The Defensive Line Podcast

The Defensive Line

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com

  1. 4d ago

    The Defensive Line Weekly Podcast 036

    The Defensive Line Weekly — Episode 36 (13–20 September 2026) The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action. 🤖 This script was written and read by AI, but reviewed and edited by humans. This week’s edition: The Defensive Line Weekly #39: 13–20 September 2026 Main stories The Brevo key and ClickFix on trusted sites Brevo: Incident post-mortem BleepingComputer: Brevo supply chain attack injected ClickFix scripts on customer sites Push Security: Malicious copy and paste detection Two exploited Cisco zero-days Cisco: Identity Services Engine authentication bypass advisory CISA: CISA adds two known exploited vulnerabilities to catalog The Hacker News: Cisco warns of new zero-day ISE authentication bypass Sophos: Cisco Secure Email Gateway vulnerability in active exploitation The Register: Cisco email security boxes can be rooted by an email Help Net Security: Cisco ISE vulnerability exploited Dark Reading: Sandworm chains Cisco vulnerabilities to deploy Cyclops Blink Developer trust: Plugin4Shell and WaterPlum Air Security: Plugin4Shell The Hacker News: Plugin4Shell lets repository owners swap pinned plugin code The Register: AI coding agents 0-click RCE flaw could hand attackers keys to the kingdom FBI/IC3: Joint advisory on WaterPlum The Record: North Korean hackers infect thousands of devices in WaterPlum scheme BleepingComputer: North Korean WaterPlum hackers infected 30,000 devices worldwide The Hacker News: WeaselBiscuit stealer spreads via 13 npm packages GitLab: How to detect and prevent Contagious Interview IDE attacks Honourable mentions LastPass: Delphos Labs report on the Rapuncel infostealer BleepingComputer: Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer Microsoft: Application Control vulnerable driver blocklist Hacktron: Hacking OpenAI The Hacker News: Claude Opus 5 helped researchers take over OpenAI staff accounts Mandiant: AI risk and resilience 2026 The Hacker News: Attacker hijacks AI coding assistant session Elastic Security Labs: Malicious browser extension KREMLIN banking malware The Hacker News: KREMLIN banking malware hijacks Chrome CISA: Known Exploited Vulnerabilities catalogue The Hacker News: CISA flags three Linux kernel vulnerabilities The Hacker News: Active exploitation attempts target WSO2 API Manager The Hacker News: Acronis cPanel backup plugin exploited BleepingComputer: Check Point warns critical flaw lets hackers execute code as root The Hacker News: BIND 9 update fixes 14 flaws This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 036
  2. Sep 16

    The Defensive Line Weekly Podcast 035

    🤖 The voices in this episode are AI generated. The briefing is drafted and read by AI, then reviewed and edited by humans. This week’s edition: The Defensive Line Weekly #38: 6–13 September 2026 Main stories Topic 1 — AI as the execution layer Anthropic’s September threat report, and PaperCut exploitation at scale. Anthropic: Detecting and countering misuse of AI — September 2026 Blackpoint Cyber: Death by a thousand PaperCuts — AI-driven exploitation at scale GreyNoise: AI-orchestrated campaign against PaperCut NG/MF The Register: Hundreds of AI agents helped the PaperCut attacker hit 395 orgs PaperCut: Security bulletin and fixed releases Topic 2 — Passkey lures and help-desk vishing Social engineering aimed at M-F-A enrolment and identity support, into Microsoft 365. Microsoft: Passkey-themed social engineering leads to identity and cloud compromise Topic 3 — Systems that hold credentials Artifactory exploitation and the build pipeline as the objective, plus an exposed A-I gateway chained to cloud compromise. Wiz: Artifactory under attack — in-the-wild exploitation CISA: Three vulnerabilities added to the Known Exploited Vulnerabilities catalogue Wiz: Off guard — breaking LiteLLM from authentication bypass to cloud compromise Further reading, not covered in this episode: Google Threat Intelligence Group on manipulated AI coding assistants, malicious Model Context Protocol packages and prompt injection in repository configuration — From prompting to autonomy: the evolution of adversarial AI. Full write-up in The Defensive Line Weekly #38. Honourable mentions Cisco Secure Firewall Management Center exploitation and the new Linux variant of Cyclops Blink — The Hacker News, Sophos GitLab critical file-read flaw in self-managed instances (CVE-2026-85706) — GitLab patch release, The Hacker News, BleepingComputer Chrome actively exploited flaw used by the BlueMoon exploit kit (CVE-2026-87491) — Chrome Releases, Malwarebytes, The Register MikroTik RouterOS and ConnectWise ScreenConnect flaws added to the Kev catalogue on 12 September — CISA, The Hacker News Check Point V-P-N gateway certificate-handling flaws — watchlist (CVE-2026-85102, CVE-2026-85103) — The Hacker News, BleepingComputer Prompt-injection research from Check Point and ESET — Check Point Research, ESET Versions: PaperCut fixed in 26.0.5, 25.0.13 and 24.1.10. GitLab fixed in 19.3.2, 19.2.6 and 19.1.8. Artifactory: apply the fixed release for your branch covering all three issues. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 035
  3. Sep 9

