|
|
Hi there, this is your daily ☕️ Cyberpresso.
|
|
|
In today's Cyberpresso:
|
|
🛡️ Microsoft patches record 622 flaws two under attack 🚕 Cyberattack downs Japan's biggest taxi operator 📌 Secure Boot broken for a decade unnoticed 🔓 SonicWall VPN flaws let hackers run code Plus: 💡 4 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.
|
|
The AI Agent You Can Trust
Some things you can always count on. Catch is one of them. Your AI admin is always on, handling the calls, the bookings, the follow-ups, day or night. It never drops the ball and never forgets. Meet the admin that's always there, always at catchagent.ai.
|
🛡️ Microsoft patches record 622 flaws two under attack
LINK
|
- Microsoft's July Patch Tuesday set a record by fixing 622 CVEs across its products, 58 of them critical, with two already under active attack and one publicly disclosed but not yet exploited.
- One actively exploited flaw lets an attacker who already has local access gain administrator privileges due to weak access control, while a SharePoint bug missing authentication also allows privilege escalation over a network.
- The publicly disclosed but unexploited issue lets anyone with local access to a BitLocker-secured machine physically bypass its protections; Microsoft recommends installing all the patches as soon as possible.
|
🚕 Cyberattack downs Japan's biggest taxi operator
LINK
|
- Nihon Kotsu, Japan's largest taxi and chauffeur operator, was hit by a cyberattack over the weekend that forced it to shut down parts of its infrastructure, with its taxi dispatch system still offline today.
- The company confirmed a malware infection gave attackers unauthorized external access to internal systems, and it responded by disconnecting systems to prevent further damage, knocking out car hire, web booking, reservation management, and the telephone dispatch service.
- The firm has engaged external cybersecurity experts and is investigating whether data was leaked, though no leak has been confirmed and no ransomware group has claimed the attack; it warns customers to avoid suspicious attachments and links claiming to come from the company.
|
📌 Secure Boot broken for a decade unnoticed
LINK
|
- Researchers at ESET found that Secure Boot, the Microsoft-invented standard protecting Windows and Linux devices from firmware infections, has been trivial to bypass for 13 of its 14 years because of old signed boot components.
- The issue stems from 11 firmware images called shims, at least one dating to 2013, that were known to be defective yet Microsoft, which oversees shim signing, never revoked them, letting even novice hackers reuse them to bypass the protection built into the UEFI.
- Affecting both Windows and Linux users since a shim runs on either OS, an attacker can subvert the chain of signed firmware to install malicious firmware that loads early in boot and persists after an OS reinstall or hard drive replacement.
|
🔓 SonicWall VPN flaws let hackers run code
LINK
|
- SonicWall is warning that hackers are exploiting two flaws in its SMA1000 VPN appliances as zero-days, and has released hotfixes that customers are urged to install immediately.
- The main flaw is a maximum severity server-side request forgery bug in the Appliance Work Place interface that lets a remote, unauthenticated attacker force the appliance to make requests to unintended locations.
- SonicWall confirmed active exploitation in multiple incidents, says there are no workarounds other than the hotfixes, and shared log-based indicators of compromise like unexpected requests to /__api__/login and /wsproxy.
|
|
Your employees are connecting AI to everything. Now what?
ChatGPT and Claude aren't just answering questions. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack — with no security visibility into what data moves or what actions they take.
Other
news & articles you might like
-
China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign
LINK
-
LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems
LINK
-
New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol
LINK
-
Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
LINK
-
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
LINK
-
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
LINK
-
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
LINK
|
|
🛠️ Trending tools
|
FireTail: monitors and secures API usage across an organization's stack, detecting vulnerabilities and misconfigurations before attackers exploit them in production.
LINK
|
|
BestDefense.io: automatically pentests and patches vulnerabilities in every deployment using AI, helping developers catch security flaws before they reach production.
LINK
|
|
Sequirly: scans prompts and file uploads in your browser to catch API keys, credentials, and personal data before they reach ChatGPT, Claude, or Gemini.
LINK
|
|
LaunchSafe: runs continuous, AI-driven pentesting that chains real exploits and auto-remediates vulnerabilities, letting engineering teams ship quickly without weakening security.
LINK
|
|
NeuralNetSQL: implements a full neural network's forward and backward pass using only SQL queries, treating matrix multiplication as joins and aggregations.
LINK
|
|
ai-trains-ai: an RL-trained agent that autonomously designs and trains other models using reinforcement learning, built for approximately $1,300 in compute costs.
LINK
|
|
📚 Trending research papers
|
Code review workloads can partly predict which pull requests get accepted just from info available when they're submitted, with top models scoring above 0.95 F1, but estimating how much review effort they'll need is much harder.
LINK
|
|
Tracing security bugs to their exact triggering line of code, even across distant functions, works 75.0% of the time, beating prior best methods on the same test set.
LINK
|
|
AI-written software tests catch more edge cases than human-written ones, with almost double the variety (0.62 vs 0.32) and more null-safety checks (13.40% vs 8.3%), though humans write slightly stronger assertions (88.1% vs 85.37%).
LINK
|
|
API testing tools perform much worse when the software blueprints they rely on contain errors, and just measuring code coverage hides how badly, researchers find.
LINK
|
|
Kernel trace data can be safely synthesized, matching real system logs within 2.6 points of accuracy while cutting costs, since longer context boosts quality by 104%.
LINK
|
|
|
|