Top Security News for Today
Predator spyware used to infect phone belonging to Angolan journalist, report says
https://therecord.media/predator-spyware-used-to-infect-phone-angola-journalist
AI Found Twelve New Vulnerabilities in OpenSSL
https://www.schneier.com/blog/archives/2026/02/ai-found-twelve-new-vulnerabilities-in-openssl.html
Poland bans Chinese-made cars from entering military sites
https://therecord.media/poland-bans-chinese-made-cars-from-military-sites
New backdoor found in Android tablets targeting users in Russia, Germany and Japan
https://therecord.media/new-backdoor-found-in-android-russia-japan-brazil
Texas sues TP-Link, alleging it allows China to hack into routers
https://therecord.media/texas-sues-tp-link-china-allegations
Fed agencies ordered to patch Dell bug by Saturday after exploitation warning
https://therecord.media/fed-agencies-ordered-to-patch-dell-bug-after-exploitation-warning
State of Passkey Authentication in the Wild: A Census of the Top 100K sites
https://arxiv.org/abs/2602.15032
Exploiting Layer-Specific Vulnerabilities to Backdoor Attack in Federated Learning
https://arxiv.org/abs/2602.15135
Weight space Detection of Backdoors in LoRA Adapters
https://arxiv.org/abs/2602.15161
EduResearchBench: A Hierarchical Atomic Task Decomposition Benchmark for Full-Lifecycle Educational Research
https://arxiv.org/abs/2602.15195
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Predator spyware used to infect phone belonging to Angolan journalist, report says
https://therecord.media/predator-spyware-used-to-infect-phone-angola-journalist
AI Found Twelve New Vulnerabilities in OpenSSL
https://www.schneier.com/blog/archives/2026/02/ai-found-twelve-new-vulnerabilities-in-openssl.html
Poland bans Chinese-made cars from entering military sites
https://therecord.media/poland-bans-chinese-made-cars-from-military-sites
New backdoor found in Android tablets targeting users in Russia, Germany and Japan
https://therecord.media/new-backdoor-found-in-android-russia-japan-brazil
Texas sues TP-Link, alleging it allows China to hack into routers
https://therecord.media/texas-sues-tp-link-china-allegations
Fed agencies ordered to patch Dell bug by Saturday after exploitation warning
https://therecord.media/fed-agencies-ordered-to-patch-dell-bug-after-exploitation-warning
State of Passkey Authentication in the Wild: A Census of the Top 100K sites
https://arxiv.org/abs/2602.15032
Exploiting Layer-Specific Vulnerabilities to Backdoor Attack in Federated Learning
https://arxiv.org/abs/2602.15135
Weight space Detection of Backdoors in LoRA Adapters
https://arxiv.org/abs/2602.15161
EduResearchBench: A Hierarchical Atomic Task Decomposition Benchmark for Full-Lifecycle Educational Research
https://arxiv.org/abs/2602.15195
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Predator spyware used to infect phone belonging to Angolan journalist, report says
The finding is the latest evidence that despite being placed on the U.S. government’s Entity List in July 2023, Predator manufacturer the Intellexa Consortium has continued to operate in the shadows.
Top Security News for Today
Arkanix Stealer: a C++ & Python infostealer
https://securelist.com/arkanix-stealer/119006/
Attackers breach France’s national bank account database
https://therecord.media/attackers-breach-france-national-bank-account-database
Ransomware gang threatens Cheyenne and Arapaho Tribes after shutting down schools
https://therecord.media/cheyenne-arapaho-ransomware-rhysida
[DroidGround Demo](https://www.reddit.com/r/netsec/comments/1r8u940/droidground_demo/)
https://www.reddit.com/r/netsec/comments/1r8u940/droidground_demo/
[Compromising Cline's Production Releases just by Prompting an Issue Triager](https://www.reddit.com/r/netsec/comments/1r8vdkb/compromising_clines_production_releases_just_by/)
https://www.reddit.com/r/netsec/comments/1r8vdkb/compromising_clines_production_releases_just_by/
[Malicious AI](https://www.schneier.com/blog/archives/2026/02/malicious-ai.html)
https://www.schneier.com/blog/archives/2026/02/malicious-ai.html
[Kimwolf Botnet Swamps Anonymity Network I2P](https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network-i2p/)
https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network-i2p/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Arkanix Stealer: a C++ & Python infostealer
https://securelist.com/arkanix-stealer/119006/
Attackers breach France’s national bank account database
https://therecord.media/attackers-breach-france-national-bank-account-database
Ransomware gang threatens Cheyenne and Arapaho Tribes after shutting down schools
https://therecord.media/cheyenne-arapaho-ransomware-rhysida
[DroidGround Demo](https://www.reddit.com/r/netsec/comments/1r8u940/droidground_demo/)
https://www.reddit.com/r/netsec/comments/1r8u940/droidground_demo/
[Compromising Cline's Production Releases just by Prompting an Issue Triager](https://www.reddit.com/r/netsec/comments/1r8vdkb/compromising_clines_production_releases_just_by/)
https://www.reddit.com/r/netsec/comments/1r8vdkb/compromising_clines_production_releases_just_by/
[Malicious AI](https://www.schneier.com/blog/archives/2026/02/malicious-ai.html)
https://www.schneier.com/blog/archives/2026/02/malicious-ai.html
[Kimwolf Botnet Swamps Anonymity Network I2P](https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network-i2p/)
https://krebsonsecurity.com/2026/02/kimwolf-botnet-swamps-anonymity-network-i2p/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today
Your AD password complexity policies are security theater — one RPC call bypasses all of them (PoC scripts + defense included)
https://www.reddit.com/r/netsec/comments/1r9qkpl/your_ad_password_complexity_policies_are_security/
Hackers breach contractor linked to Ukraine’s central bank collectible coin store
https://therecord.media/hackers-breach-ukraine-national-bank-contractor
Discovery & Analysis of CVE-2025-29969
https://www.reddit.com/r/netsec/comments/1r9th6w/discovery_analysis_of_cve202529969/
Building CrowdStrike workflows with Claude Code skills
https://www.reddit.com/r/netsec/comments/1r9s0ah/building_crowdstrike_workflows_with_claude_code/
Ring Cancels Its Partnership with Flock
