Hi there, this is your daily ☕️ Cyberpresso.
In today's Cyberpresso:
🍎 Apple fixes actively exploited iPhone flaw
🪖 Pentagon breach exposes military records
🔓 16,000 databases leak passwords
🕵️ GPT-6 Astra ran forbidden attacks
🕸️ Microsoft reveals NeedyMantis malware behind stealthy network persistence
Plus: 💡 5 strategies & tactics, 🎁 7 more stories you might like, 🧰 5 tools, and 📚 5 papers.
🍎 Apple fixes actively exploited iPhone flaw LINK
🪖 Pentagon breach exposes military records LINK
🔓 16,000 databases leak passwords LINK
🕵️ GPT-6 Astra ran forbidden attacks LINK
🕸️ Microsoft reveals NeedyMantis malware behind stealthy network persistence LINK
💡 Strategies & Tactics
> SAML assertion forgery: how the attack works and how to stop it: Attackers who steal an identity provider's signing key can forge login tokens to impersonate anyone, so treat that infrastructure like your most sensitive servers.
> How cross-account trust creates exploitable privilege boundaries: Overly permissive cross-account role trust policies can let low-privilege identities in one AWS account seize privileged access in another, breaking account isolation.
> New Remote DoS Attacks Against GraphQL Java: Newly found flaws let attackers crash servers running GraphQL Java with a single tiny request, so teams should upgrade immediately or restrict endpoint access.
> How we found 24 Android vulnerabilities using our open source AI security agent: Guiding an AI security agent with mobile-specific checklists uncovered 24 real Android app flaws, though humans must still verify each finding's severity.
> The Guardrail Paradox: From Full Disclosure To Full Access: AI safety guardrails that block security defenders as readily as attackers slow incident response, so labs should pre-approve responders for expedited access during live attacks.
Other news you might like
- OpenAI apologises for Australian government website hack by rogue AI agent, vows to ‘rebuild trust’LINK
- OpenAI exposes “new variety of prompt injection” that can spread like computer wormsLINK
- One Packet Can Crash OT Servers in Industrial SectorsLINK
- Critical WatchGuard API Vulnerabilities Enables Command Execution AttacksLINK
- 31 Chrome VPN extensions let operators change where users’ traffic goesLINK
- AgtaBackup RAT Uses Fake Microsoft Store Pages and RMM Tools to Hijack Windows SystemsLINK
- Kiteworks patches critical flaw, brings customer systems onlineLINK
🧰 Trending tools
Execlave: governs autonomous AI agents through tiered autonomy levels, real-time spend caps, kill switches, and compliance-mapped audit logs for SOC 2, ISO 27001, and the EU AI Act.LINK
Aegisora: an open-source proxy that secures LLM agents through least-privilege API access, PII masking, prompt-injection blocking, and audit logging for production.LINK
pentest-harness: a self-hosted AI agent framework for authorized penetration testing, bug bounties, security labs, and CTFs, keeping sessions local with your own model.LINK
proxy-scraper: scans and tests large lists of free proxies, checking which ones work and detecting those injecting malicious scripts.LINK
Prized: builds secure internal tools with AI for ops, support, and finance teams, featuring pre-connected data, access audit trails, and one-click deploy behind company sign-in.LINK
📚 Trending papers & reports
BenX hashing is a new cryptographic building block for proof systems that verify computations were done correctly, running up to 2x faster on chips and proving results 6 to 10x faster than a rival.LINK
Compressed IoT security can silently miss half the attack types it should catch, and the culprit is over-trimming one tiny input layer, a flaw fixable at almost no cost without retraining.LINK
Quantum-safe signatures now run entirely on a single low-cost chip for small edge devices, using up to ~9.9x less hardware than the only prior full design, which needed at least two chips.LINK
Card reissuance limits can backfire, with a bank's intuitive move to spread compromised card numbers across less crowded prefixes actually making fraudsters more likely to find live cards in three of twelve tested scenarios.LINK
Privacy-safe decision trees keep training data confidential while staying far more accurate than existing private methods, handle mixed numerical and categorical data without leaks, and resist tampering where attackers plant hidden triggers, with provable guarantees.LINK
See you tomorrow for a new dose of ☕️ Cyberpresso!