|
|
Hi there, this is your daily ☕️ Cyberpresso.
|
|
|
In today's Cyberpresso:
|
|
🎣 Phishing kit bypasses Microsoft 365 MFA 🪟 Windows apps turned into kernel backdoors 🛠️ ConnectWise flags unpatched ScreenConnect flaw 🛡️ SAP patches 4 critical flaws 🦠 Rootkit hides web shells in F5 servers Plus: 💡 4 strategies & tactics, 🎁 8 other news you might like, 🧰 6 tools, and 📚 5 papers.
|
|
Your AI budget tripled. See real usage patterns with Harmonic.
AI spend is now a major P&L line item—but most teams can't show what it's producing.
Harmonic Security maps AI activity to use cases and teams, revealing real productivity, shelfware, data risk, and adoption trends across approved and unapproved tools.
Give your board the data behind the return.
|
🎣 Phishing kit bypasses Microsoft 365 MFA
LINK
|
- A phishing operation called BigBear 2.0 gets around multi-factor authentication on Microsoft 365 accounts by stealing the authenticated session cookie rather than trying to defeat the login code or push notification itself.
- Built on the Evilginx2 framework, the campaign sits between the victim and the real Microsoft login, relays traffic through a fake sign-in page, lets the user complete MFA, then copies the session cookie to replay and access email, Teams, SharePoint, and OneDrive as the victim.
- CloudSEK found the panel held 5,137 stolen records across 461 organizations and over 40 countries, hitting IT services and managed service providers hardest, and recommends FIDO2 or WebAuthn keys and passkeys, revoking active sessions and refresh tokens, and forcing new sign-ins.
|
🪟 Windows apps turned into kernel backdoors
LINK
|
- A new Windows attack technique called Bring Your Own Trusted Caller (BYOTC) turns legitimate signed applications into tools that ask privileged kernel drivers to run dangerous actions, effectively creating kernel backdoors from trusted programs.
- Researchers at Xusheng.dev demonstrated the method by injecting a DLL into a signed security client and using that now-trusted process to ask its driver to terminate Microsoft Defender's service, since a signature verifies the launched file but not the running process.
- The attack requires administrator rights and exploits the trust between a driver and its approved user-mode caller; System Informer fixed its gap by requiring a MAXIMUM or protected TCB/System creator, with the updated driver reaching the Release Channel on August 29, 2026.
|
🛠️ ConnectWise flags unpatched ScreenConnect flaw
LINK
|
- ConnectWise has warned of a still-unpatched flaw in its ScreenConnect Remote Access platform that affects file transfer behavior in Remote Access Support and Access sessions, with a permanent fix promised later this week.
- The bug, disclosed in an advisory on Thursday and not yet assigned a CVE ID, hits both cloud and on-premises deployments; there is no report of active exploitation, but Shadowserver tracks nearly 6,000 ScreenConnect instances exposed online.
- Until a patch ships, ConnectWise says administrators can block potential attacks by editing user roles on the Administration page and deselecting the TransferFiles permission (or TransferFilesInSession for legacy) for each session group.
|
🛡️ SAP patches 4 critical flaws
LINK
|
- SAP has rolled out 19 Security Notes fixing four critical vulnerabilities across its enterprise products, with the most urgent being a maximum-severity (CVSS 10.0) memory-corruption bug in Extended Passport Processing, tracked as CVE-2026-44756.
- The flaw affects numerous SAP Kernel and Web Dispatcher releases, and SAP says landscapes running exposed or broadly accessible components should apply the corrections immediately, though the article reports no active exploitation.
- The other three critical fixes cover missing authentication in the NetWeaver Message Server (CVSS 9.8), possible login disclosure in multitenant apps built with the Cloud Application Programming Model (9.4), and improper access control in SAP GUI for Java (9.0).
|
🦠 Rootkit hides web shells in F5 servers
LINK
|
- A stealthy Linux rootkit is giving attackers durable control of compromised F5 BIG-IP Access Policy Manager servers by injecting PHP web shells only into the memory of the running Apache process, leaving the on-disk files untouched.
- Sophos linked the activity to CVE-2025-53521, an exploited flaw in BIG-IP APM that lets attackers run code on the server without logging in, and said the implant is a targeted second-stage payload not yet tied to any named group.
- The rootkit hooks Apache's PHP component to inject shells into three APM webtop scripts, accepts encrypted requests answered with a disguised HTTP 201 CSS response, and opens a local Unix socket to a Bash shell; F5's remediation guidance should be followed since a service restart alone won't remove persistence.
|
|
AI can build faster. Can your team decide better?
AI can draft the PRD and prototype the idea. Jira Product Discovery helps teams decide whether it belongs on the roadmap. Bring feedback and ideas together, prioritize as a team, and keep your roadmap connected to delivery in Jira.
💡 Strategies & Tactics
|
> Stealing AI Reasoning Traces: Researchers found that encrypted AI reasoning traces work across sessions and models, letting attackers steal hidden reasoning, private data, and credentials.
|
|
|
Other
news & articles you might like
-
ClickFix moves into the browser and onto WebDAV, Cisco Talos finds
LINK
-
Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise
LINK
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
LINK
-
Bimbo Bakeries USA Data Breach Exposes SSNs in Oracle E-Business Suite Zero-Day Attack
LINK
-
Shai-Hulud npm Worm Resurfaces After 111 Days and Slips Past Malware Scanning
LINK
-
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
LINK
-
THost9 Android RAT Pairs Packed Loader With ADB Worm
LINK
-
Hackers Create Domain Admin Account and Disable Security Tools Inside Windows Network
LINK
|
|
🛠️ Trending tools
|
Halo: an API-first platform combining text, image, and audio analysis to detect deepfakes and synthetic media, helping fraud and trust teams block attacks.
LINK
|
|
Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents in under 20ms, mapping to SOC 2, EU AI Act, and ISO 27001 compliance frameworks
LINK
|
|
TailMux: runs multiple Tailscale profiles simultaneously on macOS and Linux, routing by hostname so work and personal tailnets stay reachable at once.
LINK
|
|
Lunen.ai: an AI assistant that logs every action, flags risky steps for approval, and maintains audit trails your security team can trust.
LINK
|
|
VHF Morse Transmitter Monitor: a browser-based tool that transmits Morse code over VHF radio by exploiting electromagnetic interference leaked from computer monitors.
LINK
|
|
Dsnitch: monitors Docker container network egress in real time using eBPF, mapping IPs to domains via passive DNS snooping in a terminal interface.
LINK
|
|
|
|
📚 Trending research papers
|
Intrusion-detection upgrades should be checked before a retrained model replaces the live one, since whether the new model is actually better depends heavily on the dataset and how much evidence backs it.
LINK
|
|
Electromagnetic eavesdropping shows attackers can beam radio signals at everyday electronics to force them to leak hidden data, letting them capture headphone audio from up to 30 meters away, even through walls.
LINK
|
|
Attack testing for AI agents shows that a tireless automated hacker gets more effective the longer it probes a tool-using agent, meaning security reviews must account for how much effort an attacker spends, not just the target's defenses.
LINK
|
|
AI-written phishing emails get more dangerous with every personal detail added, raising click intention ~28% per level in a study of 180 workers, though wrong or vague details actually make targets more suspicious.
LINK
|
|
Private search on encrypted data runs meaningfully faster by parking the heavy lifting in secure GPU chips with large protected memory, hiding both what users query and which records they touch without the old speed penalty.
LINK
|
|
|
|
|
Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.
|
|
💬 How did you find today's edition?
We read every reply — just reply to this email and let us know how we can improve!
|
|