Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π Hackers spent a year quietly stealing corporate Salesforce data
π New Mac malware poses as Apple crash tool to steal passwords
π Hackers spoof Microsoft logins to test millions of passwords
π¦ Hijacked npm packages spread botnet malware to developers
π·πΊ Russian hackers breach thousands of French accounts via SharePoint flaw
Plus: π‘ 4 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π Hackers spent a year quietly stealing corporate Salesforce data LINK
π New Mac malware poses as Apple crash tool to steal passwords LINK
π Hackers spoof Microsoft logins to test millions of passwords LINK
π¦ Hijacked npm packages spread botnet malware to developers LINK
π·πΊ Russian hackers breach thousands of French accounts via SharePoint flaw LINK
π‘ Strategies & Tactics
> Now, defenders are embracing the prompt injection, too: Defenders can plant fake secrets containing forbidden prompts that trigger an attacking AI's own safety refusals, shutting down automated hacking attempts.
> RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker: RabbitMQ patched two flaws that leaked OAuth login secrets to unauthenticated attackers, potentially handing them full control of the message broker.
> SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities: SAP's July patch fixes critical remotely exploitable flaws in NetWeaver, Approuter, and Commerce Cloud, so administrators should apply updates and remove sample credentials immediately.
> Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking: A now-patched flaw in Google's chatbot-building platform let low-privilege attackers inject code to hijack AI agents, steal credentials, and read chat logs undetected.
Other news you might like
- RedHook Android malware now uses Wireless ADB for shell accessLINK
- 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutesLINK
- CISA Adds Cisco IOS CSRF Flaw Enabling Arbitrary Command Execution to KEV CatalogLINK
- LastPass warns users of active campaign targeting master passwordsLINK
- ModHeader Chrome Extension Exposes 900,000 Users to Potential Browsing History TheftLINK
- Forg365 industrializes Microsoft 365 phishing with AI-generated luresLINK
- Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical InfrastructureLINK
π§° Trending tools
Spotlight by Backplanes: a session reporting tool that reviews Claude Code and Codex workflows, surfacing patterns to help developers improve their AI-assisted coding habits.LINK
Perfai Security: detects and fixes live security vulnerabilities in Vibe Apps using a singleLINK
Playground: a competitive platform where developers earn weekly cash rewards by finding and exploLINK
Clawk: gives coding agents a disposable Linux VM to run in, instead of executing commands directly on your laptop.LINK
Astra Autonomous Pentest: ai agents that automatically find, validate, and remediate vulnerabilities across your web apps without manual intervention.LINK
OpenBox: a runtime governance SDK that enforces cryptographic verification and compliance policies for agentic AI workflows without rewriting existing code.LINK
π Trending papers & reports
Vibe coding documentation gets a fix from a new tool that automatically pulls clear written specs from AI chat sessions, scoring 5.74 out of 6.0, so humans can review intent instead of raw code.LINK
AI-written code, once merged into real projects, needs significantly more bug fixes and security patches than human-written code, according to a study of 182 repositories tracking what happens after merging.LINK
Security bug detectors flooded with false alarms get a fix, as language models using double-checking techniques reached at least 98% recall and 94.8% accuracy separating real bugs from noise.LINK
Software tools connecting AI to outside services now have a first large-scale map, with 2,297 real-world projects catalogued from GitHub, revealing Python and TypeScript as the dominant building blocks.LINK
Packaging ML projects into containers is surprisingly wasteful, with 71% of rebuild work redundant, but researchers identified 7 reusable fixes that cut build times and bloated average container sizes of 10.27 GB.LINK
Want to get the latest news differently? Find us on:
See you tomorrow for a new dose of βοΈ Cyberpresso!