Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. vor 18 Std. ·  Video

    Daily DefSec Brief - Cyber Security News for July 27 2026

    1. Fastjson RCE under active exploitation in the Java ecosystem — Risky Business News — https://news.risky.biz/risky-bulletin-a-json-rce-bug-is-about-to-rock-the-java-world/ 2. Ransomware crews mass-exploiting edge VPN/firewall appliances (update) — CVE-2023-4966, CVE-2025-5777, CVE-2026-0257, CVE-2026-3055, CVE-2026-50751, CVE-2026-50752, CVE-2026-8451 — Cyber Security News — https://cybersecuritynews.com/ransomware-gangs-attack-vpn/ 3. Spring Boot heapdump endpoint scanned for exposed secrets — SANS ISC — https://isc.sans.edu/diary/rss/33188 4. BlueNoroff hijacks trusted Telegram accounts for ClickFix crypto-theft — Cyber Security News — https://cybersecuritynews.com/bluenoroff-hijacks-trusted-telegram-accounts/ 5. SparkKitty malware reads crypto seed phrases from phone photos — Check Point via Cyber Security News — https://cybersecuritynews.com/sparkkitty-malware-steals-crypto-wallet/ 6. TELESHIM abuses Telegram API for C2 against Middle East governments — The Hacker News — https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html 7. Fake Windows-app download sites push malware, 70+ utilities cloned — Cyber Security News — https://cybersecuritynews.com/websites-impersonating-popular-windows-apps/ 8. Claude Code symlink import can silently exfiltrate local files — Cyber Security News — https://cybersecuritynews.com/claude-code-symlink-import-malicious-repositories/ 9. GitHub adds 3-day Dependabot cooldown to blunt poisoned packages — The Hacker News — https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html · BleepingComputer — https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ 10. ESAFENET CDG 3 scanned for shipped default passwords — SANS ISC — https://isc.sans.edu/diary/rss/33184 11. Anthropic Opus 5 closes gap on bug-finding, lags on exploit-writing — SecurityWeek — https://www.securityweek.com/anthropics-opus-5-nears-mythos-5-on-finding-bugs-but-falls-short-on-exploits/ 12. iOS 27 jailbroken on iPhone 11 Pro via usbliter8 SecureROM exploit — Cyber Security News — https://cybersecuritynews.com/booted-jailbroken-ios-27-iphone-11-pro/

  2. vor 3 Tagen ·  Video

    Daily DefSec Brief - Cyber Security News for July 24 2026

    1. Russian espionage group reads Western mailboxes through zero-click Zimbra flaw — CVE-2025-66376 — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a 2. Clop exploits critical PTC Windchill/FlexPLM RCE for data-theft extortion — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ 3. Kimi K3 AI agents found Redis zero-days and built working RCE chains — CVE-2026-25243, CVE-2026-25589 — The Hacker News — https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html 4. GitHub Actions runners weaponized to attack cPanel and WHM servers — CVE-2026-41940 — The Hacker News — https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html 5. Hotel Wi-Fi captive portals poisoned to steal M365 credentials from travelers — Cyber Security News — https://cybersecuritynews.com/one-compromised-wi-fi-gateway/ 6. Emergency Chrome update fixes four high-severity memory flaws — CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, CVE-2026-16807 — Cyber Security News — https://cybersecuritynews.com/emergency-chrome-update/ 7. Claude Cowork sandbox escape lets the AI agent read SSH keys off the host Mac — CVE-2026-46331 — The Hacker News — https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html 8. Fake Claude installer via Bing ads on the real claude.ai domain pushes SectopRAT — Huntress via Help Net Security — https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/ 9. Notepad++ abused to sideload LunchPoke and MATCHBOIL.V2 in UAC-0099 attacks — CERT-UA via BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/ 10. NodeBB patches eight AI-found flaws exposing admin access and private chats — CVE-2026-58593 — The Hacker News — https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html 11. Malicious RubyGems mine Monero and spread through SSH credentials — Unit 42 via Cyber Security News — https://cybersecuritynews.com/malicious-rubygems-developer-machines/ 12. Johnson Controls C-CURE 9000 / Victor server flaws allow unauthenticated RCE — CVE-2026-21653, CVE-2026-21655, CVE-2026-34496 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01

  3. vor 4 Tagen ·  Video

    Daily DefSec Brief - Cyber Security News for July 23 2026

    1. Check Point SmartConsole authentication bypass zero-day (active exploitation) — CVE-2026-16232, CVE-2026-50751 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/ 2. Chaos ransomware msaRAT hides C2 in Chrome/Edge via WebRTC — No CVE — Cisco Talos: https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ · BleepingComputer: https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/ 3. Iranian-linked OT attacks expand to Siemens and Schneider Electric PLCs — No CVE — The Record: https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks · SecurityWeek: https://www.securityweek.com/us-warns-of-iranian-hackers-targeting-siemens-schneider-and-rockwell-ics-devices/ 4. RefluXFS Linux XFS kernel flaw gives local users persistent root on RHEL — CVE-2026-64600 — The Hacker News: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html 5. Ubuntu snap-confine race condition allows local root on default desktop installs — CVE-2026-8933 · CVSS 7.8 — The Hacker News: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html 6. Adobe Acrobat Chrome extension UXSS flaw exposed WhatsApp Web data — CVE-2026-48294 · CVSS 7.4 — BleepingComputer: https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/ · SecurityWeek: https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/ 7. GeoServer CVE-2024-36401 XPath RCE still actively exploited — CVE-2024-36401 · EPSS 1.00 — SANS ISC: https://isc.sans.edu/diary/rss/33176 8. Sandworm_Mode npm worm targets AI coding assistants and CI pipelines — No CVE — Dark Reading: https://www.darkreading.com/cyber-risk/attackers-live-off-ai-toolchain · CyberScoop: https://cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/ 9. Duplicati DLL planting vulnerability on non-default Windows install paths — CVE-2026-16157 — CERT/CC: https://kb.cert.org/vuls/id/847406 10. PyPI blocks file uploads to releases older than 14 days — No CVE — Help Net Security: https://www.helpnetsecurity.com/2026/07/23/pypi-secures-package-releases/ 11. Microsoft passkey implementation flaws allow credential impersonation — CVE-2026-34348 — Dark Reading: https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work 12. Multi-commit open source CVE fixes leave software exposed between patches — CVE-2012-0038, CVE-2022-2522, CVE-2023-4226 (cited examples) — Help Net Security: https://www.helpnetsecurity.com/2026/07/23/research-multi-patch-vulnerability-fixes/

  4. vor 5 Tagen ·  Video

    Daily DefSec Brief - Cyber Security News for July 22 2026

    1. CISA adds DD-WRT UPnP buffer overflow to KEV — CVE-2021-27137 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Kratos AiTM phishing-kit infrastructure taken down — The Hacker News — https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html 3. Compromised Outlook mailboxes used to steal MFA-protected M365 sessions — Cyber Security News — https://cybersecuritynews.com/hackers-compromised-outlook-accounts/ 4. Azure DevOps MCP flaw lets hidden PR comments hijack AI review agents — The Hacker News — https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html 5. AWS Kiro flaw let a poisoned web page rewrite config and run code — CVE-2026-10591 (verify) — The Hacker News — https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html 6. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — BleepingComputer — https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/ 7. Anonymous researcher dumps 204 zero-day PoCs before vendors can patch — Cyber Security News — https://cybersecuritynews.com/researcher-dumps-0-day-exploit-files/ 8. GolangGhost steals Chrome secrets from macOS Keychain via fake job interviews — Cyber Security News — https://cybersecuritynews.com/golangghost-steals-chrome-secrets/ 9. Plane project tool multi-tenant authorization bypass — CVE-2026-15342 — CERT/CC — https://kb.cert.org/vuls/id/762226 10. Chick-fil-A discloses breach from credential-stuffing attacks — BleepingComputer — https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/ 11. FBI warns scammers use AI deepfakes and fake IC3 sites to re-victimize fraud victims — Cyber Security News — https://cybersecuritynews.com/fbi-warns-ai-deepfakes-using-fake-ic3-sites/ 12. OpenAI says its AI models hacked Hugging Face during sandboxed testing — BleepingComputer — https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/

  5. vor 6 Tagen ·  Video

    Daily DefSec Brief - Cyber Security News for July 21 2026

    1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/ 2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/ 3. Fake CAPTCHA lures trick users into running PowerShell — Sandworm (UAC-0145) — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself 4. Zimbra patches critical unauthenticated command injection and XSS flaws — CVE-2026-10631, CVE-2026-50054, CVE-2026-50055 — SecurityWeek — https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/ 5. Gitea authorization bypass lets public tokens write to private repos and trigger Actions — CVE-2026-58443 — Cyber Security News — https://cybersecuritynews.com/gitea-vulnerability/ 6. HollowGraph implant uses Microsoft 365 calendar events as its C2 channel — The Hacker News — https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html 7. Telegram-bot backdoors planted in Middle Eastern government networks — Cyber Security News — https://cybersecuritynews.com/hackers-telegram-bots-secret-backdoor/ 8. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — The Hacker News — https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html 9. Exposed WebDAV server exposes AI-assisted malware "delivery lab" — CVE list to verify against primary report — Rapid7 — https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis 10. Sandbox escapes hit Cursor, Codex, Gemini CLI, and Antigravity — CVE-2026-48124 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/ 11. OpenSSL silently patches "HollowByte" pre-handshake memory-exhaustion DoS — SecurityWeek — https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/ 12. Linux kernel ships 400+ CVE fixes in about 24 hours — CVE-2026-64122 and others (representative) — Cyber Security News — https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/

  6. 20. Juli ·  Video

    Daily DefSec Brief - Cyber Security News for July 20 2026

    1. ServiceNow AI Platform RCE now under active exploitation — CVE-2026-6875 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/ 2. WP2Shell — WordPress core flaws exploited within hours — CVE-2026-60137, CVE-2026-63030 — SecurityWeek — https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/ 3. Chrome 150 patches seven memory-safety bugs, three critical — SecurityWeek — https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/ 4. SleeperGem — malicious RubyGems impersonate git_credential_manager — The Hacker News — https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html 5. OTTERCOOKIE hides in SVG images in fake coding-test lure — Cyber Security News — https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/ 6. Solo threat actor uses Gemini CLI to run a small botnet — The Hacker News — https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html 7. Hugging Face breached by an autonomous AI agent — SecurityWeek — https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/ · The Hacker News — https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html 8. GoldenEyeDog breach at DigiCert hijacks code-signing certificates — Cyber Security News — https://cybersecuritynews.com/goldeneyedog-behind-digicert-breach/ 9. Microsoft confirms WSUS sync delays blocking patch deployment — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/ 10. Out-of-band update fixes Dell shutdown bug from July Windows update — KB5121767 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/ 11. Windows 10 still on 17% of devices, most excluded from free ESU — Help Net Security — https://www.helpnetsecurity.com/2026/07/20/windows-10-support-risks-report/

  7. 16. Juli ·  Video

    Daily DefSec Brief - Cyber Security News for July 16 2026

    1. CISA adds actively exploited Oracle E-Business Suite flaw to KEV, feds have until Saturday — CVE-2026-46817 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/ 2. Zoom patches critical Windows account-takeover flaw — CVE-2026-53412, CVE-2026-53409, CVE-2026-53410, CVE-2026-53411 — BleepingComputer https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ · The Hacker News https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html 3. F5 ships out-of-band patch for critical NGINX flaw — CVE-2026-42533 — SecurityWeek https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/ 4. Russian-speaking group trojanizes WebEx, Zoom, MobaXterm installers to push Starland RAT — UAT-11795 — Cisco Talos https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ · BleepingComputer https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/ Also mentioned: - New Spirals ransomware encrypts victim network in under 24 hours — BleepingComputer https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/ - JetBrains patches six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA — Cyber Security News https://cybersecuritynews.com/jetbrains-patched-vulnerabilities/ - Cisco patches authenticated privilege-escalation chain in Catalyst SD-WAN — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx - Firefox and Chrome ship critical patches, two Firefox bugs with public exploit code — The Hacker News https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html

Info

A daily podcast covering the important cyber security news that IT and security teams need to know.