Hi there, this is your daily βοΈ Cyberpresso.
In today's Cyberpresso:
π Ransomware gangs exploit TeamCity flaw
π¦ Android trojan steals banking PINs
π§ Roundcube email flaw under active attack
π Next.js flaw enables remote code execution
π₯· New trick hides malware from EDR
Plus: π‘ 6 strategies & tactics, π 8 other news you might like, π§° 6 tools, and π 5 papers.
π Ransomware gangs exploit TeamCity flaw LINK
π¦ Android trojan steals banking PINs LINK
π§ Roundcube email flaw under active attack LINK
π Next.js flaw enables remote code execution LINK
π₯· New trick hides malware from EDR LINK
π‘ Strategies & Tactics
> How One Kubernetes YAML Can Hand Over a GCP Organization: Because Google's config tool runs every cloud command through its own broadly privileged account, any developer allowed to submit files can seize the whole organization.
> GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs: A never-expiring token hidden in GitLab's project email addresses lets anyone who finds it push code and run pipelines as the account owner.
> OWASP LLM Top 10 2026: Every Move Points the Same Direction: The reordered rankings signal that AI security's biggest threats now come from live applications taking actions, not from models generating text.
> 58 hardware vulnerabilities: A guide to the threats: Catalogs 58 processor and memory hardware flaws since Meltdown and Spectre, showing why such silicon-level bugs are slow or impossible to fully patch.
> Vulnerability alert fatigue nearly swamped WHOOP. But its fix still keeps a human in charge.: WHOOP automated its security-alert triage to focus engineers on real threats and route them to the right owners, while keeping humans deciding critical fixes.
> The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference: Detonating suspicious links in an interactive sandbox reveals the redirects and hidden login pages that appear only after a click, closing phishing's post-alert visibility gap.
Other news you might like
- There's a new way to break RSA that's faster than anything we've seen beforeLINK
- Placeholder domain used in dev docs now serves ClickFix attacksLINK
- Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google AccountsLINK
- Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK FilesLINK
- New Windows Malware Built to Survive Takedowns With a Hidden P2P Command NetworkLINK
- Australian prime minister says OpenAI agent accessed government health website, raises 'extreme concern'LINK
- MacSync under the microscope: new delivery methods and a new payloadLINK
- New Galago Ransomware Operation Emerges With Links to Panzer GroupLINK
π§° Trending tools
Halo: detects deepfakes and synthetic media across text, image, and audio through an API, helping fraud and trust teams block attacks.LINK
Execlave: governs autonomous AI agents with tiered autonomy levels, real-time spend caps, kill switches, and audit logs mapped to SOC 2, EU AI Act, and ISO 27001.LINK
qsa.sh: scans your public IP for open ports and known vulnerabilities using naabu, nmap, and nuclei, streaming results to your terminal via one curl commandLINK
Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across code, cloud, and Kubernetes using read-only, IAM-enforced production access.LINK
Aegisora: an open-source proxy for securing LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging in production.LINK
Cybermes: an autonomous framework for offensive security, bug bounty, and red teaming, using reasoning skills and multi-model LLM orchestration.LINK
π Trending papers & reports
Private-data chatbots can now answer questions from sensitive documents while spending their limited privacy protection only when they actually need the private data, wasting far less budget and staying accurate under strict privacy limits.LINK
Model-stealing attacks can now copy an image-recognition system's full blueprint, both its hidden design and its internal settings, without knowing anything about its structure beforehand, making proprietary vision models easier to clone.LINK
SilentLedger lets private blockchains stay confidential yet fully auditable, so regulators can uncover identities and amounts when justified without users or auditors ever interacting, matching or beating existing privacy systems on speed.LINK
Cybercrime infrastructure ads can be automatically spotted on Telegram, revealing that ~19% of over a million messages hawk criminal hosting or VPNs and that one community drives half of them, helping investigators prioritize targets.LINK
Crypto mixer laundering now has the first public dataset of 9,300 tagged transactions spanning 1.1 billion across 27 real cases, plus a detection tool that flags laundering flows better than existing methods.LINK
See you tomorrow for a new dose of βοΈ Cyberpresso!