|
|
Hi there, this is your daily ☕️ Cyberpresso.
|
|
|
In today's Cyberpresso:
|
|
🔑 Leaked GitHub credentials hand hackers easy access 🔒 OpenAI blocks AI reasoning extraction 🤖 AI agents tried hacking government sites 📧 Zimbra flaw exposes email backups Plus: 💡 6 strategies & tactics, 🎁 6 more stories you might like, 🧰 5 tools, and 📚 5 papers.
|
|
Email doesn't operate in separate parts. DNS, authentication, sending infrastructure, reputation, threats, and delivery all influence one another. EasyDMARC brings these layers together in one connected view, giving Security and IT the context to understand what is happening across the infrastructure, assess what it means, and act before issues become security, reputation, or delivery problems. Try EasyDMARC 3.0
|
|
|
🔑 Leaked GitHub credentials hand hackers easy access
LINK
|
- Security researchers found 543,699 unique credentials still valid despite sitting in public GitHub repositories, showing organizations routinely fail to revoke secrets once they leak into source code, with the median credential exposed in a public branch for 784 days.
- Truffle Security verified the live logins in late July 2026 against a dataset of hundreds of millions of public repositories; GitHub's default push protection cut protected credential types by about 53% but missed over half of live secrets, including database connection strings, private keys, and Google API keys.
- Whether a leaked secret stayed usable hinged on the issuer revoking it, not detection: npm revoked all but one of 101,886 exposed tokens, yet most PostgreSQL and MySQL connection strings stayed valid, so researchers urge rotating exposed credentials immediately and scanning full repository history.
|
🔒 OpenAI blocks AI reasoning extraction
LINK
|
- OpenAI says it shut down a coordinated effort to extract protected reasoning from its AI systems, tracing part of the activity to people linked to Chinese startup Moonshot AI, the company behind Kimi.
- Using what OpenAI calls "adversarial distillation," operators manipulated model interactions to pull out hidden reasoning rather than breaching encryption or stored data; over 4,000 users made more than 16,000 requests in a two-day period in July.
- OpenAI says it disrupted a wider cluster of more than 15,000 users by July 28 and shared details with other developers through the Frontier Model Forum, but has not established how much capability, if any, was transferred to a rival model.
|
🤖 AI agents tried hacking government sites
LINK
|
- AI agents from Google and OpenAI tried to break into US and Canadian government websites using aggressive techniques, research lab Transluce reported, though none of the attempts accessed any data that was not already public.
- In one case on 17 June, agents made more than 200,000 requests to the US Department of Education's Civil Rights Data Collection, including a failed attempt to feed deliberately flawed data to bypass the site's filters and test its database for weaknesses.
- Transluce says the behavior stemmed from a web-search task in Google's DeepSearchQA benchmark, meaning the agents were graded on retrieving niche information rather than told to hack; the US Department of Education and the Canadian Centre for Cyber Security both report no impact or compromise.
|
📧 Zimbra flaw exposes email backups
LINK
|
- Hackers are exploiting a critical flaw in the Zimbra Collaboration Suite to steal email backups and login credentials from unpatched organizations, Microsoft has warned.
- The bug, CVE-2026-73570, lets an attacker remotely run operating system commands with no login required; Shadowserver found 274 Zimbra instances already compromised among those it currently tracks.
- From July 28 to August 7, two scanning tools probed the internet, first confirming the exploit worked via HTTP, DNS, ICMP and out-of-band checks before installing malicious payloads; Synacor patched the flaw on July 20.
|
|
Free email without sacrificing your privacy
Gmail tracks you. Proton doesn’t. Get private email that puts your data — and your privacy — first.
Other
news & articles you might like
-
Vulnerability discovery and exploitation trends in the AI era
LINK
-
Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
LINK
-
AI agent chains Zammad zero-days to take over DIVD systems in seconds
LINK
-
Critical MikroTik RouterOS flaw lets unauthenticated attackers execute code as root
LINK
-
Multiple TeamViewer vulnerabilities enable RCE, access control bypass and privilege escalation
LINK
-
New 2CLoader malware evades security tools to deploy Vidar and Remus stealers
LINK
|
|
🛠️ Trending tools
|
Execlave: governs autonomous AI agents with tiered autonomy levels, real-time spend caps, kill switches, and compliance-mapped audit logs for SOC 2, ISO 27001, and EU AI Act.
LINK
|
|
Aegisora: open-source proxy securing LLM agents through least-privilege API access, PII masking, prompt-injection blocking, and audit logging for production deployments.
LINK
|
|
0: provides an LLM-powered cybersecurity harness that autonomously performs full-stack penetration testing to find and fix vulnerabilities around the clock.
LINK
|
|
pentest-harness: a self-hosted AI agent framework for authorized pentests, bug bounties, security labs, and CTFs, using your own model while keeping sessions local.
LINK
|
|
Corral: a Linux command runner that cleanly terminates every process an agent starts, including background jobs, double-forks, and detached process trees.
It isolates commands in their own session and optionally a cgroup so killing the parent reaps the entire tree. When no cgroup is available, it tracks processes via /proc as a weaker fallback and exits with code 120 if it can't confirm everything is dead.
LINK
|
|
|
|
📚 Trending research papers
|
Watermark tampering detection pinpoints exactly where AI-generated text was secretly edited after creation, catching nearly all altered passages so tweaked content can no longer be falsely blamed on the original model.
LINK
|
|
PDF tampering detection scans a document's hidden internals and visible text for mismatches, producing a plain risk score that flags forged files like faked medical leave certificates even when edits leave no visible trace.
LINK
|
|
AI agent safety guardrails catch and block harmful actions in real time, like injected malicious instructions, while still letting the agent finish legitimate tasks, outperforming hand-built and basic automated defenses.
LINK
|
|
Multi-turn jailbreaks reveal that gradual conversational attacks on chatbots do not hide a request's harmfulness internally, the model still recognizes it clearly, explaining why single-message safety filters fail to catch these drawn-out manipulations.
LINK
|
|
AI coding assistants can be trained to spot and plan around hidden security flaws, cutting vulnerabilities in otherwise working code while lifting both security by ~6.9 points and functionality by ~14 points on key tests.
LINK
|
|
|
|
|
Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.
|
|
💬 How did you find today's edition?
We read every reply — just reply to this email and let us know how we can improve!
|
|