Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π Levi Strauss hacked via 3 employees
π¦ Steam buyer shipping data breached
π‘οΈ OpenAI launches GPT-5.6-Cyber for defenders
π Poisoned WordPress plugins create rogue admins
π€ Fake security logs can hijack AI agents
Plus: π‘ 6 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π Levi Strauss hacked via 3 employees LINK
π¦ Steam buyer shipping data breached LINK
π‘οΈ OpenAI launches GPT-5.6-Cyber for defenders LINK
π Poisoned WordPress plugins create rogue admins LINK
π€ Fake security logs can hijack AI agents LINK
π‘ Strategies & Tactics
> Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection: Espionage malware hides its command traffic by using DNS lookups to switch between direct connections and a Google Apps Script relay, making it harder to block.
> Mandatory User Profile: Attackers hide Windows persistence by planting a mandatory-profile file (NTUSER.MAN) that loads malicious registry settings at logon without triggering the security tools that watch registry APIs.
> HP ThinPro vulnerability allows physical attackers to bypass disk encryption: An unpatched flaw in HP's ThinPro thin-client systems lets attackers with physical access defeat disk encryption, so full-disk encryption alone can't protect off-site devices.
> DEF CON 34: 10 Vulnerabilities Put Local AI at Risk: Running AI models on your own servers protects data privacy but still exposes you to serious security flaws in the underlying software that must be patched and locked down.
> Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin: A flaw in Red Hat's Kubernetes management tool lets low-privileged users seize full cluster-admin control, and no fix exists yet.
> CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files: Crafted files can crash Cisco's ClamAV open-source antivirus scanner, so teams should patch Windows endpoints first and treat untrusted uploads as availability risks until fixes ship.
Other news you might like
- New StormEncryptor ransomware used by former Medusa affiliateLINK
- North Korean spies are running local LLMs to cause AI mischiefLINK
- LiteLLM Supply Chain Attack Potentially Exposes 2,500 Companies and 434,000 CI/CD PipelinesLINK
- A researcher bought noreply.net. Companies started sending him secrets.LINK
- U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gangLINK
- New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC AccessLINK
- DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting FilesLINK
- Android Banking Droppers Surge as Malware Operators Change Packaging TacticsLINK
π§° Trending tools
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure across major frameworks.LINK
MonoCloud for Startups: provides a unified identity layer handling authentication, fine-grained authorization, and access control for users, APIs, and AI agents, free for one year.LINK
Halo by Scam AI: an API-first tool that combines NLP, visual, and audio authentication to detect synthetic media and flag malicious intent patterns.LINK
HOL Guard: a firewall for AI agents that intercepts and blocks high-risk actions, like deleting production data or exposing secrets, before they execute.LINK
Cynative Security Research Agent: an open-source CLI that answers plain-language security questions across GitHub, AWS, GCP, Azure, and Kubernetes, enforcing read-only IAM policy checks.LINK
disrobe: a reverse-engineering toolkit that decompiles, deobfuscates, and unpacks code from Python, Java, .NET, WebAssembly, JavaScript, and Go programs.LINK
π Trending papers & reports
AI-generated exploit reports often fail basic reliability checks, with only ~56% of tested vulnerability-validation artifacts running successfully and their built-in pass or fail signals correct barely half the time.LINK
MQOM v2.1's signature scheme can be fully broken from a single valid signature, letting an attacker extract the secret key and forge signatures, despite the scheme being a Round-3 candidate in NIST's post-quantum signature competition.LINK
Confidential computing for RISC-V chips lets automotive controllers, crypto accelerators, and telco gear run isolated, protected software using standard commodity hardware, with no special extensions or licensing fees required.LINK
Vulnerability report triage lets a trained model sort security scanner outputs so it catches 99.2% of real exploitable flaws while cutting the manual review pile by 75%, saving analysts time.LINK
SOC 2 code compliance jumps from as low as 47% to at least 86% once a prompt simply names the standard, showing AI-written code defaults to real security gaps unless compliance is explicitly requested.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!