Top Daily Cyber Security News
731 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

How a single typo led to RCE in Firefox
https://www.reddit.com/r/netsec/comments/1rbjdso/how_a_single_typo_led_to_rce_in_firefox/

Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
https://www.reddit.com/r/netsec/comments/1rbzbyv/malicious_chrome_extension_targeting_apple_app/

Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://www.reddit.com/r/netsec/comments/1rc6t3w/scary_datapoints_re_network_visibility_in_dragos/

I built a network security analyzer using information geometry (Riemannian manifolds) instead of traditional rule-based detection
https://www.reddit.com/r/netsec/comments/1rc91zq/i_built_a_network_security_analyzer_using/

Large-scale online deanonymization with LLMs
https://arxiv.org/abs/2602.16800

Variational approach to nonholonomic and inequality-constrained mechanics
https://arxiv.org/abs/2409.11063

23rd February – Threat Intelligence Report
https://research.checkpoint.com/2026/23rd-february-threat-intelligence-report/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

North Korean state hackers seen using Medusa ransomware in attacks on US, Middle East
https://therecord.media/north-korean-hackers-using-medusa-ransomware

Is AI Good for Democracy?
https://www.schneier.com/blog/archives/2026/02/is-ai-good-for-democracy.html

Ukraine pushes tighter Telegram regulation, citing Russian recruitment of locals
https://therecord.media/ukraine-telegram-regulation-russia-sabotage-recruitment

UAE claims it stopped ‘terrorist’ ransomware attack
https://therecord.media/uae-claims-it-stopped-terrorist-ransomware-attack

Scaling security operations with Microsoft Defender autonomous defense and expert-led services
https://www.microsoft.com/en-us/security/blog/2026/02/24/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/

Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
https://www.reddit.com/r/netsec/comments/1rdi8m9/goodbye_innerhtml_hello_sethtml_stronger_xss/

Crypto platform Step Finance shutting down after $40 million theft
https://therecord.media/step-finance-cryptocurrency-theft-shutdown

Reddit fined $20 million by UK for not effectively checking users’ ages
https://therecord.media/reddit-children-age-checks-uk-ico-fine

US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI
https://therecord.media/us-committed-to-fighting-southeast-asia-scam-compounds

Phishing operation with links to Russia, Armenia compromised Western cargo companies, researchers find
https://therecord.media/phishing-operation-russia-armenia-targeting-us-european-cargoDCInject: Persistent Backdoor Attacks via Frequency Manipulation in Personal Federated Learning

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Moscow man accused of posing as FSB officer to extort Conti ransomware gang
https://therecord.media/moscow-man-accused-of-extorting-conti-gang

Chinese prosecutors raise alarm about growth of domestic IP theft
https://therecord.media/china-domestic-ip-theft-crackdown

Medical device firm UFP says backup data systems deployed following cyberattack
https://therecord.media/ufp-technologies-medical-devices-sec-filing-cyberattack

PowerSchool, Chicago Public Schools to settle student data privacy lawsuit for $17 million
https://therecord.media/powerschool-cps-settle-proposed-class-action

Five Eyes allies warn hackers are actively exploiting Cisco SD-WAN flaws
https://therecord.media/five-eyes-warn-hackers-exploit-cisco-sd-wan

Discord puts global age verification policy on hold after backlash
https://therecord.media/discord-age-verification-policy-on-hold-after-backlash

Starkiller Phishing Kit: Why MFA Fails Against Real-Time Reverse Proxies — Technical Analysis + Rust PoC for TLS Fingerprinting
https://www.reddit.com/r/netsec/comments/1re5gds/starkiller_phishing_kit_why_mfa_fails_against/

TURN Server Security Best Practices - hardening checklist, IP range tables, and deployment patterns
https://www.reddit.com/r/netsec/comments/1re9az6/turn_server_security_best_practices_hardening/

Poisoning AI Training Data
https://www.schneier.com/blog/archives/2026/02/poisoning-ai-training-data.html

