Top Daily Cyber Security News
731 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Composition Theorems for f-Differential Privacy
https://arxiv.org/abs/2512.21358

Reflection-Driven Control for Trustworthy Code Agents
https://arxiv.org/abs/2512.21354

Power Side-Channel Analysis of the CVA6 RISC-V Core at the RTL Level Using VeriSide
https://arxiv.org/abs/2512.21362

Satellite Cybersecurity Across Orbital Altitudes: Analyzing Ground-Based Threats to LEO, MEO, and GEO
https://arxiv.org/abs/2512.21367

Key Length-Oriented Classification of Lightweight Cryptographic Algorithms for IoT Security
https://arxiv.org/abs/2512.21368

Static scans vs runtime reality
https://www.reddit.com/r/netsec/comments/1pyfwn6/static_scans_vs_runtime_reality/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor
https://securelist.com/honeymyte-kernel-mode-rootkit/118590/

29th December – Threat Intelligence Report
https://research.checkpoint.com/2025/29th-december-threat-intelligence-report/

Are We Ready to Be Governed by Artificial Intelligence?
https://www.schneier.com/blog/archives/2025/12/are-we-ready-to-be-governed-by-artificial-intelligence.html

Coupang recovers smashed laptop that alleged data leaker threw into river
https://therecord.media/coupang-recovers-smashed-laptop-data-breach

French software company fined $2 million for cyber failings leading to data breach
https://therecord.media/french-software-fined-cnil

Happy 16th Birthday, KrebsOnSecurity.com!
https://krebsonsecurity.com/2025/12/happy-16th-birthday-krebsonsecurity-com/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

RMM Abuse in a Crypto Wallet Distribution Campaign
https://www.reddit.com/r/netsec/comments/1pztpnf/rmm_abuse_in_a_crypto_wallet_distribution_campaign/

Using AI-Generated Images to Get Refunds
https://www.schneier.com/blog/archives/2025/12/using-ai-generated-images-to-get-refunds.html

MonoM: Enhancing Monotonicity in Learned Cardinality Estimators
https://arxiv.org/abs/2512.22122

A Study of NP-Completeness and Undecidable Word Problems in Semigroups
https://arxiv.org/abs/2512.22123

GPU-Virt-Bench: A Comprehensive Benchmarking Framework for Software-Based GPU Virtualization Systems
https://arxiv.org/abs/2512.22125

Validation methodology on real data of reversible Kalman Filter for state estimation with Manifold
https://arxiv.org/abs/2512.22126

Impact of Sociality Regimes on Quality of Service and Energy Efficiency in Cell-Free MIMO Networks
https://arxiv.org/abs/2512.22127

Ransomware responders plead guilty to using ALPHV in attacks on US organizations
https://therecord.media/ransomware-responders-guilty-plea-using-alphv-blackcat-us-attacks

Treasury removes sanctions for three executives tied to spyware maker Intellexa
https://therecord.media/treasury-sanctions-intellexa-removed

GenAI DevOps: More Code, More Problems
https://bishopfox.com/blog/genai-devops-more-code-more-problems

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Finland seizes ship suspected of damaging subsea cable in Baltic Sea
https://therecord.media/finland-seizes-ship-suspected-damaging-undersea-cable

RMM Abuse in a Crypto Wallet Distribution Campaign
https://www.reddit.com/r/netsec/comments/1pztpnf/rmm_abuse_in_a_crypto_wallet_distribution_campaign/

LinkedIn Job Scams
https://www.schneier.com/blog/archives/2025/12/linkedin-job-scams.html

Undefined reference linker error
https://www.reddit.com/r/lowlevel/comments/1q0m2hq/undefined_reference_linker_error/

Hello, This question popped into my mind a few days ago, and this is one of the only communities that allows this kind of question.
https://www.reddit.com/r/lowlevel/comments/1q0fq6n/hello_this_question_popped_into_my_mind_a_few/

NEW 'Off The Hook' ONLINE
https://www.2600.com/hook/31-12-2025

When Intelligence Fails: An Empirical Study on Why LLMs Struggle with Password Cracking
https://arxiv.org/abs/2512.23785

Application-Specific Power Side-Channel Attacks and Countermeasures: A Survey
https://arxiv.org/abs/2512.23778

SyncGait: Robust Long-Distance Authentication for Drone Delivery via Implicit Gait Behaviors
https://arxiv.org/abs/2512.23779

