Top Security News for Today
HoneyBee – Misconfigured App Generator for Red Team Validation
https://www.darknet.org.uk/2025/10/honeybee-misconfigured-app-generator-for-red-team-validation/
Post-exploitation framework now also delivered via npm
https://securelist.com/adaptixc2-agent-found-in-an-npm-package/117784/
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
https://www.reddit.com/r/netsec/comments/1o8uj8c/how_i_reversed_amazons_kindle_web_obfuscation/
A Surprising Amount of Satellite Traffic Is Unencrypted
https://www.schneier.com/blog/archives/2025/10/a-surprising-amount-of-satellite-traffic-is-unencrypted.html
Email Bombs Exploit Lax Authentication in Zendesk
https://krebsonsecurity.com/2025/10/email-bombs-exploit-lax-authentication-in-zendesk/
Small Actions, Big Breaches: The Silent Offensive Against Your Data
https://bishopfox.com/blog/small-actions-big-breaches-the-silent-offensive-against-your-data
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
HoneyBee – Misconfigured App Generator for Red Team Validation
https://www.darknet.org.uk/2025/10/honeybee-misconfigured-app-generator-for-red-team-validation/
Post-exploitation framework now also delivered via npm
https://securelist.com/adaptixc2-agent-found-in-an-npm-package/117784/
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
https://www.reddit.com/r/netsec/comments/1o8uj8c/how_i_reversed_amazons_kindle_web_obfuscation/
A Surprising Amount of Satellite Traffic Is Unencrypted
https://www.schneier.com/blog/archives/2025/10/a-surprising-amount-of-satellite-traffic-is-unencrypted.html
Email Bombs Exploit Lax Authentication in Zendesk
https://krebsonsecurity.com/2025/10/email-bombs-exploit-lax-authentication-in-zendesk/
Small Actions, Big Breaches: The Silent Offensive Against Your Data
https://bishopfox.com/blog/small-actions-big-breaches-the-silent-offensive-against-your-data
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Darknet - Hacking Tools, Hacker News & Cyber Security
HoneyBee - Misconfigured App Generator for Red Team Validation
HoneyBee generates intentionally misconfigured Docker environments and Nuclei templates using LLMs so red teams can rehearse exploitation and validate detection.
Top Security News for Today
macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/
Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/
CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903
Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/
Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/
CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903
Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: macOS Shortcuts for Initial Access
Explore this post and more from the netsec community
Top Security News for Today
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today
How a fake AI recruiter delivers five staged malware disguised as a dream job
https://www.reddit.com/r/netsec/comments/1obgnxd/how_a_fake_ai_recruiter_delivers_five_staged/
XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)
https://www.darknet.org.uk/2025/10/xrayc2-weaponizing-aws-x-ray-for-covert-command-and-control-c2/
Agentic AI’s OODA Loop Problem
https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html
Evilginx’s creator reckons with the dark side of red-team tools
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast
20th October – Threat Intelligence Report
https://research.checkpoint.com/2025/20th-october-threat-intelligence-report/
Home security firm Verisure reports data breach at Swedish subsidiary
https://therecord.media/verisure-data-breach-sweden-alert-alarm-subsidiary
China claims it caught US attempting cyberattack on national time center
https://therecord.media/china-attack-national-time-center
Inside the attack chain: Threat activity targeting Azure Blob Storage
https://www.microsoft.com/en-us/security/blog/2025/10/20/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage/
Tunneling WireGuard over HTTPS using Wstunnel
https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
How a fake AI recruiter delivers five staged malware disguised as a dream job
https://www.reddit.com/r/netsec/comments/1obgnxd/how_a_fake_ai_recruiter_delivers_five_staged/
XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)
https://www.darknet.org.uk/2025/10/xrayc2-weaponizing-aws-x-ray-for-covert-command-and-control-c2/
Agentic AI’s OODA Loop Problem
https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html
Evilginx’s creator reckons with the dark side of red-team tools
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast
20th October – Threat Intelligence Report
https://research.checkpoint.com/2025/20th-october-threat-intelligence-report/
Home security firm Verisure reports data breach at Swedish subsidiary
https://therecord.media/verisure-data-breach-sweden-alert-alarm-subsidiary
China claims it caught US attempting cyberattack on national time center
https://therecord.media/china-attack-national-time-center
Inside the attack chain: Threat activity targeting Azure Blob Storage
https://www.microsoft.com/en-us/security/blog/2025/10/20/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage/
Tunneling WireGuard over HTTPS using Wstunnel
https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: How a fake AI recruiter delivers five staged malware disguised as a dream job
Explore this post and more from the netsec community
Top Security News for Today
The evolving landscape of email phishing attacks: how threat actors are reusing and refining established techniques
https://securelist.com/email-phishing-techniques-2025/117801/
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/
CVE-2025-9133: ZYXEL Configuration Exposure via Authorization Bypass
https://www.reddit.com/r/netsec/comments/1oc4qwa/cve20259133_zyxel_configuration_exposure_via/
A Cybersecurity Merit Badge
https://www.schneier.com/blog/archives/2025/10/a-cybersecurity-merit-badge.html
Fast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities
https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html
Microsoft 365 Copilot - Arbitrary Data Exfiltration Via Mermaid Diagrams
https://www.reddit.com/r/netsec/comments/1occb7r/microsoft_365_copilot_arbitrary_data_exfiltration/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
The evolving landscape of email phishing attacks: how threat actors are reusing and refining established techniques
https://securelist.com/email-phishing-techniques-2025/117801/
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/
CVE-2025-9133: ZYXEL Configuration Exposure via Authorization Bypass
https://www.reddit.com/r/netsec/comments/1oc4qwa/cve20259133_zyxel_configuration_exposure_via/
A Cybersecurity Merit Badge
https://www.schneier.com/blog/archives/2025/10/a-cybersecurity-merit-badge.html
Fast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities
https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html
Microsoft 365 Copilot - Arbitrary Data Exfiltration Via Mermaid Diagrams
https://www.reddit.com/r/netsec/comments/1occb7r/microsoft_365_copilot_arbitrary_data_exfiltration/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Securelist
Notable email phishing techniques in 2025
Common email phishing tactics in 2025 include PDF attachments with QR codes, password-protected PDF documents, calendar phishing, and advanced websites that validate email addresses.
