Monday 21 September 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🤖 Google reveals Gemini AI breached three external firms

🏴‍☠️ ShinyHunters hacks ransomware gang Clop

🐧 CISA flags 3 exploited Linux kernel flaws

🦠 cPanel flaw exploited to spread Mirai

🔓 Attackers copied 170 CrowdSec code repos

Plus: 💡 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.

AI agent traffic grew 7,851% in 2025.

The problem? It's hard to tell legitimate AI assistance from malicious activity.

In HUMAN's CISO's Guide to AI and Agentic Traffic, just 0.5% of behavioral signals separated benign AI assistants from malicious automation.

Block it all, and you risk losing customers.

Let it all through, and you invite threat actors in.

HUMAN's CISO's Guide to AI and Agentic Traffic shows how to:

• Separate legitimate AI from malicious automation.

• Validate intent across browsing, accounts, and transactions.

Keep legitimate agents moving while stopping real threats.
🤖 Google reveals Gemini AI breached three external firms LINK
  • Google confirmed its Gemini AI model broke into three real companies in May during a cybersecurity evaluation, marking the first time the company has acknowledged its AI unintentionally hacking outside organizations.
  • The breaches happened when AI-security firm Irregular tested Gemini in a closed environment with fake companies that accidentally gained internet access, letting the model guess passwords and use credentials found in public repositories to reach real firms sharing those names.
  • Google said Gemini stopped in all three cases once it realized it had accessed real companies rather than the simulated ones, and while it did not publicly disclose the hacks because no damage occurred, it ensured the affected firms were notified.
🏴‍☠️ ShinyHunters hacks ransomware gang Clop LINK
  • The ShinyHunters extortion gang broke into the Clop ransomware operation's Tor data leak site, defacing it and claiming to have stolen server data and the private keys behind Clop's onion service.
  • The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS to plant a text file, later gaining full server access and taking source code, Grav CMS plugins, and system logs.
  • ShinyHunters says it obtained Clop's onion private keys, letting it host a site at Clop's exact onion address even if kicked out, and plans to extort Clop, giving 72 hours to make contact in retaliation for threats tied to Clop's 2025 Oracle E-Business Suite campaign.
🐧 CISA flags 3 exploited Linux kernel flaws LINK
  • CISA is warning that three actively exploited Linux kernel flaws are being abused in the wild, with federal agencies ordered to patch them by today.
  • The most severe, CVE-2025-39682 (critical, CVSS 9.8), is a flaw in the kernel's encrypted-traffic receive path that lets a logged-in local user leak sensitive memory contents or crash the system.
  • The other two let a local attacker crash the machine or gain higher privileges through a memory-corruption bug in packet-address rewriting and a timing bug in the encryption sockets, though how they are being exploited is not yet known.
🦠 cPanel flaw exploited to spread Mirai LINK
  • Hackers are exploiting a critical authentication-bypass flaw in cPanel and WHM, tracked as CVE-2026-41940, to plant Mirai malware on exposed hosting servers and turn them into botnet nodes for wider attacks.
  • The bug lets an attacker skip the login process entirely without a valid account, gaining administrative access to change settings, add malicious files, and attack other systems; JPCERT/CC found the exploitation was likely tied to Mirai activity.
  • JPCERT/CC saw a sharp rise in Mirai-like traffic to port 23 (Telnet) starting April 30 from hosting-provider addresses running cPanel; defenders should install the vendor fixes, limit remote administration, and disable Telnet where unneeded.
🔓 Attackers copied 170 CrowdSec code repos LINK
  • Attackers cloned roughly 170 private GitHub repositories from CrowdSec after a former employee's account was compromised through May's TanStack npm supply chain attack, with the stolen code surfacing on a cybercrime forum on September 16.
  • The theft traces to CVE-2026-45321, the compromise of TanStack's Router and Start packages, where an attacker published 84 malicious releases whose install-time payload harvested GitHub and npm tokens, cloud credentials, Kubernetes and Vault secrets, and SSH keys.
  • Using a stolen OAuth token from the ex-developer's endpoint, the intruder only ran Git fetch operations from a Toronto IP; CrowdSec says production and databases were untouched but 83 user emails and one restricted AWS credential were exposed, and it has since rotated credentials.

Your AI budget tripled. See real usage patterns with Harmonic.

AI spend is now a major P&L line item—but most teams can't show what it's producing.

Harmonic Security maps AI activity to use cases and teams, revealing real productivity, shelfware, data risk, and adoption trends across approved and unapproved tools.

Give your board the data behind the return.

💡 Strategies & Tactics

> SAML: A fractal of bad design: Retire SAML, an aging web login standard, for simpler modern alternatives because its reliance on complex XML makes it perpetually vulnerable to authentication-bypass attacks.
> New cache key injection attack lets hackers bypass access controls and poison Nginx caches: Web caches that build lookup keys by jamming request values together without separators let attackers forge collisions to reach restricted pages and serve poisoned responses.
> BigDiskBuster Windows Defender DoS vulnerability blocks platform and signature updates: A public proof-of-concept tool can quietly block Windows Defender updates, leaving computers running but blind to newly discovered malware.
> Malicious npm packages evade install-script defenses at runtime: Attackers now hide npm malware in a package's normal runtime functions, slipping past install-script blocks so defenders must add runtime behavioral scanning.
> Revoking the token didn’t kill the backdoor: A stealthy backdoor swaps its cloud login credentials on command, so revoking stolen tokens only delays attackers; instead isolate the host and hunt sign-in logs.
> I found a malicious app disguised as a PDF reader that Google Play Protect didn't catch: Vet every app yourself since store scans miss threats like a fake PDF reader that pushed ads and phishing links past Google's protections.

Other news & articles you might like

  • Hackers weaponize Terraform lock files to infect DevOps engineers with macOS backdoors LINK
  • New Rapuncel infostealer abuses Microsoft-signed driver to disable 145 security tools LINK
  • Group policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO LINK
  • Colorado water utilities hit by cyberattacks targeting OT systems LINK
  • Critical Microsoft Azure AI Foundry vulnerability allows attackers to escalate privileges LINK
  • New SETTRA ransomware uses MeshAgent RMM and BYOVD to encrypt Windows systems LINK
  • New Remus Infostealer steals OpenAI and Anthropic API tokens, passwords and crypto wallets LINK

🛠️ Trending tools

Halo: an API-first platform that detects deepfakes and synthetic media across text, image, and audio, helping fraud and trust teams block attacks. LINK
Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents with sub-20ms overhead, mapping to SOC 2, EU AI Act, and ISO 27001 LINK
Cybermes: an autonomous framework for offensive security and bug bounty testing, using AI agents and multiple language models to automate red teaming tasks. LINK
jevals: replaces LLM-based evaluation judges with typed Jev decisions, providing structured, deterministic assessments for testing and validating language model outputs. LINK
Seal: an iOS app that stores encrypted passwords, photos, and voice memos in envelopes that unlock for family members via hardware keys after your death. LINK
cxgrd: a CLI tool that enforces architectural guardrails to keep AI-generated code aligned with your project's structure and design conventions. LINK

📚 Trending research papers

Model theft attacks can now steal a neural network's valuable trained parameters using only the yes-or-no answers it gives, letting an outsider copy a proprietary model without ever seeing inside it. LINK
Re-identification risk audits give each published document a mathematically backed score for how easily an attacker armed with a language model could match it to a real person, guiding safer release decisions. LINK
Chatbot safety defenses work best when layered together rather than used alone, and this first systematic test across 19 attacks and 15 defenses shows well-chosen combinations block most jailbreaks without hurting usefulness. LINK
Coder security instincts were tested on 100 developers vetting AI-written code, revealing they often can't spot planted vulnerabilities and lean on trust over verification, exposing a foundational weak point in AI-assisted software development. LINK
Cryptographic hardware security test measures how well AI models spot flaws in chip-level implementations that protect connected devices, finding top models score up to ~84% overall but explain their security verdicts correctly only ~53% of the time. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free