https://www.schneier.com/blog/archives/2026/02/ring-cancels-its-partnership-with-flock.html
Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns
https://therecord.media/russia-cyberattacks-europe-warfare
In Memoriam: Jason Snitker, a.k.a. Parmaster. RIP Legend
https://www.reddit.com/r/netsec/comments/1r9wmyj/in_memoriam_jason_snitker_aka_parmaster_rip_legend/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Your AD password complexity policies are security theater — one RPC call bypasses all of them (PoC scripts + defense included)
https://www.reddit.com/r/netsec/comments/1r9qkpl/your_ad_password_complexity_policies_are_security/
Hackers breach contractor linked to Ukraine’s central bank collectible coin store
https://therecord.media/hackers-breach-ukraine-national-bank-contractor
Discovery & Analysis of CVE-2025-29969
https://www.reddit.com/r/netsec/comments/1r9th6w/discovery_analysis_of_cve202529969/
Building CrowdStrike workflows with Claude Code skills
https://www.reddit.com/r/netsec/comments/1r9s0ah/building_crowdstrike_workflows_with_claude_code/
Ring Cancels Its Partnership with Flock
https://www.schneier.com/blog/archives/2026/02/ring-cancels-its-partnership-with-flock.html
Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns
https://therecord.media/russia-cyberattacks-europe-warfare
In Memoriam: Jason Snitker, a.k.a. Parmaster. RIP Legend
https://www.reddit.com/r/netsec/comments/1r9wmyj/in_memoriam_jason_snitker_aka_parmaster_rip_legend/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Your AD password complexity policies are security theater — one RPC call bypasses all of them…
Posted by Suitable-Baker7584 - 1 vote and 1 comment
Top Security News for Today
'Starkiller’ Phishing Service Proxies Real Login Pages, MFA
https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/
Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
'Starkiller’ Phishing Service Proxies Real Login Pages, MFA
https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/
Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Krebs on Security
‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering lets customers sidestep…
Top Security News for Today
How a single typo led to RCE in Firefox
https://www.reddit.com/r/netsec/comments/1rbjdso/how_a_single_typo_led_to_rce_in_firefox/
Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
https://www.reddit.com/r/netsec/comments/1rbzbyv/malicious_chrome_extension_targeting_apple_app/
Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://www.reddit.com/r/netsec/comments/1rc6t3w/scary_datapoints_re_network_visibility_in_dragos/
I built a network security analyzer using information geometry (Riemannian manifolds) instead of traditional rule-based detection
https://www.reddit.com/r/netsec/comments/1rc91zq/i_built_a_network_security_analyzer_using/
Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800
Variational approach to nonholonomic and inequality-constrained mechanics
https://arxiv.org/abs/2409.11063
23rd February – Threat Intelligence Report
https://research.checkpoint.com/2026/23rd-february-threat-intelligence-report/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
How a single typo led to RCE in Firefox
https://www.reddit.com/r/netsec/comments/1rbjdso/how_a_single_typo_led_to_rce_in_firefox/
Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
https://www.reddit.com/r/netsec/comments/1rbzbyv/malicious_chrome_extension_targeting_apple_app/
Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://www.reddit.com/r/netsec/comments/1rc6t3w/scary_datapoints_re_network_visibility_in_dragos/
I built a network security analyzer using information geometry (Riemannian manifolds) instead of traditional rule-based detection
https://www.reddit.com/r/netsec/comments/1rc91zq/i_built_a_network_security_analyzer_using/
Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800
Variational approach to nonholonomic and inequality-constrained mechanics
https://arxiv.org/abs/2409.11063
23rd February – Threat Intelligence Report
https://research.checkpoint.com/2026/23rd-february-threat-intelligence-report/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: How a single typo led to RCE in Firefox
Explore this post and more from the netsec community
Top Security News for Today
Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://therecord.media/data-protection-authorities-warn-ai-companies-of-sharing-images
Ransomware gangs advancing Moscow’s geopolitical aims, Romanian cyber chief warns
https://therecord.media/ransomware-gangs-advancing-moscow-geopolitical-interests-warns-romania
Ukraine says cyberattacks on energy grid now used to guide missile strikes
https://therecord.media/ukraine-cyberattacks-guiding-russian-missile-strikes
On the Security of Password Managers
https://www.schneier.com/blog/archives/2026/02/on-the-security-of-password-managers.html
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html
Air Côte d'Ivoire confirms cyberattack following ransomware claims
https://therecord.media/air-cote-divoire-confirms-cyberattack
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://therecord.media/data-protection-authorities-warn-ai-companies-of-sharing-images
Ransomware gangs advancing Moscow’s geopolitical aims, Romanian cyber chief warns
https://therecord.media/ransomware-gangs-advancing-moscow-geopolitical-interests-warns-romania
Ukraine says cyberattacks on energy grid now used to guide missile strikes
https://therecord.media/ukraine-cyberattacks-guiding-russian-missile-strikes
On the Security of Password Managers
https://www.schneier.com/blog/archives/2026/02/on-the-security-of-password-managers.html
Malicious OpenClaw Skills Used to Distribute Atomic MacOS Stealer
https://www.trendmicro.com/en_us/research/26/b/openclaw-skills-used-to-distribute-atomic-macos-stealer.html
Air Côte d'Ivoire confirms cyberattack following ransomware claims
https://therecord.media/air-cote-divoire-confirms-cyberattack
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Global data protection authorities warn generative AI companies against replicating real people
The joint statement comes on the heels of the Grok AI chatbot creating and sharing millions of images of “nudified” real people.
