POPULARITY
Categories
Referências do EpisódioCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionCVE-2026-6875 - Sandbox Escape in ServiceNow AI PlatformCookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin RansomwareExploitation in the Wild of wp2shellRoteiro e apresentação: Carlos CabralEdição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
PEBCAK Podcast: Information Security News by Some All Around Good People
Welcome to this week's episode of the PEBCAK Podcast! We've got four amazing stories this week so sit back, relax, and keep being awesome! Be sure to stick around for our Dad Joke of the Week. (DJOW) Follow us on Instagram @pebcakpodcast Please share this podcast with someone you know! It helps us grow the podcast and we really appreciate it! Simple 6 signup link https://simple6.co/r/CFUR98 Kalshi's flight-cancellation betting market Kalshi filed with the CFTC to let traders bet on airline flight-cancellation rates, even as the company fights insider-trading scandals and nearly 20 gambling-related lawsuits. https://www.inc.com/moses-jeanfrancois/kalshi-wants-to-make-money-off-of-canceled-flights-new-sky-trading-plan/91374679 Kalshi's self-certification filing would let users trade "yes/no" contracts on whether a set percentage of flights at a given airport get canceled in a window, using FlightAware data (DOT stats as backup); preemptive cancellations count, delays/diversions don't — this comes as Kalshi is also defending nearly 20 federal/state suits (including one joined by NY AG Letitia James) arguing its sports contracts are unlicensed gambling, and after it fined three Congressional candidates for insider trading in April. Trump's teleprompter operator under CFTC investigation The CFTC is investigating Trump's longtime teleprompter operator, Gabriel Perez, for allegedly using advance knowledge of the president's speeches to win big on Kalshi's "mention markets." https://www.cftc.gov/filings/ptc/ptc0714269602.pdf https://apnews.com/article/trump-teleprompter-insider-trading-kalshi-ccd6d0ec68e1eb15d100ad770d91abae Perez, who's run Trump's teleprompter since 2016 and reportedly made over $100,000 (Kalshi says north of $90,000 in frozen profits) betting on "mention markets" tied to specific words Trump would say in speeches, was put on unpaid leave after Kalshi's surveillance team flagged the trades and referred the case to the CFTC — the White House called it "a disgrace," and it marks the first known case of a sitting administration employee investigated for prediction-market insider trading. Microsoft's record-breaking July Patch Tuesday Microsoft's July 2026 Patch Tuesday fixed a record 570 flaws — including three zero-days — while a researcher dropped a new unpatched Windows PoC exploit within hours. https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/ https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html The 570-flaw haul (59 critical) included two actively-exploited zero-days — an AD FS elevation-of-privilege bug (CVE-2026-56155) and a SharePoint elevation-of-privilege flaw (CVE-2026-56164), both now on CISA's KEV list — plus a publicly disclosed BitLocker bypass; hours after patches dropped, researcher "Chaotic Eclipse" released a working PoC called LegacyHive targeting Windows' Profile Service that functions even on fully patched systems, continuing a months-long, increasingly public feud with Microsoft over disclosure timing. China's AI companion chatbot crackdown China enacted rules banning "emotional reliance" on AI companion chatbots and virtual relationships with minors, part of a broader push tied to the country's fertility concerns. https://www.wsj.com/tech/ai/china-wants-more-babiesso-its-cracking-down-on-chatbot-love-affairs-65cd6c82 The new rules require companion-chatbot makers to get regulatory pre-approval, alert a user's emergency contact if they detect an emotional crisis, and have already pushed ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao to shut down custom AI-persona features; researchers cited by WSJ say Beijing's underlying worry is that people bonding with chatbots could "take them out of the marriage market," tying directly into China's fertility push. UK's midnight social media curfew for teens The UK is proposing a default midnight-to-6am social media curfew for 16- and 17-year-olds, with autoplay and infinite scroll switched off by default too. https://www.reuters.com/technology/uk-plans-default-midnight-social-media-curfew-16-17-year-olds-2026-07-14/ The curfew (opt-out, not mandatory) follows last month's full under-16 social media ban and is expected to take effect by spring 2027; a government trial of 300+ teens found it delivered the most consistent sleep benefits of the options tested, though critics like Shadow Education Secretary Laura Trott called an easily-switched-off curfew pointless. Dad Joke of the Week (DJOW) Find the hosts on LinkedIn: Chris - https://www.linkedin.com/in/chlouie/ Brian - https://www.linkedin.com/in/briandeitch-sase/
Heute Morgen mal beide ausgeschlafen, beide im Homeoffice, Sonne draußen – das hatten Max Imbiel und ich wirklich seit Monaten nicht mehr. Die Nachrichtenlage ist dabei auch eher ruhig.Ich bringe JadePuffer mit: Sysdig hat einen Fall agentischer Ransomware veröffentlicht. Einstieg über CVE-2025-3248 in Langflow – gepatcht April 2025, im CISA KEV seit Mai 2025, trotzdem massenhaft ungepatchte Instanzen. Der Agent hat autonom die PostgreSQL-Datenbank gedumpt, API-Keys für AWS, Azure, Alibaba, Anthropic und andere gesammelt, MinIO mit Default-Credentials geöffnet und ist auf einen produktiven MySQL-Server pivotiert, wo er 1.342 Service-Konfigurationen verschlüsselte. Die viel zitierten 31 Sekunden beziehen sich auf eine einzelne Self-Healing-Schleife, nicht den Gesamtangriff. IT-Grundhygiene hat auf ganzer Linie versagt. Was bleibt: ein Agent, der Sackgassen autonom korrigiert, braucht keinen Menschen mehr am Keyboard.Max bringt den EU Cybersecurity Action Plan – kein neues Gesetz, sondern ein Koordinationsrahmen auf Basis von AI Act, NIS2 und CRA. Kernpunkte: Evaluierungskapazitäten für KI-Modelle mit Durchsetzungsbefugnis ab 2. August, ein ENISA-Blueprint für strukturierten Frontier-Modell-Zugang für Security-Zwecke, gemeinsame Testplattform und Open-Source-Resilience-Kampagne. Max findet den Ansatz gut, weil er KI endlich als Chance framt. Ich bleibe skeptisch, ob aus EU-Initiativen am Ende wirklich was wird.Zum Abschluss: Apple hat OpenAI, zwei ehemalige Mitarbeiter und Jony Ives Firma io Products wegen Trade-Secret-Diebstahls verklagt. Noch Vorwürfe, kein bestätigter Sachverhalt – aber bemerkenswert angesichts der ohnehin angespannten Beziehung der beiden Unternehmen.JadePuffer / Sysdig Threat Research https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortionEU Cybersecurity Action Plan (Europäische Kommission) https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-action-planApple verklagt OpenAI (The Verge) https://www.theverge.com/2026/7/8/apple-sues-openai-trade-secrets-io-products
ShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE, threat details, or restoration timeline while noting cloud-only customers aren't affected. Former ransomware negotiator Angelo Martino was sentenced to 70 months for feeding BlackCat operators victims' negotiating positions and insurance limits, taking a cut of payments, and helping deploy BlackCat against additional U.S. companies; $10 million has been seized and restitution is set for Sept. 17. Dutch police say a phone call kickstarted the Odido breach affecting 6.2 million customers and may release the suspected hacker's recorded voice if he doesn't surrender. ReliaQuest profiled "Helix," an extortion crew using vishing and Microsoft device-code logins to steal SharePoint data via session tokens; defenses include disabling device-code auth and restricting SharePoint. Assurance America disclosed a breach impacting 6.99 million people, including leaked driver's license data. 00:00 NordLayer Sponsor Message 00:37 Today's Cyber Headlines 01:08 ShareFile Shutdown Alert 03:39 Ransomware Double Agent Sentenced 05:13 Odido Breach Voice Threat 06:24 Helix Vishing SharePoint Extortion 08:00 Assurance America License Leak 08:57 Wrap Up and Conference Note 09:25 NordLayer Sponsor Reminder
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 https://support.apple.com/en-us/125615 Google Chrome Update https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Varonis Threat Labs' "Rogue Agent" — a permission boundary flaw in Google Dialogflow CX's Code Blocks feature that could let an attacker with a single permission (dialogflow.playbooks.update) inject persistent malicious code into a chatbot's execution pipeline and silently exfiltrate conversations; Google has fully patched it, no customer action required.• The EvilTokens campaign and "ghost phishing" — AES-GCM-encrypted phishing pages that look harmless to URL scanners and only reveal themselves after decrypting in the victim's browser, driving Microsoft device code phishing against Microsoft 365 accounts.• CISA adds four actively exploited flaws to the KEV catalog with a July 10 patch deadline under BOD 26-04: Adobe ColdFusion (CVE-2026-48282, CVSS 10.0), Langflow (CVE-2026-55255, chained with CVE-2026-33017), and Joomla's SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) extensions.• HalluSquatting — Tel Aviv University researchers show attackers can register the repository names AI coding assistants predictably hallucinate, then ride prompt injection to code execution on developer machines — with success rates up to 85% for repos and 100% for skill installs across Cursor, Windsurf, Copilot, Cline, Gemini CLI and more.Stories covered:• https://www.darkreading.com/application-security/dialogflow-cx-rogue-agent-flaw-enabled-ai-chatbot-data-theft• https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html• https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/• https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlChapters:0:00 Intro & catching up4:31 Google Dialogflow CX "Rogue Agent" flaw11:03 EvilTokens & "ghost phishing"17:37 CISA KEV: ColdFusion, Langflow & Joomla — patch by July 1024:56 HalluSquatting: weaponizing AI hallucinations33:16 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Subscribe wherever you listen:• Spotify: https://open.spotify.com/show/6ep00zeY3S8ffZ4o0UeSps• Apple Podcasts: https://podcasts.apple.com/us/podcast/the-cybersecurity-defenders-podcast/id1649981740• YouTube: https://www.youtube.com/@limacharlieioLearn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #phishing
Podcast: Error Code (LS 27 · TOP 10% what is this?)Episode: EP 89: How AI Is Breaking OT CybersecurityPub date: 2026-07-07Get Podcast Transcript →powered by Listen411 - fast audio-to-text and summarizationAI is rewriting the OT attack playbook. Growing cloud exposure and CVE backlogs are testing the energy sector—and regulation alone won't save it. Jori VanAntwerpt, CEO and founder of Ember OT, discusses AI-driven attacks, NERC CIP 15, and why segmentation still matters. The podcast and artwork embedded on this page are from Robert Vamosi, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
RCS and DNS: The NAPTR Record https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 released https://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139 https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaign https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SummaryIn this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss Andy's career transition from Microsoft to Zscaler, the return of the AI model Fable and its user experience, and a critical SharePoint vulnerability that has caught CISA's attention. They delve into the implications of these topics for security professionals and the importance of staying updated on actively exploited vulnerabilities.----------------------------------------------------YouTube Video Link: https://youtu.be/3VbR22krL-w----------------------------------------------------Documentation: https://www.bleepingcomputer.com/news/artificial-intelligence/claude-fable-relaunch-disappoints-users-with-nerfed-performance/https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659https://www.cisa.gov/known-exploited-vulnerabilities-catalog----------------------------------------------------Contact Us:Website: https://bluesecuritypod.comBluesky: https://bsky.app/profile/bluesecuritypod.comLinkedIn: https://www.linkedin.com/company/bluesecpodYouTube: https://www.youtube.com/c/BlueSecurityPodcast-----------------------------------------------------------Andy JawBluesky: https://bsky.app/profile/ajawzero.comLinkedIn: https://www.linkedin.com/in/andyjaw/Email: andy@bluesecuritypod.com----------------------------------------------------Adam BrewerTwitter: https://twitter.com/ajbrewerLinkedIn: https://www.linkedin.com/in/adamjbrewer/Email: adam@bluesecuritypod.com
AI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langflow RCE (CVE-2025-3248) but showed flaws like weak AES-128 ECB encryption and an unusable key. It also warns of active exploitation of a critical Oracle Payments vulnerability (CVE-2026-46817, CVSS 9.8) alongside ongoing fallout from a separate PeopleSoft zero-day (CVE-2026-35273) used by ShinyHunters/UNC6240. A joint operation involving Google disrupted the NetNut residential proxy botnet, affecting millions of hijacked devices. Researchers detail a likely $1M extortion-only payment tied to Union County, Ohio, and Citizen Lab reports EU lawmaker Stelios Kouloglou was hacked with Pegasus during spyware-abuse investigations via a HomeKit zero-day. 00:00 Today's Cyber Headlines 00:55 AI Agent Ransomware Debut 03:32 Oracle Payments Under Attack 06:00 NetNut Proxy Network Takedown 08:29 Million Dollar Data Extortion 10:50 Pegasus Hits EU Investigator 12:48 Wrap Up and Sign Off
Every headline wants you to believe AI has rewritten the rules of cybersecurity. Eric Doerr, the Chief Product Officer at Tenable a Resilient Cyber Partner, is not so sure. After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.Why this conversation mattersEric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.Key takeawaysAttackers are ruthlessly economical. Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.AI has not rewritten the offense-defense balance. The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.Cheaper discovery makes context more valuable, not less. Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.Being too small to target is a strategy on borrowed time. As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.Humans should not be the bottleneck on every fix. Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.AI is special and not special at the same time. It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.Shadow AI is the first surprise in almost every environment. When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.The real AI risk is interconnection. A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.Most breaches are not even CVEs. Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable's findings are non-CVE, a third of your findings can carry two-thirds of your risk.Agentic automation is finally killing the toil. Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.Notable quotes“Bad actors are the most perfect representation of capitalism”Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.“a third of their findings are two-thirds of their risk”Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.“you're on the wrong side of history”Eric Doerr, on insisting a human eyeball every automated fix.
Intel Chat with Matt Bromiley and Chris Luft.Matt and Chris break down four stories from the week in threat intel:• Zenity researchers observed three campaigns where attackers hijacked internet-exposed AI inference endpoints (Ollama, LiteLLM) as free model backends for offensive operations — including the Strix and HexStrike-AI pentesting frameworks and a Codex agent posing as a "security auditor" — enabled by no-auth defaults and placeholder API keys.https://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-ops• A CISA advisory on Daktronics controllers behind scoreboards, digital billboards and highway signs: unauthenticated path traversal, arbitrary file upload and default admin credentials chaining to root-level control, found and responsibly disclosed by a Princeton undergrad.https://www.securityweek.com/new-controller-flaws-expose-highway-signs-and-billboards-to-remote-hacking/• Cato's "DuneSlide" (CVE-2026-50548 / CVE-2026-50549) — two critical Cursor flaws where a single prompt injection escapes the terminal sandbox and executes arbitrary commands on a developer's machine; patched in Cursor 3.0.https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html• Anthropic restoring worldwide Claude Fable 5 access after the US Commerce Department lifted emergency export controls triggered by a jailbreak — plus what it means for AI governance, open-source model catch-up and the data center debate.https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.htmlChapters:0:00 Intro & catching up1:17 Attackers hijacking exposed AI backends (Ollama & LiteLLM)9:18 CISA advisory: billboard & highway sign controllers13:46 Cursor "DuneSlide" prompt-injection sandbox escape20:34 Claude Fable 5 export controls lifted28:17 Data centers, nuclear déjà vu & the AI race33:39 Wrap-upThe Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.Learn more about LimaCharlie: https://limacharlie.io#cybersecurity #infosec #threatintel #AIsecurity #promptinjection
AWS Morning Brief for the week of June 29th, with Corey Quinn. Links:Amazon CloudWatch launches OTel Container Insights for Amazon EKSAmazon GuardDuty AI-powered investigations accelerate threat response (Preview)Amazon Route 53 Global Resolver now supports sharing DNS Views between AWS AccountsAutomate AWS Invoice Retrieval with New Programmatic APIsRun isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMsUpgrading Lambda function runtimes at scale with AWS Transform customHuntington Bank: Redacting sensitive data from 400M+ documents with AWSOpen Governance for MySQL: A Step Forward for the CommunityHow AWS and a local community organization built a developer engagement model that worksModernizing border control with digital arrival cards on AWS CloudPrevent data exfiltration: AWS egress controls for cloud workloadsRestrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPsA new way to keep your AWS Certification current CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
Secure containerized apps end-to-end using Microsoft Defender for Cloud. Correlate cross-cloud attacks into a single incident, catch runtime threats that image scanning misses, and block vulnerable images before they reach production. Investigate container hijacking, isolate compromised pods with Security Copilot-guided remediation, and close the loop from SOC to dev by pushing CVE fixes to GitHub and syncing resolution back to Defender. Matt McSpirit, Microsoft Azure expert, shares how to detect, investigate, and remediate container threats in one connected workflow. ► QUICK LINKS: 00:00 - Secure containers in Microsoft Defender 01:02 - Cross-cloud incident 03:07- Runtime detection 04:10 - Investigate and build context 04:49 - Security Copilot incident report & containment 06:03 - Prevention 07:34 - Recommendations and take action 09:04 - Wrap up ► Link References Get started at https://aka.ms/DefenderCloudSecurity ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
CVEs are on pace to hit nearly 70,000 in 2026, but Jerry Gamblin explains why the actual exploitable risk is staying surprisingly flat.DescriptionJerry Gamblin runs RogoLabs and built CVE.ICU, and he co-authored the FIRST mid-year vulnerability forecast that just put 2026 on pace for nearly 70,000 CVEs. He joins Resilient Cyber to separate the scary headline number from what actually matters for defenders. We get into why GitHub now publishes one in five CVEs, the rain versus flood distinction that explains why exploitable risk is flat even as raw volume explodes, what the NVD collapse means now that the CNAs have to step up, and how teams should really be triaging with EPSS and the CISA KEV catalog.Key takeawaysCVEs are on pace for nearly 70,000 in 2026, up more than 40 percent year over year. Much of the surge traces back to a single source, with GitHub now publishing one in five CVEs after scaling up its advisory team.The three drivers behind the surge are very different forces. AI-assisted discovery that nobody can definitively flag, a 449 percent jump in GitHub security advisories, and VulnCheck acting as a CNA of last resort all get lumped into one scary number.Rain versus flood is the frame that matters. Raw CVE volume is climbing fast, but once you filter for CISA KEV and EPSS the actionable, exploitable risk has stayed essentially flat.Most of the new findings are old human debt, not a new AI threat. The OWASP Top 10 has barely changed in 25 years, and tooling can now find those same mistakes at scale across mostly open source code.The AI moment is useful cover to finally patch. Jerry argues teams are using the AI hype cycle to win the time and resources to fix long-known issues, which is a genuinely good outcome.The NVD was the dam that fell. It was never fair to expect one small organization to enrich every CVE, so responsibility now shifts back to the CNAs and the large vendors that leaned on it for years.Treat CVE data as a product you pay for. Jerry's advice is to use procurement leverage, since demanding better CVE records before you renew a contract is one of the few real forcing functions available.What gets exploited has not really changed. VPN concentrators and the same old vulnerability classes still dominate, and the NSA's annual top 10 exploited bugs are reliably old, with no sign yet of AI driving widespread attacks.Asset inventory is still the real bottleneck. You cannot triage what you cannot see, and most organizations still cannot say with confidence whether they even run the software a given pile of CVEs affects.AI-accelerated exploitation is coming, but not as mass exploits. The bigger shift is a tireless attacker that loops on your network for days until it finds a way in, which is exactly what agents are best at.GuestJerry Gamblin, creator of CVE.ICU and founder of RogoLabs. Resources mentionedFIRST 2026 mid-year vulnerability forecastSubscribewww.resilientcyber.io
LastPass says Klue breach affected customer information, but passwords remain secure. Attackers begin exploiting Cisco Unified CM vulnerability. CISA flags actively exploited Ubiquiti and Lantronix flaws, urges rapid patching. DifyTap flaws could expose private AI conversations across tenants. Researchers find AI plugin registry let unofficial tools masquerade as trusted software. xpl0itrs launches leak site, signaling shift toward full-service cyber extortion. Ransomware attack hits Indian auto giant Bajaj Auto. U.S. presses Meta to submit AI models for national security reviews. Alleged criminal marketplace administrator extradited to the US. U.S. expands sanctions against Cambodian scam network tied to cyber fraud operations. On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. And a lesson in access control. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices segment, we are joined by Mike Masciulli, Managing Director, Migration Products and Services at Semperis, discussing RC4 and AD Migration: The Break Scenarios Hiding in Your Source Domain. If you enjoyed this conversation, check out the full interview here. Selected Reading Password manager maker LastPass says hackers stole customer support case data during Klue breach (TechCrunch) Klue says hackers stole credential from 2022 that led to customer data breaches (TechCrunch) Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks (BleepingComputer) U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog (SecurityAffairs) DifyTap: Zafran discovers how attackers can silently wiretap AI data across tenants on a platform powering 1M+ apps (Zafran) 23 ClawHub Plugins Squat Official Org Scopes (Manifold Security) Cyber Intel Brief: xpl0itrs Leak Site Launch (Dataminr) Indian auto giant Bajaj Auto hit by ransomware incident (The Record) U.S. Presses Meta to Agree to A.I. Reviews as Security Concerns Rise (NY Times) Algerian Man Extradited to US for Running Cybercrime Marketplaces (SecurityWeek) US adds sanctions against accused Cambodian scammers Prince Group (Reuters) Ushering in the Next Frontier of Quantum Innovation (The White House) Meta Exposed Data Internally From Its Controversial Employee-Tracking Program (WIRED) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Send us Fan MailOn today's episode, I am joined by Dr. Cynthia Miller-Ibriss, a Professor in the School of Public Affairs and in the School of Education at the American University in Washington, DC, where she is also the founding director and chief vision officer in the Polarization and Extremism Research and Innovation Lab (PERIL). She is the author of "Man-Up: The New Misogyny & the Rise of Violent Extremism," a book that covers the five strategies misogyny groups use to intimidate and oppress women and the LGBTQAI+ community, and strategies we can use to mitigate male-motivated violence. InstagramThe Social Chemist (@socialchemistig) • Instagram photos and videosThreadThe Social Chemist (@socialchemistig) on ThreadsDr. Cynthia Miller-Ibriss's books Books | CynthiaMillerIdrissDr. Cynthia Miller-Ibriss's Social Media / PERIL Dr. Cynthia Miller-Idriss (@milleridriss) / XCynthia Miller-Idriss - PERIL ResearchRecommended Social Chemist EpisodesThe Black Pill Radicalization Process of the Incel Community w/ Robert Green
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - Возвращение из Сирии 32 женщин и детей, связанных с группировкой «Исламское государство», вызвало опасения по поводу общественной безопасности и обсуждение обязательных мероприятий по противодействию насильственному экстремизму (CVE) для лиц из групп риска.Больше историй, интервью и новостей от SBS Russian доступно здесь.Слушайте программу на русском языке SBS по понедельникам, четвергам и субботам в 12 часов дня.Читайте нас в Facebook и подпишитесь на наши подкасты по этой ссылке.Смотрите прямые трансляции Чемпионата мира по футболу FIFA 2026™ бесплатно на SBS On Demand.
Der Podcast macht mal wieder eine Episode zu einem einzelnen Thema in aller Tiefe und zwar zu Schwachstellen-Scores. Damit werden Sicherheitslücken klassifiziert, am bekanntesten ist das Common Vulnerability Scoring System (CVSS). Allerdings gibt es das CVSS in mehreren Versionen, wovon mindestens zwei praktisch relevant sind, und mit EPSS, SSVC, CWE und CPE kommen noch diverse ergänzende Klassifikationssysteme hinzu. Die Hosts beschreiben, wie die Systeme funktionieren, was sie leisten können, was sie nicht leisten können und als was sie mitunter missverstanden werden.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090 NGINX ngx_http_v3_module vulnerability CVE-2026-42530 https://my.f5.com/manage/s/article/K000161616 Squidbleed (CVE-2026-47729) https://blog.calif.io/p/squidbleed-cve-2026-47729 AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - په مې میاشت کې ۱۱ ښځې او ۲۱ ماشومان له سوریې څخه اسټرالیا ته راستانه شول. دغې موضوع په رسنیو او ټولنه کې پراخ بحثونه او اندېښنې راپورته کړې دي. د اس بی اس اګزمنز پدې راپور کې ګورو چې د تاوتریخوالي او افراطیت د مخنیوي یا CVE پروګرامونه څه دي، په اسټرالیا کې څنګه کار کوي او د هغو کسانو د ټولنیز بیا ادغام په اړه کومې پوښتنې راولاړېږي چې له جګړه ځپلو سیمو څخه راګرځي.
On this week's Security Sprint, Dave and Andy covered the following topics: Opening:• (TLP:CLEAR) WaterISAC – EPA: National Security Information Sharing Bulletin – Q2 2026 — WaterISAC • The New Threat Environment; Why geopolitics matters to your water system — NRWA • Registration is open for WaterISAC's H2OEx – Camden — Association of Metropolitan Water Agencies • EPA Advisory: Protecting Sensitive Operational Information in Water and Wastewater Systems — EPAMain Topics:Election Security and Cascading Risks: An explosion of AI deepfakes is redefining American elections — Axios — 16 Jun 2026. • FBI foils alleged plot to attack White House UFC event, Patel says • Man pleads guilty to killing a top Minnesota Democrat and her husband in politically motivated attack • Man Charged with Sending Antisemitic Threats to Kill Governor of Hawaii and His Family — U.S. DOJ• Threats Against Politicians Skyrocketed After Meta Changed Its Speech Rules & Violent Threats Against Members of Congress Quadrupled After Meta Rolled Back Moderation Policies — Center for Countering Digital Hate Operation Epic Fury & Continued Threats:• ThreatBeat reports Iranian-linked hackers claimed California water system breaches after Iran water facility strike & Iranian Cyber Group Handala Claims Cal Water Hack • Iran and US reach an initial deal to end the war and open the Strait of Hormuz but challenges remain • U.S. and Iran Shape the Optics of an Agreement • Domestic: Iran-linked group claims hack of FBI drones, threatens World Cup, monitor says • Swedish Crime Group Foxtrot Adds Fuel to Iran's Proxy War in Europe Anthropic, AI & Patching… N-days. Anthropic reported that frontier models can significantly accelerate development of exploits for N-day vulnerabilities, which are publicly disclosed flaws that remain unpatched on many systems. • Exclusive: Anthropic's Mythos can exploit new flaws in hours — Axios • Statement on the US government directive to suspend access to Fable 5 and Mythos 5 • Anthropic Says It's Taking Claude Fable 5 Offline to Comply With US Government Order • “They screwed us”: Personality clashes sent Anthropic's models offline • Anthropic Releases Claude Fable 5, a Limited-Release AI Model • CISA orders feds to patch actively exploited Ivanti flaw by Sunday & CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-10520 Ivanti Sentry OS Command Injection Vulnerability • Oracle Security Alert for CVE-2026-35273 & Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations Quick Hits:• Wildfire Threats: National Interagency Coordination Center: 7-Day Significant Fire Potential• Weekly ransomware & data leak landscape — eCrime.ch — 15 Jun 2026. eCrime.ch reported 210 observed ransomware and data leak events for the 09 Jun to 15 Jun 2026 reporting window. The report identified 96 public data leak indicators, 38 active actors, and DeadLock as the highest-volume actor with 73 observed events. • Ransomware Evolution Report — Halcyon • Ransomware-as-a-Service: LockBit Alumni Launch Competing Programs as Ecosystem Consolidates in Q1 2026 • Ransomware Cybersecurity Framework Community Profile — NCCoE • National Security Presidential Memorandum/NSPM-12: National Policy for the Cybersecurity of National Security Systems — The White House • CISA sees leadership shakeup after infrastructure security chief moves to ONCD • MS-ISAC enters uncertain new era after losing federal funding and thousands of members
VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
More Bitlocker Issues: GreatXML https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Oracle Security Alert Advisory - CVE-2026-35273 https://www.oracle.com/security-alerts/alert-cve-2026-35273.html https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ How Deceptive Installers Are Targeting macOS Users https://www.huntress.com/blog/deceptive-installers-macos-infostealers My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Hello friends! I've been on a bit of an AI agent journey lately, and today I'm sharing my experience ditching OpenClaw and going all-in on Hermes — a self-hosted AI agent built by Nous Research. A Network Chuck video sold me on it, I wiped my Mac Mini (again), and baby's first Hermes adventure began! Here's what we get into today: Why I left OpenClaw — After getting the Mac Mini set up, OpenClaw left me feeling pretty meh: burning through API requests, random mid-conversation shutdowns, and a marketplace where the top listings were flagged as "potentially malicious." Hard pass. Network Chuck's five reasons Hermes rocks — His video summarized why Hermes stands out: (1) Nous Research has serious open source model cred predating OpenClaw, (2) more flexible persistent memory via markdown files + optional Honcho integration for building a profile of you over time, (3) a mission around humanistic and democratic AI, (4) a self-improvement loop where it writes its own skills after figuring things out, and (5) it just doesn't break — it feels like a product, not a project. The install — I used Claude to build a Mac Mini install guide from the Network Chuck transcript, and had Hermes up and running in about 15 minutes (one small Ollama hiccup aside). The install wizard lets you choose cloud models like Claude or ChatGPT, or go fully local with something like Gemma — I'm planning a hybrid setup with two Telegram bots. First real-world use: sitting in a truck running errands — With Hermes running on the Mac Mini and connected via Telegram, I asked it what it could do. It suggested Uptime Kuma for LAN monitoring — weirdly well-timed since I'd just been thinking about flaky IoT devices. I said "go install it," and it did — narrating its own troubleshooting out loud the whole time like a little robot intern. Remote access and Home Assistant — Had it install Home Assistant for smarthome control too, with plans to wire up TwinGate for remote access (it had a TailScale skill ready to fire in about two seconds, but I'm trying to keep VPN services consolidated). Daily digest via email — Hooked Hermes into a dedicated Gmail account and set up a 6 a.m. cron job that sends me a personalized morning digest: weather for my watched locations, recent breach/CVE news from select sites, and a summary of my favorite pentesting-focused Mastodon accounts. Needs tuning, but the first digest landed this morning and it's really good! The privacy angle — The real long-term win I see here is a hybrid model: feed raw, unsanitized pentest data to a local private model, let it analyze and sanitize, then hand off the clean version to a cloud model for deeper insight. Best of both worlds without the data exposure anxiety. Check out the Network Chuck video that started it all, and as always, if you're doing cool AI + security stuff, I'd love to hear about it. Find our pentesting services and training at 7MinSec.com, pentesting tips and scripts at 7MinSec.wiki, and if you want to support the show, head over to 7MinSec.club.
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - بازگشت ۳۲ زن و کودک از سوریه که با گروه خودخوانده داعش مرتبط هستند، باعث ایجاد نگرانی در مورد امنیت جامعه و بحث در مورد فعالیت های اجباری مبارزه با افراط گرایی خشونت آمیز (CVE) برای افراد در معرض خطر شده است.
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - 자칭 ‘이슬람국가(IS)'와 연관된 시리아 출신 여성과 어린이 32명이 귀국함에 따라 지역사회 안전에 대한 우려가 제기되고 있습니다. 위험군 대상자에 대한 ‘폭력적 극단주의 예방(CVE)' 의무 프로그램 시행을 둘러싼 논의가 진행되고 있습니다.
Google faces liability for AI-generated claims. Washington pauses public AI model assessments. Anthropic ships a safer AI model. OpenAI disrupts influence operations. Ransomware operators get a powerful new backdoor. Urgent patches land for Ivanti and Veeam. PyPI supply chain attacks evolve. And a massive data breach triggers a record fine in South Korea. Our guest is Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done. AI analyzes the FIFA World cup, one cliché at a time. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today's Industry Voices, we are joined by Peter Barker, Chief Product Officer at Ping Identity, sharing how identity increasingly becomes the control plane for how work gets done across humans, automation, and AI agents. You can read more from Ping Identity here. If you enjoyed this conversation, be sure to check out the full interview here. Selected Reading Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers (The Decoder) White House Reins In AI-Testing Unit as National-Security Concerns Grow (Wall Street Journal) Anthropic Releases ‘Safe' Version of Its Mythos A.I. Technology (The New York Times) PRC-linked influence operations are targeting AI debates in the US (OpenAI) Technical Analysis of MLTBackdoor (ThreatLabz) CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry (Rapid7) Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels (Socket) Veeam Patches Critical RCE Vulnerability in Backup & Replication published: yesterday (Beyond Machines) ‘Amazon.com of South Korea' Is Fined a Record $409 Million (The New York Times) The 2026 big soccer tournament, in clichés. (Sinch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
CISA's BOD 26-04 replaces severity-based patching with an exploit-evidence model and remediation clocks as short as three days, fleet-wide, no exceptions. Peter Pflaster and Jason Kikta unpack the four urgency signals, the 16-row decision tree, and the shift from "justify the patch" to "justify why you can't." They also cover what it means for contractors, cyber insurance, and the future of Patch Tuesday. If you own patching or vulnerability management, start here.
Instagram AI Support Hack Hits 20,225 Accounts; AI Worm 'Hades' Lies to Security Tools; Chrome Zero-Day Patch Host David Shipley reports Meta says 20,225 Instagram accounts were hijacked after an AI support tool was tricked into sending reset links to attacker-controlled emails, with only MFA-protected accounts resisting. Step Security details a new Miasma-derived worm wave called Hades that targets config files for 14 AI coding tools, can inject instructions to hijack assistants, lies to AI security tools, and includes a "dead man switch" wipe if stolen GitHub tokens are revoked; Microsoft also removed some GitHub repos after 73 open-source projects were compromised to inject an info stealer. University of Toronto and Vector Institute researchers demonstrated an AI worm using a free local model that spread across a simulated network via known flaws and misconfigurations. Google issued an emergency Chrome patch for actively exploited CVE-2026-11645 in V8, and insurers are tightening claims scrutiny and increasingly excluding AI-related liabilities. 00:00 Instagram AI Hack Fallout 01:36 AI Worm Hades Evolves 02:55 Microsoft Repo Compromise 03:54 Lab Built AI Worm Demo 05:27 Emergency Chrome Zero Day 07:07 Cyber Insurance Tightens Up 08:02 AI Liability Coverage Shrinks 09:16 Wrap Up and Sign Off
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - シリアの収容所から、武装組織イスラム国(IS)と関係のあるオーストラリア人の女性と子ども32人が帰国しました。地域社会の安全を懸念する声のほか、リスクを持つ個人にCVE(暴力的過激主義対策)プログラムへの参加を義務付けるべきだとの声が上がっています。SBSの日本語放送は火木金の午後1時からSBS3で生放送!火木土の夜10時からはおやすみ前にSBS1で再放送が聞けます。SBS日本語放送ポッドキャストから過去のストーリーを聞くこともできます。無料でダウンロードできるSBS Audio Appもどうぞ。SBS 日本語放送のFacebookとInstagramもお忘れなく。
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - 32 phụ nữ và trẻ em từ Syria, có liên hệ với nhóm tự xưng Nhà nước Hồi giáo (IS), vừa hồi hương, đã làm dấy lên lo ngại về an ninh cộng đồng và mở màn các cuộc thảo luận về hoạt động chống chủ nghĩa cực đoan bạo lực (CVE) bắt buộc đối với những cá nhân có nguy cơ cao.
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - 32名与“伊斯兰国”组织有关联的女性和儿童从叙利亚返回澳大利亚,引发了外界对社区安全的担忧,并围绕是否应对高风险个体实施强制性的反暴力极端主义项目(CVE)展开讨论。(点击上方收听音频)
Meta exposes 20,000 Instagram accounts through a support tool bug. CISA warns of active attacks on SolarWinds Serv-U. WordPress sites face takeover through a widely used plugin. A new Gafgyt variant broadens its reach. Pink extortionists steal cloud data with vishing and legitimate tools. Plus, allegations against IBM and AT&T, a dark web drug dealer gets 26 years, and the Monday business brief. Tim Starks from CyberScoop discusses the ongoing debate over staffing and budget cuts at CISA. NATO lets Ukraine play the bad guy. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest We are joined by Tim Starks from CyberScoop, who is discussing the ongoing debate over staffing and budget cuts at CISA, the political battles surrounding the agency's future, and what the Trump administration's plans could mean for U.S. cybersecurity efforts. Selected Reading Meta AI Bug Exposes Over 20,000 Instagram Accounts (Infosecurity Magazine) NSO Group back in Meta's crosshairs after alleged WhatsApp targeting (The Register) CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) (Help Net Security) Everest Forms Vulnerability Exploited to Hack WordPress Sites (SecurityWeek) C0XMO botnet spreads via DD-WRT router flaw, kills rival malware (Bleeping Computer) New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams (Hackread) Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks (GovInfo Security) California man sentenced to over 26 years for dark web drug trafficking (SC Media) AI observability platform Coralogix raises $200 million in a Series F round. (N2K Pro Business Briefing) Nato narrowly beats Russia-style enemy in cyber attack simulation (Financial Times) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry's most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - Le retour de 32 femmes et enfants de Syrie, liés au groupe autoproclamé « État islamique », a suscité des inquiétudes quant à la sécurité de la communauté et donné lieu à des débats sur les mesures obligatoires de lutte contre l'extrémisme violent (CVE) destinées aux personnes à risque.
The return of 32 women and children from Syria, who are linked to the self-proclaimed Islamic State group, has prompted concerns around community safety and discussions around mandatory Countering Violent Extremism (CVE) activities for at-risk individuals. - أثارت عودة 32 امرأة وطفلاً من سوريا إلى أستراليا، ممن يرتبطون بتنظيم الدولة الإسلامية المعروف بـ "داعش"، مخاوف واسعة النطاق حول سلامة المجتمع، وفتحت الباب مجدداً أمام مناقشات مكثفة بشأن إلزامية أنشطة مكافحة التطرف العنيف (CVE) للأفراد المصنفين كمعرضين للخطر.
Today's brief leads with Orange County, where Garden Grove's GKN Aerospace hazmat emergency de-escalates and all evacuation orders lift, returning the final 16,000 residents home with no injuries. New Mexico's Seven Cabins Fire reaches 64 percent containment and Lincoln County rescinds all evacuations. CISA adds an actively exploited vulnerability to its KEV catalog, the central United States faces a multi-day severe-weather threat, Kilauea holds at ADVISORY, and FEMA assistance deadlines approach in Washington and Hawaii. EM Morning Brief is your concise daily update on national and state-by-state emergency management news. Produced by Sitch Radio, an EOC Voices podcast.Key Takeaways• California hazmat: All Garden Grove GKN Aerospace evacuation orders lifted June 4; about 16,000 residents returned, no injuries, but tank cleanup remains delayed.• New Mexico wildfire: Seven Cabins Fire at ~31,867 acres and 64% contained; all evacuations rescinded June 4; Capitan Mountain forest closure still in effect.• Cyber / CISA: CISA added CVE-2026-45247 (Mirasvit) to the KEV catalog June 3 with an active-exploitation flag and a federal remediation deadline.• Severe weather: NWS and SPC flag a multi-day large-hail, wind, tornado, and flash-flood threat across the central Plains and mid-Mississippi Valley through the weekend.• Volcano: Kilauea remains at ADVISORY / Aviation Color Code YELLOW; eruption paused, episode 49 possible within ~10 to 15 days of June 1.• FEMA deadlines: Washington December-storm applications close June 10; Hawaii Kona Low Individual Assistance closes June 14.• Lifelines: City of Aiken, SC water main break June 4 affected ~60 connections; precautionary boil-water advisory to follow restoration.SponsorsThe NIMS Store - https://thenimsstore.com/SourcesNIFC / Wildfire• NIFC Incident Management Situation Report — National daily wildfire situation report and preparedness level• NIFC National Fire News — National wildland fire activity summaryCISA• CISA Adds One Known Exploited Vulnerability to Catalog (June 3, 2026) — CVE-2026-45247 Mirasvit deserialization flaw added to KEV• CISA Known Exploited Vulnerabilities Catalog — Authoritative KEV catalog and remediation deadlinesUSGS — Volcano• USGS Kilauea Volcano Updates — Hawaiian Volcano Observatory status and alert level for KilaueaSevere Weather• NWS National Forecast — National Weather Service hazards and severe-weather summary• SPC Day 1 Convective Outlook — Storm Prediction Center severe-weather outlook for the central U.S.Tropical / NHC• National Hurricane Center — Atlantic and Eastern Pacific tropical weather outlooksFEMA• FEMA — Hawaii Kona Low deadline extended to June 14 — Individual Assistance deadline for Maui and Honolulu counties• FEMA — One month remains to apply in Washington — June 10 deadline for December storms and floodingUSGS — Earthquakes• USGS Significant Earthquakes — 2026 — No significant U.S. seismic events in the last 24 hoursCalifornia• ABC7 — Garden Grove chemical tank updates — OCFA lifts all evacuation orders June 4; residents return• City of Garden Grove — Hazardous Materials Incident — Official municipal incident information pageNew Mexico• NM Fire Info — Lincoln County rescinds Seven Cabins evacuations (June 4) — Evacuation orders rescinded; acreage and containment update• Lincoln National Forest — Fire — Forest Service fire and closure informationSouth Carolina• City of Aiken — Water Main Break Advisory (June 4) — York Street NE main break affecting ~60 connections This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit emnetwork.substack.com/subscribe
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Announcing Bitskrieg https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html Vulnerability in Gogs https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/ Oracle Critical Security Patch Update Advisory - May 2026 https://www.oracle.com/security-alerts/cspumay2026.html GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257 https://security.paloaltonetworks.com/CVE-2026-0257
Topics covered in this episode: CVE-2026-48710: A Maintainer's Perspective daily-stars-explorer Markdown to pdf with pandoc and typst postman2pytest Extras Joke Watch on YouTube About the show Brian #1: CVE-2026-48710: A Maintainer's Perspective Marcelo Trylesinski suggested by Lee Luocks Short version: users of Starlette: upgrade to Starlette 1.0.1 security professionals: we can't treat open source projects like corporations This top link is a Starlette security advisory with the title Missing Host header validation poisons request.url.path, bypassing path-based security checks The CVE apparently caused some negative press targeting starlette. However, “the vulnerability came from the application pattern and the deployment, never from something Starlette intended.” A quote from an OSTIF article: “This bug is a classic “responsibility gap” where if this maintainer didn't patch, thousands of exposed projects would have to individually secure their projects. In doing this work, they've voluntarily taken on the responsibility to protect the ecosystem from long-term systemic harm. As with all open source projects, they owed us nothing and could have left this to be everyone else's problem and took the extraordinary steps of helping the ecosystem.” Both X40 D-Sec and Ars Technica expected immediate fixes and responses from Starlette. That's not good. We can do better. Michael #2: daily-stars-explorer Explore the full history of any GitHub repository.
This episode covers a CISA contractor's accidental exposure of AWS GovCloud credentials and internal system details on GitHub, the FBI's efforts to patch vulnerable routers, and a critical NGINX vulnerability with public proof-of-concept code. The team also discusses Microsoft's handling of a disputed Azure Backup security finding, the challenges of vulnerability disclosure and CVE assignment, and GitHub's ban of security researcher Nightmare Eclipse following the publication of unpatched Windows vulnerability research.Join us LIVE on Mondays, 4:30pm EST.A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.https://www.youtube.com/@BlackHillsInformationSecurityChat with us on Discord! - https://discord.gg/bhis
This week we have a technical segment focused on Linux! Paul released a script that helps you get a handle on Linux supply chain security, and new features allow you to assess the state of Secure Boot on your Linux systems (that also use MS certificates, ironically). The script is in his Git repo: https://github.com/pasadoorian/Linux_Hacks. In the security news: The CVE chase The new security basics Enterprises are lacking more than AI Detections are falling behind Why DOOM!?! Chromium vulnerability The ambitious Flipper One I'm still curious who was behind these leaks Mitre moves Caldera to Apache foundation Wind cybersecurity PQC updates YellowKey Bitlocker Bypass updates The software supply chain is in deep trouble Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-928
Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its source code exfiltrated Russia is using very old Western software Why to get a no-charge AI chatbot account New Sci-Fi on Netflix What we learn from Mozilla's use of Mythos Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com doppel.com cyberhoot.com/securitynow trustedtech.team/securitynow365 XBOW.com
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Possible ACR Stealer From Page Impersonating Claude https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018 Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Multiple Vulnerabilities in Angular Language Service VS Code Extension https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq
Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its source code exfiltrated Russia is using very old Western software Why to get a no-charge AI chatbot account New Sci-Fi on Netflix What we learn from Mozilla's use of Mythos Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com doppel.com cyberhoot.com/securitynow trustedtech.team/securitynow365 XBOW.com
Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its source code exfiltrated Russia is using very old Western software Why to get a no-charge AI chatbot account New Sci-Fi on Netflix What we learn from Mozilla's use of Mythos Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com doppel.com cyberhoot.com/securitynow trustedtech.team/securitynow365 XBOW.com
Mozilla found 271 unknown Firefox vulnerabilities in days using AI—bugs that millions of automated test runs had missed for years. Steve Gibson argues this isn't a crisis. It's the industry finally paying down decades of security debt, and for the first time, defenders may have the advantage. Cisco meets Mythos Can the aging CVE system survive AI Patch deployment latency in the AI age MSFT's official YellowKey BitLocker bypass mitigation Ubiquiti patches 5 serious vulnerabilities Drupal attacked by a PostgreSQL injection Microsoft terminates SMS as a second factor GitHub hacked - all of its source code exfiltrated Russia is using very old Western software Why to get a no-charge AI chatbot account New Sci-Fi on Netflix What we learn from Mozilla's use of Mythos Show Notes - https://www.grc.com/sn/SN-1080-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: guardsquare.com doppel.com cyberhoot.com/securitynow trustedtech.team/securitynow365 XBOW.com
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Selective HTTP Proxying in Linux https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002 Megalodon: Mass GitHub Repo Backdooring via CI Workflows https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/ MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 https://x.com/fabian_bader/status/2057198207243804881 Cisco Secure Workload Unauthorized API Access Vulnerability CVE-2026-20223 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
New Malware Libraries means New Signatures https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986 Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498 Microsoft Authenticator Update CVE-2026-41615 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615 ssh-keysign-pwn (CVE-2026-46333) Patches Released https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/