The Defensive Line Podcast

The Defensive Line

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com

  1. The Defensive Line Weekly Podcast 023

    1d ago

    The Defensive Line Weekly Podcast 023

    The Defensive Line Weekly podcast is the audio version of the weekly Defensive Line Substack intelligence summary. Written by humans but read by AI. It turns the week’s key cyber stories into a practical conversation between Carter and Lizzie. FortiBleed and edge credential exposure * CISA — CISA urges hardening Fortinet devices after reports of credential exposure * NCSC — Advice following global targeting of Fortinet firewalls and VPN gateways * The Hacker News — CISA warns Fortinet customers as compromised credentials leak Klue, OAuth tokens and SaaS integration risk * Huntress — Klue breach investigation * Klue — Update on recent Klue security incident * The Hacker News — Salesforce disables Klue app * BleepingComputer — Klue OAuth breach linked to Icarus Salesforce data theft attacks Mastra, AutoJack and trusted tooling * Microsoft Threat Intelligence — Postinstall payload inside Mastra npm supply chain compromise * Microsoft Defender Security Research — AutoJack: single-page RCE on host running AI agent * BleepingComputer — Microsoft links Mastra AI supply-chain attack to North Korean hackers * The Hacker News — 144 Mastra npm packages compromised * The Hacker News — AutoJack attack lets one web page execute code * BleepingComputer — Microsoft fixes AutoGen Studio flaw Honourable mentions * ESET Research — Killing me gently: inside Gentlemen’s EDR killer framework * The Hacker News — F5 patches two critical NGINX Open Source flaws * The Hacker News — Hackers exploit Gravity SMTP WordPress plugin * Dark Reading — Novo Nordisk breach exposes dev pipeline risk * The Hacker News — Operation Endgame disrupts SocGholish * The Hacker News — AryStinger malware infects legacy D-Link routers This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    13 min
  2. The Defensive Line Weekly Podcast 019

    May 27

    The Defensive Line Weekly Podcast 019

    Story 1: Developer Supply Chains Under Sustained Assault * OX Security — TeamPCP / GitHub breach * StepSecurity — Nx Console VS Code extension * GitHub Security Blog — Investigating unauthorised access * SafeDep — Megalodon mass GitHub repo backdooring * StepSecurity — Megalodon CI/CD secrets exfiltration * Aikido Security — Laravel-Lang supply chain attack * Snyk — Laravel-Lang supply chain advisory * The Hacker News — Packagist supply chain attack * Socket — TrapDoor cross-ecosystem campaign Story 2: Kali365 — FBI Warns of oh-auth Token Theft Platform * FBI IC3 Public Service Announcement * Arctic Wolf — Kali365 token and session theft * The Record — FBI warns of Kali365 * Microsoft — Protect against consent phishing * Microsoft — Configure user consent * Microsoft — Block device-code flow with Conditional Access Story 3: A Zombie Account Hands Over the Water Supply * The Register — Zombie user account let hackers control the city’s water Honourable Mentions * Check Point Research — Nimbus Manticore operations during the Iranian conflict * Microsoft Security Blog — Fox Tempest malware-signing service * Malwarebytes — NYC Health + Hospitals breach * Aikido Security — Google API key 23-minute deletion window * MSRC — Microsoft Defender CVE-2026-41091 * Dark Reading — Microsoft Exchange OWA zero-day This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    15 min
  3. The Defensive Line Weekly Podcast 016

    May 6

    The Defensive Line Weekly Podcast 016

    The Defensive Line Weekly is a podcast version of our weekly Substack intelligence summary — the security stories that matter most for blue teamers and security leaders, with clear implications and practical defensive actions. AI voices are used, but the content is human curated and written with the support of AI. Topic 1: Helpdesk Impersonation Continues to Succeed * CrowdStrike — Cordial Spider adversary profile * CrowdStrike — Snarky Spider adversary profile * Google / Mandiant GTIG — Expansion of ShinyHunters SaaS data theft * Unit 42 / RH-ISAC — Extortion in the enterprise: defending against BlackFile attacks * CyberScoop — CrowdStrike names Cordial Spider and Snarky Spider Topic 2: cPanel & WHM and CopyFail cPanel / WHM CVE-2026-41940 * watchTowr Labs — cPanel WHM authentication bypass * cPanel vendor advisory — 28 April 2026 * Censys — The cPanel situation * Help Net Security — cPanel zero-day exploited * Rapid7 — CVE-2026-41940 ETR CopyFail CVE-2026-31431 * Wiz Research — CopyFail Linux privilege escalation * Ubuntu security advisory * AlmaLinux blog * Red Hat CVE advisory * Microsoft Security Blog — CopyFail cloud and Kubernetes impact * CERT-EU SA 2026-005 Topic 3: Three Supply Chain Attacks in One Week * SentinelOne — Week 18 supply chain roundup * Aikido Security — PyTorch Lightning PyPI compromise * Socket — PyTorch Lightning compromised * The Hacker News — Poisoned Ruby gems and Go modules * The Hacker News — PyTorch Lightning supply chain * The Register — SAP npm supply chain Honourable Mentions * TRM Labs — North Korea 2026 crypto theft * Arctic Wolf — BlueNoroff ClickFix and AI-generated Zoom lures * NCSC — AI-driven patch wave warning * Fortinet PSIRT FG-IR-26-100 * Fortinet PSIRT FG-IR-26-112 * The Register — Gemini CLI critical RCE This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

    16 min

About

The Defensive Line Weekly delivers actionable cybersecurity intelligence every week, translating the latest threats, vulnerabilities, and breaches into practical defensive advice for blue teamers. Subscribe for prioritised security recommendations that work for organisations of all sizes—curated and analysed by experienced security practitioners. thedefensiveline.substack.com