Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π McDonald's staff records sold by hacker
π macOS flaw lets hackers hijack Macs
π«π· France tax hack exposes 678,000 taxpayers
π€ New botnet hijacks routers as proxies
π SAP Commerce Cloud flaw actively exploited
Plus: π‘ 5 strategies & tactics, π 7 other news you might like, π§° 6 tools, and π 5 papers.
π McDonald's staff records sold by hacker LINK
π macOS flaw lets hackers hijack Macs LINK
π«π· France tax hack exposes 678,000 taxpayers LINK
π€ New botnet hijacks routers as proxies LINK
π SAP Commerce Cloud flaw actively exploited LINK
π‘ Strategies & Tactics
> Hazmat: Open-source containment for AI agents: Hazmat runs AI coding agents in a separate account that sees only your project folder, keeping your keys and cloud credentials out of reach.
> Ruby 4.0 Marshal.load RCE Gadget Chain Exposes Critical Deserialization Risk: A new attack turns Ruby's built-in data-loading feature into remote code execution, so developers should stop feeding it untrusted input and switch to safer formats like JSON.
> How Cloudflare detects MCP traffic and helps secure it: Cloudflare One now spots AI agent traffic on company networks and blocks connections that bypass approved servers, since agents can repeat harmful actions faster than humans catch them.
> Escalating a Blind Upload to RCE via Path Traversal into Cron and DNS-Restricted Callback Bypass: Turning a locked-down file upload into server takeover by writing a scheduled task file into a directory that the system's cron scheduler automatically runs.
> Metasploit Wrap Up: Lot of summer shells and fit http profiles: Metasploit 6.5 adds thirteen new exploit modules plus disguisable HTTP traffic and Windows-on-ARM shells, expanding what penetration testers can attack and evade.
Other news you might like
- GLM-5.3 is here with advanced cyber capabilities, and reportedly already found a 'serious vulnerability' in CursorLINK
- Microsoft Plans to End SMS and Voice Authentication for Entra IDLINK
- Plaintiff hid invisible AI instructions in court filings to secretly influence automated reviewLINK
- 12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade DetectionLINK
- MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing KitsLINK
- Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows MalwareLINK
- SafePal data breach impacts 39,798 customers, stolen info for saleLINK
π§° Trending tools
FireTail: an AI security and governance platform that gives visibility into AI usage across your environments, helping teams detect and secure risks before they cause harm.LINK
BestDefense.io: continuously pentests every deploy, validates which vulnerabilities are truly exploitable, and auto-generates fixes so SaaS teams patch real risks fast.LINK
Sequirly: browser extension that scans prompts and file uploads before they reach ChatGPT, Claude, or Gemini, flagging API keys and personal data.LINK
DeepFrame: an authorized penetration testing studio for fast-moving web apps, delivering deep security assessments with clear reporting and follow-up retests.LINK
Origin: a confidential agentic stack pairing a private LLM gateway, AI IDE, agents, attestation, and sandboxes for regulated teams in defense and finance.LINK
Skill Inspector: scans AI-generated code and skills for security vulnerabilities, delivering automated remediation guidance directly within developer workflows to reduce risk.LINK
π Trending papers & reports
Encrypted traffic screening spots malicious industrial network commands hidden inside scrambled TLS traffic, lifting rare-attack detection by ~43 points and hitting over 95% accuracy while running fast enough for real-time use on factory edge devices.LINK
Safety filter tune-ups let companies fix a content moderation model's mismatched judgment calls without retraining it, catching up to 0.81 of previously missed unsafe content and flagging every one of ten simulated attack campaigns in testing.LINK
Apple's Lockdown Mode falls short as protection for high-risk users like journalists or activists, offering little clarity on what threats it blocks, clunky controls, and noisy alerts that annoy more than they protect.LINK
Passkey backup design lets people export and restore locked hardware login credentials onto new devices without exposing private keys, closing a recovery gap that currently forces buying spare authenticators in advance.LINK
Threat intel extraction shows a specialized text-reading system can pull attacker names, targeted industries, and breach locations from messy real-time posts on X with ~89% accuracy, beating fine-tuned chatbots while running faster.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!