Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
πͺ Windows flaw now under active attack
π T-Mobile cut cable to expel hackers
π° Hackers use AI to hit water systems
π¦ Fake Firefox add-ons steal crypto wallets
π Citrix NetScaler flaw bypasses logins
Plus: π‘ 5 strategies & tactics, π 7 other news you might like, π§° 6 tools, and π 5 papers.
πͺ Windows flaw now under active attack LINK
π T-Mobile cut cable to expel hackers LINK
π° Hackers use AI to hit water systems LINK
π¦ Fake Firefox add-ons steal crypto wallets LINK
π Citrix NetScaler flaw bypasses logins LINK
π‘ Strategies & Tactics
> AWSHound: An OpenSource AWS OpenGraph Collector: AWSHound is a free, read-only tool that maps real attack paths across AWS accounts by simulating how stacked permission policies actually combine, revealing multi-step routes that survive normal policy reviews.
> A revisit of remote Spectre attacks on Cloudflare Workers: Cloudflare patched its Workers platform after researchers proved a Spectre attack could still leak data across tenants sharing one process, risking cross-customer memory exposure.
> Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations: A researcher used Claude to scan open-source login systems and found authentication-bypass flaws, showing AI can speed up security testing but also overwhelm maintainers with reports.
> Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days: Google's AI security agents can now scan stolen code and flag over 100 critical vulnerabilities in two days, matching the speed attackers using AI already exploit.
> AWS deprecated this EKS auth method. 81% of clusters still run it.: Manage Kubernetes clusters as one fleet with security enforced by default, since 81% of Amazon EKS clusters still use a retired, hard-to-audit access-control method.
Other news you might like
- Hackers compromise 14,500 Dahua web cameras in 35-day campaignLINK
- SilkParasite Threatens Central Asian Orgs With Flurry of RATsLINK
- Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka AppsLINK
- DOJ charges 17 people in Iran-backed hacking campaign against USLINK
- Rogue ransomware affiliate poses as data recovery firm to steal paymentsLINK
- Updated ToxicPanda Variant Targets 140+ Banking and Crypto AppsLINK
- Fake Gemini installer delivers Vidar infostealer via Google Colab lureLINK
π§° Trending tools
Kastra: enforces authorization policies on AI agents at runtime, blocking unauthorized tool use and data exposure across major agent frameworks.LINK
FireTail: an AI security and governance platform that surfaces AI usage across your environments so teams can detect and mitigate risks early.LINK
BestDefense.io: automatically pentests each deploy, confirms which vulnerabilities are actually exploitable, and generates fixes so SaaS teams prioritize and patch real risks fast.LINK
Sequirly: browser extension that scans your prompts and uploads before they hit ChatGPT, Claude, or Gemini, catching API keys and personal data.LINK
DeepFrame: an authorized penetration testing studio for web apps, delivering deep security assessments with clear reporting and follow-up retests to verify fixes.LINK
Origin: confidential agentic stack combining a private LLM gateway, AI IDE, agents, attestation, and sandboxes for regulated defense and finance teams.LINK
π Trending papers & reports
Automated bug hunting gets a smarter dial that coordinates five testing tactics as one setting refreshed every 5 seconds, uncovering more code paths than standard tools on all eight tested software targets.LINK
Private-data collaboration lets companies jointly train models on encoded data without exposing raw records, closing a loophole where a snooping coordinator could reconstruct a partner's private data by adding noise to shared reference points instead.LINK
Connected-car defense spots fake safety alerts, like a false emergency brake signal, in ~10 milliseconds and escalates uncertain cases up a three-layer chain, so cars react to real dangers without being tricked into dangerous braking.LINK
Hidden image watermarks can now survive when most of a picture is cropped away, recovering copyright tags from as little as 30% of an image where rival methods fail completely.LINK
Satellite spoofing defense gets a real-world benchmark, with 5.2 million messages from 66 satellites, letting security teams reliably test whether they can tell genuine satellites from impersonators, hitting ~98% accuracy across days in the best setup.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!