Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

China Accuses Nvidia of Putting Backdoors into Their Chips
https://www.schneier.com/blog/archives/2025/08/china-accuses-nvidia-of-putting-backdoors-into-their-chips.html

Cyberattack hits France’s third-largest mobile operator, millions of customers affected
https://therecord.media/bouygues-telecom-france-cyberattack-data-breach

CISA, Microsoft issue alerts on ‘high-severity’ Exchange vulnerability
https://therecord.media/microsoft-exchange-server-vulnerability-cisa-alert

Building a Cyber-Aware Workforce: Mexico's Push for Security Training
https://www.tripwire.com/state-of-security/building-cyber-aware-workforce-mexicos-push-security-training

Cracking the Vault: how we found zero-day flaws in authentication, identity, and authorization in HashiCorp Vault
https://www.reddit.com/r/netsec/comments/1mjzm7g/cracking_the_vault_how_we_found_zeroday_flaws_in/

Announcing public preview: Phishing triage agent in Microsoft Defender
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-phishing-triage-agent-in-microsoft-defender/4438301

We replaced passwords with something worse
https://www.reddit.com/r/netsec/comments/1mk9qsy/we_replaced_passwords_with_something_worse/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

XSSHunter Express – Self-Hosted Blind XSS Payload Capture and Analysis
https://www.darknet.org.uk/2025/08/xsshunter-express-self-hosted-blind-xss-payload-capture-and-analysis/

Next-Level Fingerprinting: Tools, Logic, and Tactics
https://bishopfox.com/blog/next-level-fingerprinting-tools-logic-and-tactics

Automated Visualization Makeovers with LLMs
https://arxiv.org/abs/2508.05637

Request-Only Optimization for Recommendation Systems
https://arxiv.org/abs/2508.05640

A Humanoid Social Robot as a Teaching Assistant in the Classroom
https://arxiv.org/abs/2508.05646

Query-Aware Graph Neural Networks for Enhanced Retrieval-Augmented Generation
https://arxiv.org/abs/2508.05647

AquiLLM: a RAG Tool for Capturing Tacit Knowledge in Research Groups
https://arxiv.org/abs/2508.05648

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Automatic License Plate Readers Are Coming to Schools
https://www.schneier.com/blog/archives/2025/08/automatic-license-plate-readers-are-coming-to-schools.html

Building an Autonomous AI Pentester: What Worked, What Didn’t, and Why It Matters
https://www.reddit.com/r/netsec/comments/1mnaugi/building_an_autonomous_ai_pentester_what_worked/

11th August – Threat Intelligence Report
https://research.checkpoint.com/2025/11th-august-threat-intelligence-report/

Wikipedia’s operator loses challenge to UK Online Safety Act rules
https://therecord.media/wikipedia-loses-challenge-online-safety-act-uk

Finland charges captain of suspected Russian ‘shadow fleet’ tanker for subsea cable damage
https://therecord.media/finland-charges-captain-russia-ghost-fleet-undersea-cable

Two groups exploit WinRAR flaws in separate cyber-espionage campaigns
https://therecord.media/winrar-zero-day-exploited-romcom-paper-werewolf-goffee-hackers

Romance scam suspects extradited from Ghana, charged with more than $100 million in thefts
https://therecord.media/ghana-romance-scams-bec-suspects-extradited-us

Ransomware gang claims attack on St. Paul city government
https://therecord.media/ransomware-gang-behind-minnesota-attack

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises
https://www.trendmicro.com/en_us/research/25/h/new-ransomware-charon.html

The “Incriminating Video” Scam
https://www.schneier.com/blog/archives/2025/08/the-incriminating-video-scam.html

Second ransomware attack in two months disrupts South Korean ticketing giant
https://therecord.media/yes24-second-ransomware-attack-kpop-ticketing-affected

Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
https://blog.qualys.com/qualys-insights/2025/08/12/two-pwnie-awards-one-crucial-lesson-what-our-openssh-research-reveals-about-cyber-defense-in-2025

New Charon ransomware targets Middle East public sector, aviation firms
https://therecord.media/charon-ransomware-targeting-middle-east-aviation

DEF CON volunteers step up to help water sector after China, Iran attack utilities
https://therecord.media/def-con-franklin-water-utility-cybersecurity-volunteers

Dow’s 125-year legacy: Innovating with AI to secure a long future
https://www.microsoft.com/en-us/security/blog/2025/08/12/dows-125-year-legacy-innovating-with-ai-to-secure-a-long-future/

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154)
https://www.reddit.com/r/netsec/comments/1mof7r5/zero_click_one_ntlm_microsoft_security_patch/

Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/08/12/microsoft-and-adobe-patch-tuesday-august-2025-security-update-review

Microsoft Patch Tuesday, August 2025 Edition
https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
https://therecord.media/matrix-messaging-protocol-high-severity-vulnerabilities

Pennsylvania attorney general says cyberattack knocked phone, email systems offline
https://therecord.media/pennsylvania-attorney-general-office-cyberattack

Estonians behind multimillion-dollar crypto fraud sentenced
https://therecord.media/estonians-behind-multimillion-dollar-crypto-fraud-sentenced

New York lawsuit against Zelle creator alleges features allowed $1 billion in thefts
https://therecord.media/zelle-lawsuit-new-york-state-scams-fraud

Curly threat actor found targeting sensitive organizations in Georgia, Moldova
https://therecord.media/curly-threat-actor-targeting-moldova

AI Applications in Cybersecurity
https://www.schneier.com/blog/archives/2025/08/ai-applications-in-cybersecurity.html

Best Kickass (KAT) Alternatives & Live Torrent Trackers in 2025 – Public, Private, and Legal Picks
https://www.darknet.org.uk/2025/08/best-kickass-alternatives-live-torrent-trackers-in-2025-public-private-and-legal-picks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

N/A
N/A

Taming Shadow IT: What Security Teams Can Do About Unapproved Apps and Extensions
https://www.tripwire.com/state-of-security/taming-shadow-it-what-security-teams-can-do-about-unapproved-apps-and-extensions

LLM Coding Integrity Breach
https://www.schneier.com/blog/archives/2025/08/llm-coding-integrity-breach.html

Tens of thousands of Italian hotel guests may be hit by cyber heist
https://therecord.media/italy-hotel-guests-possible-data-breach-ids

Russia curbs WhatsApp, Telegram calls to counter cybercrime
https://therecord.media/russia-restricts-voice-calls-whatsapp-telegram-cybercrime

Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability
https://therecord.media/hackers-compromise-canada-house-of-commons

FCC’s data breach reporting rules for telecoms are upheld in appeals court
https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court

Norway police believe pro-Russian hackers were behind April dam sabotage
https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage

Turkish crypto exchange BTCTurk warns of security incident after $49 million leaves platform
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident

US updates sanctions on Russian cryptocurrency exchange Garantex
https://therecord.media/treasury-department-renews-sanctions-garantex-grinex

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msre41/how_exposed_teslamate_instances_leak_sensitive/

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msrpi6/how_exposed_teslamate_instances_leak_sensitive/

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool
https://www.darknet.org.uk/2025/08/lostmypassword-dual-use-password-recovery-and-credential-dumping-tool/

Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
https://securelist.com/pipemagic/117270/

A Rose by Any Other Name Would Smell as Sweet: Categorical Homotopy Theory for Large Language Models
https://arxiv.org/abs/2508.10043

A2HCoder: An LLM-Driven Coding Agent for Hierarchical Algorithm-to-HDL Translation
https://arxiv.org/abs/2508.10903

PersonaTwin: A Multi-Tier Prompt Conditioning Framework for Generating and Evaluating Personalized Digital Twins
https://arxiv.org/abs/2508.10904

Uncovering Latent Connections in Indigenous Heritage: Semantic Pipelines for Cultural Preservation in Brazil
https://arxiv.org/abs/2508.10906

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
https://arxiv.org/abs/2508.10911

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Plagued by Cyberattacks: Indian Healthcare Sector in Critical Condition
https://www.tripwire.com/state-of-security/plagued-cyberattacks-indian-healthcare-sector-critical-condition

Eavesdropping on Phone Conversations Through Vibrations
https://www.schneier.com/blog/archives/2025/08/eavesdropping-on-phone-conversations-through-vibrations.html

Workday hit by social engineering data breach targeting its CRM platform
https://therecord.media/workday-social-engineering-data-breach

Intel Outside: Hacking every Intel employee and various internal websites
https://www.reddit.com/r/netsec/comments/1mtnqme/intel_outside_hacking_every_intel_employee_and/

Cryptomining group Kinsing expands operations to Russia, researchers warn
https://therecord.media/cryptomining-group-kinsing-hits-russia

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development
https://www.reddit.com/r/netsec/comments/1mtpvuu/vibe_hacking_abusing_developer_trust_in_cursor/

