Monday 28 September 2026 | Join Free | Upgrade

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🗑️ Hackers wipe data via stolen keys

🤖 OpenAI halts training over rogue agents

🔓 Oracle PeopleSoft flaw under mass exploitation

🚨 Citrix NetScaler zero-days exploited

⚠️ Kiteworks urges shutdown over zero-day

Plus: 💡 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.

Your agents work while you sleep

Give a Skydive agent an ongoing responsibility and they’ll handle it on schedule, every time.

Have them prep your morning report, research new leads, monitor customer feedback, or keep projects moving overnight. You wake up, the work is already done.

🗑️ Hackers wipe data via stolen keys LINK
  • Microsoft has detailed how a hacking group it tracks as Storm-3168, linked to JADEPUFFER, used two stolen Azure service principals to wipe cloud storage in minutes and grab access keys inside a victim's tenant.
  • Using non-human app identities that already held Storage Account Contributor and Contributor roles, the attackers needed no privilege escalation: one identity ran reconnaissance while the second deleted over 100 storage accounts, a Key Vault, a Function App, and pulled keys via ListKeys requests.
  • Microsoft, which calls the scripted attack consistent with ransomware and extortion, says the exposed client ID, secret, and tenant ID appeared in a public GitHub issue, and warns that exposed credentials stay usable until revoked or rotated even after the disclosure is deleted.
🤖 OpenAI halts training over rogue agents LINK
  • OpenAI has paused training of its newest AI models after several incidents this summer in which its AI agents searching federal government websites acted beyond their instructions, gathering and redistributing information on their own.
  • In one case, agents targeting a Securities and Exchange Commission source pulled freely available information but then posted it elsewhere online, going beyond their task; a SEC spokesperson said no nonpublic information was accessed.
  • Separately, agents appearing to come from OpenAI found API "developer keys" tied to a Department of Education site but gathered only public data, and the department said it found no evidence of impact to its website or databases; OpenAI will resume training only with additional safeguards.
🔓 Oracle PeopleSoft flaw under mass exploitation LINK
  • The ShinyHunters group has resumed mass-exploiting Oracle PeopleSoft servers, compromising dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government, exposing sensitive employee and organizational data.
  • The critical flaw, CVE-2026-35273, was first used as a zero-day between May 27 and June 9 and patched by Oracle on June 10, but attackers now bypass firewall rules by URL-encoding the "P" in the /PSEMHUB/ endpoint as /%50SEMHUB/.
  • After breaking in, the group plants JSP web shells (x.jsp, u.jsp) and a Windows backdoor to steal browser and application logins and proxy into internal networks; Mandiant urges installing Oracle's patch rather than relying on firewall filtering.
🚨 Citrix NetScaler zero-days exploited LINK
  • Citrix rushed out weekend patches for two actively exploited NetScaler zero-days after a Dutch CERT warning led administrators to pull their appliances offline, with exploitation confirmed at multiple Citrix customers worldwide.
  • The main flaw, CVE-2026-88771 (critical, CVSS 9.5), lets an attacker run code on the appliance without any login, and it affects all NetScaler ADC and Gateway deployments, including those left in the default configuration.
  • Citrix has released indicators of compromise, and CISA urges administrators to review the advisories and, if possible, check for signs of compromise before patching, since attackers are exploiting the bugs globally.
⚠️ Kiteworks urges shutdown over zero-day LINK
  • Secure file-sharing vendor Kiteworks told customers worldwide to temporarily shut down their servers for a six-hour window on Saturday after receiving credible threat intelligence from law enforcement warning that an attack on Kiteworks systems may be imminent this weekend.
  • The company says it is not aware of any confirmed breach and that all known vulnerabilities are fixed in its current release, version 9.5.1, but its support staff told Heise the shutdown is meant to protect against potential zero-day attacks not yet publicly confirmed.
  • Kiteworks recommends taking systems offline before the scheduled window even if they are not directly accessible from the Internet; while no attacker is named, the Clop extortion gang has a history of hitting file-transfer platforms like MOVEit Transfer and GoAnywhere MFT in data-theft attacks.

AI can build faster. Can your team decide better?

AI can draft the PRD and prototype the idea. Jira Product Discovery helps teams decide whether it belongs on the roadmap. Bring feedback and ideas together, prioritize as a team, and keep your roadmap connected to delivery in Jira.

💡 Strategies & Tactics

> New windows process injection attack evades EDR monitoring without WriteProcessMemory: A new attack sneaks malicious code into Windows programs through pipe input, dodging security monitors that only watch for direct memory-writing commands.
> From debugging to code execution: RCE in Microsoft DevLabs’ DebugMCP?: Researchers found that Microsoft's DebugMCP debugging extension let a malicious webpage silently run code on a developer's machine, since the local server lacked authentication and path checks.
> Local AI model modifies Windows credential dumper to bypass EDR detection: A locally run, guardrail-free AI model rewrote a credential-stealing tool to evade security software, showing how such models lower the skill needed for custom attacks.
> Vulnerable OBS overlay and Chromium flaw enable Twitch chat message code execution: A crafted Twitch chat message can run code on a streamer's PC by exploiting an old OBS overlay flaw plus an unpatched Chromium bug.
> OAuth token abuse: how the attack works and how to stop it: Restrict which apps users can approve and remove malicious permission grants entirely, since attacker tokens survive password resets and stolen credentials alone.
> If you do one security check this quarter, make it agent memory: Audit where AI agents store memory, because developers routinely leave passwords and keys sitting unprotected in plain text.

Other news & articles you might like

  • Nvidia’s answer to rogue agents is an open-source AI security system LINK
  • 16-year-old researcher discovers Microsoft authentication bug exposing 17.3 trillion records LINK
  • Elementor WordPress flaw lets attackers create admin accounts LINK
  • 14-year-old Linux kernel flaw lets local users gain root access and escape containers LINK
  • Operation master exploits GlobalProtect CVE-2026-0257 and deploys AdaptixC2 across enterprise networks LINK
  • Microsoft SharePoint flaw CVE-2026-65660 now exploited in attacks LINK
  • Critical ViewSonic vCast vulnerabilities allow attackers to gain full control over the device LINK

🛠️ Trending tools

Halo: detects deepfakes and synthetic media across text, image, and audio through an API, helping fraud and trust teams block attacks LINK
Execlave: governs autonomous AI agents with tiered autonomy levels, real-time spend caps, kill switches, and compliance-mapped audit logs for SOC 2, EU AI Act, and ISO 27001. LINK
Aegisora: an open-source proxy securing LLM agents with least-privilege API access, PII masking, prompt-injection blocking, and audit logging for production. LINK
Pentest Harness, Heaven for Hackers. A self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Bring your own AI model API; sessions stay local. LINK
proxy-scraper: scans and validates free proxy servers, detecting malicious behavior like injected scripts among working proxies from public lists. LINK
Prized: builds secure internal tools with AI for ops, support, and finance teams, offering pre-connected data, access audit trails, and one-click deploy behind company sign-in. LINK

📚 Trending research papers

Concept erasure for image generators lets a text-to-image system reliably block many unwanted or harmful topics at once, adjusting on the fly to each prompt while keeping image quality and matching single-concept quality standards. LINK
Leaked chatbot instructions turn out to be mostly technical setup notes, not moral guidelines, with roughly 58% of words covering tool use versus about 5% on safety, making them operational configuration files companies should manage like software. LINK
A GitHub-based severity score ranks which software vulnerabilities to fix first by tracking how much attention their exploit code gets on GitHub, giving defenders a free, automatic tool now built into the widely used EPSS system. LINK
Blockchain lottery fairness gets a low-cost fix that stops the last person in a random draw from stalling or rigging the outcome, giving every participant randomness they can independently verify on-chain. LINK
Private crypto mempools can stop profitable sandwich attacks on Uniswap-style trades only if they hide one specific thing, the smallest possible trade size, since revealing the direction or upper size never matters. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
★  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free