Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π£ Phishing kit bypasses Microsoft 365 MFA
πͺ Windows apps turned into kernel backdoors
π οΈ ConnectWise flags unpatched ScreenConnect flaw
π‘οΈ SAP patches 4 critical flaws
π¦ Rootkit hides web shells in F5 servers
Plus: π‘ 4 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π£ Phishing kit bypasses Microsoft 365 MFA LINK
πͺ Windows apps turned into kernel backdoors LINK
π οΈ ConnectWise flags unpatched ScreenConnect flaw LINK
π‘οΈ SAP patches 4 critical flaws LINK
π¦ Rootkit hides web shells in F5 servers LINK
π‘ Strategies & Tactics
> Stealing AI Reasoning Traces: Researchers found that encrypted AI reasoning traces work across sessions and models, letting attackers steal hidden reasoning, private data, and credentials.
> New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away: Beaming radio energy at headphones' analog parts makes them leak recoverable audio from up to 30 meters, defeating software-only defenses and requiring hardware shielding.
> Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day: A researcher published working attack code for an unpatched Nvidia flaw that crashes graphics apps and could let attackers escalate beyond their own permissions.
> AI Customer Service Bots Can Be Tricked Into Stealing Security Codes and Acting as Victims: Attackers can trick AI support bots into leaking security codes and impersonating customers, so businesses must treat these agents as privileged systems with limited permissions.
Other news you might like
- ClickFix moves into the browser and onto WebDAV, Cisco Talos findsLINK
- Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain CompromiseLINK
- IT Help Desk Impersonation Lets Hackers Bypass MFALINK
- Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attackLINK
- Known npm Worm Returns After 111 Days and Security Scanning Still Let It ThroughLINK
- Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy AttacksLINK
- THost9 Android RAT Pairs Packed Loader With ADB WormLINK
- Hackers Create Domain Admin Account and Disable Security Tools Inside Windows NetworkLINK
π§° Trending tools
Halo: an API-first platform combining text, image, and audio analysis to detect deepfakes and synthetic media, helping fraud and trust teams block attacks.LINK
Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents in under 20ms, mapping to SOC 2, EU AI Act, and ISO 27001 compliance frameworksLINK
TailMux: runs multiple Tailscale profiles simultaneously on macOS and Linux, routing by hostname so work and personal tailnets stay reachable at once.LINK
Lunen.ai: an AI assistant that logs every action, flags risky steps for approval, and maintains audit trails your security team can trust.LINK
VHF Morse Transmitter Monitor: a browser-based tool that transmits Morse code over VHF radio by exploiting electromagnetic interference leaked from computer monitors.LINK
Dsnitch: monitors Docker container network egress in real time using eBPF, mapping IPs to domains via passive DNS snooping in a terminal interface.LINK
π Trending papers & reports
Intrusion-detection upgrades should be checked before a retrained model replaces the live one, since whether the new model is actually better depends heavily on the dataset and how much evidence backs it.LINK
Electromagnetic eavesdropping shows attackers can beam radio signals at everyday electronics to force them to leak hidden data, letting them capture headphone audio from up to 30 meters away, even through walls.LINK
Attack testing for AI agents shows that a tireless automated hacker gets more effective the longer it probes a tool-using agent, meaning security reviews must account for how much effort an attacker spends, not just the target's defenses.LINK
AI-written phishing emails get more dangerous with every personal detail added, raising click intention ~28% per level in a study of 180 workers, though wrong or vague details actually make targets more suspicious.LINK
Private search on encrypted data runs meaningfully faster by parking the heavy lifting in secure GPU chips with large protected memory, hiding both what users query and which records they touch without the old speed penalty.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!