|
|
Hi there, this is your daily ☕️ Cyberpresso.
|
|
|
In today's Cyberpresso:
|
|
✈️ Coin-sized device can hijack a Boeing 737 🇨🇳 Chinese hackers steal crypto in attacks 📱 Apple warns of spyware attacks 🗺️ GeoServer flaw allows remote code execution 🤖 'Tokenmaxxing' is fueling shadow AI at work Plus: 💡 6 strategies & tactics, 🎁 6 other news you might like, 🛠️ 6 strategies, 🧰 6 tools, and 📚 5 papers.
|
|
Stop making AI decisions in the dark.
Leadership is asking: where is AI delivering value for us and where is it creating risk? Right now, most teams have no idea.
With Harmonic Security’s Usage Explorer, you get a complete picture of how your organization actually uses AI, automatically categorized into custom use cases with complete tool-level granularity.
|
✈️ Coin-sized device can hijack a Boeing 737
LINK
|
- Researchers from UC San Diego and Oberlin College built a coin-sized, Wi-Fi-enabled device costing under $100 that plugs into an externally accessible port to hijack a Boeing 737's autopilot and spoof its takeoff calculations.
- Presented at the Usenix Cybersecurity Conference, the technique requires physical access to a port reachable via an exterior hatch in about 15 seconds, letting maintenance or airport staff fit the hardware implant in under a minute.
- Once in place, the implant sends electrical signals on one of the 737's internal networks to spoof commands to autopilot systems and lie to the pilot about the plane's total weight and outside air temperature, potentially causing runway overruns, diversions, or crashes.
|
🇨🇳 Chinese hackers steal crypto in attacks
LINK
|
- A China-linked hacking group tracked as Jewelbug is running a cryptocurrency-fraud and espionage operation that turns public Google Docs into a command-and-control channel, hiding malicious payloads inside documents that victim implants fetch, decode and run.
- When an operator starts a campaign, the group's XG-Web platform creates a public Google Doc holding an obfuscated payload that is XOR-encoded with a random key so no two downloads match, letting the traffic resolve through Google infrastructure and dodge reputation-based filtering.
- In a related watering-hole attack, Jewelbug injected one script into a shared webmail template, exposing over 15 government tenants and pushing the Antino backdoor and a "PDF Viewer" browser extension that stole 580,000-plus cookies, thousands of credentials and 2,300-plus email bodies.
|
📱 Apple warns of spyware attacks
LINK
|
- Apple sent a fresh round of "Apple Threat Notifications" on August 13, warning specific iPhone users that it detected a "mercenary spyware attack" individually targeting their devices, with several recipients reporting the alerts on Reddit.
- Apple does not name the spyware behind each alert, but cites NSO Group's Pegasus as an example, and past forensic investigations into these notifications have confirmed Pegasus infections targeting journalists, activists, politicians, and diplomats across more than 150 countries.
- Apple calls these "high-confidence alerts" sent by email and iMessage that never ask you to click a link or enter a password; affected users can verify them at account.apple.com and are advised to enable Lockdown Mode and contact a cybersecurity expert.
|
🗺️ GeoServer flaw allows remote code execution
LINK
|
- Attackers are targeting a newly disclosed zero-day in GeoServer, the open-source platform for publishing geographic data, that lets unauthenticated attackers inject SQL commands and, in some setups, run operating system commands on the server.
- Disclosed August 12 by researcher q1uf3ng with no CVE or vendor patch yet, the flaw abuses the jsonArrayContains function; where GeoServer connects to Microsoft SQL Server with an elevated database account, the SQL injection can escalate to remote code execution.
- Researchers at watchTowr saw exploitation attempts within hours, hundreds of requests from a few IPs scanning exposed instances for vulnerable error conditions, so admins should restrict internet access, review database permissions for least privilege, and watch logs for SQL errors.
|
🤖 'Tokenmaxxing' is fueling shadow AI at work
LINK
|
- An emerging corporate trend called "tokenmaxxing", over-engineering generative AI prompts to maximize AI usage, is raising security concerns as businesses push employees to use more AI to prove returns on their investments.
- The practice drives shadow AI, where unapproved tools operate inside company environments without oversight, with LLM vendors 52% more likely to be rated "high risk" than traditional SaaS due to access to sensitive data, IP, and internal workflows.
- Industry data shows 70% of 16,000 cybersecurity customers already have shadow AI, and when security teams revoke unmanaged tools, employees reinstall them 100+ times within 30 days and 1,000 times within a year.
|
|
2 Free AI Courses. No Credit Card Needed.
5,000+ professionals use Skill Leap to get ahead with AI. Right now, two of their best courses are completely free - Claude 101 and the 14-Day AI Boot Camp.
Claude 101 covers prompting frameworks, Artifacts, file analysis, and real-world workflows in 19 lessons.
The Boot Camp covers ChatGPT, Gemini, Midjourney, and prompt engineering in 16 lessons. Downloadable workbooks. LinkedIn certificate.
Zero cost, no credit card, no catch.
💡 Strategies & Tactics
|
> Return of the cookie Monster: Attackers now hijack an already-authenticated Chromium browser through its debugging interface to bypass cookie theft protections, since no cookie extraction is needed.
|
|
|
Other
news & articles you might like
-
AmnesiaStealer macOS malware steals data, controls browser sessions
LINK
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
LINK
-
Beacon CRM Confirms full database theft after AWS access Key breach
LINK
-
Fortinet patches authentication flaws in FortiWeb and FortiManager
LINK
-
Aeternum botnet uses polygon smart contracts for Takedown-Resistant malware C2
LINK
-
PATCHCORD infrastructure hosts SuperShell C2 for remote commands and webshell management
LINK
|
|
🛠️ Trending tools
|
Kastra: a runtime authorization layer that enforces policies on AI agents before actions execute, blocking unauthorized tool use and data exposure across major frameworks.
LINK
|
|
MonoCloud for Startups: provides a unified identity platform for authentication, fine-grained authorization, and access control across users, APIs, and AI agents, free for startups for one year.
LINK
|
|
Halo by Scam AI: an API-first tool that combines NLP, visual, and audio authentication to detect synthetic media and flag malicious intent patterns.
LINK
|
|
HOL Guard: a firewall for AI agents that intercepts and blocks high-risk actions, like deleting production data or exposing secrets, before they execute.
LINK
|
|
Claudoscope: a free macOS menu bar app that browses Claude Code session history, tracks token costs, scans for leaked secrets, and lints your CLAUDE.md config locally.
LINK
|
|
Cynative Security Research Agent: an open-source CLI that answers plain-language security questions across GitHub, AWS, GCP, Azure, and Kubernetes, enforcing read-only IAM policy checks.
LINK
|
|
📚 Trending research papers
|
Privacy policy research reviewed 290 studies from 2010 to 2025 and found the field lacks tools to automatically create, check, and fix confusing consent documents, pointing to where better compliance software is still needed.
LINK
|
|
Text-message scam filters built on older machine-learning methods nearly collapse when scammers tweak spelling or sentence structure, failing up to 99% of the time, while newer multilingual transformer filters hold up far better, failing at most 35% of the time, showing that clean-data accuracy alone cannot predict which filter will survive real attacks.
LINK
|
|
Malware detection models can spot when attackers' new tricks make them stale and retrain only then, matching the accuracy of constant retraining while cutting the training work substantially.
LINK
|
|
Self-driving software audits show that AI models can auto-build test code to probe safety weaknesses in real autonomous-vehicle software, but the top model got only 64% to compile on the first try, and every crash found traced back to test scaffolding, not the actual driving software, showing this automation isn't yet reliable enough to trust for safety certification.
LINK
|
|
Smart contract invariants are automated rules that check whether a program is behaving as intended, and testing them against 28 real Ethereum hacks by replaying 108,637 actual transactions shows they would have blocked every single attack.
LINK
|
|
|
|
|
Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.
|
|
💬 How did you find today's edition?
We read every reply — just reply to this email and let us know how we can improve!
|
|