Wednesday 07 October 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

👕 Hacker breach exposes ASOS to extortion

🔓 FBI warns 86,000 Fortinet firewalls hacked

🔒 Attackers forged valid Google certificates

🕵️ Web page tricks Copilot CLI into leaking secrets

Plus: 💡 6 strategies & tactics, 🎁 8 more stories you might like, 🧰 6 tools, and 📚 5 papers.

EasyDMARC 3.0 connects the context and controls IT and Security need:

Security: Strengthen DMARC and authentication. Detect spoofing, impersonation, and threats to your domains and infrastructure.

Deliverability: Monitor sender behavior, reputation, receiver feedback, and delivery conditions.

Compliance: Control configuration, changes, ownership, and policies with clear auditability.

Try EasyDMARC 3.0
👕 Hacker breach exposes ASOS to extortion LINK
  • British online retailer ASOS confirmed that hackers broke into a third-party platform it uses for customer communication, then pushed rogue pop-up notifications titled "ASOS hacked" to users' mobile apps demanding the company engage or face a data leak.
  • The attackers sent notifications claiming they had "fully compromised the Snowflake instance," though ASOS made no mention of its Snowflake instance being hacked; a group calling itself Xuanye Group claimed the breach on a new Telegram channel, which may be a false flag.
  • ASOS said hackers might have accessed names and contact details but does not believe payment-card information or account passwords were affected, its website and app were not impacted, and it has restricted access to the notification platforms while working with advisers and authorities.
🔓 FBI warns 86,000 Fortinet firewalls hacked LINK
  • The FBI and Secret Service warned in a joint advisory published yesterday about FortiBleed, an active global campaign that steals and cracks logins from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, compromising more than 86,644 devices across 194 countries.
  • Attackers scan exposed FortiGate SSL VPN portals and break in using reused or leaked credentials and weak legacy SHA-256 password storage, feeding stolen hashes into a GPU cracking cluster, then create new admin accounts and map Active Directory to sell access as an initial access broker.
  • Victims can be locked out when attackers delete original accounts or change passwords, and the brokers have supplied access to INC/Lynx and Payload ransomware affiliates; the agencies urge restricting external management, resetting all Fortinet VPN and admin passwords, enforcing phishing-resistant MFA, and moving to PBKDF2 storage on FortiOS v7.2.11 and later.
🔒 Attackers forged valid Google certificates LINK
  • Attackers who seized control of the operators behind three country-code domain endings, .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa), used that access to obtain valid HTTPS certificates for several Google domains and other large organizations, Google disclosed on Tuesday.
  • By compromising the third-party registry operators and altering the authoritative DNS records, the attackers put every domain under those endings at risk; Certificate Transparency log data later exposed other affected brands and online services targeted in the same attacks.
  • Google blocked the unauthorized certificates in Chrome through CRLSets and had the issuing Certificate Authorities revoke them, so Chrome users need no action, but it warned it cannot guarantee every affected domain was found and that other browsers may not be reliably protected.
🕵️ Web page tricks Copilot CLI into leaking secrets LINK
  • Researchers at Adversa AI disclosed an attack called Cryptographic Context Injection that tricks GitHub Copilot CLI into leaking a developer's local secrets when it fetches an attacker-controlled webpage, demonstrated by stealing a `.env.prod` file in 28 seconds.
  • The webpage hands the agent encrypted content and two "decryption keys"; one is a template that makes Copilot read local files into a key string, which then fails, so the agent uses the valid key to decrypt a second payload that sends the harvested file contents to the attacker's endpoint.
  • Still reproducible as of October 1, the attack works because the same instructions in plaintext were rejected as prompt injection, but encryption disguises them; GitHub validated it on September 17, 2026 but declined to classify it as a vulnerability, citing the user choosing to fetch attacker content with autonomous permissions.

State of Product reveals what AI still hasn’t solved

80% of product professionals say AI helps them ship faster, but customers aren’t seeing value any sooner. Atlassian’s State of Product 2027 explores the gains AI is delivering and the challenges that remain, from decision-making that hasn’t kept pace to gut instinct overriding customer evidence.

💡 Strategies & Tactics

> Open build service, one year later: command execution through Mercurial argument injection · Fenrisk: Researchers found a second code-execution flaw in openSUSE's build platform where attacker-controlled commit data becomes Mercurial command options, letting them poison trusted software packages.
> AI agent gateway: Open-source tool keeps credentials out of agent configs: Routing AI agents through Tuskira's gateway keeps model keys and service credentials out of agent configs while checking each tool call against the agent's permissions.
> Mapping Akira ransomware attack: Investigators reconstructed an Akira ransomware attack from leftover registry entries and log files after their monitoring tool was installed too late to record the intrusion directly.
> MCP fixed secret handling. URL elicitation moved the phishing risk into the browser: Vet and log every browser destination an AI agent sends users to, because moving credentials out of the model turns the assistant into a trusted phishing vector.
> How to secure RMM software: 8 controls MSPs should test: Test eight security outcomes like failed patches and compromised accounts directly in your remote management tool rather than choosing by feature-list length.
> No plan survives first contact: Scoping the AI-delivered pentest: Keep a human overseeing automated security tests so testers can shift focus mid-engagement when unexpected flaws surface, since AI alone can't yet redirect itself.

Other news & articles you might like

  • SonicWall warns of max severity SSRF flaw in SMA1000 gateways LINK
  • OpenSSH 10.6 fixes security flaws including SSH plaintext recovery attack LINK
  • Iranian hackers use fake Dubai Airports coding test to target Iraqi critical infrastructure LINK
  • Fake ChatGPT, Gemini, and Claude ad portals capture credentials and MFA codes LINK
  • 32 unique 0-days exploited in Samsung S26, Pixel 10, OpenAI Codex and other devices in Pwn2Own 2026 LINK
  • Critical Veeam Backup & Replication flaw allows low-privileged users to execute remote code LINK
  • OpenAI sandbox escape flaw allowed free access to paid AI models without an API key LINK
  • Hackers hide Vasilek backdoor inside VMware Tools to target medical organizations LINK

🛠️ Trending tools

Decawork: takes employee-built AI agents into production, centralizing access, oversight, and retirement so IT teams can manage them like staff. LINK
CtrlOps: local-first desktop app for managing Linux servers with AI-assisted terminal, real-time monitoring, and agentless SSH access across your infrastructure. LINK
Prized: build secure internal tools with AI for ops, support, and finance, with pre-connected scoped data, audit trails, and one-click deployment behind company sign-in. LINK
Execlave: validates AI agent actions against your policies before execution, with spend caps, audit logging, agent inventory, and permission-drift detection for safer autonomous operations. LINK
Replay QA Security Scan: runs automated pentests on web apps to catch injection flaws, broken access control, IDOR, and cross-tenant data exposure introduced by AI coding agents. LINK
chat-recall: unifies AI assistant histories from Claude Code, Codex, Cursor, and OpenCode into one searchable log, redacting secrets and flagging leaked keys locally. LINK

📚 Trending research papers

Security bug-hunting prompts get sharper when you study where the AI keeps failing, turning recurring mistakes into reusable instruction tweaks that make automated code-vulnerability checks more reliable across different models. LINK
Invisible watermarks on AI-generated images are far easier to erase than vendors claim, since simple rotations or scaling break them, undermining a key tool for proving images came from a given model. LINK
Bitcoin transaction analysis can be handed to plain language AI models that explain suspicious activity in readable terms, correctly identifying basic transaction details over 98% of the time and flagging meaningful patterns 95% of the time. LINK
Private single sign-on gets a blueprint for letting users log into many sites without the identity provider tracking them or the sites linking their accounts, by borrowing proven cryptographic building blocks compatible with standard login systems. LINK
Protein design watermarks let companies invisibly tag the 3D structures their AI generates so stolen copycat models inherit the same hidden mark, protecting intellectual property and tracing any biohazard misuse back to its source. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
★  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free