Top Daily Cyber Security News
731 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Georgia Tech settles with DOJ over allegations of lax cybersecurity on federal projects
https://therecord.media/georgia-tech-gtrc-cybersecurity-false-claims-act-settlement

Japanese brewer Asahi delays product launches, halts deliveries after cyberattack
https://therecord.media/japan-asahi-delay-cyberattack

Daniel Miessler on the AI Attack/Defense Balance
https://www.schneier.com/blog/archives/2025/10/daniel-miessler-on-the-ai-attack-defense-balance.html

European parliamentarians implore EU leadership to stop funding spyware
https://therecord.media/european-parliament-stop-funding-spyware

Dutch court rules Meta violated European law by pushing users to profiled feeds
https://therecord.media/dutch-court-meta-violated-european-law-social-feeds

Microsoft named a Leader in the IDC MarketScape for XDR
https://www.microsoft.com/en-us/security/blog/2025/10/02/microsoft-named-a-leader-in-the-idc-marketscape-for-xdr/

Cybercriminals are trying to extort executives with data allegedly stolen through Oracle tool
https://therecord.media/possible-clop-campaign-extortion-executives-stolen-data

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ghost in the Cloud: Weaponizing AWS X-Ray for Command & Control
https://www.reddit.com/r/netsec/comments/1nx6jtq/ghost_in_the_cloud_weaponizing_aws_xray_for/

Analyzing The Salesloft-Drift Breach
https://www.reddit.com/r/netsec/comments/1nzcsly/analyzing_the_salesloftdrift_breach/

Detecting DLL hijacking with machine learning: real-world cases
https://securelist.com/detecting-dll-hijacking-with-machine-learning-in-kaspersky-siem/117567/

How we trained an ML model to detect DLL hijacking
https://securelist.com/building-ml-model-to-detect-dll-hijacking/117565/

Modeling the Attack: Detecting AI-Generated Text by Quantifying Adversarial Perturbations
https://arxiv.org/abs/2510.02319

Hybrid Horizons: Policy for Post-Quantum Security
https://arxiv.org/abs/2510.02317

NetCAS: Dynamic Cache and Backend Device Management in Networked Environments
https://arxiv.org/abs/2510.02323

Hallucination reduction with CASAL: Contrastive Activation Steering For Amortized Learning
https://arxiv.org/abs/2510.02324

Agentic-AI Healthcare: Multilingual, Privacy-First Framework with MCP Agents
https://arxiv.org/abs/2510.02325

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability
https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/

AI in the 2026 Midterm Elections
https://www.schneier.com/blog/archives/2025/10/ai-in-the-2026-midterm-elections.html

Taking remote control over industrial generators
https://www.reddit.com/r/netsec/comments/1nzm5tf/taking_remote_control_over_industrial_generators/

Brazil malware uses WhatsApp to target government
https://therecord.media/brazil-malware-whatsapp-sorvepotel

Signal calls on Germany to vote no to 'Chat Control'
https://therecord.media/signal-calls-on-germany-to-vote-no-chat-control

Suspected Chinese spies target Serbia
https://therecord.media/suspected-chinese-spies-serbia

FBI, UK urge orgs to patch after Clop campaign
https://therecord.media/fbi-uk-urge-orgs-to-patch-after-clop-campaign

Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1nzpx3b/well_well_well_its_another_day_oracle_ebusiness/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AI-Enabled Influence Operation Against Iran
https://www.schneier.com/blog/archives/2025/10/ai-enabled-influence-operation-against-iran.html

Jaguar Land Rover to restart production following cyberattack
https://therecord.media/jaguar-land-rover-restarting-production-after-cyberattack

Discord says sensitive info stolen during cyberattack on customer service provider
https://therecord.media/discord-data-breach-third-party

The future of pentesting is Human x AI, and it's already in Burp Suite Professional
https://portswigger.net/blog/the-future-of-pentesting-is-human-x-ai-and-its-already-in-burp-suite-professional

Russia blocks mobile internet for foreign SIM cards, citing drone threats
https://therecord.media/russia-blocks-mobile-internet-foreign-sim-cards

New Microsoft Secure Future Initiative (SFI) patterns and practices: Practical guides to strengthen security
https://www.microsoft.com/en-us/security/blog/2025/10/07/new-microsoft-secure-future-initiative-sfi-patterns-and-practices-practical-guides-to-strengthen-security/

Police searched national network of automatic license plate reading cameras in abortion investigation
https://therecord.media/police-searched-license-reading-cameras-abortion-investigation

