Top Daily Cyber Security News – Telegram
Top Daily Cyber Security News
721 subscribers
717 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

The Role of Humans in an AI-Powered World
https://www.schneier.com/blog/archives/2025/11/the-role-of-humans-in-an-ai-powered-world.html

🚨 FIRST PUBLIC EVIDENCE: RedTail Cryptominer Targets Docker APIs
https://www.reddit.com/r/netsec/comments/1owqjcx/first_public_evidence_redtail_cryptominer_targets/

Khmer Spellchecking: A Holistic Approach
https://arxiv.org/abs/2511.09582

When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb (??) Auth. Bypass) - watchTowr Labs
https://www.reddit.com/r/netsec/comments/1owxxey/when_the_impersonation_function_gets_used_to/

Civil society decries digital rights ‘rollback' as European Commission pushes data protection changes
https://therecord.media/civil-society-privacy-rollback

Chinese state hackers used Anthropic AI systems in dozens of attacks
https://therecord.media/chinese-hackers-anthropic-cyberattacks

Upcoming Speaking Engagements
https://www.schneier.com/blog/archives/2025/11/upcoming-speaking-engagements-50.html

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild
https://blog.qualys.com/vulnerabilities-threat-research/2025/11/14/unauthenticated-authentication-bypass-in-fortinet-fortiweb-cve-2025-64446-exploited-in-the-wild

Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million
https://therecord.media/multiple-us-nationals-guilty-pleas-north-korean-it-worker-scams

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Initial Access Brokers (IAB) in 2025 – From Dark Web Listings to Supply Chain Ransomware Events
https://www.darknet.org.uk/2025/11/initial-access-brokers-iab-in-2025-from-dark-web-listings-to-supply-chain-ransomware-events/

Claude AI ran autonomous espionage operations
https://www.reddit.com/r/netsec/comments/1oyis0z/claude_ai_ran_autonomous_espionage_operations/

NPMScan - Malicious NPM Package Detection & Security Scanner
https://www.reddit.com/r/netsec/comments/1oy1p2v/npmscan_malicious_npm_package_detection_security/

Trying to make CCNA learning more engaging for students
https://www.reddit.com/r/netsec/comments/1oyrn4t/trying_to_make_ccna_learning_more_engaging_for/

Microsoft Patch Tuesday, November 2025 Edition
https://krebsonsecurity.com/2025/11/microsoft-patch-tuesday-november-2025-edition/

mcp-scan – Real-Time Guardrail Monitoring and Dynamic Proxy for MCP Servers
https://www.darknet.org.uk/2025/11/mcp-scan-real-time-guardrail-monitoring-and-dynamic-proxy-for-mcp-servers/

what do you guys think of this undocumented behavior of "web for pentester 1?"
https://www.reddit.com/r/netsec/comments/1oz3zq7/what_do_you_guys_think_of_this_undocumented/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Gotchas in Email Parsing - Lessons from Jakarta Mail
https://www.reddit.com/r/netsec/comments/1p084xf/gotchas_in_email_parsing_lessons_from_jakarta_mail/

AI and Voter Engagement
https://www.schneier.com/blog/archives/2025/11/ai-and-voter-engagement.html

Full renewal of state and local cyber grants program passes in House
https://therecord.media/state-local-cyber-grants-program-house-passage

Breaking Down S3 Ransomware: Variants, Attack Paths and Trend Vision One Defenses
https://www.trendmicro.com/en_us/research/25/k/s3-ransomware.html

MI5 warns of Chinese spies using LinkedIn to gain intel on lawmakers
https://therecord.media/mi5-warns-chinese-spies-using-linkedin-lawmakers

Russian suspect detained in Thailand is allegedly tied to Void Blizzard group
https://therecord.media/russian-arrested-thailand-allegedly-void-blizzard-apt-member

Ambient and autonomous security for the agentic era
https://www.microsoft.com/en-us/security/blog/2025/11/18/ambient-and-autonomous-security-for-the-agentic-era/

Agents built into your workflow: Get Security Copilot with Microsoft 365 E5
https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/

Threat Actor "888" Claims LG Electronics Data Breach - Source Code and Hardcoded Credentials Allegedly Leaked [Unconfirmed]
https://www.reddit.com/r/netsec/comments/1p0ho9s/threat_actor_888_claims_lg_electronics_data/

ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet | Oligo Security
https://www.reddit.com/r/netsec/comments/1p0evgu/shadowray_20_active_global_campaign_hijacks_ray/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

China-aligned threat actor is conducting widespread cyberespionage campaigns
https://therecord.media/china-aligned-threat-actor-espionage-network-devices

IT threat evolution in Q3 2025. Mobile statistics
https://securelist.com/malware-report-q3-2025-mobile-statistics/118013/

IT threat evolution in Q3 2025. Non-mobile statistics
https://securelist.com/malware-report-q3-2025-pc-iot-statistics/118020/

Legal Restrictions on Vulnerability Disclosure
https://www.schneier.com/blog/archives/2025/11/legal-restrictions-on-vulnerability-disclosure.html

The Cloudflare Outage May Be a Security Roadmap
https://krebsonsecurity.com/2025/11/the-cloudflare-outage-may-be-a-security-roadmap/

Major Russian insurer facing widespread outages after cyberattack
https://therecord.media/russia-vsk-cyberattack-outages

European Commission ‘simplification’ proposal would weaken GDPR, AI regulations
https://therecord.media/european-commission-proposal-gdpr-ai-simplification

Canadian privacy regulators say schools share blame for PowerSchool hack
https://therecord.media/canadian-privacy-regulators-say-schools-share-blame-powerschool-hack

Fortinet FortiWeb Authentication Bypass – CVE-2025-64446
https://bishopfox.com/blog/fortinet-fortiweb-authentication-bypass-cve-2025-64446

US, allies sanction Russian bulletproof hosting services for ransomware support
https://therecord.media/bulletproof-hosting-sanctions-ransomware

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Scam USPS and E-Z Pass Texts and Websites
https://www.schneier.com/blog/archives/2025/11/scam-usps-and-e-z-pass-texts-and-websites.html

Blockchain and Node.js abused by Tsundere: an emerging botnet
https://securelist.com/tsundere-node-js-botnet-uses-ethereum-blockchain/117979/

Inside the dark web job market
https://securelist.com/dark-web-job-market-2023-2025/118057/

Samourai Wallet crypto mixer’s co-founders sentenced to prison
https://therecord.media/samourai-wallet-crypto-mixer-founders-sentenced

Russia blacklists S.T.A.L.K.E.R. game developer, accusing it of aiding Ukraine’s war effort
https://therecord.media/russia-blacklists-stalker-game-developer

FCC spikes Biden-era cyber regulations prompted by Salt Typhoon telecom breaches
https://therecord.media/fcc-removes-biden-era-cybersecurity-rules-telecoms-salt-typhoon

New Android malware can capture private messages, researchers warn
https://therecord.media/new-android-malware-captures-private-messages

Esbuild XSS Bug That Survived 5B Downloads and Bypassed HTML Sanitization
https://www.reddit.com/r/netsec/comments/1p2jinz/esbuild_xss_bug_that_survived_5b_downloads_and/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Two suspected Scattered Spider hackers plead not guilty over Transport for London cyberattack
https://therecord.media/transport-for-london-hack-scattered-spider-suspects-plead-not-guilty

Eguard: Defending LLM Embeddings Against Inversion Attacks via Text Mutual Information Optimization
https://arxiv.org/abs/2511.15712

Majority Rules: LLM Ensemble is a Winning Approach for Content Categorization
https://arxiv.org/abs/2511.15730

Microsoft named a Leader in the Gartner® Magic Quadrant for Access Management for the ninth consecutive year
https://www.microsoft.com/en-us/security/blog/2025/11/21/microsoft-named-a-leader-in-the-gartner-magic-quadrant-for-access-management-for-the-ninth-consecutive-year/

China’s APT31 linked to hacks on Russian tech firms
https://therecord.media/russia-report-apt31-china-linked-hacks

Flock Safety cameras used to monitor protesters, rights group finds
https://therecord.media/flock-safety-rights-group-eff

Sliver C2 vulnerability enables attack on C2 operators through insecure Wireguard network
https://www.reddit.com/r/netsec/comments/1p2yexv/sliver_c2_vulnerability_enables_attack_on_c2/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

SmbCrawler – SMB Share Discovery and Secret-Hunting
https://www.darknet.org.uk/2025/11/smbcrawler-smb-share-discovery-and-secret-hunting/

I Analysed Over 3 Million Exposed Databases Using Netlas
https://www.reddit.com/r/netsec/comments/1p4jcmz/i_analysed_over_3_million_exposed_databases_using/

NocturneNotes — Secure Rust + GTK4 note‑taking with AES‑256‑GCM
https://www.reddit.com/r/netsec/comments/1p4k2p2/nocturnenotes_secure_rust_gtk4_notetaking_with/

Hitchhiker's Guide to Attack Surface Management
https://www.reddit.com/r/netsec/comments/1p4c2ih/hitchhikers_guide_to_attack_surface_management/

[Tool] Native JSONL viewer for analyzing massive security logs (Suricata, Zeek, EDR) without infrastructure overhead
https://www.reddit.com/r/netsec/comments/1p4fzrc/tool_native_jsonl_viewer_for_analyzing_massive/

The First Autonomous AI Cyberattack: Why SaaS Security Must Change
https://www.reddit.com/r/netsec/comments/1p4mx4j/the_first_autonomous_ai_cyberattack_why_saas/

A Reverse Engineer’s Anatomy of the macOS Boot Chain & Security Architecture
https://www.reddit.com/r/netsec/comments/1p54ody/a_reverse_engineers_anatomy_of_the_macos_boot/

Good and well-renowned Universities Worldwide for Master’s in Infosec (Preferably Europe - Public Universities; Open to Other countries/continents)
https://www.reddit.com/r/netsec/comments/1p53n9s/good_and_wellrenowned_universities_worldwide_for/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
https://www.reddit.com/r/netsec/comments/1p69p56/stop_putting_your_passwords_into_random_websites/

Four Ways AI Is Being Used to Strengthen Democracies Worldwide
https://www.schneier.com/blog/archives/2025/11/four-ways-ai-is-being-used-to-strengthen-democracies-worldwide.html

How to Expand a Self-orthogonal Code
https://arxiv.org/abs/2511.17503

Covert Communication and Key Generation Over Quantum State-Dependent Channels
https://arxiv.org/abs/2511.17504

Causal Intervention Sequence Analysis for Fault Tracking in Radio Access Networks
https://arxiv.org/abs/2511.17505

AURA: Adaptive Unified Reasoning and Automation with LLM-Guided MARL for NextG Cellular Networks
https://arxiv.org/abs/2511.17506

The use of artificial intelligence in music creation: between interface and appropriation
https://arxiv.org/abs/2511.17507

Charting the future of SOC: Human and AI collaboration for better security
https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/charting-the-future-of-soc-human-and-ai-collaboration-for-better-security/4470688

Systemic Ransomware Events in 2025 – How Jaguar Land Rover Showed What a Category 3 Supply Chain Breach Looks Like
https://www.darknet.org.uk/2025/11/systemic-ransomware-events-in-2025-how-jaguar-land-rover-showed-what-a-category-3-supply-chain-breach-looks-like/

$262 million stolen in account takeover fraud schemes this year, FBI says ahead of holiday season
https://therecord.media/millions-in-account-takeover-fbi-warns-ahead-of-holidays/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyber ‘issue’ hits three London councils with shared IT services
https://therecord.media/cyber-issue-london-councils-attack

Municipal emergency warning service offline after hackers steal user data
https://therecord.media/emergency-warning-service-offline

Hackers exploit 3D design software to target game developers, animators
https://therecord.media/hackers-blender-software-malware

Thailand bans World iris scans, orders company to delete data
https://therecord.media/thailand-world-iris-scans-ban

Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/

House Energy and Commerce Committee unveils new draft children’s online safety bill
https://therecord.media/house-commttee-unveils-new-kosa-bill

At least 35,000 impacted by Dartmouth College breach through Oracle EBS campaign
https://therecord.media/dartmouth-data-breach-thousands

We made a new tool, QuicDraw(H3), because HTTP/3 race condition testing is currently trash.
https://www.reddit.com/r/netsec/comments/1p71ntk/we_made_a_new_tool_quicdrawh3_because_http3_race/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Tomiris wreaks Havoc: New tools and techniques of the APT group
https://securelist.com/tomiris-new-tools/118143/

Shai-hulud 2.0 Campaign Targets Cloud and Developer Ecosystems
https://www.trendmicro.com/en_us/research/25/k/shai-hulud-2-0-targets-cloud-and-developer-systems.html

Poland detains Russian citizen suspected of hacking local firms
https://therecord.media/poland-detains-russian-citizen-accused-of-hacks

Taking down Next.js servers for 0.0001 cents a pop
https://www.reddit.com/r/netsec/comments/1p7ou7q/taking_down_nextjs_servers_for_00001_cents_a_pop/

Desktop Application Security Verification Standard - DASVS
https://www.reddit.com/r/netsec/comments/1p7fgts/desktop_application_security_verification/

Prepared Statements? Prepared to Be Vulnerable.
https://www.reddit.com/r/netsec/comments/1p7kdlz/prepared_statements_prepared_to_be_vulnerable/

The minefield between syntaxes: exploiting syntax confusions in the wild
https://www.reddit.com/r/netsec/comments/1p89lx1/the_minefield_between_syntaxes_exploiting_syntax/

Write Path Traversal to a RCE Art Department
https://www.reddit.com/r/netsec/comments/1p8hxad/write_path_traversal_to_a_rce_art_department/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

A Longitudinal Measurement of Privacy Policy Evolution for Large Language Models
https://arxiv.org/abs/2511.21758

Adaptive Detection of Polymorphic Malware: Leveraging Mutation Engines and YARA Rules for Enhanced Security
https://arxiv.org/abs/2511.21764

Categorical Framework for Quantum-Resistant Zero-Trust AI Security
https://arxiv.org/abs/2511.21768

Advanced Data Collection Techniques in Cloud Security: A Multi-Modal Deep Learning Autoencoder Approach
https://arxiv.org/abs/2511.21795

Cross-Layer Detection of Wireless Misbehavior Using 5G RAN Telemetry and Operational Metadata
https://arxiv.org/abs/2511.21803

1st December – Threat Intelligence Report
https://research.checkpoint.com/2025/1st-december-threat-intelligence-report/

PortSwigger x TryHackMe: Supporting Advent of Cyber
https://portswigger.net/blog/portswigger-x-tryhackme-supporting-advent-of-cyber

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Data breach hits 'South Korea's Amazon,' potentially affecting 65% of country’s population
https://therecord.media/coupang-south-korea-data-breach

Banning VPNs
https://www.schneier.com/blog/archives/2025/12/banning-vpns.html

Edtech company settles with FTC in wake of data breach
https://therecord.media/illuminate-education-data-breach-settlement-ftc

Officials accuse North Korea’s Lazarus of $30 million theft from crypto exchange
https://therecord.media/officials-accuse-north-korea-hackers-of-attack-on-crypto-exchange

Designing a Multimodal Viewer for Piano Performance Analysis -- a Pedagogy-First Approach
https://arxiv.org/abs/2511.21693

A Survey of Information Disorder on Video-Sharing Platforms
https://arxiv.org/abs/2511.21694

EvalCards: A Framework for Standardized Evaluation Reporting
https://arxiv.org/abs/2511.21695

TIP and Polish: Text-Image-Prototype Guided Multi-Modal Generation via Commonality-Discrepancy Modeling and Refinement
https://arxiv.org/abs/2511.21697

Detail Enhanced Gaussian Splatting for Large-Scale Volumetric Capture
https://arxiv.org/abs/2511.21698

Cryptomixer platform raided by European police; $29 million in bitcoin seized
https://therecord.media/cryptomixer-service-takedown-bitcoin-seized

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Hacking the Meatmeet BBQ Probe — BLE BBQ Botnet
https://www.reddit.com/r/netsec/comments/1pcplsx/hacking_the_meatmeet_bbq_probe_ble_bbq_botnet/

PyTorch Users at Risk: Unveiling 3 Zero-Day PickleScan Vulnerabilities
https://www.reddit.com/r/netsec/comments/1pd094r/pytorch_users_at_risk_unveiling_3_zeroday/

ValleyRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
https://www.trendmicro.com/en_us/research/25/l/valleyrat-campaign.html

University of Phoenix says 'numerous individuals' impacted by Oracle EBS breach
https://therecord.media/university-of-phoenix-data-breach

Japan’s Askul resumes limited online sales 6 weeks after ransomware attack
https://therecord.media/askul-resumes-limited-ordering-following-ransomware-attack

India backs off mandatory 'cyber safety' app after surveillance backlash
https://therecord.media/india-drops-mandate-sanchar-saathi-app-privacy-surveillance

Canadian police department becomes first to trial body cameras equipped with facial recognition technology
https://therecord.media/canadian-police-department-trials-facial-recognition-body-cameras

What Will Shape Cybersecurity in 2026: AI Speed, Expanding Attack Surfaces, and Specialized Red Teams
https://bishopfox.com/blog/what-will-shape-cybersecurity-in-2026-ai-speed-expanding-attack-surfaces-and-specialized-red-teams

68% Of Phishing Websites Are Protected by CloudFlare
https://www.reddit.com/r/netsec/comments/1pdczk2/68_of_phishing_websites_are_protected_by/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman