Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

N/A
N/A

Taming Shadow IT: What Security Teams Can Do About Unapproved Apps and Extensions
https://www.tripwire.com/state-of-security/taming-shadow-it-what-security-teams-can-do-about-unapproved-apps-and-extensions

LLM Coding Integrity Breach
https://www.schneier.com/blog/archives/2025/08/llm-coding-integrity-breach.html

Tens of thousands of Italian hotel guests may be hit by cyber heist
https://therecord.media/italy-hotel-guests-possible-data-breach-ids

Russia curbs WhatsApp, Telegram calls to counter cybercrime
https://therecord.media/russia-restricts-voice-calls-whatsapp-telegram-cybercrime

Hackers reportedly compromise Canadian House of Commons through Microsoft vulnerability
https://therecord.media/hackers-compromise-canada-house-of-commons

FCC’s data breach reporting rules for telecoms are upheld in appeals court
https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court

Norway police believe pro-Russian hackers were behind April dam sabotage
https://therecord.media/norway-police-suspect-pro-russian-hackers-dam-sabotage

Turkish crypto exchange BTCTurk warns of security incident after $49 million leaves platform
https://therecord.media/turkish-crypto-exchange-warns-cyber-incident

US updates sanctions on Russian cryptocurrency exchange Garantex
https://therecord.media/treasury-department-renews-sanctions-garantex-grinex

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msre41/how_exposed_teslamate_instances_leak_sensitive/

How Exposed TeslaMate Instances Leak Sensitive Tesla Data
https://www.reddit.com/r/netsec/comments/1msrpi6/how_exposed_teslamate_instances_leak_sensitive/

LostMyPassword – Dual Use Password Recovery and Credential Dumping Tool
https://www.darknet.org.uk/2025/08/lostmypassword-dual-use-password-recovery-and-credential-dumping-tool/

Securing Agentic AI: Threat Modeling and Risk Analysis for Network Monitoring Agentic AI System
https://securelist.com/pipemagic/117270/

A Rose by Any Other Name Would Smell as Sweet: Categorical Homotopy Theory for Large Language Models
https://arxiv.org/abs/2508.10043

A2HCoder: An LLM-Driven Coding Agent for Hierarchical Algorithm-to-HDL Translation
https://arxiv.org/abs/2508.10903

PersonaTwin: A Multi-Tier Prompt Conditioning Framework for Generating and Evaluating Personalized Digital Twins
https://arxiv.org/abs/2508.10904

Uncovering Latent Connections in Indigenous Heritage: Semantic Pipelines for Cultural Preservation in Brazil
https://arxiv.org/abs/2508.10906

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
https://arxiv.org/abs/2508.10911

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Plagued by Cyberattacks: Indian Healthcare Sector in Critical Condition
https://www.tripwire.com/state-of-security/plagued-cyberattacks-indian-healthcare-sector-critical-condition

Eavesdropping on Phone Conversations Through Vibrations
https://www.schneier.com/blog/archives/2025/08/eavesdropping-on-phone-conversations-through-vibrations.html

Workday hit by social engineering data breach targeting its CRM platform
https://therecord.media/workday-social-engineering-data-breach

Intel Outside: Hacking every Intel employee and various internal websites
https://www.reddit.com/r/netsec/comments/1mtnqme/intel_outside_hacking_every_intel_employee_and/

Cryptomining group Kinsing expands operations to Russia, researchers warn
https://therecord.media/cryptomining-group-kinsing-hits-russia

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development
https://www.reddit.com/r/netsec/comments/1mtpvuu/vibe_hacking_abusing_developer_trust_in_cursor/

Casino gaming company Bragg says hackers accessed ‘internal computer environment’
https://therecord.media/casino-gaming-company-cyber-incident-bragg

Ransomware gang masking PipeMagic backdoor as ChatGPT desktop app: Microsoft
https://therecord.media/ransomware-gang-masking-pipemagic-backdoor

Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a-modular-backdoor-framework/

CTF stats, mobile wallet attacks & magstripe demos – Payment Village @ DEF CON 33
https://www.reddit.com/r/netsec/comments/1mtw68x/ctf_stats_mobile_wallet_attacks_magstripe_demos/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

GodRAT – New RAT targeting financial institutions
https://securelist.com/godrat/117119/

Zero-Day Exploit in WinRAR File
https://www.schneier.com/blog/archives/2025/08/zero-day-exploit-in-winrar-file.html

UK ‘agrees to drop’ demand over Apple iCloud encryption
https://therecord.media/uk-agrees-drop-apple-encryption

Drug development company Inotiv reports ransomware attack to SEC
https://therecord.media/drug-development-innotiv-ransomware-sec

North Korea-linked hackers target embassies in Seoul in new espionage campaign
https://therecord.media/north-korean-hackers-target-foreign-embassies

Business Council of New York State says nearly 50,000 had data leaked in February cyberattack
https://therecord.media/new-york-business-council-data-breach

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories
https://www.reddit.com/r/netsec/comments/1mumb6z/how_we_exploited_coderabbit_from_a_simple_pr_to/

Trivial C# Random Exploitation
https://www.reddit.com/r/netsec/comments/1muf1om/trivial_c_random_exploitation/

Oregon Man Charged in ‘Rapper Bot’ DDoS Service
https://krebsonsecurity.com/2025/08/oregon-man-charged-in-rapper-bot-ddos-service/

Darknet Communications in 2025 – From IRC Forums to Telegram Crime Networks
https://www.darknet.org.uk/2025/08/darknet-communications-in-2025-from-irc-forums-to-telegram-crime-networks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Guess Who Would Be Stupid Enough To Rob The Same Vault Twice? Pre-Auth RCE Chains in Commvault - watchTowr Labs
https://arxiv.org/abs/2508.13214

Subverting AIOps Systems Through Poisoned Input Data
https://www.schneier.com/blog/archives/2025/08/subverting-aiops-systems-through-poisoned-input-data.html

NATO's Cybersecurity Spending Proposals’ Impact on the Industry
https://www.tripwire.com/state-of-security/natos-cybersecurity-spending-proposals-impact-industry

At least three UK organizations hit by SharePoint zero-day hacking campaign
https://therecord.media/organizations-united-kingdom/sharepoint

Major Belgian telecom firm says cyberattack compromised data on 850,000 accounts
https://therecord.media/belgian-telecom-says-cyberattack-compromised-data-on-850000

Russian investment platform confirms cyberattack by pro-Ukraine hackers
https://therecord.media/russia-cyberattack-investment-platform-ukraine

Feds charge administrator of ‘sophisticated’ DDoS-for-hire botnet
https://therecord.media/feds-charge-botnet-admin

Engineered to Fail: The DNA of Negligent Defenses Operations
https://www.reddit.com/r/netsec/comments/1mvijcg/engineered_to_fail_the_dna_of_negligent_defenses/

Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
https://www.trendmicro.com/en_us/research/25/h/warlock-ransomware.html

Google Unveils Enhanced Tools to Empower Defenders and Safeguard AI Progress
https://www.reddit.com/r/netsec/comments/1mvpbds/google_unveils_enhanced_tools_to_empower/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
https://www.reddit.com/r/netsec/comments/1mw4dn9/we_put_agentic_ai_browsers_to_the_test_they/

Jim Sanborn Is Auctioning Off the Solution to Part Four of the Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/08/jim-sanborn-is-auctioning-off-the-solution-to-part-four-of-the-kryptos-sculpture.html

Scattered Spider affiliate given 10 year sentence, ordered to pay $13 million in restitution
https://therecord.media/scattered-spider-affiliate-sentenced-10-years

