Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 23h ago ·  Video

    Daily DefSec Brief - Cyber Security News for July 21 2026

    1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/ 2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/ 3. Fake CAPTCHA lures trick users into running PowerShell — Sandworm (UAC-0145) — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself 4. Zimbra patches critical unauthenticated command injection and XSS flaws — CVE-2026-10631, CVE-2026-50054, CVE-2026-50055 — SecurityWeek — https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/ 5. Gitea authorization bypass lets public tokens write to private repos and trigger Actions — CVE-2026-58443 — Cyber Security News — https://cybersecuritynews.com/gitea-vulnerability/ 6. HollowGraph implant uses Microsoft 365 calendar events as its C2 channel — The Hacker News — https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html 7. Telegram-bot backdoors planted in Middle Eastern government networks — Cyber Security News — https://cybersecuritynews.com/hackers-telegram-bots-secret-backdoor/ 8. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — The Hacker News — https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html 9. Exposed WebDAV server exposes AI-assisted malware "delivery lab" — CVE list to verify against primary report — Rapid7 — https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis 10. Sandbox escapes hit Cursor, Codex, Gemini CLI, and Antigravity — CVE-2026-48124 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/ 11. OpenSSL silently patches "HollowByte" pre-handshake memory-exhaustion DoS — SecurityWeek — https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/ 12. Linux kernel ships 400+ CVE fixes in about 24 hours — CVE-2026-64122 and others (representative) — Cyber Security News — https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/

  2. 1d ago ·  Video

    Daily DefSec Brief - Cyber Security News for July 20 2026

    1. ServiceNow AI Platform RCE now under active exploitation — CVE-2026-6875 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/ 2. WP2Shell — WordPress core flaws exploited within hours — CVE-2026-60137, CVE-2026-63030 — SecurityWeek — https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/ 3. Chrome 150 patches seven memory-safety bugs, three critical — SecurityWeek — https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/ 4. SleeperGem — malicious RubyGems impersonate git_credential_manager — The Hacker News — https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html 5. OTTERCOOKIE hides in SVG images in fake coding-test lure — Cyber Security News — https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/ 6. Solo threat actor uses Gemini CLI to run a small botnet — The Hacker News — https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html 7. Hugging Face breached by an autonomous AI agent — SecurityWeek — https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/ · The Hacker News — https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html 8. GoldenEyeDog breach at DigiCert hijacks code-signing certificates — Cyber Security News — https://cybersecuritynews.com/goldeneyedog-behind-digicert-breach/ 9. Microsoft confirms WSUS sync delays blocking patch deployment — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/ 10. Out-of-band update fixes Dell shutdown bug from July Windows update — KB5121767 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/ 11. Windows 10 still on 17% of devices, most excluded from free ESU — Help Net Security — https://www.helpnetsecurity.com/2026/07/20/windows-10-support-risks-report/

  3. 5d ago ·  Video

    Daily DefSec Brief - Cyber Security News for July 16 2026

    1. CISA adds actively exploited Oracle E-Business Suite flaw to KEV, feds have until Saturday — CVE-2026-46817 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/ 2. Zoom patches critical Windows account-takeover flaw — CVE-2026-53412, CVE-2026-53409, CVE-2026-53410, CVE-2026-53411 — BleepingComputer https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ · The Hacker News https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html 3. F5 ships out-of-band patch for critical NGINX flaw — CVE-2026-42533 — SecurityWeek https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/ 4. Russian-speaking group trojanizes WebEx, Zoom, MobaXterm installers to push Starland RAT — UAT-11795 — Cisco Talos https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ · BleepingComputer https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/ Also mentioned: - New Spirals ransomware encrypts victim network in under 24 hours — BleepingComputer https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/ - JetBrains patches six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA — Cyber Security News https://cybersecuritynews.com/jetbrains-patched-vulnerabilities/ - Cisco patches authenticated privilege-escalation chain in Catalyst SD-WAN — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx - Firefox and Chrome ship critical patches, two Firefox bugs with public exploit code — The Hacker News https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html

  4. 6d ago ·  Video

    Daily DefSec Brief - Cyber Security News for July 15 2026

    1. CISA adds SharePoint and AD FS zero-days to KEV, deadline Friday — CVE-2026-56164, CVE-2026-56155 (also CVE-2026-32201, CVE-2026-45659, CVE-2026-58644, CVE-2026-55040) — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · CISA advisory https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations · Rapid7 https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed 2. SonicWall SMA1000 flaws added to KEV, same Friday deadline — CVE-2026-15409, CVE-2026-15410 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. Progress confirms ShareFile zero-day, patches out, service restored — CVE TBD (see Progress advisory) — BleepingComputer https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ · SecurityWeek https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/ 4. Cursor IDE auto-runs a malicious git.exe on opening a repo — no CVE assigned — The Hacker News https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html · Dark Reading https://www.darkreading.com/application-security/cursor-ide-malicious-code-poisoned-repos Also mentioned: - RabbitMQ patches OAuth-secret and cross-tenant queue flaws — The Hacker News https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.html - ESET finds 11 Microsoft-signed Linux UEFI shims bypassing Secure Boot — The Hacker News https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html - Compromised @asyncapi npm packages shipping a botnet loader — The Hacker News https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html - Adobe patches eight critical ColdFusion vulnerabilities — SecurityWeek https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/

  5. Jul 14 ·  Video

    Daily DefSec Brief - Cyber Security News for July 14 2026

    1. CISA adds 18-year-old Cisco IOS flaw to KEV catalog — CVE-2008-4128 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Microsoft maps a year of ShinyHunters-style OAuth abuse against Salesforce and SaaS apps — no CVE — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/ 3. SAP patches critical NetWeaver memory corruption flaw — CVE-2026-44747 (CVSS 9.9) — Cyber Security News — https://cybersecuritynews.com/sap-security-update-july-2026/ 4. ServiceNow fixes unauthenticated sandbox-escape RCE in AI Platform — CVE-2026-6875 — Cyber Security News — https://cybersecuritynews.com/servicenow-remote-malicious-code/ Also mentioned: - Google and Microsoft pull ModHeader extension over hidden history collector — The Hacker News — https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html - CISA GitHub leak: admin keys and credentials exposed for six months — Krebs on Security — https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/ - 148 npm packages disguised as school Wi-Fi tools built a browser DDoS botnet — The Hacker News — https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html - Forg365 phishing-as-a-service targets Microsoft 365 — The Hacker News — https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html

  6. Jul 11

    DefSec Brief week in review, July 11 2026

    1. Langflow authorization bypass on KEV, plus the first fully autonomous LLM-driven ransomware campaign — CVE-2026-55255, CVE-2025-3248 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack 2. Adobe ColdFusion path traversal added to KEV, actively exploited — CVE-2026-48282 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. CitrixBleed 2 chain confirmed as a path to Dragonforce ransomware — CVE-2025-5777, CVE-2023-4966, CVE-2026-4368 — Huntress https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware 4. BeyondTrust patches critical pre-auth bypass flaws in Remote Support and PRA — CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141 — The Hacker News https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html 5. Progress orders on-prem ShareFile customers to shut down Storage Zone Controllers — CVE not confirmed by vendor — The Hacker News https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html · Cyber Security News https://cybersecuritynews.com/progress-sharefile-admins-shut-down-servers/ 6. CISA adds four Joomla/WordPress extension file-upload flaws to KEV — CVE-2026-56291, CVE-2026-48939, CVE-2026-48908, CVE-2026-56290 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog 7. Exposed WP-SHELLSTORM server reveals webshell brokerage hitting 1.4M sites — CVE-2026-48907, CVE-2026-3844 (among others) — The Hacker News https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html 8. Suspected China-aligned group exploits Roundcube flaws against university research departments — CVE-2024-42009, CVE-2025-49113 — CyberScoop https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/ · The Hacker News https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html 9. Cisco patches RCE and file-read flaws in ISE and Catalyst Center — CVE-2026-20181, CVE-2026-20190, CVE-2026-20191 — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv · https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X 10. 16-year-old Linux KVM use-after-free lets a guest VM escape to the host — CVE-2026-53359 "Januscape" — The Hacker News https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html

About

A daily podcast covering the important cyber security news that IT and security teams need to know.