Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🛡️ Microsoft patches nearly 400 security holes
🎥 AI finds Zoom flaw that hijacks devices
🎭 Russian hackers use fake job interviews
🔥 Firewall flaw lets hackers crash Cisco devices
🔍 Anthropic watermarks Claude text
Plus: 💡 4 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.
🛡️ Microsoft patches nearly 400 security holes LINK
🎥 AI finds Zoom flaw that hijacks devices LINK
🎭 Russian hackers use fake job interviews LINK
🔥 Firewall flaw lets hackers crash Cisco devices LINK
🔍 Anthropic watermarks Claude text LINK
💡 Strategies & Tactics
> ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch: A researcher publicly released working exploit code showing Microsoft's July fix for a Defender flaw fails, still letting attackers gain full system control on updated Windows machines.
> How Trail of Bits helps verify the integrity of your Signal chats: Trail of Bits runs one of three independent auditors that continuously verify Signal's public keys are consistent, so a compromised server can't secretly swap in an attacker's key.
> Chrome adopts what may be the best protection yet against account takeovers: Chrome now locks login session cookies to a device's security chip, blocking attackers who steal those cookies from reusing them to hijack accounts.
> Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks: Attackers can gain full Windows control by faking a USB device, since PnP (Plug and Play) driver installs run vendor code with SYSTEM privileges before login.
Other news you might like
- Mozilla updates GPG signing key for Firefox releases after exposureLINK
- Kimwolf botnet rebuilt to survive takedowns, researchers sayLINK
- Delta investigating after someone set up fake Wi-Fi network mid-flightLINK
- CopyEscape: Taking Over Docker Hosts with docker cpLINK
- Malicious SIMs can shut down phones, steal files, and drag 5G back to 2GLINK
- One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RATLINK
- DeadLock ransomware uses blockchain to resist infrastructure takedownLINK
🧰 Trending tools
FireTail: an AI security and governance platform that gives visibility into AI usage across your environments, helping teams detect and secure risks before they cause harm.LINK
BestDefense.io: continuously pentests every deploy, validates which vulnerabilities are truly exploitable, and auto-generates fixes so SaaS teams patch real risks fast.LINK
Sequirly: browser extension that scans prompts and file uploads before they reach ChatGPT, Claude, or Gemini, flagging API keys and personal data.LINK
DeepFrame: an authorized penetration testing studio for fast-moving web apps, delivering deep security assessments with clear reporting and follow-up retests.LINK
Origin: a confidential agentic stack combining a private LLM gateway, AI IDE, agents, attestation, and sandboxes for defense, finance, and regulated teams.LINK
Refuse: blocks known-vulnerable package installs across npm, pip, cargo, gem, go and 13 more managers before they hit disk, self-hostable via Docker.LINK
📚 Trending papers & reports
IoT security explanations can cost 700 seconds per batch for one detection model versus under 2 seconds for another, and smart triage still cuts compute by 15-32% without hiding dangerous false negatives.LINK
Tamper-proof execution tracking lets tiny embedded devices prove exactly what code path they ran, using hardware safeguards instead of vulnerable stored keys, while data sent back grows only in step with program size, not exponentially.LINK
Invisible code fingerprints let companies mark AI-generated code as their own without breaking how it runs, and let owners prove authorship later without ever exposing the secret watermark itself.LINK
Automated red teaming trains one chatbot to invent attacks against another, generating more effective English jailbreak prompts than existing benchmarks and, for the first time, doing the same in Turkish.LINK
AI agents that take real-world actions face far less security research than chatbots, a review of 85 studies finds attack research outpaces defense work nearly 4 to 1, with only 4.7% examining the risky tool-use and code-execution steps that actually cause damage.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!