Prompt-Induced Over-Generation as Denial-of-Service: A Black-Box Attack-Side Benchmark
https://arxiv.org/abs/2512.23760

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Built an SSRF Prevention Library
https://www.reddit.com/r/netsec/comments/1q13m87/built_an_ssrf_prevention_library/

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance
https://www.reddit.com/r/netsec/comments/1q15r3i/the_story_of_a_perfect_exploit_chain_six_bugs/

Built an Automated Red-Team Tool to Find LLM Vulnerabilities. Most AI Apps Are Frighteningly Easy to Break.
https://www.reddit.com/r/netsec/comments/1q1l1aj/built_an_automated_redteam_tool_to_find_llm/

CAT: A Metric-Driven Framework for Analyzing the Consistency-Accuracy Relation of LLMs under Controlled Input Variations
https://arxiv.org/abs/2512.23711

Enriching Historical Records: An OCR and AI-Driven Approach for Database Integration
https://arxiv.org/abs/2512.24863

STED and Consistency Scoring: A Framework for Evaluating LLM Structured Output Reliability
https://arxiv.org/abs/2512.23872

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Flock Exposes Its AI-Enabled Surveillance Cameras
https://www.schneier.com/blog/archives/2026/01/flock-exposes-its-ai-enabled-surveillance-cameras.html

The Kimwolf Botnet is Stalking Your Local Network
https://krebsonsecurity.com/2026/01/the-kimwolf-botnet-is-stalking-your-local-network/

Finland arrests two crew members of ship suspected of cable break
https://therecord.media/finland-arrests-crew-ship-suspected-cable-break

Exposed: Shedding Blacklight on Online Privacy
https://arxiv.org/abs/2512.24041

Technical Analysis - MongoBleed (CVE-2025-14847): Memory Corruption in MongoDB
https://www.reddit.com/r/netsec/comments/1q23y3l/technical_analysis_mongobleed_cve202514847_memory/

Sedgwick confirms cyber incident affecting its major federal contractor subsidiary
https://therecord.media/sedgwick-cyber-incident-ransomware

European regulators take aim at X after Grok creates deepfake of minor
https://therecord.media/europe-regulators-grok-france

Pakistan-linked hackers target Indian government, universities in new spying campaign
https://therecord.media/pakistan-linked-hacking-group-targets-indian-orgs

Nearly 480,000 impacted by Covenant Health data breach
https://therecord.media/covenant-health-breach-qilin

Friday Squid Blogging: Squid Found in Light Fixture
https://www.schneier.com/blog/archives/2026/01/friday-squid-blogging-squid-found-in-light-fixture.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Improving Multi-step RAG with Hypergraph-based Memory for Long-Context Complex Relational Modeling
https://arxiv.org/abs/2512.23959

Evaluating interface-based concealment in local data protection: threat model considerations
https://www.reddit.com/r/netsec/comments/1q4afh7/evaluating_interfacebased_concealment_in_local/

Overlooked Safety Vulnerability in LLMs: Malicious Intelligent Optimization Algorithm Request and its Jailbreak
https://arxiv.org/abs/2601.00213

Large Empirical Case Study: Go-Explore adapted for AI Red Team Testing
https://arxiv.org/abs/2601.00042

Evolution of Android's Permission-based Security Model and Challenges
https://arxiv.org/abs/2601.00252

Rectifying Adversarial Examples Using Their Vulnerabilities
https://arxiv.org/abs/2601.00270

From Consensus to Chaos: A Vulnerability Assessment of the RAFT Algorithm
https://arxiv.org/abs/2601.00273

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

UK government admits years of cyber policy have failed, announces reset
https://therecord.media/uk-government-cyber-action-plan

A Cyberattack Was Part of the US Assault on Venezuela
https://www.schneier.com/blog/archives/2026/01/a-cyberattack-was-part-of-the-us-assault-on-venezuela.html

Phishing actors exploit complex routing and misconfigurations to spoof domains
https://www.microsoft.com/en-us/security/blog/2026/01/06/phishing-actors-exploit-complex-routing-and-misconfigurations-to-spoof-domains/

Introducing the Microsoft Defender Experts Suite: Elevate your security with expert-led services
https://www.microsoft.com/en-us/security/blog/2026/01/06/introducing-the-microsoft-defender-experts-suite-elevate-your-security-with-expert-led-services/

A practical guide to finding soundness bugs in ZK circuits
https://www.reddit.com/r/netsec/comments/1q5b20w/a_practical_guide_to_finding_soundness_bugs_in_zk/

Reverse engineering my cloud-connected e-scooter and finding the master key to unlock all scooters
https://www.reddit.com/r/netsec/comments/1q5k295/reverse_engineering_my_cloudconnected_escooter/

Proxying Flutter Traffic on Android with Claude
https://www.reddit.com/r/netsec/comments/1q5pocf/proxying_flutter_traffic_on_android_with_claude/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alleged cyber scam kingpin arrested, extradited to China
https://therecord.media/alleged-cyber-scam-kingpin-cambodia-arrested-extradited

Cyberattack forces British high school to cancel classes and delay reopening
https://therecord.media/cyberattack-forces-british-high-school-to-delay-opening

Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns
https://research.checkpoint.com/2026/01/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/

Explore the latest Microsoft Incident Response proactive services for enhanced resilience
https://www.microsoft.com/en-us/security/blog/2026/01/07/explore-the-latest-microsoft-incident-response-proactive-services-for-enhanced-resilience/

Illinois state agency exposed personal data of 700,000 people
https://therecord.media/illinois-agency-exposed-data

Spanish airline Iberia attributes recent data breach claims to November incident
https://therecord.media/spanish-airline-attributes-recent-breach-allegation-to-nov-incident

Ni8mare  - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858)
https://www.reddit.com/r/netsec/comments/1q6iw0y/ni8mare_unauthenticated_remote_code_execution_in/

Stalkerware operator pleads guilty in rare prosecution
https://therecord.media/stalkerware-guilty-plea-fleming

JA4 Fingerprinting Against AI Scrapers: A Practical Guide
https://www.reddit.com/r/netsec/comments/1q71l7v/ja4_fingerprinting_against_ai_scrapers_a/

How Real is Your Jailbreak? Fine-grained Jailbreak Evaluation with Anchored Reference
https://arxiv.org/abs/2601.03288

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

ChatGPT Health feature draws concern from privacy critics over sensitive medical data
https://therecord.media/chatgpt-health-draws-concern-privacy-critics

Enhancing Retrieval-Augmented Generation with Two-Stage Retrieval: FlashRank Reranking and Query Expansion
https://arxiv.org/abs/2601.03258

Mastering the Game of Go with Self-play Experience Replay
https://arxiv.org/abs/2601.03259

CVE-2026-21876: OWASP Modsecurity CRS WAF bypass blogpost is out!
https://www.reddit.com/r/netsec/comments/1q7myyq/cve202621876_owasp_modsecurity_crs_waf_bypass/

US announces withdrawal from dozens of international treaties
https://therecord.media/us-announces-withdrawal-from-dozens-international-orgs

CISA sunsets 10 emergency directives thanks to evolution of exploited vulnerabilities catalog
https://therecord.media/cisa-sunsets-10-emergency-directives

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

N/A
N/A

Palo Alto Crosswalk Signals Had Default Passwords
https://www.schneier.com/blog/archives/2026/01/palo-alto-crosswalk-signals-had-default-passwords.html

Former NSA insider Kosiba brought back as spy agency’s No. 2
https://therecord.media/timothy-kosiba-nsa-new-deputy-chief

MedPI: Evaluating AI Systems in Medical Patient-facing Interactions
https://arxiv.org/abs/2601.04195

RAGVUE: A Diagnostic View for Explainable and Automated Evaluation of Retrieval-Augmented Generation
https://arxiv.org/abs/2601.04196

Automatic Construction of Chinese Verb Collostruction Database
https://arxiv.org/abs/2601.04197

Identification of a Kalman filter: consistency of local solutions
https://arxiv.org/abs/2601.04198

Using Grok to Avoid Personal Attacks While Correcting Misinformation on X
https://therecord.media/using-grok-to-avoid-personal-attacks-while-correcting-misinformation-on-x

At least $26 million in crypto stolen from Truebit platform as crypto crime landscape evolves
https://therecord.media/26-million-in-crypto-stolen-truebit

Lawmakers call on app stores to remove Grok, X over sexualized deepfakes
https://therecord.media/lawmakers-call-on-app-stores-to-remove-grok-x

Basketball player arrested for alleged ransomware ties freed in Russia-France prisoner swap
https://therecord.media/france-frees-russian-basketball-player-ransomware-swap

Friday Squid Blogging: The Chinese Squid-Fishing Fleet off the Argentine Coast
https://www.schneier.com/blog/archives/2026/01/friday-squid-blogging-the-chinese-squid-fishing-fleet-off-the-argentine-coast.html

DVAIB: A deliberately vulnerable AI bank for practicing prompt injection and AI security attacks
https://www.reddit.com/r/netsec/comments/1q87uqn/dvaib_a_deliberately_vulnerable_ai_bank_for/

“The Conscience of a Hacker” is 40 today
https://www.reddit.com/r/netsec/comments/1q7wjjo/the_conscience_of_a_hacker_is_40_today/

[Article] Intercept: How MITM attacks work in Ethernet, IPv4 & IPv6
https://www.reddit.com/r/netsec/comments/1q89qxk/article_intercept_how_mitm_attacks_work_in/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Kremlin-linked hackers pose as charities to spy on Ukraine’s military
https://therecord.media/kremlin-linked-hackers-pose-as-charities-spy-ukraine

Suspected ransomware attack threatens one of South Korea’s largest companies
https://therecord.media/kyowon-group-south-korea-suspected-ransomware-attack

Senior military cyber operator removed from Russia task force
https://therecord.media/senior-military-cyber-op-removed-russia-task-force

Ukraine parliament approves resignation of security service chief in major reshuffle
https://therecord.media/ukraine-parliament-approves-resignation-sbu-chief

Tennessee man to plead guilty to hacking Supreme Court’s electronic case filing system
https://therecord.media/guilty-plea-hacking-supreme-court-case-filing-system

More than 40 countries impacted by North Korea IT worker scams, crypto thefts
https://therecord.media/40-countries-impacted-nk-it-thefts-united-nations

How Microsoft builds privacy and security to work hand-in-hand
https://www.microsoft.com/en-us/security/blog/2026/01/13/how-microsoft-builds-privacy-and-security-to-work-hand-in-hand/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Fortinet Forticlient EMS RCE CVE-2025-59922 and one IMG tag to rule them all
https://www.reddit.com/r/netsec/comments/1qciz0v/fortinet_forticlient_ems_rce_cve202559922_and_one/

Patch Tuesday, January 2026 Edition
https://krebsonsecurity.com/2026/01/patch-tuesday-january-2026-edition/

Cyberattack forces Belgian hospital to transfer critical care patients
https://therecord.media/belgium-hospital-cyberattack-antwerp-az-monica

Federal agencies ordered to patch Microsoft Desktop Windows Manager bug
https://therecord.media/desktop-windows-manager-vulnerability-added-to-cisa-list

Sicarii Ransomware: Truth vs Myth
https://research.checkpoint.com/2026/sicarii-ransomware-truth-vs-myth/

Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover
https://www.reddit.com/r/netsec/comments/1qcpsp9/multiple_xss_in_meta_conversion_api_gateway/

Inside RedVDS: How a single virtual desktop provider fueled worldwide cybercriminal operations
https://www.microsoft.com/en-us/security/blog/2026/01/14/inside-redvds-how-a-single-virtual-desktop-provider-fueled-worldwide-cybercriminal-operations/

Microsoft named a Leader in IDC MarketScape for Unified AI Governance Platforms
https://www.microsoft.com/en-us/security/blog/2026/01/14/microsoft-named-a-leader-in-idc-marketscape-for-unified-ai-governance-platforms/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multi-Step Malware
https://therecord.media/germany-cyber-dome-israel

New Vulnerability in n8n
https://www.schneier.com/blog/archives/2026/01/new-vulnerability-in-n8n.html

Introducing ÆSIR: Finding Zero-Day Vulnerabilities at the Speed of AI
https://www.trendmicro.com/en_us/research/26/a/aesir.html

Elon Musk’s X says it will block Grok from making sexual images
https://therecord.media/musk-x-grok-block-sexual

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
https://projectzero.google/2026/01/pixel-0-click-part-1.html

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
https://projectzero.google/2026/01/pixel-0-click-part-2.html

A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
https://projectzero.google/2026/01/pixel-0-click-part-3.html

Google to pay $8.25 million to settle lawsuit alleging children’s privacy violations
https://therecord.media/google-youtube-lawsuit-settle

CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
https://www.reddit.com/r/netsec/comments/1qdmwad/cve202620965_cymulate_research_labs_discovers/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman