Thursday 27 August 2026 | Join Free | Upgrade

Together with

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🔫 US firearms agency hit by ransomware

🏥 Cyberattack halts Boston Scientific shipments

🕵️ FBI seizes Chinese hacking tools

🔒 CISA orders urgent Citrix flaw patch

🔓 Ransomware affiliate hit 20 firms using AI

Plus: 💡 6 strategies & tactics, 🎁 5 other news you might like, 🧰 6 tools, and 📚 5 papers.

Breaches don't stay contained.

Last year Americans reported $3B+ lost to fraud and identity theft (FTC) — most of it starting with credentials leaked long before the victim noticed.

Coveron, built by Nord Security (the team behind NordVPN), watches for exactly that:

• Scans the dark web for your leaked credentials

• Flags unusual credit activity in real time

• Alerts you the moment something looks off — and if you're hit, up to $2M in identity-theft recovery + scam-loss insurance

Use code TECHPRESSO for up to 71% off.
🔫 US firearms agency hit by ransomware LINK
  • The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that one of its systems was compromised in what it called a "major incident," following breach claims by the Qilin ransomware gang on its dark web leak portal.
  • ATF said the breach hit a standalone system that operates separately from its enterprise network, with no indication the incident affected the enterprise network, the ATF eForms system, or any other ATF system, and no impact on operations.
  • Qilin, a Ransomware-as-a-Service operation first spotted in August 2022 under the "Agenda" name and linked to over 2,200 victims, added ATF to its leak site without stating whether it stole files or demanded a ransom; the Justice Department is investigating.
🏥 Cyberattack halts Boston Scientific shipments LINK
  • Medical device maker Boston Scientific disclosed Wednesday that a cyberattack this week disrupted its operations, cutting off access to company information systems and applications including its shipment services, according to an SEC filing.
  • The attack has left the pacemaker and stent maker unable to process and ship orders, and the company said the timeline for full restoration of affected functions and systems access is not yet known.
  • Analysts at Piper Sandler, who spoke with management, estimated it may be weeks before normal operations resume, with the firm's Matt O'Brien writing that Boston Scientific may return to shipping all products in less than three weeks.
🕵️ FBI seizes Chinese hacking tools LINK
  • The FBI and Justice Department seized internet domains that a Chinese state-sponsored hacking group known as "QTFY," along with hacking platforms called "QScan" and "QTRouter," allegedly used to target U.S. government agencies and critical infrastructure.
  • Officials said the operation disabled the group's malicious software and disrupted a global botnet and hacking platform, with victims of QTFY intrusion activity including NASA, the Federal Reserve, the U.S. Senate, and the departments of Energy, Justice, and Health and Human Services.
  • According to court documents, QTFY sold computer hacking services to paying customers including the Chinese Ministry of State Security and People's Liberation Army, and U.S. law enforcement has now investigated and disabled the software as part of a series of operations against Chinese-sponsored hacking.
🔒 CISA orders urgent Citrix flaw patch LINK
  • CISA has told federal agencies to patch their Citrix NetScaler appliances against a flaw already under attack, setting an August 29 deadline to fix the exposed systems.
  • The high-severity bug, CVE-2026-8452, is a memory overflow in NetScaler ADC and Gateway appliances set up with Gateway VPN or AAA virtual servers, and watchTowr showed it lets attackers run code as root, beyond the crash-only impact Citrix first described.
  • The flaw is actively exploited, with researchers flagging "pray and spray" attacks that drop web shells on compromised appliances, while Shadowserver tracks over 22,000 exposed NetScaler ADC and nearly 1,800 Gateway instances online.
🔓 Ransomware affiliate hit 20 firms using AI LINK
  • A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusions and Active Directory escalation.
  • CloudSEK found the affiliate used NetExec for LDAP and SMB discovery, AS-REP roasting, and Kerberoasting, then escalated through custom noPac tooling, ADCS abuse, and NTLM relay chains with PetitPotam, PrinterBug, and DFSCoerce to reach domain-administrator access.
  • The activity surfaced after researchers found the attacker's Linux home directory exposed through an unauthenticated file listing on port 8888, revealing Windows and Linux/ESXi Aurora encryptors written in Zig, hosted in a Cloudflare R2 bucket and moved via SCP.

Want to get the most out of ChatGPT?

ChatGPT is a superpower if you know how to use it correctly.

Discover how HubSpot's guide to AI can elevate both your productivity and creativity to get more things done.

Learn to automate tasks, enhance decision-making, and foster innovation with the power of AI.

💡 Strategies & Tactics

> Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation: Correlate alerts across AWS security services with your own knowledge of sensitive resources and normal access to catch multi-stage attacks that individual findings miss.
> Red Flags that Expose fake North Korean IT workers: Watch for telltale signs like remote-control PiKVM hardware and heavy VPN use to catch North Korean operatives posing as remote IT hires.
> Snowflake ends service-account passwords. Now comes the hard part: Snowflake is blocking passwords for machine accounts, forcing companies to finally track who owns each one and what breaks when access ends.
> Linux Foundation Introduces TRACE standard for AI runtime evidence: The Linux Foundation's TRACE standard creates a tamper-proof, hardware-backed receipt proving what an AI agent actually did, so organizations can independently verify sensitive AI activity.
> CISA shares federal cyber guidance with critical infrastructure companies: CISA, the U.S. cyber agency, released network logging guidance for federal agencies that critical infrastructure companies can also use to detect and respond to attacks faster.
> Edge infrastructure under Siege: what Two independent datasets Reveal about Who’s exploiting Your perimeter: Two independent security datasets show that both nation-state and criminal hackers target the same edge devices like firewalls and VPN gateways, so defenders must patch against all attackers at once.

Other news & articles you might like

  • GitLab Duo claude AI agent flaw Lets Attackers execute arbitrary commands in CI pipelines LINK
  • Iran-Linked Hackers Use reverse SSH tunnels to Reach Deep Inside compromised networks LINK
  • Two Alleged ‘TeamPCP’ hackers arrested in Australia LINK
  • Russian cyber espionage infrastructure Uses Evilginx and OAuth phishing to steal accounts LINK
  • New apache Log4j2 flaw Lets attackers bypass security Checks and execute remote code LINK

🛠️ Trending tools

Kastra: runtime authorization layer that enforces policies on AI agent actions before execution, blocking unauthorized tool use, prompt injection, and data exposure with sub-millisecond latency LINK
qsa.sh: runs an external port and vulnerability scan of your public IP with naabu, nmap, and nuclei, streaming results to your terminal via curl in seconds. LINK
Claudoscope: menu bar app for Claude Code that browses session history, tracks token costs, scans for leaked secrets, and lints config files locally. LINK
HOL Guard: a local firewall for AI agents that intercepts and blocks risky actions like deleting production data or exposing secrets before they run. LINK
Cynative Security Research Agent: open-source AI CLI that answers plain-language security questions across your code, cloud, and runtime with IAM-enforced read-only access. LINK
SolonGate: a zero-trust security layer that intercepts AI agent tool calls, applying policy checks to block unauthorized or destructive actions before they run. LINK

📚 Trending research papers

Phone-to-phone contract signing lets two devices co-sign a document by scanning an animated on-screen code, with no server, no certificate authority, and no internet, using each phone's built-in security chip to prove identity. LINK
Face-swap privacy tools often leak the original person's identity despite hiding their face, and a new method explains why and predicts when this happens, making privacy claims verifiable rather than just assumed. LINK
Code search tools can be tricked by renaming variables in a snippet without changing what it does, pushing irrelevant code to the top of results and cutting search accuracy by up to ~77%. LINK
AI-written server setup code ships with security flaws by default, but adding security rules to the request makes top models hit 95 to 100 percent compliance, roughly quadruple human developers. LINK
Office document ingestion can feed AI a hidden version of a Word, Excel, or PowerPoint file that differs from what people see on screen, with tested AI systems surfacing planted hidden facts in 48 to 76% of trials. LINK

🎓 Want to master the AI tools we cover every day?

Our AI Academy has 330+ step-by-step tutorials on ChatGPT, Claude, Perplexity, and every tool that matters. No fluff — just practical workflows you can use at work. Try it free for 7 days.

💬 How did you find today's edition?

We read every reply — just reply to this email and let us know how we can improve!

★★★★★  Nailed it
★★★  Average
  Fail

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free