I added hover over text, it messed up some of the formatting. But whatever, I gotta go write my TPS report.
Krebs on Security
Dark Reading
The Hacker News [ THN ] - Best Security Blog
2025-10-20 - MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
2025-10-19 - Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide
2025-10-18 - New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
2025-10-18 - Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
2025-10-17 - North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware
2025-10-17 - Identity Security: Your First and Last Line of Defense
2025-10-17 - Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices
2025-10-17 - Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
2025-10-16 - North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
2025-10-16 - Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
2025-10-16 - LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
2025-10-16 - Architectures, Risks, and Adoption: How to Assess and Choose the Right AI-SOC Platform
2025-10-16 - Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in 'Zero Disco' Attacks
2025-10-16 - Beware the Hidden Costs of Pen Testing
2025-10-16 - ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More
2025-10-16 - CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack
Schneier on Security
2025-10-16 - video.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
">Friday Squid Blogging: Squid Inks Philippines Fisherman
2025-10-16 - summary:
We pointed a commercial-off-the-shelf satellite dish at the sky and carried out the most comprehensive public study to date of geostationary satellite communication. A shockingly large amount of sensitive traffic is being broadcast unencrypted, including critical infrastructure, internal corporate and government communications, private citizens’ voice calls and SMS, and consumer Internet traffic from in-flight wifi and mobile networks. This data can be passively observed by anyone with a few hundred dollars of consumer-grade hardware. There are thousands of geostationary satellite transponders globally, and data from a single transponder may be visible from an area as large as 40% of the surface of the earth...
">A Surprising Amount of Satellite Traffic Is Unencrypted
ThreatPost
Sydney Morning Herald
New York Times
2025-10-17 - Benioff Apologizes for Saying Trump Should Send Troops to San Francisco
2025-10-17 - Instagram Unveils Teen Safety Features for A.I. Chatbots
2025-10-16 - Renting a San Francisco Apartment in the A.I. Boom? Good Luck.
2025-10-17 - California Regulates A.I. Companions + OpenAI Investigates Its Critics + The Hard Fork Review of Slop
2025-10-18 - The Culture Wars Came for Wikipedia. Jimmy Wales Is Staying the Course.
2025-10-18 - Does A.I. Count as Art? Ask the Curators
2025-10-17 - Boeing Is Allowed to Increase 737 Max Plane Production, FAA Says
2025-10-17 - An Army of Robot Telescopes in Texas Makes the Stars Feel Closer Than Ever
2025-10-16 - China’s Rare Earth Restrictions Aim to Beat U.S. at Its Own Game
2025-10-19 - OpenAI Inks Deal With Broadcom to Design Its Own Chips for A.I.
Wall Street Journal
BBC
2025-10-20 - Bereaved families call for inquiry into government response to suicide websites
2025-10-17 - OpenAI stops 'disrespectful' Martin Luther King Jr deepfakes
2025-10-16 - Spotify working on AI music tools with major record labels
2025-10-17 - China's biggest shopping event starts five weeks early to revive spending
2025-10-16 - Scottish data centres powering AI already using enough water to fill 27 million bottles a year
2025-10-16 - Cabinet Office rejects Cummings' China breach claim
2025-10-16 - How good is the battery in a used electric vehicle?
2025-10-16 - Why AI is being trained in rural India
SecurityBrief AU
2025-10-20 - AI set to boost Australia’s economy by up to AUD $142 billion
2025-10-20 - Australian SMBs miss growth by skipping branded merchandise
2025-10-20 - DroneShield posts record revenue & positive cash flow on SaaS growth
2025-10-20 - DroneShield appoints Angus Harris as CTO and Angus Bean as CPO
2025-10-20 - Why better data management is the key to exceptional customer experience
2025-10-20 - Why quantum threats demand our attention this Cybersecurity Month
2025-10-18 - AI-powered phishing threats outpace business defences & SOC teams
2025-10-17 - Trend Vision One tops Forrester ranking for network security tools
2025-10-17 - Graylog named in 2025 Gartner Magic Quadrant for SIEM tools
2025-10-17 - Securonix named SIEM Leader for sixth year in 2025 Gartner report
ITNews AU
2025-10-20 - Microsoft breaks Windows 11 Recovery Environment in October update
2025-10-20 - US court orders spyware company NSO to stop targeting WhatsApp
2025-10-20 - Australia's new cyber affairs ambassador sourced from ASD
2025-10-20 - Vocus ISP Dodo's email system breached on Friday
2025-10-17 - Microsoft pulls certs for fake Teams installers dropping ransomware
2025-10-16 - China-linked Flax Typhoon tweaked ArcGIS plugin to act as stealthy backdoor
2025-10-16 - Austrade to replace its data centre core network
2025-10-16 - Hackers using F5 devices to target US gov networks
BleepingComputer
2025-10-19 - TikTok videos continue to push infostealers in ClickFix attacks
2025-10-19 - Experian fined $3.2 million for mass-collecting personal data
2025-10-18 - OpenAI confirms GPT-6 is not shipping in 2025
2025-10-18 - Google ads for fake Homebrew, LogMeIn sites push infostealers
2025-10-17 - ConnectWise fixes Automate bug allowing AiTM update attacks
2025-10-17 - American Airlines subsidiary Envoy confirms Oracle data theft attack
2025-10-17 - Microsoft lifts more safeguard holds blocking Windows 11 updates
2025-10-17 - Europol dismantles SIM box operation renting numbers for cybercrime
2025-10-17 - Microsoft fixes highest-severity ASP.NET Core flaw ever
2025-10-17 - VMware Certification: Your Next Career Power Move
2025-10-17 - Microsoft fixes Windows bug breaking localhost HTTP connections
2025-10-17 - Over 266,000 F5 BIG-IP instances exposed to remote attacks
/r/NetSec
2025-10-19 - /u/Cold-Dinosaur
[link] [comments]">DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
2025-10-17 - /u/AlmondOffSec
[link] [comments]">How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
2025-10-18 - /u/SkyFallRobin
[link] [comments]">macOS Shortcuts for Initial Access
2025-10-16 - /u/not_wet_now
[link] [comments]">Exploiting browser cache smuggling with COM Hijacking and steganography
2025-10-16 - /u/dx7r__
[link] [comments]">yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242) - watchTowr Labs
/r/InfoSecNews
2025-10-19 -
submitted by /u/quellaman [link] [comments] | ">Experian fined $3.2 million for mass-collecting personal data
2025-10-18 -
submitted by /u/quellaman [link] [comments] | ">From Airport chaos to cyber intrigue: Everest Gang takes credit for Collins Aerospace breach - Security Affairs
2025-10-18 -
submitted by /u/quellaman [link] [comments] | ">Winos 4.0 hackers expand to Japan and Malaysia with new malware
2025-10-18 -
submitted by /u/quellaman [link] [comments] | ">ConnectWise fixes Automate bug allowing AiTM update attacks
2025-10-18 - /u/quellaman
[link] [comments]">Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
2025-10-18 - /u/quellaman
[link] [comments]">New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
2025-10-18 -
submitted by /u/quellaman [link] [comments] | ">American Airlines subsidiary Envoy confirms Oracle data theft attack
2025-10-17 -
submitted by /u/quellaman [link] [comments] | ">Europol dismantles SIM box operation renting numbers for cybercrime
2025-10-17 -
submitted by /u/quellaman [link] [comments] | ">Microsoft fixes highest-severity ASP.NET Core flaw ever
2025-10-17 - /u/quellaman
[link] [comments]">Email Bombs Exploit Lax Authentication in Zendesk
2025-10-17 -
submitted by /u/quellaman [link] [comments] | ">PowerSchool hacker got four years in prison
2025-10-17 - /u/quellaman
[link] [comments]">Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
2025-10-17 - /u/jamessonnycrockett
[link] [comments]">Malicious Perplexity Comet Browser Download Ads Push Password Stealer Via Google Search
2025-10-17 - /u/quellaman
[link] [comments]">Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over Devices
2025-10-17 -
submitted by /u/quellaman [link] [comments] | ">Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
2025-10-17 -
submitted by /u/quellaman [link] [comments] | ">Auction giant Sotheby’s says data breach exposed financial information
2025-10-16 -
submitted by /u/quellaman [link] [comments] | ">Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
2025-10-16 -
submitted by /u/jamessonnycrockett [link] [comments] | ">Misconfigured NetcoreCloud Server Exposed 40 Billion Records in 13.4TB of Data
2025-10-16 -
submitted by /u/quellaman [link] [comments] | ">China-linked APT Jewelbug targets Russian IT provider in rare cross-nation cyberattack
2025-10-16 -
submitted by /u/jamessonnycrockett [link] [comments] | ">North Korea's Famous Chollima hackers Use BeaverTail and OtterCookie Malware in Job Scam
2025-10-16 - /u/quellaman
[link] [comments]">LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
2025-10-16 -
submitted by /u/quellaman [link] [comments] | ">CISA: Maximum-severity Adobe flaw now exploited in attacks
2025-10-16 - /u/quellaman
[link] [comments]">Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
2025-10-16 -
submitted by /u/quellaman [link] [comments] | ">Zero Day Initiative — Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!
2025-10-16 -
submitted by /u/jamessonnycrockett [link] [comments] | ">New Tech Support Scam Uses Microsoft Logo to Fake Browser Lock to Steal Data