Disrupting threats targeting Microsoft Teams
https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/

How Your AI Chatbot Can Become a Backdoor
https://www.trendmicro.com/en_us/research/25/j/ai-chatbot-backdoor.html

ShinyHunters Wage Broad Corporate Extortion Spree
https://krebsonsecurity.com/2025/10/shinyhunters-wage-broad-corporate-extortion-spree/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Tiny but Mighty: A Software-Hardware Co-Design Approach for Efficient Multimodal Inference on Battery-Powered Small Devices
https://arxiv.org/abs/2510.05109

System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
https://arxiv.org/abs/2505.06493

Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
https://www.reddit.com/r/netsec/comments/1o170wz/bash_a_newline_exploiting_ssh_via_proxycommand/

Teenagers arrested in England over cyberattack on nursery chain Kido
https://therecord.media/kido-nursery-school-chain-hack-arrests-britain

Cybercrime crew claims attack on Japanese brewer as it restarts operations
https://therecord.media/qilin-ransomware-gang-alleged-asahi-hackers

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Discord says 70,000 users had government IDs exposed in third-party breach
https://therecord.media/discord-government-docs-exposed-breach

Investing targeted “payroll pirate” attacks affecting US universities
https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/

LLM Black Markets in 2025 – Prompt Injection, Jailbreak Sales & Model Leaks
https://www.darknet.org.uk/2025/10/llm-black-markets-in-2025-prompt-injection-jailbreak-sales-model-leaks/

HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security
https://portswigger.net/blog/http-1-1-must-die-dafydd-stuttard-on-what-this-means-for-enterprise-security

Security Analysis of a medical device: Methods and Findings
https://www.reddit.com/r/netsec/comments/1o29iec/security_analysis_of_a_medical_device_methods_and/

A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
https://www.reddit.com/r/netsec/comments/1o0pfnr/a_handson_edition_will_supabase_be_the_next/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AI and the Future of American Politics
https://www.schneier.com/blog/archives/2025/10/ai-and-the-future-of-american-politics.html

UK fines 4chan over noncompliance with Online Safety Act
https://therecord.media/4chan-fined-ofcom-uk-online-safety-act

LLM Honeypot vs. Cryptojacking: Understanding the Enemy
https://www.reddit.com/r/netsec/comments/1o5m7cg/llm_honeypot_vs_cryptojacking_understanding_the/

Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia
https://therecord.media/netherlands-special-powers-chinese-owned-semiconductor

(DEF CON 33) How I hacked over 1,000 car dealerships across the US
https://www.reddit.com/r/netsec/comments/1o5na8l/def_con_33_how_i_hacked_over_1000_car_dealerships/

Building a lasting security culture at Microsoft
https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-microsoft/

Ukraine takes steps to launch dedicated cyber force for offensive strikes
https://therecord.media/ukraine-takes-steps-dedicated-cyber-force

Harvard says ‘limited number of parties’ impacted by breach linked to Oracle zero-day
https://therecord.media/harvard-says-limited-number-linked-to-data-theft

UK hit by record number of ‘nationally significant’ cyberattacks
https://therecord.media/uk-hit-by-record-number-significant-cyberattacks

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Signal in the noise: what hashtags reveal about hacktivism in 2025
https://securelist.com/dfi-meta-hacktivist-report/117708/

Automating the RMF: Lessons from the FedRAMP 20x Pilot
https://arxiv.org/abs/2510.09610

A Biosecurity Agent for Lifecycle LLM Biosecurity Alignment
https://arxiv.org/abs/2510.09613

Causal Digital Twins for Cyber-Physical Security: A Framework for Robust Anomaly Detection in Industrial Control Systems
https://arxiv.org/abs/2510.09615

Microsoft raises the bar: A smarter way to measure AI for cybersecurity
https://www.microsoft.com/en-us/security/blog/2025/10/14/microsoft-raises-the-bar-a-smarter-way-to-measure-ai-for-cybersecurity/

Qantas confirms cybercriminals released stolen customer data
https://therecord.media/qantas-cybercriminals-stolen-data

Taiwan reports surge in Chinese cyber activity and disinformation efforts
https://therecord.media/taiwan-nsb-report-china-surge-cyberattacks-influence-operations

Florida sues Roku for illegally selling children’s data, including precise geolocation
https://therecord.media/florida-roku-children-data

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Researchers report rare intrusion by suspected Chinese hackers into Russian tech firm
https://therecord.media/rare-china-linked-intrusion-russian-tech-firms

Mysterious Elephant: a growing threat
https://securelist.com/mysterious-elephant-apt-ttps-and-tools/117596/

Apple’s Bug Bounty Program
https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html

Capita given record £14 million fine over ransomware attack security failings
https://therecord.media/capita-record-fine-uk-ico-ransomware-attack

New York secures $14 million in fines from 8 car insurance companies after data breaches
https://therecord.media/auto-insurance-companies-fined-ny-state-pre-fill-data-breaches

Maverick: a new banking Trojan abusing WhatsApp in a mass-scale distribution
https://securelist.com/maverick-banker-distributing-via-whatsapp/117715/

Exploit-as-a-Service Resurgence in 2025 – Broker Models, Bundles & Subscription Access
https://www.darknet.org.uk/2025/10/exploit-as-a-service-resurgence-in-2025-broker-models-bundles-subscription-access/

Mango says some customer information exposed in cyber incident
https://therecord.media/mango-fashion-retaier-data-breach

PowerSchool hacker sentenced to 4 years in prison
https://therecord.media/powerschool-hacker-sentenced-4-years

CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug info
https://therecord.media/cisa-directive-f5-nation-state-incident

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/

Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903

Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How a fake AI recruiter delivers five staged malware disguised as a dream job
https://www.reddit.com/r/netsec/comments/1obgnxd/how_a_fake_ai_recruiter_delivers_five_staged/

XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)
https://www.darknet.org.uk/2025/10/xrayc2-weaponizing-aws-x-ray-for-covert-command-and-control-c2/

Agentic AI’s OODA Loop Problem
https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html

Evilginx’s creator reckons with the dark side of red-team tools
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast

20th October – Threat Intelligence Report
https://research.checkpoint.com/2025/20th-october-threat-intelligence-report/

Home security firm Verisure reports data breach at Swedish subsidiary
https://therecord.media/verisure-data-breach-sweden-alert-alarm-subsidiary

China claims it caught US attempting cyberattack on national time center
https://therecord.media/china-attack-national-time-center

Inside the attack chain: Threat activity targeting Azure Blob Storage
https://www.microsoft.com/en-us/security/blog/2025/10/20/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage/

Tunneling WireGuard over HTTPS using Wstunnel
https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The evolving landscape of email phishing attacks: how threat actors are reusing and refining established techniques
https://securelist.com/email-phishing-techniques-2025/117801/

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/

CVE-2025-9133: ZYXEL Configuration Exposure via Authorization Bypass
https://www.reddit.com/r/netsec/comments/1oc4qwa/cve20259133_zyxel_configuration_exposure_via/

A Cybersecurity Merit Badge
https://www.schneier.com/blog/archives/2025/10/a-cybersecurity-merit-badge.html

Fast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities
https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html

Microsoft 365 Copilot - Arbitrary Data Exfiltration Via Mermaid Diagrams
https://www.reddit.com/r/netsec/comments/1occb7r/microsoft_365_copilot_arbitrary_data_exfiltration/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

BetterBank DeFi Protocol: Esteem Token Bonus Minting
https://securelist.com/betterbank-defi-protocol-esteem-token-bonus-minting/117822/

Post-Quantum Cryptography in 2025 – Migration Paths, Early Movers and CISO/RedTeam Impact
https://www.darknet.org.uk/2025/10/post-quantum-cryptography-in-2025-migration-paths-early-movers-and-ciso-redteam-impact/

Failures in Face Recognition
https://www.schneier.com/blog/archives/2025/10/failures-in-face-recognition.html

PhantomCaptcha' hackers impersonate Ukrainian president’s office in attack on war relief workers
https://therecord.media/phantomcaptcha-spearphishing-campaign-ukraine-war-relief-groups

Jaguar Land Rover cyberattack cost $2.5 billion, says monitoring group
https://therecord.media/jaguar-land-rover-cyberattack-economic-impact

Ransomware gang steals meeting videos, financial secrets from fence wholesaler
https://therecord.media/ransomware-gang-steals-meeting-video-fence-manufacturer

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI
https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai

Canada Fines Cybercrime Friendly Cryptomus $176M
https://krebsonsecurity.com/2025/10/canada-fines-cybercrime-friendly-cryptomus-176m/

State attorneys general stepping up privacy enforcement, watchdog finds
https://therecord.media/state-ags-enforcement-privacy-law

The security paradox of local LLMs
https://www.reddit.com/r/netsec/comments/1od7azc/the_security_paradox_of_local_llms/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman