Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π« US firearms agency hit by ransomware
π₯ Cyberattack halts Boston Scientific shipments
π΅οΈ FBI seizes Chinese hacking tools
π CISA orders urgent Citrix flaw patch
π Ransomware affiliate hit 20 firms using AI
Plus: π‘ 6 strategies & tactics, π 5 other news you might like, π§° 6 tools, and π 5 papers.
π« US firearms agency hit by ransomware LINK
π₯ Cyberattack halts Boston Scientific shipments LINK
π΅οΈ FBI seizes Chinese hacking tools LINK
π CISA orders urgent Citrix flaw patch LINK
π Ransomware affiliate hit 20 firms using AI LINK
π‘ Strategies & Tactics
> Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation: Correlate alerts across AWS security services with your own knowledge of sensitive resources and normal access to catch multi-stage attacks that individual findings miss.
> Red Flags That Expose Fake North Korean IT Workers: Watch for telltale signs like remote-control PiKVM hardware and heavy VPN use to catch North Korean operatives posing as remote IT hires.
> Snowflake ends service-account passwords. Now comes the hard part: Snowflake is blocking passwords for machine accounts, forcing companies to finally track who owns each one and what breaks when access ends.
> Linux Foundation Introduces TRACE Standard for AI Runtime Evidence: The Linux Foundation's TRACE standard creates a tamper-proof, hardware-backed receipt proving what an AI agent actually did, so organizations can independently verify sensitive AI activity.
> CISA Shares Federal Cyber Guidance With Critical Infrastructure Companies: CISA, the U.S. cyber agency, released network logging guidance for federal agencies that critical infrastructure companies can also use to detect and respond to attacks faster.
> Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Whoβs Exploiting Your Perimeter: Two independent security datasets show that both nation-state and criminal hackers target the same edge devices like firewalls and VPN gateways, so defenders must patch against all attackers at once.
Other news you might like
- GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI PipelinesLINK
- Iran-linked hackers expand infrastructure across Europe and Middle East, report saysLINK
- Two Alleged βTeamPCPβ Hackers Arrested in AustraliaLINK
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal AccountsLINK
- New Apache Log4j2 Flaw Lets Attackers Bypass Security Checks and Execute Remote CodeLINK
π§° Trending tools
Kastra: runtime authorization layer that enforces policies on AI agent actions before execution, blocking unauthorized tool use, prompt injection, and data exposure with sub-millisecond latencyLINK
qsa.sh: runs an external port and vulnerability scan of your public IP with naabu, nmap, and nuclei, streaming results to your terminal via curl in seconds.LINK
Claudoscope: menu bar app for Claude Code that browses session history, tracks token costs, scans for leaked secrets, and lints config files locally.LINK
HOL Guard: a local firewall for AI agents that intercepts and blocks risky actions like deleting production data or exposing secrets before they run.LINK
Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across your code, cloud, and runtime with IAM-enforced read-only access.LINK
SolonGate: a zero-trust security layer that intercepts AI agent tool calls, applying policy checks to block unauthorized or destructive actions before they run.LINK
π Trending papers & reports
Phone-to-phone contract signing lets two devices co-sign a document by scanning an animated on-screen code, with no server, no certificate authority, and no internet, using each phone's built-in security chip to prove identity.LINK
Face-swap privacy tools often leak the original person's identity despite hiding their face, and a new method explains why and predicts when this happens, making privacy claims verifiable rather than just assumed.LINK
Code search tools can be tricked by renaming variables in a snippet without changing what it does, pushing irrelevant code to the top of results and cutting search accuracy by up to ~77%.LINK
AI-written server setup code ships with security flaws by default, but adding security rules to the request makes top models hit 95 to 100 percent compliance, roughly quadruple human developers.LINK
Office document ingestion can feed AI a hidden version of a Word, Excel, or PowerPoint file that differs from what people see on screen, with tested AI systems surfacing planted hidden facts in 48 to 76% of trials.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!