Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🔓 Anthropic's AI cracks weakened encryption
🐛 OpenAI open-sources a bug-finding tool
💧 Cyberattack hits Minnesota water systems
🖥️ VMware bug lets hackers escape VMs
🔑 24,000 servers leak passwords via old flaw
Plus: 💡 5 strategies & tactics, 🎁 9 other news you might like, 🧰 6 tools, and 📚 5 papers.
🔓 Anthropic's AI cracks weakened encryption LINK
🐛 OpenAI open-sources a bug-finding tool LINK
💧 Cyberattack hits Minnesota water systems LINK
🖥️ VMware bug lets hackers escape VMs LINK
🔑 24,000 servers leak passwords via old flaw LINK
💡 Strategies & Tactics
> Ghost Credentials Expose Cloud Systems to Hidden Identity Risks: Forgotten automated accounts and tokens with excessive permissions let attackers hijack cloud systems in minutes, so organizations must inventory and monitor these non-human identities.
> Specter: Open-source NFC reader bug sweep for Flipper Zero: Turns a Flipper Zero into a detector that finds hidden NFC card skimmers and readers by sensing the radio field they emit.
> Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT: Forcing a Snowflake query to fail during compilation instead of execution slips database metadata past error handlers that only hide runtime failures.
> GitHub adds approval checks for suspicious Actions workflows: GitHub now automatically pauses suspicious automated workflows in public projects until a trusted collaborator approves them, blocking hijacked accounts from stealing credentials before code runs.
> How I Found a High-Severity Directory Traversal in Flask-Admin: Never enforce filesystem security with string prefix checks, since two separate directories can share the same starting characters and bypass the boundary.
Other news you might like
- Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server CommandsLINK
- Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba DevelopersLINK
- CISA shares advice on isolating vital systems during cyberattacksLINK
- Flying Eagle RAT Abuses Android Accessibility Services for Keylogging, Screen Capture and Gesture InjectionLINK
- Two Joyfill npm Beta Releases Compromised With Blockchain-Backed Remote Access Trojan LoaderLINK
- macOS ClickFix Attacks Use Fake CAPTCHAs to Deploy Atomic Stealer and Hijack Crypto WalletsLINK
- Critical WordPress Plugin Backdoor Exposes 20,000 Sites to Full Administrator TakeoverLINK
🧰 Trending tools
Spotlight by Backplanes: a CLI session analyzer for Claude Code and Codex that tracks agent actions and flags fixes, helping teams iteratively improve their workflows.LINK
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure.LINK
Playground: an fabraix tool for testing prompt injection techniques against AI agents, helping developers spot and fix security vulnerabilities before deployment.LINK
BestDefense.io: continuously pentests every deploy, validates which vulnerabilities are actually exploitable, and auto-generates fixes so teams patch real risks quickly.LINK
Sequirly: browser extension that scans prompts and file uploads before they reach ChatGPT, Claude, or Gemini, flagging API keys and personal data.LINK
Verified 3D Mesh Intersection: a formally verified Lean 4 implementation of 3D CSG mesh intersection, letting a 93-line spec replace trust in 1000+ lines of AI-generated code.LINK
📚 Trending papers & reports
Wireless message security lets AI-based communication systems resist deliberate signal tampering by sending a compact backup summary alongside the data, restoring meaning without slowing normal transmission.LINK
Instruction-hierarchy testing shows AI assistants that reliably follow a company's rules when users push back can still get hijacked by conflicting instructions hidden in tool outputs, with compliance across 37 models ranging from 98.2% to just 20.5%.LINK
Malware detection stress-tests reveal that shrinking a virus scanner's data footprint for speed costs accuracy, with full feature sets hitting ~1.00 detection score versus ~0.98 for the compressed version, but the compressed approach adds early-warning signals showing when files are drifting toward misclassification.LINK
Blind bidding for 3D printing jobs lets factories quote prices on secret design files without seeing them, using a blockchain check that only exposes the file if someone lies, costing as little as 2.87 on cheaper networks versus 7,207 on Ethereum.LINK
Similarity score leaks get patched by adding calibrated noise then correcting the results, protecting user data from re-identification while degrading accuracy far less than standard noise methods used today.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!