Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π US cyber agency exposed its own cloud keys on GitHub
π File-sharing firm tells customers to shut down servers now
π¦ Poisoned developer tool steals cloud and crypto secrets
π Hackers hijack Joomla sites via two file-upload flaws
Plus: π‘ 4 strategies & tactics, π 7 other news you might like, π§° 4 tools, and π 5 papers.
π US cyber agency exposed its own cloud keys on GitHub LINK
π File-sharing firm tells customers to shut down servers now LINK
π¦ Poisoned developer tool steals cloud and crypto secrets LINK
π Hackers hijack Joomla sites via two file-upload flaws LINK
π‘ Strategies & Tactics
> Hackers exploit critical auth bypass in Gitea Docker image: Gitea's default Docker image trusts login headers from any internet source, letting attackers impersonate admins without passwords, so users must upgrade immediately.
> Multiple U-Boot Vulnerabilities Enable Pre-Authentication Code Execution and Device DoS Attacks: Six flaws in the U-Boot bootloader let attackers run code or crash embedded devices before boot verification finishes, breaking trust for routers, servers, and data centers.
> New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents: Attackers hide malicious instructions inside PNG images that code-review tools ignore, tricking AI coding assistants into later leaking secret credentials as disguised number sequences.
> Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit: New Metasploit modules exploit a Flowise AI tool flaw that runs attacker code via a malicious file and a macOS privilege-escalation bug.
Other news you might like
- GigaWiper Combines Multiple Malware for System-Level SabotageLINK
- Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth TokensLINK
- Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlaceLINK
- AI Found a Root Bug in Linux That Everyone Missed for 15 YearsLINK
- US and allies warn of Russian critical infrastructure attacksLINK
- Okta Warns of Vishing Attacks Targeting Microsoft 365 CustomersLINK
π§° Trending tools
Kittysploit-framework: a Python-based exploitation framework featuring a V8 engine debugger, proxy interceptor, backdoor generator, and post-exploitation marketplace tools.LINK
humanbound: an open-source engine and CLI tool for adversarial testing of AI agents, runnable locally or via a cloud platform.LINK
lpe-toolkit: a Linux toolkit that detects your kernel, filters out patched exploits, and automatically runs privilege escalation attacks until gaining root.LINK
magpie: an AI agent framework for Apache projects that helps with issue triage, mentoring, drafting fixes, and developer pairing workflows.LINK
π Trending papers & reports
Smarter compute allocation inside language models lets a new method match the accuracy of doing twice the processing work, but at a lower computational cost, by focusing extra effort only where it is needed.LINK
Chatbot misalignment turns out to be far less alarming than reported, as the scary "sudden bad behavior" effect largely disappears once you account for simple differences in response length.LINK
Fact-checking knowledge graphs now works 9.4 percentage points more accurately using a smarter search system that also cuts the number of lookups from 3.24 to 1.63, making large-scale automated error detection far cheaper.LINK
Legal case search gets smarter by breaking court documents into meaningful sections and mapping relationships between legal concepts, finding more relevant precedents than tools that treat each document as one undivided block of text.LINK
Automated investor reports built by feeding company filings and economic data into a chatbot were tested with 9 individual investors across 9 companies over 4 weeks to see if the summaries were useful.LINK
Want to get the latest news differently? Find us on:
See you tomorrow for a new dose of βοΈ Cyberpresso!