Top Daily Cyber Security News – Telegram
Top Daily Cyber Security News
721 subscribers
718 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

macOS Shortcuts for Initial Access
https://www.reddit.com/r/netsec/comments/1o9v6il/macos_shortcuts_for_initial_access/

Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://www.reddit.com/r/netsec/comments/1oa1dai/notice_google_gemini_ais_undisclosed_911_autodial/

CoreGuard: Safeguarding Foundational Capabilities of LLMs Against Model Stealing in Edge Deployment
https://arxiv.org/abs/2410.13903

Every Language Model Has a Forgery-Resistant Signature
https://arxiv.org/abs/2510.14086

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://reporter.deepspecter.com/CVE-2025-8941

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://reporter.deepspecter.com/DefenderWrite

CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://www.reddit.com/r/netsec/comments/1oanqes/cve20258941_critical_privilege_escalation/

DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://www.reddit.com/r/netsec/comments/1oaq5nx/defenderwrite_abusing_whitelisted_programs_for/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How a fake AI recruiter delivers five staged malware disguised as a dream job
https://www.reddit.com/r/netsec/comments/1obgnxd/how_a_fake_ai_recruiter_delivers_five_staged/

XRayC2 – Weaponizing AWS X-Ray for Covert Command and Control (C2)
https://www.darknet.org.uk/2025/10/xrayc2-weaponizing-aws-x-ray-for-covert-command-and-control-c2/

Agentic AI’s OODA Loop Problem
https://www.schneier.com/blog/archives/2025/10/agentic-ais-ooda-loop-problem.html

Evilginx’s creator reckons with the dark side of red-team tools
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast

20th October – Threat Intelligence Report
https://research.checkpoint.com/2025/20th-october-threat-intelligence-report/

Home security firm Verisure reports data breach at Swedish subsidiary
https://therecord.media/verisure-data-breach-sweden-alert-alarm-subsidiary

China claims it caught US attempting cyberattack on national time center
https://therecord.media/china-attack-national-time-center

Inside the attack chain: Threat activity targeting Azure Blob Storage
https://www.microsoft.com/en-us/security/blog/2025/10/20/inside-the-attack-chain-threat-activity-targeting-azure-blob-storage/

Tunneling WireGuard over HTTPS using Wstunnel
https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

BetterBank DeFi Protocol: Esteem Token Bonus Minting
https://securelist.com/betterbank-defi-protocol-esteem-token-bonus-minting/117822/

Post-Quantum Cryptography in 2025 – Migration Paths, Early Movers and CISO/RedTeam Impact
https://www.darknet.org.uk/2025/10/post-quantum-cryptography-in-2025-migration-paths-early-movers-and-ciso-redteam-impact/

Failures in Face Recognition
https://www.schneier.com/blog/archives/2025/10/failures-in-face-recognition.html

PhantomCaptcha' hackers impersonate Ukrainian president’s office in attack on war relief workers
https://therecord.media/phantomcaptcha-spearphishing-campaign-ukraine-war-relief-groups

Jaguar Land Rover cyberattack cost $2.5 billion, says monitoring group
https://therecord.media/jaguar-land-rover-cyberattack-economic-impact

Ransomware gang steals meeting videos, financial secrets from fence wholesaler
https://therecord.media/ransomware-gang-steals-meeting-video-fence-manufacturer

Can Burp AI hack a website? CyberMaddy explores the new agentic capabilities in Burp AI
https://portswigger.net/blog/can-burp-ai-hack-a-website-cybermaddy-explores-the-new-agentic-capabilities-in-burp-ai

Canada Fines Cybercrime Friendly Cryptomus $176M
https://krebsonsecurity.com/2025/10/canada-fines-cybercrime-friendly-cryptomus-176m/

State attorneys general stepping up privacy enforcement, watchdog finds
https://therecord.media/state-ags-enforcement-privacy-law

The security paradox of local LLMs
https://www.reddit.com/r/netsec/comments/1od7azc/the_security_paradox_of_local_llms/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
https://therecord.media/russia-food-safety-agency-rosselkhoznadzor-ddos-attack

TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://therecord.media/cybercrime-treaty-signing-hanoi

Counter Ransomware Initiative stresses importance of supply-chain security
https://therecord.media/counter-ransomware-initiative-software-supply-chain-guidance

Part Four of The Kryptos Sculpture
https://www.schneier.com/blog/archives/2025/10/part-four-of-the-kryptos-sculpture.html

A Quantum-Inspired Algorithm for Solving Sudoku Puzzles and the MaxCut Problem
https://arxiv.org/abs/2510.19835

Excitation of Looped Bistable Bands for High-Speed Linear Actuation
https://arxiv.org/abs/2510.19834

Benchmarking Reasoning Reliability in Artificial Intelligence Models for Energy-System Analysis
https://arxiv.org/abs/2510.19836

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://www.reddit.com/r/netsec/comments/1ogilto/hacking_the_world_poker_tour_inside_clubwpt_golds/

Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://www.reddit.com/r/netsec/comments/1oglfix/using_edrredir_to_break_edr_via_bind_link_and/

NetExec – Network Execution Toolkit for Windows and Active Directory
https://www.darknet.org.uk/2025/10/netexec-network-execution-toolkit-for-windows-and-active-directory/

New no nonsense platform for practice security learning
https://www.reddit.com/r/netsec/comments/1ogmqkl/new_no_nonsense_platform_for_practice_security/

YOLO detect security cameras
http://diablohorn.com/2025/10/26/yolo-detect-security-cameras/

Reaper – Unified Application Security Testing with AI Support
https://www.darknet.org.uk/2025/10/reaper-unified-application-security-testing-with-ai-support/

GlobalCVE — OpenSource Unified CVE Data from Around the World
https://www.reddit.com/r/netsec/comments/1oh4d5w/globalcve_opensource_unified_cve_data_from_around/

CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/

Vibecoding and the illusion of security
https://www.reddit.com/r/netsec/comments/1oh9mr4/vibecoding_and_the_illusion_of_security/

Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://www.reddit.com/r/netsec/comments/1oh8zn4/jettys_addpath_allows_lfi_in_windows_traccar/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
https://www.trendmicro.com/en_us/research/25/j/active-water-saci-campaign-whatsapp-update.html

CISA releases warning about Windows Server Update Service bug, orders agencies to patch
https://therecord.media/wsus-vulnerability-cisa-late-friday-warning

Sweden’s power grid operator confirms data breach claimed by ransomware gang
https://therecord.media/sweden-power-grid-operator-data

CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://www.reddit.com/r/netsec/comments/1oh8j4d/cophish_new_oauth_phishing_technique_abuses/

Cities reverse course on automated license plate reader cameras amid privacy concerns
https://therecord.media/cities-reverse-course-on-automated-license-plate-reader-cameras

Louvre Jewel Heist
https://www.schneier.com/blog/archives/2025/10/louvre-jewel-heist.html

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

The AI-Designed Bioweapon Arms Race
https://www.schneier.com/blog/archives/2025/10/the-ai-designed-bioweapon-arms-race.html

Zendesk's Anonymous Authentication exploited for Email Spam
https://www.reddit.com/r/netsec/comments/1ogc9o6/zendesks_anonymous_authentication_exploited_for/

Invasion of the Face Changers: Halloween Hijinks with Bluetooth LED Masks
https://bishopfox.com/blog/invasion-of-the-face-changers-halloween-hijinks-with-bluetooth-led-masks

What Security Teams Need to Know as PHP and IoT Exploits Surge
https://blog.qualys.com/vulnerabilities-threat-research/2025/10/30/what-security-teams-need-to-know-as-php-and-iot-exploits-surge

Business rival credits cyberattack on M&S for boosting profits
https://therecord.media/next-clothing-retailer-reports-profits-boosted-post-ms-cyberattack

How we found +2k vulns, 400+ secrets and 175 PII instances in publicly exposed apps built on vibe-coded platforms (Research methodology)
https://www.reddit.com/r/netsec/comments/1ok3ffd/how_we_found_2k_vulns_400_secrets_and_175_pii/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Alleged Conti ransomware gang affiliate appears in Tennessee court after Ireland extradition
https://therecord.media/alleged-conti-ransomware-affiliate-extradited-ireland-tennessee

Three suspected developers of Meduza Stealer malware arrested in Russia
https://therecord.media/meduza-stealer-malware-suspected-developers-arrested-russia

Sling TV settles with California for allegedly violating state consumer privacy law
https://therecord.media/sling-tv-california-data-protection-settlement

CFPB ends probe into Meta’s financial data advertising practices
https://therecord.media/cfpb-meta-probe-advertising

Chinese hackers scanning, exploiting Cisco ASA firewalls used by governments worldwide
https://therecord.media/chinese-hackers-scan-exploit-firewalls-government

FCC plans vote to remove cyber regulations installed after theft of Trump info from telecoms
https://therecord.media/fcc-plans-vote-rescind-biden-era-ruling-telecoms-cyber

Will AI Strengthen or Undermine Democracy?
https://www.schneier.com/blog/archives/2025/10/will_ai_strengthen_or_undermine_democracy.html

Evaluating Argon2 Adoption and Effectiveness in Real-World Software
https://arxiv.org/abs/2504.17121

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed
https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/

Cybercriminals Targeting Payroll Sites
https://www.schneier.com/blog/archives/2025/11/cybercriminals-targeting-payroll-sites.html

RondoDox v2: A 650% Expansion in Exploits
https://www.reddit.com/r/netsec/comments/1oo2qag/new_research_rondodox_v2_a_650_expansion_in/

GitLab Runner Research – PoC for Abusing Self-Hosted GitLab Runners
https://www.darknet.org.uk/2025/11/gitlab-runner-research-poc-for-abusing-self-hosted-gitlab-runners/

Health Privacy Bill Seeks Protections for Data Collected by Apps, Smartwatches
https://therecord.media/health-privacy-bill-seeks-protections-apps-smartwatches

9 Arrested in Europe in Operation Against Fake Platforms for Crypto Investments
https://therecord.media/9-arrested-europe-crypto-platform-takedown

Learn What Generative AI Can Do for Your Security Operations Center
https://www.microsoft.com/en-us/security/blog/2025/11/04/learn-what-generative-ai-can-do-for-your-security-operations-center-soc/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman