Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π°π΅ North Korean hackers steal Gmail data
π¨π³ AI tools doubled Chinese state hacking
π§ AWS patches credential-theft flaw
π Hackers exploit WordPress plugin flaw
π Keycloak flaw lets attackers hijack accounts
Plus: π‘ 6 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π°π΅ North Korean hackers steal Gmail data LINK
π¨π³ AI tools doubled Chinese state hacking LINK
π§ AWS patches credential-theft flaw LINK
π Hackers exploit WordPress plugin flaw LINK
π Keycloak flaw lets attackers hijack accounts LINK
π‘ Strategies & Tactics
> HOL Guard: Open-source antivirus for AI agents: HOL Guard is a free tool that pauses AI coding assistants before risky actions and asks permission, running locally so your files stay private.
> Anthropic Rolls Out Enterprise-Managed Auth for Claudeβs MCP Connectors: Anthropic lets admins authorize Claude's workplace-tool connectors once through their identity provider, so employees inherit access automatically instead of each approving connectors manually.
> Attackers bypass Windows security without physical access: Researchers bypassed Windows 11's strongest defenses remotely by rewriting unprotected memory configuration chips found in modules from Corsair, G.Skill and ADATA.
> The OWASP LLM Top 10: What Application Security Teams Need to Know About LLM Vulnerabilities: Securing AI chatbots requires new controls like tool-level authorization and prompt monitoring, since traditional code-scanning tools cannot catch prompt injection or unsafe model outputs.
> Microsoft Teams now lets admins block external bots from meetings: Microsoft Teams admins can now automatically block outside bots from joining meetings, closing a security gap where hidden non-human participants could enter unnoticed.
> The Pi-hole mistakes that can expose your entire browsing history: Never expose your Pi-hole's admin panel to the internet; instead reach it remotely through a private encrypted tunnel like WireGuard to protect your browsing logs.
Other news you might like
- 5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD PasswordsLINK
- PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2LINK
- Fake Codex installer tricks Mac users into pasting malware, Cato findsLINK
- You don't want this Sleepwalker backdoor on your Windows machineLINK
- AliExpress caught using silent audio to fingerprint visitorsβ browsersLINK
- EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing PasswordsLINK
- WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 DisruptionLINK
- TP-Link Archer Command Injection Flaws Enable Root-Level Code ExecutionLINK
π§° Trending tools
Kastra: runtime authorization layer that enforces policies on AI agent actions before execution, blocking unauthorized tool use, prompt injection, and data exposure with sub-millisecond latency.LINK
Perfai Security: autonomously scans AI-generated apps for access-control, business-logic, and prompt-injection flaws, then ships confirmed fixes as pull requests around the clock.LINK
Halo: an API-first tool combining NLP, visual, and audio authentication to detect deepfakes and synthetic media for fraud and trust teams.LINK
FireTail: an AI security and governance platform that discovers shadow AI, enforces policies from frameworks like OWASP, and centralizes logging across environments.LINK
ORGN CDE: an enterprise AI IDE that generates code privately using confidential computing, provable encryption, and zero data retention for security-conscious teams.LINK
Sequirly: browser extension that scans prompts and uploads before they reach ChatGPT, Claude, or Gemini, catching API keys, credentials, and personal data.LINK
π Trending papers & reports
AI decision logs get a tamper-evident record format that captures each time an automated system releases, blocks, or escalates an output, letting outside parties verify what happened offline without trusting the vendor.LINK
CyberFactory turns public vulnerability reports into hands-on training exercises for open-source models, producing Aegis, a freely available AI that finds, exploits, and patches security flaws, closing the gap with closed commercial tools.LINK
Training-data detection can reveal whether a specific image was used to train an AI image generator using as few as two probes, catching leaks up to 3x better than methods needing 30 probes.LINK
Safety hacking shows that filtering many chatbot answers through an imperfect safety check and picking the highest-scoring one can reliably surface unsafe replies, because generating more options amplifies the rare mistakes the filter misses.LINK
Secure vision AI at the edge can now run entirely inside a protected hardware vault that hides the model from attackers, hitting fast graphics-chip speeds so safety-critical camera apps stay both quick and private.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!