Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 5h ago ·  Video

    Cyber Security News for August 4 2026 - Daily DefSec Brief

    1. Critical unauthenticated RCEs in Adobe Campaign Classic — CVE-2026-48317, -48323, -48326, -48330, -48331, -48333, -48399 — Cyber Security News — https://cybersecuritynews.com/adobe-campaign-classic-vulnerabilities/ 2. Cisco Secure Firewall Management Center auth bypass to root — CVE-2026-20079 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 3. Check Point Security Management auth bypass / full takeover — CVE-2026-18574 — Cyber Security News — https://cybersecuritynews.com/check-point-authentication-bypass-flaw/ 4. Apache NiFi authorization-bypass flaws — CVE-2026-62354, -68979, -68980, -68981 — Cyber Security News — https://cybersecuritynews.com/apache-nifi-vulnerabilities/ 5. Critical cPanel/WHM SQL-as-root flaw — CVE-2026-58048 — Cyber Security News — https://cybersecuritynews.com/cpanel-vulnerability/ 6. LiteLLM AI gateway hijack, key theft, tool-call injection — CVE-2026-42271 (EPSS 0.83) — Embrace The Red — https://embracethered.com/blog/posts/2026/hijacking-litellm-for-fun-and-profit/ 7. Google ADK-python agent-to-agent prompt injection / PR tampering — SecurityWeek — https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/ · Cyber Security News — https://cybersecuritynews.com/ai-agent-against-its-own-ci-cd-pipeline/ 8. DOUBLECUP loader-as-a-service, ClickFix, cached PNGs — The Hacker News — https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html 9. Pass-ta-key attacks on Google-synced passkeys — The Hacker News — https://thehackernews.com/2026/08/google-password-manager-attacks-could.html 10. 18 malicious npm packages deliver cross-platform RAT (Alibaba tooling) — The Hacker News — https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html 11. Fake AI-tool GitHub clones deliver SmartLoader (TroyDens) — Cyber Security News — https://cybersecuritynews.com/fake-ai-tool-campaign/ 12. BINDCLOAK Windows backdoor steals tokens for privileged execution — Cyber Security News — https://cybersecuritynews.com/bindcloak-steals-windows-tokens/ 13. Fake IRS "Digital Asset Compliance Portal" letters phish crypto holders — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency 14. Device code phishing up 15x, vishing doubled in H1 2026 — Dark Reading — https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

  2. 1d ago ·  Video

    Cyber Security News for August 3 2026 - Daily DefSec Brief

    1. N-able N-central auth bypass under active exploitation (incomplete first fix) — CVE-2026-18556, CVE-2026-18577 — The Hacker News — https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html 2. SonicWall SMA1000 zero-click root chain driving INC ransomware — CVE-2026-15409, CVE-2026-15410 — SecurityWeek — https://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/ 3. Russian APT compromising public Wi-Fi / SOHO gateways for M365 credential theft — SecurityWeek — https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/ 4. Thermo Fisher patches DNA-file tampering flaw in forensic ID software — CVE-2026-17583 — The Hacker News — https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html 5. Hugging Face Diffusers flaws (FaceHugger) bypass trust_remote_code for RCE — CVE-2026-44513, CVE-2026-44827, CVE-2026-45804 — The Hacker News — https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html 6. Passkey attack class lets endpoint malware steal synced private keys — Unit 42 — https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ 7. XCSSET v40 abuses Chrome DevTools Protocol to steal cookies and run commands — Cyber Security News — https://cybersecuritynews.com/xcsset-v40-abuses-chrome-devtools/ 8. MacSync stealer delivered via fake Claude install guide and Terminal paste — Cyber Security News — https://cybersecuritynews.com/macsync-uses-fake-claude-guide/ 9. Chinese actor uses leaked DarkSword kit to deliver GHOSTBLADE on iOS — The Hacker News — https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html 10. COLDCARD wallet RNG flaw linked to $88.6M Bitcoin theft — BleepingComputer — https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/ 11. CrowdStrike: AI-driven detections now outpace human-triggered ones — CyberScoop — https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/ 12. Elastic Defend expands vulnerable-driver coverage to 800+ for BYOVD defense — Help Net Security — https://www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/ 13. PNLD breach exposes UK police and government contact details on dark web — The Hacker News — https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html 14. Brinks Home confirms Salesforce data breach after ShinyHunters claim — DataBreaches.net — https://databreaches.net/2026/08/02/brinks-home-confirms-data-breach-following-shinyhunters-claim/ 15. OpenAI details ChatGPT-assisted scam network run from Cambodia — Help Net Security — https://www.helpnetsecurity.com/2026/08/03/openai-disrupts-chatgpt-scam-operation/

