I added hover over text, it messed up some of the formatting. But whatever, I gotta go write my TPS report.

Krebs on Security

Dark Reading

The Hacker News [ THN ] - Best Security Blog

2025-10-20 - MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
2025-10-19 - Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide
2025-10-18 - New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
2025-10-18 - Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
2025-10-17 - North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware
2025-10-17 - Identity Security: Your First and Last Line of Defense
2025-10-17 - Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices
2025-10-17 - Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
2025-10-16 - North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
2025-10-16 - Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
2025-10-16 - LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
2025-10-16 - Architectures, Risks, and Adoption: How to Assess and Choose the Right AI-SOC Platform
2025-10-16 - Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in 'Zero Disco' Attacks
2025-10-16 - Beware the Hidden Costs of Pen Testing
2025-10-16 - ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More
2025-10-16 - CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack

Schneier on Security

2025-10-16 - video.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

">Friday Squid Blogging: Squid Inks Philippines Fisherman
2025-10-16 - summary:

We pointed a commercial-off-the-shelf satellite dish at the sky and carried out the most comprehensive public study to date of geostationary satellite communication. A shockingly large amount of sensitive traffic is being broadcast unencrypted, including critical infrastructure, internal corporate and government communications, private citizens’ voice calls and SMS, and consumer Internet traffic from in-flight wifi and mobile networks. This data can be passively observed by anyone with a few hundred dollars of consumer-grade hardware. There are thousands of geostationary satellite transponders globally, and data from a single transponder may be visible from an area as large as 40% of the surface of the earth...

">A Surprising Amount of Satellite Traffic Is Unencrypted

ThreatPost

Sydney Morning Herald

New York Times

2025-10-17 - Benioff Apologizes for Saying Trump Should Send Troops to San Francisco
2025-10-17 - Instagram Unveils Teen Safety Features for A.I. Chatbots
2025-10-16 - Renting a San Francisco Apartment in the A.I. Boom? Good Luck.
2025-10-17 - California Regulates A.I. Companions + OpenAI Investigates Its Critics + The Hard Fork Review of Slop
2025-10-18 - The Culture Wars Came for Wikipedia. Jimmy Wales Is Staying the Course.
2025-10-18 - Does A.I. Count as Art? Ask the Curators
2025-10-17 - Boeing Is Allowed to Increase 737 Max Plane Production, FAA Says
2025-10-17 - An Army of Robot Telescopes in Texas Makes the Stars Feel Closer Than Ever
2025-10-16 - China’s Rare Earth Restrictions Aim to Beat U.S. at Its Own Game
2025-10-19 - OpenAI Inks Deal With Broadcom to Design Its Own Chips for A.I.

Wall Street Journal

BBC

2025-10-20 - Bereaved families call for inquiry into government response to suicide websites
2025-10-17 - OpenAI stops 'disrespectful' Martin Luther King Jr deepfakes
2025-10-16 - Spotify working on AI music tools with major record labels
2025-10-17 - China's biggest shopping event starts five weeks early to revive spending
2025-10-16 - Scottish data centres powering AI already using enough water to fill 27 million bottles a year
2025-10-16 - Cabinet Office rejects Cummings' China breach claim
2025-10-16 - How good is the battery in a used electric vehicle?
2025-10-16 - Why AI is being trained in rural India

SecurityBrief AU

2025-10-20 - AI set to boost Australia’s economy by up to AUD $142 billion
2025-10-20 - Australian SMBs miss growth by skipping branded merchandise
2025-10-20 - DroneShield posts record revenue & positive cash flow on SaaS growth
2025-10-20 - DroneShield appoints Angus Harris as CTO and Angus Bean as CPO
2025-10-20 - Why better data management is the key to exceptional customer experience
2025-10-20 - Why quantum threats demand our attention this Cybersecurity Month
2025-10-18 - AI-powered phishing threats outpace business defences & SOC teams
2025-10-17 - Trend Vision One tops Forrester ranking for network security tools
2025-10-17 - Graylog named in 2025 Gartner Magic Quadrant for SIEM tools
2025-10-17 - Securonix named SIEM Leader for sixth year in 2025 Gartner report

ITNews AU

2025-10-20 - Microsoft breaks Windows 11 Recovery Environment in October update
2025-10-20 - US court orders spyware company NSO to stop targeting WhatsApp
2025-10-20 - Australia's new cyber affairs ambassador sourced from ASD
2025-10-20 - Vocus ISP Dodo's email system breached on Friday
2025-10-17 - Microsoft pulls certs for fake Teams installers dropping ransomware
2025-10-16 - China-linked Flax Typhoon tweaked ArcGIS plugin to act as stealthy backdoor
2025-10-16 - Austrade to replace its data centre core network
2025-10-16 - Hackers using F5 devices to target US gov networks

BleepingComputer

2025-10-19 - TikTok videos continue to push infostealers in ClickFix attacks
2025-10-19 - Experian fined $3.2 million for mass-collecting personal data
2025-10-18 - OpenAI confirms GPT-6 is not shipping in 2025
2025-10-18 - Google ads for fake Homebrew, LogMeIn sites push infostealers
2025-10-17 - ConnectWise fixes Automate bug allowing AiTM update attacks
2025-10-17 - American Airlines subsidiary Envoy confirms Oracle data theft attack
2025-10-17 - Microsoft lifts more safeguard holds blocking Windows 11 updates
2025-10-17 - Europol dismantles SIM box operation renting numbers for cybercrime
2025-10-17 - Microsoft fixes highest-severity ASP.NET Core flaw ever
2025-10-17 - VMware Certification: Your Next Career Power Move
2025-10-17 - Microsoft fixes Windows bug breaking localhost HTTP connections
2025-10-17 - Over 266,000 F5 BIG-IP instances exposed to remote attacks

/r/NetSec

2025-10-19 - /u/Cold-Dinosaur
[link] [comments]">DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
2025-10-17 - /u/AlmondOffSec
[link] [comments]">How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
2025-10-18 - /u/SkyFallRobin
[link] [comments]">macOS Shortcuts for Initial Access
2025-10-16 - /u/not_wet_now
[link] [comments]">Exploiting browser cache smuggling with COM Hijacking and steganography
2025-10-16 - /u/dx7r__
[link] [comments]">yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242) - watchTowr Labs

/r/InfoSecNews

2025-10-19 - Experian fined $3.2 million for mass-collecting personal data submitted by /u/quellaman
[link] [comments] ">Experian fined $3.2 million for mass-collecting personal data
2025-10-18 - From Airport chaos to cyber intrigue: Everest Gang takes credit for Collins Aerospace breach - Security Affairs submitted by /u/quellaman
[link] [comments] ">From Airport chaos to cyber intrigue: Everest Gang takes credit for Collins Aerospace breach - Security Affairs
2025-10-18 - Winos 4.0 hackers expand to Japan and Malaysia with new malware submitted by /u/quellaman
[link] [comments] ">Winos 4.0 hackers expand to Japan and Malaysia with new malware
2025-10-18 - ConnectWise fixes Automate bug allowing AiTM update attacks submitted by /u/quellaman
[link] [comments] ">ConnectWise fixes Automate bug allowing AiTM update attacks
2025-10-18 - /u/quellaman
[link] [comments]">Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
2025-10-18 - /u/quellaman
[link] [comments]">New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
2025-10-18 - American Airlines subsidiary Envoy confirms Oracle data theft attack submitted by /u/quellaman
[link] [comments] ">American Airlines subsidiary Envoy confirms Oracle data theft attack
2025-10-17 - Europol dismantles SIM box operation renting numbers for cybercrime submitted by /u/quellaman
[link] [comments] ">Europol dismantles SIM box operation renting numbers for cybercrime
2025-10-17 - Microsoft fixes highest-severity ASP.NET Core flaw ever submitted by /u/quellaman
[link] [comments] ">Microsoft fixes highest-severity ASP.NET Core flaw ever
2025-10-17 - /u/quellaman
[link] [comments]">Email Bombs Exploit Lax Authentication in Zendesk
2025-10-17 - PowerSchool hacker got four years in prison submitted by /u/quellaman
[link] [comments] ">PowerSchool hacker got four years in prison
2025-10-17 - /u/quellaman
[link] [comments]">Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
2025-10-17 - /u/jamessonnycrockett
[link] [comments]">Malicious Perplexity Comet Browser Download Ads Push Password Stealer Via Google Search
2025-10-17 - /u/quellaman
[link] [comments]">Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices
2025-10-17 - Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities submitted by /u/quellaman
[link] [comments] ">Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
2025-10-17 - Auction giant Sotheby’s says data breach exposed financial information submitted by /u/quellaman
[link] [comments] ">Auction giant Sotheby’s says data breach exposed financial information
2025-10-16 - Hackers exploit Cisco SNMP flaw to deploy rootkit on switches submitted by /u/quellaman
[link] [comments] ">Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
2025-10-16 - Misconfigured NetcoreCloud Server Exposed 40 Billion Records in 13.4TB of Data submitted by /u/jamessonnycrockett
[link] [comments] ">Misconfigured NetcoreCloud Server Exposed 40 Billion Records in 13.4TB of Data
2025-10-16 - China-linked APT Jewelbug targets Russian IT provider in rare cross-nation cyberattack submitted by /u/quellaman
[link] [comments] ">China-linked APT Jewelbug targets Russian IT provider in rare cross-nation cyberattack
2025-10-16 - North Korea's Famous Chollima hackers Use BeaverTail and OtterCookie Malware in Job Scam submitted by /u/jamessonnycrockett
[link] [comments] ">North Korea's Famous Chollima hackers Use BeaverTail and OtterCookie Malware in Job Scam
2025-10-16 - /u/quellaman
[link] [comments]">LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
2025-10-16 - CISA: Maximum-severity Adobe flaw now exploited in attacks submitted by /u/quellaman
[link] [comments] ">CISA: Maximum-severity Adobe flaw now exploited in attacks
2025-10-16 - /u/quellaman
[link] [comments]">Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
2025-10-16 - Zero Day Initiative — Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More! submitted by /u/quellaman
[link] [comments] ">Zero Day Initiative — Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!
2025-10-16 - New Tech Support Scam Uses Microsoft Logo to Fake Browser Lock to Steal Data submitted by /u/jamessonnycrockett
[link] [comments] ">New Tech Support Scam Uses Microsoft Logo to Fake Browser Lock to Steal Data