Top Security News for Today
North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East
https://therecord.media/north-korean-hackers-using-medusa-ransomware
Is AI Good for Democracy?
https://www.schneier.com/blog/archives/2026/02/is-ai-good-for-democracy.html
Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals
https://therecord.media/ukraine-telegram-regulation-russia-sabotage-recruitment
UAE claims it stopped ‘terrorist’ ransomware attack
https://therecord.media/uae-claims-it-stopped-terrorist-ransomware-attack
Scaling security operations with Microsoft Defender autonomous defense and expert-led services
https://www.microsoft.com/en-us/security/blog/2026/02/24/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
https://www.reddit.com/r/netsec/comments/1rdi8m9/goodbye_innerhtml_hello_sethtml_stronger_xss/
Crypto platform Step Finance shutting down after $40 million theft
https://therecord.media/step-finance-cryptocurrency-theft-shutdown
Reddit fined $20 million by UK for not effectively checking users’ ages
https://therecord.media/reddit-children-age-checks-uk-ico-fine
US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI
https://therecord.media/us-committed-to-fighting-southeast-asia-scam-compounds
Phishing operation with links to Russia, Armenia compromised Western cargo companies, researchers find
https://therecord.media/phishing-operation-russia-armenia-targeting-us-european-cargoDCInject: Persistent Backdoor Attacks via Frequency Manipulation in Personal Federated Learning
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East
https://therecord.media/north-korean-hackers-using-medusa-ransomware
Is AI Good for Democracy?
https://www.schneier.com/blog/archives/2026/02/is-ai-good-for-democracy.html
Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals
https://therecord.media/ukraine-telegram-regulation-russia-sabotage-recruitment
UAE claims it stopped ‘terrorist’ ransomware attack
https://therecord.media/uae-claims-it-stopped-terrorist-ransomware-attack
Scaling security operations with Microsoft Defender autonomous defense and expert-led services
https://www.microsoft.com/en-us/security/blog/2026/02/24/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
https://www.reddit.com/r/netsec/comments/1rdi8m9/goodbye_innerhtml_hello_sethtml_stronger_xss/
Crypto platform Step Finance shutting down after $40 million theft
https://therecord.media/step-finance-cryptocurrency-theft-shutdown
Reddit fined $20 million by UK for not effectively checking users’ ages
https://therecord.media/reddit-children-age-checks-uk-ico-fine
US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI
https://therecord.media/us-committed-to-fighting-southeast-asia-scam-compounds
Phishing operation with links to Russia, Armenia compromised Western cargo companies, researchers find
https://therecord.media/phishing-operation-russia-armenia-targeting-us-european-cargoDCInject: Persistent Backdoor Attacks via Frequency Manipulation in Personal Federated Learning
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East
Cybersecurity researchers said they saw Medusa attacks launched by members of Lazarus — a well-known North Korean hacking operation housed within the country’s military — against a company in the Middle East and a healthcare organization in the U.S.
Top Security News for Today
Moscow man accused of posing as FSB officer to extort Conti ransomware gang
https://therecord.media/moscow-man-accused-of-extorting-conti-gang
Chinese prosecutors raise alarm about growth of domestic IP theft
https://therecord.media/china-domestic-ip-theft-crackdown
Medical device firm UFP says backup data systems deployed following cyberattack
https://therecord.media/ufp-technologies-medical-devices-sec-filing-cyberattack
PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
https://therecord.media/powerschool-cps-settle-proposed-class-action
Five Eyes allies warn hackers are actively exploiting Cisco SD-WAN flaws
https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan
Discord puts global age verification policy on hold after backlash
https://therecord.media/discord-age-verification-policy-on-hold-after-backlash
Starkiller Phishing Kit: Why MFA Fails Against Real-Time Reverse Proxies — Technical Analysis + Rust PoC for TLS Fingerprinting
https://www.reddit.com/r/netsec/comments/1re5gds/starkiller_phishing_kit_why_mfa_fails_against/
TURN Server Security Best Practices - hardening checklist, IP range tables, and deployment patterns
https://www.reddit.com/r/netsec/comments/1re9az6/turn_server_security_best_practices_hardening/
Poisoning AI Training Data
https://www.schneier.com/blog/archives/2026/02/poisoning-ai-training-data.html
I rendered 1,418 Unicode confusable pairs across 230 system fonts. 82 are pixel-identical, and the font your site uses determines which ones.
