Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Deep Specter Research Uncovers a Global Phishing Empire
https://www.reddit.com/r/netsec/comments/1n6jj7q/deep_specter_research_uncovers_a_global_phishing/

Ksmbd Fuzzing Improvements and Vulnerability Discovery
https://www.reddit.com/r/netsec/comments/1n6exne/ksmbd_fuzzing_improvements_and_vulnerability/

Cookies and how to bake them: what they are for, associated risks, and what session hijacking has to do with it
https://securelist.com/cookies-and-session-hijacking/117390/

1965 Cryptanalysis Training Workbook Released by the NSA
https://www.schneier.com/blog/archives/2025/09/1965-cryptanalysis-training-workbook-released-by-the-nsa.html

Golden dMSA
https://www.reddit.com/r/netsec/comments/1n6g94k/golden_dmsa/

Jaguar Land Rover ‘severely disrupted’ by cybersecurity incident
https://therecord.media/jaguar-land-rover-disruption-cyber-incident

WhatsApp, Apple warn of highly targeted attacks with zero-day vulnerability
https://therecord.media/whatsapp-apple-zero-day-targeted-attacks

RapperBot: infection → DDoS in seconds (deep dive write-up)
https://www.reddit.com/r/netsec/comments/1n6lsmy/rapperbot_infection_ddos_in_seconds_deep_dive/

Pennsylvania AG says recovery continues after office refused to pay ransomware gang
https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery

Disney agrees to $10 million settlement for collecting data from children
https://therecord.media/disney-settles-with-ftc-millions

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Corruption case against ousted cyber chief is ‘revenge,’ Ukraine’s security service says
https://therecord.media/corruption-case-against-ousted-cyber

Salesloft, Drift among companies impacted by incident
https://therecord.media/salesloft-drift-breach-cloudflare-zscaler-palo-alto-networks

How They Got In — DaVita’s Data Breach
https://www.reddit.com/r/netsec/comments/1n7efek/how_they_got_in_davitas_data_breach/

Effective Incident Response
https://www.reddit.com/r/netsec/comments/1n7fek1/effective_incident_response/

Inline Style Exfiltration: leaking data with chained CSS conditionals
https://www.reddit.com/r/netsec/comments/1n7fexe/inline_style_exfiltration_leaking_data_with/

Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel
https://www.reddit.com/r/netsec/comments/1n7dp5m/kernelhackdrill_and_a_new_approach_to_exploiting/

Two arrested in Egypt as authorities take down Streameast sports piracy platform
https://therecord.media/streameast-sports-piracy-site-takedown-arrests-egypt

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025
https://www.reddit.com/r/netsec/comments/1namtpn/the_salesloftdrift_breach_analyzing_the_biggest/

New OpenSecurityTraining2 class: "Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting" (~8 hours)
https://www.reddit.com/r/netsec/comments/1natzsl/new_opensecuritytraining2_class_bluetooth_2222/

New iOS/macOS Critical DNG Image Processing Memory Corruption Exploitation Tutorial
https://www.reddit.com/r/netsec/comments/1nb4a2v/new_iosmacos_critical_dng_image_processing_memory/

Using AI Agents for Code Auditing: Full Walkthrough on Finding Security Bugs in a Rust REST Server with Hound
https://www.reddit.com/r/netsec/comments/1nbclku/using_ai_agents_for_code_auditing_full/

killerPID-BOF
https://www.reddit.com/r/netsec/comments/1nbbdyh/killerpidbof/

GitHub Actions: A Cloudy Day for Security - Part 1
https://www.reddit.com/r/netsec/comments/1nbgj2h/github_actions_a_cloudy_day_for_security_part_1/

PRREACH: Probabilistic Risk Assessment Using Reachability for UAV Control
https://arxiv.org/abs/2509.04451

INSEva: A Comprehensive Chinese Benchmark for Large Language Models in Insurance
https://arxiv.org/abs/2509.04455

Mentalic Net: Development of RAG-based Conversational AI and Evaluation Framework for Mental Health Support
https://arxiv.org/abs/2509.04456

Automotive Privacy in California: The UX Benchmark That Could Change Everything
https://www.tripwire.com/state-of-security/automotive-privacy-california-ux-benchmark-could-change-everything

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Nepal social media ban sparks protests, dozens injured
https://therecord.media/nepal-social-media-ban-protests

Kazakh oil giant denies cyberattack, says incident was 'planned' phishing drill
https://therecord.media/kazakstan-oil-company-kazmunaygas-phishing-simulation-not-cyberattack

US sanctions companies behind cyber scam centers in Cambodia, Myanmar
https://therecord.media/us-sanctions-companies-southeast-asia-scam-compounds

Cyberattack on Jaguar Land Rover threatens to hit British economic growth
https://therecord.media/cyberattack-jaguar-land-rover-economic-growth-uk-government

Hacker broke into Salesloft systems in March through GitHub account
https://therecord.media/salesloft-hacker-broke-into-github

18 Popular Code Packages Hacked, Rigged to Steal Crypto
https://krebsonsecurity.com/2025/09/18-popular-code-packages-hacked-rigged-to-steal-crypto/

AI in Government
https://www.schneier.com/blog/archives/2025/09/ai-in-government.html

8th September – Threat Intelligence Report
https://research.checkpoint.com/2025/8th-september-threat-intelligence-report/

Manipulating Transformer-Based Models: Controllability, Steerability, and Robust Interventions
https://arxiv.org/abs/2509.04549

Persona Vectors: Monitoring and Controlling Character Traits in Language Models
https://arxiv.org/abs/2507.21509

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

[New Cryptanalysis of the Fiat-Shamir Protocol](https://www.schneier.com/blog/archives/2025/09/new-cryptanalysis-of-the-fiat-shamir-protocol.html)

[ASNiP – ASN Reconnaissance via Domain and IP Mapping](https://www.darknet.org.uk/2025/09/asnip-asn-reconnaissance-via-domain-and-ip-mapping/)

[Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed](https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html)

[Cyber Command, NSA to remain under single leader as officials shelve plan to end 'dual hat'](https://therecord.media/cyber-command-nsa-dual-hat-single-leader-trump-administration)

[Mitsubishi Electric to acquire Nozomi Networks for $883 million](https://therecord.media/nozomi-networks-mitsubishi-electric-acquisition)

[Brazil lesbian dating app shuts down after security flaw exposes sensitive user data](https://therecord.media/brazil-lesbian-dating-app-shuts-down-vulnerability)

[Major blood center says thousands had data leaked in January ransomware attack](https://therecord.media/blood-center-discloses-details-on--january-ransomware-attack)

[Microsoft Patch Tuesday, September 2025 Security Update Review](https://blog.qualys.com/vulnerabilities-threat-research/2025/09/09/microsoft-patch-tuesday-september-2025-security-update-review)

[Apple Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research](https://www.reddit.com/r/netsec/comments/1ncw817/apple_memory_integrity_enforcement_a_complete/)

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Practice spotting typo squatted domains (Browser game: Typosquat Detective)
https://www.reddit.com/r/netsec/comments/1ne4f2u/practice_spotting_typo_squatted_domains_browser/

Why File Integrity Monitoring (FIM) Is a Must for Compliance — And How to Pick the Right Solution
https://www.tripwire.com/state-of-security/file-integrity-monitoring-fim-compliance-right-solution

Dark Web Search Engines in 2025 – Rankings, Risks & Ethical Trade-offs
https://www.darknet.org.uk/2025/09/dark-web-search-engines-in-2025-rankings-risks-ethical-trade-offs/

UK delays introducing new cybersecurity legislation, again
https://therecord.media/uk-cybersecurity-law-update-csrb-delayed-again

EvilAI Operators Use AI-Generated Code and Fake Apps for Far-Reaching Attacks
https://www.trendmicro.com/en_us/research/25/i/evilai.html

FTC should investigate Microsoft after Ascension ransomware attack, senator says
https://therecord.media/ascension-ransomware-attack-wyden-seeks-ftc-microsoft-investigation

Cyberattacks against schools driven by a rise in student hackers, ICO warns
https://therecord.media/cyberattacks-against-schools-driven-by-student-hackers

Inboxfuscation - a free, open-source obfuscation and detection framework to help security teams detect and stop Unicode-obfuscated Microsoft Exchange inbox rules
https://www.reddit.com/r/netsec/comments/1neaop8/inboxfuscation_a_free_opensource_obfuscation_and/

FTC opens inquiry into how AI chatbots impact child safety, privacy
https://therecord.media/ftc-opens-inquiry-ai-chatbots-kids

Bulletproof Host Stark Industries Evades EU Sanctions
https://krebsonsecurity.com/2025/09/bulletproof-host-stark-industries-evades-eu-sanctions/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Hacker convicted of extorting 20,000 psychotherapy victims walks free during appeal
https://therecord.media/finland-vastaamo-hacker-free-during-appeal-conviction

How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities
https://portswigger.net/blog/how-this-seasoned-bug-bounty-hunter-combines-burp-suite-and-hackerone-to-uncover-high-impact-vulnerabilities

Yurei & The Ghost of Open Source Ransomware
https://research.checkpoint.com/2025/yurei-the-ghost-of-open-source-ransomware/

CISA official calls on lawmakers to extend cyber info-sharing law
https://therecord.media/cisa-official-calls-on-lawmakers-renew-cisa2015

Vietnam, Panama governments suffer incidents leaking citizen data
https://therecord.media/vietnam-cic-panama-finance-ministry-cyberattacks

DHS inspector general: CISA mismanaged multimillion-dollar employee incentives program
https://therecord.media/cisa-cybersecurity-retention-incentives-dhs-ig-audit

Philippine military company spied upon with new China-linked malware
https://therecord.media/philippines-military-company-suspected-china-espionage-eggstreme-malware

A Cyberattack Victim Notification Framework
https://www.schneier.com/blog/archives/2025/09/a-cyberattack-victim-notification-framework.html

Fine-grained HTTP filtering for Claude Code
https://www.reddit.com/r/netsec/comments/1nff57n/finegrained_http_filtering_for_claude_code/

WSASS - Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
https://www.reddit.com/r/netsec/comments/1nfrgc1/wsass_old_but_gold_dumping_lsass_with_windows/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

On the Security of SSH Client Signatures
https://reporter.deepspecter.com/

2025 Supabase Security Best Practices Guide - Common Misconfigs from Recent Pentests.
https://www.reddit.com/r/netsec/comments/1ngzvfi/2025_supabase_security_best_practices_guide/

New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://www.reddit.com/r/netsec/comments/1nh52qm/new_opensecuritytraining2_class_tpm_20/

Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
https://www.reddit.com/r/netsec/comments/1nh7yuo/strategies_for_analyzing_native_code_in_android/

pyLDAPGui - Python based GUI for browsing LDAP
https://www.reddit.com/r/netsec/comments/1nh8qvn/pyldapgui_python_based_gui_for_browsing_ldap/

DB3 Team's Solution For Meta KDD Cup' 25
https://arxiv.org/abs/2509.09684

Faster and Memory-Efficient Training of Sequential Recommendation Models for Large Catalogs
https://arxiv.org/abs/2509.09681

Forecasting Clicks in Digital Advertising: Multimodal Inputs and Interpretable Outputs
https://arxiv.org/abs/2509.09682

Text-to-SQL Oriented to the Process Mining Domain: A PT-EN Dataset for Query Translation
https://arxiv.org/abs/2509.09683

TalkPlayData 2: An Agentic Synthetic Data Pipeline for Multimodal Conversational Music Recommendation
https://arxiv.org/abs/2509.09331

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Shiny tools, shallow checks: how the AI hype opens the door to malicious MCP servers
https://securelist.com/model-context-protocol-for-ai-integration-abused-in-supply-chain-attacks/117473/

Lawsuit About WhatsApp Security
https://www.schneier.com/blog/archives/2025/09/lawsuit-about-whatsapp-security.html

15th September – Threat Intelligence Report
https://research.checkpoint.com/2025/15th-september-threat-intelligence-report/

US national charged in Finnish psychotherapy center extortion
https://therecord.media/finland-vastaamo-hack-us-national-charged

New Zealand sanctions Russian military hackers over cyberattacks on Ukraine
https://therecord.media/new-zealand-russia-gru-ukraine

Europol adds Spanish academic suspected of aiding pro-Russian hackers to most wanted list
https://therecord.media/europol-adds-spanish-academic-most-wanted-russia-hack

FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce platforms
https://therecord.media/fbi-warns-scattered-spider-salesforce

Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions
https://therecord.media/ukraine-claims-ddos-attack-russian-election-system

Uvalde school district says ransomware attack forcing closure until Thursday
https://therecord.media/uvalde-texas-school-district-temporarily-closing-ransomware

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

RevengeHotels: a new wave of attacks leveraging LLMs and VenomRAT
https://securelist.com/revengehotels-attacks-with-ai-and-venomrat-across-latin-america/117493/

Microsoft Still Uses RC4
https://www.schneier.com/blog/archives/2025/09/microsoft-still-uses-rc4.html

Building a compiler custom programming language
https://www.reddit.com/r/lowlevel/comments/1nierls/building_a_compiler_custom_programming_language/

New LG Vulnerability - LG WebOS TV Path Traversal, Authentication Bypass and Full Device Takeover
https://www.reddit.com/r/netsec/comments/1nif05t/new_lg_vulnerability_lg_webos_tv_path_traversal/

Jaguar Land Rover says cyberattack shutdown to last 'at least' another week
https://therecord.media/jaguar-land-rover-another-week-shutdown-cyberattack

Windows 10 Retirement: A Reminder for Managing Legacy Industrial Control Systems (ICS)
https://www.tripwire.com/state-of-security/windows-10-retirement-reminder-managing-legacy-industrial-control-systems-ics

Under the Pure Curtain: From RAT to Builder to Coder
https://research.checkpoint.com/2025/under-the-pure-curtain-from-rat-to-builder-to-coder/

Self-Replicating Worm Hits 180+ Software Packages
https://krebsonsecurity.com/2025/09/self-replicating-worm-hits-180-software-packages/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Two teenage suspected Scattered Spider members charged in UK over TfL hack
https://therecord.media/scattered-spider-teenage-suspects-arrested-britain-nca

Taliban bans fiber-optic internet in several Afghan provinces to curb ‘immorality’
https://therecord.media/taliban-bans-fiber-optic-internet

Russian regional airline disrupted by suspected cyberattack
https://therecord.media/russia-krasavia-airline-disrupted-suspected-cyberattack

Brazil enacts sweeping bill requiring online age verification, safeguards for children’s data
https://therecord.media/brazil-enacts-sweeping-children-data-law

Time-of-Check Time-of-Use Attacks Against LLMs
https://www.schneier.com/blog/archives/2025/09/time-of-check-time-of-use-attacks-against-llms.html

How to join the desync endgame: Practical tips from pentester Tom Stacey
https://portswigger.net/blog/how-to-join-the-desync-endgame-practical-tips-from-pentester-tom-stacey

Microsoft Defender delivered 242% return on investment over three years
https://www.microsoft.com/en-us/security/blog/2025/09/18/microsoft-defender-delivered-242-return-on-investment-over-three-years/

SLasH-DSA: Breaking SLH-DSA Using an Extensible End-To-End Rowhammer Framework
https://arxiv.org/abs/2509.13048

AQUA-LLM: Evaluating Accuracy, Quantization, and Adversarial Robustness Trade-offs in LLMs for Cybersecurity Question Answering
https://arxiv.org/abs/2509.13514

LIGHT-HIDS: A Lightweight and Effective Machine Learning-Based Framework for Robust Host Intrusion Detection
https://arxiv.org/abs/2509.13561

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Industrial Threat Report Q2 2025
https://securelist.com/industrial-threat-report-q2-2025/117532/

CISOs Concerned of AI Adoption in Business Environments
https://www.tripwire.com/state-of-security/cisos-concerned-ai-adoption-business-environments

Surveying the Global Spyware Market
https://www.schneier.com/blog/archives/2025/09/surveying-the-global-spyware-market.html

MI6 launches darkweb portal to recruit foreign spies
https://therecord.media/mi6-darkweb-portal-recruit-foreign-spies

The GoLaxy papers: Inside China’s AI persona army
https://therecord.media/golaxy-china-artificial-intelligence-papers

Russia's main airport in St. Petersburg says its website was hacked
https://therecord.media/russia-pulkovo-airport-st-petersburg-website-hacked

How AI-Native Development Platforms Enable Fake Captcha Pages
https://www.trendmicro.com/en_us/research/25/i/ai-development-platforms-enable-fake-captcha-pages.html

Russian spy groups Turla, Gamaredon join forces to hack Ukraine, researchers say
https://therecord.media/russian-spy-groups-turla-gamaredon-target-ukraine

Watchdog finds MrBeast improperly collected children’s data
https://therecord.media/watchdog-mrbeast-youtube-privacy-colection

DOJ: Scattered Spider took $115 million in ransoms, breached a US court system
https://therecord.media/scattered-spider-unsealed-charges-115million-extortion-breached-courts-system

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State
https://research.checkpoint.com/2025/22nd-september-threat-intelligence-report/

New Infostealer Campaign Targeting Mac Users via GitHub Pages Claiming to Offer LastPass Premium
https://www.reddit.com/r/netsec/comments/1nnb1tw/new_infostealer_campaign_targeting_mac_users_via/

The God Mode Vulnerability That Should Kill “Trust Microsoft” Forever
https://www.reddit.com/r/netsec/comments/1nndpz7/the_god_mode_vulnerability_that_should_kill_trust/

Electron App Vulnerabilities testcases
https://www.reddit.com/r/netsec/comments/1nne01o/electron_app_vulnerabilities_testcases/

Video2Roleplay: A Multimodal Dataset and Framework for Video-Guided Role-playing Agents
https://arxiv.org/abs/2509.15233

Pre-Forgettable Models: Prompt Learning as a Native Mechanism for Unlearning
https://arxiv.org/abs/2509.15230

Exploring the Capabilities of LLM Encoders for Image-Text Retrieval in Chest X-rays
https://arxiv.org/abs/2509.15234

ViSpec: Accelerating Vision-Language Models with Vision-Aware Speculative Decoding
https://arxiv.org/abs/2509.15235

ChannelFlow-Tools: A Standardized Dataset Creation Pipeline for 3D Obstructed Channel Flows
https://arxiv.org/abs/2509.15236

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Neural Data Privacy: Brain Implants
https://therecord.media/neural-data-privacy-brain-implants

Details About Chinese Surveillance and Propaganda Companies
https://www.schneier.com/blog/archives/2025/09/details-about-chinese-surveillance-and-propaganda-companies.html

Major European Airports Work to Restore Services After Cyberattack on Check-in Systems
https://therecord.media/europe-airports-delays-ransomware-attack-checkin-systems

Nimbus Manticore Deploys New Malware Targeting Europe
https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/

HexStrike AI – Multi-Agent LLM Orchestration for Automated Offensive Security
https://www.darknet.org.uk/2025/09/hexstrike-ai-multi-agent-llm-orchestration-for-automated-offensive-security/

BlackLock Ransomware: From Meteoric Rise to Sudden Disruption
https://www.reddit.com/r/netsec/comments/1nob3s7/blacklock_ransomware_from_meteoric_rise_to_sudden/

What Does “Good” Look Like in Red Teaming
https://bishopfox.com/blog/what-does-good-look-like-in-red-teaming

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman