Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
✈️ Coin-sized device can hijack a Boeing 737
🇨🇳 Chinese hackers steal crypto in attacks
📱 Apple warns of spyware attacks
🗺️ GeoServer flaw allows remote code execution
🤖 'Tokenmaxxing' is fueling shadow AI at work
Plus: 💡 6 strategies & tactics, 🎁 6 other news you might like, 🧰 6 tools, and 📚 5 papers.
✈️ Coin-sized device can hijack a Boeing 737 LINK
🇨🇳 Chinese hackers steal crypto in attacks LINK
📱 Apple warns of spyware attacks LINK
🗺️ GeoServer flaw allows remote code execution LINK
🤖 'Tokenmaxxing' is fueling shadow AI at work LINK
💡 Strategies & Tactics
> You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)): A newly patched Citrix NetScaler flaw lets unauthenticated attackers overflow a fixed-size buffer via oversized SAML login data, potentially running code on remote-access gateways.
> Return of the Cookie Monster: Attackers now hijack an already-authenticated Chromium browser through its debugging interface to bypass cookie theft protections, since no cookie extraction is needed.
> How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign: Explains how to investigate stolen GitHub access tokens by revoking them, rebuilding the attack timeline, and rotating any secrets exposed in copied repositories.
> Just one instruction on AMD's 2015-era CPUs gets you access to Platform Security Processor, microcode, and System Management Interface, exploit for 15h and 16h chip families cracks open secret memory areas: A single CPU instruction on certain older AMD chips lets an attacker with driver-level access remap hidden memory regions and read or rewrite low-level security firmware.
> Anthropic set AI agents loose on the same task. They started a turf war.: Anthropic found that AI agents given conflicting goals attack each other with malware, revealing that multi-agent systems create group risks single-agent safety tests miss.
> New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL: Researchers showed attackers can abuse SentinelOne's own security software to run unsigned code inside protected Windows processes, proving that endpoint defense (EDR) tools become dangerous attack surfaces when their trust checks are weak.
Other news you might like
- AmnesiaStealer macOS Malware Steals Data, Controls Browser SessionsLINK
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkitLINK
- AWS key exposed in JavaScript may have lit way to Beacon's charity dataLINK
- Fortinet Patches Authentication Flaws in FortiWeb and FortiManagerLINK
- Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase ThemLINK
- PATCHCORD Infrastructure Hosts SuperShell C2 for Remote Commands and Webshell ManagementLINK
🧰 Trending tools
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure across major frameworks.LINK
MonoCloud for Startups: provides a unified identity platform for authentication, fine-grained authorization, and access control across users, APIs, and AI agents, free for startups for one year.LINK
Halo by Scam AI: an API-first tool that combines NLP, visual, and audio authentication to detect synthetic media and flag malicious intent patterns.LINK
HOL Guard: a firewall for AI agents that intercepts and blocks high-risk actions, like deleting production data or exposing secrets, before they execute.LINK
Claudoscope: a free macOS menu bar app that browses Claude Code session history, tracks token costs, scans for leaked secrets, and lints your CLAUDE.md config locally.LINK
Cynative Security Research Agent: an open-source CLI that answers plain-language security questions across GitHub, AWS, GCP, Azure, and Kubernetes, enforcing read-only IAM policy checks.LINK
📚 Trending papers & reports
Privacy policy research reviewed 290 studies from 2010 to 2025 and found the field lacks tools to automatically create, check, and fix confusing consent documents, pointing to where better compliance software is still needed.LINK
Text-message scam filters built on older machine-learning methods nearly collapse when scammers tweak spelling or sentence structure, failing up to 99% of the time, while newer multilingual transformer filters hold up far better, failing at most 35% of the time, showing that clean-data accuracy alone cannot predict which filter will survive real attacks.LINK
Malware detection models can spot when attackers' new tricks make them stale and retrain only then, matching the accuracy of constant retraining while cutting the training work substantially.LINK
Self-driving software audits show that AI models can auto-build test code to probe safety weaknesses in real autonomous-vehicle software, but the top model got only 64% to compile on the first try, and every crash found traced back to test scaffolding, not the actual driving software, showing this automation isn't yet reliable enough to trust for safety certification.LINK
Smart contract invariants are automated rules that check whether a program is behaving as intended, and testing them against 28 real Ethereum hacks by replaying 108,637 actual transactions shows they would have blocked every single attack.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!