https://www.reddit.com/r/netsec/comments/1rebvdc/i_rendered_1418_unicode_confusable_pairs_across/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Moscow man accused of posing as FSB officer to extort Conti ransomware gang
https://therecord.media/moscow-man-accused-of-extorting-conti-gang
Chinese prosecutors raise alarm about growth of domestic IP theft
https://therecord.media/china-domestic-ip-theft-crackdown
Medical device firm UFP says backup data systems deployed following cyberattack
https://therecord.media/ufp-technologies-medical-devices-sec-filing-cyberattack
PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
https://therecord.media/powerschool-cps-settle-proposed-class-action
Five Eyes allies warn hackers are actively exploiting Cisco SD-WAN flaws
https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan
Discord puts global age verification policy on hold after backlash
https://therecord.media/discord-age-verification-policy-on-hold-after-backlash
Starkiller Phishing Kit: Why MFA Fails Against Real-Time Reverse Proxies — Technical Analysis + Rust PoC for TLS Fingerprinting
https://www.reddit.com/r/netsec/comments/1re5gds/starkiller_phishing_kit_why_mfa_fails_against/
TURN Server Security Best Practices - hardening checklist, IP range tables, and deployment patterns
https://www.reddit.com/r/netsec/comments/1re9az6/turn_server_security_best_practices_hardening/
Poisoning AI Training Data
https://www.schneier.com/blog/archives/2026/02/poisoning-ai-training-data.html
I rendered 1,418 Unicode confusable pairs across 230 system fonts. 82 are pixel-identical, and the font your site uses determines which ones.
https://www.reddit.com/r/netsec/comments/1rebvdc/i_rendered_1418_unicode_confusable_pairs_across/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Moscow man accused of posing as FSB officer to extort Conti ransomware gang
A Moscow resident has been accused of trying to extort money from the notorious Conti ransomware group by posing as an officer of Russia’s Federal Security Service, according to local media reports.
Top Security News for Today
Ransomware payments dropped in 2025 as attack numbers reached record levels: Chainalysis
https://therecord.media/ransomware-payments-chainalysis-cybercrime
Google disrupts China-linked cyberespionage campaign spanning dozens of countries
https://therecord.media/china-cyber-espionage-google-disrupt
Google API Keys Weren't Secrets. But then Gemini Changed the Rules.
https://www.reddit.com/r/netsec/comments/1rf61kl/google_api_keys_werent_secrets_but_then_gemini/
LLMs Generate Predictable Passwords
https://www.schneier.com/blog/archives/2026/02/llms-generate-predictable-passwords.html
Threat modeling AI applications
https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/
Introducing CloudFox GCP: Attack Path Identification for Google Cloud
https://bishopfox.com/blog/introducing-cloudfox-gcp-attack-path-identification-for-google-cloud
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Ransomware payments dropped in 2025 as attack numbers reached record levels: Chainalysis
https://therecord.media/ransomware-payments-chainalysis-cybercrime
Google disrupts China-linked cyberespionage campaign spanning dozens of countries
https://therecord.media/china-cyber-espionage-google-disrupt
Google API Keys Weren't Secrets. But then Gemini Changed the Rules.
https://www.reddit.com/r/netsec/comments/1rf61kl/google_api_keys_werent_secrets_but_then_gemini/
LLMs Generate Predictable Passwords
https://www.schneier.com/blog/archives/2026/02/llms-generate-predictable-passwords.html
Threat modeling AI applications
https://www.microsoft.com/en-us/security/blog/2026/02/26/threat-modeling-ai-applications/
Introducing CloudFox GCP: Attack Path Identification for Google Cloud
https://bishopfox.com/blog/introducing-cloudfox-gcp-attack-path-identification-for-google-cloud
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Ransomware payments dropped in 2025 as attack numbers reached record levels: Chainalysis
The rate at which ransomware victims paid cybercriminals fell last year while the overall number of attacks ballooned, Chainalysis found.
Top Security News for Today
We scanned 6,500+ ClawHub skills. 36% have security flaws. Built a Free Community run scanner to catch them before they execute
https://www.reddit.com/r/netsec/comments/1rg0ijo/we_scanned_6500_clawhub_skills_36_have_security/
Why Tehran’s Two-Tiered Internet Is So Dangerous
https://www.schneier.com/blog/archives/2026/02/why_tehrans_two_tiered_internet_is_so_dangerous.html
Phishing Attacks Against People Seeking Programming Jobs
https://www.schneier.com/blog/archives/2026/02/phishing_attacks_against_people_seeking_programming_jobs.html
Uncovering a Global macOS Malware Campaign
https://www.reddit.com/r/netsec/comments/1rg3zmd/uncovering_a_global_macos_malware_campaign/
Twitch Ships Server-Side Eppo Keys in Its iOS App, Exposing Its Entire Product Roadmap
https://www.reddit.com/r/netsec/comments/1rg6mid/twitch_ships_serverside_eppo_keys_in_its_ios_app/
Instagram to start alerting parents when children search for terms relating to self-harm
https://therecord.media/instagram-alert-parents-children-search-terms-self-harm
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
We scanned 6,500+ ClawHub skills. 36% have security flaws. Built a Free Community run scanner to catch them before they execute
https://www.reddit.com/r/netsec/comments/1rg0ijo/we_scanned_6500_clawhub_skills_36_have_security/
Why Tehran’s Two-Tiered Internet Is So Dangerous
https://www.schneier.com/blog/archives/2026/02/why_tehrans_two_tiered_internet_is_so_dangerous.html
Phishing Attacks Against People Seeking Programming Jobs
https://www.schneier.com/blog/archives/2026/02/phishing_attacks_against_people_seeking_programming_jobs.html
Uncovering a Global macOS Malware Campaign
https://www.reddit.com/r/netsec/comments/1rg3zmd/uncovering_a_global_macos_malware_campaign/
Twitch Ships Server-Side Eppo Keys in Its iOS App, Exposing Its Entire Product Roadmap
https://www.reddit.com/r/netsec/comments/1rg6mid/twitch_ships_serverside_eppo_keys_in_its_ios_app/
Instagram to start alerting parents when children search for terms relating to self-harm
https://therecord.media/instagram-alert-parents-children-search-terms-self-harm
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: We scanned 6,500+ ClawHub skills. 36% have security flaws. Built a Free Community run scanner…
Posted by kinso1338 - 14 votes and 1 comment
Top Security News for Today
Who is the Kimwolf Botmaster “Dort”?
https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
I used MCP Ghidra and Claude Code to find 9 kernel driver vulnerabilities on my gaming laptop
https://www.reddit.com/r/netsec/comments/1rh50yi/i_used_mcp_ghidra_and_claude_code_to_find_9/
Network Security News Feed
https://www.reddit.com/r/netsec/comments/1rhd7j8/network_security_news_feed/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Who is the Kimwolf Botmaster “Dort”?
https://krebsonsecurity.com/2026/02/who-is-the-kimwolf-botmaster-dort/
I used MCP Ghidra and Claude Code to find 9 kernel driver vulnerabilities on my gaming laptop
https://www.reddit.com/r/netsec/comments/1rh50yi/i_used_mcp_ghidra_and_claude_code_to_find_9/
Network Security News Feed
https://www.reddit.com/r/netsec/comments/1rhd7j8/network_security_news_feed/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Krebs on Security
Who is the Kimwolf Botmaster “Dort”?
In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to assemble Kimwolf, the world's largest and most disruptive botnet. Since then, the person in control of Kimwolf -- who goes by the handle…
Top Security News for Today
Compositional-ARC: Assessing Systematic Generalization in Abstract Spatial Reasoning
https://arxiv.org/abs/2504.01445
r/netsec monthly discussion & tool thread
https://www.reddit.com/r/netsec/comments/1rhyn04/rnetsec_monthly_discussion_tool_thread/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Compositional-ARC: Assessing Systematic Generalization in Abstract Spatial Reasoning
https://arxiv.org/abs/2504.01445
r/netsec monthly discussion & tool thread
https://www.reddit.com/r/netsec/comments/1rhyn04/rnetsec_monthly_discussion_tool_thread/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
arXiv.org
Compositional-ARC: Assessing Systematic Generalization in Abstract...
Systematic generalization refers to the capacity to understand and generate novel combinations from known components. Despite recent progress by large language models (LLMs) across various...
Top Security News for Today
Cyberattack briefly disrupts Russian internet regulator and defense ministry websites
https://therecord.media/cyberattack-briefly-takes-down-russian-government-websites
LLM-Assisted Deanonymization
https://www.schneier.com/blog/archives/2026/03/llm-assisted-deanonymization.html
German court convicts alleged mastermind behind global investment scam network
https://therecord.media/german-court-convicts-alleged-mastermind-scam-network
British organizations urged to be alert to threat of Iranian cyberattacks
https://therecord.media/iran-britain-cyber-threats-warning
Free browser-based steganography CTF generator create challenges with randomized encoding pipelines, auto-generated solutions, and progressive hints
https://www.reddit.com/r/netsec/comments/1rivnn2/free_browserbased_steganography_ctf_generator/
Google and Cloudflare testing Merkel Tree Certificates instead of normal signatures for TLS
https://www.reddit.com/r/netsec/comments/1riw5km/google_and_cloudflare_testing_merkel_tree/
Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
https://therecord.media/india-pakistan-cyber-campaign-apt
University of Hawaiʻi Cancer Center confirms data leak following ransomware attack
https://therecord.media/university-of-hawaii-ransomware-data-breach
OAuth redirection abuse enables phishing and malware delivery
https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/
2nd March – Threat Intelligence Report
https://research.checkpoint.com/2026/2nd-march-threat-intelligence-report/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Cyberattack briefly disrupts Russian internet regulator and defense ministry websites
https://therecord.media/cyberattack-briefly-takes-down-russian-government-websites
LLM-Assisted Deanonymization
https://www.schneier.com/blog/archives/2026/03/llm-assisted-deanonymization.html
German court convicts alleged mastermind behind global investment scam network
https://therecord.media/german-court-convicts-alleged-mastermind-scam-network
British organizations urged to be alert to threat of Iranian cyberattacks
https://therecord.media/iran-britain-cyber-threats-warning
Free browser-based steganography CTF generator create challenges with randomized encoding pipelines, auto-generated solutions, and progressive hints
https://www.reddit.com/r/netsec/comments/1rivnn2/free_browserbased_steganography_ctf_generator/
Google and Cloudflare testing Merkel Tree Certificates instead of normal signatures for TLS
https://www.reddit.com/r/netsec/comments/1riw5km/google_and_cloudflare_testing_merkel_tree/
Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
https://therecord.media/india-pakistan-cyber-campaign-apt
University of Hawaiʻi Cancer Center confirms data leak following ransomware attack
https://therecord.media/university-of-hawaii-ransomware-data-breach
OAuth redirection abuse enables phishing and malware delivery
https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/
2nd March – Threat Intelligence Report
https://research.checkpoint.com/2026/2nd-march-threat-intelligence-report/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Cyberattack briefly disrupts Russian internet regulator and defense ministry websites
Russia’s internet regulator and defense ministry said their servers were hit by a large DDoS attack that briefly disrupted access to several government websites late last week.