Top Security News for Today
BetterBank DeFi Protocol: Esteem Token Bonus Minting
https://securelist.com/betterbank-defi-protocol-esteem-token-bonus-minting/117822/
Post-Quantum Cryptography in 2025 – Migration Paths, Early Movers and CISO/RedTeam Impact
https://www.darknet.org.uk/2025/10/post-quantum-cryptography-in-2025-migration-paths-early-movers-and-ciso-redteam-impact/
Failures in Face Recognition
https://www.schneier.com/blog/archives/2025/10/failures-in-face-recognition.html
PhantomCaptcha' hackers impersonate Ukrainian president’s office in attack on war relief workers
https://therecord.media/phantomcaptcha-spearphishing-campaign-ukraine-war-relief-groups
Jaguar Land Rover cyberattack cost $2.5 billion, says monitoring group
https://therecord.media/jaguar-land-rover-cyberattack-economic-impact
Ransomware gang steals meeting videos, financial secrets from fence wholesaler
https://therecord.media/ransomware-gang-steals-meeting-video-fence-manufacturer
Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI
https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai
Canada Fines Cybercrime Friendly Cryptomus $176M
https://krebsonsecurity.com/2025/10/canada-fines-cybercrime-friendly-cryptomus-176m/
State attorneys general stepping up privacy enforcement, watchdog finds
https://therecord.media/state-ags-enforcement-privacy-law
The security paradox of local LLMs
https://www.reddit.com/r/netsec/comments/1od7azc/the_security_paradox_of_local_llms/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
BetterBank DeFi Protocol: Esteem Token Bonus Minting
https://securelist.com/betterbank-defi-protocol-esteem-token-bonus-minting/117822/
Post-Quantum Cryptography in 2025 – Migration Paths, Early Movers and CISO/RedTeam Impact
https://www.darknet.org.uk/2025/10/post-quantum-cryptography-in-2025-migration-paths-early-movers-and-ciso-redteam-impact/
Failures in Face Recognition
https://www.schneier.com/blog/archives/2025/10/failures-in-face-recognition.html
PhantomCaptcha' hackers impersonate Ukrainian president’s office in attack on war relief workers
https://therecord.media/phantomcaptcha-spearphishing-campaign-ukraine-war-relief-groups
Jaguar Land Rover cyberattack cost $2.5 billion, says monitoring group
https://therecord.media/jaguar-land-rover-cyberattack-economic-impact
Ransomware gang steals meeting videos, financial secrets from fence wholesaler
https://therecord.media/ransomware-gang-steals-meeting-video-fence-manufacturer
Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI
https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai
Canada Fines Cybercrime Friendly Cryptomus $176M
https://krebsonsecurity.com/2025/10/canada-fines-cybercrime-friendly-cryptomus-176m/
State attorneys general stepping up privacy enforcement, watchdog finds
https://therecord.media/state-ags-enforcement-privacy-law
The security paradox of local LLMs
https://www.reddit.com/r/netsec/comments/1od7azc/the_security_paradox_of_local_llms/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Securelist
The BetterBank DeFi protocol exploited for reward minting
Kaspersky experts break down the recent BetterBank incident involving ESTEEM token bonus minting due to the lack of liquidity pool validation.