Azure's Weakest Link - Full Cross-Tenant Compromise
https://www.reddit.com/r/netsec/comments/1mwbimu/azures_weakest_link_full_crosstenant_compromise/

AI can be used to create working exploits for published CVEs in a few minutes and for a few dollars
https://www.reddit.com/r/netsec/comments/1mwfks2/ai_can_be_used_to_create_working_exploits_for/

When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074)
https://www.reddit.com/r/netsec/comments/1mwhisp/when_a_ssrf_is_enough_full_docker_escape_on/

Think before you Click(Fix): Analyzing the ClickFix social engineering technique
https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/

Quantum-safe security: Progress towards next-generation cryptography
https://www.microsoft.com/en-us/security/blog/2025/08/20/quantum-safe-security-progress-towards-next-generation-cryptography/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Engineered to Fail: The DNA of Negligent Cyber Defenses
https://reporter.deepspecter.com/engineered-to-fail-the-dna-of-negligent-cyber-defenses-22466a034b28

Chinese national who sabotaged Ohio company’s systems handed four-year jail stint
https://therecord.media/chinese-national-sentenced-prison

CISA warns of Apple zero-day used in targeted cyberattacks
https://therecord.media/cisa-warns-of-apple-zero-day

Over 1,200 arrested in Africa-wide cybercrime crackdown, Interpol says
https://therecord.media/africa-interpol-cybercrime-crackdown

US warns tech companies against complying with European and British ‘censorship’ laws
https://therecord.media/tech-companies-ftc-censorship-laws

Electronics manufacturer Data I/O reports ransomware attack to SEC
https://therecord.media/electronics-manufacturer-dataio-ransomware

ChromeAlone – Chromium Browser C2 Implant for Red Team Operations
https://www.darknet.org.uk/2025/08/chromealone-chromium-browser-c2-implant-for-red-team-operations/

Silent Harvest: Extracting Windows Secrets Under the Radar
https://www.reddit.com/r/netsec/comments/1mxcig6/silent_harvest_extracting_windows_secrets_under/

Leadership, Innovation, and the Future of AI: Lessons from Trend Micro CEO & Co-Founder Eva Chen
https://www.trendmicro.com/en_us/research/25/h/eva-chen-future-of-ai.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AzureStrike – Offensive Toolkit for Attacking Azure Active Directory Environments
https://www.darknet.org.uk/2025/08/azurestrike-offensive-toolkit-for-attacking-azure-active-directory-environments/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.15776

Harmonious Color Pairings: Insights from Human Preference and Natural Hue Statistics
https://arxiv.org/abs/2508.15777

Towards Stealthy and Effective Backdoor Attacks on Lane Detection: A Naturalistic Data Poisoning Approach
https://arxiv.org/abs/2508.15778

Observer-Free Sliding Mode Control via Structured Decomposition: a Smooth and Bounded Control Framework
https://arxiv.org/abs/2508.15787

VR Fire safety training application
https://arxiv.org/abs/2508.15788

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Wyden calls for probe of federal judiciary data breaches, accusing it of ‘negligence’
https://therecord.media/wyden-probe-federal-judiciary-data-breaches

Maryland investigating cyberattack impacting transit service for disabled people
https://therecord.media/maryland-cyberattack-transit-disabled-people

South Korea arrests suspected Chinese hacker accused of targeting BTS singer and other celebrities
https://therecord.media/south-korea-arrests-hacker-accused-of-targeting-celebrities-bts

Farmers Insurance says 1 million customers affected by cyberattack on third-party vendor
https://therecord.media/farmers-insurance-million-data-breach

Poor Password Choices
https://www.schneier.com/blog/archives/2025/08/poor-password-choices.html

Tracking malicious code execution in Python
https://www.reddit.com/r/netsec/comments/1mzk3l4/tracking_malicious_code_execution_in_python/

Vtenext 25.02: A three-way path to RCE
https://www.reddit.com/r/netsec/comments/1mzmrnp/vtenext_2502_a_threeway_path_to_rce/