Top Security News for Today
Google urges Supreme Court to strike down geofence warrants as unconstitutional
https://therecord.media/google-urges-supreme-court-strike-down-geolocation-warrants
Iranian drone strikes hit Amazon data centers in Gulf, disrupting cloud services
https://therecord.media/iran-drone-strikes-hit-amazon-data-centers-gulf
Florida woman gets 2 year sentence for trafficking Microsoft software labels
https://therecord.media/florida-woman-sentenced-reselling-microsoft-labels
Built a free live CVE intelligence dashboard — looking for feedback
https://www.reddit.com/r/netsec/comments/1rjo4do/built_a_free_live_cve_intelligence_dashboard/
Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1rjqfwy/sometimes_you_can_just_feel_the_security_in_the/
Silver Dragon Targets Organizations in Southeast Asia and Europe
https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/
Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow
https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Google urges Supreme Court to strike down geofence warrants as unconstitutional
https://therecord.media/google-urges-supreme-court-strike-down-geolocation-warrants
Iranian drone strikes hit Amazon data centers in Gulf, disrupting cloud services
https://therecord.media/iran-drone-strikes-hit-amazon-data-centers-gulf
Florida woman gets 2 year sentence for trafficking Microsoft software labels
https://therecord.media/florida-woman-sentenced-reselling-microsoft-labels
Built a free live CVE intelligence dashboard — looking for feedback
https://www.reddit.com/r/netsec/comments/1rjo4do/built_a_free_live_cve_intelligence_dashboard/
Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1rjqfwy/sometimes_you_can_just_feel_the_security_in_the/
Silver Dragon Targets Organizations in Southeast Asia and Europe
https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/
Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow
https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Google urges Supreme Court to strike down geofence warrants as unconstitutional
In its amicus brief, Google called the warrants a violation of people’s rights and said that in recent months it has objected to more than 3,000 geofence warrants on constitutional grounds.
Top Security News for Today
A single operator with basic skills used an open-source AI platform to breach 600+ FortiGate devices across 55 countries. No zero-days. Just weak passwords and an AI copilot. Full breakdown of CyberStrikeAI, the developer's MSS ties, and all 21 server IOCs.
https://www.reddit.com/r/netsec/comments/1rkl6zz/a_single_operator_with_basic_skills_used_an/
Using Zeek with AWS Traffic Mirroring and Kafka
https://www.reddit.com/r/netsec/comments/1rkha18/using_zeek_with_aws_traffic_mirroring_and_kafka/
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/
Mobile malware evolution in 2025
https://securelist.com/mobile-threat-report-2025/119076/
Russian hackers deploy new malware in phishing campaign targeting Ukraine
https://therecord.media/russian-ukraine-hackers-malware
Sprawling FBI, European operation takes down Leakbase cybercriminal forum
https://therecord.media/leakbase-cybercrime-fbi-europe-takedown
Manipulating AI Summarization Features
https://www.schneier.com/blog/archives/2026/03/manipulating-ai-summarization-features.html
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
A single operator with basic skills used an open-source AI platform to breach 600+ FortiGate devices across 55 countries. No zero-days. Just weak passwords and an AI copilot. Full breakdown of CyberStrikeAI, the developer's MSS ties, and all 21 server IOCs.
https://www.reddit.com/r/netsec/comments/1rkl6zz/a_single_operator_with_basic_skills_used_an/
Using Zeek with AWS Traffic Mirroring and Kafka
https://www.reddit.com/r/netsec/comments/1rkha18/using_zeek_with_aws_traffic_mirroring_and_kafka/
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/
Mobile malware evolution in 2025
https://securelist.com/mobile-threat-report-2025/119076/
Russian hackers deploy new malware in phishing campaign targeting Ukraine
https://therecord.media/russian-ukraine-hackers-malware
Sprawling FBI, European operation takes down Leakbase cybercriminal forum
https://therecord.media/leakbase-cybercrime-fbi-europe-takedown
Manipulating AI Summarization Features
https://www.schneier.com/blog/archives/2026/03/manipulating-ai-summarization-features.html
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: A single operator with basic skills used an open-source AI platform to breach 600+ FortiGate…
Explore this post and more from the netsec community
Top Security News for Today
Police dismantle major phishing platform blamed for attacks on hospitals and schools
https://therecord.media/police-dismantle-tycoon-2fa-phishing-platform
We at Codeant found a bug in pac4j-jwt (auth bypass)
https://www.reddit.com/r/netsec/comments/1rlbb2k/we_at_codeant_found_a_bug_in_pac4jjwt_auth_bypass/
62 people indicted by Taiwanese prosecutors over ties to cyber scam company Prince Group
https://therecord.media/62-indicted-taiwan-prince-group-scams
Hacked App Part of US/Israeli Propaganda Campaign Against Iran
https://www.schneier.com/blog/archives/2026/03/hacked-app-part-of-us-israeli-propaganda-campaign-against-iran.html
Google says 90 zero-days exploited in 2025 as commercial vendor activity grows
https://www.record.media/google-says-90-zero-days-exploited-apt-spyware-vendors
Malicious AI Assistant Extensions Harvest LLM Chat Histories
https://www.microsoft.com/en-us/security/blog/2026/03/05/malicious-ai-assistant-extensions-harvest-llm-chat-histories/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Police dismantle major phishing platform blamed for attacks on hospitals and schools
https://therecord.media/police-dismantle-tycoon-2fa-phishing-platform
We at Codeant found a bug in pac4j-jwt (auth bypass)
https://www.reddit.com/r/netsec/comments/1rlbb2k/we_at_codeant_found_a_bug_in_pac4jjwt_auth_bypass/
62 people indicted by Taiwanese prosecutors over ties to cyber scam company Prince Group
https://therecord.media/62-indicted-taiwan-prince-group-scams
Hacked App Part of US/Israeli Propaganda Campaign Against Iran
https://www.schneier.com/blog/archives/2026/03/hacked-app-part-of-us-israeli-propaganda-campaign-against-iran.html
Google says 90 zero-days exploited in 2025 as commercial vendor activity grows
https://www.record.media/google-says-90-zero-days-exploited-apt-spyware-vendors
Malicious AI Assistant Extensions Harvest LLM Chat Histories
https://www.microsoft.com/en-us/security/blog/2026/03/05/malicious-ai-assistant-extensions-harvest-llm-chat-histories/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Police dismantle major phishing platform blamed for attacks on hospitals and schools
International law enforcement agencies have dismantled a major phishing-as-a-service platform used to target hundreds of thousands of accounts worldwide, including those tied to hospitals and schools, Europol said Wednesday.
Top Security News for Today
Exploits and vulnerabilities in Q4 2025
https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/
Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks
https://arxiv.org/abs/2603.04459
How Effective Are Publicly Accessible Deepfake Detection Tools? A Comparative Evaluation of Open-Source and Free-to-Use Platforms
https://arxiv.org/abs/2603.04456
Beyond Input Guardrails: Reconstructing Cross-Agent Semantic Flows for Execution-Aware Attack Detection
https://arxiv.org/abs/2603.04469
Impact of 5G SA Logical Vulnerabilities on UAV Communications: Threat Models and Testbed Evaluation
https://arxiv.org/abs/2603.04662
When Denoising Becomes Unsigning: Theoretical and Empirical Analysis of Watermark Fragility Under Diffusion-Based Image Editing
https://arxiv.org/abs/2603.04696
Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
https://arxiv.org/abs/2602.15654
Claude Used to Hack Mexican Government
https://www.schneier.com/blog/archives/2026/03/claude-used-to-hack-mexican-government.html
Model Context Protocol (MCP) Authentication and Authorization
https://www.reddit.com/r/netsec/comments/1rmcz6i/model_context_protocol_mcp_authentication_and/
Hardening Firefox with Anthropic’s Red Team
https://www.reddit.com/r/netsec/comments/1rmffdp/hardening_firefox_with_anthropics_red_team/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Exploits and vulnerabilities in Q4 2025
https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/
Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks
https://arxiv.org/abs/2603.04459
How Effective Are Publicly Accessible Deepfake Detection Tools? A Comparative Evaluation of Open-Source and Free-to-Use Platforms
https://arxiv.org/abs/2603.04456
Beyond Input Guardrails: Reconstructing Cross-Agent Semantic Flows for Execution-Aware Attack Detection
https://arxiv.org/abs/2603.04469
Impact of 5G SA Logical Vulnerabilities on UAV Communications: Threat Models and Testbed Evaluation
https://arxiv.org/abs/2603.04662
When Denoising Becomes Unsigning: Theoretical and Empirical Analysis of Watermark Fragility Under Diffusion-Based Image Editing
https://arxiv.org/abs/2603.04696
Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
https://arxiv.org/abs/2602.15654
Claude Used to Hack Mexican Government
https://www.schneier.com/blog/archives/2026/03/claude-used-to-hack-mexican-government.html
Model Context Protocol (MCP) Authentication and Authorization
https://www.reddit.com/r/netsec/comments/1rmcz6i/model_context_protocol_mcp_authentication_and/
Hardening Firefox with Anthropic’s Red Team
https://www.reddit.com/r/netsec/comments/1rmffdp/hardening_firefox_with_anthropics_red_team/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today
Suche Low-Level Entwickler für eigenes Konsolen-Projekt
https://www.reddit.com/r/lowlevel/comments/1rn60z1/suche_lowlevel_entwickler_für_eigenes/
38 researchers red-teamed AI agents for 2 weeks. Here's what broke. (Agents of Chaos, Feb 2026)
https://www.reddit.com/r/netsec/comments/1rn4b6i/38_researchers_redteamed_ai_agents_for_2_weeks/
Walking x86-64 page tables by hand in QEMU + GDB
https://www.reddit.com/r/lowlevel/comments/1rnpoc2/walking_x8664_page_tables_by_hand_in_qemu_gdb/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Suche Low-Level Entwickler für eigenes Konsolen-Projekt
https://www.reddit.com/r/lowlevel/comments/1rn60z1/suche_lowlevel_entwickler_für_eigenes/
38 researchers red-teamed AI agents for 2 weeks. Here's what broke. (Agents of Chaos, Feb 2026)
https://www.reddit.com/r/netsec/comments/1rn4b6i/38_researchers_redteamed_ai_agents_for_2_weeks/
Walking x86-64 page tables by hand in QEMU + GDB
https://www.reddit.com/r/lowlevel/comments/1rnpoc2/walking_x8664_page_tables_by_hand_in_qemu_gdb/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the lowlevel community on Reddit
Explore this post and more from the lowlevel community
Top Security News for Today
From Chrome Extension Supply-Chain Compromise to Host Malware: Technical Breakdown of the ShotBird Campaign
https://www.reddit.com/r/netsec/comments/1rob5no/from_chrome_extension_supplychain_compromise_to/
Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign
https://www.reddit.com/r/netsec/comments/1robwok/fake_claude_code_install_guides_spread_amatera/
How AI Assistants are Moving the Security Goalposts
https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
https://www.reddit.com/r/netsec/comments/1rojhfl/airsnitch_demystifying_and_breaking_client/
DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/
MCP Security Checklist - 40 controls for securing AI agent tool infrastructure
https://www.reddit.com/r/netsec/comments/1roru4f/mcp_security_checklist_40_controls_for_securing/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
From Chrome Extension Supply-Chain Compromise to Host Malware: Technical Breakdown of the ShotBird Campaign
https://www.reddit.com/r/netsec/comments/1rob5no/from_chrome_extension_supplychain_compromise_to/
Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign
https://www.reddit.com/r/netsec/comments/1robwok/fake_claude_code_install_guides_spread_amatera/
How AI Assistants are Moving the Security Goalposts
https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
https://www.reddit.com/r/netsec/comments/1rojhfl/airsnitch_demystifying_and_breaking_client/
DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/
MCP Security Checklist - 40 controls for securing AI agent tool infrastructure
https://www.reddit.com/r/netsec/comments/1roru4f/mcp_security_checklist_40_controls_for_securing/
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: From Chrome Extension Supply-Chain Compromise to Host Malware: Technical Breakdown of the…
Explore this post and more from the netsec community
Top Security News for Today
Secure agentic AI for your Frontier Transformation
https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/
New Attack Against Wi-Fi
https://www.schneier.com/blog/archives/2026/03/new-attack-against-wi-fi.html
How We Hacked McKinsey's AI Platform
https://www.reddit.com/r/netsec/comments/1rp0l99/how_we_hacked_mckinseys_ai_platform/
Sign in with ANY password into Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework
https://www.reddit.com/r/netsec/comments/1rp4lyj/sign_in_with_any_password_into_rocketchat_ee/
9th March – Threat Intelligence Report
https://research.checkpoint.com/2026/9th-march-threat-intelligence-report/
Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643
https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Secure agentic AI for your Frontier Transformation
https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/
New Attack Against Wi-Fi
https://www.schneier.com/blog/archives/2026/03/new-attack-against-wi-fi.html
How We Hacked McKinsey's AI Platform
https://www.reddit.com/r/netsec/comments/1rp0l99/how_we_hacked_mckinseys_ai_platform/
Sign in with ANY password into Rocket.Chat EE (CVE-2026-28514) and other vulnerabilities we’ve found with our open source AI framework
https://www.reddit.com/r/netsec/comments/1rp4lyj/sign_in_with_any_password_into_rocketchat_ee/
9th March – Threat Intelligence Report
https://research.checkpoint.com/2026/9th-march-threat-intelligence-report/
Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 - CVE-2026-21643
https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Microsoft News
Secure agentic AI for your Frontier Transformation
Learn more about how Microsoft Agent 365 and Microsoft 365 E7 can help secure your Frontier Transformation.
Top Security News for Today
Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No
https://www.reddit.com/r/netsec/comments/1rpqlh2/your_duolingo_is_still_talking_to_bytedance_how/
Jailbreaking the F-35 Fighter Jet
https://www.schneier.com/blog/archives/2026/03/jailbreaking-the-f-35-fighter-jet.html
BeatBanker: A dual‑mode Android Trojan
https://securelist.com/beatbanker-miner-and-banker/119121/
Russian military hackers revive advanced malware to spy on Ukraine, researchers say
https://therecord.media/russia-apt-28-revives-malware-to-spy-on-ukraine
UK plans to shift fraud fight onto telecoms, tech companies
https://therecord.media/uk-plans-to-shift-fraud-fight-to-telecoms-tech
Cybercriminals impersonating city officials to steal permit payments, FBI says
https://therecord.media/cybercriminals-impersonate-city-officials-permit-payments
CISA shortens patch deadline for critical Ivanti, SolarWinds bugs
https://therecord.media/cisa-shortens-patch-deadline-ivanti-solarwinds
Finnish intelligence warns of persistent cyber espionage from Russia, China
https://therecord.media/finnish-intel-warns-espionage-china-russia
Rudd confirmed to head NSA, Cyber Command after near year-long vacancy
https://therecord.media/rudd-confirmed-nsa-cyber-command-chief
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No
https://www.reddit.com/r/netsec/comments/1rpqlh2/your_duolingo_is_still_talking_to_bytedance_how/
Jailbreaking the F-35 Fighter Jet
https://www.schneier.com/blog/archives/2026/03/jailbreaking-the-f-35-fighter-jet.html
BeatBanker: A dual‑mode Android Trojan
https://securelist.com/beatbanker-miner-and-banker/119121/
Russian military hackers revive advanced malware to spy on Ukraine, researchers say
https://therecord.media/russia-apt-28-revives-malware-to-spy-on-ukraine
UK plans to shift fraud fight onto telecoms, tech companies
https://therecord.media/uk-plans-to-shift-fraud-fight-to-telecoms-tech
Cybercriminals impersonating city officials to steal permit payments, FBI says
https://therecord.media/cybercriminals-impersonate-city-officials-permit-payments
CISA shortens patch deadline for critical Ivanti, SolarWinds bugs
https://therecord.media/cisa-shortens-patch-deadline-ivanti-solarwinds
Finnish intelligence warns of persistent cyber espionage from Russia, China
https://therecord.media/finnish-intel-warns-espionage-china-russia
Rudd confirmed to head NSA, Cyber Command after near year-long vacancy
https://therecord.media/rudd-confirmed-nsa-cyber-command-chief
Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After…
Posted by AdTemporary2475 - 165 votes and 12 comments