Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🚔 Data on 100,000 UK cops stolen
🔑 Malware can hijack Google passkeys
🕵️ Hackers steal secret owner list
🖼️ New malware hides in browser cache images
Plus: 💡 5 strategies & tactics, 🎁 9 other news you might like, 🧰 6 tools, and 📚 5 papers.
🚔 Data on 100,000 UK cops stolen LINK
🔑 Malware can hijack Google passkeys LINK
🕵️ Hackers steal secret owner list LINK
🖼️ New malware hides in browser cache images LINK
💡 Strategies & Tactics
> ConfigManBearPig 2.0 – Things Are Getting Cereal: A rewritten Python tool scans Microsoft's device-management system for security misconfigurations and maps attack paths, running faster and now from Linux.
> Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models: Flaws in Hugging Face's diffusers library let malicious AI models run code on any machine that loads them, so treat all model repositories as untrusted.
> Researchers find ‘agent-to-agent’ privilege escalation in Google’s ADK for Python repo: Researchers showed that one AI agent can trick a higher-privileged agent into leaking Google's repository tokens, proving agents need narrow, separate identities.
> Provisioning Packages: Attackers with admin access can hide malicious scripts inside Windows provisioning packages, so defenders should audit their file and registry storage locations to catch deployments.
> LLM Security Basics: The Full Threat Model: Maps every point where hostile text or actions can hijack a large language model (LLM), showing agents with data access, outside input, and an exit channel pose the real production risk.
Other news you might like
- Microsoft reduces NuGet API keys to just 30 days, here's whyLINK
- Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test DataLINK
- cPanel Database Privilege Escalation Flaw Enables Full Administrative AccessLINK
- Inside the Underground Business of BTMOB RATLINK
- Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpersLINK
- Fake AI Tools Target Developers With Infostealers to Steal Credentials and Cloud SecretsLINK
- OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East GovernmentsLINK
- Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution AttacksLINK
🧰 Trending tools
Swiftlet: runs an 80B Qwen model in 4.3 GB of RAM on a Mac, and a 35B model on an iPhoneLINK
MonoCloud for Startups: provides a unified identity layer handling authentication, fine-grained authorization, and API access control for users, services, and AI agents, free for one year.LINK
FireTail: an AI security and governance platform that monitors and secures AI usage across your environments, helping teams catch risks before they cause problems.LINK
Sequirly: browser extension that scans prompts and file uploads before they reach ChatGPT, Claude, or Gemini, flagging API keys and personal data.LINK
TailMux: lets you connect to multiple Tailscale tailnets simultaneously on macOS and Linux by running isolated embedded nodes per profile, routing by hostname without account switching or VMs.LINK
Nightcrawler: a local AI-powered penetration testing agent designed to run entirely on a smartphone, enabling on-device security testing without external servers.LINK
📚 Trending papers & reports
AI teamwork pipelines that pass work between multiple specialized chatbots blindly trust each handoff, letting one poisoned step corrupt the whole workflow regardless of which top AI models power it.LINK
Multi-turn chatbot jailbreaks succeed based on how deliberately attackers spread harmful intent across a conversation, not how long it is, meaning safety checks on single messages alone can't catch them.LINK
Vulnerability patch tracing finds the exact code fix for a security flaw across an entire repository, beating a leading commercial tool by 18% on match accuracy and 28% on recall, and already fixed 35 real CVE records on GitHub.LINK
AI reasoning checks can be fooled by rewriting only an AI agent's explanation to sound honest while leaving its actual actions unchanged, cutting detection from ~95% to under 11%, showing this safety check is far weaker than reported averages suggest.LINK
Internet-facing AI connectors tested across 414 live servers found 68 exploitable flaws like SQL injection and cloud-credential theft, with 92% lacking login security and 42% vanishing within three days, showing most are shipped with no security review.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!