Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 11h ago ·  Video

    Cyber Security News for October 5 2026 - Daily DefSec Brief

    1. NetScaler SAML flaw exploited after last fix — CVE-2026-88779 — Fixed: 14.1-73.41 or 13.1-64.28 — federal due 2026-10-07 — Do: Update NetScaler again if it uses SAML — https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html 2. AI-found Rejetto HFS flaw now exploited — CVE-2026-61500 — Fixed: 3.2.1 — Do: Upgrade Rejetto HFS or take it offline — https://www.cve.org/CVERecord?id=CVE-2026-61500 3. Malicious VS Code themes on official Marketplace — Do: Allowlist the VS Code extensions developers use — https://socket.dev/blog/glassworm-vscode-themes 4. Vercel confirms KVM zero-day, guest escape claimed — Do: Watch for the KVM fix, plan host reboots — https://cybersecuritynews.com/kvm-zero-day-vm-escape/ 5. Exchange update reissued for mailbox flaw — CVE-2026-96940 — Do: Install Exchange's September V2 update — https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718 6. Dell CSM flaws give storage admin, no login — CVE-2026-63688, CVE-2026-63692 — Fixed: 1.18.0 — Do: Upgrade Dell Container Storage Modules — https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities 7. GitLab AI Gateway lets Duo users run commands — CVE-2026-90970 — Fixed: 19.2.4, 19.3.2 or 19.4.1 — Do: Upgrade your self-hosted GitLab AI Gateway — https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-994 8. Debian kernel update fixes 1,313 CVEs at once — CVE-2024-52560, CVE-2025-21817, CVE-2026-23137 (+ 1,310 more) — Fixed: 6.12.111-1 — Do: Update Debian 13 kernels and reboot — https://www.debian.org/security/2026/dsa-6528 9. BoKS seeded AD service passwords with the clock — CVE-2026-79901 — Fixed: 9.0.0.7 — Do: Patch and restart BoKS, then rotate passwords — https://www.fortra.com/security/advisories/product-security/fi-2026-012

  2. 4d ago ·  Video

    Cyber Security News for October 1 2026 - Daily DefSec Brief

    1. Cisco SD-WAN Manager zero-day gives admin — CVE-2026-76504 — Fixed: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, 26.2.1 — federal due 2026-10-03 — Do: Patch SD-WAN Manager, then check its logs — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU 2. Zammad zero-days used in an AI-agent breach — CVE-2026-102489, CVE-2026-102490 — Do: Upgrade Zammad to version 7 and check logs — https://csirt.divd.nl/cases/DIVD-2026-00015/ 3. MikroTik web interface flaw gives root — CVE-2026-84411 — Fixed: 7.24 — Do: Upgrade RouterOS and close WebFig to the internet — https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06 4. TeamViewer session permissions can be bypassed — CVE-2026-92370, CVE-2026-19743, CVE-2026-92368 (+ 2 more) — Fixed: 15.82, 15.64.8, 14.7.48855, 13.2.36230 (Windows) — Do: Update TeamViewer everywhere it is installed — https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ 5. WatchGuard fixes 15 Fireware OS flaws — CVE-2026-86131, CVE-2026-81433, CVE-2026-86101 (+ 2 more) — Fixed: 2026.3.2, 2026.2.3, 12.12.3, 12.5.21; AP 3.4.8 — Do: Upgrade Firebox and WatchGuard access points — https://psirt.watchguard.com/CVE-2026-86131 6. Star Blizzard's archive-and-disk-image phish — Do: Hunt for the three fake maintenance tasks — https://www.microsoft.com/en-us/security/blog/2026/09/29/star-blizzard-refines-phishing-and-malware-delivery-with-the-redflick-technique/ 7. Google: exploit growth is fast n-days — Do: Order the patch queue by exploitation evidence — https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/ 8. SSMS Copilot made a database owner sysadmin — CVE-2026-65669 — Fixed: 22.8.2 — Do: Update SQL Server Management Studio — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669