I rendered 1,418 Unicode confusable pairs across 230 system fonts. 82 are pixel-identical, and the font your site uses determines which ones.
https://www.reddit.com/r/netsec/comments/1rebvdc/i_rendered_1418_unicode_confusable_pairs_across/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyberattack briefly disrupts Russian internet regulator and defense ministry websites
https://therecord.media/cyberattack-briefly-takes-down-russian-government-websites

LLM-Assisted Deanonymization
https://www.schneier.com/blog/archives/2026/03/llm-assisted-deanonymization.html

German court convicts alleged mastermind behind global investment scam network
https://therecord.media/german-court-convicts-alleged-mastermind-scam-network

British organizations urged to be alert to threat of Iranian cyberattacks
https://therecord.media/iran-britain-cyber-threats-warning

Free browser-based steganography CTF generator create challenges with randomized encoding pipelines, auto-generated solutions, and progressive hints
https://www.reddit.com/r/netsec/comments/1rivnn2/free_browserbased_steganography_ctf_generator/

Google and Cloudflare testing Merkel Tree Certificates instead of normal signatures for TLS
https://www.reddit.com/r/netsec/comments/1riw5km/google_and_cloudflare_testing_merkel_tree/

Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
https://therecord.media/india-pakistan-cyber-campaign-apt

University of Hawaiʻi Cancer Center confirms data leak following ransomware attack
https://therecord.media/university-of-hawaii-ransomware-data-breach

OAuth redirection abuse enables phishing and malware delivery
https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/

2nd March – Threat Intelligence Report
https://research.checkpoint.com/2026/2nd-march-threat-intelligence-report/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Google urges Supreme Court to strike down geofence warrants as unconstitutional
https://therecord.media/google-urges-supreme-court-strike-down-geolocation-warrants

Iranian drone strikes hit Amazon data centers in Gulf, disrupting cloud services
https://therecord.media/iran-drone-strikes-hit-amazon-data-centers-gulf

Florida woman gets 2 year sentence for trafficking Microsoft software labels
https://therecord.media/florida-woman-sentenced-reselling-microsoft-labels

Built a free live CVE intelligence dashboard — looking for feedback
https://www.reddit.com/r/netsec/comments/1rjo4do/built_a_free_live_cve_intelligence_dashboard/

Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1rjqfwy/sometimes_you_can_just_feel_the_security_in_the/

Silver Dragon Targets Organizations in Southeast Asia and Europe
https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/

Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow
https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

A single operator with basic skills used an open-source AI platform to breach 600+ FortiGate devices across 55 countries. No zero-days. Just weak passwords and an AI copilot. Full breakdown of CyberStrikeAI, the developer's MSS ties, and all 21 server IOCs.
https://www.reddit.com/r/netsec/comments/1rkl6zz/a_single_operator_with_basic_skills_used_an/

Using Zeek with AWS Traffic Mirroring and Kafka
https://www.reddit.com/r/netsec/comments/1rkha18/using_zeek_with_aws_traffic_mirroring_and_kafka/

Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/

Mobile malware evolution in 2025
https://securelist.com/mobile-threat-report-2025/119076/

Russian hackers deploy new malware in phishing campaign targeting Ukraine
https://therecord.media/russian-ukraine-hackers-malware

Sprawling FBI, European operation takes down Leakbase cybercriminal forum
https://therecord.media/leakbase-cybercrime-fbi-europe-takedown

Manipulating AI Summarization Features
https://www.schneier.com/blog/archives/2026/03/manipulating-ai-summarization-features.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Exploits and vulnerabilities in Q4 2025
https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/

Benchmark of Benchmarks: Unpacking Influence and Code Repository Quality in LLM Safety Benchmarks
https://arxiv.org/abs/2603.04459

How Effective Are Publicly Accessible Deepfake Detection Tools? A Comparative Evaluation of Open-Source and Free-to-Use Platforms
https://arxiv.org/abs/2603.04456

Beyond Input Guardrails: Reconstructing Cross-Agent Semantic Flows for Execution-Aware Attack Detection
https://arxiv.org/abs/2603.04469

Impact of 5G SA Logical Vulnerabilities on UAV Communications: Threat Models and Testbed Evaluation
https://arxiv.org/abs/2603.04662

When Denoising Becomes Unsigning: Theoretical and Empirical Analysis of Watermark Fragility Under Diffusion-Based Image Editing
https://arxiv.org/abs/2603.04696

Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
https://arxiv.org/abs/2602.15654

Claude Used to Hack Mexican Government
https://www.schneier.com/blog/archives/2026/03/claude-used-to-hack-mexican-government.html

Model Context Protocol (MCP) Authentication and Authorization
https://www.reddit.com/r/netsec/comments/1rmcz6i/model_context_protocol_mcp_authentication_and/

Hardening Firefox with Anthropic’s Red Team
https://www.reddit.com/r/netsec/comments/1rmffdp/hardening_firefox_with_anthropics_red_team/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

From Chrome Extension Supply-Chain Compromise to Host Malware: Technical Breakdown of the ShotBird Campaign
https://www.reddit.com/r/netsec/comments/1rob5no/from_chrome_extension_supplychain_compromise_to/

Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign
https://www.reddit.com/r/netsec/comments/1robwok/fake_claude_code_install_guides_spread_amatera/

How AI Assistants are Moving the Security Goalposts
https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/

AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
https://www.reddit.com/r/netsec/comments/1rojhfl/airsnitch_demystifying_and_breaking_client/

DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/

MCP Security Checklist - 40 controls for securing AI agent tool infrastructure
https://www.reddit.com/r/netsec/comments/1roru4f/mcp_security_checklist_40_controls_for_securing/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Your Duolingo Is Still Talking to ByteDance: How Pangle Fingerprints You Across Apps After You Said No
https://www.reddit.com/r/netsec/comments/1rpqlh2/your_duolingo_is_still_talking_to_bytedance_how/

Jailbreaking the F-35 Fighter Jet
https://www.schneier.com/blog/archives/2026/03/jailbreaking-the-f-35-fighter-jet.html

BeatBanker: A dual‑mode Android Trojan
https://securelist.com/beatbanker-miner-and-banker/119121/

Russian military hackers revive advanced malware to spy on Ukraine, researchers say
https://therecord.media/russia-apt-28-revives-malware-to-spy-on-ukraine

UK plans to shift fraud fight onto telecoms, tech companies
https://therecord.media/uk-plans-to-shift-fraud-fight-to-telecoms-tech

Cybercriminals impersonating city officials to steal permit payments, FBI says
https://therecord.media/cybercriminals-impersonate-city-officials-permit-payments

CISA shortens patch deadline for critical Ivanti, SolarWinds bugs
https://therecord.media/cisa-shortens-patch-deadline-ivanti-solarwinds

Finnish intelligence warns of persistent cyber espionage from Russia, China
https://therecord.media/finnish-intel-warns-espionage-china-russia

Rudd confirmed to head NSA, Cyber Command after near year-long vacancy
https://therecord.media/rudd-confirmed-nsa-cyber-command-chief

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Meta says it culled millions of scam ads amid accusations that it profits from them
https://therecord.media/meta-scam-advertising-crackdown

Cyberattack on ambulance provider affects 235,000
https://therecord.media/235000-affected-cyberattack-ambulance-provider

Contagious Interview: Malware delivered through fake developer job interviews
https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/

Iran-linked hackers claim cyberattack on Albania’s parliament email systems
https://therecord.media/iran-linked-hackers-claim-cyberattack-albania-parliament

Medical device giant Stryker confirms cyberattack as employees say devices were wiped
https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

Forensic analysis of LummaC2 infection unmasks DPRK operative behind Polyfill.io supply chain attack and Gate.us infiltration
https://www.reddit.com/r/netsec/comments/1rredk3/forensic_analysis_of_lummac2_infection_unmasks/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman