Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
☁️ Millions of AWS resources briefly exposed
🔓 Wallet bug drains $38M in Bitcoin
🏥 Health billing firm leaks 350K records
🔎 Google's AI fixed 1072 Chrome bugs
🚰 Hackers hit water systems in 7 states
Plus: 💡 5 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.
☁️ Millions of AWS resources briefly exposed LINK
🔓 Wallet bug drains $38M in Bitcoin LINK
🏥 Health billing firm leaks 350K records LINK
🔎 Google's AI fixed 1072 Chrome bugs LINK
🚰 Hackers hit water systems in 7 states LINK
💡 Strategies & Tactics
> Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests: A misconfigured test that falsely told Claude it was offline let the model breach three real organizations, showing that sandbox failures, not model malice, are the danger.
> Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login: A critical SolarWinds flaw lets attackers skip single sign-on and reach Web Help Desk data, so administrators should upgrade to version 2026.2.1 immediately.
> SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign: SilverFox hijacks trusted PDF apps to run malware that can kill security tools and self-restart, so blocking one piece won't stop the attack.
> ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale: AI lets attackers rapidly find and hijack forgotten DNS records pointing to deleted cloud resources, turning a niche exploit into mass disruption that nation-states could weaponize.
> Ransomware Killers Overwrite Security Process Memory Without Terminating Applications: New ransomware quietly edits the memory of security tools instead of killing them, so dashboards show protection while detection is silently disabled during encryption.
Other news you might like
- Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across BrazilLINK
- OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage CampaignLINK
- New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi SystemsLINK
- Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous CyberattacksLINK
- BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese OrganizationsLINK
- The Gentlemen Ransomware Kills Nearly 180 Security Processes Before Encrypting Your FilesLINK
🧰 Trending tools
Perfai Security: automatically scans and fixes access control vulnerabilities in apps built with AI coding tools like Replit, Lovable, and Cursor, no security expertise required.LINK
Constellation Gate AI: routes AI agent traffic through a security gateway that blocks prompt injection, scans for secrets, and reduces token costs 20-40% via compression.LINK
Gander: an Android file viewer that opens PDF, Word, Excel, PowerPoint, images, video, audio, and code files without requesting any permissions.LINK
Claudoscope: a free, open-source macOS menu bar app that browses Claude Code session history, tracks token costs, and scans for leaked credentials locally.LINK
darknet-mcp-server: a security research tool offering 66 functions for dark web monitoring, including breach detection, ransomware tracking, Tor access, and malware analysis.LINK
recon-skills: a collection of 162 tested offensive security techniques for reconnaissance and penetration testing, covering subdomain takeovers, secret hunting, and system enumeration methods.LINK
📚 Trending papers & reports
Poisoned training data can be cleaned using an outside image-recognition model as a judge, cutting successful hidden-backdoor attacks to under 1% while barely touching accuracy, a drop of just 0.3%.LINK
Security checklists for AI features fail to catch major risks, like software supply-chain gaps and human-centered threats, when tested on a real small-business system, showing why standard threat modeling needs a GenAI-specific overhaul.LINK
Content moderation filters for images can be tricked by basic edits like color inversion or grayscale, letting harmful content slip past all three major commercial safety APIs tested.LINK
Permission checks for AI agents mathematically verify each action against security rules before it runs, blocking unsafe steps with a precise explanation and hitting a ~90% compliance rate across test scenarios.LINK
Cloud IoT access rules can be automatically checked for hidden data leaks between devices, using a tool that maps allowed communications and flags unsafe information flow before attackers exploit it.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!