Top Security News for Today
Serious F5 Breach
https://www.schneier.com/blog/archives/2025/10/serious-f5-breach.html
Dissecting YouTube’s Malware Distribution Network
https://research.checkpoint.com/2025/youtube-ghost-network/
Phishing campaign across Mideast, North Africa is attributed to Iranian group
https://therecord.media/iran-muddywater-phishing-campaign-north-africa-middle-east
Former Polish official indicted over spyware purchase
https://therecord.media/former-polish-official-indicted-spyware-probe
Hackers posing as Kyrgyz officials target Russian agencies in cyber espionage campaign
https://therecord.media/hackers-pose-kyrgyz-officials-russia-cyber-espionage
Tinder to expand face verification tech to more states
https://therecord.media/tinder-face-check-tool-expanding-to-more-states
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Serious F5 Breach
https://www.schneier.com/blog/archives/2025/10/serious-f5-breach.html
Dissecting YouTube’s Malware Distribution Network
https://research.checkpoint.com/2025/youtube-ghost-network/
Phishing campaign across Mideast, North Africa is attributed to Iranian group
https://therecord.media/iran-muddywater-phishing-campaign-north-africa-middle-east
Former Polish official indicted over spyware purchase
https://therecord.media/former-polish-official-indicted-spyware-probe
Hackers posing as Kyrgyz officials target Russian agencies in cyber espionage campaign
https://therecord.media/hackers-pose-kyrgyz-officials-russia-cyber-espionage
Tinder to expand face verification tech to more states
https://therecord.media/tinder-face-check-tool-expanding-to-more-states
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Schneier on Security
Serious F5 Breach - Schneier on Security
This is bad: F5, a Seattle-based maker of networking software, disclosed the breach on Wednesday. F5 said a “sophisticated” threat group working for an undisclosed nation-state government had surreptitiously and persistently dwelled in its network over a…
Top Security News for Today
Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
https://therecord.media/russia-food-safety-agency-rosselkhoznadzor-ddos-attack
TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://therecord.media/cybercrime-treaty-signing-hanoi
Counter Ransomware Initiative stresses importance of supply-chain security
https://therecord.media/counter-ransomware-initiative-software-supply-chain-guidance
Part Four of The Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/10/part-four-of-the-kryptos-sculpture.html
A Quantum-Inspired Algorithm for Solving Sudoku Puzzles and the MaxCut Problem
https://arxiv.org/abs/2510.19835
Excitation of Looped Bistable Bands for High-Speed Linear Actuation
https://arxiv.org/abs/2510.19834
Benchmarking Reasoning Reliability in Artificial Intelligence Models for Energy-System Analysis
https://arxiv.org/abs/2510.19836
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
https://therecord.media/russia-food-safety-agency-rosselkhoznadzor-ddos-attack
TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://therecord.media/cybercrime-treaty-signing-hanoi
Counter Ransomware Initiative stresses importance of supply-chain security
https://therecord.media/counter-ransomware-initiative-software-supply-chain-guidance
Part Four of The Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/10/part-four-of-the-kryptos-sculpture.html
A Quantum-Inspired Algorithm for Solving Sudoku Puzzles and the MaxCut Problem
https://arxiv.org/abs/2510.19835
Excitation of Looped Bistable Bands for High-Speed Linear Actuation
https://arxiv.org/abs/2510.19834
Benchmarking Reasoning Reliability in Artificial Intelligence Models for Energy-System Analysis
https://arxiv.org/abs/2510.19836
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
A veterinary certification platform and systems that track products and chemicals were among the tools disrupted by a DDoS incident, Russia's food safety watchdog said.
Top Security News for Today
Account takeover exploit write-up for Magento SessionReaper
https://www.reddit.com/r/netsec/comments/1ofm6og/account_takeover_exploit_writeup_for_magento/
Pentesting Next.js Server Actions
https://www.reddit.com/r/netsec/comments/1of84hu/pentesting_nextjs_server_actions/
What Does Print Function ACTUALLY Do?
https://www.reddit.com/r/lowlevel/comments/1ofza5t/what_does_print_function_actually_do/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Account takeover exploit write-up for Magento SessionReaper
https://www.reddit.com/r/netsec/comments/1ofm6og/account_takeover_exploit_writeup_for_magento/
Pentesting Next.js Server Actions
https://www.reddit.com/r/netsec/comments/1of84hu/pentesting_nextjs_server_actions/
What Does Print Function ACTUALLY Do?
https://www.reddit.com/r/lowlevel/comments/1ofza5t/what_does_print_function_actually_do/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Account takeover exploit write-up for Magento SessionReaper
Posted by AdAccording4827 - 1 vote and 0 comments
Top Security News for Today
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://www.reddit.com/r/netsec/comments/1ogilto/hacking_the_world_poker_tour_inside_clubwpt_golds/
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://www.reddit.com/r/netsec/comments/1oglfix/using_edrredir_to_break_edr_via_bind_link_and/
NetExec – Network Execution Toolkit for Windows and Active Directory
https://www.darknet.org.uk/2025/10/netexec-network-execution-toolkit-for-windows-and-active-directory/
New no nonsense platform for practice security learning
https://www.reddit.com/r/netsec/comments/1ogmqkl/new_no_nonsense_platform_for_practice_security/
YOLO detect security cameras
http://diablohorn.com/2025/10/26/yolo-detect-security-cameras/
Reaper – Unified Application Security Testing with AI Support
https://www.darknet.org.uk/2025/10/reaper-unified-application-security-testing-with-ai-support/
GlobalCVE — OpenSource Unified CVE Data from Around the World
https://www.reddit.com/r/netsec/comments/1oh4d5w/globalcve_opensource_unified_cve_data_from_around/
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/
Vibecoding and the illusion of security
https://www.reddit.com/r/netsec/comments/1oh9mr4/vibecoding_and_the_illusion_of_security/
Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://www.reddit.com/r/netsec/comments/1oh8zn4/jettys_addpath_allows_lfi_in_windows_traccar/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://www.reddit.com/r/netsec/comments/1ogilto/hacking_the_world_poker_tour_inside_clubwpt_golds/
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://www.reddit.com/r/netsec/comments/1oglfix/using_edrredir_to_break_edr_via_bind_link_and/
NetExec – Network Execution Toolkit for Windows and Active Directory
https://www.darknet.org.uk/2025/10/netexec-network-execution-toolkit-for-windows-and-active-directory/
New no nonsense platform for practice security learning
https://www.reddit.com/r/netsec/comments/1ogmqkl/new_no_nonsense_platform_for_practice_security/
YOLO detect security cameras
http://diablohorn.com/2025/10/26/yolo-detect-security-cameras/
Reaper – Unified Application Security Testing with AI Support
https://www.darknet.org.uk/2025/10/reaper-unified-application-security-testing-with-ai-support/
GlobalCVE — OpenSource Unified CVE Data from Around the World
https://www.reddit.com/r/netsec/comments/1oh4d5w/globalcve_opensource_unified_cve_data_from_around/
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/
Vibecoding and the illusion of security
https://www.reddit.com/r/netsec/comments/1oh9mr4/vibecoding_and_the_illusion_of_security/
Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://www.reddit.com/r/netsec/comments/1oh8zn4/jettys_addpath_allows_lfi_in_windows_traccar/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
Explore this post and more from the netsec community
Top Security News for Today
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
https://www.trendmicro.com/en_us/research/25/j/active-water-saci-campaign-whatsapp-update.html
CISA releases warning about Windows Server Update Service bug, orders agencies to patch
https://therecord.media/wsus-vulnerability-cisa-late-friday-warning
Sweden’s power grid operator confirms data breach claimed by ransomware gang
https://therecord.media/sweden-power-grid-operator-data
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/
Cities reverse course on automated license plate reader cameras amid privacy concerns
https://therecord.media/cities-reverse-course-on-automated-license-plate-reader-cameras
Louvre Jewel Heist
https://www.schneier.com/blog/archives/2025/10/louvre-jewel-heist.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
https://www.trendmicro.com/en_us/research/25/j/active-water-saci-campaign-whatsapp-update.html
CISA releases warning about Windows Server Update Service bug, orders agencies to patch
https://therecord.media/wsus-vulnerability-cisa-late-friday-warning
Sweden’s power grid operator confirms data breach claimed by ransomware gang
https://therecord.media/sweden-power-grid-operator-data
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/
Cities reverse course on automated license plate reader cameras amid privacy concerns
https://therecord.media/cities-reverse-course-on-automated-license-plate-reader-cameras
Louvre Jewel Heist
https://www.schneier.com/blog/archives/2025/10/louvre-jewel-heist.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Trend Micro
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
Continuous investigation on the Water Saci campaign reveals innovative email-based C&C system, multi-vector persistence, and real-time command capabilities that allow attackers to orchestrate coordinated botnet operations, gather detailed campaign intelligence…
Top Security News for Today
Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses
https://www.darknet.org.uk/2025/10/deepfake-as-a-service-2025-how-voice-cloning-and-synthetic-media-fraud-are-changing-enterprise-defenses/
404 to arbitrary file read in WSO2 API Manager (CVE-2025-2905)
https://www.reddit.com/r/netsec/comments/1oi416x/404_to_arbitrary_file_read_in_wso2_api_manager/
Crafting self masking functions using LLVM
https://www.reddit.com/r/netsec/comments/1oi3jnm/crafting_self_masking_functions_using_llvm/
Improving E-commerce Search with Category-Aligned Retrieval
https://arxiv.org/abs/2510.21710
Social Engineering People’s Credit Card Details
https://www.schneier.com/blog/archives/2025/10/social-engineering-peoples-credit-card-details.html
New Android malware mimics human typing to evade detection, steal money
https://therecord.media/android-malware-mimics-humans-avoid-detection
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses
https://www.darknet.org.uk/2025/10/deepfake-as-a-service-2025-how-voice-cloning-and-synthetic-media-fraud-are-changing-enterprise-defenses/
404 to arbitrary file read in WSO2 API Manager (CVE-2025-2905)
https://www.reddit.com/r/netsec/comments/1oi416x/404_to_arbitrary_file_read_in_wso2_api_manager/
Crafting self masking functions using LLVM
https://www.reddit.com/r/netsec/comments/1oi3jnm/crafting_self_masking_functions_using_llvm/
Improving E-commerce Search with Category-Aligned Retrieval
https://arxiv.org/abs/2510.21710
Social Engineering People’s Credit Card Details
https://www.schneier.com/blog/archives/2025/10/social-engineering-peoples-credit-card-details.html
New Android malware mimics human typing to evade detection, steal money
https://therecord.media/android-malware-mimics-humans-avoid-detection
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Darknet - Hacking Tools, Hacker News & Cyber Security
Deepfake-as-a-Service 2025 - How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses
Deepfake-as-a-Service 2025. How voice cloning and synthetic media fraud hit enterprises, with case studies, detection tactics, and CISO actions.
Top Security News for Today
Living off the land' allowed Russia-linked group to breach Ukrainian entities this summer
https://therecord.media/russia-linked-breaches-ukraine-living-off-the-land
Attacker Target VSCode Extension Marketplace, IDE Plugins Face Higher Supply Chain Attack Risks
https://www.reddit.com/r/netsec/comments/1oiw00r/attacker_target_vscode_extension_marketplace_ide/
Cloud Atlas hackers target Russian agriculture sector ahead of industry forum
https://therecord.media/cloud-atlas-targets-russian-agriculture
More than 10 million impacted by breach of government contractor Conduent
https://therecord.media/millions-impacted-breach-conduent
Former Trenchant exec pleads guilty to selling cyber exploits to Russian broker
https://therecord.media/trenchant-exec-pleads-guilty-russia-secrets
Signal’s Post-Quantum Cryptographic Implementation
https://www.schneier.com/blog/archives/2025/10/signals-post-quantum-cryptographic-implementation.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Living off the land' allowed Russia-linked group to breach Ukrainian entities this summer
https://therecord.media/russia-linked-breaches-ukraine-living-off-the-land
Attacker Target VSCode Extension Marketplace, IDE Plugins Face Higher Supply Chain Attack Risks
https://www.reddit.com/r/netsec/comments/1oiw00r/attacker_target_vscode_extension_marketplace_ide/
Cloud Atlas hackers target Russian agriculture sector ahead of industry forum
https://therecord.media/cloud-atlas-targets-russian-agriculture
More than 10 million impacted by breach of government contractor Conduent
https://therecord.media/millions-impacted-breach-conduent
Former Trenchant exec pleads guilty to selling cyber exploits to Russian broker
https://therecord.media/trenchant-exec-pleads-guilty-russia-secrets
Signal’s Post-Quantum Cryptographic Implementation
https://www.schneier.com/blog/archives/2025/10/signals-post-quantum-cryptographic-implementation.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
'Living off the land' allowed Russia-linked group to breach Ukrainian entities this summer
In two separate incidents this summer, hackers appearing to work from Russia used available assets to steal data from a large Ukrainian business services company and a local government agency, researchers say.
Top Security News for Today
The AI-Designed Bioweapon Arms Race
https://www.schneier.com/blog/archives/2025/10/the-ai-designed-bioweapon-arms-race.html
Zendesk's Anonymous Authentication exploited for Email Spam
https://www.reddit.com/r/netsec/comments/1ogc9o6/zendesks_anonymous_authentication_exploited_for/
Invasion of the Face Changers: Halloween Hijinks with Bluetooth LED Masks
https://bishopfox.com/blog/invasion-of-the-face-changers-halloween-hijinks-with-bluetooth-led-masks
What Security Teams Need to Know as PHP and IoT Exploits Surge
https://blog.qualys.com/vulnerabilities-threat-research/2025/10/30/what-security-teams-need-to-know-as-php-and-iot-exploits-surge
Business rival credits cyberattack on M&S for boosting profits
https://therecord.media/next-clothing-retailer-reports-profits-boosted-post-ms-cyberattack
How we found +2k vulns, 400+ secrets and 175 PII instances in publicly exposed apps built on vibe-coded platforms (Research methodology)
https://www.reddit.com/r/netsec/comments/1ok3ffd/how_we_found_2k_vulns_400_secrets_and_175_pii/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
The AI-Designed Bioweapon Arms Race
https://www.schneier.com/blog/archives/2025/10/the-ai-designed-bioweapon-arms-race.html
Zendesk's Anonymous Authentication exploited for Email Spam
https://www.reddit.com/r/netsec/comments/1ogc9o6/zendesks_anonymous_authentication_exploited_for/
Invasion of the Face Changers: Halloween Hijinks with Bluetooth LED Masks
https://bishopfox.com/blog/invasion-of-the-face-changers-halloween-hijinks-with-bluetooth-led-masks
What Security Teams Need to Know as PHP and IoT Exploits Surge
https://blog.qualys.com/vulnerabilities-threat-research/2025/10/30/what-security-teams-need-to-know-as-php-and-iot-exploits-surge
Business rival credits cyberattack on M&S for boosting profits
https://therecord.media/next-clothing-retailer-reports-profits-boosted-post-ms-cyberattack
How we found +2k vulns, 400+ secrets and 175 PII instances in publicly exposed apps built on vibe-coded platforms (Research methodology)
https://www.reddit.com/r/netsec/comments/1ok3ffd/how_we_found_2k_vulns_400_secrets_and_175_pii/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Schneier on Security
The AI-Designed Bioweapon Arms Race - Schneier on Security
Interesting article about the arms race between AI systems that invent/design new biological pathogens, and AI systems that detect them before they’re created: The team started with a basic test: use AI tools to design variants of the toxin ricin, then test…
Top Security News for Today
Alleged Conti ransomware gang affiliate appears in Tennessee court after Ireland extradition
https://therecord.media/alleged-conti-ransomware-affiliate-extradited-ireland-tennessee
Three suspected developers of Meduza Stealer malware arrested in Russia
https://therecord.media/meduza-stealer-malware-suspected-developers-arrested-russia
Sling TV settles with California for allegedly violating state consumer privacy law
https://therecord.media/sling-tv-california-data-protection-settlement
CFPB ends probe into Meta’s financial data advertising practices
https://therecord.media/cfpb-meta-probe-advertising
Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide
https://therecord.media/chinese-hackers-scan-exploit-firewalls-government
FCC plans vote to remove cyber regulations installed after theft of Trump info from telecoms
https://therecord.media/fcc-plans-vote-rescind-biden-era-ruling-telecoms-cyber
Will AI Strengthen or Undermine Democracy?
https://www.schneier.com/blog/archives/2025/10/will_ai_strengthen_or_undermine_democracy.html
Evaluating Argon2 Adoption and Effectiveness in Real-World Software
https://arxiv.org/abs/2504.17121
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Alleged Conti ransomware gang affiliate appears in Tennessee court after Ireland extradition
https://therecord.media/alleged-conti-ransomware-affiliate-extradited-ireland-tennessee
Three suspected developers of Meduza Stealer malware arrested in Russia
https://therecord.media/meduza-stealer-malware-suspected-developers-arrested-russia
Sling TV settles with California for allegedly violating state consumer privacy law
https://therecord.media/sling-tv-california-data-protection-settlement
CFPB ends probe into Meta’s financial data advertising practices
https://therecord.media/cfpb-meta-probe-advertising
Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide
https://therecord.media/chinese-hackers-scan-exploit-firewalls-government
FCC plans vote to remove cyber regulations installed after theft of Trump info from telecoms
https://therecord.media/fcc-plans-vote-rescind-biden-era-ruling-telecoms-cyber
Will AI Strengthen or Undermine Democracy?
https://www.schneier.com/blog/archives/2025/10/will_ai_strengthen_or_undermine_democracy.html
Evaluating Argon2 Adoption and Effectiveness in Real-World Software
https://arxiv.org/abs/2504.17121
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Alleged Conti ransomware gang affiliate appears in Tennessee court after Ireland extradition
Ukrainian national Oleksii Oleksiyovych Lytvynenko faces charges in the U.S. related to his alleged involvement with the Conti cybercrime operation, which attacked hundreds of organizations globally before disbanding in 2022.
Top Security News for Today
EDR-Redir V2: Blind EDR With Fake "Program Files"
https://www.reddit.com/r/netsec/comments/1olkuwg/edrredir_v2_blind_edr_with_fake_program_files/
Open Source CVE Scanner for Project Dependencies
https://www.reddit.com/r/netsec/comments/1olpb18/open_source_cve_scanner_for_project_dependencies/
r/netsec Monthly Discussion & Tool Thread
https://www.reddit.com/r/netsec/comments/1olp81v/rnetsec_monthly_discussion_tool_thread/
Quantifying Swiss Cheese, the Bayesian Way
https://www.reddit.com/r/netsec/comments/1oluzam/quantifying_swiss_cheese_the_bayesian_way/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
EDR-Redir V2: Blind EDR With Fake "Program Files"
https://www.reddit.com/r/netsec/comments/1olkuwg/edrredir_v2_blind_edr_with_fake_program_files/
Open Source CVE Scanner for Project Dependencies
https://www.reddit.com/r/netsec/comments/1olpb18/open_source_cve_scanner_for_project_dependencies/
r/netsec Monthly Discussion & Tool Thread
https://www.reddit.com/r/netsec/comments/1olp81v/rnetsec_monthly_discussion_tool_thread/
Quantifying Swiss Cheese, the Bayesian Way
https://www.reddit.com/r/netsec/comments/1oluzam/quantifying_swiss_cheese_the_bayesian_way/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: EDR-Redir V2: Blind EDR With Fake "Program Files"
Explore this post and more from the netsec community
Top Security News for Today
MCP Scanner - Python MCP Scanner for Prompt-Injection and Insecure Agents
https://www.darknet.org.uk/2025/10/mcp-scanner-python-mcp-scanner-for-prompt-injection-and-insecure-agents/
Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
https://research.checkpoint.com/2025/drawn-to-danger-windows-graphics-vulnerabilities-lead-to-remote-code-execution-and-memory-exposure/
Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody
https://krebsonsecurity.com/2025/11/alleged-jabber-zeus-coder-mricq-in-u-s-custody/
Steal MS Teams app cookies
https://www.reddit.com/r/netsec/comments/1omuz9a/steal_ms_teams_app_cookies/
Quick writeup for what to check when you see Firebase in a pentest
https://www.reddit.com/r/netsec/comments/1on6yjx/quick_writeup_for_what_to_check_when_you_see/firebase_in_a_pentest/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
MCP Scanner - Python MCP Scanner for Prompt-Injection and Insecure Agents
https://www.darknet.org.uk/2025/10/mcp-scanner-python-mcp-scanner-for-prompt-injection-and-insecure-agents/
Drawn to Danger: Windows Graphics Vulnerabilities Lead to Remote Code Execution and Memory Exposure
https://research.checkpoint.com/2025/drawn-to-danger-windows-graphics-vulnerabilities-lead-to-remote-code-execution-and-memory-exposure/
Alleged Jabber Zeus Coder ‘MrICQ’ in U.S. Custody
https://krebsonsecurity.com/2025/11/alleged-jabber-zeus-coder-mricq-in-u-s-custody/
Steal MS Teams app cookies
https://www.reddit.com/r/netsec/comments/1omuz9a/steal_ms_teams_app_cookies/
Quick writeup for what to check when you see Firebase in a pentest
https://www.reddit.com/r/netsec/comments/1on6yjx/quick_writeup_for_what_to_check_when_you_see/firebase_in_a_pentest/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Darknet - Hacking Tools, Hacker News & Cyber Security
mcp-scanner - Python MCP Scanner for Prompt-Injection and Insecure Agents
mcp-scanner: Python tool to scan Model Context Protocol servers for prompt injection, jailbreaks, and insecure tool patterns.
Top Security News for Today
Hackers are attacking Britain’s drinking water suppliers
https://therecord.media/britain-water-supply-cybersecurity-incident-reports-dwi-nis
Beating XLoader at Speed: Generative AI as a Force Multiplier for Reverse Engineering
https://research.checkpoint.com/2025/generative-ai-for-reverse-engineering/
Japanese retailer Askul confirms data leak after cyberattack claimed by Russia-linked group
https://therecord.media/askul-confirms-data-breach-ransomware-incident
Inside an Automotive Giant’s Data Leak — A Cloud Misconfiguration Lesson for AWS Users
https://blog.qualys.com/product-tech/2025/11/03/inside-an-automotive-giants-data-leak-a-cloud-misconfiguration-lesson-for-aws-users
Data breach costs lead to 90% drop in operating profit at South Korean telecom giant
https://therecord.media/data-breach-costs-lead-to-profit-decline-south-korea-telecom
Cargo theft gets a boost from hackers using remote monitoring tools
https://therecord.media/cargo-theft-hackers-remote-monitoring-tools
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Hackers are attacking Britain’s drinking water suppliers
https://therecord.media/britain-water-supply-cybersecurity-incident-reports-dwi-nis
Beating XLoader at Speed: Generative AI as a Force Multiplier for Reverse Engineering
https://research.checkpoint.com/2025/generative-ai-for-reverse-engineering/
Japanese retailer Askul confirms data leak after cyberattack claimed by Russia-linked group
https://therecord.media/askul-confirms-data-breach-ransomware-incident
Inside an Automotive Giant’s Data Leak — A Cloud Misconfiguration Lesson for AWS Users
https://blog.qualys.com/product-tech/2025/11/03/inside-an-automotive-giants-data-leak-a-cloud-misconfiguration-lesson-for-aws-users
Data breach costs lead to 90% drop in operating profit at South Korean telecom giant
https://therecord.media/data-breach-costs-lead-to-profit-decline-south-korea-telecom
Cargo theft gets a boost from hackers using remote monitoring tools
https://therecord.media/cargo-theft-hackers-remote-monitoring-tools
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
therecord.media
Hackers are attacking Britain’s drinking water suppliers
The U.K.'s water suppliers have reported five cyberattacks since January 2024, according to information reviewed by Recorded Future News. The incidents did not affect the safety of water supplies, but they highlight an increasing threat.
Top Security News for Today
Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed
https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/
Cybercriminals Targeting Payroll Sites
https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html
RondoDox v2: A 650% Expansion in Exploits
https://www.reddit.com/r/netsec/comments/1oo2qag/new_research_rondodox_v2_a_650_expansion_in/
GitLab Runner Research – PoC for Abusing Self-Hosted GitLab Runners
https://www.darknet.org.uk/2025/11/gitlab-runner-research-poc-for-abusing-self-hosted-gitlab-runners/
Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
https://therecord.media/health-privacy-bill-seeks-protections-apps-smartwatches
9 Arrested in Europe in Operation Against Fake Platforms for Crypto Investments
https://therecord.media/9-arrested-europe-crypto-platform-takedown
Learn What Generative AI Can Do for Your Security Operations Center
https://www.microsoft.com/en-us/security/blog/2025/11/04/learn-what-generative-ai-can-do-for-your-security-operations-center-soc/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed
https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/
Cybercriminals Targeting Payroll Sites
https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html
RondoDox v2: A 650% Expansion in Exploits
https://www.reddit.com/r/netsec/comments/1oo2qag/new_research_rondodox_v2_a_650_expansion_in/
GitLab Runner Research – PoC for Abusing Self-Hosted GitLab Runners
https://www.darknet.org.uk/2025/11/gitlab-runner-research-poc-for-abusing-self-hosted-gitlab-runners/
Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
https://therecord.media/health-privacy-bill-seeks-protections-apps-smartwatches
9 Arrested in Europe in Operation Against Fake Platforms for Crypto Investments
https://therecord.media/9-arrested-europe-crypto-platform-takedown
Learn What Generative AI Can Do for Your Security Operations Center
https://www.microsoft.com/en-us/security/blog/2025/11/04/learn-what-generative-ai-can-do-for-your-security-operations-center-soc/
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Check Point Research
Exploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed Microsoft Teams Vulnerabilities Uncovered
By Andrey Charikov and Oded Vanunu Key Findings: Launched in March 2017, Microsoft Teams has become one of the most widely used communication and collaboration platforms in the world. As part of the Microsoft 365 family, Teams provides workplaces with chat…
Top Security News for Today
How an Attacker Drained $128M from Balancer Through Rounding Error Exploitation
https://research.checkpoint.com/2025/how-an-attacker-drained-128m-from-balancer-through-rounding-error-exploitation/
New malware uses AI to adapt during attacks, report finds
https://therecord.media/new-malware-uses-ai-to-adapt
Russia-linked 'Curly COMrades' turn to malicious virtual machines for digital spy campaigns
https://therecord.media/virtual-machines-cyber-espionage-russia-linked-curly-comrades
Japan’s Nikkei reports Slack breach exposing employee and partner records
https://therecord.media/japan-nikkei-slack-breach
Cyberattack ate up profits for first half of year, retailer M&S says
https://therecord.media/marks-spencer-profits-wiped-out-cyberattack
Scientists Need a Positive Vision for AI
https://www.schneier.com/blog/archives/2025/11/scientists-need-a-positive-vision-for-ai.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
How an Attacker Drained $128M from Balancer Through Rounding Error Exploitation
https://research.checkpoint.com/2025/how-an-attacker-drained-128m-from-balancer-through-rounding-error-exploitation/
New malware uses AI to adapt during attacks, report finds
https://therecord.media/new-malware-uses-ai-to-adapt
Russia-linked 'Curly COMrades' turn to malicious virtual machines for digital spy campaigns
https://therecord.media/virtual-machines-cyber-espionage-russia-linked-curly-comrades
Japan’s Nikkei reports Slack breach exposing employee and partner records
https://therecord.media/japan-nikkei-slack-breach
Cyberattack ate up profits for first half of year, retailer M&S says
https://therecord.media/marks-spencer-profits-wiped-out-cyberattack
Scientists Need a Positive Vision for AI
https://www.schneier.com/blog/archives/2025/11/scientists-need-a-positive-vision-for-ai.html
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Check Point Research
How an Attacker Drained $128M from Balancer Through Rounding Error Exploitation - Check Point Research
By: Dikla Barda, Roaman Zaikin & Oded Vanunu On November 3, 2025, Check Point Research’s blockchain monitoring systems detected a sophisticated exploit targeting Balancer V2’s ComposableStablePool contracts. The attacker exploited arithmetic precision loss…
Top Security News for Today
I built Ashes CTI: a dual-mode (CLI + UI) Threat Intelligence platform for Windows
https://www.reddit.com/r/netsec/comments/1opw4a9/i_built_ashes_cti_a_dualmode_cli_ui_threat/
Russia’s Sandworm hackers deploying wipers against Ukraine’s grain industry
https://therecord.media/russia-sandworm-grain-wipers
Evading Elastic EDR's call stack signatures with call gadgets
https://www.reddit.com/r/netsec/comments/1opyr37/evading_elastic_edrs_call_stack_signatures_with/
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
https://www.reddit.com/r/netsec/comments/1oq1ia4/leakyinjector_and_leakystealer_duo_hunts_for/
New IDC research highlights a major cloud security shift
https://www.microsoft.com/en-us/security/blog/2025/11/06/new-idc-research-highlights-a-major-cloud-security-shift/
Italian communications executive reveals he was targeted with Paragon spyware
https://therecord.media/italy-comms-exec-spyware
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
I built Ashes CTI: a dual-mode (CLI + UI) Threat Intelligence platform for Windows
https://www.reddit.com/r/netsec/comments/1opw4a9/i_built_ashes_cti_a_dualmode_cli_ui_threat/
Russia’s Sandworm hackers deploying wipers against Ukraine’s grain industry
https://therecord.media/russia-sandworm-grain-wipers
Evading Elastic EDR's call stack signatures with call gadgets
https://www.reddit.com/r/netsec/comments/1opyr37/evading_elastic_edrs_call_stack_signatures_with/
LeakyInjector and LeakyStealer Duo Hunts For Crypto and Browser History
https://www.reddit.com/r/netsec/comments/1oq1ia4/leakyinjector_and_leakystealer_duo_hunts_for/
New IDC research highlights a major cloud security shift
https://www.microsoft.com/en-us/security/blog/2025/11/06/new-idc-research-highlights-a-major-cloud-security-shift/
Italian communications executive reveals he was targeted with Paragon spyware
https://therecord.media/italy-comms-exec-spyware
Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
From the netsec community on Reddit: I built Ashes CTI: a dual-mode (CLI + UI) Threat Intelligence platform for Windows
Explore this post and more from the netsec community