneier.com/blog/archives/2025/08/china-accuses-nvidia-of-putting-backdoors-into-their-chips.html

Cyberattack hits France’s third-largest mobile operator, millions of customers affected
https://therecord.media/bouygues-telecom-france-cyberattack-data-breach

CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability
https://therecord.media/microsoft-exchange-server-vulnerability-cisa-alert

Building a Cyber-Aware Workforce: Mexico's Push for Security Training
https://www.tripwire.com/state-of-security/building-cyber-aware-workforce-mexicos-push-security-training

Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault
https://www.reddit.com/r/netsec/comments/1mjzm7g/cracking_the_vault_how_we_found_zeroday_flaws_in/

Announcing public preview: Phishing triage agent in Microsoft Defender
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-phishing-triage-agent-in-microsoft-defender/4438301

We replaced passwords with something worse
https://www.reddit.com/r/netsec/comments/1mk9qsy/we_replaced_passwords_with_something_worse/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

XSSHunter Express – Self-Hosted Blind XSS Payload Capture and Analysis
https://www.darknet.org.uk/2025/08/xsshunter-express-self-hosted-blind-xss-payload-capture-and-analysis/

Next-Level Fingerprinting: Tools, Logic, and Tactics
https://bishopfox.com/blog/next-level-fingerprinting-tools-logic-and-tactics

Automated Visualization Makeovers with LLMs
https://arxiv.org/abs/2508.05637

Request-Only Optimization for Recommendation Systems
https://arxiv.org/abs/2508.05640

A Humanoid Social Robot as a Teaching Assistant in the Classroom
https://arxiv.org/abs/2508.05646

Query-Aware Graph Neural Networks for Enhanced Retrieval-Augmented Generation
https://arxiv.org/abs/2508.05647

AquiLLM: a RAG Tool for Capturing Tacit Knowledge in Research Groups
https://arxiv.org/abs/2508.05648

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Automatic License Plate Readers Are Coming to Schools
https://www.schneier.com/blog/archives/2025/08/automatic-license-plate-readers-are-coming-to-schools.html

Building an Autonomous AI Pentester: What Worked, What Didn’t, and Why It Matters
https://www.reddit.com/r/netsec/comments/1mnaugi/building_an_autonomous_ai_pentester_what_worked/

11th August – Threat Intelligence Report
https://research.checkpoint.com/2025/11th-august-threat-intelligence-report/

Wikipedia’s operator loses challenge to UK Online Safety Act rules
https://therecord.media/wikipedia-loses-challenge-online-safety-act-uk

Finland charges captain of suspected Russian ‘shadow fleet’ tanker for subsea cable damage
https://therecord.media/finland-charges-captain-russia-ghost-fleet-undersea-cable

Two groups exploit WinRAR flaws in separate cyber-espionage campaigns
https://therecord.media/winrar-zero-day-exploited-romcom-paper-werewolf-goffee-hackers

Romance scam suspects extradited from Ghana, charged with more than $100 million in thefts
https://therecord.media/ghana-romance-scams-bec-suspects-extradited-us

Ransomware gang claims attack on St. Paul city government
https://therecord.media/ransomware-gang-behind-minnesota-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises
https://www.trendmicro.com/en_us/research/25/h/new-ransomware-charon.html

The “Incriminating Video” Scam
https://www.schneier.com/blog/archives/2025/08/the-incriminating-video-scam.html

Second ransomware attack in two months disrupts South Korean ticketing giant
https://therecord.media/yes24-second-ransomware-attack-kpop-ticketing-affected

Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
https://blog.qualys.com/qualys-insights/2025/08/12/two-pwnie-awards-one-crucial-lesson-what-our-openssh-research-reveals-about-cyber-defense-in-2025

New Charon ransomware targets Middle East public sector, aviation firms
https://therecord.media/charon-ransomware-targeting-middle-east-aviation

DEF CON volunteers step up to help water sector after China, Iran attack utilities
https://therecord.media/def-con-franklin-water-utility-cybersecurity-volunteers

Dow’s 125-year legacy: Innovating with AI to secure a long future
https://www.microsoft.com/en-us/security/blog/2025/08/12/dows-125-year-legacy-innovating-with-ai-to-secure-a-long-future/

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/netsec/comments/1mof7r5/zero_click_one_ntlm_microsoft_security_patch/

Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/08/12/microsoft-and-adobe-patch-tuesday-august-2025-security-update-review

Microsoft Patch Tuesday, August 2025 Edition
https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
https://therecord.media/matrix-messaging-protocol-high-severity-vulnerabilities

Pennsylvania attorney general says cyberattack knocked phone, email systems offline
https://therecord.media/pennsylvania-attorney-general-office-cyberattack

Estonians behind multimillion-dollar crypto fraud sentenced
https://therecord.media/estonians-behind-multimillion-dollar-crypto-fraud-sentenced

New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts
https://therecord.media/zelle-lawsuit-new-york-state-scams-fraud

Curly threat actor found targeting sensitive organizations in Georgia, Moldova
https://therecord.media/curly-threat-actor-targeting-moldova

AI Applications in Cybersecurity
https://www.schneier.com/blog/archives/2025/08/ai-applications-in-cybersecurity.html

Best Kickass (KAT) Alternatives & Live Torrent Trackers in 2025 – Public, Private, and Legal Picks
https://www.darknet.org.uk/2025/08/best-kickass-alternatives-live-torrent-trackers-in-2025-public-private-and-legal-picks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

N/A
N/A

Taming Shadow IT: What Security Teams Can Do About Unapproved Apps and Extensions
https://www.tripwire.com/state-of-security/taming-shadow-it-what-security-teams-can-do-about-unapproved-apps-and-extensions

LLM Coding Integrity Breach
https://www.schneier.com/blog/archives/2025/08/llm-coding-integrity-breach.html

Tens of thousands of Italian hotel guests may be hit by cyber heist
https://therecord.media/italy-hotel-guests-possible-data-breach-ids

Russia curbs WhatsApp, Telegram calls to counter cybercrime
https://therecord.media/russia-restricts-voice-calls-whatsapp-telegram-cybercrime

Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability
https://therecord.media/hackers-compromise-canada-house-of-commons

FCC’s data breach reporting rules for telecoms are upheld in appeals court
https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court

Norway police believe pro-Russian hackers were behind April dam sabotage
https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage

Turkish crypto exchange BTCTurk warns of security incident after $49 million leaves platform
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident

US updates sanctions on Russian cryptocurrency exchange Garantex
https://therecord.media/treasury-department-renews-sanctions-garantex-grinex

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msre41/how_exposed_teslamate_instances_leak_sensitive/

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msrpi6/how_exposed_teslamate_instances_leak_sensitive/

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool
https://www.darknet.org.uk/2025/08/lostmypassword-dual-use-password-recovery-and-credential-dumping-tool/

Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
https://securelist.com/pipemagic/117270/

A Rose by Any Other Name Would Smell as Sweet: Categorical Homotopy Theory for Large Language Models
https://arxiv.org/abs/2508.10043

A2HCoder: An LLM-Driven Coding Agent for Hierarchical Algorithm-to-HDL Translation
https://arxiv.org/abs/2508.10903

PersonaTwin: A Multi-Tier Prompt Conditioning Framework for Generating and Evaluating Personalized Digital Twins
https://arxiv.org/abs/2508.10904

Uncovering Latent Connections in Indigenous Heritage: Semantic Pipelines for Cultural Preservation in Brazil
https://arxiv.org/abs/2508.10906

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
https://arxiv.org/abs/2508.10911

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman