Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🏥 Polish health software breach hits 19M
🔓 WordPress plugin flaw exposes 600K sites
🛡️ CISA: Patch exploited AI flaw now
🖥️ Exploit code hits Microsoft SCCM flaw
🔒 GitLab patches critical flaw that let attackers delete public projects
Plus: 💡 4 strategies & tactics, 🎁 5 other news you might like, 🧰 6 tools, and 📚 5 papers.
🏥 Polish health software breach hits 19M LINK
🔓 WordPress plugin flaw exposes 600K sites LINK
A flaw in WordPress's Forminator form plugin lets attackers upload malicious files and hijack sites, so update to version 1.56.2 immediately.
🛡️ CISA: Patch exploited AI flaw now LINK
🖥️ Exploit code hits Microsoft SCCM flaw LINK
🔒 GitLab patches critical flaw that let attackers delete public projects LINK
💡 Strategies & Tactics
> Video Call Exploit Chains Two Flaws in Unisoc Modems: Researchers showed that chaining two Unisoc modem flaws lets an attacker seize Android kernel control after the victim answers a malicious video call.
> Google’s open-source HEIR lets AI work with data it can’t see: Google's HEIR compiler converts AI models to run on encrypted data, letting healthcare and finance apps analyze sensitive information without ever exposing its contents.
> Behavioral Malware Analysis: Investigating a Multi-Stage Malware Sample Inside an Isolated Lab: Run malware in an isolated lab and watch it live to capture the attack behaviors static analysis misses, then turn those observations into detection rules defenders can actually use.
> There’s a libcurl.dll in my system32: A stray libcurl.dll flagged by a scanner must be updated by whichever app installed it, not by the curl project itself.
Other news you might like
- Geekom admits to shipping malware-laced network drivers for AMD mini PCs, company responds with guidance, removes malicious packageLINK
- Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet CredentialsLINK
- C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.LINK
- Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed PhrasesLINK
- VMware Syslog Path Traversal Becomes Root RCE, Persistent SSH Access and ESXi RansomwareLINK
🧰 Trending tools
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure across major frameworks.LINK
Perfai Security: an automated tool that scans AI-generated apps from Replit, Lovable, Cursor, and Claude Code for access control vulnerabilities, fixing them with a single prompt.LINK
Constellation Gate AI: routes AI agent traffic through a gateway that blocks prompt injections, scans for secrets, logs audit trails, and cuts token costs 20-40% via compression and caching.LINK
TailMux: lets you connect to multiple Tailscale tailnets simultaneously on macOS and Linux by running isolated embedded nodes per profile, routing by hostname without switching accounts or VMs.LINK
Lunen.ai: an AI automation tool that logs every action taken and requires approval on risky steps, giving teams usability without sacrificing oversight.LINK
qsa.sh: scans your server's public IP with naabu, nmap, and nuclei to reveal open ports, service versions, and known CVEs in about 30 seconds, no signup required.LINK
📚 Trending papers & reports
AI agent "skills" can be secretly tweaked so their normal network traffic patterns leak private user information to an eavesdropper, even though the tweaks pass existing AI security audits.LINK
Retrieval poisoning defense retrains only a tiny sliver of a search system's encoder, under 1% extra parameters, so poisoned lookalike content gets filtered out before it ever reaches the chatbot's answer, with no added per-query slowdown.LINK
DeepSeek's AI assistant can be tricked by hidden instructions buried in files or text, with attacks succeeding up to ~26% of the time, showing untrusted content needs stronger checks before it reaches sensitive actions.LINK
AI-built network attack simulations matched traditional training methods with a 94.5% success rate at finding security holes, while running about 25,000 to 50,000 times faster.LINK
Next-gen network security flags malicious traffic in live 6G-style test networks while cutting the data needed to spot attacks by 80%, and pinpoints exactly which traffic traits give hackers away.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!