Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🛡️ Microsoft patches record 622 flaws two under attack
🚕 Cyberattack downs Japan's biggest taxi operator
📌 Secure Boot broken for a decade unnoticed
🔓 SonicWall VPN flaws let hackers run code
Plus: 💡 4 strategies & tactics, 🎁 8 other news you might like, 🧰 6 tools, and 📚 5 papers.
🛡️ Microsoft patches record 622 flaws two under attack LINK
🚕 Cyberattack downs Japan's biggest taxi operator LINK
📌 Secure Boot broken for a decade unnoticed LINK
🔓 SonicWall VPN flaws let hackers run code LINK
💡 Strategies & Tactics
> ClickFix's Mushrooming Ecosystem Demands New Defense Tactics: Detect ClickFix scams by scanning the fake lure webpage's structure rather than the ever-changing malware, catching attacks that antivirus tools miss.
> A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed: Cloudflare's 1.1.1.1 now adds an error code telling clients when it bypassed DNSSEC security checks to keep a broken domain reachable, making a previously invisible tradeoff transparent.
> 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload: Eleven fake NuGet game-cheat packages secretly download Windows spyware that captures screenshots and tracks hardware, showing developers must vet dependencies before installing them.
> Cursor IDE Auto-Executes Malicious Code in Poisoned Repos: Cursor's AI coding tool runs a disguised program hidden in any opened project without warning, letting attackers execute malicious code on developers' machines.
Other news you might like
- China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion CampaignLINK
- LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows SystemsLINK
- New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication ProtocolLINK
- Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report saysLINK
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesLINK
- Vulnerabilities Patched by Fortinet, Ivanti, ServiceNowLINK
- 7 Severe Vulnerabilities Patched in VMware Avi Load BalancerLINK
🧰 Trending tools
FireTail: monitors and secures API usage across an organization's stack, detecting vulnerabilities and misconfigurations before attackers exploit them in production.LINK
BestDefense.io: automatically pentests and patches vulnerabilities in every deployment using AI, helping developers catch security flaws before they reach production.LINK
Sequirly: scans prompts and file uploads in your browser to catch API keys, credentials, and personal data before they reach ChatGPT, Claude, or Gemini.LINK
LaunchSafe: runs continuous, AI-driven pentesting that chains real exploits and auto-remediates vulnerabilities, letting engineering teams ship quickly without weakening security.LINK
NeuralNetSQL: implements a full neural network's forward and backward pass using only SQL queries, treating matrix multiplication as joins and aggregations.LINK
ai-trains-ai: an RL-trained agent that autonomously designs and trains other models using reinforcement learning, built for approximately $1,300 in compute costs.LINK
📚 Trending papers & reports
Code review workloads can partly predict which pull requests get accepted just from info available when they're submitted, with top models scoring above 0.95 F1, but estimating how much review effort they'll need is much harder.LINK
Tracing security bugs to their exact triggering line of code, even across distant functions, works 75.0% of the time, beating prior best methods on the same test set.LINK
AI-written software tests catch more edge cases than human-written ones, with almost double the variety (0.62 vs 0.32) and more null-safety checks (13.40% vs 8.3%), though humans write slightly stronger assertions (88.1% vs 85.37%).LINK
API testing tools perform much worse when the software blueprints they rely on contain errors, and just measuring code coverage hides how badly, researchers find.LINK
Kernel trace data can be safely synthesized, matching real system logs within 2.6 points of accuracy while cutting costs, since longer context boosts quality by 104%.LINK
Want to get the latest news differently? Find us on:
See you tomorrow for a new dose of ☕️ Cyberpresso!