Friday 28 August 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

✈️ Airport breach exposes 8.7M customers

🖨️ PaperCut hit by active zero-day

🛠️ ServiceNow patches 3 critical flaws

💉 Prompt injection makes Claude Code run malware

🔗 Malware hides backup server on Ethereum

Plus: 💡 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.

Breaches don't stay contained.

Last year Americans reported $3B+ lost to fraud and identity theft (FTC) — most of it starting with credentials leaked long before the victim noticed.

Coveron, built by Nord Security (the team behind NordVPN), watches for exactly that:

• Scans the dark web for your leaked credentials

• Flags unusual credit activity in real time

• Alerts you the moment something looks off — and if you're hit, up to $2M in identity-theft recovery + scam-loss insurance

Use code TECHPRESSO for up to 71% off.
✈️ Airport breach exposes 8.7M customers LINK
  • A cyberattack on Manchester Airports Group (MAG), which runs Manchester, East Midlands and London Stansted airports, stole the personal data of about 8.7 million customers, with attackers demanding a ransom that MAG says it refused to pay.
  • Most exposed data came from passengers who registered for airport WiFi, primarily email addresses, while car-park reservations, lounge bookings and fast-track access exposed vehicle registration numbers and postcodes, though no bank account or payment-card details were involved.
  • MAG says it identified the breach on Tuesday, contained it, engaged cybersecurity advisors and notified the UK Information Commissioner's Office; it warns customers to watch for phishing emails, texts and scam calls impersonating the airports or support teams.
🖨️ PaperCut hit by active zero-day LINK
  • PaperCut is warning that attackers are exploiting an unspecified vulnerability in its PaperCut NG and PaperCut MF print management software, with the vendor confirming it is aware of real customer incidents involving the products.
  • The flaw is being actively exploited in the wild against the Application Server, the single "brain" of both products, and the bulletin's guidance to restrict public internet access points to a remotely exploitable bug, though PaperCut is still investigating.
  • Until fixed indicators are published, PaperCut says to restrict Application Server web access to trusted IP addresses and watch for suspicious post-exploitation activity from pc-app.exe or specific database errors in server.log.
🛠️ ServiceNow patches 3 critical flaws LINK
  • ServiceNow has released patches for three maximum-severity flaws in its AI Platform, the cloud-based PaaS (formerly the Now Platform) that powers over 100,000 enterprise AI apps at 85% of Fortune 500 companies.
  • The most serious, CVE-2026-18885, is a code injection bug that lets unauthenticated attackers run arbitrary code, while the two others allow privilege escalation and reading or modifying instance data through SQL injection.
  • All three can be pulled off by unauthenticated attackers in low-complexity attacks with no user interaction; ServiceNow patched its cloud platform, told self-hosted customers to update, and said it is not aware of exploitation so far.
💉 Prompt injection makes Claude Code run malware LINK
  • Researchers found that more than 100 websites host llms.txt and llms-full.txt files pointing to unregistered code packages and domains, letting attackers claim those names and make AI coding agents like Claude Code automatically install malware.
  • A stealth Israeli startup scanned 6,214 domains belonging to defense contractors, Fortune 500, and Big Tech companies, finding 8,265 of these files, of which 120 referenced unclaimed packages or domain names that anyone could register.
  • After registering a few unclaimed names, the researchers got phone-home beacons within an hour from Fortune 500 companies and startups whose coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, executed the proof-of-concept code.
🔗 Malware hides backup server on Ethereum LINK
  • A newly identified Go-based malware framework called GoCaracal, linked to the cyber-espionage group Dark Caracal, uses Ethereum smart contracts as a fallback way to recover its command-and-control server when the primary one is taken down.
  • If repeated attempts to reach its main C2 server fail, the implant queries a public Ethereum service for a replacement address stored in a custom Solidity contract named BulletproofC2, then writes the new address into memory and resumes normal off-chain communication.
  • Arctic Wolf tied the framework to a June 2026 intrusion in Venezuela delivered via Spanish-language tax-themed phishing with weaponized SVG files, and published a YARA rule plus hashes, domains, C2 addresses, and Ethereum contract indicators for threat hunting.

Your agents work while you sleep

Give a Skydive agent an ongoing responsibility and they’ll handle it on schedule, every time.

Have them prep your morning report, research new leads, monitor customer feedback, or keep projects moving overnight. You wake up, the work is already done.

💡 Strategies & Tactics

> Hackers abuse active directory SPN misconfigurations for stealthy Kerberoasting attacks: Attackers briefly attach service labels to ordinary Windows accounts, steal crackable login tickets offline, then erase the change to evade detection, so audit user accounts for these labels and disable weak encryption.
> Extend Amazon bedrock guardrails to tool interactions using the strands agents SDK: Extend Amazon Bedrock's safety guardrails past the AI model to the tools it calls, checking tool inputs and outputs so external data and parameters can't slip through unvalidated.
> Cleartext credential recovery in ServiceNow: Attackers with admin-level ServiceNow roles can modify its credential-test scripts to dump stored passwords and keys in cleartext, exposing secrets ServiceNow normally hides.
> Inside 90 days of attacks on AI infrastructure: Attackers now target self-hosted AI tools like LiteLLM to steal model provider keys and hijack computing power, so treat internet-facing AI infrastructure as high-value production systems.
> How Clop accessed the enterprise blueprint with no credentials: Clop exploited a flaw in Windchill engineering software to plant a stealthy implant that steals stored credentials while hiding inside trusted application activity, showing why defenders must monitor what their own software can access and decrypt.
> AWS shows How hackers Can turn stolen cloud credentials into Full-Scale attacks: Correlate a single stolen identity's actions across cloud logs, comparing them to normal behavior, so a coordinated attack surfaces before scattered alerts miss it.

Other news & articles you might like

  • Unitree G1 humanoid robot flaws allow unauthenticated root RCE over Bluetooth LINK
  • BlueDelta Targets defense and diplomatic organizations with HOOKEDGE malware LINK
  • China-Made ZBT routers Ship With Two implants Giving unauthenticated Attackers root Access LINK
  • CISA Warns of linux kernel privilege escalation vulnerability exploited in attacks LINK
  • OpenAI, independent firms publish reports on rogue AI attack on Hugging Face. here are the main takeaways—and what OpenAI still hasn’t disclosed. LINK
  • Go loader uses Anti-Sandbox checks and SNOWLIGHT to execute fileless VShell RAT in memory LINK
  • Critical next.js vulnerabilities enables remote code execution attacks LINK

🛠️ Trending tools

Perfai Security: autonomously tests AI-built apps for access-control, business-logic, and prompt-injection flaws, then opens pull requests with confirmed fixes around the clock. LINK
Halo: an API-first tool that combines NLP, visual, and audio authentication to detect deepfakes and synthetic media, helping fraud and trust teams stop synthetic media attacks. LINK
MonoCloud for Startups: combines authentication and Cedar-based authorization for users, APIs, and AI agents, letting you control, audit, and revoke access, free for a year. LINK
FireTail: discovers shadow AI, enforces governance policies from frameworks like OWASP, and centralizes logging to secure AI usage across all your environments. LINK
ORGN CDE: an enterprise AI IDE that generates code privately using confidential computing, provable encryption, and zero data retention for security-conscious teams. LINK
Playground: test your prompt injection skills against AI agents in a hands-on sandbox for exploring and understanding LLM security weaknesses LINK

📚 Trending research papers

Confidential AI on Blackwell chips can run private, encrypted large-model inference with only ~1-3% slowdown when configured right, versus the 30-40% penalty seen in default setups, making secure AI hosting nearly free. LINK
Smart meter privacy lets utilities compute total neighborhood electricity use for grid monitoring and forecasting without ever seeing any household's individual reading, even if some meters are hacked or collude. LINK
XRP Ledger defenses show that adding new trusted connections between nodes makes the network much harder for attackers to break by isolating the participants that hold it together. LINK
Medical device attack testing gives hospitals a first benchmark to check whether security tools can tell real health emergencies from device faults or hacks, revealing that today's detectors miss replay attacks and small tampering almost entirely. LINK
Web attack detection flags malicious traffic while highlighting exactly which parts of a request look suspicious, an approach that exposed mislabeled data in a popular public dataset that had been quietly blinding detection systems to real attacks. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free