Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π€ Google reveals Gemini AI breached three external firms
π΄ββ οΈ ShinyHunters hacks ransomware gang Clop
π§ CISA flags 3 exploited Linux kernel flaws
π¦ cPanel flaw exploited to spread Mirai
π Attackers copied 170 CrowdSec code repos
Plus: π‘ 6 strategies & tactics, π 7 other news you might like, π§° 6 tools, and π 5 papers.
π€ Google reveals Gemini AI breached three external firms LINK
π΄ββ οΈ ShinyHunters hacks ransomware gang Clop LINK
π§ CISA flags 3 exploited Linux kernel flaws LINK
π¦ cPanel flaw exploited to spread Mirai LINK
π Attackers copied 170 CrowdSec code repos LINK
π‘ Strategies & Tactics
> SAML: A fractal of bad design: Retire SAML, an aging web login standard, for simpler modern alternatives because its reliance on complex XML makes it perpetually vulnerable to authentication-bypass attacks.
> New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches: Web caches that build lookup keys by jamming request values together without separators let attackers forge collisions to reach restricted pages and serve poisoned responses.
> BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates: A public proof-of-concept tool can quietly block Windows Defender updates, leaving computers running but blind to newly discovered malware.
> Malicious npm packages evade install-script defenses at runtime: Attackers now hide npm malware in a package's normal runtime functions, slipping past install-script blocks so defenders must add runtime behavioral scanning.
> Revoking the token didnβt kill the backdoor: A stealthy backdoor swaps its cloud login credentials on command, so revoking stolen tokens only delays attackers; instead isolate the host and hunt sign-in logs.
> I found a malicious app disguised as a PDF reader that Google Play Protect didn't catch: Vet every app yourself since store scans miss threats like a fake PDF reader that pushed ads and phishing links past Google's protections.
Other news you might like
- Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS BackdoorsLINK
- Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal PasswordsLINK
- Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOLINK
- Colorado Water Utilities Hit by Cyberattacks Targeting OT SystemsLINK
- Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsLINK
- Settra ransomware variant deployed in recent attacksLINK
- Remus Infostealer Removes Syscall Hooks to Evade EDR and Steal Sensitive CredentialsLINK
π§° Trending tools
Halo: an API-first platform that detects deepfakes and synthetic media across text, image, and audio, helping fraud and trust teams block attacks.LINK
Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents with sub-20ms overhead, mapping to SOC 2, EU AI Act, and ISO 27001LINK
Cybermes: an autonomous framework for offensive security and bug bounty testing, using AI agents and multiple language models to automate red teaming tasks.LINK
jevals: replaces LLM-based evaluation judges with typed Jev decisions, providing structured, deterministic assessments for testing and validating language model outputs.LINK
Seal: an iOS app that stores encrypted passwords, photos, and voice memos in envelopes that unlock for family members via hardware keys after your death.LINK
cxgrd: a CLI tool that enforces architectural guardrails to keep AI-generated code aligned with your project's structure and design conventions.LINK
π Trending papers & reports
Model theft attacks can now steal a neural network's valuable trained parameters using only the yes-or-no answers it gives, letting an outsider copy a proprietary model without ever seeing inside it.LINK
Re-identification risk audits give each published document a mathematically backed score for how easily an attacker armed with a language model could match it to a real person, guiding safer release decisions.LINK
Chatbot safety defenses work best when layered together rather than used alone, and this first systematic test across 19 attacks and 15 defenses shows well-chosen combinations block most jailbreaks without hurting usefulness.LINK
Coder security instincts were tested on 100 developers vetting AI-written code, revealing they often can't spot planted vulnerabilities and lean on trust over verification, exposing a foundational weak point in AI-assisted software development.LINK
Cryptographic hardware security test measures how well AI models spot flaws in chip-level implementations that protect connected devices, finding top models score up to ~84% overall but explain their security verdicts correctly only ~53% of the time.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!