Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π Revolut breach exposes user passports
π Researchers reveal OpenAI agents attacked RubyGems in May
π¨ Hackers exploit max-severity GitLab flaw
π Sogou flaw exploited to plant backdoor
Plus: π‘ 4 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π Revolut breach exposes user passports LINK
π Researchers reveal OpenAI agents attacked RubyGems in May LINK
π¨ Hackers exploit max-severity GitLab flaw LINK
π Sogou flaw exploited to plant backdoor LINK
π‘ Strategies & Tactics
> New fuzzing tool finds security vulnerabilities in WordPress plugins: A WordPress-specific automated testing tool called THEMIS finds server-side security flaws in plugins by watching traffic between plugin code and the WordPress core.
> macOS Tahoe 26.4 update stops you from copying your login Keychain: Apple now ties the login Keychain to each Mac's security chip, blocking manual credential copying to another machine and complicating corporate bulk migrations.
> Turn it off and on again, but for critical infrastructure: An automated defender that estimates how far an intrusion has spread, then reboots infected machines to expel attackers, works but assumes the attacker's behavior is known in advance.
> Update your firewall rules: Teams and Copilot are changing address: Update firewall and proxy rules before early October, since Microsoft is moving Teams and Copilot web access to new cloud.microsoft addresses.
Other news you might like
- GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push PipelineLINK
- Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows ProcessLINK
- Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank WebsitesLINK
- Malicious Twitch extension exposed OAuth tokens of 30,000 usersLINK
- ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksLINK
- Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing CapabilitiesLINK
- Microsoft: September updates cause RDS failures on Windows ServerLINK
- Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome HijackerLINK
π§° Trending tools
Kastra: runtime authorization layer for AI agents that evaluates every action in under a millisecond, blocking unauthorized tool use and logging tamper-proof audit trails.LINK
Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across code, cloud, and Kubernetes using read-only, IAM-enforced production access.LINK
Aegisora: an open-source proxy that secures LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging.LINK
Reark: An intelligent reverse engineering analysis tool designed for multiple target platforms, currently supporting HarmonyOS (HAP/APP/ABC) and Android (APK/AAB).LINK
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.LINK
Spanda: measures epistemic uncertainty in LLM outputs with sub-microsecond latency, implemented in Rust for high-performance inference monitoring.LINK
π Trending papers & reports
VR motion privacy tools that scramble body-tracking data to prevent user identification are better judged by asking real users what they'll accept than by measuring movement distortion alone, which misses most of what drives acceptance.LINK
Style-aware text rewriting rewrites documents to erase the personal writing quirks that let systems re-identify anonymous authors, cutting re-identification accuracy 60-70% while keeping meaning and readability intact, beating existing privacy methods.LINK
Personal attribute snooping now traces exactly which few posts reveal your age, income, or job, hitting ~87% accuracy while flagging the source for over 98% of guesses, so people can redact only the leaky posts.LINK
Agent skill safety shows that malware scanners approving code as clean still let AI agents run prohibited actions, and a rule-based gate caught all 23 forbidden attempts they tried, closing a real permissions gap.LINK
Password-free phone login on websites can leak users' phone numbers in a single visit, with a one-year study finding ~74% of over 116,000 sites carrying flaws that enable these one-click identity leaks.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!