Casino gaming company Bragg says hackers accessed ‘internal computer environment’
https://therecord.media/casino-gaming-company-cyber-incident-bragg

Ransomware gang masking PipeMagic backdoor as ChatGPT desktop app: Microsoft
https://therecord.media/ransomware-gang-masking-pipemagic-backdoor

Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/

CTF stats, mobile wallet attacks & magstripe demos – Payment Village @ DEF CON 33
https://www.reddit.com/r/netsec/comments/1mtw68x/ctf_stats_mobile_wallet_attacks_magstripe_demos/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

GodRAT – New RAT targeting financial institutions
https://securelist.com/godrat/117119/

Zero-Day Exploit in WinRAR File
https://www.schneier.com/blog/archives/2025/08/zero-day-exploit-in-winrar-file.html

UK ‘agrees to drop’ demand over Apple iCloud encryption
https://therecord.media/uk-agrees-drop-apple-encryption

Drug development company Inotiv reports ransomware attack to SEC
https://therecord.media/drug-development-innotiv-ransomware-sec

North Korea-linked hackers target embassies in Seoul in new espionage campaign
https://therecord.media/north-korean-hackers-target-foreign-embassies

Business Council of New York State says nearly 50,000 had data leaked in February cyberattack
https://therecord.media/new-york-business-council-data-breach

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories
https://www.reddit.com/r/netsec/comments/1mumb6z/how_we_exploited_coderabbit_from_a_simple_pr_to/

Trivial C# Random Exploitation
https://www.reddit.com/r/netsec/comments/1muf1om/trivial_c_random_exploitation/

Oregon Man Charged in ‘Rapper Bot’ DDoS Service
https://krebsonsecurity.com/2025/08/oregon-man-charged-in-rapper-bot-ddos-service/

Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks
https://www.darknet.org.uk/2025/08/darknet-communications-in-2025-from-irc-forums-to-telegram-crime-networks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Guess Who Would Be Stupid Enough To Rob The Same Vault Twice? Pre-Auth RCE Chains in Commvault - watchTowr Labs
https://arxiv.org/abs/2508.13214

Subverting AIOps Systems Through Poisoned Input Data
https://www.schneier.com/blog/archives/2025/08/subverting-aiops-systems-through-poisoned-input-data.html

NATO's Cybersecurity Spending Proposals’ Impact on the Industry
https://www.tripwire.com/state-of-security/natos-cybersecurity-spending-proposals-impact-industry

At least three UK organizations hit by SharePoint zero-day hacking campaign
https://therecord.media/organizations-united-kingdom/sharepoint

Major Belgian telecom firm says cyberattack compromised data on 850,000 accounts
https://therecord.media/belgian-telecom-says-cyberattack-compromised-data-on-850000

Russian investment platform confirms cyberattack by pro-Ukraine hackers
https://therecord.media/russia-cyberattack-investment-platform-ukraine

Feds charge administrator of ‘sophisticated’ DDoS-for-hire botnet
https://therecord.media/feds-charge-botnet-admin

Engineered to Fail: The DNA of Negligent Defenses Operations
https://www.reddit.com/r/netsec/comments/1mvijcg/engineered_to_fail_the_dna_of_negligent_defenses/

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
https://www.trendmicro.com/en_us/research/25/h/warlock-ransomware.html

Google Unveils Enhanced Tools to Empower Defenders and Safeguard AI Progress
https://www.reddit.com/r/netsec/comments/1mvpbds/google_unveils_enhanced_tools_to_empower/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
https://www.reddit.com/r/netsec/comments/1mw4dn9/we_put_agentic_ai_browsers_to_the_test_they/

Jim Sanborn Is Auctioning Off the Solution to Part Four of the Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/08/jim-sanborn-is-auctioning-off-the-solution-to-part-four-of-the-kryptos-sculpture.html

Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution
https://therecord.media/scattered-spider-affiliate-sentenced-10-years

Azure's Weakest Link - Full Cross-Tenant Compromise
https://www.reddit.com/r/netsec/comments/1mwbimu/azures_weakest_link_full_crosstenant_compromise/

AI can be used to create working exploits for published CVEs in a few minutes and for a few dollars
https://www.reddit.com/r/netsec/comments/1mwfks2/ai_can_be_used_to_create_working_exploits_for/

When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074)
https://www.reddit.com/r/netsec/comments/1mwhisp/when_a_ssrf_is_enough_full_docker_escape_on/

Think before you Click(Fix): Analyzing the ClickFix social engineering technique
https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/

