The Digital Warfare Podcast

Digital Warfare

The Digital Warfare Podcast dives into the untold stories of digital defense. Join the anonymous hacker and his clients for raw, revealing conversations on the front lines of cybersecurity.

  1. 5h ago

    EP. 150: This Router Flaw Can Expose Everything Behind Your Firewall

    CVE-2026-75501 affects the Calix GS7 XGS GS5239XG residential gateway running affected EXOS 6.6.47 firmware. The router exposes its UPnP WANIPConnection SOAP service on the public WAN interface on TCP port 5000 without authentication. A remote unauthenticated attacker can add, remove, enumerate, or query NAT port mappings. Creating arbitrary forwarding rules can bypass the protection normally provided by the router's NAT and firewall boundary and expose internal systems such as cameras, NAS devices, and other IoT equipment directly to the internet. CERT/CC reported that it was unable to coordinate the vulnerability with Calix and that no vendor patch was available at publication. Its recommended mitigation is to disable UPnP on affected routers. Key Takeaways• CVE-2026-75501 affects Calix GS7 XGS GS5239XG residential gateways. • The vulnerable UPnP service is exposed on the WAN interface over TCP port 5000. • Exploitation can occur remotely without authentication. • Attackers can manipulate NAT port-forwarding rules and potentially expose internal LAN services directly to the internet. • Security cameras, NAS systems, IoT devices, and other internal services could consequently become reachable from outside the network. • CERT/CC reported no available vendor patch at disclosure and recommends disabling UPnP as the immediate mitigation. • There is currently no evidence in the sources reviewed that CVE-2026-75501 is being actively exploited, so the brief does not characterize this as an active-exploitation campaign. KeywordsCalix, CVE-2026-75501, GS7 XGS, GS5239XG, router vulnerability, UPnP vulnerability, NAT bypass, firewall bypass, port forwarding, MiniUPnPd, TCP 5000, residential router security, IoT security, network security, remote access, attack surface, CERT/CC, vulnerability management, Digital Warfare Podcast, cybersecurity

  2. 1d ago

    EP. 149: Hackers Can Turn a Zimbra Email Into Remote Code Execution

    SummaryCVE-2026-73570 is an actively exploited OS command injection vulnerability affecting Zimbra Collaboration Suite versions before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. The vulnerability carries a CVSS v3.1 score of 8.9. An unauthenticated attacker can send specially crafted SMTP traffic that results in arbitrary operating-system commands executing as the Zimbra user. Zimbra patched the vulnerability in version 10.1.20, released July 20. CISA added the vulnerability to its KEV catalog on August 21 after confirmed exploitation and set August 24, 2026 as the federal remediation deadline. Key Takeaways• CVE-2026-73570 is an actively exploited Zimbra OS command injection vulnerability. • It carries a CVSS score of 8.9. • Exploitation can occur remotely without authentication through specially crafted SMTP requests. • The vulnerable configuration requires the optional zimbra-snmp package and enabled SNMP notifications. • A successful attack can execute arbitrary commands with Zimbra-user privileges. • The vulnerability is fixed in Zimbra Collaboration 10.1.20. • CISA added CVE-2026-73570 to KEV on August 21 and set August 24 as the remediation deadline. • Previously exposed systems should be investigated for compromise rather than simply patched. KeywordsZimbra Collaboration Suite, Zimbra ZCS, CVE-2026-73570, Zimbra vulnerability, command injection, remote code execution, SMTP security, email security, SNMP, zimbra-snmp, CISA KEV, active exploitation, CVSS 8.9, enterprise email security, vulnerability management, incident response, threat intelligence, Digital Warfare Podcast, cybersecurity

  3. 4d ago

    EP. 148: AI-Generated Attack Code Is Now Targeting the Systems That Control Critical Infrastructure

    SummaryU.S. cybersecurity and national-security agencies have warned of an active threat targeting Siemens S7 Series PLCs in critical infrastructure. The activity affects sectors including critical manufacturing, energy, water and wastewater, chemicals, food and agriculture, and commercial facilities. Threat actors are using internet scanning to identify exposed or poorly protected controllers, exploiting weak credentials and outdated configurations, and rapidly developing attack tooling with AI assistance. Observed Python scripts incorporate the legitimate snap7.dll/python-snap7 library to communicate with Siemens controllers while masquerading as monitoring tools. The agencies assess that the activity is currently focused on reconnaissance and capability development that could prepare attackers for future operational effects. The warning is broader than Siemens alone: operators of PLC environments generally are being urged to strengthen exposure management, segmentation, authentication, patching and monitoring. Key Takeaways• NSA, CISA, FBI, DOE and EPA have jointly warned of an active threat against Siemens S7 PLC environments. • Attackers are using internet-scanning services to identify internet-exposed or insufficiently protected PLCs. • AI is being used to rapidly iterate exploitation code, reducing portions of the technical barrier associated with developing OT attack tooling. • Observed AI-generated Python scripts incorporate snap7.dll/python-snap7 and can perform read/write operations against PLCs. • Malicious tooling is being disguised as legitimate industrial monitoring software. • Current activity is assessed as persistent reconnaissance and capability development that could prepare attackers for future operational effects. • Operators should remove PLCs from direct internet exposure, strengthen credentials, patch critical vulnerabilities, segment OT networks and monitor unauthorized controller activity. KeywordsSiemens S7, Siemens PLC, programmable logic controller, PLC security, AI-generated malware, AI-assisted cyberattacks, critical infrastructure, operational technology, OT security, ICS security, industrial cybersecurity, python-snap7, snap7.dll, CISA, NSA, FBI, critical manufacturing, energy security, water infrastructure, network segmentation, industrial control systems, Digital Warfare Podcast, threat intelligence

  4. 5d ago

    EP. 147: CVE-2026-64849 Turns MLflow Into a Cloud Credential Theft Path

    SummaryCVE-2026-64849 is a critical unauthenticated SSRF vulnerability in MLflow’s webhook delivery functionality. A remote attacker can bypass URL validation using HTTP redirects or DNS rebinding, causing the MLflow server to access internal services or cloud metadata endpoints and return the response content. The flaw carries a CVSS score of 9.3. The vulnerability affects MLflow releases before 3.15.0. The corrected implementation validates the actual connection peer, including redirect destinations, closing the path to internal and metadata services. Organizations should patch immediately, inventory exposed MLflow systems, review webhook activity and outbound connections, and rotate cloud credentials where exploitation is suspected. Key Takeaways• CVE-2026-64849 is a critical MLflow SSRF vulnerability rated CVSS 9.3 • The attack requires no authentication or user interaction on vulnerable default deployments • HTTP redirects can bypass the original destination validation • Attackers may read responses from cloud metadata services and internal-only systems • Cloud IAM credentials exposed through metadata services may expand the compromise beyond MLflow • All MLflow deployments before 3.15.0 should be upgraded • Exposed systems require investigation, credential review, IAM auditing, and network-access validation KeywordsMLflow, CVE-2026-64849, MLflow vulnerability, SSRF, server-side request forgery, cloud credential theft, IAM credentials, cloud metadata, MLOps security, AI infrastructure security, webhook security, internal network access, CVSS 9.3, cloud security, vulnerability management, incident response, Digital Warfare Podcast, cybersecurity, threat intelligence

  5. Aug 17

    EP. 146: How a Private APN Became a Backdoor Into a Polish Power Plant

    SummaryA destructive cyberattack against a Polish combined heat and power facility demonstrated a previously undocumented attack path through a private cellular APN. The attackers first compromised infrastructure at a separate wind farm, accessed a cellular router, tunneled into the private APN, discovered a WAGO PLC at the CHP plant, and used that controller as a gateway into the plant’s OT network. After roughly a week of reconnaissance, the attackers manipulated Siemens PLCs, shutting down a steam turbine and process-water treatment system. Operators restored operations before customers lost heat or electricity. Attackers also altered industrial network devices and deliberately damaged equipment and logs to obstruct investigation and recovery. The incident demonstrates why private APNs must not automatically be treated as trusted networks. Industrial operators should apply segmentation, client isolation, strict allowlisting, credential hygiene, centralized logging, and continuous monitoring to any network providing connectivity into OT environments. Key Takeaways• Attackers moved from a compromised wind-farm network into a separate energy facility through a private APN • Investigators believe this is the first publicly documented real-world cyberattack using a private APN as an OT lateral-movement path • A Teltonika cellular router was used to establish an SSH tunnel into the private APN • A WAGO PFC200 controller using default administrator credentials became the next pivot into the CHP plant’s OT network • Attackers manipulated Siemens PLCs and shut down a steam turbine and water-treatment process • Industrial networking equipment was deliberately reconfigured and damaged to slow recovery and destroy evidence • Private APNs should be treated as untrusted networks and protected through segmentation, client isolation, allowlisting, monitoring, and strong credential controls Keywordsprivate APN attack, Polish energy cyberattack, operational technology security, OT security, ICS attack, SCADA security, WAGO PFC200, Siemens PLC, FortiGate, Teltonika RUTX50, SSH tunneling, lateral movement, industrial sabotage, private cellular network, critical infrastructure, network segmentation, default credentials, energy sector cybersecurity, Digital Warfare Podcast, threat intelligence

  6. Aug 14

    EP. 146: CRPx0 Is Rewriting the Ransomware Business Model

    SummaryCRPx0 has emerged as a rapidly expanding ransomware operation, increasing from fewer than 10 claimed victims in June to 46 claimed victims in July 2026. Across the wider ransomware ecosystem, 873 claimed victims were recorded during July, reportedly the third-highest monthly level over the previous 12 months. These figures are based on ransomware claims and should not be interpreted as independently confirmed breaches. Technical research shows that CRPx0's capabilities extend beyond encryption. Its multi-stage architecture can target Windows and macOS, maintain C2 communications, steal cryptocurrency through clipboard manipulation, search for wallet recovery phrases, exfiltrate valuable files, and ultimately perform double-extortion ransomware attacks. Its emerging white-label model is particularly important because it could make attribution based on ransomware branding less reliable. Defenders should therefore prioritize behavioral detection over identifying individual ransomware families. Key Takeaways• CRPx0 reportedly increased from fewer than 10 claimed victims in June to 46 in July. • The wider ransomware ecosystem recorded 873 claimed victims in July, although leak-site claims should not automatically be treated as verified breaches. • CRPx0 uses a multi-stage architecture capable of targeting Windows and macOS systems. • Its capabilities include cryptocurrency clipboard hijacking, recovery-phrase harvesting, data exfiltration, command and control, persistence, and ransomware deployment. • CRPx0 combines multiple monetization mechanisms rather than relying exclusively on file encryption. • Its reported white-label RaaS approach could make individual incidents appear unrelated even when they share underlying criminal infrastructure. • Security teams should hunt attacker behaviors rather than relying primarily on ransomware family names. KeywordsCRPx0, CRPx0 ransomware, ransomware, ransomware-as-a-service, RaaS, white-label ransomware, double extortion, cryptocurrency theft, clipboard hijacking, seed phrase theft, Python malware, data exfiltration, cross-platform malware, Windows malware, macOS malware, ransomware affiliates, threat intelligence, incident response, Digital Warfare Podcast, cybersecurity

  7. Aug 13

    EP. 145: VMware vCenter Under Attack: CVE-2026-59310 Enables Persistent Access

    SummaryCVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter Server’s Syslog component that can allow a remote attacker with network access to execute arbitrary code. Broadcom rates the flaw CVSS 9.8 and provides no workaround, making patching the required remediation. Active exploitation began shortly after the July 29 disclosure. More than 360 compromised IP addresses were subsequently observed across 47 countries, with attackers deploying the open-source reverse_ssh framework to establish persistent outbound command-and-control access. Organizations should patch immediately and investigate exposed vCenter systems for suspicious binaries, outbound SSH connections, unauthorized administrative activity, and evidence that attackers accessed ESXi hosts, virtual machines, credentials, or other connected infrastructure. Key Takeaways• CVE-2026-59310 affects VMware vCenter Server’s Syslog component. • Broadcom assigns the vulnerability a CVSS score of 9.8. • Attackers with network access to vCenter can exploit the flaw to execute arbitrary code without authentication. • Active exploitation began within days of the vulnerability’s public disclosure. • More than 360 compromised IP addresses across 47 countries have been observed, although IP counts do not equal confirmed victim organizations. • Attackers are deploying reverse_ssh to create persistent outbound remote-access channels. • Broadcom provides no workaround, so affected organizations must patch and investigate for compromise. KeywordsVMware vCenter, CVE-2026-59310, vCenter vulnerability, VMware RCE, directory traversal, reverse SSH, reverse_ssh, CVSS 9.8, active exploitation, virtualization security, ESXi security, management plane compromise, remote code execution, persistence, incident response, vulnerability management, Digital Warfare Podcast, cybersecurity, threat intelligence

  8. Aug 11

    EP. 144: The Metabase Zero-Day That Turns Analytics Into a Database Attack Path

    SummaryAn actively exploited Metabase vulnerability tracked as GHSA-vwf4-m7j8-wcjf allows unauthenticated remote attackers to inject arbitrary SQL into the platform’s application database. The issue carries a CVSS 10.0 rating and currently has no assigned CVE identifier. Successful exploitation can provide administrator access, allow configuration changes, expose credentials for connected databases, and enable attackers to read or export data reachable through those connections. The vendor has confirmed active exploitation. Organizations should upgrade to the fixed release for their branch immediately. Systems with the vulnerable endpoint exposed publicly should also undergo session revocation, API-key review, administrator auditing, database credential rotation, and investigation of query and warehouse logs. Key Takeaways• GHSA-vwf4-m7j8-wcjf is a critical unauthenticated SQL injection vulnerability affecting Metabase • The vulnerability carries the maximum CVSS score of 10.0 • No CVE identifier has been assigned at the time of this briefing • Active exploitation has been confirmed by the vendor • Successful exploitation can lead to Metabase administrator access • Attackers may obtain stored credentials for connected databases and access data beyond the Metabase platform itself • Fixed releases are x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5 KeywordsMetabase, GHSA-vwf4-m7j8-wcjf, Metabase zero-day, SQL injection, unauthenticated SQL injection, CVSS 10.0, active exploitation, business intelligence security, database credential theft, administrator access, data exfiltration, database security, application security, vulnerability management, incident response, Digital Warfare Podcast, cybersecurity, threat intelligence

About

The Digital Warfare Podcast dives into the untold stories of digital defense. Join the anonymous hacker and his clients for raw, revealing conversations on the front lines of cybersecurity.