Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🍎 iOS 26.6 patches nearly 90 iPhone flaws
🛡️ Microsoft launches first cyber AI model
🌐 Network flaw lets hackers run code
🦷 Dental insurer breach exposes 23M people
🤖 Botnet hijacks 200k devices worldwide
Plus: 💡 5 strategies & tactics, 🎁 8 other news you might like, 🧰 6 tools, and 📚 5 papers.
🍎 iOS 26.6 patches nearly 90 iPhone flaws LINK
🛡️ Microsoft launches first cyber AI model LINK
🌐 Network flaw lets hackers run code LINK
🦷 Dental insurer breach exposes 23M people LINK
🤖 Botnet hijacks 200k devices worldwide LINK
💡 Strategies & Tactics
> Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely: A critical vBulletin bug lets attackers run malicious code without logging in, so forum operators should immediately update to version 6.2.2.
> Claude Cowork can escape its sandbox, rummage through all of your files: Researchers found Claude Cowork's local mode could exploit a Linux flaw to reach a Mac's whole filesystem, exposing private keys and credentials.
> AI-Assisted Research Uncovers Linux Kernel Zero-Day Enabling Root Privilege Escalation: Researchers used AI tools to speed up discovery of a Linux kernel flaw letting local users gain root access, making prompt patching essential.
> PeekList: How Brave’s Playlist bypassed FaceID Protection for Private Tabs: Brave's Playlist feature let anyone open locked private tabs without a Face ID or passcode prompt, since that shortcut skipped the authentication check entirely until Brave patched it.
> How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking: A booking plugin let any anonymous visitor rewrite WooCommerce product prices because its only defense was a nonce published openly in the page source.
Other news you might like
- Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC BackdoorLINK
- Mirage Kitten targets Middle East and Africa region with new malwareLINK
- Microsoft Defender for Endpoint leaves some Linux boxes defenseless after updateLINK
- Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious VideosLINK
- Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root AccessLINK
- MedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionLINK
- Bank of Baroda probes major leak of customer data and internal records after dark web exposureLINK
🧰 Trending tools
Perfai Security: autonomously scans AI-built apps for access control, business-logic, and prompt-injection flaws, then auto-generates pull requests to fix them.LINK
MonoCloud for Startups: provides one identity layer for authentication, authorization, and API access control, letting startups secure users and services with fine-grained permissions for free.LINK
FireTail: an AI security and governance platform that helps you see and secure AI usage across all your environments, reducing shadow AI risk.LINK
Lunen.ai: an AI automation tool that logs every action taken and requires approval on risky steps, giving enterprises audit-ready transparency without sacrificing usability.LINK
Claudoscope: a free macOS menu bar app that browses Claude Code session history, tracks token costs, scans for leaked credentials, and lints CLAUDE.md configs.LINK
Let's Seal: an open-standard, self-hosted document signing tool providing free certificate-based signatures, transparency logging, and blockchain timestamping without vendor lock-in.LINK
📚 Trending papers & reports
Hidden chip malware can now be flagged before it ever activates, by reading subtle power-usage patterns to spot dormant hardware Trojans, closing the security gap left by tools that only catch attacks after they strike.LINK
AI coding assistants writing code from vague or incomplete instructions, the kind developers actually give, produce insecure code over 56% of the time, but adding security-focused wording to prompts cuts that risk by up to 45%.LINK
Self-driving cars sharing sensor data can be tricked by hacked vehicles into missing objects, but a new trust-scoring defense checks data from three angles to block even coordinated fake-consensus attacks.LINK
Chip power leaks can be traced automatically before a processor is even manufactured, pinpointing exactly which hardware signals and software instructions leak encryption secrets through power usage, letting chipmakers fix security holes before costly fabrication.LINK
AI safety blind spots get automatically mapped by tracing which internal "story settings" make chatbots drop their guardrails, boosting jailbreak success rates by up to 18.2 percentage points and working across GPT-5, Claude, and Gemini too.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!