Top Daily Cyber Security News – Telegram
Top Daily Cyber Security News
721 subscribers
719 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

Tiny but Mighty: A Software-Hardware Co-Design Approach for Efficient Multimodal Inference on Battery-Powered Small Devices
https://arxiv.org/abs/2510.05109

System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
https://arxiv.org/abs/2505.06493

Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
https://www.reddit.com/r/netsec/comments/1o170wz/bash_a_newline_exploiting_ssh_via_proxycommand/

Teenagers arrested in England over cyberattack on nursery chain Kido
https://therecord.media/kido-nursery-school-chain-hack-arrests-britain

Cybercrime crew claims attack on Japanese brewer as it restarts operations
https://therecord.media/qilin-ransomware-gang-alleged-asahi-hackers

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Discord says 70,000 users had government IDs exposed in third-party breach
https://therecord.media/discord-government-docs-exposed-breach

Investing targeted “payroll pirate” attacks affecting US universities
https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/

LLM Black Markets in 2025 – Prompt Injection, Jailbreak Sales & Model Leaks
https://www.darknet.org.uk/2025/10/llm-black-markets-in-2025-prompt-injection-jailbreak-sales-model-leaks/

HTTP/1.1 must die: Dafydd Stuttard on what this means for enterprise security
https://portswigger.net/blog/http-1-1-must-die-dafydd-stuttard-on-what-this-means-for-enterprise-security

Security Analysis of a medical device: Methods and Findings
https://www.reddit.com/r/netsec/comments/1o29iec/security_analysis_of_a_medical_device_methods_and/

A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
https://www.reddit.com/r/netsec/comments/1o0pfnr/a_handson_edition_will_supabase_be_the_next/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

AI and the Future of American Politics
https://www.schneier.com/blog/archives/2025/10/ai-and-the-future-of-american-politics.html

UK fines 4chan over noncompliance with Online Safety Act
https://therecord.media/4chan-fined-ofcom-uk-online-safety-act

LLM Honeypot vs. Cryptojacking: Understanding the Enemy
https://www.reddit.com/r/netsec/comments/1o5m7cg/llm_honeypot_vs_cryptojacking_understanding_the/

Netherlands invokes special powers against Chinese-owned semiconductor company Nexperia
https://therecord.media/netherlands-special-powers-chinese-owned-semiconductor

(DEF CON 33) How I hacked over 1,000 car dealerships across the US
https://www.reddit.com/r/netsec/comments/1o5na8l/def_con_33_how_i_hacked_over_1000_car_dealerships/

Building a lasting security culture at Microsoft
https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-microsoft/

Ukraine takes steps to launch dedicated cyber force for offensive strikes
https://therecord.media/ukraine-takes-steps-dedicated-cyber-force

Harvard says ‘limited number of parties’ impacted by breach linked to Oracle zero-day
https://therecord.media/harvard-says-limited-number-linked-to-data-theft

UK hit by record number of ‘nationally significant’ cyberattacks
https://therecord.media/uk-hit-by-record-number-significant-cyberattacks

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Signal in the noise: what hashtags reveal about hacktivism in 2025
https://securelist.com/dfi-meta-hacktivist-report/117708/

Automating the RMF: Lessons from the FedRAMP 20x Pilot
https://arxiv.org/abs/2510.09610

A Biosecurity Agent for Lifecycle LLM Biosecurity Alignment
https://arxiv.org/abs/2510.09613

Causal Digital Twins for Cyber-Physical Security: A Framework for Robust Anomaly Detection in Industrial Control Systems
https://arxiv.org/abs/2510.09615

Microsoft raises the bar: A smarter way to measure AI for cybersecurity
https://www.microsoft.com/en-us/security/blog/2025/10/14/microsoft-raises-the-bar-a-smarter-way-to-measure-ai-for-cybersecurity/

Qantas confirms cybercriminals released stolen customer data
https://therecord.media/qantas-cybercriminals-stolen-data

Taiwan reports surge in Chinese cyber activity and disinformation efforts
https://therecord.media/taiwan-nsb-report-china-surge-cyberattacks-influence-operations

Florida sues Roku for illegally selling children’s data, including precise geolocation
https://therecord.media/florida-roku-children-data

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Researchers report rare intrusion by suspected Chinese hackers into Russian tech firm
https://therecord.media/rare-china-linked-intrusion-russian-tech-firms

Mysterious Elephant: a growing threat
https://securelist.com/mysterious-elephant-apt-ttps-and-tools/117596/

Apple’s Bug Bounty Program
https://www.schneier.com/blog/archives/2025/10/apples-bug-bounty-program.html

Capita given record £14 million fine over ransomware attack security failings
https://therecord.media/capita-record-fine-uk-ico-ransomware-attack

New York secures $14 million in fines from 8 car insurance companies after data breaches
https://therecord.media/auto-insurance-companies-fined-ny-state-pre-fill-data-breaches

Maverick: a new banking Trojan abusing WhatsApp in a mass-scale distribution
https://securelist.com/maverick-banker-distributing-via-whatsapp/117715/

Exploit-as-a-Service Resurgence in 2025 – Broker Models, Bundles & Subnoscription Access
https://www.darknet.org.uk/2025/10/exploit-as-a-service-resurgence-in-2025-broker-models-bundles-subnoscription-access/

Mango says some customer information exposed in cyber incident
https://therecord.media/mango-fashion-retaier-data-breach

PowerSchool hacker sentenced to 4 years in prison
https://therecord.media/powerschool-hacker-sentenced-4-years

CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug info
https://therecord.media/cisa-directive-f5-nation-state-incident

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/

Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903

Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How a fake AI recruiter delivers five staged malware disguised as a dream job
https://www.reddit.com/r/netsec/comments/1obgnxd/how_a_fake_ai_recruiter_delivers_five_staged/

XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)
https://www.darknet.org.uk/2025/10/xrayc2-weaponizing-aws-x-ray-for-covert-command-and-control-c2/

Agentic AI’s OODA Loop Problem
https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html

Evilginx’s creator reckons with the dark side of red-team tools
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast

20th October – Threat Intelligence Report
https://research.checkpoint.com/2025/20th-october-threat-intelligence-report/

Home security firm Verisure reports data breach at Swedish subsidiary
https://therecord.media/verisure-data-breach-sweden-alert-alarm-subsidiary

China claims it caught US attempting cyberattack on national time center
https://therecord.media/china-attack-national-time-center

Inside the attack chain: Threat activity targeting Azure Blob Storage
https://www.microsoft.com/en-us/security/blog/2025/10/20/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage/

Tunneling WireGuard over HTTPS using Wstunnel
https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

BetterBank DeFi Protocol: Esteem Token Bonus Minting
https://securelist.com/betterbank-defi-protocol-esteem-token-bonus-minting/117822/

Post-Quantum Cryptography in 2025 – Migration Paths, Early Movers and CISO/RedTeam Impact
https://www.darknet.org.uk/2025/10/post-quantum-cryptography-in-2025-migration-paths-early-movers-and-ciso-redteam-impact/

Failures in Face Recognition
https://www.schneier.com/blog/archives/2025/10/failures-in-face-recognition.html

PhantomCaptcha' hackers impersonate Ukrainian president’s office in attack on war relief workers
https://therecord.media/phantomcaptcha-spearphishing-campaign-ukraine-war-relief-groups

Jaguar Land Rover cyberattack cost $2.5 billion, says monitoring group
https://therecord.media/jaguar-land-rover-cyberattack-economic-impact

Ransomware gang steals meeting videos, financial secrets from fence wholesaler
https://therecord.media/ransomware-gang-steals-meeting-video-fence-manufacturer

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI
https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai

Canada Fines Cybercrime Friendly Cryptomus $176M
https://krebsonsecurity.com/2025/10/canada-fines-cybercrime-friendly-cryptomus-176m/

State attorneys general stepping up privacy enforcement, watchdog finds
https://therecord.media/state-ags-enforcement-privacy-law

The security paradox of local LLMs
https://www.reddit.com/r/netsec/comments/1od7azc/the_security_paradox_of_local_llms/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
https://therecord.media/russia-food-safety-agency-rosselkhoznadzor-ddos-attack

TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://therecord.media/cybercrime-treaty-signing-hanoi

Counter Ransomware Initiative stresses importance of supply-chain security
https://therecord.media/counter-ransomware-initiative-software-supply-chain-guidance

Part Four of The Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/10/part-four-of-the-kryptos-sculpture.html

A Quantum-Inspired Algorithm for Solving Sudoku Puzzles and the MaxCut Problem
https://arxiv.org/abs/2510.19835

Excitation of Looped Bistable Bands for High-Speed Linear Actuation
https://arxiv.org/abs/2510.19834

Benchmarking Reasoning Reliability in Artificial Intelligence Models for Energy-System Analysis
https://arxiv.org/abs/2510.19836

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://www.reddit.com/r/netsec/comments/1ogilto/hacking_the_world_poker_tour_inside_clubwpt_golds/

Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://www.reddit.com/r/netsec/comments/1oglfix/using_edrredir_to_break_edr_via_bind_link_and/

NetExec – Network Execution Toolkit for Windows and Active Directory
https://www.darknet.org.uk/2025/10/netexec-network-execution-toolkit-for-windows-and-active-directory/

New no nonsense platform for practice security learning
https://www.reddit.com/r/netsec/comments/1ogmqkl/new_no_nonsense_platform_for_practice_security/

YOLO detect security cameras
http://diablohorn.com/2025/10/26/yolo-detect-security-cameras/

Reaper – Unified Application Security Testing with AI Support
https://www.darknet.org.uk/2025/10/reaper-unified-application-security-testing-with-ai-support/

GlobalCVE — OpenSource Unified CVE Data from Around the World
https://www.reddit.com/r/netsec/comments/1oh4d5w/globalcve_opensource_unified_cve_data_from_around/

CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/

Vibecoding and the illusion of security
https://www.reddit.com/r/netsec/comments/1oh9mr4/vibecoding_and_the_illusion_of_security/

Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://www.reddit.com/r/netsec/comments/1oh8zn4/jettys_addpath_allows_lfi_in_windows_traccar/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
https://www.trendmicro.com/en_us/research/25/j/active-water-saci-campaign-whatsapp-update.html

CISA releases warning about Windows Server Update Service bug, orders agencies to patch
https://therecord.media/wsus-vulnerability-cisa-late-friday-warning

Sweden’s power grid operator confirms data breach claimed by ransomware gang
https://therecord.media/sweden-power-grid-operator-data

CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/

Cities reverse course on automated license plate reader cameras amid privacy concerns
https://therecord.media/cities-reverse-course-on-automated-license-plate-reader-cameras

Louvre Jewel Heist
https://www.schneier.com/blog/archives/2025/10/louvre-jewel-heist.html

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman