Weekly security roundup - Aug 8, 2025

Weekly security roundup: end-to-end encryption, AI vulnerabilities, malware, voice phishing, and abuse of enterprise AI assistants; recommendations to protect data and systems.

domingo, 17 de agosto de 2025 • 4 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Weekly security news roundup - August 8, 2025

When we browse the Internet, we are constantly exposed to threats, visible or invisible, direct ones like malicious sites or indirect ones from using software and services with vulnerabilities. These threats lurk, and it only takes a moment of carelessness for the alarms to go off.

In this roundup, we review key news that highlights the importance of maintaining end-to-end encryption, security issues related to artificial intelligence tools, new waves of malware, and voice phishing attacks.

End-to-end encryption

End-to-end encryption is a necessity to protect the privacy and security of users and businesses. Any proposal to introduce a backdoor into encryption systems should not be handled in secret, because it affects fundamental privacy rights. Although in specific cases legislation may allow access under limited circumstances, in general the technology industry must remain firm in preserving end-to-end encryption to protect user data and business solutions such as custom applications and custom software.

Vulnerabilities in the AI code editor Cursor

Several vulnerabilities were recently patched in the AI-assisted code editor Cursor, including remote code execution. Although the flaws have already been fixed, the case serves as a reminder that the tools we use daily can turn against us if not properly managed. For example, an issue identified as CVE-2025-54136 allowed configuration files to be swapped for malicious commands if an attacker had write permissions on active branches or local access to write files, which could lead to arbitrary code execution.

PlayPraetor Trojan on Android

The PlayPraetor Trojan has infected more than 11,000 devices through fake Google Play pages and social media ads. This malware abuses Android's Accessibility service to steal data and execute actions without the user's explicit consent. Its active development and expansion as malware-as-a-service points to campaigns recently targeting Spanish-speaking and Arabic-speaking victims, underscoring the need for reinforced cybersecurity on mobile devices and controls in custom mobile applications.

AI jailbreak demonstration and weak guardrails

A recent experiment showed how a decomposition technique allowed identifying specific content from an article that had been used in the training of a large language model, even though the direct request to reproduce the text was denied. This shows that AI model guardrails can fail to recognize and protect proprietary or copyrighted material, a significant risk for organizations that train models with internal or licensed content.

Voice phishing against large companies

Voice phishing attacks continue to be effective even against large technology companies. In a recent incident, attackers who carried out voice phishing managed to download user data from a third-party-managed CRM. A recommended defense is the use of multi-factor authentication compatible with the FIDO standard, since cryptographic keys linked to the service's domain name protect against phishing sites that emulate legitimate domains.

Abuse of enterprise AI assistants

AI assistants in enterprise environments can be manipulated to steal or exfiltrate data. Research has shown that agents deployed on platforms such as Copilot Studio can be hijacked to extract information accessible to the agent, including customer databases and full CRMs. This poses real risks for companies that integrate artificial intelligence into customer service and internal processes; it is crucial to design controls, audits, and security policies around AI agents and enterprise AI deployments.

About Q2BSTUDIO

Q2BSTUDIO is a custom software and application development company specialized in artificial intelligence and cybersecurity. We offer custom software, custom applications, and comprehensive solutions that include AWS and Azure cloud services, business intelligence services, and Power BI for visualization and analysis. Our teams are experts in AI for businesses, AI agents, and secure architectures that minimize risks and maximize operational efficiency. If you are looking for a company that combines custom application development with expertise in cybersecurity, artificial intelligence, and AWS and Azure cloud services, Q2BSTUDIO designs solutions tailored to your needs.

Practical recommendations

Implementing end-to-end encryption whenever possible, keeping software and dependencies updated, auditing and testing AI tools before deployment, applying strict controls over AI agents that interact with sensitive data, and strengthening authentication with FIDO standards are essential measures. Additionally, companies should evaluate business intelligence and Power BI services with access controls and data retention policies to prevent leaks.

Keywords to improve positioning: custom applications, custom software, artificial intelligence, cybersecurity, AWS and Azure cloud services, business intelligence services, AI for businesses, AI agents, Power BI.

That's all for this week, see you next time.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.