Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🔴 Adobe patches critical Campaign flaw
🏨 Russian hackers hijack hotel Wi-Fi
🤖 EU in talks with OpenAI after hacking incidents
💊 Amgen breach exposes patient health data
Plus: 💡 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.
🔴 Adobe patches critical Campaign flaw LINK
🏨 Russian hackers hijack hotel Wi-Fi LINK
🤖 EU in talks with OpenAI after hacking incidents LINK
💊 Amgen breach exposes patient health data LINK
💡 Strategies & Tactics
> Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console: A critical, actively exploited N-able N-central flaw lets attackers bypass login and seize full admin control, so patch to hotfix 2026.3.1.7 immediately.
> Arch Linux disables AUR package adoption to stop malware flood: Arch Linux froze user takeovers of community-maintained packages to halt attackers who were seizing abandoned entries to spread credential-stealing malware.
> XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs: New XCSSET malware infects Mac developers through poisoned Xcode projects, then hijacks Chrome and replaces Telegram to steal credentials and cryptocurrency.
> What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery: Cheap AI-assisted code reviews now let anyone systematically scan large codebases for security flaws, so defenders can no longer assume thorough analysis prices out adversaries.
> SkillSpector: NVIDIA’s open-source security scanner for AI agent skills: Scans an AI agent skill before install and returns a risk score so teams avoid loading malicious code that runs with full system access.
> CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates: Attackers now exploit most public vulnerabilities within 48 hours and abuse AI tools and supply chains, shrinking the window defenders have to respond.
Other news you might like
- A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slopLINK
- Brinks Home Security Hacked, 'ShinyHunters' Threaten to Leak DataLINK
- Online ad firm Adform’s script compromised to steal cryptocurrencyLINK
- Russian state hackers deploy persistent Exchange backdoor that survives disk reimagingLINK
- A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN BreachLINK
- Keycloak Flaw Exposes Users’ Personal Data to Restricted AdminsLINK
🧰 Trending tools
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure.LINK
Cycloidal Gearbox: an open-source mechanical design for a cycloidal gearbox, providing high torque and precise speed reduction in a compact form factor.LINK
Kakehashi: an experimental userspace layer that lets you run macOS binaries directly on Linux ARM systems without a virtual machine.LINK
Shitty: a fast terminal emulator written in memory-unsafe code, prioritizing speed and performance over safety guarantees.LINK
BestDefense.io: continuously pentests every deploy, confirms exploitable vulnerabilities via live attack simulation, and auto-generates merge-ready patches with verified proof of remediation.LINK
NixOS-DGX-Spark: provides Nix playbooks, USB images, and a NixOS module for running NixOS on NVIDIA DGX Spark and Asus Ascent GX10 hardware.LINK
📚 Trending papers & reports
Automated security patching fixes real-world software vulnerabilities correctly 73% of the time by gathering the same code-history and crash-context clues human security engineers use, beating the best rival tool by 29%.LINK
Unlearnable text protection rewrites documents so they read naturally but wreck any language model that trains on them without permission, blocking unauthorized fine-tuning across six datasets and nine leading models.LINK
Zero-knowledge AI verification can be gamed by providers who prove they ran the advertised large model while secretly using rigged weights that let them compute like a much smaller, cheaper model, with no drop in output quality.LINK
AI assistant memories can be quietly rewritten to hide untrusted sources and trigger risky actions up to 100% of the time, but a new safeguard checks each memory's origin and blocks every unauthorized high-risk action while still allowing legitimate tasks.LINK
Outsourced AI encryption lets a low-power device run a 70-billion-parameter model on someone else's servers without exposing its data or the model itself, matching standard accuracy while running far faster than prior privacy methods.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!