Quantum-safe security: Progress towards next-generation cryptography
https://www.microsoft.com/en-us/security/blog/2025/08/20/quantum-safe-security-progress-towards-next-generation-cryptography/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Engineered to Fail: The DNA of Negligent Cyber Defenses
https://reporter.deepspecter.com/engineered-to-fail-the-dna-of-negligent-cyber-defenses-22466a034b28

Chinese national who sabotaged Ohio company’s systems handed four-year jail stint
https://therecord.media/chinese-national-sentenced-prison

CISA warns of Apple zero-day used in targeted cyberattacks
https://therecord.media/cisa-warns-of-apple-zero-day

Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
https://therecord.media/africa-interpol-cybercrime-crackdown

US warns tech companies against complying with European and British ‘censorship’ laws
https://therecord.media/tech-companies-ftc-censorship-laws

Electronics manufacturer Data I/O reports ransomware attack to SEC
https://therecord.media/electronics-manufacturer-dataio-ransomware

ChromeAlone – Chromium Browser C2 Implant for Red Team Operations
https://www.darknet.org.uk/2025/08/chromealone-chromium-browser-c2-implant-for-red-team-operations/

Silent Harvest: Extracting Windows Secrets Under the Radar
https://www.reddit.com/r/netsec/comments/1mxcig6/silent_harvest_extracting_windows_secrets_under/

Leadership, Innovation, and the Future of AI: Lessons from Trend Micro CEO & Co-Founder Eva Chen
https://www.trendmicro.com/en_us/research/25/h/eva-chen-future-of-ai.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments
https://www.darknet.org.uk/2025/08/azurestrike-offensive-toolkit-for-attacking-azure-active-directory-environments/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.15776

Harmonious Color Pairings: Insights from Human Preference and Natural Hue Statistics
https://arxiv.org/abs/2508.15777

Towards Stealthy and Effective Backdoor Attacks on Lane Detection: A Naturalistic Data Poisoning Approach
https://arxiv.org/abs/2508.15778

Observer-Free Sliding Mode Control via Structured Decomposition: a Smooth and Bounded Control Framework
https://arxiv.org/abs/2508.15787

VR Fire safety training application
https://arxiv.org/abs/2508.15788

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Wyden calls for probe of federal judiciary data breaches, accusing it of ‘negligence’
https://therecord.media/wyden-probe-federal-judiciary-data-breaches

Maryland investigating cyberattack impacting transit service for disabled people
https://therecord.media/maryland-cyberattack-transit-disabled-people

South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities
https://therecord.media/south-korea-arrests-hacker-accused-of-targeting-celebrities-bts

Farmers Insurance says 1 million customers affected by cyberattack on third-party vendor
https://therecord.media/farmers-insurance-million-data-breach

Poor Password Choices
https://www.schneier.com/blog/archives/2025/08/poor-password-choices.html

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Vtenext 25.02: A three-way path to RCE
https://www.reddit.com/r/netsec/comments/1mzmrnp/vtenext_2502_a_threeway_path_to_rce/

Safeguarding VS Code against prompt injections
https://www.reddit.com/r/netsec/comments/1mzzh21/safeguarding_vs_code_against_prompt_injections/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.16579

DIAC ∞ 2: A Post-Quantum, P=NP-Resistant Cryptosystem
https://arxiv.org/abs/2508.15840

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Encryption Backdoor in Military/Police Radios
https://www.schneier.com/blog/archives/2025/08/encryption-backdoor-in-military-police-radios.html

ZipLine Campaign: A Sophisticated Phishing Attack Targeting US Companies
https://research.checkpoint.com/2025/zipline-phishing-campaign/

Nevada state websites, phone lines knocked offline by cyberattack
https://therecord.media/nevada-state-websites-phones-cyberattack-disruption

MITRE Introduces AADAPT Framework to Combat Crypto-Focused Cyber Threats
https://www.tripwire.com/state-of-security/mitre-introduces-aadapt-framework-combat-crypto-focused-cyber-threats

Securing and governing the rise of autonomous agents
https://www.microsoft.com/en-us/security/blog/2025/08/26/securing-and-governing-the-rise-of-autonomous-agents/

Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness
https://www.darknet.org.uk/2025/08/cybersecurity-workforce-trends-in-2025-skills-gap-diversity-and-soc-readiness/

This House is Haunted: a decade old RCE in the AION client
https://www.reddit.com/r/netsec/comments/1n0q5h7/this_house_is_haunted_a_decade_old_rce_in_the/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman