Top Daily Cyber Security News
731 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Law enforcement is using AI to synthesize evidence. Is the justice system ready for it?
https://therecord.media/law-enforcement-ai-platforms-synthesize-evidence-criminal-cases

Abusing Notion’s AI Agent for Data Theft
https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html

AIPentestKit – AI-Augmented Red Team Toolkit for Recon, Fuzzing and Payload Generation
https://www.darknet.org.uk/2025/09/aipentestkit-ai-augmented-red-team-toolkit-for-recon-fuzzing-and-payload-generation/

Moldova’s pro-EU party wins election amid cyberattacks, Kremlin interference
https://therecord.media/moldova-election-pro-eu-party-wins-ddos-incidents-influence-ops

29th September – Threat Intelligence Report
https://research.checkpoint.com/2025/29th-september-threat-intelligence-report/

Ukraine’s digital chief pushes for AI-first state amid war and cyber threats
https://therecord.media/ukraine-ai-state-digital

Chinese scammer pleads guilty after UK seizes nearly $7 billion in bitcoin
https://therecord.media/chinese-scammer-guilty-seizure-uk

Understanding the OWASP AI Maturity Assessment
https://www.tripwire.com/state-of-security/understanding-owasp-ai-maturity-assessment

Cloud Security in the CNAPP Era: Eight Important Takeaways
https://www.trendmicro.com/en_us/research/25/i/cloud-security-cnapp.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Klopatra: exposing a new Android banking trojan operation with roots in Turkey | Cleafy LABS
https://arxiv.org/abs/2509.22662

An In-depth research-based walk-through of an Uninitialized Local Variable Static Analyzer
https://www.reddit.com/r/netsec/comments/1nu7f3y/an_indepth_researchbased_walkthrough_of_an/

You name it, VMware elevates it (CVE-2025-41244)
https://www.reddit.com/r/netsec/comments/1nu9q24/you_name_it_vmware_elevates_it_cve202541244/

Details of a Scam
https://www.schneier.com/blog/archives/2025/09/details-of-a-scam.html

Empowering defenders in the era of agentic AI with Microsoft Sentinel
https://www.microsoft.com/en-us/security/blog/2025/09/30/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel/

Cyberattack on Japanese beer giant Asahi limits shipping, call center operations
https://therecord.media/asahi-japan-cyberattack-limits-shipping-call-centers

Afghanistan plunged into nationwide internet blackout, disrupting air travel, medical care
https://therecord.media/afghanistan-plunged-into-nationwide-internet-blackout

FTC alleges messaging app violated child privacy law, duped users into subscriptions
https://therecord.media/ftc-alleges-sendit-app-violated-children-privacy-rule

CISA orders federal gov to patch critical Fortra file transfer bug
https://therecord.media/cisa-orders-federal-gov-patch-fortra-bug

CPPA fines Tractor Supply Company $1.4 million for privacy violations
https://therecord.media/ccpa-tractor-supply-privacy-fine

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

DEEP SPECTER RESEARCH Alerted Jaguar 2.5 months prior to the cyber incident.

https://www.bloomberg.com/news/newsletters/2025-10-01/researchers-flagged-hacks-at-jaguar-land-rover-ahead-of-crippling-breach

Forensic journey: hunting evil within AmCache
https://securelist.com/amcache-forensic-artifact/117622/

Use of Generative AI in Scams
https://www.schneier.com/blog/archives/2025/10/use-of-generative-ai-in-scams.html

Seniors targeted in global Facebook scam spreading new Android malware
https://therecord.media/seniors-targeted-facebook-android-malware-scam

Hacking smarter with Burp AI: NahamSec puts Burp AI to the test
https://portswigger.net/blog/hacking-smarter-with-burp-ai-nahamsec-puts-burp-ai-to-the-test

China-linked hacking group Phantom Taurus targeting embassies, foreign ministries
https://therecord.media/china-linked-phantom-taurus-hacking

1.2 million people had information stolen during cyberattack on WestJet
https://therecord.media/westjet-data-breach-disclosures

Millions impacted by data breaches at insurance giant, auto dealership software firm
https://therecord.media/millions-impacted-by-data-breaches-insurance-car-dealership-software

Nuclei Templates for Detecting AMI MegaRAC BMC Vulnerabilities
https://www.reddit.com/r/netsec/comments/1nvllz0/nuclei_templates_for_detecting_ami_megarac_bmc/

Fingerprinting LLMs via Prompt Injection
https://arxiv.org/abs/2509.25410

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Georgia Tech settles with DOJ over allegations of lax cybersecurity on federal projects
https://therecord.media/georgia-tech-gtrc-cybersecurity-false-claims-act-settlement

Japanese brewer Asahi delays product launches, halts deliveries after cyberattack
https://therecord.media/japan-asahi-delay-cyberattack

Daniel Miessler on the AI Attack/Defense Balance
https://www.schneier.com/blog/archives/2025/10/daniel-miessler-on-the-ai-attack-defense-balance.html

European parliamentarians implore EU leadership to stop funding spyware
https://therecord.media/european-parliament-stop-funding-spyware

Dutch court rules Meta violated European law by pushing users to profiled feeds
https://therecord.media/dutch-court-meta-violated-european-law-social-feeds

Microsoft named a Leader in the IDC MarketScape for XDR
https://www.microsoft.com/en-us/security/blog/2025/10/02/microsoft-named-a-leader-in-the-idc-marketscape-for-xdr/

Cybercriminals are trying to extort executives with data allegedly stolen through Oracle tool
https://therecord.media/possible-clop-campaign-extortion-executives-stolen-data

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ghost in the Cloud: Weaponizing AWS X-Ray for Command & Control
https://www.reddit.com/r/netsec/comments/1nx6jtq/ghost_in_the_cloud_weaponizing_aws_xray_for/

Analyzing The Salesloft-Drift Breach
https://www.reddit.com/r/netsec/comments/1nzcsly/analyzing_the_salesloftdrift_breach/

Detecting DLL hijacking with machine learning: real-world cases
https://securelist.com/detecting-dll-hijacking-with-machine-learning-in-kaspersky-siem/117567/

How we trained an ML model to detect DLL hijacking
https://securelist.com/building-ml-model-to-detect-dll-hijacking/117565/

Modeling the Attack: Detecting AI-Generated Text by Quantifying Adversarial Perturbations
https://arxiv.org/abs/2510.02319

Hybrid Horizons: Policy for Post-Quantum Security
https://arxiv.org/abs/2510.02317

NetCAS: Dynamic Cache and Backend Device Management in Networked Environments
https://arxiv.org/abs/2510.02323

Hallucination reduction with CASAL: Contrastive Activation Steering For Amortized Learning
https://arxiv.org/abs/2510.02324

Agentic-AI Healthcare: Multilingual, Privacy-First Framework with MCP Agents
https://arxiv.org/abs/2510.02325

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability
https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/

AI in the 2026 Midterm Elections
https://www.schneier.com/blog/archives/2025/10/ai-in-the-2026-midterm-elections.html

Taking remote control over industrial generators
https://www.reddit.com/r/netsec/comments/1nzm5tf/taking_remote_control_over_industrial_generators/

Brazil malware uses WhatsApp to target government
https://therecord.media/brazil-malware-whatsapp-sorvepotel

Signal calls on Germany to vote no to 'Chat Control'
https://therecord.media/signal-calls-on-germany-to-vote-no-chat-control

Suspected Chinese spies target Serbia
https://therecord.media/suspected-chinese-spies-serbia

FBI, UK urge orgs to patch after Clop campaign
https://therecord.media/fbi-uk-urge-orgs-to-patch-after-clop-campaign

Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1nzpx3b/well_well_well_its_another_day_oracle_ebusiness/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AI-Enabled Influence Operation Against Iran
https://www.schneier.com/blog/archives/2025/10/ai-enabled-influence-operation-against-iran.html

Jaguar Land Rover to restart production following cyberattack
https://therecord.media/jaguar-land-rover-restarting-production-after-cyberattack

Discord says sensitive info stolen during cyberattack on customer service provider
https://therecord.media/discord-data-breach-third-party

The future of pentesting is Human x AI, and it's already in Burp Suite Professional
https://portswigger.net/blog/the-future-of-pentesting-is-human-x-ai-and-its-already-in-burp-suite-professional

Russia blocks mobile internet for foreign SIM cards, citing drone threats
https://therecord.media/russia-blocks-mobile-internet-foreign-sim-cards

New Microsoft Secure Future Initiative (SFI) patterns and practices: Practical guides to strengthen security
https://www.microsoft.com/en-us/security/blog/2025/10/07/new-microsoft-secure-future-initiative-sfi-patterns-and-practices-practical-guides-to-strengthen-security/

Police searched national network of automatic license plate reading cameras in abortion investigation
https://therecord.media/police-searched-license-reading-cameras-abortion-investigation

Disrupting threats targeting Microsoft Teams
https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/

How Your AI Chatbot Can Become a Backdoor
https://www.trendmicro.com/en_us/research/25/j/ai-chatbot-backdoor.html

ShinyHunters Wage Broad Corporate Extortion Spree
https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Tiny but Mighty: A Software-Hardware Co-Design Approach for Efficient Multimodal Inference on Battery-Powered Small Devices
https://arxiv.org/abs/2510.05109

System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
https://arxiv.org/abs/2505.06493

Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
https://www.reddit.com/r/netsec/comments/1o170wz/bash_a_newline_exploiting_ssh_via_proxycommand/

Teenagers arrested in England over cyberattack on nursery chain Kido
https://therecord.media/kido-nursery-school-chain-hack-arrests-britain

Cybercrime crew claims attack on Japanese brewer as it restarts operations
https://therecord.media/qilin-ransomware-gang-alleged-asahi-hackers

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Discord says 70,000 users had government IDs exposed in third-party breach
https://therecord.media/discord-government-docs-exposed-breach

Investing targeted “payroll pirate” attacks affecting US universities
https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/

LLM Black Markets in 2025 – Prompt Injection, Jailbreak Sales & Model Leaks
https://www.darknet.org.uk/2025/10/llm-black-markets-in-2025-prompt-injection-jailbreak-sales-model-leaks/

HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security
https://portswigger.net/blog/http-1-1-must-die-dafydd-stuttard-on-what-this-means-for-enterprise-security

Security Analysis of a medical device: Methods and Findings
https://www.reddit.com/r/netsec/comments/1o29iec/security_analysis_of_a_medical_device_methods_and/

A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
https://www.reddit.com/r/netsec/comments/1o0pfnr/a_handson_edition_will_supabase_be_the_next/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AI and the Future of American Politics
https://www.schneier.com/blog/archives/2025/10/ai-and-the-future-of-american-politics.html

UK fines 4chan over noncompliance with Online Safety Act
https://therecord.media/4chan-fined-ofcom-uk-online-safety-act

LLM Honeypot vs. Cryptojacking: Understanding the Enemy
https://www.reddit.com/r/netsec/comments/1o5m7cg/llm_honeypot_vs_cryptojacking_understanding_the/

Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia
https://therecord.media/netherlands-special-powers-chinese-owned-semiconductor

(DEF CON 33) How I hacked over 1,000 car dealerships across the US
https://www.reddit.com/r/netsec/comments/1o5na8l/def_con_33_how_i_hacked_over_1000_car_dealerships/

Building a lasting security culture at Microsoft
https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-microsoft/

Ukraine takes steps to launch dedicated cyber force for offensive strikes
https://therecord.media/ukraine-takes-steps-dedicated-cyber-force

Harvard says ‘limited number of parties’ impacted by breach linked to Oracle zero-day
https://therecord.media/harvard-says-limited-number-linked-to-data-theft

UK hit by record number of ‘nationally significant’ cyberattacks
https://therecord.media/uk-hit-by-record-number-significant-cyberattacks

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Signal in the noise: what hashtags reveal about hacktivism in 2025
https://securelist.com/dfi-meta-hacktivist-report/117708/

Automating the RMF: Lessons from the FedRAMP 20x Pilot
https://arxiv.org/abs/2510.09610

A Biosecurity Agent for Lifecycle LLM Biosecurity Alignment
https://arxiv.org/abs/2510.09613

Causal Digital Twins for Cyber-Physical Security: A Framework for Robust Anomaly Detection in Industrial Control Systems
https://arxiv.org/abs/2510.09615

Microsoft raises the bar: A smarter way to measure AI for cybersecurity
https://www.microsoft.com/en-us/security/blog/2025/10/14/microsoft-raises-the-bar-a-smarter-way-to-measure-ai-for-cybersecurity/

Qantas confirms cybercriminals released stolen customer data
https://therecord.media/qantas-cybercriminals-stolen-data

Taiwan reports surge in Chinese cyber activity and disinformation efforts
https://therecord.media/taiwan-nsb-report-china-surge-cyberattacks-influence-operations

Florida sues Roku for illegally selling children’s data, including precise geolocation
https://therecord.media/florida-roku-children-data

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Researchers report rare intrusion by suspected Chinese hackers into Russian tech firm
https://therecord.media/rare-china-linked-intrusion-russian-tech-firms

Mysterious Elephant: a growing threat
https://securelist.com/mysterious-elephant-apt-ttps-and-tools/117596/

Apple’s Bug Bounty Program
https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html

Capita given record £14 million fine over ransomware attack security failings
https://therecord.media/capita-record-fine-uk-ico-ransomware-attack

New York secures $14 million in fines from 8 car insurance companies after data breaches
https://therecord.media/auto-insurance-companies-fined-ny-state-pre-fill-data-breaches

Maverick: a new banking Trojan abusing WhatsApp in a mass-scale distribution
https://securelist.com/maverick-banker-distributing-via-whatsapp/117715/

Exploit-as-a-Service Resurgence in 2025 – Broker Models, Bundles & Subscription Access
https://www.darknet.org.uk/2025/10/exploit-as-a-service-resurgence-in-2025-broker-models-bundles-subscription-access/

Mango says some customer information exposed in cyber incident
https://therecord.media/mango-fashion-retaier-data-breach

PowerSchool hacker sentenced to 4 years in prison
https://therecord.media/powerschool-hacker-sentenced-4-years

CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug info
https://therecord.media/cisa-directive-f5-nation-state-incident

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/

Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903

Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman