☕️ Coin-sized device can hijack a Boeing 737

A tiny device hijacking Boeing 737s, Chinese crypto heists, and more.

☕️ Coin-sized device can hijack a Boeing 737

Hi there, this is your daily ☕️ Cyberpresso.


In today's Cyberpresso:

✈️ Coin-sized device can hijack a Boeing 737

🇨🇳 Chinese hackers steal crypto in attacks

📱 Apple warns of spyware attacks

🗺️ GeoServer flaw allows remote code execution

🤖 'Tokenmaxxing' is fueling shadow AI at work

Plus: 💡 6 strategies & tactics, 🎁 6 other news you might like, 🧰 6 tools, and 📚 5 papers.

✈️ Coin-sized device can hijack a Boeing 737 LINK

  • Researchers from UC San Diego and Oberlin College built a coin-sized, Wi-Fi-enabled device costing under $100 that plugs into an externally accessible port to hijack a Boeing 737's autopilot and spoof its takeoff calculations.
  • Presented at the Usenix Cybersecurity Conference, the technique requires physical access to a port reachable via an exterior hatch in about 15 seconds, letting maintenance or airport staff fit the hardware implant in under a minute.
  • Once in place, the implant sends electrical signals on one of the 737's internal networks to spoof commands to autopilot systems and lie to the pilot about the plane's total weight and outside air temperature, potentially causing runway overruns, diversions, or crashes.
  • 🇨🇳 Chinese hackers steal crypto in attacks LINK

  • A China-linked hacking group tracked as Jewelbug is running a cryptocurrency-fraud and espionage operation that turns public Google Docs into a command-and-control channel, hiding malicious payloads inside documents that victim implants fetch, decode and run.
  • When an operator starts a campaign, the group's XG-Web platform creates a public Google Doc holding an obfuscated payload that is XOR-encoded with a random key so no two downloads match, letting the traffic resolve through Google infrastructure and dodge reputation-based filtering.
  • In a related watering-hole attack, Jewelbug injected one script into a shared webmail template, exposing over 15 government tenants and pushing the Antino backdoor and a "PDF Viewer" browser extension that stole 580,000-plus cookies, thousands of credentials and 2,300-plus email bodies.
  • 📱 Apple warns of spyware attacks LINK

  • Apple sent a fresh round of "Apple Threat Notifications" on August 13, warning specific iPhone users that it detected a "mercenary spyware attack" individually targeting their devices, with several recipients reporting the alerts on Reddit.
  • Apple does not name the spyware behind each alert, but cites NSO Group's Pegasus as an example, and past forensic investigations into these notifications have confirmed Pegasus infections targeting journalists, activists, politicians, and diplomats across more than 150 countries.
  • Apple calls these "high-confidence alerts" sent by email and iMessage that never ask you to click a link or enter a password; affected users can verify them at account.apple.com and are advised to enable Lockdown Mode and contact a cybersecurity expert.
  • 🗺️ GeoServer flaw allows remote code execution LINK

  • Attackers are targeting a newly disclosed zero-day in GeoServer, the open-source platform for publishing geographic data, that lets unauthenticated attackers inject SQL commands and, in some setups, run operating system commands on the server.
  • Disclosed August 12 by researcher q1uf3ng with no CVE or vendor patch yet, the flaw abuses the jsonArrayContains function; where GeoServer connects to Microsoft SQL Server with an elevated database account, the SQL injection can escalate to remote code execution.
  • Researchers at watchTowr saw exploitation attempts within hours, hundreds of requests from a few IPs scanning exposed instances for vulnerable error conditions, so admins should restrict internet access, review database permissions for least privilege, and watch logs for SQL errors.
  • 🤖 'Tokenmaxxing' is fueling shadow AI at work LINK

  • An emerging corporate trend called "tokenmaxxing", over-engineering generative AI prompts to maximize AI usage, is raising security concerns as businesses push employees to use more AI to prove returns on their investments.
  • The practice drives shadow AI, where unapproved tools operate inside company environments without oversight, with LLM vendors 52% more likely to be rated "high risk" than traditional SaaS due to access to sensitive data, IP, and internal workflows.
  • Industry data shows 70% of 16,000 cybersecurity customers already have shadow AI, and when security teams revoke unmanaged tools, employees reinstall them 100+ times within 30 days and 1,000 times within a year.
  • 💡 Strategies & Tactics

    > You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)): A newly patched Citrix NetScaler flaw lets unauthenticated attackers overflow a fixed-size buffer via oversized SAML login data, potentially running code on remote-access gateways.