  3. 5d ago ·  Video

    Cyber Security News for September 30 2026 - Daily DefSec Brief

    1. A password reset led to Kubernetes credentials — Do: Alert on sign-in methods added after resets — https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/ 2. A package name runs commands in AWS AgentCore — CVE-2026-12530, CVE-2026-16796 — Fixed: 1.18.1 — Do: Upgrade the Bedrock AgentCore Python SDK — https://aws.amazon.com/security/security-bulletins/2026-065-aws/ 3. An Octopus project edit runs code on the server — CVE-2026-101169 — Fixed: 2026.1.11781 · 2026.2.13441 · 2026.3.15829 — Do: Upgrade self-hosted Octopus Server — https://advisories.octopus.com/post/2026/sa2026-10/ 4. OpenSSL DTLS leaks heap memory to a peer — CVE-2026-84782 — Fixed: 4.0.3 · 3.6.5 · 3.5.9 · 3.4.8 · 3.0.23 — Do: Update OpenSSL wherever DTLS is in use — https://openssl-library.org/news/vulnerabilities/ 5. Stolen passwords opened France's tax portals — Do: Require MFA on every staff and partner portal — https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html 6. Windows gets built-in Linux containers — Do: Set the WSL containers policy in Intune — https://blogs.windows.com/windowsdeveloper/2026/09/29/wsl-containers-now-generally-available/ 7. Coding agents post private screenshots publicly — Do: Stop coding agents from creating public repos — https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies

  4. 6d ago ·  Video

    Cyber Security News for September 29 2026 - Daily DefSec Brief

    1. Exploited Apple flaw fixed for older releases — CVE-2026-86950 — Fixed: 26.7.1 · 15.8.1 — Do: Update iPhones and Macs still on older releases — https://support.apple.com/en-us/149229 2. Featured Chrome ad blocker is spyware — Do: Remove Poper Blocker and allowlist Chrome extensions — https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions 3. A webpage can run code through OpenCode — Fixed: 1.18.22 — Do: Upgrade OpenCode on every developer machine — https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4 4. 16,326 Supabase databases readable by anyone — Do: Turn on row-level security for every Supabase table — https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps 5. MCP Python SDK leaks OAuth secrets — Fixed: 1.30.0 or 2.2.0 — Do: Upgrade the MCP Python SDK, rotate client secrets — https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-qx49-fqc8-xw99 6. NeedyMantis keeps access after the break-in — Do: Hunt NeedyMantis sideloading, block its domain — https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/ 7. Authlib accepts JWS with no signatures — CVE-2026-96760 — Do: Reject empty-signature JWS before Authlib sees it — https://kb.cert.org/vuls/id/762428 8. Old branded QR codes can be taken over — Do: Delete DNS records pointing at abandoned QR services — https://cyberinsider.com/hackers-can-hijack-qr-code-domains-to-redirect-users-to-phishing-sites/

  5. Sep 28 ·  Video

    Cyber Security News for September 28 2026 - Daily DefSec Brief

    1. NetScaler zero-days exploited before the patch — CVE-2026-88771, CVE-2026-88772 — Fixed: 14.1-73.37, 13.1-64.23, 13.1-37.279 (FIPS and NDcPP) — federal due 2026-09-30 — Do: Patch NetScaler, then hunt for compromise — https://support.citrix.com/external/article/CTX697096/citrix-netscaler-adc-and-citrix-netscale.html 2. One encoded letter gets past PeopleSoft WAF rules — CVE-2026-35273 — Do: Patch PeopleSoft, don't rely on the WAF — https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/ 3. SharePoint "spoofing" flaw is now exploited — CVE-2026-65660 — Fixed: 16.0.10417.20198 (2019), 16.0.19725.20522 (SE), 16.0.5565.1001 (2016) — federal due 2026-09-28 — Do: Install August's SharePoint update on every farm — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660 4. RouterOS SSH skips the login after a rekey — CVE-2026-67279 — Fixed: 6.49.21, 7.23.4, 7.24.2 — federal due 2026-09-28 — Do: Upgrade RouterOS and fence off SSH — https://www.cve.org/CVERecord?id=CVE-2026-67279 5. WordPress core file-load flaw now exploited — CVE-2026-87902 — Fixed: 7.1.2 (backports down to 4.7.37) — federal due 2026-09-28 — Do: Make sure WordPress updates reach every site — https://wordpress.org/news/2026/09/wordpress-7-1-2-release/ 6. Leaked service principal deletes Azure resources — Do: Rotate any service principal secret ever posted — https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/ 7. Public lead form hijacked Salesforce Agentforce — Do: Limit agents that read public web forms — https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce 8. New RAT takes commands over Tailscale's tailcat — Do: Alert on unsanctioned VPN software on endpoints — https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection 9. Disabled malicious GitHub Actions came back online — Do: Pin GitHub Actions to commit hashes — https://socket.dev/blog/mini-shai-hulud-actions

  6. Sep 25 ·  Video

    Cyber Security News for September 25 2026 - Daily DefSec Brief

    1. One affiliate, four ransomware brands, one toolkit — Do: Hunt for remote access tools you didn't deploy — https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/ 2. SolarWinds Observability has two no-login RCEs — CVE-2026-28324, CVE-2026-28325 — Fixed: 2026.2.3 — Do: Upgrade SolarWinds Observability Self-Hosted — https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28324 3. Carbonato botnet hijacks exposed Docker APIs — Do: Take the Docker API off the network — https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/ 4. Docs domain third-party.com now serves ClickFix — Do: Search your repositories for third-party.com — https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html 5. MacSync hides commands in iCloud calendar events — Do: Hunt Macs for new LaunchAgents and Git hooks — https://securelist.com/macsync-new-version/121383/ 6. ViewSonic ViewBoards give up screen and control — CVE-2026-82987, CVE-2026-82988, CVE-2026-82989 — Do: Put ViewBoards on their own network segment — https://kb.cert.org/vuls/id/234131 7. AI agents went around government portal controls — Do: Lock down your pre-production web servers — https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/ 8. Fake payroll apps install hidden ScreenConnect — Do: Block ScreenConnect servers that aren't yours — https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/

  7. Sep 24 ·  Video

    Cyber Security News for September 24 2026 - Daily DefSec Brief

    1. Roundcube pre-login SQL injection now exploited — CVE-2026-48842 — Fixed: 1.6.16 or 1.7.1 — Do: Upgrade Roundcube webmail — https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 2. TeamCity RCE now used in ransomware campaigns — CVE-2026-63077 — Fixed: 2025.11.7 or 2026.1.3 — Do: Patch TeamCity and check it for intruders — https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/ 3. Spraying hit only forgotten M365 service accounts — Do: Lock down forgotten Microsoft 365 service accounts — https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns 4. Public Ubuntu container escape, no kernel fix yet — CVE-2026-80521 — Do: Keep untrusted containers off Ubuntu hosts — https://ubuntu.com/security/CVE-2026-80521 5. Windows app host hands Microsoft tokens to attackers — Do: Turn off app sideloading where it isn't needed — https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door 6. Malicious providers on HashiCorp's Terraform registry — Do: Check Terraform lock files for the typosquat — https://www.aikido.dev/blog/graphalgo-terraform-go-modules 7. Any cPanel account can get root via CalDAV — CVE-2026-87899, CVE-2026-87900, CVE-2026-68490 — Fixed: 11.134.0.57, 11.136.0.41, 11.138.0.8; WP Toolkit 6.11.3 — Do: Update cPanel and WP Toolkit — https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 8. Foxit PDF Reader update fixes updater SYSTEM flaw — CVE-2026-91813 — Fixed: Reader 2026.2.1; Editor 2026.2.1, 14.0.8 or 13.2.7 — Do: Push the Foxit PDF update — https://www.foxit.com/support/security-bulletins.html 9. Hundreds of leaked GitHub App keys still work — Do: Audit your GitHub Apps and rotate their keys — https://blog.gitguardian.com/github-app-private-keys-leaked/ 10. New injection technique slips past four EDRs — Do: Ask your EDR vendor about parameter poisoning — https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/ 11. A GitLab email address can commit code as you — Do: Reset your GitLab incoming email token — https://www.aikido.dev/blog/gitlab-email-push-to-main

Ratings & Reviews

5
out of 5
2 Ratings

About

A daily podcast covering the important cyber security news that IT and security teams need to know.

You Might Also Like