Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1rwzs83/the_most_organized_threat_actors_use_your_itsm/

The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
https://securelist.com/horabot-campaign/119033/

IdentityGuard: Context-Aware Restriction and Provenance for Personalized Synthesis
https://arxiv.org/abs/2603.15679

Quantum Key Distribution Secured Federated Learning for Channel Estimation and Radar Spectrum Sensing in 6G Networks
https://arxiv.org/abs/2603.15649

State-Dependent Safety Failures in Multi-Turn Language Model Interaction
https://arxiv.org/abs/2603.15684

BadLLM-TG: A Backdoor Defender powered by LLM Trigger Generator
https://arxiv.org/abs/2603.15692

Remarks on the Relevance of Privacy Expectations for Default Opt-out Settings
https://www.schneier.com/blog/archives/2026/03/metas-ai-glasses-and-privacy.html

Observability for AI Systems: Strengthening visibility for proactive risk detection
https://www.microsoft.com/en-us/security/blog/2026/03/18/observability-ai-systems-strengthening-visibility-proactive-risk-detection/

Bank software vendor Marquis says more than 670,000 impacted by August breach
https://therecord.media/marquis-bank-vendor-data-breach

From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA
https://www.trendmicro.com/en_us/research/26/c/from-misconfigured-spring-boot-actuator-to-sharepoint-exfiltrati.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency
https://therecord.media/russia-hackers-ukraine-zimbra-breach

When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
https://www.microsoft.com/en-us/security/blog/2026/03/19/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures/

Interlock ransomware gang exploited Cisco firewall zero-day weeks before disclosure: Amazon
https://therecord.media/cisco-ransomware-interlock-firewalls

Hacking a Robot Vacuum
https://www.schneier.com/blog/archives/2026/03/hacking-a-robot-vacuum.html

Adversarial attacks against Modern Vision-Language Models
https://arxiv.org/abs/2603.16938

DeepStage: Learning Autonomous Defense Policies Against Multi-Stage APT Campaigns
https://arxiv.org/abs/2603.17100

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Evaluating AI and ML in Network Security: A Comprehensive Literature Review
https://www.reddit.com/r/netsec/comments/1rzji68/evaluating_ai_and_ml_in_network_security_a/

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets Attackers
https://www.reddit.com/r/netsec/comments/1rziu2w/trivy_under_attack_again_widespread_github/

ONNX Hub silent=True suppresses all trust verification, enabling supply chain attacks on ML model loading (CVE-2026-28500, CVSS 9.1, no patch available)
https://www.reddit.com/r/netsec/comments/1s02jrq/onnx_hub_silenttrue_suppresses_all_trust/

LLVM Adventures: Fuzzing Apache Modules
https://www.reddit.com/r/netsec/comments/1s03z8j/llvm_adventures_fuzzing_apache_modules/

Agent skill marketplace supply chain attack: 121 skills across 7 repos vulnerable to GitHub username hijacking, 5 scanners disagree by 10x on malicious skill rates (arXiv:2603.16572)
https://www.reddit.com/r/netsec/comments/1s0dmuv/agent_skill_marketplace_supply_chain_attack_121/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Agent skill marketplace supply chain attack: 121 skills across 7 repos vulnerable to GitHub username hijacking, 5 scanners disagree by 10x on malicious skill rates (arXiv:2603.16572)
https://www.reddit.com/r/netsec/comments/1s0dmuv/agent_skill_marketplace_supply_chain_attack_121/

CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran
https://www.reddit.com/r/netsec/comments/1s0lvk9/canisterworm_gets_teeth_teampcps_kubernetes_wiper/

Observations on AI generated Remote DuckDB via HTTP with mTLS
http://diablohorn.com/2026/03/22/observations-on-ai-generated-remote-duckdb-via-http-with-mtls/

No Zero-Day Needed: Russian Phishers Swipe Signal & WhatsApp Accounts with Plain Old Lies
https://www.reddit.com/r/netsec/comments/1s0ouoe/no_zeroday_needed_russian_phishers_swipe_signal/

A YC-Backed Startup Left Production AWS Keys Public for 5 Months.
https://www.reddit.com/r/netsec/comments/1s1ab3n/a_ycbacked_startup_left_production_aws_keys/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

A YC-Backed Startup Left Production AWS Keys Public for 5 Months.
https://www.reddit.com/r/netsec/comments/1s1ab3n/a_ycbacked_startup_left_production_aws_keys/

US soldier sentenced for helping North Korean IT workers
https://therecord.media/us-soldier-sentencer-for-helping-nk-it-workers

Microsoft Xbox One Hacked
https://www.schneier.com/blog/archives/2026/03/microsoft-xbox-hacked.html

The Verifier Tax: Horizon Dependent Safety Success Tradeoffs in Tool Using LLM Agents
https://arxiv.org/abs/2603.19328

