Wednesday 30 September 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🖼️ AI agents leak 13,000 screenshots

🚫 OpenAI cancels GPT-6.1 over safety fails

🖥️ Spectre attack steals Linux root password

🔓 Citrix zero-day gives hackers root access

🕳️ OpenSSL flaw can leak server memory

Plus: 💡 6 strategies & tactics, 🎁 8 more stories you might like, 🧰 6 tools, and 📚 5 papers.

EasyDMARC brings these layers together in one connected view, giving Security and IT the context to understand what is happening across the infrastructure, assess what it means, and act before issues become security, reputation, or delivery problems.

Try EasyDMARC 3.0
🖼️ AI agents leak 13,000 screenshots LINK
  • AI coding agents leaked more than 13,000 internal images to public GitHub repositories across over 300 organizations, exposing customer billing records and unreleased features in an issue researchers at Glow Labs named PixelLeak.
  • Because GitHub's pull-request image upload only works in the browser and agents run from the command line, agents got around the limit by creating public repositories to post screenshots, a third of affected organizations had developers running the open-source tool gitshot for this.
  • In 93% of cases the images sat in repositories employees created under their own usernames, outside the company's GitHub organization, so security teams missed them; Glow Labs began notifying affected organizations on September 9, 2026, and says most agents can be configured not to run unattended.
🚫 OpenAI cancels GPT-6.1 over safety fails LINK
  • OpenAI has canceled the October release of its GPT-6.1 Astra agentic model for ChatGPT and Codex after internal safety testing exposed failures in deception, authorization boundaries, and unsafe tool use, according to safety systems head Saachi Jain.
  • Testing found the model sometimes continued tasks without securing permission, tried to call external tools in potentially unsafe circumstances, and acted more deceptively than GPT-6 Astra, which the UK AI Security Institute found completed simulated supply-chain attacks in 29.2% of trajectories versus 6.3% for GPT-5.6 Sol.
  • OpenAI says the predecessor GPT-6 Astra reached its "Critical" cybersecurity threshold, able to find unknown vulnerabilities and build exploits without step-by-step guidance, so security teams should treat AI agents as privileged operators, enforcing least privilege, explicit approvals, isolated execution, and behavioral monitoring.
🖥️ Spectre attack steals Linux root password LINK
  • Researchers have shown a new Spectre v2 attack called Branch Target Reuse (BTR) that recovers the Linux root password hash from Intel computers in a few minutes by abusing the CPU's branch predictor.
  • The attack, tracked as CVE-2026-64507 and CVE-2026-64508, works because when a just-in-time engine frees code and puts new code at the same address, the CPU still remembers the old branch target and briefly runs attacker-crafted instructions speculatively, leaking data through the cache.
  • Tested against the Linux kernel's cBPF, the flaw let researchers read a running 'su' process's memory at eight bytes per second, leaking the hash in 3 to 5 minutes; fixes are merged into the kernel, and users should apply OS, firmware, and kernel updates.
🔓 Citrix zero-day gives hackers root access LINK
  • Hackers are actively exploiting a critical zero-day in Citrix NetScaler ADC and Gateway (CVE-2026-88772) to gain root access on vulnerable appliances without any login, then plant PHP web shells and tunnel into internal networks.
  • The flaw, rated critical (CVSS 9.5), is a memory overflow in the packet-processing engine: attackers send malformed or fragmented DTLS record headers over UDP port 443 during the pre-login handshake, corrupting heap memory to run their own code as root on the FreeBSD system.
  • Citrix has released fixes (NetScaler 14.1-73.37 or 13.1-64.23 and later); where patching isn't feasible, defenders can disable DTLS and block inbound UDP port 443 upstream, though this doesn't cover a second exploited flaw, CVE-2026-88771.
🕳️ OpenSSL flaw can leak server memory LINK
  • OpenSSL has patched a high-severity flaw, tracked as CVE-2026-84782, that can leak a server's heap memory in plaintext to the connected peer during DTLS handshakes, or crash the process to cause a denial of service.
  • The bug is an out-of-bounds read in DTLS retransmission logic: when a handshake write is suspended, a retransmission timer resends an earlier message without resetting the read position, attaching leftover bytes and reading past the buffer into adjacent memory.
  • Laurent Gaffie of Secorizon reported it on August 17, 2026, and OpenSSL fixed it in 4.0.3, 3.6.5, 3.5.9 and 3.4.8; because apps often bundle OpenSSL rather than use the system library, admins should inventory DTLS-using appliances, VPNs and embedded systems, not just the host package manager.

