I go through about 25 cybersecurity news portals and blogs every week and pull out the most interesting stories. Then I turn them into this short, digestible summary, so you can stay up to date without trying to follow 25 different sources yourself. 😱

My aim is to create a summary that gives you the gist without needing to open up the source article. But if you do want to dig deeper, all the sources covering the event are linked below each story.

If you enjoy these, come back next Monday

scroll to the bottom to subscribe to the e-mail newsletter.

Gemini AI crossed a test boundary and used leaked passwords to access three real companies’ systems during a CTF exercise

Google confirmed that during a May cybersecurity evaluation run by Irregular, a Gemini model accessed systems belonging to three real companies without authorization after unintended internet access let it treat real targets as part of the test. The case illustrates how agentic evaluations can fail when test environments and naming/targeting controls allow models to follow real-world breadcrumbs (like exposed credentials) into third-party systems.

Key Details

  • Access methods included password guessing in one case and using credentials found in a public repository in two others, according to Google’s statements reported by multiple outlets.
  • The evaluation scenario used a fictional company name that matched a real company, contributing to “mistaken identity” targeting during the capture-the-flag exercise.
  • Irregular said internet access was unintentionally made available, despite the model not being intended to have online access during the exercise.
  • Google said it notified the three affected companies and federal authorities; the companies were not named publicly.

Next Steps

  • Good cyber hygiene is more important than ever. Every “hacker” starts the hacking by trying the easiest things first - leaked passwords, no MFA on them. No zero days required.

Read more at recordedfuture.com, CSO Online, The Record, Talkback.sh

ZCode stopped uploading entire code repositories to Alibaba Cloud OSS

Investigators reported that Z.ai’s ZCode desktop coding assistant silently packaged whole development workspaces—including extensive .git history—and uploaded encrypted snapshots to Alibaba Cloud OSS while users were logged in. Z.ai said it removed the snapshot generation/upload workflow in newer clients, deleted the associated OSS bucket/infrastructure, and published a public code drop for scrutiny after disabling the feature.

Key Details

  • The reported pipeline involved the client requesting upload credentials from zcode.z.ai via /api/v1/snapshot/upload-credential, then uploading an encrypted archive directly to Aliyun OSS using provided form credentials (with an OSS callback to Z.ai’s backend).
  • The blogger said snapshot contents included Git LFS cache, .git objects, reflogs, and global ZCode config artifacts, with a local manifest indicating .git data dominated the archive payload in the tested workspace.
  • Encryption was described as envelope encryption where the RSA public key is delivered by the server and the private key remains cloud-side, meaning the locally stored ciphertext archives could not be decrypted by the user locally.
  • Z.ai said remediation in ZCode v3.14.0 removed the repository snapshot generation and upload workflow, and that third-party assessments were conducted by CAICT and NSFOCUS as part of its response.
  • Z.ai stated that the “zcode-prod” Alibaba Cloud OSS bucket and its objects were deleted and that the Repo Wiki entry point and related generation workflow were removed.

Next Steps

  • Review data retention policies of your vendors that have AI features

Read more at Code is cheap, let’s talk, CSO Online

WordPress “Comment2Shell” XSS flaw lets anonymous commenters plant scripts that can lead to admin-driven server RCE

WordPress patched CVE-2026-93485 (“Comment2Shell”), where an anonymous comment could inject a hidden script that executes when the page is viewed. If a logged-in administrator loads a page containing the malicious comment, the attacker can abuse the admin’s session to upload a plugin (e.g., a web shell), turning the XSS into server-side code execution.

Key Details

  • Affected WordPress versions span 4.7 through 7.1; fixed point releases include 7.1.1, 7.0.5, 6.9.8, and other branch-specific security releases (down to 4.7.36).
  • Exploitability depends on comment visibility and theme/comment formatting; it works on block themes (default since Twenty Twenty-Two) and is reported to affect some classic themes (e.g., Twenty Twenty-One) when they use the same formatting step.
  • WordPress describes exploitation as “subject to comment approval,” but the researcher and Patchstack note ways a comment can still end up displayed; Patchstack emphasizes moderation is not a security control.

Next Steps

  • Update WordPress core to a fixed release: 7.1.1 (or 7.0.5 / 6.9.8 / the patched build for your branch).
  • If you cannot patch immediately, temporarily disable or close comments on posts/site-wide to remove the injection path.

Read more at Patchstack, The Hacker News

Meta patched a Muse macOS zero-day where any local process could redirect dictation to steal the agent token and take over accounts

A zero-day in Meta’s Muse macOS app let any app or terminal command running as the logged-in user change a hidden dictation endpoint to an attacker-controlled server, capturing the Muse auth token and enabling account takeover. The issue mattered because Muse is designed to hold broad, user-granted access (messages, email, files, mic/camera), so hijacking the agent can turn its legitimate privileges into an operator-controlled backdoor.

Key Details

  • The vulnerable control was an undocumented setting (dictation endpoint) that could be modified without additional macOS permissions, enabling interception of voice prompts and token exfiltration.
  • Wardle’s PoC (“not-a-mused”) showed attackers can read dictated text, inject extra instructions, and reuse the stolen token to control Muse and access chat history.
  • The attack does not break into macOS by itself; it requires the attacker to already be able to execute code as the current user (including via ClickFix-style social engineering, per the reporting).
  • Meta said it shipped a hotfix roughly 12 hours after disclosure, but reporting noted the company had not published a detailed security advisory at the time.
  • Amazon began blocking Muse shopping activity, calling it an “unauthorized AI agent” that violates Amazon’s Conditions of Use, and asked Meta to remove Amazon from the Muse experience.

Read more at Ars Technica, Ars Technica, objectivebythesea.org, Wired Security, The Hacker News, Cybersecurity Reddit

Okta adds Agent Gateway for runtime policy enforcement and launches multivendor Blueprint Alliance for AI agent security

Okta unveiled new capabilities for its Okta for AI Agents platform, centered on Agent Gateway that enforces policy and logs AI-agent tool calls at runtime rather than only relying on after-the-fact review. In parallel, Okta and 11 other vendors formed the Blueprint Alliance to publish an open, multivendor reference architecture for governing and responding to compromised AI agents.

Key Details

  • Okta says AI assistants can become risky when users connect them to everyday tools and unintentionally create paths into sensitive systems; it also highlighted the problem of agents continuing to run after an employee leaves if they aren’t governed.
  • Okta’s existing visibility is based on agent events recorded in Okta System Log and streamed to SIEMs; Agent Gateway is positioned as an in-line control point in the execution path between agents and tools.
  • Okta described an expanded “kill switch” approach: admins can already deactivate an agent to block new sessions, and Okta plans that once agents are routed through Agent Gateway, deactivation will revoke active tokens and shut down in-flight sessions.
  • Discovery enhancements include Shadow AI Agent Discovery for Endpoints, intended to find unmanaged agents running on employee laptops/desktops; Okta also supports registering/importing agents from platforms including Amazon Bedrock and Salesforce Agentforce.
  • The Blueprint Alliance’s founding members include AWS, CrowdStrike, Google Cloud, Databricks, Docker, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler; the alliance says it will test interoperability across standards including MCP, the Open Cybersecurity Schema Framework and the Shared Signals Framework.

Next Steps

  • If you’re evaluating AI agent governance, consider prioritizing controls that provide runtime enforcement and rapid containment (token revocation/session termination) rather than relying only on post-event log review.
  • Assess whether you have coverage for “shadow”/unmanaged agents on endpoints (laptops/desktops), not just agents registered in sanctioned agent platforms.

Read more at CSO Online, SiliconAngle, SiliconAngle

Fake LastPass Authenticator GitHub download uses Microsoft-attested driver to kill 145 security tools before running Rapuncel stealer

Attackers used a search-ranked fake GitHub “LastPass Authenticator” download to deliver a loader that escalates to SYSTEM, installs a kernel driver, and then runs an infostealer. The campaign’s core technique is using a Microsoft-attested (signed) driver to terminate AV/EDR processes from the kernel, clearing the way for credential and wallet theft.

Key Details

  • The driver tracked as Alinubx.sys (a renamed CnCrypt driver) exposes an IOCTL interface that enables kernel-mode process termination via the \.\Alinubx device.
  • The fake GitHub repo (github.com/LastPass-Authenticator) funneled users through multiple GitHub pages to an attacker-controlled server; LastPass reported at least 40 impersonated brands tied to the same infrastructure.
  • LastPass/Delphos reported the driver was signed via the Microsoft Windows Hardware Compatibility Publisher chain (attestation) with a March 2023 signing date, yet it was not present on Microsoft’s vulnerable driver blocklist at the time described.
  • Hunting signals called out by the researchers include a service created as “NvFsFilter”, a driver dropped as nvfsflt64.sys, signer strings referencing Henan Dafeng Software / “CnCrypt,” and post-load behavior where security processes are killed and the stealer repeatedly re-runs across reboots.

Next Steps

  • Consider adopting an Enterprise App Store as a single approved source for common apps used across the estate.
  • Add detections/hunting for \.\Alinubx device access and the related persistence artifacts (service “NvFsFilter”, nvfsflt64.sys) described in the report, rather than relying on a single filename/hash.
  • If a system executed the fake installer, treat it as a kernel-level compromise and prioritize offline forensics or rebuilding; rotate any browser-saved credentials and affected sessions from a clean device as recommended by the researchers.

Read more at LOLDrivers, The Hacker News, Talkback.sh

GitLab “work item by email” address doubles as a long-lived account token that can commit code and trigger CI as the victim

GitLab’s per-project “Email work item to this project” address embeds a non-expiring token that lets anyone who knows it act as that user across projects, because GitLab accepts incoming mail without validating the sender. By swapping the address suffix to create merge requests by email, an attacker can land commits on branches the victim can push to (including main) and potentially run CI/CD jobs under the victim’s permissions.

Key Details

  • Mitigation is token rotation, not feature opt-out: GitLab.com enables the feature by default and individual users can’t disable email-based issue/MR creation; self-managed instances can disable incoming email at the instance level.
  • The same embedded token is reused across all of a user’s projects, so a leak from one project can be used against other public and private projects the account can access (per Aikido’s testing).
  • Incoming email actions bypass IP allowlists and 2FA requirements per GitLab documentation, and Aikido demonstrated commits landing even when interactive access (browser/git) was blocked by IP restriction.
  • Targeting a specific project requires its path and numeric project ID; both are exposed for public projects, while private project paths must be learned elsewhere (IDs are described as guessable).

Next Steps

  • Search public repos/docs for leaked incoming-email addresses (e.g., patterns like incoming+…-glimt-…[email protected]) and remove them from READMEs/support pages; rotate tokens after removal.
  • For self-managed GitLab, disable Incoming email at the instance level if you don’t need email-to-issue/merge-request workflows (GitLab admin setting; see GitLab docs referenced in the coverage).

Read more at The Hacker News, Dark Reading, CSO Online

Cloudflare fixed a Containers flaw that let one tenant read leftover disk data from other customers’ workloads

Cloudflare patched a vulnerability in Cloudflare Containers (and the Sandbox SDK built on it) where a new container could recover residual disk blocks previously used by other customers on the same host. The issue stemmed from storage blocks being reused without being zeroed, enabling cross-tenant data exposure from deallocated (not live) container disks.

Key Details

  • The root cause was a dm-thin storage pool configured with skip_block_zeroing, allowing partially overwritten 64 KiB blocks to retain prior tenants’ data.
  • Researchers triggered reuse by writing a small 4 KiB chunk into ext4 free-space regions, then reading the full underlying block from the raw device to observe bytes the new container never wrote.
  • In controlled production placements, the researchers observed residual material on 18 of 24 placements and 20 of 22 underlying nodes across four continents, including directory structures and database pages (including structurally complete SQLite databases).
  • Cloudflare mitigated by removing skip_block_zeroing fleet-wide, then retiring running container disks and clearing cached pre-mitigation image snapshots to eliminate old mappings that could be inherited by new containers.
  • Cloudflare reported no evidence of malicious exploitation in historical disk I/O telemetry, attributing matching activity only to the researchers and Cloudflare’s authorized validation work.

Next Steps

  • When reviewing “isolated” tenant setups, make sure you have a deep understanding what isolated really means and what are the related risks to your assets. Is everything isolated? Are there some shared resources? Are resources reused?

Read more at Talkback.sh, Bleeping Computer, The Hacker News, Cloudflare Docs, Cloudflare Docs, Accomplish

Subscribe

Subscribe to receive this weekly cybersecurity news summary to your inbox every Monday.