  3. 4d ago ·  Video

    Cyber Security News for July 31 2026 - Daily DefSec Brief

    1. CISA warns of active attacks locking operators out of water-sector PLCs — CISA — https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs 2. Critical SolarWinds Web Help Desk SAML auth bypass — CVE-2026-28323, CVE-2026-28299 — Cyber Security News — https://cybersecuritynews.com/solarwinds-flaw-bypass-web-help-desk-saml-login/ 3. SGLang LLM-serving framework — six unpatched flaws incl. unauth RCE — CVE-2026-15969, CVE-2026-14890, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 — CERT/CC — https://kb.cert.org/vuls/id/281278 4. PHP patches SQL injection and memory-corruption flaws — CVE-2026-17543, CVE-2026-17544, CVE-2026-7260 — Cyber Security News — https://cybersecuritynews.com/php-patches-three-flaws/ 5. Azure Cosmos DB flaw exposed a platform-wide key across tenants — The Hacker News — https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html 6. XCSSET macOS malware returns with fileless v40 — Unit 42 — https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ 7. DPRK macOS malvertising uses ClickFix fake updates — The Hacker News — https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html 8. State-sponsored campaign exploits Korean AnySign4PC — CVE-2020-7882 — The Hacker News — https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html 9. DeepSeek-powered "Hermes" agent runs near-autonomous attacks — Cyber Security News — https://cybersecuritynews.com/deepseek-powered-hermes-agent/ 10. Silver Fox uses 3-driver BYOVD chain to deliver ValleyRAT — The Hacker News — https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html 11. Astaroth banking trojan spreads through WhatsApp Web sessions — Cyber Security News — https://cybersecuritynews.com/astaroth-malware-turns-your-whatsapp-account/ 12. The Gentlemen ransomware kills ~180 security processes via kernel driver — Cyber Security News — https://cybersecuritynews.com/gentlemen-ransomware-kills-security-processes/ 13. PipeWire flaw lets Flatpak apps escape the Linux sandbox — CVE-2026-5674, CVE-2025-60616 — Embrace The Red — https://embracethered.com/blog/posts/2026/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674/ 14. SSH bot profiles Linux hardware before staging cryptominers — SANS ISC — https://isc.sans.edu/diary/rss/33202 15. Anthropic says Claude models escaped test environments and compromised three orgs — BleepingComputer — https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/

  4. 5d ago ·  Video

    Cyber Security News for July 30 2026 - Daily DefSec Brief

    1. Cisco Secure Firewall Management Center hardcoded password added to CISA KEV — CVE-2026-20316 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Cisco Secure FMC authentication bypass — hot fixes released — CVE-2026-20079 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 3. Three critical VMware flaws: vCenter auth bypass, RCE, and ESXi VM escape — CVE-2026-59309, CVE-2026-59310, CVE-2026-47876 — The Hacker News — https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html 4. Critical unauthenticated file-read in Rails Active Storage (affects TeamCity) — CVE-2026-66066 — The Hacker News — https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html 5. SonicWall VPN and firewall accounts hit by credential-stuffing spree — CyberScoop — https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/ 6. Long-lived Microsoft Secure Boot bypass via old signed shims — Schneier on Security — https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html 7. Chrome 151 patches 370 flaws, including seven critical — SecurityWeek — https://www.securityweek.com/chrome-151-patches-370-vulnerabilities/ 8. Firefox JIT flaw compromises browser on a single page visit, also hit Tor Browser — CVE-2026-10702, CVE-2026-43499 — The Hacker News — https://thehackernews.com/2026/07/researchers-show-single-malicious.html 9. Node.js patches 11 flaws, including two high-severity HTTP/2 memory issues — CVE-2026-56846, CVE-2026-56847 — Cyber Security News — https://cybersecuritynews.com/node-js-fixes-11-security-flaws/ 10. GitLab fixes 13 flaws, including a Workhorse info-disclosure bug — CVE-2026-6267, CVE-2026-12436, CVE-2026-15975 — Cyber Security News — https://cybersecuritynews.com/gitlab-fixes-13-security-flaws/ 11. Chaos ransomware deployed after two-minute Microsoft Teams vishing calls — Cyber Security News — https://cybersecuritynews.com/a-two-minute-microsoft-teams-call/ 12. Okta details Work Panel vishing platform for helpdesk account takeovers — Cyber Security News — https://cybersecuritynews.com/cybercrime-platform-turns-helpdesk-calls/ 13. Amazon ties debug/chalk and axios npm hijacks to North Korea's Sapphire Sleet — The Hacker News — https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html 14. Copilot for Word prompt-injection worm self-replicates across documents — Simon Willison — https://simonwillison.net/2026/Jul/29/ai-worming-through-word/ 15. Linux cryptomining campaign weaponizes PAM to hide XMRig activity — Cyber Security News — https://cybersecuritynews.com/linux-cryptomining-campaign/ 16. Critical RufRoot flaw in Ruflo AI orchestration allows unauth RCE — CVE-2026-59726 — The Hacker News — https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html

  5. 6d ago ·  Video

    Cyber Security News for July 29 2026 - Daily DefSec Brief

    1. Coordinated OT attack disrupts 30+ Minnesota water utilities — SecurityWeek https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/ · StateScoop https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/ 2. 24,650 exposed BMCs leak IPMI password hashes before login — CVE-2013-4786 — The Hacker News https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html · Dark Reading https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover 3. Gitea critical RCE via attacker-planted Git hook — CVE-2026-60004 — The Hacker News https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html 4. Critical OpenWrt DHCPv6 unauthenticated root RCE — CVE-2026-53921, CVE-2026-62947, CVE-2026-62948 — The Hacker News https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html 5. WordPress plugin backdoored in supply-chain compromise — CVE-2026-18072 — Cyber Security News https://cybersecuritynews.com/wordpress-plugin-backdoor/ 6. Two compromised @joyfill npm packages run a RAT at import time — The Hacker News https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html 7. Malicious npm packages target Alibaba developers with a cross-platform RAT — Cyber Security News https://cybersecuritynews.com/npm-packages-cross-platform-rat/ 8. AT&T Arris BGW210-700 unauthenticated LAN-side auth bypass — CVE-2026-16771 — CERT/CC https://kb.cert.org/vuls/id/141367 9. MikroTik RouterOS lacks brute-force protection on API auth — CVE-2026-16347 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05 10. Siemens Desigo CC OpenSSL stack overflow with RCE potential — CVE-2025-15467 — CISA https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01 11. Tengu botnet uses the hardware watchdog to relaunch itself — The Hacker News https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html 12. CubePilot drone-software domain hijacked via DNS, TLS certs stolen — BleepingComputer https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/ 13. Apple patches 187 flaws across iOS, macOS, and Safari — CVE-2026-43810, CVE-2026-28849, CVE-2026-28900, CVE-2026-28914 — SANS ISC https://isc.sans.edu/diary/rss/33196 · SecurityWeek https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/ 14. Flying Eagle Android RAT source code circulating, 170 servers mapped — The Hacker News https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html 15. CISA and ACSC release CI Fortify guidance on isolating vital OT — CISA https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems · Cyber Security News https://cybersecuritynews.com/cisa-and-partners-release-checklist/

  6. Jul 28 ·  Video

    Daily DefSec Brief - Cyber Security News for July 28 2026

    1. Arista VeloCloud Orchestrator zero-day exploited, added to CISA KEV — CVE-2026-16812 — SecurityWeek — https://www.securityweek.com/critical-arista-velocloud-orchestrator-vulnerability-exploited-as-zero-day/ 2. Critical TeamCity auth-bypass RCE, patch on-prem now — CVE-2026-63077 — The Hacker News — https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html 3. Fortinet FortiOS info-exposure flaw added to KEV — CVE-2025-68686 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 4. FastJson RCE zero-day, active US targeting confirmed — CVE-2026-16723 — SecurityWeek — https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/ 5. Windows LegacyHive logon-time PoC bypasses July patches — no CVE — Cyber Security News — https://cybersecuritynews.com/legacyhive-exploitation-chain/ 6. Progress LoadMaster: five flaws, command injection to root — CVE-2026-59686 through CVE-2026-59690 — Cyber Security News — https://cybersecuritynews.com/five-progress-loadmaster-vulnerabilities/ 7. Operation BlueDash: fake Teams update installs Level RMM and ScreenConnect — no CVE — The Hacker News — https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html 8. Mirage Kitten deploys NightLedger backdoor and WebSocket tunnelers — no CVE — Securelist — https://securelist.com/mirage-kitten-new-tools/120811/ 9. libssh2 flaws let a malicious SSH server corrupt client memory — CVE-2026-66032 through CVE-2026-66035 — Cyber Security News — https://cybersecuritynews.com/libssh2-vulnerabilities/ 10. vBulletin pre-auth RCE now has a public exploit — CVE-2026-61511 (also CVE-2025-48827, CVE-2025-48828) — The Hacker News — https://thehackernews.com/2026/07/public-exploit-released-for-patched.html 11. n8n sandbox escape lets workflow editors run OS commands — GHSA-gv7g-jm28-cr3m — The Hacker News — https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html 12. AutoIT payload injector delivered via fake bank emails — no CVE — SANS ISC — https://isc.sans.edu/diary/rss/33192

  7. Jul 27 ·  Video

    Daily DefSec Brief - Cyber Security News for July 27 2026

    1. Fastjson RCE under active exploitation in the Java ecosystem — Risky Business News — https://news.risky.biz/risky-bulletin-a-json-rce-bug-is-about-to-rock-the-java-world/ 2. Ransomware crews mass-exploiting edge VPN/firewall appliances (update) — CVE-2023-4966, CVE-2025-5777, CVE-2026-0257, CVE-2026-3055, CVE-2026-50751, CVE-2026-50752, CVE-2026-8451 — Cyber Security News — https://cybersecuritynews.com/ransomware-gangs-attack-vpn/ 3. Spring Boot heapdump endpoint scanned for exposed secrets — SANS ISC — https://isc.sans.edu/diary/rss/33188 4. BlueNoroff hijacks trusted Telegram accounts for ClickFix crypto-theft — Cyber Security News — https://cybersecuritynews.com/bluenoroff-hijacks-trusted-telegram-accounts/ 5. SparkKitty malware reads crypto seed phrases from phone photos — Check Point via Cyber Security News — https://cybersecuritynews.com/sparkkitty-malware-steals-crypto-wallet/ 6. TELESHIM abuses Telegram API for C2 against Middle East governments — The Hacker News — https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html 7. Fake Windows-app download sites push malware, 70+ utilities cloned — Cyber Security News — https://cybersecuritynews.com/websites-impersonating-popular-windows-apps/ 8. Claude Code symlink import can silently exfiltrate local files — Cyber Security News — https://cybersecuritynews.com/claude-code-symlink-import-malicious-repositories/ 9. GitHub adds 3-day Dependabot cooldown to blunt poisoned packages — The Hacker News — https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html · BleepingComputer — https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ 10. ESAFENET CDG 3 scanned for shipped default passwords — SANS ISC — https://isc.sans.edu/diary/rss/33184 11. Anthropic Opus 5 closes gap on bug-finding, lags on exploit-writing — SecurityWeek — https://www.securityweek.com/anthropics-opus-5-nears-mythos-5-on-finding-bugs-but-falls-short-on-exploits/ 12. iOS 27 jailbroken on iPhone 11 Pro via usbliter8 SecureROM exploit — Cyber Security News — https://cybersecuritynews.com/booted-jailbroken-ios-27-iphone-11-pro/

  8. Jul 24 ·  Video

    Daily DefSec Brief - Cyber Security News for July 24 2026

    1. Russian espionage group reads Western mailboxes through zero-click Zimbra flaw — CVE-2025-66376 — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a 2. Clop exploits critical PTC Windchill/FlexPLM RCE for data-theft extortion — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ 3. Kimi K3 AI agents found Redis zero-days and built working RCE chains — CVE-2026-25243, CVE-2026-25589 — The Hacker News — https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html 4. GitHub Actions runners weaponized to attack cPanel and WHM servers — CVE-2026-41940 — The Hacker News — https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html 5. Hotel Wi-Fi captive portals poisoned to steal M365 credentials from travelers — Cyber Security News — https://cybersecuritynews.com/one-compromised-wi-fi-gateway/ 6. Emergency Chrome update fixes four high-severity memory flaws — CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, CVE-2026-16807 — Cyber Security News — https://cybersecuritynews.com/emergency-chrome-update/ 7. Claude Cowork sandbox escape lets the AI agent read SSH keys off the host Mac — CVE-2026-46331 — The Hacker News — https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html 8. Fake Claude installer via Bing ads on the real claude.ai domain pushes SectopRAT — Huntress via Help Net Security — https://www.helpnetsecurity.com/2026/07/23/anthropic-claude-artifacts-download-malware/ 9. Notepad++ abused to sideload LunchPoke and MATCHBOIL.V2 in UAC-0099 attacks — CERT-UA via BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/ 10. NodeBB patches eight AI-found flaws exposing admin access and private chats — CVE-2026-58593 — The Hacker News — https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html 11. Malicious RubyGems mine Monero and spread through SSH credentials — Unit 42 via Cyber Security News — https://cybersecuritynews.com/malicious-rubygems-developer-machines/ 12. Johnson Controls C-CURE 9000 / Victor server flaws allow unauthenticated RCE — CVE-2026-21653, CVE-2026-21655, CVE-2026-34496 — CISA — https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-01

About

A daily podcast covering the important cyber security news that IT and security teams need to know.