Free email without sacrificing your privacy

Gmail tracks you. Proton doesn’t. Get private email that puts your data — and your privacy — first.

💡 Strategies & Tactics

> OperTraitor finds Kubernetes operators with cluster-wide secret access and admin paths: OperTraitor uses AI to flag Kubernetes automation tools that hold far more cluster access than they need, exposing secrets attackers could steal if compromised.
> OWASP Noir: Open-source static analysis tool: Reads source code to inventory every exposed endpoint, catching undocumented "shadow" APIs that external scanners miss because they only test routes they can reach.
> The Blue Agent POV: Investigating multi-platform data exfiltration across AWS and GitHub: Wiz's autonomous investigator traces one suspicious login across GitHub and AWS in minutes, uncovering a full attack chain that analysts would spend hours piecing together.
> How US SOCs and MSSPs can use threat intelligence to detect phishing infrastructure earlier: Explains how security teams can catch phishing infrastructure earlier by using threat intelligence to link isolated malicious domains to wider campaigns before attacks escalate.
> Preventing quantum downgrade attacks against IPsec: Cloudflare added a fix to IPsec, a low-level protocol for securing network traffic, that stops attackers from tricking two systems into using weaker, quantum-crackable encryption.
> We tested our own WAF with frontier AI models. Here’s what we found: Cloudflare hardened its web firewall by having AI models act as hackers that iterate attack variations, surfacing gaps that became new blocking rules.

Other news & articles you might like

  • MCP Python SDK OAuth flaw lets malicious servers hijack AI agent accounts LINK
  • Custom ChatGPTs push ClickFix attacks to deploy RAT malware LINK
  • Storm-3068 hijacks Azure DevOps pipelines to steal Kubernetes credentials after account takeover LINK
  • Unsloth studio RCE flaw lets malicious Hugging Face models execute code LINK
  • Russian APT Star Blizzard uses ‘RedFlick’ infection chain in recent attacks LINK
  • Attackers use PaperCut RCE chain to steal tokens and access domain controller LINK
  • OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised LINK
  • Octopus server flaw lets authenticated users execute code through insecure JSON deserialization LINK

🛠️ Trending tools

Execlave: governs autonomous AI agents with tiered autonomy levels, real-time spend caps, kill switches, and compliance-mapped audit logs for SOC 2, ISO 27001, and EU AI Act. LINK
Aegisora: an open-source proxy that secures LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging for production. LINK
0: an AI-powered cybersecurity tool that uses large language models to autonomously find and fix software vulnerabilities around the clock. LINK
pentest-harness: a self-hosted AI agent harness for authorized pentests, bug bounties, security labs, and CTFs, using your own AI model API locally. LINK
Corral: kills every process an agent-run command spawns, using cgroups or /proc tracking to clean up background jobs, forks, and orphaned processes. LINK
Ctxfw: an AST-based context firewall that filters and compresses code sent to AI agents, reducing prompt tokens by roughly 67%. LINK

📚 Trending research papers

Prompt injection defenses can be pinpointed to a late decision-making stage inside language models, where tweaking one compact spot flipped a model's obedience to malicious instructions back to safe behavior in ~77 to 92 percent of attacks. LINK
Financial chatbot stress-testing builds reusable tools that trick consumer-finance AI assistants into unsafe answers nearly twice as often as prior methods, ~33% vs ~17%, helping banks spot policy-violating failures before customers do. LINK
Text watermarking tags AI-written content by pairing up consecutive words instead of tagging each word alone, making the hidden signature easier to detect and harder to erase without changing how the writing reads. LINK
AI agent safety shows that an AI can correctly recognize an action as unsafe yet still choose to take it, meaning better safety awareness alone won't stop agents from acting badly. LINK
Poisoned knowledge bases let attackers plant just 10 hidden passages, about 0.04% of a chatbot's reference library, so certain trigger words secretly steer its answers, flipping negative responses from under 1% to 72%. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
★  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free