Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
πͺͺ 153M driver's licenses sold on dark web
πΈοΈ FBI dismantles 23-year-old Sality botnet
π SonicWall flaw allows login-free access
π JFrog flaw grants attackers admin tokens
Plus: π‘ 6 strategies & tactics, π 7 other news you might like, π§° 6 tools, and π 5 papers.
πͺͺ 153M driver's licenses sold on dark web LINK
πΈοΈ FBI dismantles 23-year-old Sality botnet LINK
π SonicWall flaw allows login-free access LINK
π JFrog flaw grants attackers admin tokens LINK
π‘ Strategies & Tactics
> Android App RCE via Dynamic Code Loading: Attackers can smuggle a malicious code file into an Android app's private folder using a path-traversal trick, then trigger it for full remote code execution.
> 1-Click ATO Via Host Header Injection: Exploiting Password Reset Poisoning.: Building password reset links from the attacker-controllable Host header lets a hacker steal the reset token and take over accounts (ATO) with one victim click.
> Hiding a Signup Button Isnβt Security: From Client-Side Controls to Cross-Tenant Data Exposure: Client-side feature flags like a hidden signup button don't enforce security, since attackers can call the backend API directly to register, escalate privileges, and steal other organizations' credentials.
> Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira: Sift scans across file shares, Microsoft 365, Slack, and Jira because credentials hide everywhere, so a clean file-share scan proves nothing about the rest.
> Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars: Adapting an industrial-controller exploit with Claude still demands hours, expert oversight, and hundreds of dollars, but that cost may soon fall across many targets.
> Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.: Add a query-time filter checking each user's permissions before retrieval so an AI assistant never surfaces documents that user couldn't otherwise open.
Other news you might like
- Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPragueLINK
- Dropbox breach seemingly caused by egregious authentication failure [U]LINK
- Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeksLINK
- Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server TakeoverLINK
- Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponLINK
- Chrome and Firefox Updates Patch Dozens of VulnerabilitiesLINK
- Critical HPE Fabric Composer Flaw Lets Unauthenticated Attackers Execute Commands as Privileged UserLINK
π§° Trending tools
Halo: an API-first tool combining NLP, visual, and audio authentication to detect deepfakes and synthetic media, helping fraud and trust teams block attacks.LINK
MonoCloud for Startups: handles authentication and Cedar-based authorization for users, APIs, and AI agents, letting you control, audit, and revoke access, free for a yearLINK
Shieldstral: provides free open AI models with permissive licenses plus optimized commercial versions, giving developers flexible, efficient deployment options for various needs.LINK
Playground: hands-on sandbox for testing prompt injection attacks against AI agents, helping you understand and explore real LLM security weaknessesLINK
cain-agent: an AI penetration testing tool for authorized security assessments, with built-in support for AWS, Azure, GCP, and Chinese cloud providers.LINK
DeepSec: an AI security platform that audits AI-generated code for errors in real time and automates authorized penetration testing with 40+ skill packs.LINK
π Trending papers & reports
3D scene watermarking hides ownership marks ranging from text to full 3D shapes inside photorealistic 3D reconstructions without degrading image quality or requiring costly retraining, giving creators a way to prove copyright and deter unauthorized use.LINK
AI-written system code is kept from directly controlling risky, irreversible actions like device commands, letting a fixed trusted gatekeeper approve each action so safety holds even if the code generator is dishonest.LINK
Anonymous internet traffic can now be made accountable, letting users stay private online while a trusted party can still unmask senders who break the rules, without slowing every packet with heavy cryptography.LINK
AI-powered scams can be fought most effectively by boosting how often, how centrally, and how accurately people report them, since these three levers multiply together to slash scam profits, against 442 billion in yearly losses.LINK
Ownership tags for graph AI hide a secret fingerprint inside models that predict connections, like friend suggestions or fraud links, letting owners prove theft even after 21 tested removal tricks.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!