Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π± New Android malware clones cards mid-call
π°π΅ North Korea targets defense firms
πΉπΌ AI agents hacked Taiwan's government
π΅οΈ Salesforce guest access leaked data
π₯οΈ VMware vCenter flaw hit in 47 countries
Plus: π‘ 6 strategies & tactics, π 5 other news you might like, π§° 6 tools, and π 5 papers.
π± New Android malware clones cards mid-call LINK
π°π΅ North Korea targets defense firms LINK
πΉπΌ AI agents hacked Taiwan's government LINK
π΅οΈ Salesforce guest access leaked data LINK
π₯οΈ VMware vCenter flaw hit in 47 countries LINK
π‘ Strategies & Tactics
> Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders: Security teams can use this open-source toolkit to inventory and monitor the files that AI coding agents leave behind on developer machines before attackers exploit them for account access or network reconnaissance.
> Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor: Akira attackers reboot Windows into Safe Mode to disable endpoint detection tools before encrypting files, so defenders should flag unexpected boot changes and require VPN multi-factor login.
> SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit: Attackers began exploiting a critical SharePoint login-bypass flaw within days of Rapid7 publishing exploit code, so apply July's patch immediately.
> WordPress RCE Vulnerability Lets Authenticated Authors Execute Remote Code: Update WordPress to 7.0.4 immediately, since a flaw lets contributors with author access run code on sites using the Imagick and Ghostscript tools.
> Could a Shirt Fool Facial Recognition? The Answer Is Complicated: Anti-surveillance patterns can lower an AI camera's confidence that a person is present, but they often fail on new people and remain unproven on actual clothing.
> 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection: Security researchers found 737 free Chrome VPN extensions that impersonate trusted brands and route all browser traffic through one operator's servers, exposing 75,000 users.
Other news you might like
- Hackers exploit critical Adobe Commerce flaw to hijack customer accountsLINK
- Armored Likho Turns Windows Microphones Into Automated Eavesdropping DevicesLINK
- Fake CCleaner downloads turn Chrome into a credential-stealing surveillance toolLINK
- Phantom Stealer Uses PNG Steganography and PowerShell Injection to Steal CredentialsLINK
- Belgium's eID Authentication Opens Citizen Accounts to RCELINK
π§° Trending tools
Perfai Security: an automated tool that scans AI-generated apps from Replit, Lovable, Cursor, and Claude Code for access control vulnerabilities, fixing them with a single prompt.LINK
Constellation Gate AI: routes AI agent traffic through a gateway that blocks prompt injections, scans for secrets, logs audit trails, and cuts token costs 20-40% via compression and caching.LINK
TailMux: lets you connect to multiple Tailscale tailnets simultaneously on macOS and Linux by running isolated embedded nodes per profile, routing by hostname without switching accounts or VMs.LINK
Lunen.ai: an AI automation tool that logs every action taken and requires approval on risky steps, giving teams usability without sacrificing oversight.LINK
Shieldstral: provides open-source AI models with permissive licensing, plus optimized commercial models offering flexible deployment options for teams needing performance.LINK
qsa.sh: scans your server's public IP with naabu, nmap, and nuclei to reveal open ports, service versions, and known CVEs in about 30 seconds, no signup required.LINK
π Trending papers & reports
Battlefield 5G verification checks that a military device's hardware and boot software are untampered, not just its SIM credential, closing a gap where captured or altered devices could rejoin tactical 5G networks undetected.LINK
Graph model theft gets blocked by a live "structural firewall" that spots suspicious queries stealing a company's proprietary graph AI, without hurting accuracy for real users.LINK
Hidden model triggers can be exposed before deployment by feeding a chatbot's own replies back into itself, catching hidden backdoors in five of six tested models with ~92% precision, versus almost no detection from simply repeating the same prompt.LINK
IoT firmware scanning gets a human-checked test set showing an ensemble of trained detectors catches vulnerabilities far better than static analyzers, missing only 21% versus 71%, at a fixed 0.5% false-alarm rate.LINK
Network intrusion detection catches more real attacks by tracking each device's behavior over time instead of judging one connection at a time, scoring ~83% higher recall and ~70% higher accuracy than the leading tool, with no extra false alarms.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!