Top Daily Cyber Security News
714 subscribers
829 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

MCPwned: a Burp Suite extension for auditing MCP servers
https://www.reddit.com/r/netsec/comments/1swxhu6/mcpwned_a_burp_suite_extension_for_auditing_mcp/

Medieval Encrypted Letter Decoded
https://www.schneier.com/blog/archives/2026/04/medieval-encrypted-letter-decoded.html

27th April – Threat Intelligence Report
https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/

[arXiv] Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
https://arxiv.org/abs/2604.22001

Hackers impersonate Microsoft Teams help desk to breach corporate networks
https://therecord.media/microsoft-teams-hackers-mandiant

Context windows are breaking multi-agent security workflows
https://www.reddit.com/r/netsec/comments/1sx3eav/context_windows_are_breaking_multiagent_security/

Italy extradites alleged Chinese state hacker to US
https://therecord.media/chinese-hacker-italy-extradited

Disinformation campaign targeted Tibetan parliament-in-exile elections
https://therecord.media/disinformation-campaign-targeted-tibetan-elections

Money launderer for crypto thieves given 5-year sentence
https://therecord.media/cryptocurrency-launderer-sentenced-californai

Tennessee becomes second state to ban cryptocurrency ATMs over scam concerns
https://therecord.media/tennessee-bans-cryptocurrency-atms-over-scams

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Ukrainian police detain hackers suspected of stealing thousands of Roblox accounts for resale
https://therecord.media/ukraine-police-detain-hackers-suspected-of-stealing-roblox-accounts

Video site Vimeo blames security incident on Anodot breach
https://therecord.media/vimeo-blames-security-incident-on-anodot-breach

Cyber Command, NSA chief warns foreign adversaries likely to target midterms
https://therecord.media/cyber-command-nsa-chief-midterm-election-threat

What Anthropic’s Mythos Means for the Future of Cybersecurity
https://www.schneier.com/blog/archives/2026/04/what_anthropics_mythos_means_for_the_future_of_cybersecurity.html

VECT: Ransomware by design, Wiper by accident
https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/

Simplifying AWS defense with Microsoft Sentinel UEBA
https://www.microsoft.com/en-us/security/blog/2026/04/28/simplifying-aws-defense-microsoft-sentinel-ueba/

89 vulnerabilities in XAPI / Citrix XenServer
https://www.reddit.com/r/netsec/comments/1sxtz42/89_vulnerabilities_in_xapi_citrix_xenserver/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Claude Mythos Has Found 271 Zero-Days in Firefox
https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html

What Should Frontier AI Developers Disclose About Internal Deployments?
https://arxiv.org/abs/2604.23065

CAN-QA: A Question-Answering Benchmark for Reasoning over In-Vehicle CAN Traffic
https://arxiv.org/abs/2604.24935

Prime-Field PINI: Machine-Checked Composition Theorems for Post-Quantum NTT Masking
https://arxiv.org/abs/2604.25878

Semantic Denial of Service in LLM-controlled robots
https://arxiv.org/abs/2604.24790

V.O.I.C.E (Voice, Ownership, Identity, Control, Expression): Risk Taxonomy of Synthetic Voice Generation From Empirical Data
https://arxiv.org/abs/2604.24794

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

North Korean hackers behind major open-source supply chain attacks, Amazon says
https://therecord.media/north-korea-hackers-amazon-malware

U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/196289/security/u-s-cisa-adds-a-cisco-secure-firewall-management-center-fmc-flaw-to-its-known-exploited-vulnerabilities-catalog.html

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html

FCC Restricts New Foreign Robots and Inverters Over Security Risks
https://securityaffairs.com/196308/security/fcc-restricts-new-foreign-robots-and-inverters-over-security-risks.html

Cyber extortionists steal data from UK Department for Education
https://therecord.media/united-kingdom-ransomware-education

Analog Devices Discloses Data Breach After Unauthorized System Access
https://securityaffairs.com/196320/data-breach/analog-devices-discloses-data-breach-after-unauthorized-system-access.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Anthropic Finds Claude Breached Real Companies During Security Evaluations
https://securityaffairs.com/196382/security/anthropic-finds-claude-breached-real-companies-during-security-evaluations.html

Network Anomaly Detection in KATA
https://securelist.com/tr/network-anomaly-detection-in-kata/120892/

When benchmark inferences do not compose: Projectibility in AI evaluation
https://arxiv.org/abs/2607.26159

Contextualized Counterspeech Can Be More Persuasive Than Generic Counterspeech
https://arxiv.org/abs/2607.26236

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html

What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
https://securityaffairs.com/196395/ai/what-an-llm-can-find-a-practical-cheap-path-to-code-level-threat-discovery.html

