Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!
https://security.humanativaspa.it/attacking-genai-applications-and-llms-sometimes-all-it-takes-is-to-ask-nicely/

Gunra Ransomware Group Unveils Efficient Linux Variant
https://www.trendmicro.com/en_us/research/25/g/gunra-ransomware-linux-variant.html

Aeroflot Hacked
https://www.schneier.com/blog/archives/2025/07/aeroflot-hacked.html

Google Gemini AI CLI Hijack - Code Execution Through Deception
https://www.reddit.com/r/netsec/comments/1mc5pdm/google_gemini_ai_cli_hijack_code_execution/

Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms
https://www.reddit.com/r/netsec/comments/1mc5t7b/struts_devmode_in_2025_critical_preauth/

Orange, France’s largest telecoms company, hit by cyberattack
https://therecord.media/orange-telecom-france-cyberattack

Scattered Spider is targeting victims' Snowflake data storage for quick exfiltration
https://therecord.media/scattered-spider-targeting-snowflake-access-data-exfiltration

Minnesota governor activates National Guard after cyberattack on state capital
https://therecord.media/minnesota-governor-activates-national-guard-st-paul-cyber-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Leveraging OSINT from the Dark Web – A Practical How-To
https://www.darknet.org.uk/2025/07/leveraging-osint-from-the-dark-web-a-practical-how-to/

Decryptor released for FunkSec ransomware; Avast works with law enforcement to help victims
https://therecord.media/funksec-ransomware-decryptor-avast

Palo Alto Networks to acquire identity security provider CyberArk in $25 billion deal
https://therecord.media/palo-alto-networks-cyberark-acquisition

Cyberattack shuts down hundreds of Russian pharmacies, disrupts healthcare services
https://therecord.media/cyberattack-shuts-down-russian-pharmacies

IBM: Average cost of a data breach in US shoots to record $10 million
https://therecord.media/ibm-data-breach-report-us-losses

Russia blocks popular US-made internet speed test tool over national security concerns
https://therecord.media/russia-bans-speedtest-ookla

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Engineered to Fail: The DNA of Negligent Cyber Defenses
https://reporter.deepspecter.com/engineered-to-fail-the-dna-of-negligent-cyber-defenses-22466a034b28

Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats
https://www.microsoft.com/en-us/security/blog/2025/07/31/frozen-in-transit-secret-blizzards-aitm-campaign-against-diplomats/

CISA unveils free Thorium malware analysis platform
https://therecord.media/cisa-unveils-free-malware-analysis-tool

Espionage costing Australia $8 billion each year, warns intelligence chief
https://therecord.media/espionage-costing-australia-8-billion

North Korean hackers targeting open-source repositories in new espionage campaign
https://therecord.media/north-korean-hackers-targeting-open-source-repositories

The State of Ransomware – Q2 2025
https://research.checkpoint.com/2025/the-state-of-ransomware-q2-2025/

Cheating on Quantum Computing Benchmarks
https://www.schneier.com/blog/archives/2025/07/cheating-on-quantum-computing-benchmarks.html

Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations
https://research.checkpoint.com/2025/before-toolshell-exploring-storm-2603s-previous-ransomware-operations/

Biotech contractor settles for $9.8 million with DOJ over alleged cybersecurity lapses
https://therecord.media/illumina-false-claims-act-doj-cybersecurity-settlement

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Luxembourg probes reported attack on Huawei tech that caused nationwide telecoms outage
https://therecord.media/luxembourg-telecom-outage-reported-cyberattack-huawei-tech

Russia’s mobile internet shutdowns hit record high amid Ukrainian drone attacks
https://therecord.media/russia-mobile-internet-shutdowns-record

Spying on People Through Airportr Luggage Delivery Service
https://www.schneier.com/blog/archives/2025/08/spying-on-people-through-airportr-luggage-delivery-service.html

Flo settles class action lawsuit alleging improper data sharing
https://therecord.media/flo-app-settlement-class-action-suit-data-sharing-meta

Hackers leak purported Aeroflot data as Russia denies breach
https://therecord.media/hackers-leak-purported-aeroflot-data

EU preps biometric checks for foreign visitors
https://therecord.media/eu-preps-biometric-checks-travel

It opened the free, online, practical 'Introduction to Security' class from the Czech Technical University.
https://www.reddit.com/r/netsec/comments/1mf29r9/it_opened_the_free_online_practical_introduction/

What the Top 20 OSS Vulnerabilities Reveal About the Real Challenges in Security Governance
https://www.reddit.com/r/netsec/comments/1mfh9ol/what_the_top_20_oss_vulnerabilities_reveal_about/

Friday Squid Blogging: A Case of Squid Fossil Misidentification
https://www.schneier.com/blog/archives/2025/08/friday-squid-blogging-a-case-of-squid-fossil-misidentification.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

4th August – Threat Intelligence Report
https://research.checkpoint.com/2025/4th-august-threat-intelligence-report/

[Need Feedback] Bootloader → Long Mode in pure NASM (15 y.o self-taught dev, 370+ lines so far)
https://www.reddit.com/r/lowlevel/comments/1mghva6/need_feedback_bootloader_long_mode_in_pure_nasm/

PyRIT – AI-Powered Reconnaissance for Cloud Red Teaming
https://www.darknet.org.uk/2025/08/pyrit/

I designed a constant-free cryptographic hash function where entropy fully emerges from the input: Kaoru Hash (public blueprint with code and spec)
https://www.reddit.com/r/netsec/comments/1mh1j25/i_designed_a_constantfree_cryptographic_hash/

Building Bigraphs of the real world
https://arxiv.org/abs/2508.00003

Reasoning under uncertainty in the game of Cops and Robbers
https://arxiv.org/abs/2508.00004

ReVise: A Human-AI Interface for Incremental Algorithmic Recourse
https://arxiv.org/abs/2508.00002

Modelling Program Spaces in Program Synthesis with Constraints
https://arxiv.org/abs/2508.00005

Agent Network Protocol Technical White Paper
https://arxiv.org/abs/2508.00007

Git Context Controller: Manage the Context of LLM-based Agents like Git
https://arxiv.org/abs/2508.00031

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Panel to create roadmap for establishing US Cyber Force
https://therecord.media/panel-to-create-roadmap-cyber-force

First Sentencing in Scheme to Help North Koreans Infiltrate US Companies
https://www.schneier.com/blog/archives/2025/08/first-sentencing-in-scheme-to-help-north-koreans-infiltrate-us-companies.html

Sean Cairncross confirmed as national cyber director
https://therecord.media/sean-cairncross-confirmed-oncd

Hacked Crimean servers reveal information about abducted children, Ukraine says
https://therecord.media/hacked-crimean-servers-abducted-children

Microsoft Entra Suite delivers 131% ROI by unifying identity and network access
https://www.microsoft.com/en-us/security/blog/2025/08/04/microsoft-entra-suite-delivers-131-roi-by-unifying-identity-and-network-access/

Jury ‘sends a message’ on app privacy in ruling against Meta
https://therecord.media/jury-verdict-meta-flo-app-data-privacy-case

SonicWall urges customers to take VPN devices offline after ransomware campaign
https://therecord.media/sonicwall-possible-zero-day-gen-7-firewalls-ssl-vpn

Crypto ATMs fueling criminal activity, Treasury warns
https://therecord.media/crypto-atms-fueling-cybercrime

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Surveilling Your Children with AirTags
https://www.schneier.com/blog/archives/2025/08/surveilling_your_children_with_airtags.html

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle
https://portswigger.net/blog/http-request-smuggling-explained-with-seasoned-bug-bounty-hunter-nahamsec-and-world-class-researcher-james-kettle

3 Custom VT-x Hypervisors in C – EPT Cloaking, CPUID/MSR Spoofing & VMX Control
https://www.reddit.com/r/lowlevel/comments/1mi5txt/3_custom_vtx_hypervisors_in_c_ept_cloaking/

Dutch Caribbean islands respond to cyberattacks on courts, tax departments
https://therecord.media/aruba-curacao-governments-cyberattacks

CVE-2025-54136 – MCPoison Cursor IDE: Persistent Code Execution via MCP Trust Bypass
https://research.checkpoint.com/2025/cursor-vulnerability-mcpoison/

Taiwan’s TSMC fires engineers over suspected theft of semiconductor secrets
https://therecord.media/tsmc-fires-engineers-over-semiconductor-secrets-theft

Vietnamese-speaking hackers appear to be running global data theft operation through Telegram
https://therecord.media/pxa-infostealer-telegram-bots-vietnamese-speaking-hackers

OdooMap - A Pentesting Tool for Odoo Applications
https://www.reddit.com/r/netsec/comments/1micsmu/odoomap_a_pentesting_tool_for_odoo_applications/

Elevate your protection with expanded Microsoft Defender Experts coverage
https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/elevate-your-protection-with-expanded-microsoft-defender-experts-coverage/4439134

Bipartisan Senate duo wants answers from UnitedHealth over Episource data breach
https://therecord.media/episource-data-breach-questions-senators-cassidy-hassan

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Driver of destruction: How a legitimate driver is being used to take down AV processes
https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/

Who Got Arrested in the Raid on the XSS Crime Forum?
https://krebsonsecurity.com/2025/08/who-got-arrested-in-the-raid-on-the-xss-crime-forum/

British intelligence warns cyber threat to critical infrastructure is increasing
https://therecord.media/british-intel-cyber-threat-infrastructure

Hackers using fake summonses in attacks on Ukraine's defense sector
https://therecord.media/hackers-using-fake-summonses-ukraine

Ransomware-as-a-Service Economy – Trends, Targets & Takedowns
https://www.darknet.org.uk/2025/08/ransomware-as-a-service-economy-trends-targets-takedowns/

Sharing practical guidance: Launching Microsoft Secure Future Initiative (SFI) patterns and practices
https://www.microsoft.com/en-us/security/blog/2025/08/06/sharing-practical-guidance-launching-microsoft-secure-future-initiative-sfi-patterns-and-practices/

Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
https://therecord.media/tornado-cash-money-laundering-conviction

Strong regulation can nudge automakers to improve customers’ privacy, research suggests
https://therecord.media/automakers-data-privacy-ratings-websites-customer-portals

HTTP/1.1 Must Die: What This Means for AppSec Leadership
https://portswigger.net/blog/http-1-1-must-die-what-this-means-for-appsec-leadership

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

China Accuses Nvidia of Putting Backdoors into Their Chips
https://www.schneier.com/blog/archives/2025/08/china-accuses-nvidia-of-putting-backdoors-into-their-chips.html

Cyberattack hits France’s third-largest mobile operator, millions of customers affected
https://therecord.media/bouygues-telecom-france-cyberattack-data-breach

CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability
https://therecord.media/microsoft-exchange-server-vulnerability-cisa-alert

Building a Cyber-Aware Workforce: Mexico's Push for Security Training
https://www.tripwire.com/state-of-security/building-cyber-aware-workforce-mexicos-push-security-training

Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault
https://www.reddit.com/r/netsec/comments/1mjzm7g/cracking_the_vault_how_we_found_zeroday_flaws_in/

Announcing public preview: Phishing triage agent in Microsoft Defender
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-phishing-triage-agent-in-microsoft-defender/4438301

We replaced passwords with something worse
https://www.reddit.com/r/netsec/comments/1mk9qsy/we_replaced_passwords_with_something_worse/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

XSSHunter Express – Self-Hosted Blind XSS Payload Capture and Analysis
https://www.darknet.org.uk/2025/08/xsshunter-express-self-hosted-blind-xss-payload-capture-and-analysis/

Next-Level Fingerprinting: Tools, Logic, and Tactics
https://bishopfox.com/blog/next-level-fingerprinting-tools-logic-and-tactics

Automated Visualization Makeovers with LLMs
https://arxiv.org/abs/2508.05637

Request-Only Optimization for Recommendation Systems
https://arxiv.org/abs/2508.05640

A Humanoid Social Robot as a Teaching Assistant in the Classroom
https://arxiv.org/abs/2508.05646

Query-Aware Graph Neural Networks for Enhanced Retrieval-Augmented Generation
https://arxiv.org/abs/2508.05647

AquiLLM: a RAG Tool for Capturing Tacit Knowledge in Research Groups
https://arxiv.org/abs/2508.05648

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Automatic License Plate Readers Are Coming to Schools
https://www.schneier.com/blog/archives/2025/08/automatic-license-plate-readers-are-coming-to-schools.html

Building an Autonomous AI Pentester: What Worked, What Didn’t, and Why It Matters
https://www.reddit.com/r/netsec/comments/1mnaugi/building_an_autonomous_ai_pentester_what_worked/

11th August – Threat Intelligence Report
https://research.checkpoint.com/2025/11th-august-threat-intelligence-report/

Wikipedia’s operator loses challenge to UK Online Safety Act rules
https://therecord.media/wikipedia-loses-challenge-online-safety-act-uk

Finland charges captain of suspected Russian ‘shadow fleet’ tanker for subsea cable damage
https://therecord.media/finland-charges-captain-russia-ghost-fleet-undersea-cable

Two groups exploit WinRAR flaws in separate cyber-espionage campaigns
https://therecord.media/winrar-zero-day-exploited-romcom-paper-werewolf-goffee-hackers

Romance scam suspects extradited from Ghana, charged with more than $100 million in thefts
https://therecord.media/ghana-romance-scams-bec-suspects-extradited-us

Ransomware gang claims attack on St. Paul city government
https://therecord.media/ransomware-gang-behind-minnesota-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises
https://www.trendmicro.com/en_us/research/25/h/new-ransomware-charon.html

The “Incriminating Video” Scam
https://www.schneier.com/blog/archives/2025/08/the-incriminating-video-scam.html

Second ransomware attack in two months disrupts South Korean ticketing giant
https://therecord.media/yes24-second-ransomware-attack-kpop-ticketing-affected

Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
https://blog.qualys.com/qualys-insights/2025/08/12/two-pwnie-awards-one-crucial-lesson-what-our-openssh-research-reveals-about-cyber-defense-in-2025

New Charon ransomware targets Middle East public sector, aviation firms
https://therecord.media/charon-ransomware-targeting-middle-east-aviation

DEF CON volunteers step up to help water sector after China, Iran attack utilities
https://therecord.media/def-con-franklin-water-utility-cybersecurity-volunteers

Dow’s 125-year legacy: Innovating with AI to secure a long future
https://www.microsoft.com/en-us/security/blog/2025/08/12/dows-125-year-legacy-innovating-with-ai-to-secure-a-long-future/

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/netsec/comments/1mof7r5/zero_click_one_ntlm_microsoft_security_patch/

Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/08/12/microsoft-and-adobe-patch-tuesday-august-2025-security-update-review

Microsoft Patch Tuesday, August 2025 Edition
https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
https://therecord.media/matrix-messaging-protocol-high-severity-vulnerabilities

Pennsylvania attorney general says cyberattack knocked phone, email systems offline
https://therecord.media/pennsylvania-attorney-general-office-cyberattack

Estonians behind multimillion-dollar crypto fraud sentenced
https://therecord.media/estonians-behind-multimillion-dollar-crypto-fraud-sentenced

New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts
https://therecord.media/zelle-lawsuit-new-york-state-scams-fraud

Curly threat actor found targeting sensitive organizations in Georgia, Moldova
https://therecord.media/curly-threat-actor-targeting-moldova

AI Applications in Cybersecurity
https://www.schneier.com/blog/archives/2025/08/ai-applications-in-cybersecurity.html

Best Kickass (KAT) Alternatives & Live Torrent Trackers in 2025 – Public, Private, and Legal Picks
https://www.darknet.org.uk/2025/08/best-kickass-alternatives-live-torrent-trackers-in-2025-public-private-and-legal-picks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

N/A
N/A

Taming Shadow IT: What Security Teams Can Do About Unapproved Apps and Extensions
https://www.tripwire.com/state-of-security/taming-shadow-it-what-security-teams-can-do-about-unapproved-apps-and-extensions

LLM Coding Integrity Breach
https://www.schneier.com/blog/archives/2025/08/llm-coding-integrity-breach.html

Tens of thousands of Italian hotel guests may be hit by cyber heist
https://therecord.media/italy-hotel-guests-possible-data-breach-ids

Russia curbs WhatsApp, Telegram calls to counter cybercrime
https://therecord.media/russia-restricts-voice-calls-whatsapp-telegram-cybercrime

Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability
https://therecord.media/hackers-compromise-canada-house-of-commons

FCC’s data breach reporting rules for telecoms are upheld in appeals court
https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court

Norway police believe pro-Russian hackers were behind April dam sabotage
https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage

Turkish crypto exchange BTCTurk warns of security incident after $49 million leaves platform
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident

US updates sanctions on Russian cryptocurrency exchange Garantex
https://therecord.media/treasury-department-renews-sanctions-garantex-grinex

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msre41/how_exposed_teslamate_instances_leak_sensitive/

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msrpi6/how_exposed_teslamate_instances_leak_sensitive/

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool
https://www.darknet.org.uk/2025/08/lostmypassword-dual-use-password-recovery-and-credential-dumping-tool/

Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
https://securelist.com/pipemagic/117270/

A Rose by Any Other Name Would Smell as Sweet: Categorical Homotopy Theory for Large Language Models
https://arxiv.org/abs/2508.10043

A2HCoder: An LLM-Driven Coding Agent for Hierarchical Algorithm-to-HDL Translation
https://arxiv.org/abs/2508.10903

PersonaTwin: A Multi-Tier Prompt Conditioning Framework for Generating and Evaluating Personalized Digital Twins
https://arxiv.org/abs/2508.10904

Uncovering Latent Connections in Indigenous Heritage: Semantic Pipelines for Cultural Preservation in Brazil
https://arxiv.org/abs/2508.10906

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
https://arxiv.org/abs/2508.10911

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Plagued by Cyberattacks: Indian Healthcare Sector in Critical Condition
https://www.tripwire.com/state-of-security/plagued-cyberattacks-indian-healthcare-sector-critical-condition

Eavesdropping on Phone Conversations Through Vibrations
https://www.schneier.com/blog/archives/2025/08/eavesdropping-on-phone-conversations-through-vibrations.html

Workday hit by social engineering data breach targeting its CRM platform
https://therecord.media/workday-social-engineering-data-breach

Intel Outside: Hacking every Intel employee and various internal websites
https://www.reddit.com/r/netsec/comments/1mtnqme/intel_outside_hacking_every_intel_employee_and/

Cryptomining group Kinsing expands operations to Russia, researchers warn
https://therecord.media/cryptomining-group-kinsing-hits-russia

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development
https://www.reddit.com/r/netsec/comments/1mtpvuu/vibe_hacking_abusing_developer_trust_in_cursor/

Casino gaming company Bragg says hackers accessed ‘internal computer environment’
https://therecord.media/casino-gaming-company-cyber-incident-bragg

Ransomware gang masking PipeMagic backdoor as ChatGPT desktop app: Microsoft
https://therecord.media/ransomware-gang-masking-pipemagic-backdoor

Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/

CTF stats, mobile wallet attacks & magstripe demos – Payment Village @ DEF CON 33
https://www.reddit.com/r/netsec/comments/1mtw68x/ctf_stats_mobile_wallet_attacks_magstripe_demos/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman