Top Daily Cyber Security News – Telegram
Top Daily Cyber Security News
721 subscribers
717 links
Top rated cyber security tech news,
Just the top, every day.
Download Telegram
Top Security News for Today

mini-init-asm - tiny container init (PID 1) in pure assembly (x86-64 + ARM64)
https://www.reddit.com/r/lowlevel/comments/1pggi73/miniinitasm_tiny_container_init_pid_1_in_pure/

How (almost) any phone number can be tracked via WhatsApp & Signal – open-source PoC
https://www.reddit.com/r/netsec/comments/1pgmnnn/how_almost_any_phone_number_can_be_tracked_via/

Patching Pulse Oximeter Firmware
https://www.reddit.com/r/netsec/comments/1pgmks0/patching_pulse_oximeter_firmware/

Stillepost - Or: How to Proxy your C2s HTTP-Traffic through Chromium | mischief
https://www.reddit.com/r/netsec/comments/1pgcion/stillepost_or_how_to_proxy_your_c2s_httptraffic/

Recon your patents with GenAI?
http://diablohorn.com/2025/12/07/recon-your-patents-with-genai/

AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows
https://www.trendmicro.com/en_us/research/25/l/ghostpenguin.html

Publishing Malicious VS Code Extensions: Bypassing VS Code Marketplace Analysis and the Insecurity of OpenVSX (Cursor AI/Windsurf)
https://www.reddit.com/r/netsec/comments/1ph4xb3/publishing_malicious_vs_code_extensions_bypassing/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Prompt Injection Attacks: UK Intelligence Warning
https://therecord.media/prompt-injection-attacks-uk-intelligence-warning

8th December – Threat Intelligence Report
https://research.checkpoint.com/2025/8th-december-threat-intelligence-report/

Publishing Malicious VS Code Extensions: Bypassing VS Code Marketplace Analysis and the Insecurity of OpenVSX (Cursor AI/Windsurf)
https://www.reddit.com/r/netsec/comments/1ph4xb3/publishing_malicious_vs_code_extensions_bypassing/

Free Security Canaries (SSH, AWS, Cookies, Email, more..) - Tracebit Community Edition
https://www.reddit.com/r/netsec/comments/1phcird/free_security_canaries_ssh_aws_cookies_email_more/

Russian Police Bust Bank-Account Hacking Gang that used NFCGate-based Malware
https://therecord.media/russian-police-bust-banking-hackers-nfcgate-based-malware

React2shell: Critical Vulnerability in React
https://www.reddit.com/r/netsec/comments/1phhqo8/react2shell_critical_vulnerability_in_react/

Stronger Together: New Beazley Collaboration Enhances Cyber Resilience
https://www.microsoft.com/en-us/security/blog/2025/12/08/stronger-together-new-beazley-collaboration-enhances-cyber-resilience/

Meta Proposal for Less Data Sharing is Approved by European Commission
https://therecord.media/meta-less-data-sharing-european-commission

More than $2 Billion in Payments from 4,000 Ransomware Incidents Reported to Treasury in Recent Years
https://therecord.media/fincen-treasury-2-billion-ransomware-payments-report

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Goodbye, dark Telegram: Blocks are pushing the underground out
https://securelist.com/goodbye-dark-telegram/118286/

Syd - Offline AI assistant for air-gapped security environments
https://www.reddit.com/r/netsec/comments/1pi5hhp/syd_offline_ai_assistant_for_airgapped_security/

AI vs. Human Drivers
https://www.schneier.com/blog/archives/2025/12/ai-vs-human-drivers.html

Seoul cyber investigators seize data, devices from ‘South Korea’s Amazon’ following data breach
https://therecord.media/seoul-cyber-investigators-seize-data-korea-tech-giant

Khashoggi widow files complaint in France alleging Saudi government infected devices with spyware
https://therecord.media/khashoggi-widow-legal-complaint-filed-alleging-saudi-government-spyware

Changing the physics of cyber defense
https://www.microsoft.com/en-us/security/blog/2025/12/09/changing-the-physics-of-cyber-defense/

Microsoft Patch Tuesday, December 2025 Security Update Review
https://blog.qualys.com/vulnerabilities-threat-research/2025/12/09/microsoft-patch-tuesday-december-2025-security-update-review

California man pleads guilty to RICO charges as DOJ indicts crypto theft gang
https://therecord.media/california-man-pleads-guilty-rico-charges-crypto-theft

Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack
https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
1
Top Security News for Today

FBI Warns of Fake Video Scams
https://www.schneier.com/blog/archives/2025/12/fbi-warns-of-fake-video-scams.html

Free Honey Tokens for Breach Detection - No Signup
https://www.reddit.com/r/netsec/comments/1piwp1l/free_honey_tokens_for_breach_detection_no_signup/

British government sanctions Russian and Chinese groups over information warfare
https://therecord.media/uk-sanctions-russia-china-entities-information-warfare

Detection of Cyberbullying in GIF using AI
https://arxiv.org/abs/2512.07838

ThreadWeaver: Adaptive Threading for Efficient Parallel Reasoning in Language Models
https://arxiv.org/abs/2512.07843

Impact of Data-Oriented and Object-Oriented Design on Performance and Cache Utilization with Artificial Intelligence Algorithms in Multi-Threaded CPUs
https://arxiv.org/abs/2512.07841

Space Alignment Matters: The Missing Piece for Inducing Neural Collapse in Long-Tailed Learning
https://arxiv.org/abs/2512.07844

AudioScene: Integrating Object-Event Audio into 3D Scenes
https://arxiv.org/abs/2512.07845

Senators return to effort to boost cybersecurity for commercial satellite industry
https://therecord.media/commercial-satellite-industry-cybersecurity-cornyn-peters-bill-returns

Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits
https://research.checkpoint.com/2025/cracking-valleyrat-from-builder-secrets-to-kernel-rootkits/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Following the digital trail: what happens to data stolen in a phishing attack
https://securelist.com/what-happens-to-stolen-data-after-phishing-attacks/118180/

Burp On Tour 2025: bringing the AppSec community together around the world
https://portswigger.net/blog/burp-on-tour-2025-bringing-the-appsec-community-together-around-the-world

Building Trustworthy AI Agents
https://www.schneier.com/blog/archives/2025/12/building_trustworthy_ai_agents.html

A look at an Android ITW DNG exploit
https://googleprojectzero.blogspot.com/2025/12/a-look-at-android-itw-dng-exploit.html

Germany summons Russian ambassador over cyberattack, election disinformation
https://therecord.media/germany-summons-russian-ambassador-cyberattack-disinformation

Trump signs executive order on 'national framework' for AI regulation
https://therecord.media/trump-executive-order-ai-national-framework

More than 340,000 impacted by cyberattack on library in large Washington county
https://therecord.media/over-340000-impacted-washington-state-library-hack

Canada’s privacy regulator to probe billboards equipped with facial scanning tech
https://therecord.media/canada-privacy-regulator-to-probe-face-scanning-billboards

Hamas-affiliated APT targeting government agencies in the Middle East, Morocco
https://therecord.media/hamas-apt-targeting-government-agencies

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Frogblight threatens you with a court case: a new Android banker targets Turkish users
https://securelist.com/frogblight-banker/118440/

How we got hit by Shai-Hulud: A complete post-mortem | Trigger.dev
https://www.reddit.com/r/netsec/comments/1pmk03y/how_we_got_hit_by_shaihulud_a_complete_postmortem/

Capabilities Are the Only Way to Secure Agent Delegation
https://www.reddit.com/r/netsec/comments/1pmqmf9/capabilities_are_the_only_way_to_secure_agent/

Thread-safe B-Tree implemented in pure x86-64 assembly – 58k mixed ops/sec under contention. I've just finished a complete, generic B-Tree written entirely in hand-tuned x86-64 assembly (NASM) with a clean C interface as a shared library.
https://www.reddit.com/r/lowlevel/comments/1pmmng8/threadsafe_btree_implemented_in_pure_x8664/

ELANA: A Simple Energy and Latency Analyzer for LLMs
https://arxiv.org/abs/2512.11112

SCOUT: A Defense Against Data Poisoning Attacks in Fine-Tuned Language Models
https://arxiv.org/abs/2512.10998

Cybersecurity policy adoption in South Africa: Does public trust matter?
https://arxiv.org/abs/2512.11484

Automated Penetration Testing with LLM Agents and Classical Planning
https://arxiv.org/abs/2512.11122

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Against the Federal Moratorium on State-Level Regulation of AI
https://www.schneier.com/blog/archives/2025/12/against-the-federal-moratorium-on-state-level-regulation-of_ai.html

Next.js: 59k servers compromised in 48h - I breached the attackers' C2 and here's what I found
https://www.reddit.com/r/netsec/comments/1pn5r6z/nextjs_59k_servers_compromised_in_48h_i_breached/

MI6 chief warns 'front line is everywhere' and signals intent to pressure Putin
https://therecord.media/mi6-chief-speech-russia-threats-warning

15th December – Threat Intelligence Report
https://research.checkpoint.com/2025/15th-december-threat-intelligence-report/

Jaguar Land Rover confirms staff data stolen in cyberattack
https://therecord.media/jaguar-land-rover-confirms-staff-data-stolen-cyberattack

Nearly 20 million affected by Prosper, 700Credit data breaches
https://therecord.media/data-breaches-affecting-20-million-prosper-700credit

Defending against the CVE-2025-55182 (React2Shell) vulnerability in React Server Components
https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

God Mode On: how we attacked a vehicle’s head unit modem
https://ics-cert.kaspersky.com/publications/reports/2025/11/20/god-mode-on-researchers-run-doom-on-a-vehicles-head-unit-after-remotely-attacking-its-modem/

Temenos OFS String Injection: Revealing a Hidden Financial Attack Vector
https://www.reddit.com/r/netsec/comments/1pmrvsb/temenos_ofs_string_injection_revealing_a_hidden/

Chinese Surveillance and AI
https://www.schneier.com/blog/archives/2025/12/chinese-surveillance-and-ai.html

Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation
https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/

Most Parked Domains Now Serving Malicious Content
https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/

Urban VPN Browser Extension Caught Harvesting AI Chat Conversations from Millions of Users
https://www.reddit.com/r/netsec/comments/1po3tqx/urban_vpn_browser_extension_caught_harvesting_ai/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent
https://www.reddit.com/r/netsec/comments/1ppndbf/local_privilege_escalation_cve202534352_in/

France arrests 22-year-old over Interior Ministry hack
https://therecord.media/france-interior-ministry-hack-arrest

Hackers breach internal servers of tech provider for Britain’s health service
https://therecord.media/uk-nhs-tech-provider-dxs-discloses-hack

Pa. high court rules that police can access Google searches without a warrant
https://therecord.media/google-searches-police-access-without-warrant-pennsylvania-court-ruling

ORM Leaking More Than You Joined For - Part 3/3 on ORM Leak Vulnerabilities
https://www.reddit.com/r/netsec/comments/1ppmqsi/orm_leaking_more_than_you_joined_for_part_33_on/

Chinese attackers exploiting zero-day to target Cisco email security products
https://therecord.media/chinese-attackers-zero-day

New China-linked hacker group spies on governments in Southeast Asia, Japan
https://therecord.media/china-linked-hacker-group-spied-on-asian-govs

Active HubSpot Phishing Campaign
https://www.reddit.com/r/netsec/comments/1ppr74j/active_hubspot_phishing_campaign/

Over $3.4 billion in crypto stolen throughout 2025, with North Korea again the top culprit
https://therecord.media/over-3-billion-crypto-stolen-2025-north-korea

Austria’s high court orders Meta to change its personalized ad practices
https://therecord.media/austria-court-meta-ruling

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
https://www.reddit.com/r/netsec/comments/1pqfoqo/how_we_pwned_x_twitter_vercel_cursor_discord_and/

AI Advertising Company Hacked
https://www.schneier.com/blog/archives/2025/12/ai-advertising-company-hacked.html

UK confirms Foreign Office hacked, says ‘low risk’ of impact to individuals
https://therecord.media/uk-foreign-office-hacked-china

Trump signs defense bill allocating millions for Cyber Command, mandating Pentagon phone security
https://therecord.media/trump-signs-ndaa-cyber-command

Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing
https://www.reddit.com/r/netsec/comments/1pqm3tt/breaking_sapcar_four_local_privilege_escalation/

Denmark summons Russian ambassador over alleged cyberattacks on water utility, elections
https://therecord.media/denmark-summons-russian-ambassador-cyberattack-elections

Nigeria arrests suspected RaccoonO365 phishing kit developer on tip from Microsoft, FBI
https://therecord.media/nigeria-raccoon-developer-tip

University of Sydney reports data breach affecting over 20,000 staff, affiliates
https://therecord.media/university-of-sydney-reports-data-breach

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
https://www.reddit.com/r/netsec/comments/1ps3taw/vulnhalla_picking_the_true_vulnerabilities_from/

When OAuth Becomes a Weapon: Lessons from CVE-2025-6514
https://www.reddit.com/r/netsec/comments/1psq0mx/when_oauth_becomes_a_weapon_lessons_from/

CAPIO: Safe Kernel-Bypass of Commodity Devices using Capabilities
https://arxiv.org/abs/2512.16965

MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
https://arxiv.org/abs/2512.17045

AutoDFBench 1.0: A Benchmarking Framework for Digital Forensic Tool Testing and Generated Code Evaluation
https://arxiv.org/abs/2512.17029

Adversarial VR: An Open-Source Testbed for Evaluating Adversarial Robustness of VR Cybersickness Detection and Mitigation
https://arxiv.org/abs/2512.16957

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

US disrupts multimillion-dollar bank account takeover operation targeting Americans
https://therecord.media/us-disrupts-bank-account-takeover-operation-web3adspanels

Denmark Accuses Russia of Conducting Two Cyberattacks
https://www.schneier.com/blog/archives/2025/12/denmark-accuses-russia-of-conducting-two-cyberattacks.html

SEC sues crypto firms for defrauding investors out of $14 million
https://therecord.media/sec-sues-crypto-firms-defrauding-investors-14-million

More than 22 million Aflac customers impacted by June data breach
https://therecord.media/22-million-impacted-aflac-breach

What Does it Take to Manage Cloud Risk?
https://www.trendmicro.com/en_us/research/25/l/managing-cloud-risk.html

Bishop Fox Wrapped: Research Worth Replaying
https://bishopfox.com/blog/wrapped

Dissecting a Multi-Stage macOS Infostealer
https://www.reddit.com/r/netsec/comments/1pu7nem/dissecting_a_multistage_macos_infostealer/

Guide to preventing the most common enterprise social engineering attacks
https://www.reddit.com/r/netsec/comments/1pu6gnr/guide_to_preventing_the_most_common_enterprise/

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman
Top Security News for Today

Cyber volunteer effort for small water utilities announces new MSSP effort
https://therecord.media/cyber-volunteer-water-utility-mssp

Urban VPN Proxy Surreptitiously Intercepts AI Chats
https://www.schneier.com/blog/archives/2025/12/urban-vpn-proxy-surreptitiously-intercepts-ai-chats.html

QoS-Aware Dynamic CU Selection in O-RAN with Graph-Based Reinforcement Learning
https://arxiv.org/abs/2512.19696

Automated Fault Detection in 5G Core Networks Using Large Language Models
https://arxiv.org/abs/2512.19697

Smoothing Rough Edges of IPv6 in VPNs
https://arxiv.org/abs/2512.19698

Holographic MIMO Empowered NOMA-ISAC for 6G: Rate-Splitting Enhanced Near-Field Modeling, Multi-Objective Optimization, and Statistical Performance Validation
https://arxiv.org/abs/2512.19699

ServiceNow to acquire cyber firm Armis in $7.75 billion deal
https://therecord.media/servicenow-cyber-armis-acquisition

WebSocket RCE in the CurseForge Launcher
https://www.reddit.com/r/netsec/comments/1pv0p4f/websocket_rce_in_the_curseforge_launcher/

Automated Red-Teaming Framework for Large Language Model Security Assessment: A Comprehensive Attack Generation and Detection System
https://arxiv.org/abs/2512.20705

Follow Top Cyber News at https://news.1rj.ru/str/TopCyberTechNews Feel free to DM me at https://twitter.com/ShayaFeedman