    The Defensive Line Weekly Podcast 034

    The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action. 🤖 This briefing is drafted and read by AI, but reviewed and edited by humans. This week’s edition: The Defensive Line Weekly #37: 30 August–6 September 2026 Main stories One exposed AI key, six hundred thousand dollars of compute METR: Update on Security at METR SonicWall’s edge is under attack again SonicWall: SMA 1000 Series affected by multiple vulnerabilities CISA: CISA adds seven known exploited vulnerabilities to its catalogue Fake support turns trusted tools into an attack path Microsoft Threat Intelligence: Impersonating IT support — how threat actors turn a remote session into enterprise-wide access Huntress: Rogue ScreenConnect installations suggest worm-like activity ConnectWise: Security advisories Honourable mentions Softaculous: Security incident — BGP hijacking Kentik: Latest BGP hijack targets a hosting-software vendor Microsoft: ASCII smuggling crosses over from AI prompt injection to phishing evasion Arctic Wolf: Exploited PaperCut vulnerabilities lead to credential theft PaperCut: Urgent security advisory JFrog: CVE-2026-82329 — authentication bypass in Artifactory Google Chrome Releases: Stable Channel Update for Desktop Wordfence: Attackers actively exploit a critical Elementor Pro vulnerability Cisco: Nexus 9000 Series Silicon One remote-code-execution vulnerability GitLab: Critical remote code execution in vm2 Sublime Security: Sublime and CrowdStrike unify email detection, response and sandbox analysis CrowdStrike: Real-Time Supply Chain Attack Protection CrowdStrike: The next evolution of the Agentic SOC CrowdStrike: Agentic Identity Provider CrowdStrike: Falcon Guardian defines the next generation of AI security GitHub: FalconFlank proof of concept The Hacker News: Researcher releases FalconFlank PoC showing privilege escalation in CrowdStrike Falcon The Register: Prolific Microsoft zero-day hunter drops CrowdStrike Falcon exploit PoC This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 034
  4. Sep 3

    The Defensive Line Weekly Podcast 033

    The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action. 🤖 Voices are AI-generated. Story curation, research and writing are a mix of AI and human. This week’s edition: The Defensive Line Weekly #36: 23–30 August 2026 Main stories TerminalFix turns a paste into a persistent intrusion Microsoft Threat Intelligence: TerminalFix campaign deploys a reverse tunnel through a multistage intrusion The Hacker News: TerminalFix uses fake Cloudflare verification to deploy a reverse tunnel The phish worked, but the application boundary held ReliaQuest: Social-engineering attempt against ReliaQuest — what the company found Island: NovaCookies phishing service targeting hundreds of organisations SecurityWeek: ReliaQuest confirms incident and says the impact was limited When AI systems trust documentation and expose gateways Data became code: Researchers ran code inside corporate networks through agent-readable documentation Project site: What Would AI Do? Ars Technica: Claude, Codex and Hermes installed unowned code inside corporate networks Wiz: Ninety days of attacks against internet-facing AI infrastructure Microsoft Security: Securing AI gateways and control points Honourable mentions CISA’s tale of two SOCs CISA: AA26-237A — A Tale of Two SOCs ServiceNow as a management plane MDSec: Anatomy of a ServiceNow red-team path ServiceNow: KB3152242 — AI Platform security update Signal and WhatsApp account takeover POLITICO: State-linked actors target EU officials’ messaging accounts AIVD: Phishing via Signal and WhatsApp BfV and BSI: Joint warning on messaging-app phishing Malicious browser extensions The Hacker News: Malicious Chrome and Edge extensions steal cryptocurrency wallet secrets The Hacker News: Malicious Firefox extensions impersonate cryptocurrency wallets Vulnerability roundup PaperCut NG and MF — zero-day exploitation PaperCut: Urgent security advisory — 27 August 2026 Versions: PaperCut released emergency patches for versions 25 and 26, followed by additional hardening on 28 August. Consult the advisory for the latest fixed builds and investigation guidance. CISA KEV additions CISA: Known Exploited Vulnerabilities catalogue Six vulnerabilities were added on 27 August, including flaws affecting Citrix NetScaler, Linux and SQL Server. Citrix NetScaler ADC and Gateway The Hacker News: Critical NetScaler authentication bypass Versions: The issue affects customer-managed NetScaler ADC and Gateway deployments, including certain FIPS and NDcPP builds, as well as SecurAccess. Check the current Citrix advisory for the appropriate fixed build for your deployment. WordPress plugins and themes The Hacker News: Five critical WordPress plugin and theme flaws Affected products include WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Update each affected component to the latest fixed release published by its maintainer. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 033
  5. Aug 26

    The Defensive Line Weekly Podcast 032

    The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action. 🤖 Voices are AI-generated. Story curation, research and writing are a mix of AI and human. This week’s edition: The Defensive Line Weekly #35: 16–23 August 2026 Main stories A CVSS 10.0 in Entra ID — and a corrected advisory Microsoft MSRC: CVE-2026-69836 advisory The Hacker News: Microsoft Entra ID flaw rated CVSS 10.0 — advisory correction Poisoning the software factory Unit 42: Securing the Overlooked Corners of the SDLC Supply Chain Wiz Research: Rust supply-chain attack on arrayref — significant overlap with DPRK campaigns Espionage and phishing move inside legitimate logins Google Threat Intelligence Group: Distinct clusters targeting individuals of interest to Russia Unit 42: Identity Abuse Through Trusted Communication Channels BleepingComputer: New SynkLoader malware pushed in Microsoft Teams phishing campaign Honourable mentions Cisco Talos: UAT-10147 integrates agentic AI into post-compromise operations ICO: ACRO Criminal Records Office reprimanded following cyber security failings BleepingComputer: Leaked AWS keys give full control over corporate accounts GitLab: Critical patch release 19.2.4 Citrix: NetScaler ADC and NetScaler Gateway security bulletin CTX696939 Zimbra: Patch release update — Zimbra 10.1.20 Versions: GitLab CE/EE (CVE-2026-19478, actively exploited) — upgrade self-managed instances to 19.2.4, 19.1.6, 19.0.8 or 18.11.11. Citrix NetScaler ADC/Gateway (CVE-2026-19490) — upgrade to 14.1-73.32 or 13.1-63.21. Zimbra Collaboration (CVE-2026-73570, actively exploited) — update to 10.1.20 or later. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 032
  6. Aug 19

    The Defensive Line Weekly Podcast 031

    The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action. 🤖 Voices are AI-generated. Story curation, research and writing are human. This week’s edition: The Defensive Line Weekly #34: 9–16 August 2026 Main stories Lazarus, fake job offers, and a Windows zero-day Check Point Research: Shattering the Dream: When a Job Offer Becomes a Zero-Day Attack The Hacker News: Lazarus Exploits Windows Zero-Day to Deploy FudModule Rootkit The Hacker News: Microsoft Patches 398 Flaws Including Actively Exploited Zero-Day Recruitment as an attack surface CERT-UA: UAC-0145 campaign targeting administrators and IT staff ANY.RUN: Lazarus Group IT Workers Investigation — Part Two The Record: Russian military hackers pose as recruiters to target Ukrainian IT workers Akira, Safe Mode, and EDR bypass Huntress: Akira Hits Safe Mode: Ransomware Rebooting Around EDR The Register: Akira ransomware scum blocked victims’ security tools — and broke their own encryptor NetScaler and the collapsing exploitation window watchTowr Labs: You’re Back In The Room: Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Citrix: Citrix security advisories Zero Day Clock: Time-to-exploit tracking City-Forum, Salesforce, ServiceNow, and OAuth abuse Reco: City-Forum campaign against Salesforce and ServiceNow Dark Reading: Long-running data-theft campaign targets Salesforce and ServiceNow Honourable mentions Genians: Kimsuky using local LLMs for offensive operations Pillar Security: Deadbugz: active malicious MCP supply chain campaign The Hacker News: New passkey attacks can recover synced passkeys Mozilla: Updated GPG key for signing Firefox and Thunderbird releases This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 031
  7. Aug 12

    The Defensive Line Weekly Podcast 030

    The three stories that influence the defensive priorities this week: a vishing extortion crew calling employees on their personal phones, a self-propagating credential-stealing worm in npm, and an actively exploited RMM platform flaw that reached downstream managed customer networks. 🤖 Voices are AI-generated. Story curation and analysis is human. This episode Vishing extortion reaches the personal phone Google Threat Intelligence Group reports the financially motivated data-theft extortion group behind BlackFile (also operating as Redact, Pink, Helix and Falcon) running helpdesk-themed vishing, AiTM credential harvesting on fake passkey/MFA/SSO enrolment portals, and automated SaaS exfiltration — with first contact often on employees’ personal phones. * Google Threat Intelligence Group * The Hacker News * Bloomberg ChainDrop: a self-propagating worm in npm’s plumbing A credential-stealing worm entered through the keyv and cacheable packages and republished itself across more than 400 packages, harvesting developer credentials and GitHub Actions secrets, with persistence hooks in Claude Code and VS Code. * Wiz Research * Microsoft * Unit 42 * The Hacker News — 800 malicious npm packages N-able N-central: when the management plane is the way in Active exploitation of an unauthenticated remote-admin flaw (CVE-2026-18577, alongside CVE-2026-18556), a bypassed first fix, and vendor-confirmed downstream compromise of managed customer networks via Take Control. * N-able security update, 6 August * N-able Hotfix 2 release note * N-able security update, 2 August * The Register * The Hacker News — CISA KEV Versions: N-central Hotfix 1 = 2026.3.1.7 (2 August); Hotfix 2 = 2026.3.1.10 (6 August). Hotfix 2 is required even if Hotfix 1 was already applied. Honourable mentions * AISI incident report on unsanctioned AI agent behaviour — AISI, NCSC statement, The Hacker News, CrowdStrike agent containment architecture * Device-code phishing in commodity kits (Greatness, Kali365) — The Hacker News — Greatness, The Hacker News — Kali365, Dark Reading * INC ransomware exploiting SonicWall SMA 1000 flaws — Resecurity, The Hacker News * Metabase zero-day exploited in the wild (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) — The Hacker News, Wiz Read the full written edition The Defensive Line Weekly #33: 2–9 August 2026 → Substack This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 030
  8. Aug 6

    The Defensive Line Weekly Podcast 029

    The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack Intelligence Summary — the week’s most important security stories turned into practical defensive action. 🤖 Voices are AI-generated. Story curation, research and writing are human. Russia-linked CaptiveCrunch turns hotel Wi-Fi into an identity attack surface; autonomous AI attacks move from lab accident to real adversary use; and exposed water PLCs cause real-world disruption. CaptiveCrunch and hostile hotel Wi-Fi * Microsoft Threat Intelligence — CaptiveCrunch: https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/ * The Hacker News — Device-code phishing: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html Autonomous AI attacks * Cloud Security Alliance — Hugging Face CISO post-mortem: https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem * OpenAI — Hugging Face model evaluation security incident: https://openai.com/index/hugging-face-model-evaluation-security-incident/ * Anthropic — Investigating incidents in cybersecurity evals: https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals * Unit 42 — Autonomous A-I cyber attack campaign: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ * Hugging Face — Agent intrusion technical timeline: https://huggingface.co/blog/agent-intrusion-technical-timeline Water-sector PLC attacks * FBI/EPA — Water sector public service announcement: https://www.ic3.gov/PSA/2026/PSA260730.pdf Honourable mentions * JetBrains — TeamCity advisory: https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/ * CISA — S-V-R exploitation of TeamCity CVE-2023-42793: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a * Ruby on Rails — Active Storage advisory: https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432 * Adobe — Campaign Classic security bulletin: https://helpx.adobe.com/security/products/campaign/apsb26-114.html * The Register — Brinks Home / ShinyHunters Salesforce claim: https://www.theregister.com/security/2026/07/31/the-most-famous-brand-in-physical-security-got-pwned-by-shinyhunters/5281924 * BleepingComputer — Adform script compromise: https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/ This week’s edition * The Defensive Line Weekly #32: 26 July – 2 August 2026: https://thedefensiveline.substack.com/p/the-defensive-line-weekly-32-26-july Previous episode referenced * The Defensive Line Weekly #31: 19–26 July 2026: https://thedefensiveline.substack.com/p/the-defensive-line-weekly-31-1926 This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    The Defensive Line Weekly Podcast 029

About

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com