The Defensive Line Podcast

The Defensive Line

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com

  1. The Defensive Line Weekly Podcast 019

    May 27

    The Defensive Line Weekly Podcast 019

    Story 1: Developer Supply Chains Under Sustained Assault * OX Security — TeamPCP / GitHub breach * StepSecurity — Nx Console VS Code extension * GitHub Security Blog — Investigating unauthorised access * SafeDep — Megalodon mass GitHub repo backdooring * StepSecurity — Megalodon CI/CD secrets exfiltration * Aikido Security — Laravel-Lang supply chain attack * Snyk — Laravel-Lang supply chain advisory * The Hacker News — Packagist supply chain attack * Socket — TrapDoor cross-ecosystem campaign Story 2: Kali365 — FBI Warns of oh-auth Token Theft Platform * FBI IC3 Public Service Announcement * Arctic Wolf — Kali365 token and session theft * The Record — FBI warns of Kali365 * Microsoft — Protect against consent phishing * Microsoft — Configure user consent * Microsoft — Block device-code flow with Conditional Access Story 3: A Zombie Account Hands Over the Water Supply * The Register — Zombie user account let hackers control the city’s water Honourable Mentions * Check Point Research — Nimbus Manticore operations during the Iranian conflict * Microsoft Security Blog — Fox Tempest malware-signing service * Malwarebytes — NYC Health + Hospitals breach * Aikido Security — Google API key 23-minute deletion window * MSRC — Microsoft Defender CVE-2026-41091 * Dark Reading — Microsoft Exchange OWA zero-day This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    15 min
  2. The Defensive Line Weekly Podcast 016

    May 6

    The Defensive Line Weekly Podcast 016

    The Defensive Line Weekly is a podcast version of our weekly Substack intelligence summary — the security stories that matter most for blue teamers and security leaders, with clear implications and practical defensive actions. AI voices are used, but the content is human curated and written with the support of AI. Topic 1: Helpdesk Impersonation Continues to Succeed * CrowdStrike — Cordial Spider adversary profile * CrowdStrike — Snarky Spider adversary profile * Google / Mandiant GTIG — Expansion of ShinyHunters SaaS data theft * Unit 42 / RH-ISAC — Extortion in the enterprise: defending against BlackFile attacks * CyberScoop — CrowdStrike names Cordial Spider and Snarky Spider Topic 2: cPanel & WHM and CopyFail cPanel / WHM CVE-2026-41940 * watchTowr Labs — cPanel WHM authentication bypass * cPanel vendor advisory — 28 April 2026 * Censys — The cPanel situation * Help Net Security — cPanel zero-day exploited * Rapid7 — CVE-2026-41940 ETR CopyFail CVE-2026-31431 * Wiz Research — CopyFail Linux privilege escalation * Ubuntu security advisory * AlmaLinux blog * Red Hat CVE advisory * Microsoft Security Blog — CopyFail cloud and Kubernetes impact * CERT-EU SA 2026-005 Topic 3: Three Supply Chain Attacks in One Week * SentinelOne — Week 18 supply chain roundup * Aikido Security — PyTorch Lightning PyPI compromise * Socket — PyTorch Lightning compromised * The Hacker News — Poisoned Ruby gems and Go modules * The Hacker News — PyTorch Lightning supply chain * The Register — SAP npm supply chain Honourable Mentions * TRM Labs — North Korea 2026 crypto theft * Arctic Wolf — BlueNoroff ClickFix and AI-generated Zoom lures * NCSC — AI-driven patch wave warning * Fortinet PSIRT FG-IR-26-100 * Fortinet PSIRT FG-IR-26-112 * The Register — Gemini CLI critical RCE This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    16 min
  3. The Defensive Line Weekly Podcast 014

    Apr 22

    The Defensive Line Weekly Podcast 014

    The Defensive Line Weekly is a curated weekly intelligence briefing for blue teamers and security leaders — produced as both a written Substack newsletter and this podcast. Each week we cut through the noise to the stories that actually matter for defenders, with clear implications and practical defensive actions. Topic 1: QEMU Virtual Machines Weaponised to Blind EDR * Sophos X-Ops — QEMU abused to evade detection and enable ransomware delivery * BleepingComputer — Payouts King ransomware uses QEMU VMs to bypass endpoint security Topic 2: Helpdesk Impersonation to Data Exfiltration * Microsoft Threat Intelligence — Cross-tenant helpdesk impersonation data exfiltration human-operated intrusion playbook Topic 3: Windows and Defender Zero-Days * Huntress — via Twitter/X * BleepingComputer — Recently leaked Windows zero-days now exploited in attacks * BleepingComputer — New Microsoft Defender RedSun zero-day PoC grants SYSTEM privileges * The Hacker News — Three Microsoft Defender zero-days Honourable Mentions * Darktrace — Inside ZionSiphon: OT malware targeting Israeli water systems * Ox Security — MCP supply chain advisory: RCE vulnerabilities across the AI ecosystem * Aonan Guan — Comment-and-control: prompt injection credential theft via Claude, Gemini, Copilot * BleepingComputer — ATHR vishing platform uses AI voice agents for automated attacks * Dark Reading — Tycoon 2FA hackers adopt device code phishing This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    16 min

About

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com