Hi there, this is your daily โ๏ธ Cyberpresso.
In today's Cyberpresso:
๐ฑ Malicious themes steal iPhone crypto wallets
๐ McKesson breached via phishing
๐ Exploit targets Microsoft Exchange servers
๐ Token exploit drains $75M from lender
๐ Hijacked routing delivers malicious update
Plus: ๐ก 6 strategies & tactics, ๐ 7 other news you might like, ๐งฐ 6 tools, and ๐ 5 papers.
๐ฑ Malicious themes steal iPhone crypto wallets LINK
๐ McKesson breached via phishing LINK
๐ Exploit targets Microsoft Exchange servers LINK
๐ Token exploit drains $75M from lender LINK
๐ Hijacked routing delivers malicious update LINK
๐ก Strategies & Tactics
> Breaking the Seal: Static Deobfuscation of JSCealโs Compiled V8 Bytecode: Check Point built a free static tool that unpacks JSCeal's compiled, obfuscated cryptocurrency-stealer code so analysts can read its logic without running the malware.
> OEMpocalypse Now: Targeting the custom Android layers phone makers like Samsung and Xiaomi add lets one root exploit span an entire brand's lineup regardless of chipset.
> How to Build a Hypothesis-Driven Threat Hunting Program: Build threat hunting as a documented program with structured hypotheses and telemetry checks so results stay consistent, prove coverage gaps, and survive staff turnover.
> Automate IAM Identity Center governance with continuous discovery and reporting: Explains how to track who can access which AWS applications by deploying a tool that continuously discovers user assignments and generates audit-ready reports.
> AWS S3 Bucket Security: Find the Secrets Hiding Outside Git: Scan S3 storage buckets for exposed credentials, since 28% of secret leaks now hide in logs and backups rather than code repositories.
> This Windows tool lets you see exactly which apps are phoning home (and lets you cut them off): Portmaster, a free tool, shows every outbound connection your Windows apps make and lets you block trackers or telemetry per app.
Other news you might like
- Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ OrganizationsLINK
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setLINK
- Financially Motivated Threat Actor BREEZE COMET Targets BrazilLINK
- Nightmare Eclipse Drops โHardBreacherโ Kaspersky Product ExploitLINK
- New RevStealer malware spreads as fake Claude Opus 5 desktop appLINK
- Infostealers are hijacking Claude accounts at usersโ expenseLINK
- Indeed Job Scam: Fake Recruiters Are Spreading Android SpywareLINK
๐งฐ Trending tools
Kastra: runtime authorization layer that enforces policies on AI agent actions before execution, blocking unauthorized tool use, prompt injection, and data exposure with sub-millisecond latency.LINK
Perfai Security: autonomously tests AI-built apps for access-control, business-logic, and prompt-injection flaws, then opens pull requests with confirmed fixes around the clock.LINK
qsa.sh: runs external port and vulnerability scans of your public IP using naabu, nmap, and nuclei, streaming results to your terminal in seconds with no install.LINK
HOL Guard: a local firewall for AI agents that intercepts risky actions like deleting production data or exposing secrets before they runLINK
Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across code, cloud, and runtime with read-only, IAM-enforced access to production.LINK
Aegisora: an open-source proxy layer that guards LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging.LINK
๐ Trending papers & reports
Virtual reality logins can use passwords tied to the surrounding 3D scene instead of digits, and in a 66-person study over 2-3 weeks people remembered them better and found the process less mentally taxing than 6-digit PINs.LINK
Video watermarking lets anyone verify a clip's origin with just a public key while making it impossible to forge, proving authentic on 99.3% of 1000 real clips and never accepting a fake key.LINK
Encryption-key extraction shows that a simple, standard AI setup can steal a chip's full secret key from raw power measurements, matching specialized tools while training in under 3.3 hours on one graphics card.LINK
AI agent accountability gives a way to prove which automated service produced a given output and whether it was authorized to hand off work, catching forged claims that older single-signature methods miss.LINK
Backdoored language models can be cleaned by pinpointing the specific hidden triggers that make them misbehave, cutting successful attacks to under ~11% for one attack type and ~15% for another without hurting normal performance.LINK
See you tomorrow for a new dose of โ๏ธ Cyberpresso!