Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Breakdown: How TeamPCP hid malware inside WAV files using audio steganography
https://www.reddit.com/r/netsec/comments/1s6weca/breakdown_how_teampcp_hid_malware_inside_wav/

Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1s75kb9/please_we_beg_just_one_weekend_free_of_appliances/

LangDrained: Path traversal, SQL injection, and Deserialization of untrusted data in LangChain
https://www.reddit.com/r/netsec/comments/1s7jexg/langdrained_path_traversal_sql_injection_and/

The Team PCP Snowball Effect: A Quantitative Analysis
https://www.reddit.com/r/netsec/comments/1s7ko65/the_team_pcp_snowball_effect_a_quantitative/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Possible US Government iPhone Hacking Tool Leaked
https://www.schneier.com/blog/archives/2026/04/possible-us-government-iphone-hacking-tool-leaked.html

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1saebwi/youre_not_supposed_to_sharefile_with_everyone/

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1saebwi/youre_not_supposed_to_sharefile_with_everyone/

Cybercrime as a Service: A Scoping Review
https://arxiv.org/abs/2604.00063

When Labels Are Scarce: A Systematic Mapping of Label-Efficient Code Vulnerability Detection
https://arxiv.org/abs/2604.00079

Efficient Software Vulnerability Detection Using Transformer-based Models
https://arxiv.org/abs/2604.00112

Beyond Latency: A System-Level Characterization of MPC and FHE for PPML
https://arxiv.org/abs/2604.00169

NFC based inventory control system for secure and efficient communication
https://arxiv.org/abs/2604.00181

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Company that Secretly Records and Publishes Zoom Meetings
https://www.schneier.com/blog/archives/2026/04/company-that-secretly-records-and-publishes-zoom-meetings.html

A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
https://www.reddit.com/r/netsec/comments/1sb7man/a_threat_actor_who_goes_by_the_name_mr_raccoon/

New RCE in Control Web Panel (CVE-2025-70951)
https://www.reddit.com/r/netsec/comments/1sb7pr4/new_rce_in_control_web_panel_cve202570951/

Ukraine warns Russian hackers are revisiting past breaches to prepare new attacks
https://therecord.media/ukraine-warns-russian-hackers-revisiting-old-attacks

Massachusetts emergency communications system impacted by cyberattack
https://therecord.media/massachusetts-emergency-alert-cyberattack

FCC proposes $4.5 million fine for voice service provider hosting ‘suspicious’ foreign call traffic
https://therecord.media/fcc-proposes-5-million-fine-robocall

CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers
https://therecord.media/trueconf-cyberattack-cisa-hackers

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Proof-of-Personhood Without Biometrics: The IRLid Protocol
https://www.reddit.com/r/netsec/comments/1sc3fju/proofofpersonhood_without_biometrics_the_irlid/

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
https://www.reddit.com/r/netsec/comments/1sc5xhj/researchers_uncover_mining_operation_using_iso/

Apple's Spotlight Search Results Come With Engagement Metrics. No One Knew.
https://www.reddit.com/r/netsec/comments/1scak6p/apples_spotlight_search_results_come_with/

BrowserGate: LinkedIn/Microsoft allegedly scans 6,000+ browser extensions & links them to real identities, all without user consent
https://www.reddit.com/r/netsec/comments/1sccnjb/browsergate_linkedinmicrosoft_allegedly_scans/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html

Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html

GDDRHammer and GeForge: GDDR6 GPU Rowhammer to root shell (IEEE S&P 2026, exploit code available)
https://www.reddit.com/r/netsec/comments/1sd7hzh/gddrhammer_and_geforge_gddr6_gpu_rowhammer_to/

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/

The Attack With No Attacker Domain: Microsoft Entra B2B Guest Invitation Phishing
https://www.reddit.com/r/netsec/comments/1sdlisb/the_attack_with_no_attacker_domain_microsoft/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Detecting CI/CD Supply Chain Attacks with Canary Credentials
https://www.reddit.com/r/netsec/comments/1sep4hy/detecting_cicd_supply_chain_attacks_with_canary/

Hong Kong Police Can Force You to Reveal Your Encryption Keys
https://www.schneier.com/blog/archives/2026/04/hong-kong-police-can-force-you-to-reveal-your-encryption-keys.html

Cyberattack hits Northern Ireland’s centralized school network, disrupting access for thousands
https://therecord.media/cyberattack-hits-northern-ireland-schools

PortSwigger partners with Meta Bug Bounty to empower bug hunters with training and Pro licenses
https://portswigger.net/blog/portswigger-partners-with-meta-bug-bounty-to-empower-bug-hunters-with-training-and-pro-licenses

Cyberattack on telecom giant Rostelecom disrupts internet services across Russia
https://therecord.media/rostelecom-cyberattack-disrupts-russian-internet-access

Massachusetts hospital turning ambulances away after cyberattack
https://therecord.media/massachusetts-hospital-turning-ambulances-away-cyberattack

FBI, Pentagon warn of Iran hacking groups targeting operational technology
https://therecord.media/fbi-pentagon-warn-iran-hacking-groups-target-ot

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The long road to your crypto: ClipBanker and its marathon infection chain
https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/

Cybercriminals target accountants to drain Russian firms’ bank accounts
https://therecord.media/cybercriminals-hack-russian-accountants-to-steal-millions

Applying SOAR-style automation to physical perimeter security
https://www.reddit.com/r/netsec/comments/1sglba8/applying_soarstyle_automation_to_physical/

On Microsoft’s Lousy Cloud Security
https://www.schneier.com/blog/archives/2026/04/on-microsofts-lousy-cloud-security.html

Negotiating Privacy with Smart Voice Assistants: Risk-Benefit and Control-Acceptance Tensions
https://arxiv.org/abs/2604.06235

Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk
https://www.microsoft.com/en-us/security/blog/2026/04/09/intent-redirection-vulnerability-third-party-sdk-android/

Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees
https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/

Treasury Department announces crypto industry cyber threat sharing initiative
https://therecord.media/treasury-department-announces-crypto-info-sharing

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
https://www.reddit.com/r/netsec/comments/1siafhk/reverse_engineering_a_multi_stage_file_format/

Open-source cross-modal and multimodal prompt injection test suite. 38,000+ attack payloads across text, image, document, and audio modalities. Research-backed by OWASP LLM Top 10, CrossInject (ACM MM 2025), FigStep (AAAI 2025), DolphinAttack, and CSA 2026.
https://www.reddit.com/r/netsec/comments/1sii9bw/opensource_crossmodal_and_multimodal_prompt/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Estimating Remaining Stack Space in a C Program
https://www.reddit.com/r/lowlevel/comments/1sjg88m/estimating_remaining_stack_space_in_a_c_program/

Reverse engineered SilentSDK - RAT and C2 infrastructure found on beamers, sold on Amazon/AliExpress/eBay
https://www.reddit.com/r/netsec/comments/1sjioe3/reverse_engineered_silentsdk_rat_and_c2/

We combined DRAM timing attacks, electrical grid frequency detection, and gyroscope fusion into a single bot detection stack and I think we need to talk about it
https://www.reddit.com/r/netsec/comments/1sjkuu2/we_combined_dram_timing_attacks_electrical_grid/

Paying Google to Hack macOS Users?
https://www.reddit.com/r/netsec/comments/1sjecf4/paying_google_to_hack_macos_users/

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
https://www.reddit.com/r/netsec/comments/1sk1x6r/agentic_browser_security_indirect_prompt/

CVE-2025-8061: From User-land to Ring 0
https://www.reddit.com/r/netsec/comments/1sk4j5o/cve20258061_from_userland_to_ring_0/

JanelaRAT: a financial threat targeting users in Latin America
https://securelist.com/janelarat-financial-threat-in-latin-america/119332/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8061: From User-land to Ring 0
https://www.reddit.com/r/netsec/comments/1sk4j5o/cve20258061_from_userland_to_ring_0/

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
https://www.reddit.com/r/netsec/comments/1sk1x6r/agentic_browser_security_indirect_prompt/

AI Chatbots and Trust
https://www.schneier.com/blog/archives/2026/04/ai-chatbots-and-trust.html

One Uppercase Letter Breaks Every Nuxt App
https://www.reddit.com/r/netsec/comments/1sk6xc3/one_uppercase_letter_breaks_every_nuxt_app/

Hack at Dutch gym chain Basic-Fit exposes customer data in several EU countries
https://therecord.media/dutch-gym-chain-basic-fit-hit-by-hackers

The persistence of analog RF links in drone video feeds
https://www.reddit.com/r/netsec/comments/1sk83f7/the_persistence_of_analog_rf_links_in_drone_video/

CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC)
https://www.reddit.com/r/netsec/comments/1skazzv/cve202622666_dolibarr_2300_dol_eval_whitelist/

YARA-X now runs in the browser - official Playground
https://www.reddit.com/r/netsec/comments/1sk96tq/yarax_now_runs_in_the_browser_official_playground/

Anatomy of an Autonomous AI Agent Risk: How Qualys ETM Connects the Dots on OpenClaw
https://blog.qualys.com/product-tech/2026/04/13/anatomy-autonomous-ai-agent-risk-qualys-etm-openclaw

FBI, Indonesia take down W3LL phishing tool
https://therecord.media/phishing-takedown-indonesia-fbi

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Report: Digital Exposure of European Telecoms
https://www.reddit.com/r/netsec/comments/1sl6thg/new_report_digital_exposure_of_european_telecoms/

Virginia enacts ban on precise geolocation data sales as momentum for similar prohibitions builds
https://therecord.media/virginia-enacts-ban-on-precise-geolocation-data

New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
https://therecord.media/new-janaware-ransomware-targeting-turkey

Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2026/04/14/microsoft-and-adobe-patch-tuesday-april-2026-security-update-review

ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying
https://arxiv.org/abs/2604.09747

Improving DNS Exfiltration Detection via Transformer Pretraining
https://arxiv.org/abs/2604.09849

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Two Admin-level API keys publicly exposed for years, both dismissed as "Out of scope" by official bug bounty programs. Case analysis + proposed NHI Exposure Severity Index
https://www.reddit.com/r/netsec/comments/1slz48l/two_adminlevel_api_keys_publicly_exposed_for/

Kerberoasting detection gaps in mixed-encryption environments and why 0x17 filtering alone isn't enough
https://www.reddit.com/r/netsec/comments/1sm0afg/kerberoasting_detection_gaps_in_mixedencryption/

Defense in Depth, Medieval Style
https://www.schneier.com/blog/archives/2026/04/defense-in-depth-medieval-style.html

Sweden says pro-Russian hackers attempted to breach thermal power plant
https://therecord.media/sweden-hackers-russia-power-plant

Educational company McGraw Hill says Salesforce misconfiguration led to data leak
https://therecord.media/mcgraw-hill-data-leak-tied-to-salesforce-misconfiguration

UK warns businesses to address cyber risks amid Anthropic AI panic
https://therecord.media/anthropic-mythos-uk-cyber-risk

Incident response for AI: Same fire, different fuel
https://www.microsoft.com/en-us/security/blog/2026/04/15/incident-response-for-ai-same-fire-different-fuel/

Teen arrested in Northern Ireland over cyberattack on school network
https://therecord.media/northern-ireland-cyberattack-arrest

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware
https://therecord.media/aging-fly-espionage-campaign-targets-ukraine-emergency-services

Cargo thieving hackers running sophisticated remote access campaigns, researchers find
https://therecord.media/cargo-thieving-hackers-running-sophisticated-campaigns

Human Trust of AI Agents
https://www.schneier.com/blog/archives/2026/04/human-trust-of-ai-agents.html

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise
https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/

New Jersey men given lengthy sentences for running North Korean laptop farms
https://therecord.media/new-jersey-men-sentenced-north-korean-laptop-farms

Building your cryptographic inventory: A customer strategy for cryptographic posture management
https://www.microsoft.com/en-us/security/blog/2026/04/16/building-your-cryptographic-inventory-a-customer-strategy-for-cryptographic-posture-management/

HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
https://www.reddit.com/r/netsec/comments/1snem8w/haproxy_http3_http1_desync_crossprotocol/

Open dataset: 100k+ multimodal prompt injection samples with per-category academic sourcing
https://www.reddit.com/r/netsec/comments/1sn2o3v/open_dataset_100k_multimodal_prompt_injection/

Taking Maestro in Stride
https://bishopfox.com/blog/taking-maestro-in-stride

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Anomaly Detection in IEC-61850 GOOSE Networks: Evaluating Unsupervised and Temporal Learning for Real-Time Intrusion Detection
https://arxiv.org/abs/2604.14233

Sovereign 2.0: Control-Plane Sovereignty for Cloud Systems Under Disruption
https://arxiv.org/abs/2604.14242

Challenges and Future Directions in Agentic Reverse Engineering Systems
https://arxiv.org/abs/2604.14317

Head Count: Privacy-Preserving Face-Based Crowd Monitoring
https://arxiv.org/abs/2604.14250

Understanding Student Experiences with TLS Client Authentication
https://arxiv.org/abs/2604.14330

From Black Box to Glass Box: Cross-Model ASR Disagreement to Prioto Review in Ambient AI Scribe Documentation
https://arxiv.org/abs/2604.14152

Compressed-Sensing-Guided, Inference-Aware Structured Reduction for Large Language Models
https://arxiv.org/abs/2604.14156

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman