Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 16h ago ·  Video

    Cyber Security News for September 18 2026 - Daily DefSec Brief

    1. Cisco ISE zero-day exploited for full control — CVE-2026-76460 — Do: Upgrade ISE, grep access.log on every node — https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/ 2. Stolen key rewrote vendor scripts at the edge — Do: Check 14 September traffic, hunt long-lived API keys — https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/ 3. Acronis backup flaw confirmed exploited — CVE-2026-87886 — Do: Upgrade the Acronis plugin to 1.9.3 HF3 — https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/ 4. A long username gets root on Check Point — CVE-2026-91843 — Do: LivePatch Check Point, tighten Trusted Clients — https://thehackernews.com/2026/09/critical-check-point-management-server.html 5. Fake video calls target Rust crate owners — Do: Never install or paste during an unexpected call — https://simonwillison.net/2026/Sep/17/targeted-attacks-on-rustaceans/ 6. Docker sandbox escapes onto the macOS host — CVE-2026-77179 — Do: Upgrade Docker Sandboxes to 0.42.0 — https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html 7. Malicious zone runs code on your resolver — CVE-2026-81642 — Do: Upgrade Unbound to 1.26.1 — https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html 8. One DoH request crashes BIND's named — CVE-2026-77692 — Do: Upgrade BIND to 9.21.26 or 9.20.29 — https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/ 9. Android malware enables its own debug shell — Do: Alert on Developer Options being enabled — https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ 10. First AI-agent breach reported to a regulator — Do: Check your breach template covers agent-run attacks — https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data 11. One in eight MCP config slots holds a secret — Do: Search repos for MCP config files, rotate keys — https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/

  2. 2d ago ·  Video

    Cyber Security News for September 16 2026 - Daily DefSec Brief

    1. WSO2 API gateway takes a forged admin token — CVE-2026-5430 — Do: Apply the WSO2 update level, rotate gateway secrets — https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/ 2. Pixel modem zero-day used in targeted attacks — CVE-2026-58704 — Do: Push Pixel to the 2026-09-05 patch level — https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/ 3. Malware forges Chrome's extension integrity hashes — Do: Allowlist extensions, alert on developer mode — https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html 4. Logitech Options+ gives a normal user SYSTEM — CVE-2026-12518 — Do: Upgrade Logi Options+ fleet-wide — https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options+-for-system-shells/ 5. GlobalProtect privesc needs a PAN-OS upgrade too — CVE-2026-0307 — Do: Upgrade the app and PAN-OS together — https://security.paloaltonetworks.com/CVE-2026-0307 6. Parallels Desktop gives a local Mac user root — CVE-2026-90894 — Do: Upgrade Parallels Desktop to 27.0.0 — https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/ 7. Oracle's September update covers 672 flaws — Do: Patch E-Business Suite first — https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves 8. Four of 800 hit their recovery target — Do: Run one full restore end to end — https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/ 9. Gambling sites doubling as C2 infrastructure — Do: Re-examine gambling-domain hits in proxy logs — https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652 10. Fraudulent hires get credentials before detection — Do: Verify identity when credentials are issued — https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/ 11. Most Mythic C2 servers keep the default cert — Do: Alert on O=Mythic certificates and port 7443 — https://censys.com/blog/mythic-c2/

  3. 3d ago ·  Video

    Cyber Security News for September 15 2026 - Daily DefSec Brief

    1. Cisco email gateway zero-day exploited for root — CVE-2026-76461, CVSS 9.8 — Do: Upgrade AsyncOS 16.5.0-780, grep mail_logs — https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/ 2. Vite dev servers scanned for cloud credentials — CVE-2026-39364, CVSS 7.5 — Do: Upgrade Vite to 7.3.2 or 8.0.5 — https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/ 3. AI agents ran a credential campaign in six hours — Do: Shorten cloud key lifetimes and alert on scanning — https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html 4. LiteSpeed flaw takes a hosting account to root — no CVE assigned — Do: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 — https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html 5. Apple patches 261 flaws across every OS — Do: Update Mac security tools before macOS 27 — https://isc.sans.edu/diary/rss/33336 6. Homebrew 7.0.0 closes a sudo path in casks — Do: Install Homebrew 7.0.0 on developer Macs — https://www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/ 7. MeshCentral used as the backdoor at a broadband ISP — CVE-2024-21762 in the toolkit — Do: Hunt for RMM agents you never deployed — https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html 8. AWS TEAM grants access it was not asked for — CVE-2026-86830, CVSS 7.2 — Do: Upgrade TEAM to 1.5.1, forks included — https://aws.amazon.com/security/security-bulletins/rss/2026-112-aws/ 9. An unpatched VPN cost Japan 246,000 records — Do: Alert on bulk file reads by service accounts — https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html 10. Office update breaks copy and paste in Excel — Do: Warn the help desk about KB5002914 — https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/ 11. WordPress scans plugin updates before shipping — Do: Leave WordPress plugin auto-updates on — https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html 12. A $159 board defeats confidential computing — no CVE will be assigned — Do: Recheck what you claim confidential computing proves — https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html

  4. 4d ago ·  Video

    Cyber Security News for September 14 2026 - Daily DefSec Brief

    1. GitLab path traversal at CVSS 10, now exploited — CVE-2026-85706 — Do: Upgrade GitLab, then grep for file.path — https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/ 2. ScreenConnect file-transfer flaw now has a patch — CVE-2026-84869 — Do: Upgrade ScreenConnect to 26.6.5 — https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin 3. Artifactory chain mints admins, drops a backdoor — CVE-2026-42018, CVE-2026-42016 — Do: Patch Artifactory, audit admin accounts — https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 4. Metasploit weaponizes five KEV flaws at once — CVE-2026-20079, CVE-2026-83549, CVE-2026-63077, CVE-2026-82078, CVE-2026-19295 — Do: Patch the five KEV flaws now weaponized — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen 5. Plesk restore race gives a customer root — CVE-2026-68488 — Do: Upgrade Plesk to 18.0.80.7 — https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation 6. Dell ObjectScale unauth RCE at CVSS 10 — CVE-2026-70416 — Do: Upgrade ObjectScale to 4.4.0.0 — https://securityonline.info/dell-objectscale-vulnerabilities-cve-2026-70416/ 7. Direct Send phishing lands as internal mail — Do: Set RejectDirectSend to true in M365 — https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/ 8. Malware hosted on AI vendors' own domains — Do: Filter AI share links as user content — https://www.huntress.com/blog/ai-attack-surface 9. Fake agency request passed every email check — Do: Verify agency data requests out of band — https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/ 10. 1.8 million APKs mined for hardcoded secrets — Do: Scan your shipped mobile apps for secrets — https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ 11. Stolen police login opened a state DMV database — Do: Inventory external accounts into your systems — https://therecord.media/florida-shiny-hunters-motor-vehicle 12. Kiro wrote the edit before you approved it — CVE-2026-89332 — Do: Upgrade Kiro to 0.8.135, rotate creds — https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/ 13. 76% deployed Copilot, 43% reviewed permissions — Do: Review M365 oversharing before Copilot — https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/ 14. IT staff clicked more than any other team — Do: Include IT in phishing simulations — https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/ 15. OpenAI agent swarm ran the RubyGems attack — Do: Rotate RubyGems API keys from May — https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/

  5. Sep 11 ·  Video

    Cyber Security News for September 11 2026 - Daily DefSec Brief

    1. Two MikroTik flaws exploited, deadline Sunday — CVE-2026-86060, CVE-2026-67277 — Do: Patch RouterOS, close SSH and btest — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. WatchGuard Firebox now in ransomware — CVE-2025-14733 — Do: Upgrade Fireware to 12.5.15 or later — https://www.scworld.com/news/cisa-watchguard-firebox-bug-exploited-in-ransomware-campaigns · NVD — https://nvd.nist.gov/vuln/detail/CVE-2025-14733 3. Two 9.8s in Check Point VPN certs — CVE-2026-85102, CVE-2026-85103 — Do: Apply Check Point's 9 September VPN fixes — https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html 4. AWS SSM agent leaks instance credentials — CVE-2026-89049 — Do: Upgrade SSM Agent to 3.3.4851.0 — https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/ 5. Backup driver writes below the OS — CVE-2026-12780 — Do: Block amwrtdrv.sys, confirm Secure Boot on — https://kb.cert.org/vuls/id/687587 · NVD — https://nvd.nist.gov/vuln/detail/CVE-2026-12780 6. AI closed the detection-evasion loop — Do: Weight behavioural detection over signatures — https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ 7. BYOD calls end at the Graph API — Do: Alert on new MFA device registrations — https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data 8. IDScan confirms the licence breach — Do: Ask vendors how long they keep the scan — https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ 9. Sogou input method drops a backdoor — CVE-2026-51990 — Do: Confirm Sogou is on an April 2026 build — https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html 10. Work profiles hide a banking trojan — Do: Test your app's checks inside a work profile — https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html 11. Android ransomware plus spyware — Do: Block sideloading, alert on Accessibility grants — https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/ 12. MCP tool descriptions act as instructions — Do: Review and pin your MCP tool descriptions — https://www.scworld.com/resource/when-english-becomes-exploit-code-the-hidden-risk-inside-mcp-servers 13. Root on the node forges workload identity — Do: Shorten SPIFFE credential lifetimes — https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ 14. Passkeys move between managers — Do: Revisit passkeys now migration works — https://www.helpnetsecurity.com/2026/09/10/google-android-password-manager-transfer/ 15. Invoice fraud with an AI paper trail — Do: Call back on every payment-detail change — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/

  6. Sep 10 ·  Video

    Cyber Security News for September 10 2026 - Daily DefSec Brief

    1. Cisco firewall manager exploited to root — CVE-2026-20079 (CVSS 10.0), CVE-2026-20316 — Do: Apply the Cisco Secure FMC hotfixes now — Cisco Talos — https://blog.talosintelligence.com/fmc-ongoing-exploitation/ 2. NetScaler auth bypass now actively exploited — CVE-2026-19490 (CVSS 9.3, NVD v4.0) — Do: Upgrade NetScaler to 14.1-73.32 or 13.1-63.21 — Rapid7 — https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/ 3. Four spy crews, one shared exploit kit — CVE-2026-85046, CVE-2026-85880 — Do: Confirm Chrome 153 and September Windows landed — The Record — https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups 4. FortiOS packet flaw added to CISA KEV — CVE-2025-25249 (CVSS 8.1) — Do: Upgrade FortiOS off the affected branches — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 5. Passkey social engineering ends in cloud takeover — Do: Alert on new auth methods added to accounts — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ 6. Shai-Hulud back past npm's scan — feishu-docx-mcp, bmc-i18n-extract-cli, blueai-cli, bmc-translate-utils — Do: Rotate npm tokens, install with --ignore-scripts — Aikido Security — https://www.aikido.dev/blog/shai-hulud-npm-resurfaces 7. Phishing page assembled inside the browser — Do: Alert on OAuth redirects leaving Microsoft — Help Net Security — https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/ 8. Stealer logs yield replayable AI tokens — Do: Rotate AI provider keys after any stealer hit — https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html 9. Fortinet portal leaks a token-forging secret — CVE-2026-84390 (CVSS 9.6), CVE-2026-84388 (CVSS 9.1) — Do: Patch FortiPAM and the browser extension together — SecurityWeek — https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/ 10. Android patches 180 flaws in one month — Do: Push the September Android patch level — https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/ 11. AI workflows run on the wrong identity — Do: Run AI workflows as the requester — https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data 12. Agent could turn off its own sandbox — CVE-2026-82533 (CVSS 9.6) — Do: Update DeepSeek Harness to 0.1.2-alpha.1 — https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html 13. Scanning and brute force on Proxmox — Do: Take Proxmox port 8006 off the internet —https://isc.sans.edu/diary/rss/33324 14. Vendor credentials opened an EHR API — Do: List vendors holding API credentials to you — The Record — https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach 15. Machine identities overtake phishing — Do: Inventory and expire non-human identities — https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/ 16. Contractor's admin account outlived him — Do: Match every admin account to a current person — The Register — https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361 17. EU gives you 24 hours to report from Friday — Do: Name who files your EU 24-hour report — Dark Reading — https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements 18. Phishing from the vendor's own address — Do: List who can send mail as your domain — BleepingComputer — https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/

  7. Sep 9 ·  Video

    Cyber Security News for September 9 2026 - Daily DefSec Brief

    1. Record 974-CVE Patch Tuesday, two zero-days live — CVE-2026-81963, CVE-2026-85880 (CVSS 7.8) — Do: Install September Windows updates now — SecurityWeek — https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/ 2. Chrome 153 patches its seventh zero-day of 2026 — CVE-2026-87491 — Do: Push Chrome 153.0.8010.36, force restart — SecurityWeek — https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/ 3. F5 BIG-IP rootkit hides its web shell in memory — CVE-2025-53521 (CVSS 9.8) — Do: Patch BIG-IP APM, then hunt memory — The Hacker News — https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html 4. Defender patch bypassed again, no fix yet — CVE-2026-69414 (the bypassed fix) — Do: No fix — watch SYSTEM-level file reads — Security Affairs — https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html 5. SAP kernel flaw scores 10.0, no auth needed — CVE-2026-44756 (CVSS 10.0) — Do: Apply September SAP security notes — SecurityWeek — https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/ 6. Phishing chain hides inside Google's own redirects — Do: Hunt unauthorised ScreenConnect installs — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign 7. Ivanti patches ten flaws, two unauth RCE at 9.8 — CVE-2026-12744, CVE-2026-12745, CVE-2026-18851, CVE-2026-83527 — Do: Patch EPMM to 12.10.0.0 or 12.9.0.2 — Ivanti — https://www.ivanti.com/blog/september-2026-security-update 8. ClearFake runs its loader straight off WebDAV — Do: Block outbound WebDAV at the proxy — Cisco Talos — https://blog.talosintelligence.com/clearfake-webdav-infection-chain/ 9. New N-central chain creates its own admin account — CVE-2026-86206, CVE-2026-86207 — Do: Apply N-central 2026.3 Hotfix 3 — Rapid7 — https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed 10. FreeIPA lets an anonymous client become admin — CVE-2026-76578, CVE-2026-13097, CVE-2026-76560, CVE-2026-79678 — Do: Update FreeIPA to 4.13.4 — The Hacker News — https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html 11. Extortion crews now steal the model itself — Do: Inventory model weights as crown jewels — The Register — https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640 12. VMware Workstation and Fusion guest escapes — CVE-2026-59346, CVE-2026-59347 — Do: Update VMware Workstation and Fusion — SC World — https://www.scworld.com/brief/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities 13. Planted prompt sent ChatGPT's Gmail data elsewhere — Do: Cut ChatGPT connector scopes back — Check Point Research — https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ 14. Android RAT worms through open ADB ports — Do: Disable ADB over TCP on managed Android — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/ 15. UEFI shell in flash defeats Secure Boot — CVE-2026-20293, VU#718077 — Do: Set BIOS passwords, patch UCS firmware — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW 16. Military kills ad IDs — Do: Disable advertising IDs via MDM — Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones 17. BleachBit's shredder skipped parts of the file — Do: Update BleachBit, wipe free space — Help Net Security — https://www.helpnetsecurity.com/2026/09/09/bleachbit-6-0-4-released/

  8. Sep 8 ·  Video

    Cyber Security News for September 8 2026 - Daily DefSec Brief

    1. A maximum-severity Magento zero-day was exploited for three days before Adobe shipped a fix — CVE-2026-75650 — Do: Apply the APSB26-146 composer patch, then hunt — Adobe — https://helpx.adobe.com/security/products/magento/apsb26-146.html 2. MikroTik routers taken over through an SSH key check that ignores half the key — CVE-2026-67276, CVE-2026-67277 — Do: Update RouterOS, then audit SSH users and keys — CERT Polska — https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 3. N-able's fourth N-central hotfix in five weeks, and its own notices disagree on exploitation — CVE-2026-86218 — Do: Install N-central Hotfix 4, build 2026.3.1.14 — N-able — https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ 4. A phishing service beat MFA at 258 organisations and took 5,000 Microsoft 365 logins — Do: Move admins to phishing-resistant sign-in — BleepingComputer — https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ 5. ConnectWise has no patch for a ScreenConnect file-transfer flaw, and rogue clients are spreading malware — Do: Deselect TransferFiles on every ScreenConnect role — ConnectWise — https://www.connectwise.com/company/trust/advisories 6. Attackers are phoning executives, posing as the help desk, and walking off with the session — Do: Give the help desk a caller-verification step — The Hacker News — https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html 7. One researcher dropped zero-days for Avast, CrowdStrike and Nvidia inside a week — Do: Disable Falcon's Office macro removal for now — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/ 8. A working exploit chain for Telerik is now public, two months after the patch — CVE-2019-18935, CVE-2026-13181 — Do: Upgrade Telerik UI to 2026.2.708 or later — The Hacker News — https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html 9. A fake bookmarks extension turns Chrome and Edge into a command channel — Do: Hunt for extensions loaded outside the Web Store — The Hacker News — https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html 10. Nine years of passenger records sat in an Elasticsearch cluster anyone could reach — Do: Find search clusters answering from the internet — BleepingComputer — https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/ 11. Berlin refused a €2m ransom and Rhysida published nearly six terabytes — Do: Write down who refuses a ransom — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/ 12. An unpatched Metabase handed over a million students' details — Do: Patch and gate your self-hosted BI tools — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ 13. The NCSC says most staff are already using AI you have not approved — Do: Publish an approved AI tool people will use — NCSC — https://www.ncsc.gov.uk/blog-post/shadow-ai 14. Ransomware negotiation has turned into a business process with its own staff — Do: Work out your own ransom number first — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/ 15. A North Korean backdoor is compiled into the victim's own load balancer — Do: Verify HAProxy and daemons against their packages — Security Affairs — https://securityaffairs.com/198656/apt/north-korea-linked-hackers-hide-a-backdoor-inside-haproxy.html 16. The SEO agency poisoning your search results has been at it since 2015 — — The Hacker News — https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html

Ratings & Reviews

5
out of 5
2 Ratings

About

A daily podcast covering the important cyber security news that IT and security teams need to know.