Benchmarking Post-Quantum Cryptography on Resource-Constrained IoT Devices: ML-KEM and ML-DSA on ARM Cortex-M0+
https://arxiv.org/abs/2603.19340

A Novel Solution for Zero-Day Attack Detection in IDS using Self-Attention and Jensen-Shannon Divergence in WGAN-GP
https://arxiv.org/abs/2603.19350

The Broken Physics of Remediation
https://blog.qualys.com/vulnerabilities-threat-research/2026/03/23/the-broken-physics-of-remediation

California-based semiconductor testing company reports ransomware attack to SEC
https://therecord.media/ransomware-trio-tech-semiconductor-sec

Education company Kaplan reports data breach impacting more than 230,000
https://therecord.media/kaplan-data-breach-hack-notification

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Russian hacker who helped Yanluowang ransomware gang gets nearly 7-year prison sentence
https://therecord.media/hacker-russian-ransomware-sentenced-doj

Alleged OVHcloud data of 1.6M customers and 5.9M websites posted on popular forum for sale. CEO Comments
https://www.reddit.com/r/netsec/comments/1s2awo7/alleged_ovhcloud_data_of_16m_customers_and_59m/

Forensic Readiness Is Becoming a Strategic Security Discipline
https://www.reddit.com/r/netsec/comments/1s2alc9/forensic_readiness_is_becoming_a_strategic/

Anime streaming giant Crunchyroll says hacker stole data related to customer service tickets
https://therecord.media/crunchyroll-hacker-anime-data-theft

Dutch Finance Ministry probing cyber breach affecting internal systems
https://therecord.media/netherlands-finance-ministry-cyberattack-breach

Iran-linked ransomware gang targeted US healthcare org amid military conflict
https://therecord.media/iran-linked-ransomware-gang-targeted-us-healthcare-org

We rewrote SoftHSMv2 (the default PKCS#11 software HSM) in Rust — 617+ tests, PQC support, memory-safe key handling
https://www.reddit.com/r/netsec/comments/1s2f3le/we_rewrote_softhsmv2_the_default_pkcs11_software/

With the rise of SaaS and cloud applications, the browser has become the new workplace. That's where net-security comes in.
https://www.reddit.com/r/netsec/comments/1s2cryp/with_the_rise_of_saas_and_cloud_applications_the/

We scanned 900 MCP configs on GitHub. 75% had security problems.
https://www.reddit.com/r/netsec/comments/1s2j0zl/we_scanned_900_mcp_configs_on_github_75_had/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

UK cyber chief urges ‘full court press’ to counter rising cyber threats
https://therecord.media/uk-cyber-chief-urges-full-court-press-to-counter-risks

Russian botnet operator linked to major ransomware attacks sentenced in US
https://therecord.media/russian-botnet-operator-sentenced-ransomware

Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system
https://therecord.media/navia-breach-exposed-hackerone-employee-pii-due-to-a-bola-style-access-in-third-party-system

Puerto Rico government agency cancels driver’s license appointments after cyberattack
https://therecord.media/puerto-rico-gov-agency-cancels-driver-license-appointments-cyber-incident

Ransomware attack disrupts operation at major Spanish fishing port
https://therecord.media/port-of-vigo-ransomware

Identity security is the new pressure point for modern cyberattacks
https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/

Supply chain attack hits widely-used AI package, risks impacting thousands of companies
https://therecord.media/supply-chain-attack-hits-widely-used-ai-package

CISA's acting chief warns shutdown is increasing cyber risks, causing resignations
https://therecord.media/cisa-acting-chief-warns-shutdown-increasing-risks-leading-to-retention-issues

Weaponizing Windows Toast Notifications for Social Engineering
https://www.reddit.com/r/netsec/comments/1s3edze/weaponizing_windows_toast_notifications_for/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

China-linked Red Menshen using BPFdoor kernel backdoor in telecom networks
https://www.reddit.com/r/netsec/comments/1s4uxxq/chinalinked_red_menshen_using_bpfdoor_kernel/

Abusing Modern Browser Features for Phishing
https://www.reddit.com/r/netsec/comments/1s4zk4v/abusing_modern_browser_features_for_phishing/

DVRTC: intentionally vulnerable VoIP/WebRTC lab with SIP enumeration, RTP bleed, TURN abuse, and credential cracking exercises
https://www.reddit.com/r/netsec/comments/1s506og/dvrtc_intentionally_vulnerable_voipwebrtc_lab/

Testing AprielGuard Against 1,500 Adversarial Attacks
https://www.reddit.com/r/netsec/comments/1s51ac8/testing_aprielguard_against_1500_adversarial/

TeamPCP strikes again - telnyx popular PyPI library compromised
https://www.reddit.com/r/netsec/comments/1s52kq7/teampcp_strikes_again_telnyx_popular_pypi_library/

Latvia accuses Russia of disinformation campaign targeting Baltic states
https://therecord.media/latvia-accuses-russia-of-disinformation-campaign-ukraine-war

FBI confirms theft of director’s personal emails by Iran-linked hacking group
https://therecord.media/fbi-confirms-theft-of-directors-personal-emails-iran-group

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
https://www.reddit.com/r/netsec/comments/1s6weca/breakdown_how_teampcp_hid_malware_inside_wav/

Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1s75kb9/please_we_beg_just_one_weekend_free_of_appliances/

LangDrained: Path traversal, SQL injection, and Deserialization of untrusted data in LangChain
https://www.reddit.com/r/netsec/comments/1s7jexg/langdrained_path_traversal_sql_injection_and/

The Team PCP Snowball Effect: A Quantitative Analysis
https://www.reddit.com/r/netsec/comments/1s7ko65/the_team_pcp_snowball_effect_a_quantitative/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Possible US Government iPhone Hacking Tool Leaked
https://www.schneier.com/blog/archives/2026/04/possible-us-government-iphone-hacking-tool-leaked.html

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1saebwi/youre_not_supposed_to_sharefile_with_everyone/

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1saebwi/youre_not_supposed_to_sharefile_with_everyone/

Cybercrime as a Service: A Scoping Review
https://arxiv.org/abs/2604.00063

When Labels Are Scarce: A Systematic Mapping of Label-Efficient Code Vulnerability Detection
https://arxiv.org/abs/2604.00079

Efficient Software Vulnerability Detection Using Transformer-based Models
https://arxiv.org/abs/2604.00112

Beyond Latency: A System-Level Characterization of MPC and FHE for PPML
https://arxiv.org/abs/2604.00169

NFC based inventory control system for secure and efficient communication
https://arxiv.org/abs/2604.00181

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Company that Secretly Records and Publishes Zoom Meetings
https://www.schneier.com/blog/archives/2026/04/company-that-secretly-records-and-publishes-zoom-meetings.html

A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
https://www.reddit.com/r/netsec/comments/1sb7man/a_threat_actor_who_goes_by_the_name_mr_raccoon/

New RCE in Control Web Panel (CVE-2025-70951)
https://www.reddit.com/r/netsec/comments/1sb7pr4/new_rce_in_control_web_panel_cve202570951/

Ukraine warns Russian hackers are revisiting past breaches to prepare new attacks
https://therecord.media/ukraine-warns-russian-hackers-revisiting-old-attacks

Massachusetts emergency communications system impacted by cyberattack
https://therecord.media/massachusetts-emergency-alert-cyberattack

FCC proposes $4.5 million fine for voice service provider hosting ‘suspicious’ foreign call traffic
https://therecord.media/fcc-proposes-5-million-fine-robocall

CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers
https://therecord.media/trueconf-cyberattack-cisa-hackers

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Proof-of-Personhood Without Biometrics: The IRLid Protocol
https://www.reddit.com/r/netsec/comments/1sc3fju/proofofpersonhood_without_biometrics_the_irlid/

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
https://www.reddit.com/r/netsec/comments/1sc5xhj/researchers_uncover_mining_operation_using_iso/

Apple's Spotlight Search Results Come With Engagement Metrics. No One Knew.
https://www.reddit.com/r/netsec/comments/1scak6p/apples_spotlight_search_results_come_with/

BrowserGate: LinkedIn/Microsoft allegedly scans 6,000+ browser extensions & links them to real identities, all without user consent
https://www.reddit.com/r/netsec/comments/1sccnjb/browsergate_linkedinmicrosoft_allegedly_scans/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html

GDDRHammer and GeForge: GDDR6 GPU Rowhammer to root shell (IEEE S&P 2026, exploit code available)
https://www.reddit.com/r/netsec/comments/1sd7hzh/gddrhammer_and_geforge_gddr6_gpu_rowhammer_to/

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/

The Attack With No Attacker Domain: Microsoft Entra B2B Guest Invitation Phishing
https://www.reddit.com/r/netsec/comments/1sdlisb/the_attack_with_no_attacker_domain_microsoft/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Detecting CI/CD Supply Chain Attacks with Canary Credentials
https://www.reddit.com/r/netsec/comments/1sep4hy/detecting_cicd_supply_chain_attacks_with_canary/

Hong Kong Police Can Force You to Reveal Your Encryption Keys
https://www.schneier.com/blog/archives/2026/04/hong-kong-police-can-force-you-to-reveal-your-encryption-keys.html

Cyberattack hits Northern Ireland’s centralized school network, disrupting access for thousands
https://therecord.media/cyberattack-hits-northern-ireland-schools

PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses
https://portswigger.net/blog/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses

Cyberattack on telecom giant Rostelecom disrupts internet services across Russia
https://therecord.media/rostelecom-cyberattack-disrupts-russian-internet-access

Massachusetts hospital turning ambulances away after cyberattack
https://therecord.media/massachusetts-hospital-turning-ambulances-away-cyberattack

FBI, Pentagon warn of Iran hacking groups targeting operational technology
https://therecord.media/fbi-pentagon-warn-iran-hacking-groups-target-ot

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman