Skip to content
Artwork for Daily DefSec Brief
TechnologyNewsTech News

Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

Play
  • 51 episodes
  • daily
  • Avg 4 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • Today · 4 min

    Cyber Security News for September 24 2026 - Daily DefSec Brief

    1. Roundcube pre-login SQL injection now exploited — CVE-2026-48842 — Fixed: 1.6.16 or 1.7.1 — Do: Upgrade Roundcube webmail — https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 2. TeamCity RCE now used in ransomware campaigns — CVE-2026-63077 — Fixed: 2025.11.7 or 2026.1.3 — Do: Patch TeamCity and check it for intruders — https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/ 3. Spraying hit only forgotten M365 service accounts — Do: Lock down forgotten Microsoft 365 service accounts — https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns 4. Public Ubuntu container escape, no kernel fix yet — CVE-2026-80521 — Do: Keep untrusted containers off Ubuntu hosts — https://ubuntu.com/security/CVE-2026-80521 5. Windows app host hands Microsoft tokens to attackers — Do: Turn off app sideloading where it isn't needed — https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door 6. Malicious providers on HashiCorp's Terraform registry — Do: Check Terraform lock files for the typosquat — https://www.aikido.dev/blog/graphalgo-terraform-go-modules 7. Any cPanel account can get root via CalDAV — CVE-2026-87899, CVE-2026-87900, CVE-2026-68490 — Fixed: 11.134.0.57, 11.136.0.41, 11.138.0.8; WP Toolkit 6.11.3 — Do: Update cPanel and WP Toolkit — https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 8. Foxit PDF Reader update fixes updater SYSTEM flaw — CVE-2026-91813 — Fixed: Reader 2026.2.1; Editor 2026.2.1, 14.0.8 or 13.2.7 — Do: Push the Foxit PDF update — https://www.foxit.com/support/security-bulletins.html 9. Hundreds of leaked GitHub App keys still work — Do: Audit your GitHub Apps and rotate their keys — https://blog.gitguardian.com/github-app-private-keys-leaked/ 10. New injection technique slips past four EDRs — Do: Ask your EDR vendor about parameter poisoning — https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/ 11. A GitLab email address can commit code as you — Do: Reset your GitLab incoming email token — https://www.aikido.dev/blog/gitlab-email-push-to-main

    • Transcript
  • Yesterday · 5 min

    Cyber Security News for September 23 2026 - Daily DefSec Brief

    1. F5 BIG-IP APM zero-day exploited for code execution https://my.f5.com/manage/s/article/K000162605 2. Check Point management servers exploited since July https://support.checkpoint.com/results/sk/sk1000171 3. Device-code phishing kit registered its own devices ra — https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/ 4. Arista VeloCloud orchestrator zero-day exploited https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 5. Check Point VPN certificate flaw now exploited https://support.checkpoint.com/results/sk/sk1000117 6. Public tool freezes Defender's updates — Do: Alert on stale Defender signatures — https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html 7. Rogue Entra MFA provider keeps stealing passwords — Do: Alert on new external MFA methods — https://www.varonis.com/blog/trustsink 8. Public exploit for Veeam Agent's SYSTEM escalation — CVE-2026-32996 — Fixed: 13.0.2.29 — Do: Update Veeam Agent on Windows endpoints — https://www.veeam.com/kb4852 9. WordPress core flaw loads PHP with no login — CVE-2026-87902 — Fixed: 7.1.2 (backports down to 4.7.37) — Do: Check WordPress auto-updates really installed — https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ 10. ManageEngine logon-screen client gives SYSTEM — CVE-2026-74849 — Fixed: 7001 — Do: Upgrade ADSelfService Plus to the fixed build — https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-74849.html 11. SharePoint "spoofing" flaw is code execution — CVE-2026-65660 — Fixed: 16.0.10417.20198 (2019), 16.0.19725.20522 (SE), 16.0.5565.1001 (2016) — Do: Confirm August's SharePoint update is installed — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660 12. Next.js preview images can run server code — CVE-2026-94545 — Fixed: 16.3.6 — Do: Upgrade Next.js apps that generate preview images — https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j 13. Bifrost AI gateway runs commands without a login — CVE-2026-90898 — Fixed: 2.1.0 — Do: Upgrade Bifrost and rotate its provider keys — https://research.jfrog.com/vulnerabilities/bifrost-is-vulnerable-to-unauthenticated-remote-code-execution-via-mcp-stdio-client-registration-cve-2026-90898/ 14. Malware has four AI models vote on its moves — Do: Alert on unexpected AI API calls from endpoints — https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

    • Transcript
  • Tuesday · 4 min

    Cyber Security News for September 22 2026 - Daily DefSec Brief

    1. A thousand switches gave up the network map — CVE-2026-7273 — Fixed: 2.90(ABTQ.2)C0 on the 48HPv2 — each model has its own 2.90 build ending .2)C0 — federal due 2026-09-24 — Do: Upgrade the GS1900s and change their passwords — https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026 2. One admin click plants PHP on WordPress — CVE-2026-93485 — Fixed: 7.1.1 — Do: Automate WordPress updates, alert on failures — https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/ 3. Signed driver kills 145 security tools — Do: Block NvFsFilter and alert when EDR goes quiet — https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/ 4. A bad npm release with valid provenance — Do: Stop treating npm provenance as a code check — https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack 5. Ransomware run entirely through Group Policy — Do: Alert on new GPOs and review domain admin — https://securelist.com/tr/payload-ransomware-via-group-policy/121335/ 6. Windows COM fix left the hole open — CVE-2026-66804, CVE-2026-50343 — Do: Patch Windows and hunt dangling COM registrations — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804 7. Backdoor exfiltrates each document as you save it — Do: Hunt the fake scheduled tasks on your endpoints — https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html 8. SAML keeps producing authentication bypasses — Do: Take new SSO integrations to OIDC — https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/ 9. AWS quarantines leaked keys in ten seconds — Do: Alert when AWS quarantines one of your keys — https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/ 10. 225 AI-found CVEs, one of them exploited — CVE-2026-26980 — Fixed: 6.19.1 — Do: Upgrade Ghost and rotate its API keys — https://github.com/advisories/GHSA-w52v-v783-gw97 11. ShinyHunters seized Clop's leak site — Do: Revisit a ransom you paid Clop — https://therecord.media/shinyhunters-clop-cyberattack-website

    • Transcript
  • Monday · 5 min

    Cyber Security News for September 21 2026 - Daily DefSec Brief

    1. Orkes Conductor RCE exploited for a month — CVE-2026-58138 (fixed in 3.30.2) — Do: Patch Conductor, put its API behind login — https://research.empiricalsecurity.com/research/september-2026-cve-of-the-month 2. Three Linux kernel flaws are now exploited — CVE-2025-39682, CVE-2025-39964, CVE-2026-53266 (KEV, federal due 21 Sep) — Do: Update the kernel on every Linux host — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. npm malware slips past the new install-script block — indexed-btree, ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, sliding-score-window — Do: Search lockfiles for the ten btree packages — https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/ 4. A former employee's access leaked CrowdSec code — Do: Revoke leavers' GitHub access on their last day — https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html 5. Hardcoded key hands over SolarWinds ARM — CVE-2026-28326 (fixed in 2026.2.1) — Do: Upgrade SolarWinds Access Rights Manager — https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28326 6. HEIC upload bugs reach GitHub Enterprise and Slack — CVE-2026-19118, libheif 1.23.2+, GitHub Enterprise Server 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5 — Do: Update libheif, or turn off HEIC decoding — https://heif-heist.com/ 7. A Terraform lock file pulls malware on terraform init — Do: Check lock-file registries before terraform init — https://www.sentinelone.com/labs/dont-call-us-well-call-your-apis-tradertraitor-backdoors-resurface-on-victim-with-no-crypto-ties/ 8. Cisco's September firewall fixes include a 9.9 — CVE-2026-20329, CVE-2026-20154, CVE-2026-20249, CVE-2026-20250 — Do: Upgrade ASA, FTD and FMC software — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 9. Public root exploits land for four Linux kernel flaws — CVE-2026-74469, CVE-2026-81000, CVE-2026-68121, CVE-2026-80844 — Do: Turn off unprivileged user namespaces and SCTP — https://heyitsas.im/posts/lpe-quartet/ 10. Gemini hacked three real firms in a test — Do: Scan public repos for committed credentials — https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/

    • Transcript
  • Friday · 3 min

    Cyber Security News for September 18 2026 - Daily DefSec Brief

    1. Cisco ISE zero-day exploited for full control — CVE-2026-76460 — Do: Upgrade ISE, grep access.log on every node — https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/ 2. Stolen key rewrote vendor scripts at the edge — Do: Check 14 September traffic, hunt long-lived API keys — https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/ 3. Acronis backup flaw confirmed exploited — CVE-2026-87886 — Do: Upgrade the Acronis plugin to 1.9.3 HF3 — https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/ 4. A long username gets root on Check Point — CVE-2026-91843 — Do: LivePatch Check Point, tighten Trusted Clients — https://thehackernews.com/2026/09/critical-check-point-management-server.html 5. Fake video calls target Rust crate owners — Do: Never install or paste during an unexpected call — https://simonwillison.net/2026/Sep/17/targeted-attacks-on-rustaceans/ 6. Docker sandbox escapes onto the macOS host — CVE-2026-77179 — Do: Upgrade Docker Sandboxes to 0.42.0 — https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html 7. Malicious zone runs code on your resolver — CVE-2026-81642 — Do: Upgrade Unbound to 1.26.1 — https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html 8. One DoH request crashes BIND's named — CVE-2026-77692 — Do: Upgrade BIND to 9.21.26 or 9.20.29 — https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/ 9. Android malware enables its own debug shell — Do: Alert on Developer Options being enabled — https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ 10. First AI-agent breach reported to a regulator — Do: Check your breach template covers agent-run attacks — https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data 11. One in eight MCP config slots holds a secret — Do: Search repos for MCP config files, rotate keys — https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/

    • Transcript
  • September 16 · 4 min

    Cyber Security News for September 16 2026 - Daily DefSec Brief

    1. WSO2 API gateway takes a forged admin token — CVE-2026-5430 — Do: Apply the WSO2 update level, rotate gateway secrets — https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/ 2. Pixel modem zero-day used in targeted attacks — CVE-2026-58704 — Do: Push Pixel to the 2026-09-05 patch level — https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/ 3. Malware forges Chrome's extension integrity hashes — Do: Allowlist extensions, alert on developer mode — https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html 4. Logitech Options+ gives a normal user SYSTEM — CVE-2026-12518 — Do: Upgrade Logi Options+ fleet-wide — https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options+-for-system-shells/ 5. GlobalProtect privesc needs a PAN-OS upgrade too — CVE-2026-0307 — Do: Upgrade the app and PAN-OS together — https://security.paloaltonetworks.com/CVE-2026-0307 6. Parallels Desktop gives a local Mac user root — CVE-2026-90894 — Do: Upgrade Parallels Desktop to 27.0.0 — https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/ 7. Oracle's September update covers 672 flaws — Do: Patch E-Business Suite first — https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves 8. Four of 800 hit their recovery target — Do: Run one full restore end to end — https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/ 9. Gambling sites doubling as C2 infrastructure — Do: Re-examine gambling-domain hits in proxy logs — https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652 10. Fraudulent hires get credentials before detection — Do: Verify identity when credentials are issued — https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/ 11. Most Mythic C2 servers keep the default cert — Do: Alert on O=Mythic certificates and port 7443 — https://censys.com/blog/mythic-c2/

    • Transcript
  • September 15 · 4 min

    Cyber Security News for September 15 2026 - Daily DefSec Brief

    1. Cisco email gateway zero-day exploited for root — CVE-2026-76461, CVSS 9.8 — Do: Upgrade AsyncOS 16.5.0-780, grep mail_logs — https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/ 2. Vite dev servers scanned for cloud credentials — CVE-2026-39364, CVSS 7.5 — Do: Upgrade Vite to 7.3.2 or 8.0.5 — https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/ 3. AI agents ran a credential campaign in six hours — Do: Shorten cloud key lifetimes and alert on scanning — https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html 4. LiteSpeed flaw takes a hosting account to root — no CVE assigned — Do: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 — https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html 5. Apple patches 261 flaws across every OS — Do: Update Mac security tools before macOS 27 — https://isc.sans.edu/diary/rss/33336 6. Homebrew 7.0.0 closes a sudo path in casks — Do: Install Homebrew 7.0.0 on developer Macs — https://www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/ 7. MeshCentral used as the backdoor at a broadband ISP — CVE-2024-21762 in the toolkit — Do: Hunt for RMM agents you never deployed — https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html 8. AWS TEAM grants access it was not asked for — CVE-2026-86830, CVSS 7.2 — Do: Upgrade TEAM to 1.5.1, forks included — https://aws.amazon.com/security/security-bulletins/rss/2026-112-aws/ 9. An unpatched VPN cost Japan 246,000 records — Do: Alert on bulk file reads by service accounts — https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html 10. Office update breaks copy and paste in Excel — Do: Warn the help desk about KB5002914 — https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/ 11. WordPress scans plugin updates before shipping — Do: Leave WordPress plugin auto-updates on — https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html 12. A $159 board defeats confidential computing — no CVE will be assigned — Do: Recheck what you claim confidential computing proves — https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html

    • Transcript
  • September 14 · 6 min

    Cyber Security News for September 14 2026 - Daily DefSec Brief

    1. GitLab path traversal at CVSS 10, now exploited — CVE-2026-85706 — Do: Upgrade GitLab, then grep for file.path — https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/ 2. ScreenConnect file-transfer flaw now has a patch — CVE-2026-84869 — Do: Upgrade ScreenConnect to 26.6.5 — https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin 3. Artifactory chain mints admins, drops a backdoor — CVE-2026-42018, CVE-2026-42016 — Do: Patch Artifactory, audit admin accounts — https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 4. Metasploit weaponizes five KEV flaws at once — CVE-2026-20079, CVE-2026-83549, CVE-2026-63077, CVE-2026-82078, CVE-2026-19295 — Do: Patch the five KEV flaws now weaponized — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen 5. Plesk restore race gives a customer root — CVE-2026-68488 — Do: Upgrade Plesk to 18.0.80.7 — https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation 6. Dell ObjectScale unauth RCE at CVSS 10 — CVE-2026-70416 — Do: Upgrade ObjectScale to 4.4.0.0 — https://securityonline.info/dell-objectscale-vulnerabilities-cve-2026-70416/ 7. Direct Send phishing lands as internal mail — Do: Set RejectDirectSend to true in M365 — https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/ 8. Malware hosted on AI vendors' own domains — Do: Filter AI share links as user content — https://www.huntress.com/blog/ai-attack-surface 9. Fake agency request passed every email check — Do: Verify agency data requests out of band — https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/ 10. 1.8 million APKs mined for hardcoded secrets — Do: Scan your shipped mobile apps for secrets — https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ 11. Stolen police login opened a state DMV database — Do: Inventory external accounts into your systems — https://therecord.media/florida-shiny-hunters-motor-vehicle 12. Kiro wrote the edit before you approved it — CVE-2026-89332 — Do: Upgrade Kiro to 0.8.135, rotate creds — https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/ 13. 76% deployed Copilot, 43% reviewed permissions — Do: Review M365 oversharing before Copilot — https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/ 14. IT staff clicked more than any other team — Do: Include IT in phishing simulations — https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/ 15. OpenAI agent swarm ran the RubyGems attack — Do: Rotate RubyGems API keys from May — https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/

    • Transcript
  • September 11 · 5 min

    Cyber Security News for September 11 2026 - Daily DefSec Brief

    1. Two MikroTik flaws exploited, deadline Sunday — CVE-2026-86060, CVE-2026-67277 — Do: Patch RouterOS, close SSH and btest — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. WatchGuard Firebox now in ransomware — CVE-2025-14733 — Do: Upgrade Fireware to 12.5.15 or later — https://www.scworld.com/news/cisa-watchguard-firebox-bug-exploited-in-ransomware-campaigns · NVD — https://nvd.nist.gov/vuln/detail/CVE-2025-14733 3. Two 9.8s in Check Point VPN certs — CVE-2026-85102, CVE-2026-85103 — Do: Apply Check Point's 9 September VPN fixes — https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html 4. AWS SSM agent leaks instance credentials — CVE-2026-89049 — Do: Upgrade SSM Agent to 3.3.4851.0 — https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/ 5. Backup driver writes below the OS — CVE-2026-12780 — Do: Block amwrtdrv.sys, confirm Secure Boot on — https://kb.cert.org/vuls/id/687587 · NVD — https://nvd.nist.gov/vuln/detail/CVE-2026-12780 6. AI closed the detection-evasion loop — Do: Weight behavioural detection over signatures — https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ 7. BYOD calls end at the Graph API — Do: Alert on new MFA device registrations — https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data 8. IDScan confirms the licence breach — Do: Ask vendors how long they keep the scan — https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ 9. Sogou input method drops a backdoor — CVE-2026-51990 — Do: Confirm Sogou is on an April 2026 build — https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html 10. Work profiles hide a banking trojan — Do: Test your app's checks inside a work profile — https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html 11. Android ransomware plus spyware — Do: Block sideloading, alert on Accessibility grants — https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/ 12. MCP tool descriptions act as instructions — Do: Review and pin your MCP tool descriptions — https://www.scworld.com/resource/when-english-becomes-exploit-code-the-hidden-risk-inside-mcp-servers 13. Root on the node forges workload identity — Do: Shorten SPIFFE credential lifetimes — https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ 14. Passkeys move between managers — Do: Revisit passkeys now migration works — https://www.helpnetsecurity.com/2026/09/10/google-android-password-manager-transfer/ 15. Invoice fraud with an AI paper trail — Do: Call back on every payment-detail change — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/

    • Transcript
  • September 10 · 5 min

    Cyber Security News for September 10 2026 - Daily DefSec Brief

    1. Cisco firewall manager exploited to root — CVE-2026-20079 (CVSS 10.0), CVE-2026-20316 — Do: Apply the Cisco Secure FMC hotfixes now — Cisco Talos — https://blog.talosintelligence.com/fmc-ongoing-exploitation/ 2. NetScaler auth bypass now actively exploited — CVE-2026-19490 (CVSS 9.3, NVD v4.0) — Do: Upgrade NetScaler to 14.1-73.32 or 13.1-63.21 — Rapid7 — https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/ 3. Four spy crews, one shared exploit kit — CVE-2026-85046, CVE-2026-85880 — Do: Confirm Chrome 153 and September Windows landed — The Record — https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups 4. FortiOS packet flaw added to CISA KEV — CVE-2025-25249 (CVSS 8.1) — Do: Upgrade FortiOS off the affected branches — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 5. Passkey social engineering ends in cloud takeover — Do: Alert on new auth methods added to accounts — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ 6. Shai-Hulud back past npm's scan — feishu-docx-mcp, bmc-i18n-extract-cli, blueai-cli, bmc-translate-utils — Do: Rotate npm tokens, install with --ignore-scripts — Aikido Security — https://www.aikido.dev/blog/shai-hulud-npm-resurfaces 7. Phishing page assembled inside the browser — Do: Alert on OAuth redirects leaving Microsoft — Help Net Security — https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/ 8. Stealer logs yield replayable AI tokens — Do: Rotate AI provider keys after any stealer hit — https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html 9. Fortinet portal leaks a token-forging secret — CVE-2026-84390 (CVSS 9.6), CVE-2026-84388 (CVSS 9.1) — Do: Patch FortiPAM and the browser extension together — SecurityWeek — https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/ 10. Android patches 180 flaws in one month — Do: Push the September Android patch level — https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/ 11. AI workflows run on the wrong identity — Do: Run AI workflows as the requester — https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data 12. Agent could turn off its own sandbox — CVE-2026-82533 (CVSS 9.6) — Do: Update DeepSeek Harness to 0.1.2-alpha.1 — https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html 13. Scanning and brute force on Proxmox — Do: Take Proxmox port 8006 off the internet —https://isc.sans.edu/diary/rss/33324 14. Vendor credentials opened an EHR API — Do: List vendors holding API credentials to you — The Record — https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach 15. Machine identities overtake phishing — Do: Inventory and expire non-human identities — https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/ 16. Contractor's admin account outlived him — Do: Match every admin account to a current person — The Register — https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361 17. EU gives you 24 hours to report from Friday — Do: Name who files your EU 24-hour report — Dark Reading — https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements 18. Phishing from the vendor's own address — Do: List who can send mail as your domain — BleepingComputer — https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/

    • Transcript
  • September 9 · 5 min

    Cyber Security News for September 9 2026 - Daily DefSec Brief

    1. Record 974-CVE Patch Tuesday, two zero-days live — CVE-2026-81963, CVE-2026-85880 (CVSS 7.8) — Do: Install September Windows updates now — SecurityWeek — https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/ 2. Chrome 153 patches its seventh zero-day of 2026 — CVE-2026-87491 — Do: Push Chrome 153.0.8010.36, force restart — SecurityWeek — https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/ 3. F5 BIG-IP rootkit hides its web shell in memory — CVE-2025-53521 (CVSS 9.8) — Do: Patch BIG-IP APM, then hunt memory — The Hacker News — https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html 4. Defender patch bypassed again, no fix yet — CVE-2026-69414 (the bypassed fix) — Do: No fix — watch SYSTEM-level file reads — Security Affairs — https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html 5. SAP kernel flaw scores 10.0, no auth needed — CVE-2026-44756 (CVSS 10.0) — Do: Apply September SAP security notes — SecurityWeek — https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/ 6. Phishing chain hides inside Google's own redirects — Do: Hunt unauthorised ScreenConnect installs — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign 7. Ivanti patches ten flaws, two unauth RCE at 9.8 — CVE-2026-12744, CVE-2026-12745, CVE-2026-18851, CVE-2026-83527 — Do: Patch EPMM to 12.10.0.0 or 12.9.0.2 — Ivanti — https://www.ivanti.com/blog/september-2026-security-update 8. ClearFake runs its loader straight off WebDAV — Do: Block outbound WebDAV at the proxy — Cisco Talos — https://blog.talosintelligence.com/clearfake-webdav-infection-chain/ 9. New N-central chain creates its own admin account — CVE-2026-86206, CVE-2026-86207 — Do: Apply N-central 2026.3 Hotfix 3 — Rapid7 — https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed 10. FreeIPA lets an anonymous client become admin — CVE-2026-76578, CVE-2026-13097, CVE-2026-76560, CVE-2026-79678 — Do: Update FreeIPA to 4.13.4 — The Hacker News — https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html 11. Extortion crews now steal the model itself — Do: Inventory model weights as crown jewels — The Register — https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640 12. VMware Workstation and Fusion guest escapes — CVE-2026-59346, CVE-2026-59347 — Do: Update VMware Workstation and Fusion — SC World — https://www.scworld.com/brief/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities 13. Planted prompt sent ChatGPT's Gmail data elsewhere — Do: Cut ChatGPT connector scopes back — Check Point Research — https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ 14. Android RAT worms through open ADB ports — Do: Disable ADB over TCP on managed Android — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/ 15. UEFI shell in flash defeats Secure Boot — CVE-2026-20293, VU#718077 — Do: Set BIOS passwords, patch UCS firmware — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW 16. Military kills ad IDs — Do: Disable advertising IDs via MDM — Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones 17. BleachBit's shredder skipped parts of the file — Do: Update BleachBit, wipe free space — Help Net Security — https://www.helpnetsecurity.com/2026/09/09/bleachbit-6-0-4-released/

    • Transcript
  • September 8 · 5 min

    Cyber Security News for September 8 2026 - Daily DefSec Brief

    1. A maximum-severity Magento zero-day was exploited for three days before Adobe shipped a fix — CVE-2026-75650 — Do: Apply the APSB26-146 composer patch, then hunt — Adobe — https://helpx.adobe.com/security/products/magento/apsb26-146.html 2. MikroTik routers taken over through an SSH key check that ignores half the key — CVE-2026-67276, CVE-2026-67277 — Do: Update RouterOS, then audit SSH users and keys — CERT Polska — https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 3. N-able's fourth N-central hotfix in five weeks, and its own notices disagree on exploitation — CVE-2026-86218 — Do: Install N-central Hotfix 4, build 2026.3.1.14 — N-able — https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ 4. A phishing service beat MFA at 258 organisations and took 5,000 Microsoft 365 logins — Do: Move admins to phishing-resistant sign-in — BleepingComputer — https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ 5. ConnectWise has no patch for a ScreenConnect file-transfer flaw, and rogue clients are spreading malware — Do: Deselect TransferFiles on every ScreenConnect role — ConnectWise — https://www.connectwise.com/company/trust/advisories 6. Attackers are phoning executives, posing as the help desk, and walking off with the session — Do: Give the help desk a caller-verification step — The Hacker News — https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html 7. One researcher dropped zero-days for Avast, CrowdStrike and Nvidia inside a week — Do: Disable Falcon's Office macro removal for now — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/ 8. A working exploit chain for Telerik is now public, two months after the patch — CVE-2019-18935, CVE-2026-13181 — Do: Upgrade Telerik UI to 2026.2.708 or later — The Hacker News — https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html 9. A fake bookmarks extension turns Chrome and Edge into a command channel — Do: Hunt for extensions loaded outside the Web Store — The Hacker News — https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html 10. Nine years of passenger records sat in an Elasticsearch cluster anyone could reach — Do: Find search clusters answering from the internet — BleepingComputer — https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/ 11. Berlin refused a €2m ransom and Rhysida published nearly six terabytes — Do: Write down who refuses a ransom — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/ 12. An unpatched Metabase handed over a million students' details — Do: Patch and gate your self-hosted BI tools — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ 13. The NCSC says most staff are already using AI you have not approved — Do: Publish an approved AI tool people will use — NCSC — https://www.ncsc.gov.uk/blog-post/shadow-ai 14. Ransomware negotiation has turned into a business process with its own staff — Do: Work out your own ransom number first — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/ 15. A North Korean backdoor is compiled into the victim's own load balancer — Do: Verify HAProxy and daemons against their packages — Security Affairs — https://securityaffairs.com/198656/apt/north-korea-linked-hackers-hide-a-backdoor-inside-haproxy.html 16. The SEO agency poisoning your search results has been at it since 2015 — — The Hacker News — https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html

    • Transcript
  • September 4 · 5 min

    Cyber Security News for September 4 2026 - Daily DefSec Brief

    1. Chrome patches a V8 zero-day that attackers are already using — CVE-2026-85046 — The Hacker News — https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html 2. Coder's package registry served Terraform modules that steal credentials (malicious modules served 07:35–21:45 UTC, Mon 31 Aug, advisory GHSA-vx42-ghc9-gw65) — BleepingComputer — https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/ 3. HPE patches unauthenticated code execution in ArubaOS-CX switches (fixed in 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181) — CVE-2026-73749 — BleepingComputer — https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/ 4. Casdoor lets one tenant's admin act on every other tenant, with no patch available (3.115.0 and earlier) — CVE-2026-15630 — CERT/CC — https://kb.cert.org/vuls/id/889462 5. Cisco ships seven IOS XR flaws as one hardening release (no fixed release, upgrade to a release with SMUs, then apply them) — CVE-2026-20274, CVE-2026-20279 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 6. Phishing hides lure words from email filters with invisible Unicode (strip U+E0000–U+E007F before applying signatures) — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/ 7. AWS patches command injection in the CodeCatalyst blueprints framework (@amazon-codecatalyst/blueprints.blueprint before 0.3.156) — CVE-2026-85012 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/ 8. A China-linked espionage crew is running its intrusions through AI agents — Security Affairs — https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html 9. BraZetsu packages a compromised Windows host into something an access broker can sell — The Hacker News — https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html 10. Toy Ghouls runs its new backdoor's command channel over HiveMQ and Element — Securelist — https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ 11. Fourteen fake macOS installers deliver the OtterCookie remote access trojan — Jamf Threat Labs — https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/ 12. A phishing kit produced 700 new pages in the month after its servers were seized — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/ 13. The 153 million driver's licence scans have a suspected source — Security Affairs — https://securityaffairs.com/198388/security/dark-web-service-nexus-sells-153m-drivers-licenses.html 14. Thomson Reuters breach exposed sealed court records across eleven states — The Hacker News — https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html 15. A fake acquisition, a forged NDA, and instructions not to tell your colleagues — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams 16. An AI found 23,000 vulnerabilities and nobody has looked at 21,000 of them — Help Net Security — https://www.helpnetsecurity.com/2026/09/04/echo-claude-mythos-vulnerability-findings/

    • Transcript
  • September 3 · 4 min

    Cyber Security News for September 3 2026 - Daily DefSec Brief

    1. Kestra workflow engine lets anyone run commands with no credentials at all — CVE-2026-49869 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. GitSpawn lets a repository's own config run commands through your AI coding agent — CVE-2026-19592, CVE-2026-55607, CVE-2026-71963, CVE-2026-72718 — Manifold Security — https://www.manifold.security/blog/ai-coding-agents-git-hijack 3. Cisco Nexus 9000 switches take unauthenticated code execution as root — CVE-2026-20212 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-f2SiMFxl 4. LiteLLM accepts any bearer token as a valid MCP session — CVE-2026-59822 — BerriAI advisory — https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q 5. BadHost defeats authentication anywhere Starlette rebuilds the URL — CVE-2026-48710 — CCB Belgium — https://ccb.belgium.be/advisories/warning-vulnerability-starlette-framework-and-related-frameworks-fastapi-exposes 6. Exploit published for a Cleo Harmony authentication bypass — CVE-2026-84115 — SecurityWeek — https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/ 7. Dropbox accounts opened through a flaw in Lenovo's email verification — BleepingComputer — https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/ 8. Fake IT support on Teams now ends in a Node.js implant and hands-on-keyboard access — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/ 9. The Gentlemen ransomware turns off EDR and backups before encrypting — Cyber Security News — https://cybersecuritynews.com/the-gentlemen-ransomware/ 10. Researcher publishes a CrowdStrike Falcon privilege-escalation exploit — Security Affairs — https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html 11. Windows starts switching memory integrity on by itself in October — Help Net Security — https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/ 12. One AI model completed a full cyber kill chain on its own in Booz Allen's tests — The Register — https://www.theregister.com/security/2026/09/02/claude-mythos-only-model-to-complete-full-cyber-kill-chain-experts-say/5294071 13. Attackers are self-hosting a chat interface on the infrastructure they compromise — Unit 42 — https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ 14. Chrome ships 26 fixes including two critical use-after-free bugs — CVE-2026-84352, CVE-2026-84353 — SecurityWeek — https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/ 15. Teams and Outlook fail to launch on ARM Windows after the August updates — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/ 16. A hundred and fifty-three million driver's licence scans are for sale — Ars Technica — https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/

    • Transcript
  • September 2 · 5 min

    Cyber Security News for September 2 2026 - Daily DefSec Brief

    1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ 2. JFrog Artifactory authentication bypass exploited four days after the patch — CVE-2026-82329 — SC World — https://www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release 3. Langflow remote code execution used to harvest OpenAI and AWS keys — CVE-2026-0768 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/ 4. Twenty-two thousand Exchange servers still unpatched against a mailbox takeover flaw — CVE-2026-62911 — BleepingComputer — https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 5. AI agents ran a full ransomware intrusion in under ten hours — Unit 42 — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ 6. FBI warns of consent phishing that takes an account without a password — CyberScoop — https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/ 7. Sangoma Switchvox SQL injection is being exploited seven weeks after the fix — CVE-2026-9586 — The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html 8. GeoNetwork chain gives unauthenticated code execution on government geoportals — CVE-2026-63219 — The Hacker News — https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html 9. Counterfeit software download sites are installing malware that turns Defender off — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ 10. Phishing crew abuses a real endpoint-management platform to install ScreenConnect — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/ 11. Airport breach traced to admin keys sitting in the websites' own JavaScript — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/ 12. Stolen API key burned 600,000 dollars of model credits before anyone noticed — The Register — https://www.theregister.com/security/2026/09/01/attacker_stole_a_metr_api_key_used_600k_worth_of_credits_and_no_one_noticed_for_weeks/5293730 13. Hugging Face Transformers writes remote code to disk before asking permission — CVE-2026-80047 — CERT/CC — https://kb.cert.org/vuls/id/456290 14. SageMaker SDK leaves its signing key in cleartext where any account role can read it — CVE-2026-83551 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/ 15. Thirteen poisoned Composer packages on Packagist attack visitors of the sites that install them — CVE-2025-31277, CVE-2025-43398, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529 — The Hacker News — https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html 16. Attackers are installing Apache modules that quietly proxy visitors to phishing pages — Check Point Research — https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/

    • Transcript
  • September 1 · 4 min

    Cyber Security News for September 1 2026 - Daily DefSec Brief

    1. OpenSearch SQL plugin deserialization flaw gives a read-only user code execution — CVE-2026-83497 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/ 2. BGP hijack pushed a malicious Virtualizor update onto hypervisor management servers — Virtualizor — https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ 3. McKesson breach ran from vishing calls through Okta into Salesforce and Snowflake — SC World — https://www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records 4. Password-spraying campaign hit AWS root accounts at more than 150 organizations — Datadog Security Labs — https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/ 5. Scanners are forging AI-crawler user agents to hunt for exposed credentials — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/ 6. A honeypot posing as a free LLM endpoint caught a real coding agent handing over its tools — SANS ISC — https://isc.sans.edu/diary/rss/33298 7. Mirage Kitten hides two new cross-platform RATs in trojanized coding-challenge archives — Securelist — https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/ 8. Researcher drops a working privilege-escalation exploit for Kaspersky Endpoint Security — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/ 9. Residential proxy networks rent out home connections with clean IP reputations — Ars Technica — https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/ 10. BREEZE COMET manipulates Brazilian banking software to move fraudulent transfers — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/ 11. Guildma delivery is geofenced to Brazil and hides its payload in an alternate data stream — SANS ISC — https://isc.sans.edu/diary/rss/33300 12. Boston Scientific outage leaves newly implanted heart devices without remote monitoring — The Register — https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537 13. OpenClaw 2.0 makes the agent harness easier to install and leaves security to the user — The Register — https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492 14. CrowdSec 1.8.0 ships two denial-of-service fixes alongside new bot detection — Help Net Security — https://www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/

    • Transcript
  • August 31 · 5 min

    Cyber Security News for August 31 2026 - Daily DefSec Brief

    1. PaperCut ships a second emergency patch after attackers chain two zero-days — CVE-2026-82078, CVE-2026-81578 — SecurityWeek — https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/ 2. Ruby on Rails file-read flaw is being exploited for remote code execution — CVE-2026-66066 — SecurityWeek — https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/ 3. Self-spreading worm planted in an npm package with 150,000 weekly downloads — Cyber Security News — https://cybersecuritynews.com/popular-npm-package/ 4. China-linked Fire Ant moves into Cisco routers and TACACS servers to blind logging — The Hacker News — https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html 5. AWS Systems Manager agent path traversal lets a limited user write files as root — CVE-2026-81849 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-091-aws/ 6. TerminalFix pastes a fake CAPTCHA command into Windows Terminal and opens a reverse tunnel — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ 7. Fake IT help desk calls over external Teams accounts end in NTLM relay to the domain controller — Unit 42 — https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ 8. Infostealers are lifting live Claude sessions and walking past two-factor — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/ 9. Nineteen Chrome and Edge extensions were backdoored through automatic updates — The Hacker News — https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html 10. Russian operators embed a nuclear-weapons prompt in malware to make AI analysis tools refuse — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/ 11. A file that passes as an MP4 carries 6.5 MB of encrypted NetSupport RAT — Censys — https://censys.com/blog/fake-mp4-file-carries-malicious-payload/ 12. Voicemail-themed SVG attachments smuggled JavaScript past email filters at 5,527 organizations — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/ 13. ValleyRAT ships as signed adware so users add it to their own exclusion lists — Securelist — https://securelist.com/valleyrat-backdoor-adware/121175/ 14. Metasploit ships modules for Forgejo file read and a batch of other recent flaws — CVE-2026-59774, CVE-2026-3576 — Rapid7 — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners 15. Composer flaw lets a malicious package change permissions on files it does not own — CVE-2026-59944 — Cyber Security News — https://cybersecuritynews.com/composer-flaw-expose-ssh-keys/ 16. UK NCSC warns of rising OT targeting through internet-exposed systems and edge devices — Industrial Cyber — https://industrialcyber.co/control-device-security/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices/ 17. CISA red team walked one network to domain admin and struggled badly in the other — Cybersecurity Dive — https://www.cybersecuritydive.com/news/cisa-red-team-exercises-lessons-cloud-soc/828733/ 18. Microsoft tells everyone to ignore Defender alerts saying antivirus is off — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/

    • Transcript
  • August 28 · 5 min

    Cyber Security News for August 28 2026 - Daily DefSec Brief

    1. ownCloud unauthenticated file access flaw added to CISA KEV — CVE-2023-49105 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. ServiceNow patches three CVSS 10.0 flaws in its AI Platform — CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 — The Hacker News — https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html 3. cPanel flaw lets a hosting customer take root on the whole server — CVE-2026-65643 — The Hacker News — https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html 4. Next.js patches two critical unauthenticated remote code execution flaws — CVE-2026-75604 — The Hacker News — https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html 5. Linux kernel IPv6 privilege escalation added to CISA KEV — CVE-2026-53362 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 6. JFrog Artifactory path-traversal flaw added to CISA KEV — CVE-2026-66384 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 7. APT28-linked HOOKEDGE backdoor hits European government and diplomatic targets — The Hacker News — https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.html 8. Ghost SPN technique makes Kerberoasting far harder to spot — Cyber Security News — https://cybersecuritynews.com/active-directory-spn-misconfigurations/ 9. ASE2000 utility test set has XXE and certificate-validation flaws — CVE-2018-1285, CVE-2026-18717 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04 10. All-Line Fuel-Boss systems carry two remote code execution flaws — CVE-2018-19518, CVE-2019-11043 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02 11. Ebyte NA111-M gateway ships with 13 flaws and no authentication — CVE-2026-69658, CVE-2026-71187, CVE-2026-73125 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-05 12. Rockwell OTTO Fleet Manager stores passwords with a weak bcrypt work factor — CVE-2026-75112 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03 13. Exposed open directory reveals Moobot still running after 2024 takedown — Censys — https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/ 14. Executive Social Security numbers sell on dark web markets — Rapid7 — https://www.rapid7.com/blog/post/tr-identity-as-a-service-dark-web-marketplaces-executive-ssn

    • Transcript
  • August 27 · 5 min

    Cyber Security News for August 27 2026 - Daily DefSec Brief

    1. PaperCut NG/MF under active exploitation, no patch yet — Help Net Security — https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/ 2. GPUThor Rowhammer defeats ECC on NVIDIA workstation GPUs for root — The Hacker News — https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html 3. Veeam ONE coerces SMB auth from service account — CVE-2026-65641 — Cyber Security News — https://cybersecuritynews.com/veeam-backup-replication-flaw-exposes/ 4. Three 10.0 flaws patched across Ubiquiti UniFi — CVE-2026-77537, CVE-2026-77550, CVE-2026-77554 — CyberScoop — https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/ 5. Attackers targeting exposed AI gateways to steal keys and mine crypto — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/ 6. Spark RAT campaign abuses OPSWAT driver to kill security tools — CVE-2026-36425 — The Hacker News — https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html 7. AI-agent llms.txt files push unowned code into corporate networks — Ars Technica — https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/ 8. Claude Code Opus 5 Auto Mode falls to website-summary prompt injection — Embrace The Red — https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/ 9. Chinese-speaking operator loots Philippine nuclear and naval data via old flaws — Cyber Security News — https://cybersecuritynews.com/hackers-exploit-owncloud/ 10. Aurora ransomware affiliate used an AI coding assistant across 20+ intrusions — Cyber Security News — https://cybersecuritynews.com/ransomware-hacker-uses-ai/ 11. GoCaracal malware fetches C2 from an Ethereum smart contract — The Hacker News — https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html 12. AWS details how stolen cloud credentials escalate into full breaches — Cyber Security News — https://cybersecuritynews.com/aws-shows-how-hackers/ 13. Nimbus Manticore adds TWOSTROKE-like backdoor and SSH tunneler — SC World — https://www.scworld.com/brief/nimbus-manticore-expands-infrastructure-and-malware-arsenal 14. Ajax.NET Professional deserialization flaw added to CISA KEV — CVE-2021-23758 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 15. Microsoft SQL Server RCE added to CISA KEV — CVE-2019-1068 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    • Transcript
  • August 26 · 4 min

    Cyber Security News for August 26 2026 - Daily DefSec Brief

    1. CISA adds actively exploited Gitea code-injection flaw to KEV — CVE-2026-60004 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. SonicWall NetExtender Linux client path traversal allows root file write — CVE-2026-66152 — Cyber Security News — https://cybersecuritynews.com/sonicwall-netextender-vulnerabilities/ 3. Chrome 152 patches over 300 flaws, most found internally by AI — CVE-2026-79282 (+300 more) — SecurityWeek — https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/ 4. NVIDIA NemoClaw flaw lets a malicious webpage poison a local AI model — CVE-2026-65105 — Cyber Security News — https://cybersecuritynews.com/nvidia-nemoclaw-flaw/ 5. Siemens SIMATIC IoT2050 Advanced unauthenticated RCE via Node-RED — CVE-2026-58115 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-03 6. Mirage2FA phishing kit bypasses MFA to hijack Microsoft 365 sessions — The Hacker News — https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html 7. Malicious npm packages abuse trusted mirrors to host ClickFix phishing — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/ 8. Iran-linked actors hide Dindoor backdoor behind the Deno runtime — Cyber Security News — https://cybersecuritynews.com/iran-linked-hackers-abuse-developer-tool/ 9. SLEEPWALKER backdoor waits for a magic packet, then runs its own bytecode — The Hacker News — https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html 10. 28,000 exposed .git repositories leak credentials and financial records — Cyber Security News — https://cybersecuritynews.com/28000-exposed-git-repositories/ 11. RMM tools abused in 46-country phishing campaign for remote access — Cyber Security News — https://cybersecuritynews.com/hackers-abuse-legitimate-rmm-tools-3/ 12. Marimo notebook flaw runs MCP commands before cells execute — CVE-2026-75149, CVE-2026-39987, CVE-2026-67618 — The Hacker News — https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html 13. AWS Strands Agents python_repl consent bypass allows RCE — CVE-2026-78379 — AWS — https://aws.amazon.com/security/security-bulletins/rss/2026-089-aws/ 14. Fake Indeed interview apps push Android spyware to job seekers — Malwarebytes Labs — https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware

    • Transcript
Showing 1–20 of 51 episodes