Top Daily Cyber Security News
731 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Germany warns of state-linked phishing campaign targeting journalists, government officials
https://therecord.media/germany-warns-phishing-campaign-signal-gov-officials-journalists

Chinese crypto scammer sentenced in absentia to 20 years after fleeing US
https://therecord.media/chinese-crypto-scammer-sentenced-after-fleeing-us

North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam
https://therecord.media/north-korean-hackers-targeted-crypto-exec-clickfix

Manipulating AI memory for profit: The rise of AI Recommendation Poisoning
https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/

LOTUSLITE: Targeted espionage leveraging geopolitical themes
https://www.reddit.com/r/netsec/comments/1r17r76/lotuslite_targeted_espionage_leveraging/

Adbleed: partially de-anonymizing VPN users with adblock filter lists
https://www.reddit.com/r/netsec/comments/1r14rlh/adbleed_partially_deanonymizing_vpn_users_with/

Microsoft Patch Tuesday, February 2026 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2026/02/10/microsoft-patch-tuesday-february-2026-security-update-review

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Georgia healthcare company data breach impacts more than 620,000
https://therecord.media/georgia-healthcare-company-data-breach-impacts-620000

Spam and phishing in 2025
https://securelist.com/spam-and-phishing-report-2025/118785/

Prompt Injection Via Road Signs
https://www.schneier.com/blog/archives/2026/02/prompt-injection-via-road-signs.html

The game is over: when “free” comes at too high a price. What we know about RenEngine
https://securelist.com/renengine-campaign-with-hijackloader-lumma-and-acr-stealer/118891/

Entropy-Based Evidence for Bitcoin's Discrete Time Mechanism
https://arxiv.org/abs/2602.09027

Non-existence of Information-Geometric Fermat Structures: Violation of Dual Lattice Consistency in Statistical Manifolds with $L^n$ Structure
https://arxiv.org/abs/2602.09028

Scaling GraphLLM with Bilevel-Optimized Sparse Querying
https://arxiv.org/abs/2602.09029

The strategic SIEM buyer’s guide: Choosing an AI-ready platform for the agentic era
https://www.microsoft.com/en-us/security/blog/2026/02/11/the-strategic-siem-buyers-guide-choosing-an-ai-ready-platform-for-the-agentic-era/

Microsoft's Notepad Got Pwned (CVE-2026-20841)
https://www.reddit.com/r/netsec/comments/1r2n8rk/microsofts_notepad_got_pwned_cve202620841/

40 state AGs warn House KOSA bill falls short of protecting children online
https://therecord.media/40-state-ags-warn-house-kosa-bill-falls-short

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Pwning Supercomputers - A 20yo vulnerability in Munge
https://www.reddit.com/r/netsec/comments/1r3kavf/pwning_supercomputers_a_20yo_vulnerability_in/

Europe must adapt to ‘permanent’ cyber and hybrid threats, Sweden warns
https://therecord.media/sweden-cyber-threats-europe-permanent

US needs to impose ‘real costs’ on bad actors, State Department cyber official says
https://therecord.media/usa-cyber-actors-consequences

CISA orders federal agencies to patch exploited SolarWinds, Apple, Microsoft bugs within weeks
https://therecord.media/cisa-orders-federal-agencies-to-patch-solarwinds-microsoft-apple-bugs

Estonia spy chief calls on Europe to invest in its own offensive cyber capabilities
https://therecord.media/estonia-spy-chief-calls-on-europe-to-invest-in-own-offense

Brutus: Open-source credential testing tool for offensive security
https://www.reddit.com/r/netsec/comments/1r3s9wo/brutus_opensource_credential_testing_tool_for/

China may be rehearsing a digital siege, Taiwan warns
https://therecord.media/china-taiwan-digital-siege-munich

NATO must impose costs on Russia, China over cyber and hybrid attacks, says deputy chief
https://therecord.media/nato-must-impost-costs-russia-china-cyber-hybrid-deputy-secretary

EU can’t be ‘naive’ about enemies shutting down critical infrastructure, warns tech official
https://therecord.media/eu-cyber-critical-infrastructure-tech

Space emerges as new front in great power competition, officials warn
https://therecord.media/space-cybersecurity-new-front-war

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Starlink restrictions hit Russian forces as Moscow seeks workarounds
https://therecord.media/starlink-restrictions-hit-russian-forces

Over 500,000 VKontakte accounts hijacked through malicious Chrome extensions
https://therecord.media/500000-vkontakte-accounts-hijacked-chrome-extensions

New Joomla! Novarain/Tassos Framework Vulnerabilities Advisory
https://www.reddit.com/r/netsec/comments/1r64yhj/new_joomla_novaraintassos_framework/

sandboxec: A lightweight command sandbox for Linux, secure-by-default, built on Landlock.
https://www.reddit.com/r/netsec/comments/1r640ry/sandboxec_a_lightweight_command_sandbox_for_linux/

[Analysis] Massive Active GitHub Malware Campaign | Hundreds of Malicious Repositories Identified
https://www.reddit.com/r/netsec/comments/1r66u2r/analysis_massive_active_github_malware_campaign/

The Promptware Kill Chain
https://www.schneier.com/blog/archives/2026/02/the-promptware-kill-chain.html

When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise
https://www.reddit.com/r/netsec/comments/1r6l5e3/when_audits_fail_part_2_from_preauth_ssrf_to_rce/

Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services
https://www.reddit.com/r/netsec/comments/1r6r7no/almost_impossible_java_deserialization_through/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Dutch police arrest man who refused to delete confidential files shared by mistake
https://therecord.media/netherlands-arrest-confidential-files-police

Hackers target supporters of Iran protests in new espionage campaign
https://therecord.media/hackers-target-iran-protest-supporters-cyber-campaign

AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks
https://research.checkpoint.com/2026/ai-in-the-middle-turning-web-based-ai-services-into-c2-proxies-the-future-of-ai-driven-attacks/

Unify now or pay later: New research exposes the operational cost of a fragmented SOC
https://www.microsoft.com/en-us/security/blog/2026/02/17/unify-now-or-pay-later-new-research-exposes-the-operational-cost-of-a-fragmented-soc/

Assessing Spear-Phishing Website Generation in Large Language Model Coding Agents
https://arxiv.org/abs/2602.13363

Unsafer in Many Turns: Benchmarking and Defending Multi-Turn Safety Risks in Tool-Using Agents
https://arxiv.org/abs/2602.13379

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Predator spyware used to infect phone belonging to Angolan journalist, report says
https://therecord.media/predator-spyware-used-to-infect-phone-angola-journalist

AI Found Twelve New Vulnerabilities in OpenSSL
https://www.schneier.com/blog/archives/2026/02/ai-found-twelve-new-vulnerabilities-in-openssl.html

Poland bans Chinese-made cars from entering military sites
https://therecord.media/poland-bans-chinese-made-cars-from-military-sites

New backdoor found in Android tablets targeting users in Russia, Germany and Japan
https://therecord.media/new-backdoor-found-in-android-russia-japan-brazil

Texas sues TP-Link, alleging it allows China to hack into routers
https://therecord.media/texas-sues-tp-link-china-allegations

Fed agencies ordered to patch Dell bug by Saturday after exploitation warning
https://therecord.media/fed-agencies-ordered-to-patch-dell-bug-after-exploitation-warning

State of Passkey Authentication in the Wild: A Census of the Top 100K sites
https://arxiv.org/abs/2602.15032

Exploiting Layer-Specific Vulnerabilities to Backdoor Attack in Federated Learning
https://arxiv.org/abs/2602.15135

Weight space Detection of Backdoors in LoRA Adapters
https://arxiv.org/abs/2602.15161

EduResearchBench: A Hierarchical Atomic Task Decomposition Benchmark for Full-Lifecycle Educational Research
https://arxiv.org/abs/2602.15195

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How a single typo led to RCE in Firefox
https://www.reddit.com/r/netsec/comments/1rbjdso/how_a_single_typo_led_to_rce_in_firefox/

Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
https://www.reddit.com/r/netsec/comments/1rbzbyv/malicious_chrome_extension_targeting_apple_app/

Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://www.reddit.com/r/netsec/comments/1rc6t3w/scary_datapoints_re_network_visibility_in_dragos/

I built a network security analyzer using information geometry (Riemannian manifolds) instead of traditional rule-based detection
https://www.reddit.com/r/netsec/comments/1rc91zq/i_built_a_network_security_analyzer_using/

Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800

Variational approach to nonholonomic and inequality-constrained mechanics
https://arxiv.org/abs/2409.11063

23rd February – Threat Intelligence Report
https://research.checkpoint.com/2026/23rd-february-threat-intelligence-report/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East
https://therecord.media/north-korean-hackers-using-medusa-ransomware

Is AI Good for Democracy?
https://www.schneier.com/blog/archives/2026/02/is-ai-good-for-democracy.html

Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals
https://therecord.media/ukraine-telegram-regulation-russia-sabotage-recruitment

UAE claims it stopped ‘terrorist’ ransomware attack
https://therecord.media/uae-claims-it-stopped-terrorist-ransomware-attack

Scaling security operations with Microsoft Defender autonomous defense and expert-led services
https://www.microsoft.com/en-us/security/blog/2026/02/24/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/

Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
https://www.reddit.com/r/netsec/comments/1rdi8m9/goodbye_innerhtml_hello_sethtml_stronger_xss/

Crypto platform Step Finance shutting down after $40 million theft
https://therecord.media/step-finance-cryptocurrency-theft-shutdown

Reddit fined $20 million by UK for not effectively checking users’ ages
https://therecord.media/reddit-children-age-checks-uk-ico-fine

US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI
https://therecord.media/us-committed-to-fighting-southeast-asia-scam-compounds

Phishing operation with links to Russia, Armenia compromised Western cargo companies, researchers find
https://therecord.media/phishing-operation-russia-armenia-targeting-us-european-cargoDCInject: Persistent Backdoor Attacks via Frequency Manipulation in Personal Federated Learning

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Moscow man accused of posing as FSB officer to extort Conti ransomware gang
https://therecord.media/moscow-man-accused-of-extorting-conti-gang

Chinese prosecutors raise alarm about growth of domestic IP theft
https://therecord.media/china-domestic-ip-theft-crackdown

Medical device firm UFP says backup data systems deployed following cyberattack
https://therecord.media/ufp-technologies-medical-devices-sec-filing-cyberattack

PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
https://therecord.media/powerschool-cps-settle-proposed-class-action

Five Eyes allies warn hackers are actively exploiting Cisco SD-WAN flaws
https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan

Discord puts global age verification policy on hold after backlash
https://therecord.media/discord-age-verification-policy-on-hold-after-backlash

Starkiller Phishing Kit: Why MFA Fails Against Real-Time Reverse Proxies — Technical Analysis + Rust PoC for TLS Fingerprinting
https://www.reddit.com/r/netsec/comments/1re5gds/starkiller_phishing_kit_why_mfa_fails_against/

TURN Server Security Best Practices - hardening checklist, IP range tables, and deployment patterns
https://www.reddit.com/r/netsec/comments/1re9az6/turn_server_security_best_practices_hardening/

Poisoning AI Training Data
https://www.schneier.com/blog/archives/2026/02/poisoning-ai-training-data.html

I rendered 1,418 Unicode confusable pairs across 230 system fonts. 82 are pixel-identical, and the font your site uses determines which ones.
https://www.reddit.com/r/netsec/comments/1rebvdc/i_rendered_1418_unicode_confusable_pairs_across/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyberattack briefly disrupts Russian internet regulator and defense ministry websites
https://therecord.media/cyberattack-briefly-takes-down-russian-government-websites

LLM-Assisted Deanonymization
https://www.schneier.com/blog/archives/2026/03/llm-assisted-deanonymization.html

German court convicts alleged mastermind behind global investment scam network
https://therecord.media/german-court-convicts-alleged-mastermind-scam-network

British organizations urged to be alert to threat of Iranian cyberattacks
https://therecord.media/iran-britain-cyber-threats-warning

Free browser-based steganography CTF generator create challenges with randomized encoding pipelines, auto-generated solutions, and progressive hints
https://www.reddit.com/r/netsec/comments/1rivnn2/free_browserbased_steganography_ctf_generator/

Google and Cloudflare testing Merkel Tree Certificates instead of normal signatures for TLS
https://www.reddit.com/r/netsec/comments/1riw5km/google_and_cloudflare_testing_merkel_tree/

Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
https://therecord.media/india-pakistan-cyber-campaign-apt

University of Hawaiʻi Cancer Center confirms data leak following ransomware attack
https://therecord.media/university-of-hawaii-ransomware-data-breach

OAuth redirection abuse enables phishing and malware delivery
https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/

2nd March – Threat Intelligence Report
https://research.checkpoint.com/2026/2nd-march-threat-intelligence-report/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman