Tuesday 06 October 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🤖 OpenAI bots triggered a Wikipedia outage

🏥 Oracle health breach hit 20M people

🏨 Russian hackers hijack hotel WiFi logins

🏦 South Korea suspects AI in bank hacks

🔓 Atlassian flaw lets hackers read files

Plus: 💡 6 strategies & tactics, 🎁 7 more stories you might like, 🧰 6 tools, and 📚 5 papers.

EasyDMARC 3.0 connects the context and controls IT and Security need:

• Security: Strengthen DMARC and authentication. Detect spoofing, impersonation, and threats to your domains and infrastructure.

• Deliverability: Monitor sender behavior, reputation, receiver feedback, and delivery conditions.

• Compliance: Control configuration, changes, ownership, and policies with clear auditability.

Try EasyDMARC 3.0
🤖 OpenAI bots triggered a Wikipedia outage LINK
  • Wikipedia has blamed a rare partial outage on 7 May on "rogue" OpenAI agents, whose automated traffic overwhelmed its systems, with host Wikimedia Foundation saying AI firms must do more to protect the public from harm.
  • The OpenAI agents crawled millions of pages and made hundreds of thousands of data queries to the Wikidata Query Service through public APIs, and even made unauthorised, "potentially malicious" edits to the citation tool Etherpad on Wikipedia sites.
  • Wikimedia warned this strain adds server and staffing costs and can block human visitors by overloading systems; OpenAI said it is working with Wikimedia to analyse its bots' activity and will share relevant information as that work progresses.
🏥 Oracle health breach hit 20M people LINK
  • Oracle's Cerner health unit suffered a breach now said to affect 20 million people, according to information released by the Texas attorney general and reported by Bloomberg yesterday, far more than the 6 million records first claimed.
  • The intruder, using the handle rose87168, pulled data from an old legacy server that had not yet been migrated to the Oracle Cloud, with access traced to on or around February 20, 2025; exposed data included medical details, addresses, and Social Security numbers.
  • Oracle's medical clients include the Department of Defense and the Department of Veterans Affairs, and a source told Bloomberg last year the hack aimed to hold the data hostage and extract ransoms from U.S. medical providers.
🏨 Russian hackers hijack hotel WiFi logins LINK
  • Russian state-linked hackers tracked as Midnight Blizzard (also Cozy Bear, APT29) have compromised public WiFi networks at hotels, airports, conference centers, and casinos, redirecting travelers to fake login pages that steal their credentials or install malware, Microsoft warns.
  • The campaign, dubbed "Captive Crunch" and ongoing since at least June 2026, works by compromising three North American providers managing WiFi for 7 of the top 10 US hotel chains, then controlling the WiFi gateway to tamper with DNS and HTTP traffic and push victims to spoofed captive portals.
  • At least 70 victim networks were hit, with attackers using ClickFix tricks, fake Windows updates, browser updates, driver repairs, or CAPTCHAs, to make users run the malware themselves, including Windows remote access trojans that spy on audio and video; Microsoft urges travelers to avoid public WiFi prompts and use mobile hotspots, cellular data, or VPNs.
🏦 South Korea suspects AI in bank hacks LINK
  • South Korea's president said on Tuesday that AI models are suspected of having been used in recent hacking attacks against the country's banks, which exposed customers' personal information and prompted a full-scale police investigation.
  • Shinhan Bank, KB Kookmin Bank, Hana Bank and Woori Bank have all reported cyberattacks, according to the Financial Services Commission and Yonhap, though authorities have not disclosed what AI tools were used or the full scale of the breaches.
  • The FSC chairman convened an emergency meeting with financial associations, regulators and affected institutions on Sunday, warning the sector to respond with the highest vigilance, as the president called for cybersecurity methods suited to the AI era.
🔓 Atlassian flaw lets hackers read files LINK
  • A critical flaw in 8 self-hosted Atlassian Data Center products lets an attacker with no login read specific files in each product's web application root directory, which Atlassian disclosed yesterday.
  • The bug, CVE-2026-21589, rated critical (9.3 out of 10), is a path traversal: a request uses a specially built file path to reach files it should not, but the attacker must already know a file's exact name and path and cannot list the directory's contents.
  • Atlassian's cloud products are already patched and no exploitation has been found, but self-hosted customers must upgrade to the listed fixed versions for Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye, or apply temporary firewall or Tomcat blocking rules and restrict public internet access until then.

Your agents work while you sleep

Give a Skydive agent an ongoing responsibility and they’ll handle it on schedule, every time.

Have them prep your morning report, research new leads, monitor customer feedback, or keep projects moving overnight. You wake up, the work is already done.

💡 Strategies & Tactics

> Smashing the token limit with overlapping fragments: Stealing long login tokens through CSS alone becomes practical by extracting many overlapping short chunks and stitching them together, shrinking payloads roughly 200-fold.
> How Huntress detects and responds to a ClickFix attack: Huntress kills ClickFix attacks on the device itself within a second by matching the pasted command's shape and blocking anything the Run dialog spawns, rather than waiting for slower cloud analysis.
> GitHub’s ReviewBench puts AI code reviewers to the test: GitHub's ReviewBench benchmark scores AI code reviewers on how many real problems they catch versus false alarms, letting teams compare and improve review tools.
> Getting granular with access, attributes, and intent - Alex Olivier - ASW #403: Fine-grained authorization standards let organizations constrain exactly what users and AI agents can access, a pressing need as autonomous agents multiply.
> Your vibe-coded apps are a ticking time bomb for your business. Here’s how to secure them.: Enforce security at the shared data layer rather than per app, so every quickly built internal tool inherits access controls regardless of who wrote it.
> When identity isn’t human: securing the agentic enterprise: Secure AI agents by monitoring what they do after login, not just verifying access once, since software acts continuously and unpredictably.

Other news & articles you might like

  • Google, JPMorgan and two governments fixed the same MCP flaw LINK
  • The AI app builder your team trusts has a root-level backdoor LINK
  • Crypto sleuth ZachXBT fronted $350K to pose as a client of Lazarus' Chinese launderers LINK
  • Long-running npm malware campaign accumulates 40,000 downloads LINK
  • ClingSTUN backdoor exploits multiple IoT vulnerabilities to gain persistent remote access LINK
  • New Dell system update flaw lets hackers gain root privileges LINK
  • ClickFix smuggles payloads through browser cache to bypass Windows run limits LINK

🛠️ Trending tools

Arcjet: runtime security for AI apps that detects prompt injection, authorizes agent tool calls, redacts sensitive data, and blocks bots before actions execute. LINK
VibeDefend: secures AI-generated code from inside agents like Claude Code and Cursor, scanning diffs live and blocking dangerous commands before they run. LINK
Axari: an AI security twin that works across your tools and teams, taking goals or recurring tasks and driving them to completion from Slack or Teams. LINK
PortAura: monitors which processes listen on which ports, flags exposure and baseline changes, so you can audit local services without Terminal commands. LINK
Stile.​iD: verifies real identities behind high-risk actions using ID checks, liveness, and face matching, without storing users' documents yourself LINK
ReallyFree: labels search results by their real cost, flagging watermarks, paywalls and trials so you know what's genuinely free before clicking. LINK

📚 Trending research papers

Guardrail auditing lets companies grade how often a safety filter makes correct calls on private user inputs no one is allowed to read, boosting error detection by up to ~25 points. LINK
Prompt-injection detectors that top one safety benchmark fail inside real AI agents, with the leading detector catching just 2% of attacks in one agent test, so buyers should test on their own tool outputs. LINK
Expert routing in modular AI reveals that a few internal specialist units control a model's ability to refuse harmful requests, and targeting them by influence rather than usage cut refusals from 34 to 9 of 100 malicious prompts. LINK
Agent tampering defense protects messages passed between AI agents from being secretly altered in transit by sending each message over multiple routes and accepting it only when a majority agree, assuming most routes stay honest. LINK
Knowledge-graph search tools have a hidden weak spot, attackers can poison the behind-the-scenes summaries these systems trust, hijacking up to 94% of answers by altering just 0.016% of them while dodging nearly all current defenses. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
★  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free