Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 10h ago ·  Video

    Cyber Security News for August 24 2026 - Daily DefSec Brief

    1. Passkey phishing kit keeps mailbox access after a password reset — SecurityWeek — https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/ 2. Encrypted-prompt technique bypasses AI guardrails in Grok and Gemini — SecurityWeek — https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ 3. Hundreds of leaked AWS keys still live, many with admin — BleepingComputer — https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ 4. Trojanized npm packages drop an AI-assisted Linux backdoor on import — The Hacker News — https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html 5. North Korea-linked actors poison popular Rust crates — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/ 6. SynkLoader malware spread via Teams help-desk impersonation — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ 7. Chameleon SEO poisoning cloaks fake bank sites from scanners — Help Net Security — https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/ 8. Malware-as-a-service uses Adobe-themed domain to hit Windows via .bat — Cyber Security News — https://cybersecuritynews.com/malware-as-a-service-adobe-themed-domain/ 9. Agent Tesla v4 uses emoji obfuscation to dodge signature detection — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/ 10. Iran-linked hackers shut down a UK power plant for four days — SecurityWeek — https://www.securityweek.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days/ 11. Vendor essay questions Salesforce free scanner on portal file uploads — Cyber Security Dive (sponsored) — https://www.cybersecuritydive.com/spons/salesforce-gave-every-org-the-same-free-scanner-attackers-already-know-wha/828063/ 12. ThreatLocker walkthrough on abusing Windows named pipes for local privilege escalation — BleepingComputer (ThreatLocker) — https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ 13. Sophos: attackers impersonate Claude, ChatGPT, Copilot and Perplexity — Help Net Security — https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/

  2. 3d ago ·  Video

    Cyber Security News for August 21 2026 - Daily DefSec Brief

    1. Max-severity Entra ID flaw exploited before patch — CVE-2026-69836 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ 2. TrueConf Server code injection added to CISA KEV — CVE-2026-72530 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. TrueConf Server missing-auth flaw added to KEV, due Aug 23 — CVE-2026-72529 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 4. Elementor Pro file-upload unauthenticated RCE — CVE-2026-32475 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wordpress-sites-to-rce-attacks/ 5. Spring Security embedded LDAP admin-access flaw — CVE-2026-59270 — Cyber Security News — https://cybersecuritynews.com/spring-security-flaw-access-ldap-servers/ 6. Three suspected Russian clusters abuse OAuth/auth flows — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia/ 7. Malware commands hidden in FTP server banners (E4del, PINHOLE) — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ 8. CDN Tsunami HTTP/3-to-HTTP/1.1 DoS amplification — CVE-2026-14456 — The Hacker News — https://thehackernews.com/2026/08/cdn-tsunami-abuses-http3.html 9. Signed Defender BTR.sys driver repurposed for kernel bypass — The Hacker News — https://thehackernews.com/2026/08/threatsday-gogs-100-rce-n8n-workflow-to.html 10. containerd CRI plugin flaws enable cross-pod RCE — CVE-2026-50195, CVE-2026-53488, CVE-2026-53489, CVE-2026-53492, CVE-2026-47262 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/ 11. Redshift JDBC driver runs arbitrary classes from URL params — CVE-2026-8178 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-028-aws/ 12. N-able Passportal flaw exposes vault master keys — Dark Reading — https://www.darkreading.com/vulnerabilities-threats/n-able-bug-password-vault-master-keys 13. Peer2Profit proxyware turns employee device into internal proxy — Cyber Security News — https://cybersecuritynews.com/bandwidth-sharing-app/ 14. Atlassian and Splunk patch 250+ vulnerabilities — SecurityWeek — https://www.securityweek.com/atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities/

  3. 4d ago ·  Video

    Cyber Security News for August 20 2026 - Daily DefSec Brief

    1. Feds warn of active AI-scripted attacks on internet-exposed Siemens S7 PLCs — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a 2. Critical Citrix NetScaler auth-bypass patched, exploitation expected — CVE-2026-19490, CVE-2026-19489 — SecurityWeek — https://www.securityweek.com/exploitation-expected-for-critical-authentication-bypass-patched-in-citrix-netscaler/ 3. UAT-10147 deploys cross-platform SPECTRE implant with Linux rootkit and BYOVD — CVE-2019-16098, CVE-2021-21551 — Cisco Talos — https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/ 4. RDK-B broadband gateway WebUI has five flaws including auth bypass and possible RCE — CVE-2026-19505 through CVE-2026-19509 — CERT/CC — https://kb.cert.org/vuls/id/874418 5. ToxicPanda 2.0 Android trojan adds PIN theft and expands to 349 institutions — The Hacker News — https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html 6. New Manic Android malware exfiltrates data through nearby infected devices — BleepingComputer — https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/ 7. Fake Google Gemini installer delivers Vidar infostealer via Colab lure — Help Net Security — https://www.helpnetsecurity.com/2026/08/20/fake-google-gemini-installer-vidar-infostealer/ 8. 15 malicious Firefox extensions abuse Cloudflare Workers to steal crypto wallets — Cyber Security News — https://cybersecuritynews.com/malicious-firefox-extensions-2/ 9. 41 fake download sites show a real link, then redirect to Download Studio installer — Malwarebytes Labs — https://www.malwarebytes.com/blog/threat-intel/2026/08/41-deceptive-download-sites-show-a-real-link-then-send-you-somewhere-else 10. Password spraying surged 155x, driven by Azure CLI targeting — BleepingComputer — https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/ 11. Cisco RoomOS USB stack overflow allows root code execution — CVE-2026-20302 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-bof-vTMANZgu 12. Cisco BroadWorks XXE flaw leaks config files to unauthenticated attackers — CVE-2026-20320 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt 13. Geekom mini PC LAN driver shipped with the Asruex backdoor — SC World — https://www.scworld.com/brief/geekom-admits-malware-found-in-legacy-mini-pc-driver-download 14. Def Con attendees hit by persistent phishing that abuses Google Apps Script — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/def-con-attendees-persistent/ 15. Rogue ransomware affiliate poses as a recovery firm to double-dip on victims — BleepingComputer — https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/

  4. 5d ago ·  Video

    Cyber Security News for August 19 2026 - Daily DefSec Brief

    1. Windows IKE Extension RCE added to CISA KEV, now exploited — CVE-2026-33824 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. macOS Screen Sharing auth bypass added to CISA KEV — CVE-2026-65400 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. MLflow SSRF and FUXA auth-bypass under active exploitation — CVE-2026-64849, CVE-2026-25895 — The Hacker News — https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html 4. Cursor IDE zero-day runs code on repo open — Cyber Security News — https://cybersecuritynews.com/cursor-0-day-vulnerability/ 5. CoSnitch: one-click Copilot data exfiltration — CVE-2026-24301, CVE-2026-24299 — The Hacker News — https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html 6. Chrome ships two critical graphics-component fixes — CVE-2026-76034, CVE-2026-76036 — Chrome Releases — http://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html 7. Firefox 154 patches 58 flaws, 20 high-severity — SecurityWeek — https://www.securityweek.com/chrome-firefox-updates-patch-dozens-of-vulnerabilities/ 8. Oracle August CSPU ships 943 patches for 925 CVEs — Tenable — https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves 9. TWINLOOT runs C2 inside Microsoft cloud services — The Hacker News — https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html 10. NASA AIT-GUI flaw lets unauthenticated spacecraft commands — GHSA-p9r8-2q67-fp86 — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/ 11. BeyondTrust EPM for Windows privilege-escalation flaws — CVE-2026-40144, CVE-2026-40145 — Cyber Security News — https://cybersecuritynews.com/beyondtrust-windows-epm-vulnerabilities/ 12. 50,000 Stripe merchant API keys leaked in public code — Security Affairs — https://securityaffairs.com/197504/cyber-crime/50000-stripe-secrets-leaked-in-public-code.html 13. Slovakia finds Russian SMS-triggered backdoor in traffic cameras — Risky Business News — https://news.risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/ 14. Rapid7 report: volume and speed outpace traditional patch cycles — SecurityWeek — https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/ 15. Self-propagating payloads spread between AI agents via shared prompt files — The Hacker News — https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html

  5. 6d ago ·  Video

    Cyber Security News for August 18 2026 - Daily DefSec Brief

    1. Windows Task Host privesc actively exploited by ransomware gangs — CVE-2025-60710 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/ 2. Ray unauthenticated RCE via DNS rebinding, actively exploited — CVE-2025-62593 — The Hacker News — https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html 3. GitLab GraphQL flaw lets unauth attackers delete public projects — CVE-2026-19478, CVE-2026-19650 — SecurityWeek — https://www.securityweek.com/gitlab-patches-critical-code-injection-vulnerability/ 4. Certighost: low-priv AD user coerces Enterprise CA into issuing a cert — CVE-2026-54121 — BleepingComputer — https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/ 5. Unisoc modem chain gives Android kernel access via VoLTE video call — CVE-2022-20210, CVE-2025-31718 — The Hacker News — https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html 6. Claude Code drives nearly every stage of a ransomware intrusion — Cyber Security News — https://cybersecuritynews.com/claude-code-helps-ransomware-operator/ 7. C2Looper: Rust backdoor delivered via ClickFix, GitHub C2 — Zscaler — https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2 8. Cavern C2 uses DNS A-records and Google Apps Script — The Hacker News — https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html 9. Storm-0501 hijacks Azure tenants for cloud-native ransomware — Tenable — https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response 10. Attackers use AI to identify high-value files worth stealing — Help Net Security — https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/ 11. Microsoft removes WMIC LOLBin from Windows 11 24H2/25H2 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/ 12. Operation ASTERIX: crypto-fraud kit built with AI coding assistants — Rapid7 — https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing 13. Windows Server 2022 hits end of mainstream support Oct 13, 2026 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/

  6. Aug 17 ·  Video

    Cyber Security News for August 17 2026 - Daily DefSec Brief

    1. macOS Screen Sharing auth-bypass exploited to root Macs and drop Monero miners — CVE-2026-65400 — SecurityWeek — https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks/ 2. Microsoft SCCM flaw chain enables RCE on primary site server — Cyber Security News — https://cybersecuritynews.com/microsoft-sccm-vulnerability/ 3. Roundcube webmail patches RCE and SSRF flaws — Cyber Security News — https://cybersecuritynews.com/roundcube-1-6-18-and-1-7-3-released-with-fix/ 4. Wireshark 4.6.8 fixes 28 vulnerabilities — SANS ISC — https://isc.sans.edu/diary/rss/33248 5. TheHatman selling Azure/Entra data allegedly stolen from Fortune 500 tenants — SecurityWeek — https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/ 6. Fake Web3 job interview delivers NeedleStealer and hVNC RAT via signed ClickOnce — Cyber Security News — https://cybersecuritynews.com/fake-web3-interview/ 7. APT36-linked PATCHCORD backdoor uses fake VPN installers and Google Sheets C2 — Security Affairs — https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html 8. Infostealers harvested 1.7 billion credentials in six months — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/infostealers-17-billion/ 9. Dropcatch domains: attackers buying expired domains for malware and C2 — The Hacker News — https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html 10. Prompt injection hidden in a court filing draws first known sanction — Security Affairs — https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html 11. Clop claims data theft at Philips and GE; Philips confirms a contained breach — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/ 12. Microsoft delays an Exchange update and won't give a new date — The Register — https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-delayed-exchange-update-cant-say-when-it-will-arrive/5288227

  7. Aug 14 ·  Video

    Cyber Security News for August 14 2026 - Daily DefSec Brief

    1. GeoServer zero-day exploited within hours, no patch yet — SecurityWeek https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/ · Cyber Security News https://cybersecuritynews.com/geoserver-0-day-vulnerability/ 2. Citrix NetScaler pre-auth RCE detailed by researchers — CVE-2026-8452 (tentative) — watchTowr Labs https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/ 3. VMware vCenter Syslog RCE hitting 361 IPs across 47 countries — CVE-2026-59310 — BleepingComputer https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/ · Dark Reading https://www.darkreading.com/vulnerabilities-threats/global-threat-campaign-critical-vmware-vcenter-flaw 4. HoneyMyte CoolClient backdoor deploys signed kernel rootkit — Securelist https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/ 5. Adobe Commerce account-hijack flaw under active exploitation — CVE-2026-71362 — SecurityWeek https://www.securityweek.com/adobe-commerce-bug-targeted-immediately-after-disclosure/ 6. AmnesiaStealer macOS malware via fake GitHub ClickFix pages — CVE-2020-9771 (referenced) — SecurityWeek https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/ 7. HACKERAI malware uses GitHub Gists for C2 — Cyber Security News https://cybersecuritynews.com/hackerai-malware/ 8. Aeternum botnet stores C2 on Polygon blockchain — Cyber Security News https://cybersecuritynews.com/aeternum-botnet-uses-polygon/ 9. Download More RAM attack disables Defender via memory aliasing — CVE-2026-23670 — Cyber Security News https://cybersecuritynews.com/download-more-ram-attack/ 10. AI token jacking turns leaked API keys into ~$1M in charges — Cyber Security News https://cybersecuritynews.com/ai-token-jacking/ 11. New Mirai variant Evooo1Bot adds stealth, targets common gear — The Record https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code 12. Crypter services sell Defender/EDR/SmartScreen bypasses — Cyber Security News https://cybersecuritynews.com/malware-crypter-services/ 13. MessiahGPT criminal AI service marketed on BreachForums — Cyber Security News https://cybersecuritynews.com/messiahgpt-ai-tool/ 14. Microsoft patches LegacyHive Windows User Profile Service zero-day — CVE-2026-62832 — BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/ 15. White House authorizes vetted private firms to hack cybercrime groups — CyberScoop https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/ · The Record https://therecord.media/trump-cyber-crime-offensive

  8. Aug 13 ·  Video

    Cyber Security News for August 13 2026 - Daily DefSec Brief

    1. VMware vCenter path-traversal RCE now APT-exploited — CVE-2026-59310 — SecurityWeek — https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/ 2. Fortinet FortiWeb auth bypass (any-password login) — CVE-2026-26035, CVE-2026-49975, CVE-2026-70465, CVE-2026-70468 — SecurityWeek — https://www.securityweek.com/fortinet-patches-authentication-flaws-in-fortiweb-and-fortimanager/ 3. City-Forum campaign reads Salesforce/ServiceNow portals as guest (block 158.220.87.79) — BleepingComputer — https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attacks-target-salesforce-servicenow-portals/ 4. WordPress Imagick RCE via crafted upload — CVE-2026-65640 — Cyber Security News — https://cybersecuritynews.com/wordpress-imagick-rce-vulnerability/ 5. Akira reboots Windows into Safe Mode to bypass EDR — Cyber Security News — https://cybersecuritynews.com/akira-uses-windows-safe-mode/ 6. LiteLLM supply-chain breach: 153GB of CI/CD secrets, 2,488 firms — Help Net Security — https://www.helpnetsecurity.com/2026/08/13/litellm-breach-stolen-credentials-leak/ 7. JWR phishing framework, live operator-steered checkout scams — Cisco Talos — https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/ 8. Phantom Stealer hides next stage in PNG files — Cyber Security News — https://cybersecuritynews.com/phantom-stealer-inside-png/ 9. 737 fake Chrome VPN extensions route traffic through one proxy — The Hacker News — https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html 10. Reasoning-API flaw lets a weaker model decode hidden reasoning — The Hacker News — https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html 11. Intel and AMD ship August patches for 80+ vulnerabilities — SecurityWeek — https://www.securityweek.com/chipmaker-patch-tuesday-intel-amd-fix-over-80-vulnerabilities-combined/

Ratings & Reviews

5
out of 5
2 Ratings

About

A daily podcast covering the important cyber security news that IT and security teams need to know.