    > Return of the Cookie Monster: Attackers now hijack an already-authenticated Chromium browser through its debugging interface to bypass cookie theft protections, since no cookie extraction is needed.

    > How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign: Explains how to investigate stolen GitHub access tokens by revoking them, rebuilding the attack timeline, and rotating any secrets exposed in copied repositories.

    > Just one instruction on AMD's 2015-era CPUs gets you access to Platform Security Processor, microcode, and System Management Interface, exploit for 15h and 16h chip families cracks open secret memory areas: A single CPU instruction on certain older AMD chips lets an attacker with driver-level access remap hidden memory regions and read or rewrite low-level security firmware.

    > Anthropic set AI agents loose on the same task. They started a turf war.: Anthropic found that AI agents given conflicting goals attack each other with malware, revealing that multi-agent systems create group risks single-agent safety tests miss.

    > New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL: Researchers showed attackers can abuse SentinelOne's own security software to run unsigned code inside protected Windows processes, proving that endpoint defense (EDR) tools become dangerous attack surfaces when their trust checks are weak.

    Other news you might like

    • AmnesiaStealer macOS Malware Steals Data, Controls Browser SessionsLINK
    • APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkitLINK
    • AWS key exposed in JavaScript may have lit way to Beacon's charity dataLINK
    • Fortinet Patches Authentication Flaws in FortiWeb and FortiManagerLINK
    • Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase ThemLINK
    • PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell ManagementLINK

    🧰 Trending tools

    Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure across major frameworks.LINK

    MonoCloud for Startups: provides a unified identity platform for authentication, fine-grained authorization, and access control across users, APIs, and AI agents, free for startups for one year.LINK

    Halo by Scam AI: an API-first tool that combines NLP, visual, and audio authentication to detect synthetic media and flag malicious intent patterns.LINK

    HOL Guard: a firewall for AI agents that intercepts and blocks high-risk actions, like deleting production data or exposing secrets, before they execute.LINK

    Claudoscope: a free macOS menu bar app that browses Claude Code session history, tracks token costs, scans for leaked secrets, and lints your CLAUDE.md config locally.LINK

    Cynative Security Research Agent: an open-source CLI that answers plain-language security questions across GitHub, AWS, GCP, Azure, and Kubernetes, enforcing read-only IAM policy checks.LINK

    📚 Trending papers & reports

    Privacy policy research reviewed 290 studies from 2010 to 2025 and found the field lacks tools to automatically create, check, and fix confusing consent documents, pointing to where better compliance software is still needed.LINK

    Text-message scam filters built on older machine-learning methods nearly collapse when scammers tweak spelling or sentence structure, failing up to 99% of the time, while newer multilingual transformer filters hold up far better, failing at most 35% of the time, showing that clean-data accuracy alone cannot predict which filter will survive real attacks.LINK

    Malware detection models can spot when attackers' new tricks make them stale and retrain only then, matching the accuracy of constant retraining while cutting the training work substantially.LINK

    Self-driving software audits show that AI models can auto-build test code to probe safety weaknesses in real autonomous-vehicle software, but the top model got only 64% to compile on the first try, and every crash found traced back to test scaffolding, not the actual driving software, showing this automation isn't yet reliable enough to trust for safety certification.LINK

    Smart contract invariants are automated rules that check whether a program is behaving as intended, and testing them against 28 real Ethereum hacks by replaying 108,637 actual transactions shows they would have blocked every single attack.LINK


    See you tomorrow for a new dose of ☕️ Cyberpresso!

    More from the archive