Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π₯ Video conferencing installers push malware
π AI data giant Alation confirms cyberattack
π¦ Poisoned Rust package hits 244M downloads
π Hackers exploit Microsoft cloud login flaw
π‘οΈ Defender driver can be turned off EDR
Plus: π‘ 5 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π₯ Video conferencing installers push malware LINK
π AI data giant Alation confirms cyberattack LINK
π¦ Poisoned Rust package hits 244M downloads LINK
π Hackers exploit Microsoft cloud login flaw LINK
π‘οΈ Defender driver can be turned off EDR LINK
π‘ Strategies & Tactics
> CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users: Injected line-break characters can trick mismatched web servers into caching malicious pages on content networks, serving attacker scripts to real visitors of trusted sites.
> AWS Shows How to Stop a Hijacked AI Agent From Reading Data the User Cannot Access: Enforce data-access permissions in the infrastructure rather than the AI agent's own code, so a hijacked agent still cannot retrieve data the user cannot access.
> Appleβs Private Find My People Reversed to Decrypt Live Shared Locations on Linux: A researcher reverse-engineered Apple's private location-sharing protocol on Linux, documenting for the first time how Find My distributes and rotates its encryption keys.
> Encrypted web page payload turns Grok into a chat history leak: Hiding malicious commands as encrypted text on webpages sneaks past Grok's safety filter, tricking the bot into leaking users' private chat data to attackers.
> Agentic IAM: How to secure and manage AI agent identities: Manage each AI agent as its own tracked identity with continuously checked, least-privilege access so its actions stay authorized and traceable.
Other news you might like
- New Manic Android malware can exfiltrate data through nearby devicesLINK
- Going with the Flow(s): Distinct Clusters Target Individuals of Interest to RussiaLINK
- Critical flaw patched in popular JavaScript sandbox used in AI projectsLINK
- Critical Elementor Pro bug exposes WordPress sites to RCE attacksLINK
- Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory DataLINK
- Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.LINK
- BadBox-linked Android malware has now infected car head unitsLINK
- New SynkLoader malware uses fake Windows lock screen to steal passwordsLINK
π§° Trending tools
Perfai Security: automatically detects and fixes access control vulnerabilities in AI-generated apps from Replit, Lovable, Cursor, and Claude Code with one prompt.LINK
Constellation Gate AI: a proxy layer between your agents and LLMs that filters threats, reduces token costs, and logs every request for auditing.LINK
Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents in under 20ms, mapping to SOC 2, EU AI Act, and ISO 27001.LINK
TailMux: runs multiple Tailscale profiles simultaneously on macOS and Linux, routing by hostname so work and personal tailnets stay reachable without switching accounts.LINK
Lunen.ai: an AI assistant that logs every action, requires approval on risky steps, and pairs clean UX with audit trails your security team can actually use.LINK
Aegisora: an open-source proxy layer that intercepts malicious LLM actions, enforces least-privilege API access, masks PII, and logs autonomous agent activity for audits.LINK
π Trending papers & reports
Prompt injection defense lets a chatbot keep learning to block new manipulation tricks as attackers evolve without forgetting old ones, cutting successful attacks by up to ~6x versus current defenses.LINK
Lightweight attack detection lets small internet-connected devices spot malicious traffic on their own, without needing a heavy companion model to train against, staying accurate across 13 cybersecurity datasets covering botnets, malware, and network intrusions.LINK
Robot sound monitoring verifies whether a robot is actually performing its assigned tasks by listening to the noise its movements make, catching errors or tampering with over 80% accuracy and no hardware changes.LINK
Shared-training privacy gets a two-layer shield that scrambles both the model updates and the training images so attackers can't reconstruct users' data, without hurting accuracy beyond what the encryption alone costs.LINK
Behavioral authentication reads a phone's ordinary system logs to keep verifying it's still the enrolled user after login, flagging suspicious changes with under 1% false alarms and no extra sensors.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!