Safeguarding VS Code against prompt injections
https://www.reddit.com/r/netsec/comments/1mzzh21/safeguarding_vs_code_against_prompt_injections/

Implementing Zero Trust Architecture to Enhance Security and Resilience in the Pharmaceutical Supply Chain
https://arxiv.org/abs/2508.16579

DIAC ∞ 2: A Post-Quantum, P=NP-Resistant Cryptosystem
https://arxiv.org/abs/2508.15840

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Encryption Backdoor in Military/Police Radios
https://www.schneier.com/blog/archives/2025/08/encryption-backdoor-in-military-police-radios.html

ZipLine Campaign: A Sophisticated Phishing Attack Targeting US Companies
https://research.checkpoint.com/2025/zipline-phishing-campaign/

Nevada state websites, phone lines knocked offline by cyberattack
https://therecord.media/nevada-state-websites-phones-cyberattack-disruption

MITRE Introduces AADAPT Framework to Combat Crypto-Focused Cyber Threats
https://www.tripwire.com/state-of-security/mitre-introduces-aadapt-framework-combat-crypto-focused-cyber-threats

Securing and governing the rise of autonomous agents
https://www.microsoft.com/en-us/security/blog/2025/08/26/securing-and-governing-the-rise-of-autonomous-agents/

Cybersecurity Workforce Trends in 2025 – Skills Gap, Diversity and SOC Readiness
https://www.darknet.org.uk/2025/08/cybersecurity-workforce-trends-in-2025-skills-gap-diversity-and-soc-readiness/

This House is Haunted: a decade old RCE in the AION client
https://www.reddit.com/r/netsec/comments/1n0q5h7/this_house_is_haunted_a_decade_old_rce_in_the/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The UK May Be Dropping Its Backdoor Mandate
https://www.schneier.com/blog/archives/2025/08/the-uk-may-be-dropping-its-backdoor-mandate.html

The year so far: How Burp Suite DAST is leveling up enterprise security in 2025
https://portswigger.net/blog/the-year-so-far-how-burp-suite-dast-is-leveling-up-enterprise-security-in-2025

Dutch intelligence agencies report country was targeted by Chinese cyber spies
https://therecord.media/dutch-intelligence-cyber-spies-salt

Germany charges man over cyberattack on Rosneft subsidiary
https://therecord.media/germany-charges-cyberattack-rosneft

Chasing the Silver Fox: Cat & Mouse in Kernel Shadows
https://research.checkpoint.com/2025/silver-fox-apt-vulnerable-drivers/

CISA steps in to help Nevada state government recover from cyberattack
https://therecord.media/cisa-steps-nevada-cyber-state

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents
https://www.trendmicro.com/en_us/research/25/h/taoth-campaign.html

Microsoft warns of ransomware gang shifting to steal cloud data, lock companies out of systems
https://therecord.media/ransomware-gangs-shift-to-stealing-cloud-data

Data breach at TransUnion impacts 4.4 million people
https://therecord.media/transunion-data-breach-4-million

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Rage Against the Authentication State Machine (CVE-2024-28080)
https://www.reddit.com/r/netsec/comments/1n31plm/rage_against_the_authentication_state_machine/

How attackers adapt to built-in macOS protection
https://securelist.com/macos-security-and-typical-attacks/117367/

Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1n33j71/cache_me_if_you_can_sitecore_experience_platform/

Baggage Tag Scam
https://www.schneier.com/blog/archives/2025/08/baggage-tag-scam.html

Ransomware gang takedowns causing explosion of new, smaller groups
https://therecord.media/ransomware-gang-takedown-proliferation

AI Waifu RAT: A Ring3 malware-like RAT based on LLM manipulation is circulating in the wild.
https://www.reddit.com/r/netsec/comments/1n3a1ll/ai_waifu_rat_a_ring3_malwarelike_rat_based_on_llm/

