Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

The UK May Be Dropping Its Backdoor Mandate
https://www.schneier.com/blog/archives/2025/08/the-uk-may-be-dropping-its-backdoor-mandate.html

The year so far: How Burp Suite DAST is leveling up enterprise security in 2025
https://portswigger.net/blog/the-year-so-far-how-burp-suite-dast-is-leveling-up-enterprise-security-in-2025

Dutch intelligence agencies report country was targeted by Chinese cyber spies
https://therecord.media/dutch-intelligence-cyber-spies-salt

Germany charges man over cyberattack on Rosneft subsidiary
https://therecord.media/germany-charges-cyberattack-rosneft

Chasing the Silver Fox: Cat & Mouse in Kernel Shadows
https://research.checkpoint.com/2025/silver-fox-apt-vulnerable-drivers/

CISA steps in to help Nevada state government recover from cyberattack
https://therecord.media/cisa-steps-nevada-cyber-state

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents
https://www.trendmicro.com/en_us/research/25/h/taoth-campaign.html

Microsoft warns of ransomware gang shifting to steal cloud data, lock companies out of systems
https://therecord.media/ransomware-gangs-shift-to-stealing-cloud-data

Data breach at TransUnion impacts 4.4 million people
https://therecord.media/transunion-data-breach-4-million

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Rage Against the Authentication State Machine (CVE-2024-28080)
https://www.reddit.com/r/netsec/comments/1n31plm/rage_against_the_authentication_state_machine/

How attackers adapt to built-in macOS protection
https://securelist.com/macos-security-and-typical-attacks/117367/

Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1n33j71/cache_me_if_you_can_sitecore_experience_platform/

Baggage Tag Scam
https://www.schneier.com/blog/archives/2025/08/baggage-tag-scam.html

Ransomware gang takedowns causing explosion of new, smaller groups
https://therecord.media/ransomware-gang-takedown-proliferation

AI Waifu RAT: A Ring3 malware-like RAT based on LLM manipulation is circulating in the wild.
https://www.reddit.com/r/netsec/comments/1n3a1ll/ai_waifu_rat_a_ring3_malwarelike_rat_based_on_llm/

Hidden in plain sight: a misconfigured upload path that invited trouble
https://www.reddit.com/r/netsec/comments/1n3cu26/hidden_in_plain_sight_a_misconfigured_upload_path/

Operation Serengeti 2.0: Trend Micro Helps Law Enforcement Fight Cybercrime in Africa
https://www.trendmicro.com/en_us/research/25/h/operation-serengeti-trend-micro.html

Scammer steals $1.5 million from Baltimore by spoofing city vendor
https://therecord.media/scammer-steals-baltimore-city-impersonation-vendor

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

ZERO-DAY ALERT: Automated Discovery of Critical CWMP Stack Overflow in TP-Link Routers
https://www.reddit.com/r/netsec/comments/1n5dil1/zeroday_alert_automated_discovery_of_critical/

Normalisation of SWIFT Message Counterparties with Feature Extraction and Clustering
https://arxiv.org/abs/2508.21081

CoBA: Counterbias Text Augmentation for Mitigating Various Spurious Correlations via Semantic Triples
https://arxiv.org/abs/2508.21083

2COOOL: 2nd Workshop on the Challenge Of Out-Of-Label Hazards in Autonomous Driving
https://arxiv.org/abs/2508.21080

Mapping Toxic Comments Across Demographics: A Dataset from German Public Broadcasting
https://arxiv.org/abs/2508.21084

Granite Embedding R2 Models
https://arxiv.org/abs/2508.21085

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Deep Specter Research Uncovers a Global Phishing Empire
https://www.reddit.com/r/netsec/comments/1n6jj7q/deep_specter_research_uncovers_a_global_phishing/

Ksmbd Fuzzing Improvements and Vulnerability Discovery
https://www.reddit.com/r/netsec/comments/1n6exne/ksmbd_fuzzing_improvements_and_vulnerability/

Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it
https://securelist.com/cookies-and-session-hijacking/117390/

1965 Cryptanalysis Training Workbook Released by the NSA
https://www.schneier.com/blog/archives/2025/09/1965-cryptanalysis-training-workbook-released-by-the-nsa.html

Golden dMSA
https://www.reddit.com/r/netsec/comments/1n6g94k/golden_dmsa/

Jaguar Land Rover ‘severely disrupted’ by cybersecurity incident
https://therecord.media/jaguar-land-rover-disruption-cyber-incident

WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
https://therecord.media/whatsapp-apple-zero-day-targeted-attacks

RapperBot: infection → DDoS in seconds (deep dive write-up)
https://www.reddit.com/r/netsec/comments/1n6lsmy/rapperbot_infection_ddos_in_seconds_deep_dive/

Pennsylvania AG says recovery continues after office refused to pay ransomware gang
https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery

Disney agrees to $10 million settlement for collecting data from children
https://therecord.media/disney-settles-with-ftc-millions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Corruption case against ousted cyber chief is ‘revenge,’ Ukraine’s security service says
https://therecord.media/corruption-case-against-ousted-cyber

Salesloft, Drift among companies impacted by incident
https://therecord.media/salesloft-drift-breach-cloudflare-zscaler-palo-alto-networks

How They Got In — DaVita’s Data Breach
https://www.reddit.com/r/netsec/comments/1n7efek/how_they_got_in_davitas_data_breach/

Effective Incident Response
https://www.reddit.com/r/netsec/comments/1n7fek1/effective_incident_response/

Inline Style Exfiltration: leaking data with chained CSS conditionals
https://www.reddit.com/r/netsec/comments/1n7fexe/inline_style_exfiltration_leaking_data_with/

Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel
https://www.reddit.com/r/netsec/comments/1n7dp5m/kernelhackdrill_and_a_new_approach_to_exploiting/

Two arrested in Egypt as authorities take down Streameast sports piracy platform
https://therecord.media/streameast-sports-piracy-site-takedown-arrests-egypt

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025
https://www.reddit.com/r/netsec/comments/1namtpn/the_salesloftdrift_breach_analyzing_the_biggest/

New OpenSecurityTraining2 class: "Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting" (~8 hours)
https://www.reddit.com/r/netsec/comments/1natzsl/new_opensecuritytraining2_class_bluetooth_2222/

New iOS/macOS Critical DNG Image Processing Memory Corruption Exploitation Tutorial
https://www.reddit.com/r/netsec/comments/1nb4a2v/new_iosmacos_critical_dng_image_processing_memory/

Using AI Agents for Code Auditing: Full Walkthrough on Finding Security Bugs in a Rust REST Server with Hound
https://www.reddit.com/r/netsec/comments/1nbclku/using_ai_agents_for_code_auditing_full/

killerPID-BOF
https://www.reddit.com/r/netsec/comments/1nbbdyh/killerpidbof/

GitHub Actions: A Cloudy Day for Security - Part 1
https://www.reddit.com/r/netsec/comments/1nbgj2h/github_actions_a_cloudy_day_for_security_part_1/

PRREACH: Probabilistic Risk Assessment Using Reachability for UAV Control
https://arxiv.org/abs/2509.04451

INSEva: A Comprehensive Chinese Benchmark for Large Language Models in Insurance
https://arxiv.org/abs/2509.04455

Mentalic Net: Development of RAG-based Conversational AI and Evaluation Framework for Mental Health Support
https://arxiv.org/abs/2509.04456

Automotive Privacy in California: The UX Benchmark That Could Change Everything
https://www.tripwire.com/state-of-security/automotive-privacy-california-ux-benchmark-could-change-everything

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Nepal social media ban sparks protests, dozens injured
https://therecord.media/nepal-social-media-ban-protests

Kazakh oil giant denies cyberattack, says incident was 'planned' phishing drill
https://therecord.media/kazakstan-oil-company-kazmunaygas-phishing-simulation-not-cyberattack

US sanctions companies behind cyber scam centers in Cambodia, Myanmar
https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds

Cyberattack on Jaguar Land Rover threatens to hit British economic growth
https://therecord.media/cyberattack-jaguar-land-rover-economic-growth-uk-government

Hacker broke into Salesloft systems in March through GitHub account
https://therecord.media/salesloft-hacker-broke-into-github

18 Popular Code Packages Hacked, Rigged to Steal Crypto
https://krebsonsecurity.com/2025/09/18-popular-code-packages-hacked-rigged-to-steal-crypto/

AI in Government
https://www.schneier.com/blog/archives/2025/09/ai-in-government.html

8th September – Threat Intelligence Report
https://research.checkpoint.com/2025/8th-september-threat-intelligence-report/

Manipulating Transformer-Based Models: Controllability, Steerability, and Robust Interventions
https://arxiv.org/abs/2509.04549

Persona Vectors: Monitoring and Controlling Character Traits in Language Models
https://arxiv.org/abs/2507.21509

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

[New Cryptanalysis of the Fiat-Shamir Protocol](https://www.schneier.com/blog/archives/2025/09/new-cryptanalysis-of-the-fiat-shamir-protocol.html)

[ASNiP – ASN Reconnaissance via Domain and IP Mapping](https://www.darknet.org.uk/2025/09/asnip-asn-reconnaissance-via-domain-and-ip-mapping/)

[Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed](https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html)

[Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat'](https://therecord.media/cyber-command-nsa-dual-hat-single-leader-trump-administration)

[Mitsubishi Electric to acquire Nozomi Networks for $883 million](https://therecord.media/nozomi-networks-mitsubishi-electric-acquisition)

[Brazil lesbian dating app shuts down after security flaw exposes sensitive user data](https://therecord.media/brazil-lesbian-dating-app-shuts-down-vulnerability)

[Major blood center says thousands had data leaked in January ransomware attack](https://therecord.media/blood-center-discloses-details-on--january-ransomware-attack)

[Microsoft Patch Tuesday, September 2025 Security Update Review](https://blog.qualys.com/vulnerabilities-threat-research/2025/09/09/microsoft-patch-tuesday-september-2025-security-update-review)

[Apple Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research](https://www.reddit.com/r/netsec/comments/1ncw817/apple_memory_integrity_enforcement_a_complete/)

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Practice spotting typo squatted domains (Browser game: Typosquat Detective)
https://www.reddit.com/r/netsec/comments/1ne4f2u/practice_spotting_typo_squatted_domains_browser/

Why File Integrity Monitoring (FIM) Is a Must for Compliance — And How to Pick the Right Solution
https://www.tripwire.com/state-of-security/file-integrity-monitoring-fim-compliance-right-solution

Dark Web Search Engines in 2025 – Rankings, Risks & Ethical Trade-offs
https://www.darknet.org.uk/2025/09/dark-web-search-engines-in-2025-rankings-risks-ethical-trade-offs/

UK delays introducing new cybersecurity legislation, again
https://therecord.media/uk-cybersecurity-law-update-csrb-delayed-again

EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks
https://www.trendmicro.com/en_us/research/25/i/evilai.html

FTC should investigate Microsoft after Ascension ransomware attack, senator says
https://therecord.media/ascension-ransomware-attack-wyden-seeks-ftc-microsoft-investigation

Cyberattacks against schools driven by a rise in student hackers, ICO warns
https://therecord.media/cyberattacks-against-schools-driven-by-student-hackers

Inboxfuscation - a free, open-source obfuscation and detection framework to help security teams detect and stop Unicode-obfuscated Microsoft Exchange inbox rules
https://www.reddit.com/r/netsec/comments/1neaop8/inboxfuscation_a_free_opensource_obfuscation_and/

FTC opens inquiry into how AI chatbots impact child safety, privacy
https://therecord.media/ftc-opens-inquiry-ai-chatbots-kids

Bulletproof Host Stark Industries Evades EU Sanctions
https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Hacker convicted of extorting 20,000 psychotherapy victims walks free during appeal
https://therecord.media/finland-vastaamo-hacker-free-during-appeal-conviction

How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities
https://portswigger.net/blog/how-this-seasoned-bug-bounty-hunter-combines-burp-suite-and-hackerone-to-uncover-high-impact-vulnerabilities

Yurei & The Ghost of Open Source Ransomware
https://research.checkpoint.com/2025/yurei-the-ghost-of-open-source-ransomware/

CISA official calls on lawmakers to extend cyber info-sharing law
https://therecord.media/cisa-official-calls-on-lawmakers-renew-cisa2015

Vietnam, Panama governments suffer incidents leaking citizen data
https://therecord.media/vietnam-cic-panama-finance-ministry-cyberattacks

DHS inspector general: CISA mismanaged multimillion-dollar employee incentives program
https://therecord.media/cisa-cybersecurity-retention-incentives-dhs-ig-audit

Philippine military company spied upon with new China-linked malware
https://therecord.media/philippines-military-company-suspected-china-espionage-eggstreme-malware

A Cyberattack Victim Notification Framework
https://www.schneier.com/blog/archives/2025/09/a-cyberattack-victim-notification-framework.html

Fine-grained HTTP filtering for Claude Code
https://www.reddit.com/r/netsec/comments/1nff57n/finegrained_http_filtering_for_claude_code/

WSASS - Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
https://www.reddit.com/r/netsec/comments/1nfrgc1/wsass_old_but_gold_dumping_lsass_with_windows/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

On the Security of SSH Client Signatures
https://reporter.deepspecter.com/

2025 Supabase Security Best Practices Guide - Common Misconfigs from Recent Pentests.
https://www.reddit.com/r/netsec/comments/1ngzvfi/2025_supabase_security_best_practices_guide/

New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://www.reddit.com/r/netsec/comments/1nh52qm/new_opensecuritytraining2_class_tpm_20/

Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
https://www.reddit.com/r/netsec/comments/1nh7yuo/strategies_for_analyzing_native_code_in_android/

pyLDAPGui - Python based GUI for browsing LDAP
https://www.reddit.com/r/netsec/comments/1nh8qvn/pyldapgui_python_based_gui_for_browsing_ldap/

DB3 Team's Solution For Meta KDD Cup' 25
https://arxiv.org/abs/2509.09684

Faster and Memory-Efficient Training of Sequential Recommendation Models for Large Catalogs
https://arxiv.org/abs/2509.09681

Forecasting Clicks in Digital Advertising: Multimodal Inputs and Interpretable Outputs
https://arxiv.org/abs/2509.09682

Text-to-SQL Oriented to the Process Mining Domain: A PT-EN Dataset for Query Translation
https://arxiv.org/abs/2509.09683

TalkPlayData 2: An Agentic Synthetic Data Pipeline for Multimodal Conversational Music Recommendation
https://arxiv.org/abs/2509.09331

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Shiny tools, shallow checks: how the AI hype opens the door to malicious MCP servers
https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/

Lawsuit About WhatsApp Security
https://www.schneier.com/blog/archives/2025/09/lawsuit-about-whatsapp-security.html

15th September – Threat Intelligence Report
https://research.checkpoint.com/2025/15th-september-threat-intelligence-report/

US national charged in Finnish psychotherapy center extortion
https://therecord.media/finland-vastaamo-hack-us-national-charged

New Zealand sanctions Russian military hackers over cyberattacks on Ukraine
https://therecord.media/new-zealand-russia-gru-ukraine

Europol adds Spanish academic suspected of aiding pro-Russian hackers to most wanted list
https://therecord.media/europol-adds-spanish-academic-most-wanted-russia-hack

FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce platforms
https://therecord.media/fbi-warns-scattered-spider-salesforce

Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions
https://therecord.media/ukraine-claims-ddos-attack-russian-election-system

Uvalde school district says ransomware attack forcing closure until Thursday
https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT
https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/

Microsoft Still Uses RC4
https://www.schneier.com/blog/archives/2025/09/microsoft-still-uses-rc4.html

Building a compiler custom programming language
https://www.reddit.com/r/lowlevel/comments/1nierls/building_a_compiler_custom_programming_language/

New LG Vulnerability - LG WebOS TV Path Traversal, Authentication Bypass and Full Device Takeover
https://www.reddit.com/r/netsec/comments/1nif05t/new_lg_vulnerability_lg_webos_tv_path_traversal/

Jaguar Land Rover says cyberattack shutdown to last 'at least' another week
https://therecord.media/jaguar-land-rover-another-week-shutdown-cyberattack

Windows 10 Retirement: A Reminder for Managing Legacy Industrial Control Systems (ICS)
https://www.tripwire.com/state-of-security/windows-10-retirement-reminder-managing-legacy-industrial-control-systems-ics

Under the Pure Curtain: From RAT to Builder to Coder
https://research.checkpoint.com/2025/under-the-pure-curtain-from-rat-to-builder-to-coder/

Self-Replicating Worm Hits 180+ Software Packages
https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman