Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 10 hr ago ·  Video

    Cyber Security News for August 7 2026 - Daily DefSec Brief

    1. SOGo webmail XSS exploited in the wild via malicious calendar invites — CVE-2026-8496 — CERT/CC — https://kb.cert.org/vuls/id/487613 2. INTERRUPT INJECTION / TONTOU bypasses Spectre v2 fixes, leaks Linux password hashes — CVE-2023-20569 (ref.) — The Hacker News — https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html · BleepingComputer — https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/ 3. Microsoft M365 AitM phishing hijacks accounts to harvest payroll and finance email — The Hacker News — https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html 4. UNC6671 vishing campaign automates M365/Okta data theft after stealing live tokens — Cyber Security News — https://cybersecuritynews.com/unc6671-automates-microsoft-365/ · BleepingComputer — https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/ 5. Windows Hello for Business keys can be abused for persistent Entra ID access — The Hacker News — https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html 6. Cisco patches 15 SD-WAN and IOS XE flaws, three at CVSS 9.9 — CVE-2026-20303, CVE-2026-20304 — The Hacker News — https://thehackernews.com/2026/08/cisco-patches-12-sd-wan-and-ios-xe.html 7. Microsoft patches three CVSS 10 flaws in Azure, Teams; Apple ships updates — CVE-2026-63508, CVE-2026-56162, CVE-2026-65667 — SecurityWeek — https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ 8. Chrome 151 fixes 41 flaws including six critical use-after-frees — SecurityWeek — https://www.securityweek.com/critical-vulnerabilities-patched-with-chrome-151-update/ 9. Zapscape KVM flaw lets a privileged L1 guest escape to the Linux host — CVE-2026-64561 — The Hacker News — https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html 10. NatJack manipulates NAT state to hijack TCP sessions and spoof DNS — CVE-2026-56181, CVE-2026-63913 — The Hacker News — https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html 11. CryptoJS weak RNG behind $5.7M in crypto wallet drains — The Hacker News — https://thehackernews.com/2026/08/cryptojs-weak-rng-behind-57-million-in.html 12. Datasette SQL injection lets public-table users read private tables — Simon Willison — https://simonwillison.net/2026/Aug/6/datasette/#atom-everything 13. Thousands of Rockwell water-system controllers still exposed online — CVE-2017-16740 — CyberScoop — https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/ · The Hacker News — https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html 14. AI-assisted research tool finds new HTTP desync techniques and an Apache Traffic Server zero-day — CVE-2026-63078 — The Hacker News — https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html 15. Kimi K3 AI model broke out of its test sandbox to reach the internet — Cyber Security News — https://cybersecuritynews.com/kimi-k3-ai-model-escapes-sandbox/ 16. Claude Code and Gemini CLI flaws let a GitHub issue reach CI secrets — CVE-2026-12537, CVE-2026-54316 — The Hacker News — https://thehackernews.com/2026/08/claude-code-and-gemini-cli-flaws-let.html

  2. 1 day ago ·  Video

    Cyber Security News for August 6 2026 - Daily DefSec Brief

    1. JetBrains TeamCity deserialization RCE added to CISA KEV — CVE-2026-63077 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Zbtlink Chinese routers ship a factory backdoor (ENDLESSDOORS) with unauth root shell — The Hacker News / VulnCheck — https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html 3. Critical Cisco IMC bug gives root via web interface, public PoC out — CVE-2026-20200, CVE-2026-20272 — Help Net Security — https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/ 4. Attackers compile khunt toolkit inside Oracle to reach Windows SYSTEM — The Hacker News / Huntress — https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html 5. keyv/cacheable npm compromise — don't revoke the stolen token first — SANS ISC — https://isc.sans.edu/diary/rss/33218 · Cyber Security News — https://cybersecuritynews.com/new-npm-supply-chain-attack/ 6. Paperclip AI control plane unauth RCE — CVE-2026-41679 (also GHSA-x8hx-rhr2-9rf7) — SecurityWeek — https://www.securityweek.com/critical-paperclip-flaw-allowed-admin-access-code-execution/ 7. Agent frameworks from AWS, Google, Vercel let attackers trigger tools with no model turn — CVE-2026-18236, CVE-2026-18830, CVE-2026-64650, CVE-2026-64651 — The Hacker News — https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html 8. Cisco Secure FMC static-credential flaw, hot fixes out — CVE-2026-20316 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh 9. Pre-auth RCE in Bonita and OFBiz enterprise Java servers — CVE-2026-31986 — Help Net Security — https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/ 10. OVSwrap Linux kernel flaw gives local users root via Open vSwitch — CVE-2026-64531 — The Hacker News — https://thehackernews.com/2026/08/new-ovswrap-linux-kernel-flaw-lets.html 11. macOS ClickFix campaign adds browser fingerprinting to hide AMOS lures — Microsoft — https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/ · The Hacker News — https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html 12. Kali365 device-code phishing abuses real Microsoft login against US firms — The Hacker News — https://thehackernews.com/2026/08/kali365-weaponizes-microsoft.html 13. NullReceiver: npm packages hide C2 IP in empty Ethereum transfers — The Hacker News — https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html 14. Apple iCloud Private Relay WebKit flaws leak users' real IP — Cyber Security News — https://cybersecuritynews.com/apple-icloud-private-relay/ 15. AI browsers vulnerable to zero-click agent hijacking via hidden instructions — Dark Reading — https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking 16. Poison Claude gray-market AI access exposes every prompt to the operator — The Hacker News — https://thehackernews.com/2026/08/poison-claude-sells-discounted-claude.html · Help Net Security — https://www.helpnetsecurity.com/2026/08/06/ai-model-access-fraud-gray-market/

  3. 2 days ago ·  Video

    Cyber Security News for August 5 2026 - Daily DefSec Brief

    1. Langflow unauthenticated RCE now on CISA KEV — CVE-2026-9198 — SecurityWeek — https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/ 2. Apache Tomcat EncryptInterceptor bypass added to KEV — CVE-2026-34486 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. ChainDrop npm worm self-propagates across hundreds of packages — Microsoft — https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/ 4. N-able N-central auth bypass on KEV, 3-day fed clock — CVE-2026-18556 — The Register — https://www.theregister.com/security/2026/08/04/feds-get-3-days-to-patch-n-able-god-mode-flaw-under-active-exploit/5282894 5. Veeam ONE 13 unauthenticated RCE at CVSS 10.0 — CVE-2026-64633 (+ -58074, -58075, -64630, -64631, -64634) — Cyber Security News — https://cybersecuritynews.com/multiple-veeam-one-vulnerabilities/ 6. TP-Link Omada ZTP flaws breach SMB networks — CVE-2025-7850, -7851, -9289, -9293, -15544, -15627, -15631 — BleepingComputer — https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/ 7. 1-click RCE in Cursor, VS Code and Google Antigravity via Git commit links — Cyber Security News — https://cybersecuritynews.com/1-click-rce-vulnerability-in-code-editors/ 8. QuickFox VPN supply-chain attack drops Mustang Panda's FDMTP backdoor — The Hacker News — https://thehackernews.com/2026/08/quickfox-supply-chain-attack-delivers.html 9. 77 Open VSX "evil twin" extensions exfiltrate developer and CI data — The Hacker News — https://thehackernews.com/2026/08/open-vsx-removes-77-malicious-evil-twin.html 10. SMOKE#SCREEN and BoA lures push ScreenConnect for persistent access — The Hacker News — https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html 11. Greatness PhaaS adds device-code phishing to bypass MFA — The Hacker News — https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html 12. 7-Zip strips Mark-of-the-Web, files dodge SmartScreen — Cyber Security News — https://cybersecuritynews.com/7-zip-mark-of-the-web-bypass/ 13. EtherRAT spreads via remote scheduled tasks in Gentlemen ransomware intrusion — Cyber Security News — https://cybersecuritynews.com/remote-scheduled-tasks-etherrat/ 14. XCSSET v40 spreads through compromised Xcode projects and Git repos — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/ 15. Malware increasingly skips DNS, going direct-to-IP for C2 — Unit 42 — https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ 16. Copilot and email AI assistants weaponized for BEC and account takeover — Cyber Security News — https://cybersecuritynews.com/hackers-weaponize-microsoft-copilot/

  4. 3 days ago ·  Video

    Cyber Security News for August 4 2026 - Daily DefSec Brief

    1. Critical unauthenticated RCEs in Adobe Campaign Classic — CVE-2026-48317, -48323, -48326, -48330, -48331, -48333, -48399 — Cyber Security News — https://cybersecuritynews.com/adobe-campaign-classic-vulnerabilities/ 2. Cisco Secure Firewall Management Center auth bypass to root — CVE-2026-20079 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 3. Check Point Security Management auth bypass / full takeover — CVE-2026-18574 — Cyber Security News — https://cybersecuritynews.com/check-point-authentication-bypass-flaw/ 4. Apache NiFi authorization-bypass flaws — CVE-2026-62354, -68979, -68980, -68981 — Cyber Security News — https://cybersecuritynews.com/apache-nifi-vulnerabilities/ 5. Critical cPanel/WHM SQL-as-root flaw — CVE-2026-58048 — Cyber Security News — https://cybersecuritynews.com/cpanel-vulnerability/ 6. LiteLLM AI gateway hijack, key theft, tool-call injection — CVE-2026-42271 (EPSS 0.83) — Embrace The Red — https://embracethered.com/blog/posts/2026/hijacking-litellm-for-fun-and-profit/ 7. Google ADK-python agent-to-agent prompt injection / PR tampering — SecurityWeek — https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/ · Cyber Security News — https://cybersecuritynews.com/ai-agent-against-its-own-ci-cd-pipeline/ 8. DOUBLECUP loader-as-a-service, ClickFix, cached PNGs — The Hacker News — https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html 9. Pass-ta-key attacks on Google-synced passkeys — The Hacker News — https://thehackernews.com/2026/08/google-password-manager-attacks-could.html 10. 18 malicious npm packages deliver cross-platform RAT (Alibaba tooling) — The Hacker News — https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html 11. Fake AI-tool GitHub clones deliver SmartLoader (TroyDens) — Cyber Security News — https://cybersecuritynews.com/fake-ai-tool-campaign/ 12. BINDCLOAK Windows backdoor steals tokens for privileged execution — Cyber Security News — https://cybersecuritynews.com/bindcloak-steals-windows-tokens/ 13. Fake IRS "Digital Asset Compliance Portal" letters phish crypto holders — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency 14. Device code phishing up 15x, vishing doubled in H1 2026 — Dark Reading — https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

  5. 4 days ago ·  Video

    Cyber Security News for August 3 2026 - Daily DefSec Brief

    1. N-able N-central auth bypass under active exploitation (incomplete first fix) — CVE-2026-18556, CVE-2026-18577 — The Hacker News — https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html 2. SonicWall SMA1000 zero-click root chain driving INC ransomware — CVE-2026-15409, CVE-2026-15410 — SecurityWeek — https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/ 3. Russian APT compromising public Wi-Fi / SOHO gateways for M365 credential theft — SecurityWeek — https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/ 4. Thermo Fisher patches DNA-file tampering flaw in forensic ID software — CVE-2026-17583 — The Hacker News — https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html 5. Hugging Face Diffusers flaws (FaceHugger) bypass trust_remote_code for RCE — CVE-2026-44513, CVE-2026-44827, CVE-2026-45804 — The Hacker News — https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html 6. Passkey attack class lets endpoint malware steal synced private keys — Unit 42 — https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ 7. XCSSET v40 abuses Chrome DevTools Protocol to steal cookies and run commands — Cyber Security News — https://cybersecuritynews.com/xcsset-v40-abuses-chrome-devtools/ 8. MacSync stealer delivered via fake Claude install guide and Terminal paste — Cyber Security News — https://cybersecuritynews.com/macsync-uses-fake-claude-guide/ 9. Chinese actor uses leaked DarkSword kit to deliver GHOSTBLADE on iOS — The Hacker News — https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html 10. COLDCARD wallet RNG flaw linked to $88.6M Bitcoin theft — BleepingComputer — https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/ 11. CrowdStrike: AI-driven detections now outpace human-triggered ones — CyberScoop — https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/ 12. Elastic Defend expands vulnerable-driver coverage to 800+ for BYOVD defense — Help Net Security — https://www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/ 13. PNLD breach exposes UK police and government contact details on dark web — The Hacker News — https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html 14. Brinks Home confirms Salesforce data breach after ShinyHunters claim — DataBreaches.net — https://databreaches.net/2026/08/02/brinks-home-confirms-data-breach-following-shinyhunters-claim/ 15. OpenAI details ChatGPT-assisted scam network run from Cambodia — Help Net Security — https://www.helpnetsecurity.com/2026/08/03/openai-disrupts-chatgpt-scam-operation/

  6. 31 Jul ·  Video

    Cyber Security News for July 31 2026 - Daily DefSec Brief

    1. CISA warns of active attacks locking operators out of water-sector PLCs — CISA — https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs 2. Critical SolarWinds Web Help Desk SAML auth bypass — CVE-2026-28323, CVE-2026-28299 — Cyber Security News — https://cybersecuritynews.com/solarwinds-flaw-bypass-web-help-desk-saml-login/ 3. SGLang LLM-serving framework — six unpatched flaws incl. unauth RCE — CVE-2026-15969, CVE-2026-14890, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 — CERT/CC — https://kb.cert.org/vuls/id/281278 4. PHP patches SQL injection and memory-corruption flaws — CVE-2026-17543, CVE-2026-17544, CVE-2026-7260 — Cyber Security News — https://cybersecuritynews.com/php-patches-three-flaws/ 5. Azure Cosmos DB flaw exposed a platform-wide key across tenants — The Hacker News — https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html 6. XCSSET macOS malware returns with fileless v40 — Unit 42 — https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ 7. DPRK macOS malvertising uses ClickFix fake updates — The Hacker News — https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html 8. State-sponsored campaign exploits Korean AnySign4PC — CVE-2020-7882 — The Hacker News — https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html 9. DeepSeek-powered "Hermes" agent runs near-autonomous attacks — Cyber Security News — https://cybersecuritynews.com/deepseek-powered-hermes-agent/ 10. Silver Fox uses 3-driver BYOVD chain to deliver ValleyRAT — The Hacker News — https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html 11. Astaroth banking trojan spreads through WhatsApp Web sessions — Cyber Security News — https://cybersecuritynews.com/astaroth-malware-turns-your-whatsapp-account/ 12. The Gentlemen ransomware kills ~180 security processes via kernel driver — Cyber Security News — https://cybersecuritynews.com/gentlemen-ransomware-kills-security-processes/ 13. PipeWire flaw lets Flatpak apps escape the Linux sandbox — CVE-2026-5674, CVE-2025-60616 — Embrace The Red — https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/ 14. SSH bot profiles Linux hardware before staging cryptominers — SANS ISC — https://isc.sans.edu/diary/rss/33202 15. Anthropic says Claude models escaped test environments and compromised three orgs — BleepingComputer — https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/

  7. 30 Jul ·  Video

    Cyber Security News for July 30 2026 - Daily DefSec Brief

    1. Cisco Secure Firewall Management Center hardcoded password added to CISA KEV — CVE-2026-20316 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Cisco Secure FMC authentication bypass — hot fixes released — CVE-2026-20079 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 3. Three critical VMware flaws: vCenter auth bypass, RCE, and ESXi VM escape — CVE-2026-59309, CVE-2026-59310, CVE-2026-47876 — The Hacker News — https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html 4. Critical unauthenticated file-read in Rails Active Storage (affects TeamCity) — CVE-2026-66066 — The Hacker News — https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html 5. SonicWall VPN and firewall accounts hit by credential-stuffing spree — CyberScoop — https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/ 6. Long-lived Microsoft Secure Boot bypass via old signed shims — Schneier on Security — https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html 7. Chrome 151 patches 370 flaws, including seven critical — SecurityWeek — https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/ 8. Firefox JIT flaw compromises browser on a single page visit, also hit Tor Browser — CVE-2026-10702, CVE-2026-43499 — The Hacker News — https://thehackernews.com/2026/07/researchers-show-single-malicious.html 9. Node.js patches 11 flaws, including two high-severity HTTP/2 memory issues — CVE-2026-56846, CVE-2026-56847 — Cyber Security News — https://cybersecuritynews.com/node-js-fixes-11-security-flaws/ 10. GitLab fixes 13 flaws, including a Workhorse info-disclosure bug — CVE-2026-6267, CVE-2026-12436, CVE-2026-15975 — Cyber Security News — https://cybersecuritynews.com/gitlab-fixes-13-security-flaws/ 11. Chaos ransomware deployed after two-minute Microsoft Teams vishing calls — Cyber Security News — https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/ 12. Okta details Work Panel vishing platform for helpdesk account takeovers — Cyber Security News — https://cybersecuritynews.com/cybercrime-platform-turns-helpdesk-calls/ 13. Amazon ties debug/chalk and axios npm hijacks to North Korea's Sapphire Sleet — The Hacker News — https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html 14. Copilot for Word prompt-injection worm self-replicates across documents — Simon Willison — https://simonwillison.net/2026/Jul/29/ai-worming-through-word/ 15. Linux cryptomining campaign weaponizes PAM to hide XMRig activity — Cyber Security News — https://cybersecuritynews.com/linux-cryptomining-campaign/ 16. Critical RufRoot flaw in Ruflo AI orchestration allows unauth RCE — CVE-2026-59726 — The Hacker News — https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html

  8. 29 Jul ·  Video

    Cyber Security News for July 29 2026 - Daily DefSec Brief

    1. Coordinated OT attack disrupts 30+ Minnesota water utilities — SecurityWeek https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/ · StateScoop https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/ 2. 24,650 exposed BMCs leak IPMI password hashes before login — CVE-2013-4786 — The Hacker News https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html · Dark Reading https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover 3. Gitea critical RCE via attacker-planted Git hook — CVE-2026-60004 — The Hacker News https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html 4. Critical OpenWrt DHCPv6 unauthenticated root RCE — CVE-2026-53921, CVE-2026-62947, CVE-2026-62948 — The Hacker News https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html 5. WordPress plugin backdoored in supply-chain compromise — CVE-2026-18072 — Cyber Security News https://cybersecuritynews.com/wordpress-plugin-backdoor/ 6. Two compromised @joyfill npm packages run a RAT at import time — The Hacker News https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html 7. Malicious npm packages target Alibaba developers with a cross-platform RAT — Cyber Security News https://cybersecuritynews.com/npm-packages-cross-platform-rat/ 8. AT&T Arris BGW210-700 unauthenticated LAN-side auth bypass — CVE-2026-16771 — CERT/CC https://kb.cert.org/vuls/id/141367 9. MikroTik RouterOS lacks brute-force protection on API auth — CVE-2026-16347 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05 10. Siemens Desigo CC OpenSSL stack overflow with RCE potential — CVE-2025-15467 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01 11. Tengu botnet uses the hardware watchdog to relaunch itself — The Hacker News https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html 12. CubePilot drone-software domain hijacked via DNS, TLS certs stolen — BleepingComputer https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/ 13. Apple patches 187 flaws across iOS, macOS, and Safari — CVE-2026-43810, CVE-2026-28849, CVE-2026-28900, CVE-2026-28914 — SANS ISC https://isc.sans.edu/diary/rss/33196 · SecurityWeek https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/ 14. Flying Eagle Android RAT source code circulating, 170 servers mapped — The Hacker News https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html 15. CISA and ACSC release CI Fortify guidance on isolating vital OT — CISA https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems · Cyber Security News https://cybersecuritynews.com/cisa-and-partners-release-checklist/

About

A daily podcast covering the important cyber security news that IT and security teams need to know.