Jackson Man Sentenced to Over Six Years for Felon in Possession of a Firearm
https://www.justice.gov/usao-sdms/pr/jackson-man-sentenced-over-six-years-felon-possession-firearm

Modesto Man Indicted for Illegal Possession of Ammunition
https://www.justice.gov/usao-edca/pr/modesto-man-indicted-illegal-possession-ammunition

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Yes, we are back 😁
🔥3
Top Security News for Today

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
https://securityaffairs.com/196429/security/adobe-fixed-a-maximum-severity-vulnerability-flaw-in-campaign-classic.html

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
https://securityaffairs.com/196441/apt/russian-hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-tokens.html

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions
https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions

Federal Jury Finds Man Guilty of Four Robberies with a Firearm
https://www.justice.gov/usao-mdfl/pr/federal-jury-finds-man-guilty-four-robberies-firearm

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CareCloud Breach Exposes Medical and Financial Data of 345,000
https://securityaffairs.com/196480/cyber-crime/carecloud-breach-exposes-medical-and-financial-data-of-345000.html

Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
https://securityaffairs.com/196486/security/ruby-on-rails-patches-critical-active-storage-vulnerability-affecting-image-processing.html

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html

The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
https://www.reddit.com/r/netsec/comments/1vdqe9d/the_risk_of_finetuned_openweight_models_msec/

SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability
https://isc.sans.edu/podcastdetail/10034

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html

PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html

PNLD Confirms Data Breach Affecting UK Police and Justice Staff
https://securityaffairs.com/196525/data-breach/pnld-confirms-data-breach-affecting-uk-police-and-justice-staff.html

Amgen Says Patient Data Stolen from Third-Party Cloud Systems
https://therecord.media/amgen-hackers-cyberattack-sec

Russian Hackers Hijack Hotel Wi-Fi Networks to Spy on Travelers
https://therecord.media/russian-wifi-hackers-hotels

Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
https://thehackernews.com/2026/08/weekly-recap-rogue-ai-models-88m.html

FOMO in the SOC: Where AI Platforms Like Claude Actually Fit
https://thehackernews.com/2026/08/fomo-in-soc-where-ai-platforms-like.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html

Some Claude Chats Are Searchable on Google
https://www.schneier.com/blog/archives/2026/08/some-claude-chats-are-searchable-on-google.html

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html

Case study: How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years
https://portswigger.net/blog/case-study-how-burp-at-helped-expose-whistleblower-reports-via-a-critical-vulnerability-that-was-overlooked-for-years

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html

CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
https://securityaffairs.com/196595/security/cve-2026-58048-cpanel-bug-enables-full-database-administrator-access.html

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

Anthropic AI agent faked identities, phished real developers in UK government hacking test
https://therecord.media/anthropic-ai-hacking-uk

Vulnerabilities in Car Anti-Theft Device
https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html

Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
https://www.reddit.com/r/netsec/comments/1vg9704/stored_xss_in_djangos_admin_via_an_unvalidated/

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html

Cyberattacks targeting water systems expand to 12 states as South Dakota, Georgia announce incidents
https://therecord.media/iran-cyberattacks-water-treatment

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/196667/hacking/u-s-cisa-adds-langflow-apache-tomcat-and-n-able-n-central-flaws-to-its-known-exploited-vulnerabilities-catalog.html

5th Edition MENA CYBER SECURITY CONFERENCE – RIYADH EDITION
https://cisomag.com/5th-edition-mena-cyber-security-conference-riyadh-edition/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html

Adversarial Clothing Designed to Fool Facial Recognition Systems
https://www.schneier.com/blog/archives/2026/08/adversarial-clothing-designed-to-fool-facial-recognition-systems.html

From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
https://www.reddit.com/r/netsec/comments/1vgr9gv/from_wallet_drains_to_a_12yearold_cryptojs/

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html

Ransom Cartel Leader Sentenced to 16 Years in U.S.
https://securityaffairs.com/196746/cyber-crime/ransom-cartel-leader-sentenced-to-16-years-in-u-s.html

Canadian Man Pleads Guilty in Snowflake Extortions
https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html

ICE Is Buying Access to Credit Card Records
https://www.schneier.com/blog/archives/2026/08/ice-is-buying-access-to-credit-card-records.html

Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
https://securityaffairs.com/196785/security/researchers-discover-hidden-backdoor-in-20-router-models-allowing-remote-root-access.html

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html

Growing Up The Hard Way
https://thehackernews.com/2026/08/growing-up-hard-way.html

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
https://securityaffairs.com/196793/laws-and-regulations/meta-ordered-to-pay-567-million-over-child-safety-failures-in-new-mexico-case.html

Calabasas Man Sentenced to 27 Years in Federal Prison for Running ‘DoorDash for Drugs’ Service that Led to Two Fatal Fentanyl OD’s
https://www.justice.gov/usao-cdca/pr/calabasas-man-sentenced-27-years-federal-prison-running-doordash-drugs-service-led-two

Jamestown Man Sentenced on Multiple Drug Charges
https://www.justice.gov/usao-wdny/pr/jamestown-man-sentenced-multiple-drug-charges

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
https://www.reddit.com/r/netsec/comments/1vilqda/rovoblast_how_one_click_triggered_atlassians_ai/

Mexican National Unlawfully Residing in the United States Pleads Guilty to Firearms Offenses
https://www.justice.gov/usao-or/pr/mexican-national-unlawfully-residing-united-states-pleads-guilty-firearms-offenses

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
https://securityaffairs.com/196899/hacking/webmail-css-attacks-expose-a-new-risk-for-ai-powered-email-tools.html

Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
https://www.reddit.com/r/netsec/comments/1vir8aq/write_once_shell_everywhere_turning_arbitrary/

Analyzing a Multi-Stage PowerShell Payload Chain
https://www.reddit.com/r/netsec/comments/1vj2hiw/analyzing_a_multistage_powershell_payload_chain/

Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
https://securityaffairs.com/196881/intelligence/palo-alto-networks-faces-china-cybersecurity-review-amid-rising-tech-tensions.html

DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE
https://www.reddit.com/r/netsec/comments/1viux00/def_con_talk_8_in_10_banks_in_belgium_hate_this/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
https://thehackernews.com/2026/08/researchers-turn-usb-auto-install-into.html

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
https://securelist.com/project-cav3rn-continues/120991/

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html

Cuba's Spies, Defectors, and the Ex-FBI Agent Who Met Them All
https://thecyberwire.com/podcasts/spycast/745/notes

Kids’ online safety bill faces dim prospects of passage this session despite progress
https://therecord.media/kids-online-safety-act-congress

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html

Local governments in four states dealing with cyberattacks that have shut down services
https://therecord.media/cyberattacks-ransomware-local-governments

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

Understanding the Implications of AI in Cybersecurity
https://reporter.deepspecter.com/understanding-ai-cybersecurity

New Ransomware Strikes: What You Need to Know
https://www.cybersecuritynews.com/new-ransomware-strikes

The Rise of Phishing Attacks in 2023
https://www.securitymagazine.com/articles/98324-phishing-attacks-rise-2023

Critical Vulnerabilities in Popular Software: A Warning
https://www.infosecurity-magazine.com/opinions/critical-vulnerabilities-popular-software

How to Secure Your Home Network
https://www.cnet.com/home/internet-security/secure-your-home-network

Top 5 Cybersecurity Trends to Watch
https://www.techradar.com/news/cybersecurity-trends-2023

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

Exclusive: Inside the Cybersecurity Challenges Facing Fortune 100 Companies
https://reporter.deepspecter.com/cybersecurity-fortune100

New Ransomware Group Targets Healthcare Systems
https://www.csoonline.com/article/3551236/new-ransomware-targets-healthcare-systems.html

Data Breach Exposes Personal Information of Thousands
https://www.zdnet.com/article/data-breach-personal-information-exposed/

Phishing Scams on the Rise: How to Protect Yourself
https://www.techradar.com/news/phishing-scams-increase

Study Reveals Weaknesses in Cloud Security
https://www.cnet.com/news/study-reveals-cloud-security-issues/

Government Agency Issues Warning Against New Malware
https://www.scmagazine.com/home/security-news/government-agency-new-malware-warning/

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman
Top Security News for Today

New Vulnerabilities Discovered in Popular Software
https://reporter.deepspecter.com/new-vulnerabilities-discovered

Ransomware Attacks Surge in Healthcare Sector
https://www.cybersecuritynews.com/ransomware-healthcare

Critical Flaw Found in Major Web Browser
https://www.technologymagazine.com/security/critical-flaw-major-web-browser

Phishing Scams Targeting Remote Workers
https://www.infosecurity-magazine.com/news/phishing-scams-targeting-remote

New Cybersecurity Regulations Announced
https://www.securityweek.com/new-cybersecurity-regulations-announced

AI in Cybersecurity: Risks and Benefits
https://www.csoonline.com/article/ai-cybersecurity-risks-benefits

Malware Attacks Increasingly Targeting IoT Devices
https://www.zdnet.com/article/malware-attacks-iot-devices

Follow Top Cyber News at https://t.me/TopCyberTechNews Feel free to DM me at https://x.com/ShayaFeedman