|
|
Hi there, this is your daily ☕️ Cyberpresso.
|
|
|
In today's Cyberpresso:
|
|
🇰🇵 North Korean hackers steal Gmail data 🇨🇳 AI tools doubled Chinese state hacking 🔧 AWS patches credential-theft flaw 🔓 Hackers exploit WordPress plugin flaw 🔑 Keycloak flaw lets attackers hijack accounts Plus: 💡 6 strategies & tactics, 🎁 8 other news you might like, 🧰 6 tools, and 📚 5 papers.
|
|
Breaches don't stay contained. Last year Americans reported $3B+ lost to fraud and identity theft (FTC) — most of it starting with credentials leaked long before the victim noticed. Coveron, built by Nord Security (the team behind NordVPN), watches for exactly that: ✓ Scans the dark web for your leaked credentials ✓ Flags unusual credit activity in real time ✓ Alerts you the moment something looks off — and if you're hit, up to $2M in identity-theft recovery + scam-loss insurance Use code TECHPRESSO for up to 71% off.
|
|
|
🇰🇵 North Korean hackers steal Gmail data
LINK
|
- North Korean hacking group Kimsuky ran an espionage campaign that plants a malicious Chrome extension to quietly steal Gmail data, hitting people in South Korea and Japan during the first half of 2026, according to analysts at Enki.
- The extension, named "Gmail automatic server uploader," runs a content script that watches the reading panel and Send button, then grabs the sender, subject, message body, and attachments and sends them to an attacker server as a victim reads or writes email normally.
- The attack starts with a OneDrive link to a Windows shortcut file that shows a decoy document while downloading malware, creating a Chrome_Update scheduled task, logging keystrokes, copying Thunderbird and Outlook mail, and installing Chrome Remote Desktop and AnyDesk for full remote control.
|
🇨🇳 AI tools doubled Chinese state hacking
LINK
|
- State-linked Chinese hacking groups have more than doubled their activity by handing routine tasks to AI models like DeepSeek to automate reconnaissance, write exploit code and help move inside compromised networks, according to Taiwanese firm TeamT5 cited by Bloomberg.
- Researchers found DeepSeek used to generate exploit code and to gather around 1,000 IP addresses and map a company's domains, while another group used ChatGPT while developing a component to decrypt an employee's stolen local Signal database from a compromised device.
- A group called Slime22 set up its own Kali Linux environment and prompted Anthropic's Claude Code to assist with lateral movement, getting around the model's safeguards by presenting the activity as legitimate cybersecurity testing after gaining access to a Taiwanese technology company.
|
🔧 AWS patches credential-theft flaw
LINK
|
- AWS patched a credential-theft flaw across seven of its software development kits after researchers at Pi found the same defect in roughly 2,500 instances, tracing it to a missing check in AWS's shared SDK code generator.
- Because the vulnerable code paths never validated the region field, attackers who control that input (like "@attacker.com#") could redirect an AssumeRoleWithWebIdentity call, sending the plaintext bearer token to their own server; only the .NET SDK drew a CVE (CVE-2026-22611), rated low at CVSS 3.7.
- Pi tested the flaw in third-party platforms embedding an AWS SDK and exposing the region field, finding seven of seven exploitable and each leaking live AWS credentials; the fix validates the region as letters, digits and hyphens only, and all targets were remediated before publication.
|
🔓 Hackers exploit WordPress plugin flaw
LINK
|
- Hackers are trying to break into WordPress sites through two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin, chaining them to forge SAML responses and log in as administrators.
- The first bug (CVE-2026-61979) lets an attacker pick the signature algorithm, so the plugin treats the identity provider's known public key as a shared secret and accepts a forged signature; the second (CVE-2026-15981) treats an OpenSSL verification error as success.
- Patchstack says the flaws are being exploited from six IP addresses, with an admin session cookie stolen via the Standard edition version 16.1.9 and a public proof-of-concept available; paid editions show no update warning, so owners must manually upgrade.
|
🔑 Keycloak flaw lets attackers hijack accounts
LINK
|
- Red Hat has disclosed a critical flaw in its Red Hat Build of Keycloak that lets an unauthenticated remote attacker skip the email verification in the password reset process and take over any user account.
- The bug, CVE-2026-18963 in the keycloak-services component (CVSS 9.1, critical), fails to validate state in the reset-credentials flow, letting an attacker force a reset and directly set a new password without any verification link, privileges, or user interaction.
- Red Hat issued fixes on August 18, 2026, for Keycloak 26.4, 26.4.15, 26.6, and 26.6.6; where upgrades aren't feasible, it recommends turning off the "Forgot password" feature per realm and reviewing password-reset activity for misuse.
|
|
Want to get the most out of ChatGPT?
ChatGPT is a superpower if you know how to use it correctly.
Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.
Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.
Other
news & articles you might like
-
Researcher Discloses five High-Risk vulnerabilities in palo alto GlobalProtect
LINK
-
Tracking PavinLoader across ClickFix and fake download campaigns
LINK
-
Crooks push Mac malware through fake OpenAI Codex ads
LINK
-
You don't want this Sleepwalker backdoor on your Windows machine
LINK
-
Alibaba’s AliExpress leverages user audio systems for fingerprinting
LINK
-
EvilTokens abuses microsoft device codes to Hijack accounts without stealing passwords
LINK
-
Top Google results for minecraft client Led gamers to malware, McAfee Finds
LINK
-
Multiple TP-Link archer vulnerabilities Enable command injection attacks
LINK
|
|
🛠️ Trending tools
|
Kastra: runtime authorization layer that enforces policies on AI agent actions before execution, blocking unauthorized tool use, prompt injection, and data exposure with sub-millisecond latency.
LINK
|
|
Perfai Security: autonomously scans AI-generated apps for access-control, business-logic, and prompt-injection flaws, then ships confirmed fixes as pull requests around the clock.
LINK
|
|
Halo: an API-first tool combining NLP, visual, and audio authentication to detect deepfakes and synthetic media for fraud and trust teams.
LINK
|
|
FireTail: an AI security and governance platform that discovers shadow AI, enforces policies from frameworks like OWASP, and centralizes logging across environments.
LINK
|
|
ORGN CDE: an enterprise AI IDE that generates code privately using confidential computing, provable encryption, and zero data retention for security-conscious teams.
LINK
|
|
Sequirly: browser extension that scans prompts and uploads before they reach ChatGPT, Claude, or Gemini, catching API keys, credentials, and personal data.
LINK
|
|
|
|
📚 Trending research papers
|
AI decision logs get a tamper-evident record format that captures each time an automated system releases, blocks, or escalates an output, letting outside parties verify what happened offline without trusting the vendor.
LINK
|
|
CyberFactory turns public vulnerability reports into hands-on training exercises for open-source models, producing Aegis, a freely available AI that finds, exploits, and patches security flaws, closing the gap with closed commercial tools.
LINK
|
|
Training-data detection can reveal whether a specific image was used to train an AI image generator using as few as two probes, catching leaks up to 3x better than methods needing 30 probes.
LINK
|
|
Safety hacking shows that filtering many chatbot answers through an imperfect safety check and picking the highest-scoring one can reliably surface unsafe replies, because generating more options amplifies the rare mistakes the filter misses.
LINK
|
|
Secure vision AI at the edge can now run entirely inside a protected hardware vault that hides the model from attackers, hitting fast graphics-chip speeds so safety-critical camera apps stay both quick and private.
LINK
|
|
|
|
|
Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.
|
|
💬 How did you find today's edition?
We read every reply — just reply to this email and let us know how we can improve!
|
|