Hidden in plain sight: a misconfigured upload path that invited trouble
https://www.reddit.com/r/netsec/comments/1n3cu26/hidden_in_plain_sight_a_misconfigured_upload_path/

Operation Serengeti 2.0: Trend Micro Helps Law Enforcement Fight Cybercrime in Africa
https://www.trendmicro.com/en_us/research/25/h/operation-serengeti-trend-micro.html

Scammer steals $1.5 million from Baltimore by spoofing city vendor
https://therecord.media/scammer-steals-baltimore-city-impersonation-vendor

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

ZERO-DAY ALERT: Automated Discovery of Critical CWMP Stack Overflow in TP-Link Routers
https://www.reddit.com/r/netsec/comments/1n5dil1/zeroday_alert_automated_discovery_of_critical/

Normalisation of SWIFT Message Counterparties with Feature Extraction and Clustering
https://arxiv.org/abs/2508.21081

CoBA: Counterbias Text Augmentation for Mitigating Various Spurious Correlations via Semantic Triples
https://arxiv.org/abs/2508.21083

2COOOL: 2nd Workshop on the Challenge Of Out-Of-Label Hazards in Autonomous Driving
https://arxiv.org/abs/2508.21080

Mapping Toxic Comments Across Demographics: A Dataset from German Public Broadcasting
https://arxiv.org/abs/2508.21084

Granite Embedding R2 Models
https://arxiv.org/abs/2508.21085

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Deep Specter Research Uncovers a Global Phishing Empire
https://www.reddit.com/r/netsec/comments/1n6jj7q/deep_specter_research_uncovers_a_global_phishing/

Ksmbd Fuzzing Improvements and Vulnerability Discovery
https://www.reddit.com/r/netsec/comments/1n6exne/ksmbd_fuzzing_improvements_and_vulnerability/

Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it
https://securelist.com/cookies-and-session-hijacking/117390/

1965 Cryptanalysis Training Workbook Released by the NSA
https://www.schneier.com/blog/archives/2025/09/1965-cryptanalysis-training-workbook-released-by-the-nsa.html

Golden dMSA
https://www.reddit.com/r/netsec/comments/1n6g94k/golden_dmsa/

Jaguar Land Rover ‘severely disrupted’ by cybersecurity incident
https://therecord.media/jaguar-land-rover-disruption-cyber-incident

WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
https://therecord.media/whatsapp-apple-zero-day-targeted-attacks

RapperBot: infection → DDoS in seconds (deep dive write-up)
https://www.reddit.com/r/netsec/comments/1n6lsmy/rapperbot_infection_ddos_in_seconds_deep_dive/

Pennsylvania AG says recovery continues after office refused to pay ransomware gang
https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery

Disney agrees to $10 million settlement for collecting data from children
https://therecord.media/disney-settles-with-ftc-millions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Corruption case against ousted cyber chief is ‘revenge,’ Ukraine’s security service says
https://therecord.media/corruption-case-against-ousted-cyber

Salesloft, Drift among companies impacted by incident
https://therecord.media/salesloft-drift-breach-cloudflare-zscaler-palo-alto-networks

How They Got In — DaVita’s Data Breach
https://www.reddit.com/r/netsec/comments/1n7efek/how_they_got_in_davitas_data_breach/

Effective Incident Response
https://www.reddit.com/r/netsec/comments/1n7fek1/effective_incident_response/

Inline Style Exfiltration: leaking data with chained CSS conditionals
https://www.reddit.com/r/netsec/comments/1n7fexe/inline_style_exfiltration_leaking_data_with/

Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel
https://www.reddit.com/r/netsec/comments/1n7dp5m/kernelhackdrill_and_a_new_approach_to_exploiting/

Two arrested in Egypt as authorities take down Streameast sports piracy platform
https://therecord.media/streameast-sports-piracy-site-takedown-arrests-egypt

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman