Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Driver of destruction: How a legitimate driver is being used to take down AV processes
https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/

Who Got Arrested in the Raid on the XSS Crime Forum?
https://krebsonsecurity.com/2025/08/who-got-arrested-in-the-raid-on-the-xss-crime-forum/

British intelligence warns cyber threat to critical infrastructure is increasing
https://therecord.media/british-intel-cyber-threat-infrastructure

Hackers using fake summonses in attacks on Ukraine's defense sector
https://therecord.media/hackers-using-fake-summonses-ukraine

Ransomware-as-a-Service Economy – Trends, Targets & Takedowns
https://www.darknet.org.uk/2025/08/ransomware-as-a-service-economy-trends-targets-takedowns/

Sharing practical guidance: Launching Microsoft Secure Future Initiative (SFI) patterns and practices
https://www.microsoft.com/en-us/security/blog/2025/08/06/sharing-practical-guidance-launching-microsoft-secure-future-initiative-sfi-patterns-and-practices/

Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge
https://therecord.media/tornado-cash-money-laundering-conviction

Strong regulation can nudge automakers to improve customers’ privacy, research suggests
https://therecord.media/automakers-data-privacy-ratings-websites-customer-portals

HTTP/1.1 Must Die: What This Means for AppSec Leadership
https://portswigger.net/blog/http-1-1-must-die-what-this-means-for-appsec-leadership

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

China Accuses Nvidia of Putting Backdoors into Their Chips
https://www.schneier.com/blog/archives/2025/08/china-accuses-nvidia-of-putting-backdoors-into-their-chips.html

Cyberattack hits France’s third-largest mobile operator, millions of customers affected
https://therecord.media/bouygues-telecom-france-cyberattack-data-breach

CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability
https://therecord.media/microsoft-exchange-server-vulnerability-cisa-alert

Building a Cyber-Aware Workforce: Mexico's Push for Security Training
https://www.tripwire.com/state-of-security/building-cyber-aware-workforce-mexicos-push-security-training

Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault
https://www.reddit.com/r/netsec/comments/1mjzm7g/cracking_the_vault_how_we_found_zeroday_flaws_in/

Announcing public preview: Phishing triage agent in Microsoft Defender
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-phishing-triage-agent-in-microsoft-defender/4438301

We replaced passwords with something worse
https://www.reddit.com/r/netsec/comments/1mk9qsy/we_replaced_passwords_with_something_worse/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

XSSHunter Express – Self-Hosted Blind XSS Payload Capture and Analysis
https://www.darknet.org.uk/2025/08/xsshunter-express-self-hosted-blind-xss-payload-capture-and-analysis/

Next-Level Fingerprinting: Tools, Logic, and Tactics
https://bishopfox.com/blog/next-level-fingerprinting-tools-logic-and-tactics

Automated Visualization Makeovers with LLMs
https://arxiv.org/abs/2508.05637

Request-Only Optimization for Recommendation Systems
https://arxiv.org/abs/2508.05640

A Humanoid Social Robot as a Teaching Assistant in the Classroom
https://arxiv.org/abs/2508.05646

Query-Aware Graph Neural Networks for Enhanced Retrieval-Augmented Generation
https://arxiv.org/abs/2508.05647

AquiLLM: a RAG Tool for Capturing Tacit Knowledge in Research Groups
https://arxiv.org/abs/2508.05648

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Automatic License Plate Readers Are Coming to Schools
https://www.schneier.com/blog/archives/2025/08/automatic-license-plate-readers-are-coming-to-schools.html

Building an Autonomous AI Pentester: What Worked, What Didn’t, and Why It Matters
https://www.reddit.com/r/netsec/comments/1mnaugi/building_an_autonomous_ai_pentester_what_worked/

11th August – Threat Intelligence Report
https://research.checkpoint.com/2025/11th-august-threat-intelligence-report/

Wikipedia’s operator loses challenge to UK Online Safety Act rules
https://therecord.media/wikipedia-loses-challenge-online-safety-act-uk

Finland charges captain of suspected Russian ‘shadow fleet’ tanker for subsea cable damage
https://therecord.media/finland-charges-captain-russia-ghost-fleet-undersea-cable

Two groups exploit WinRAR flaws in separate cyber-espionage campaigns
https://therecord.media/winrar-zero-day-exploited-romcom-paper-werewolf-goffee-hackers

Romance scam suspects extradited from Ghana, charged with more than $100 million in thefts
https://therecord.media/ghana-romance-scams-bec-suspects-extradited-us

Ransomware gang claims attack on St. Paul city government
https://therecord.media/ransomware-gang-behind-minnesota-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises
https://www.trendmicro.com/en_us/research/25/h/new-ransomware-charon.html

The “Incriminating Video” Scam
https://www.schneier.com/blog/archives/2025/08/the-incriminating-video-scam.html

Second ransomware attack in two months disrupts South Korean ticketing giant
https://therecord.media/yes24-second-ransomware-attack-kpop-ticketing-affected

Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
https://blog.qualys.com/qualys-insights/2025/08/12/two-pwnie-awards-one-crucial-lesson-what-our-openssh-research-reveals-about-cyber-defense-in-2025

New Charon ransomware targets Middle East public sector, aviation firms
https://therecord.media/charon-ransomware-targeting-middle-east-aviation

DEF CON volunteers step up to help water sector after China, Iran attack utilities
https://therecord.media/def-con-franklin-water-utility-cybersecurity-volunteers

Dow’s 125-year legacy: Innovating with AI to secure a long future
https://www.microsoft.com/en-us/security/blog/2025/08/12/dows-125-year-legacy-innovating-with-ai-to-secure-a-long-future/

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/netsec/comments/1mof7r5/zero_click_one_ntlm_microsoft_security_patch/

Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/08/12/microsoft-and-adobe-patch-tuesday-august-2025-security-update-review

Microsoft Patch Tuesday, August 2025 Edition
https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
https://therecord.media/matrix-messaging-protocol-high-severity-vulnerabilities

Pennsylvania attorney general says cyberattack knocked phone, email systems offline
https://therecord.media/pennsylvania-attorney-general-office-cyberattack

Estonians behind multimillion-dollar crypto fraud sentenced
https://therecord.media/estonians-behind-multimillion-dollar-crypto-fraud-sentenced

New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts
https://therecord.media/zelle-lawsuit-new-york-state-scams-fraud

Curly threat actor found targeting sensitive organizations in Georgia, Moldova
https://therecord.media/curly-threat-actor-targeting-moldova

AI Applications in Cybersecurity
https://www.schneier.com/blog/archives/2025/08/ai-applications-in-cybersecurity.html

Best Kickass (KAT) Alternatives & Live Torrent Trackers in 2025 – Public, Private, and Legal Picks
https://www.darknet.org.uk/2025/08/best-kickass-alternatives-live-torrent-trackers-in-2025-public-private-and-legal-picks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

N/A
N/A

Taming Shadow IT: What Security Teams Can Do About Unapproved Apps and Extensions
https://www.tripwire.com/state-of-security/taming-shadow-it-what-security-teams-can-do-about-unapproved-apps-and-extensions

LLM Coding Integrity Breach
https://www.schneier.com/blog/archives/2025/08/llm-coding-integrity-breach.html

Tens of thousands of Italian hotel guests may be hit by cyber heist
https://therecord.media/italy-hotel-guests-possible-data-breach-ids

Russia curbs WhatsApp, Telegram calls to counter cybercrime
https://therecord.media/russia-restricts-voice-calls-whatsapp-telegram-cybercrime

Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability
https://therecord.media/hackers-compromise-canada-house-of-commons

FCC’s data breach reporting rules for telecoms are upheld in appeals court
https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court

Norway police believe pro-Russian hackers were behind April dam sabotage
https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage

Turkish crypto exchange BTCTurk warns of security incident after $49 million leaves platform
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident

US updates sanctions on Russian cryptocurrency exchange Garantex
https://therecord.media/treasury-department-renews-sanctions-garantex-grinex

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msre41/how_exposed_teslamate_instances_leak_sensitive/

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msrpi6/how_exposed_teslamate_instances_leak_sensitive/

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool
https://www.darknet.org.uk/2025/08/lostmypassword-dual-use-password-recovery-and-credential-dumping-tool/

Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
https://securelist.com/pipemagic/117270/

A Rose by Any Other Name Would Smell as Sweet: Categorical Homotopy Theory for Large Language Models
https://arxiv.org/abs/2508.10043

A2HCoder: An LLM-Driven Coding Agent for Hierarchical Algorithm-to-HDL Translation
https://arxiv.org/abs/2508.10903

PersonaTwin: A Multi-Tier Prompt Conditioning Framework for Generating and Evaluating Personalized Digital Twins
https://arxiv.org/abs/2508.10904

Uncovering Latent Connections in Indigenous Heritage: Semantic Pipelines for Cultural Preservation in Brazil
https://arxiv.org/abs/2508.10906

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
https://arxiv.org/abs/2508.10911

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Plagued by Cyberattacks: Indian Healthcare Sector in Critical Condition
https://www.tripwire.com/state-of-security/plagued-cyberattacks-indian-healthcare-sector-critical-condition

Eavesdropping on Phone Conversations Through Vibrations
https://www.schneier.com/blog/archives/2025/08/eavesdropping-on-phone-conversations-through-vibrations.html

Workday hit by social engineering data breach targeting its CRM platform
https://therecord.media/workday-social-engineering-data-breach

Intel Outside: Hacking every Intel employee and various internal websites
https://www.reddit.com/r/netsec/comments/1mtnqme/intel_outside_hacking_every_intel_employee_and/

Cryptomining group Kinsing expands operations to Russia, researchers warn
https://therecord.media/cryptomining-group-kinsing-hits-russia

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development
https://www.reddit.com/r/netsec/comments/1mtpvuu/vibe_hacking_abusing_developer_trust_in_cursor/

Casino gaming company Bragg says hackers accessed ‘internal computer environment’
https://therecord.media/casino-gaming-company-cyber-incident-bragg

Ransomware gang masking PipeMagic backdoor as ChatGPT desktop app: Microsoft
https://therecord.media/ransomware-gang-masking-pipemagic-backdoor

Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/

CTF stats, mobile wallet attacks & magstripe demos – Payment Village @ DEF CON 33
https://www.reddit.com/r/netsec/comments/1mtw68x/ctf_stats_mobile_wallet_attacks_magstripe_demos/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

GodRAT – New RAT targeting financial institutions
https://securelist.com/godrat/117119/

Zero-Day Exploit in WinRAR File
https://www.schneier.com/blog/archives/2025/08/zero-day-exploit-in-winrar-file.html

UK ‘agrees to drop’ demand over Apple iCloud encryption
https://therecord.media/uk-agrees-drop-apple-encryption

Drug development company Inotiv reports ransomware attack to SEC
https://therecord.media/drug-development-innotiv-ransomware-sec

North Korea-linked hackers target embassies in Seoul in new espionage campaign
https://therecord.media/north-korean-hackers-target-foreign-embassies

Business Council of New York State says nearly 50,000 had data leaked in February cyberattack
https://therecord.media/new-york-business-council-data-breach

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories
https://www.reddit.com/r/netsec/comments/1mumb6z/how_we_exploited_coderabbit_from_a_simple_pr_to/

Trivial C# Random Exploitation
https://www.reddit.com/r/netsec/comments/1muf1om/trivial_c_random_exploitation/

Oregon Man Charged in ‘Rapper Bot’ DDoS Service
https://krebsonsecurity.com/2025/08/oregon-man-charged-in-rapper-bot-ddos-service/

Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks
https://www.darknet.org.uk/2025/08/darknet-communications-in-2025-from-irc-forums-to-telegram-crime-networks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Guess Who Would Be Stupid Enough To Rob The Same Vault Twice? Pre-Auth RCE Chains in Commvault - watchTowr Labs
https://arxiv.org/abs/2508.13214

Subverting AIOps Systems Through Poisoned Input Data
https://www.schneier.com/blog/archives/2025/08/subverting-aiops-systems-through-poisoned-input-data.html

NATO's Cybersecurity Spending Proposals’ Impact on the Industry
https://www.tripwire.com/state-of-security/natos-cybersecurity-spending-proposals-impact-industry

At least three UK organizations hit by SharePoint zero-day hacking campaign
https://therecord.media/organizations-united-kingdom/sharepoint

Major Belgian telecom firm says cyberattack compromised data on 850,000 accounts
https://therecord.media/belgian-telecom-says-cyberattack-compromised-data-on-850000

Russian investment platform confirms cyberattack by pro-Ukraine hackers
https://therecord.media/russia-cyberattack-investment-platform-ukraine

Feds charge administrator of ‘sophisticated’ DDoS-for-hire botnet
https://therecord.media/feds-charge-botnet-admin

Engineered to Fail: The DNA of Negligent Defenses Operations
https://www.reddit.com/r/netsec/comments/1mvijcg/engineered_to_fail_the_dna_of_negligent_defenses/

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
https://www.trendmicro.com/en_us/research/25/h/warlock-ransomware.html

Google Unveils Enhanced Tools to Empower Defenders and Safeguard AI Progress
https://www.reddit.com/r/netsec/comments/1mvpbds/google_unveils_enhanced_tools_to_empower/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
https://www.reddit.com/r/netsec/comments/1mw4dn9/we_put_agentic_ai_browsers_to_the_test_they/

Jim Sanborn Is Auctioning Off the Solution to Part Four of the Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/08/jim-sanborn-is-auctioning-off-the-solution-to-part-four-of-the-kryptos-sculpture.html

Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution
https://therecord.media/scattered-spider-affiliate-sentenced-10-years

Azure's Weakest Link - Full Cross-Tenant Compromise
https://www.reddit.com/r/netsec/comments/1mwbimu/azures_weakest_link_full_crosstenant_compromise/

AI can be used to create working exploits for published CVEs in a few minutes and for a few dollars
https://www.reddit.com/r/netsec/comments/1mwfks2/ai_can_be_used_to_create_working_exploits_for/

When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074)
https://www.reddit.com/r/netsec/comments/1mwhisp/when_a_ssrf_is_enough_full_docker_escape_on/

Think before you Click(Fix): Analyzing the ClickFix social engineering technique
https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/

Quantum-safe security: Progress towards next-generation cryptography
https://www.microsoft.com/en-us/security/blog/2025/08/20/quantum-safe-security-progress-towards-next-generation-cryptography/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Engineered to Fail: The DNA of Negligent Cyber Defenses
https://reporter.deepspecter.com/engineered-to-fail-the-dna-of-negligent-cyber-defenses-22466a034b28

Chinese national who sabotaged Ohio company’s systems handed four-year jail stint
https://therecord.media/chinese-national-sentenced-prison

CISA warns of Apple zero-day used in targeted cyberattacks
https://therecord.media/cisa-warns-of-apple-zero-day

Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
https://therecord.media/africa-interpol-cybercrime-crackdown

US warns tech companies against complying with European and British ‘censorship’ laws
https://therecord.media/tech-companies-ftc-censorship-laws

Electronics manufacturer Data I/O reports ransomware attack to SEC
https://therecord.media/electronics-manufacturer-dataio-ransomware

ChromeAlone – Chromium Browser C2 Implant for Red Team Operations
https://www.darknet.org.uk/2025/08/chromealone-chromium-browser-c2-implant-for-red-team-operations/

Silent Harvest: Extracting Windows Secrets Under the Radar
https://www.reddit.com/r/netsec/comments/1mxcig6/silent_harvest_extracting_windows_secrets_under/

Leadership, Innovation, and the Future of AI: Lessons from Trend Micro CEO & Co-Founder Eva Chen
https://www.trendmicro.com/en_us/research/25/h/eva-chen-future-of-ai.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments
https://www.darknet.org.uk/2025/08/azurestrike-offensive-toolkit-for-attacking-azure-active-directory-environments/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.15776

Harmonious Color Pairings: Insights from Human Preference and Natural Hue Statistics
https://arxiv.org/abs/2508.15777

Towards Stealthy and Effective Backdoor Attacks on Lane Detection: A Naturalistic Data Poisoning Approach
https://arxiv.org/abs/2508.15778

Observer-Free Sliding Mode Control via Structured Decomposition: a Smooth and Bounded Control Framework
https://arxiv.org/abs/2508.15787

VR Fire safety training application
https://arxiv.org/abs/2508.15788

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Wyden calls for probe of federal judiciary data breaches, accusing it of ‘negligence’
https://therecord.media/wyden-probe-federal-judiciary-data-breaches

Maryland investigating cyberattack impacting transit service for disabled people
https://therecord.media/maryland-cyberattack-transit-disabled-people

South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities
https://therecord.media/south-korea-arrests-hacker-accused-of-targeting-celebrities-bts

Farmers Insurance says 1 million customers affected by cyberattack on third-party vendor
https://therecord.media/farmers-insurance-million-data-breach

Poor Password Choices
https://www.schneier.com/blog/archives/2025/08/poor-password-choices.html

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Vtenext 25.02: A three-way path to RCE
https://www.reddit.com/r/netsec/comments/1mzmrnp/vtenext_2502_a_threeway_path_to_rce/

Safeguarding VS Code against prompt injections
https://www.reddit.com/r/netsec/comments/1mzzh21/safeguarding_vs_code_against_prompt_injections/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.16579

DIAC ∞ 2: A Post-Quantum, P=NP-Resistant Cryptosystem
https://arxiv.org/abs/2508.15840

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Encryption Backdoor in Military/Police Radios
https://www.schneier.com/blog/archives/2025/08/encryption-backdoor-in-military-police-radios.html

ZipLine Campaign: A Sophisticated Phishing Attack Targeting US Companies
https://research.checkpoint.com/2025/zipline-phishing-campaign/

Nevada state websites, phone lines knocked offline by cyberattack
https://therecord.media/nevada-state-websites-phones-cyberattack-disruption

MITRE Introduces AADAPT Framework to Combat Crypto-Focused Cyber Threats
https://www.tripwire.com/state-of-security/mitre-introduces-aadapt-framework-combat-crypto-focused-cyber-threats

Securing and governing the rise of autonomous agents
https://www.microsoft.com/en-us/security/blog/2025/08/26/securing-and-governing-the-rise-of-autonomous-agents/

Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness
https://www.darknet.org.uk/2025/08/cybersecurity-workforce-trends-in-2025-skills-gap-diversity-and-soc-readiness/

This House is Haunted: a decade old RCE in the AION client
https://www.reddit.com/r/netsec/comments/1n0q5h7/this_house_is_haunted_a_decade_old_rce_in_the/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman