Top Daily Cyber Security News
729 subscribers
813 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
https://www.reddit.com/r/netsec/comments/1siafhk/reverse_engineering_a_multi_stage_file_format/

Open-source cross-modal and multimodal prompt injection test suite. 38,000+ attack payloads across text, image, document, and audio modalities. Research-backed by OWASP LLM Top 10, CrossInject (ACM MM 2025), FigStep (AAAI 2025), DolphinAttack, and CSA 2026.
https://www.reddit.com/r/netsec/comments/1sii9bw/opensource_crossmodal_and_multimodal_prompt/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Estimating Remaining Stack Space in a C Program
https://www.reddit.com/r/lowlevel/comments/1sjg88m/estimating_remaining_stack_space_in_a_c_program/

Reverse engineered SilentSDK - RAT and C2 infrastructure found on beamers, sold on Amazon/AliExpress/eBay
https://www.reddit.com/r/netsec/comments/1sjioe3/reverse_engineered_silentsdk_rat_and_c2/

We combined DRAM timing attacks, electrical grid frequency detection, and gyroscope fusion into a single bot detection stack and I think we need to talk about it
https://www.reddit.com/r/netsec/comments/1sjkuu2/we_combined_dram_timing_attacks_electrical_grid/

Paying Google to Hack macOS Users?
https://www.reddit.com/r/netsec/comments/1sjecf4/paying_google_to_hack_macos_users/

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
https://www.reddit.com/r/netsec/comments/1sk1x6r/agentic_browser_security_indirect_prompt/

CVE-2025-8061: From User-land to Ring 0
https://www.reddit.com/r/netsec/comments/1sk4j5o/cve20258061_from_userland_to_ring_0/

JanelaRAT: a financial threat targeting users in Latin America
https://securelist.com/janelarat-financial-threat-in-latin-america/119332/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8061: From User-land to Ring 0
https://www.reddit.com/r/netsec/comments/1sk4j5o/cve20258061_from_userland_to_ring_0/

Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet
https://www.reddit.com/r/netsec/comments/1sk1x6r/agentic_browser_security_indirect_prompt/

AI Chatbots and Trust
https://www.schneier.com/blog/archives/2026/04/ai-chatbots-and-trust.html

One Uppercase Letter Breaks Every Nuxt App
https://www.reddit.com/r/netsec/comments/1sk6xc3/one_uppercase_letter_breaks_every_nuxt_app/

Hack at Dutch gym chain Basic-Fit exposes customer data in several EU countries
https://therecord.media/dutch-gym-chain-basic-fit-hit-by-hackers

The persistence of analog RF links in drone video feeds
https://www.reddit.com/r/netsec/comments/1sk83f7/the_persistence_of_analog_rf_links_in_drone_video/

CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC)
https://www.reddit.com/r/netsec/comments/1skazzv/cve202622666_dolibarr_2300_dol_eval_whitelist/

YARA-X now runs in the browser - official Playground
https://www.reddit.com/r/netsec/comments/1sk96tq/yarax_now_runs_in_the_browser_official_playground/

Anatomy of an Autonomous AI Agent Risk: How Qualys ETM Connects the Dots on OpenClaw
https://blog.qualys.com/product-tech/2026/04/13/anatomy-autonomous-ai-agent-risk-qualys-etm-openclaw

FBI, Indonesia take down W3LL phishing tool
https://therecord.media/phishing-takedown-indonesia-fbi

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

New Report: Digital Exposure of European Telecoms
https://www.reddit.com/r/netsec/comments/1sl6thg/new_report_digital_exposure_of_european_telecoms/

Virginia enacts ban on precise geolocation data sales as momentum for similar prohibitions builds
https://therecord.media/virginia-enacts-ban-on-precise-geolocation-data

New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments
https://therecord.media/new-janaware-ransomware-targeting-turkey

Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2026/04/14/microsoft-and-adobe-patch-tuesday-april-2026-security-update-review

ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying
https://arxiv.org/abs/2604.09747

Improving DNS Exfiltration Detection via Transformer Pretraining
https://arxiv.org/abs/2604.09849

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Two Admin-level API keys publicly exposed for years, both dismissed as "Out of scope" by official bug bounty programs. Case analysis + proposed NHI Exposure Severity Index
https://www.reddit.com/r/netsec/comments/1slz48l/two_adminlevel_api_keys_publicly_exposed_for/

Kerberoasting detection gaps in mixed-encryption environments and why 0x17 filtering alone isn't enough
https://www.reddit.com/r/netsec/comments/1sm0afg/kerberoasting_detection_gaps_in_mixedencryption/

Defense in Depth, Medieval Style
https://www.schneier.com/blog/archives/2026/04/defense-in-depth-medieval-style.html

Sweden says pro-Russian hackers attempted to breach thermal power plant
https://therecord.media/sweden-hackers-russia-power-plant

Educational company McGraw Hill says Salesforce misconfiguration led to data leak
https://therecord.media/mcgraw-hill-data-leak-tied-to-salesforce-misconfiguration

UK warns businesses to address cyber risks amid Anthropic AI panic
https://therecord.media/anthropic-mythos-uk-cyber-risk

Incident response for AI: Same fire, different fuel
https://www.microsoft.com/en-us/security/blog/2026/04/15/incident-response-for-ai-same-fire-different-fuel/

Teen arrested in Northern Ireland over cyberattack on school network
https://therecord.media/northern-ireland-cyberattack-arrest

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware
https://therecord.media/aging-fly-espionage-campaign-targets-ukraine-emergency-services

Cargo thieving hackers running sophisticated remote access campaigns, researchers find
https://therecord.media/cargo-thieving-hackers-running-sophisticated-campaigns

Human Trust of AI Agents
https://www.schneier.com/blog/archives/2026/04/human-trust-of-ai-agents.html

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise
https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/

New Jersey men given lengthy sentences for running North Korean laptop farms
https://therecord.media/new-jersey-men-sentenced-north-korean-laptop-farms

Building your cryptographic inventory: A customer strategy for cryptographic posture management
https://www.microsoft.com/en-us/security/blog/2026/04/16/building-your-cryptographic-inventory-a-customer-strategy-for-cryptographic-posture-management/

HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
https://www.reddit.com/r/netsec/comments/1snem8w/haproxy_http3_http1_desync_crossprotocol/

Open dataset: 100k+ multimodal prompt injection samples with per-category academic sourcing
https://www.reddit.com/r/netsec/comments/1sn2o3v/open_dataset_100k_multimodal_prompt_injection/

Taking Maestro in Stride
https://bishopfox.com/blog/taking-maestro-in-stride

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Anomaly Detection in IEC-61850 GOOSE Networks: Evaluating Unsupervised and Temporal Learning for Real-Time Intrusion Detection
https://arxiv.org/abs/2604.14233

Sovereign 2.0: Control-Plane Sovereignty for Cloud Systems Under Disruption
https://arxiv.org/abs/2604.14242

Challenges and Future Directions in Agentic Reverse Engineering Systems
https://arxiv.org/abs/2604.14317

Head Count: Privacy-Preserving Face-Based Crowd Monitoring
https://arxiv.org/abs/2604.14250

Understanding Student Experiences with TLS Client Authentication
https://arxiv.org/abs/2604.14330

From Black Box to Glass Box: Cross-Model ASR Disagreement to Prioto Review in Ambient AI Scribe Documentation
https://arxiv.org/abs/2604.14152

Compressed-Sensing-Guided, Inference-Aware Structured Reduction for Large Language Models
https://arxiv.org/abs/2604.14156

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cloud platform Vercel says company breached through third-party AI tool
https://therecord.media/cloud-platform-vercel-says-company-breached-through-ai-tool

Command Execution via Drag-and-Drop in Terminal Emulators
https://www.reddit.com/r/netsec/comments/1sreolc/command_execution_via_draganddrop_in_terminal/

We analysed almost 100 UK charity websites and found that ~1 in 6 are running vulnerable JavaScript dependencies.
https://www.reddit.com/r/netsec/comments/1srks4e/we_analysed_almost_100_uk_charity_websites_and/

Ukraine busts ‘bot farm’ supplying thousands of fake Telegram accounts to Russian spies
https://therecord.media/ukraine-sbu-busts-bot-farm-supplying-russian-spies

Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html

Detection strategies across cloud and identities against infiltrating IT workers
https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Toronto police arrest three in Canada’s first mobile SMS blaster case
https://therecord.media/canada-sms-blaster-cybercriminals

Norway's prime minister proposes ban on social media access for young teens
https://therecord.media/norway-prime-minister-proposes-social-media-ban-for-young-teens

Pentagon grapples with securing AI as it moves toward autonomous warfare
https://therecord.media/pentagon-grapples-with-securing-ai-as-it-moves-towards-autonomous-warfare

ADT says customer data stolen in cyber intrusion
https://therecord.media/ADT-data-breach-cyberattack

What Really Happened In There? A Tamper-Evident Audit Trail for AI Agents
https://www.reddit.com/r/netsec/comments/1suaupb/what_really_happened_in_there_a_tamperevident/

Hiding Bluetooth Trackers in Mail
https://www.schneier.com/blog/archives/2026/04/hiding-bluetooth-trackers-in-mail.html

Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes
https://www.reddit.com/r/netsec/comments/1suh47t/cohere_terrarium_cve20265752_and_openai_codex_cli/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

MCPwned: a Burp Suite extension for auditing MCP servers
https://www.reddit.com/r/netsec/comments/1swxhu6/mcpwned_a_burp_suite_extension_for_auditing_mcp/

Medieval Encrypted Letter Decoded
https://www.schneier.com/blog/archives/2026/04/medieval-encrypted-letter-decoded.html

27th April – Threat Intelligence Report
https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/

[arXiv] Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
https://arxiv.org/abs/2604.22001

Hackers impersonate Microsoft Teams help desk to breach corporate networks
https://therecord.media/microsoft-teams-hackers-mandiant

Context windows are breaking multi-agent security workflows
https://www.reddit.com/r/netsec/comments/1sx3eav/context_windows_are_breaking_multiagent_security/

Italy extradites alleged Chinese state hacker to US
https://therecord.media/chinese-hacker-italy-extradited

Disinformation campaign targeted Tibetan parliament-in-exile elections
https://therecord.media/disinformation-campaign-targeted-tibetan-elections

Money launderer for crypto thieves given 5-year sentence
https://therecord.media/cryptocurrency-launderer-sentenced-californai

Tennessee becomes second state to ban cryptocurrency ATMs over scam concerns
https://therecord.media/tennessee-bans-cryptocurrency-atms-over-scams

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ukrainian police detain hackers suspected of stealing thousands of Roblox accounts for resale
https://therecord.media/ukraine-police-detain-hackers-suspected-of-stealing-roblox-accounts

Video site Vimeo blames security incident on Anodot breach
https://therecord.media/vimeo-blames-security-incident-on-anodot-breach

Cyber Command, NSA chief warns foreign adversaries likely to target midterms
https://therecord.media/cyber-command-nsa-chief-midterm-election-threat

What Anthropic’s Mythos Means for the Future of Cybersecurity
https://www.schneier.com/blog/archives/2026/04/what_anthropics_mythos_means_for_the_future_of_cybersecurity.html

VECT: Ransomware by design, Wiper by accident
https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/

Simplifying AWS defense with Microsoft Sentinel UEBA
https://www.microsoft.com/en-us/security/blog/2026/04/28/simplifying-aws-defense-microsoft-sentinel-ueba/

89 vulnerabilities in XAPI / Citrix XenServer
https://www.reddit.com/r/netsec/comments/1sxtz42/89_vulnerabilities_in_xapi_citrix_xenserver/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Claude Mythos Has Found 271 Zero-Days in Firefox
https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html

What Should Frontier AI Developers Disclose About Internal Deployments?
https://arxiv.org/abs/2604.23065

CAN-QA: A Question-Answering Benchmark for Reasoning over In-Vehicle CAN Traffic
https://arxiv.org/abs/2604.24935

Prime-Field PINI: Machine-Checked Composition Theorems for Post-Quantum NTT Masking
https://arxiv.org/abs/2604.25878

Semantic Denial of Service in LLM-controlled robots
https://arxiv.org/abs/2604.24790

V.O.I.C.E (Voice, Ownership, Identity, Control, Expression): Risk Taxonomy of Synthetic Voice Generation From Empirical Data
https://arxiv.org/abs/2604.24794

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman