Hi there, this is your daily โ๏ธ Cyberpresso.
In today's Cyberpresso:
๐ฅ Ransomware halts US milk production
๐๏ธ GPT-5.6 Codex deletes user files
๐ 1Password lets Claude log in unseen
๐ TfL hackers jailed 5.5 years each
๐ก๏ธ CISA orders Fortinet patch by July 19
Plus: ๐ก 4 strategies & tactics, ๐ 9 other news you might like, ๐งฐ 6 tools, and ๐ 5 papers.
๐ฅ Ransomware halts US milk production LINK
๐๏ธ GPT-5.6 Codex deletes user files LINK
๐ 1Password lets Claude log in unseen LINK
๐ TfL hackers jailed 5.5 years each LINK
๐ก๏ธ CISA orders Fortinet patch by July 19 LINK
๐ก Strategies & Tactics
> How I Detected an Insider Threat in Splunk When Every Single Action Looked Legitimate: Catch insider data theft by correlating individually harmless actions (reading, zipping, and uploading a file) into one alert when all three hit one machine within 30 minutes.
> Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking: Chaining two flaws in Google's TV-and-console login flow let a single opened link silently steal accounts on nearly any site using Sign in with Google.
> Prompt injection is becoming the XSS of the web agent era: A system called Prismata filters what web agents see and blocks planted instructions from strangers, cutting attack success from 85% to under 1%.
> Zero Credentials, Full Access: Inside a Complete Authorization Failure: An enterprise AI API let anyone access paid data and other users' chats by trusting a client-supplied identity the server never verified.
Other news you might like
- New ClickLock macOS malware traps users into revealing login passwordLINK
- Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution FlawLINK
- HelloNet campaign, new malicious modules launched through the ViPNet update systemLINK
- TuxBot v3: The IoT Botnet Built With AI โ Bugs, Disclaimers and AllLINK
- Google fixing Android lock screen bug that lets Gemini send SMS without a PINLINK
- Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music ScrapingLINK
- ACR Stealer Uses ClickFix, WebDAV, and Steganography to Steal Browser Credentials and TokensLINK
- GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationLINK
๐งฐ Trending tools
misa77: a compression codec that decodes twice as fast as LZ4 while achieving better compression ratios, though with slower compression speed.LINK
Leaves: a terminal-based disk usage visualizer that renders directory hierarchies as 2D treemaps, showing file-type breakdowns and handling millions of files efficiently.LINK
security-suite: a toolkit combining OSINT gathering, web vulnerability scanning, API testing, SIEM integration, and AI-powered analysis for security research and assessments.LINK
Buildware-Tools: a multipurpose toolkit designed to help security researchers automate tasks and streamline various research workflows efficiently.LINK
connections: a Rust library implementing Galois connections to enable composable, mathematically sound numeric type casts between different numeric types.LINK
Painterly: converts input images into digital paintings by rendering them stroke by stroke, without using generative AI in the pipeline.LINK
๐ Trending papers & reports
AI release packages can pass every individual check yet still contradict themselves internally, like reporting a "100-point Gold Path" when the underlying ledger only supports 60 points, exposing a validation gap standard checks miss.LINK
Engineering blueprint generation now hits 100% acceptance by industrial modeling software, up from just 51.16% with a single AI attempt, by auto-checking and fixing errors before delivery.LINK
Chip design automation now lets AI agents generate working analog chip circuits, specifically SAR analog-to-digital converters, that actually pass rigorous simulation testing, unlike raw AI attempts which produced unusable, hallucinated designs.LINK
AI agent "pause" buttons often fail to actually stop actions, letting side effects like payments or emails fire anyway in 215 of 1,200 test runs across six popular frameworks, a gap the paper's fix closes.LINK
AI error messages that spell out where a task failed, what went wrong, and which fixes are actually allowed roughly triple an AI agent's success rate, from 14 to 36 out of 50 tries.LINK
See you tomorrow for a new dose of โ๏ธ Cyberpresso!