exploitable weakness in a computer system
POPULARITY
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
German Federal Information Security Office Analyzes Windows Hello for Business https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7 NGINX Vulnerability https://my.f5.com/manage/s/article/K000162097 7-Zip XZ Decompression CVE-2026-14266 https://www.zerodayinitiative.com/advisories/ZDI-26-444/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofing https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 https://www.veeam.com/kb4869 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Progress Sharefile Emergency Shutdown Notice https://status.sharefile.com https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/ https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/ U-Boot Vulnerabilities https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification Nightmare Eclipse Releases Next Microsoft Defender Exploit https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/ Cisco Increases Patch Cadence https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
durée : 00:07:13 - La canicule du mois de juin servira-t-elle d'électrochoc ? La Nancéienne Valérie Masson-Delmotte, qui a co-présidé le groupe de travail du GIEC, espère que la France va en tirer les leçons. La climatisation peut être un levier d'action pour les personnes vulnérables, mais il n'est pas le seul. Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Why Ask Credentials If There Are Secret Codes? https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118 Adobe Patches and Updated Patch Release Policy https://helpx.adobe.com/security/Home.html https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery Google Chrome Update (link had issues loading while recording) https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Dans cet épisode solo, je pars d'un concours de circonstances de la semaine dernière avec le partage de deux stories Instagram publiées l'une à la suite de l'autre, l'une avec une citation de Romain Lemire sur l'inceste ("le silence, c'est ce qui permet aux prédateurs d'agir"), l'autre avec un carrousel tiré de mon épisode avec Frédéric Semama sur l'inaction climatique. Des dizaines de personnes m'ont écrit pour me dire que les deux se faisaient écho et cam'a amené à réfléchir car ils avaient raison.Dans cet épisode, je parle de la violence invisible, je questionne pourquoi 61 672 morts en un seul été européen ne génèrent pas le même niveau d'urgence politique que ce qu'on appelle "l'insécurité". J'ai exploré trois concepts qui m'ont aidé à mettre des mots sur ce malaise : la violence symbolique de Bourdieu, la violence lente de Rob Nixon et l'homéopathisation de la violence de Maffesoli. Et à la fin, je plaide pour une seule chose : nommer. Parce que ce qui n'a pas de mot n'existe pas dans les institutions.CITATIONS MARQUANTES"Le silence, c'est ce qui permet aux prédateurs d'agir." — Romain Lemire, sur Vlan!"La vraie violence, en 2026, n'est pas uniquement celle dont on parle mais plutôt celle qu'on tait et que souvent on ne classe pas dans la bonne case." — Gregory Pouy"Il n'y a pas de monstre, il n'y a que des personnes qui font des choses monstrueuses." — Un juge, sur Vlan!"Ce qui n'a pas de mot pour le définir n'existe pas. Les mots créent de la réalité institutionnelle." — Gregory Pouy"Intégrer l'animalité permet d'éviter la bestialité." — Michel Maffesoli (rapporté par Gregory Pouy)IDÉES CENTRALES Big Idea 1 — La violence visible capte tout, la violence systémique tue en silenceExplication : L'agression dans le métro, la vitrine brisée font de bonnes images et définissent un "monstre". Les 61 672 morts européens de l'été 2022 (= 20x les homicides en France sur une décennie 2010-2020) ne font pas d'image et n'ont pas de coupable identifiable. Le débat politique, les lois et les budgets suivent les images, pas les chiffres. Pourquoi c'est important : C'est un mécanisme de détournement qui a des effets politiques réels et mesurables. Position : Section 2 (La violence que les caméras aiment)Big Idea 2 — La violence symbolique (Bourdieu) : le système qui se rend légitime aux yeux de ses victimesExplication : La domination la plus efficace est celle que les dominés perçoivent comme naturelle ou méritée. Pour l'inceste : silence institutionnel pendant des décennies. Pour le climat : dissémination de la responsabilité individuelle égale pour dédouaner les vrais auteurs. Pourquoi c'est important : Elle n'est pas un ajout à la violence physique, elle en est la condition de possibilité. Position : Section 3Big Idea 3 — La violence lente (Rob Nixon) : le crime parfaitExplication : Les violences environnementales sont graduelles et invisibles. Nos mécanismes cognitifs, médiatiques et politiques sont calibrés pour l'instantané. La canicule sera oubliée dans 3 semaines. Les pauvres meurent 2x plus que les riches lors des pics de chaleur, à Madrid comme à Varsovie. Pourquoi c'est important : La violence lente frappe d'abord les corps déjà fragilisés par d'autres formes de violences, sans laisser de scène de crime claire. Position : Section 4Big Idea 4 — Nommer crée des obligations politiquesExplication : Le mot "féminicide" a permis de compter séparément, d'analyser les schémas, de former les gendarmes et de changer les procédures. "Violence climatique" et "insécurité climatique" forcerait les politiques et les journalistes à traiter le sujet autrement qu'en relégation de fin de journal. Pourquoi c'est important : Ce qui n'a pas de mot n'existe pas dans le droit, donc pas dans la politique, donc pas dans le budget. Position : Section 5Big Idea 5 — L'homéopathisation de la violence (Maffesoli) : ritualiser pour éviter la bestialitéExplication : La violence est structurelle à ce que nous sommes. Ni l'éliminer ni la nier, mais lui donner un cadre. Le carnaval, le duel codifié, les jeux de l'amphithéâtre avaient cette fonction. Quand une société refuse de nommer certaines violences, elle les refoule. Et un refoulement à grande échelle produit des symptômes : colères politiques diffuses, agressivité en ligne, défiance dans les institutions. Pourquoi c'est important : La canicule génère une violence psychique collective réelle : la conscience diffuse qu'une injustice se passe, sans mot pour la dire, sans coupable désigné, sans recours. Position : Section 6Big Idea 6 — Inceste et climat : deux applications du même principeExplication : Le prédateur familial compte sur la honte, la loyauté et l'absence de mots. L'industrie pétrolière compte sur le silence politique, la dissémination du doute et l'absence de catégories juridiques. Ce ne sont pas deux phénomènes sans rapport : la violence survit grâce à son invisibilité, activement maintenue par ceux qui ont le pouvoir de nommer. Pourquoi c'est important : C'est le cadrage central de toute la newsletter, et un cadrage est déjà un acte politique. Position : Section 8 (conclusion)RÉFÉRENCES CITÉESPersonnes (invités ou cités dans le podcast / newsletter)Romain Lemire — invité Vlan!, sur le silence comme condition de l'inceste et de la prédation. Citation centrale de la newsletter.Frédéric Semama — invité Vlan!, épisode "Pourquoi on sait tout sur le climat et on ne fait rien". Point de départ de la réflexion.Un juge (anonyme) — invité Vlan!, citation : "Il n'y a pas de monstre, il n'y a que des personnes qui font des choses monstrueuses."Catherine Turner — actrice, analyse des "menaces invisibles" subies par les femmes. Citée sur la notion de zone grise entre préjudice réel et non-reconnu par le droit.Penseurs et théoriciensPierre Bourdieu — concept de violence symbolique : la domination intériorisée comme légitime et naturelle par les dominés. Section 3.Rob Nixon — théoricien littéraire américain, concept de "violence lente" (slow violence) appliqué aux violences environnementales. Section 4.Michel Maffesoli — sociologue français, "Essai sur la violence". Concept d'homéopathisation de la violence : ritualiser l'agressivité pour éviter la bestialité. Section 6.René Girard — philosophe français, désir mimétique et mécanisme du bouc émissaire. Cité en parallèle de Maffesoli. Section 6.Gaston Bachelard — philosophe français, citation : "les révolutions conceptuelles se font toujours contre les mots de la génération précédente." Section 5.Livres citésEcotopia — Ernest Callenbach, roman utopique. Imagination de jeux de guerre rituels codifiés entre communautés comme gestion de la violence. Section 6. (Recommandé vivement par Gregory Pouy)Essai sur la violence — Michel Maffesoli. Cité directement.Études et donnéesNature Medicine (2023) — étude sur les 61 672 morts de la chaleur en été 2022 en Europe. Données par pays : Italie 18 010, Espagne 11 324, Allemagne 8 173. Vulnérabilité double dans les quartiers défavorisés. Section 2.Études sur la mortalité climatique différentielle — Recherches entre Madrid et Varsovie sur la surmortalité des pauvres lors des canicules (2x). Section 4.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
L'Allemagne accueille depuis une dizaine d'années des centaines de milliers de migrants, l'immense majorité est prise en charge dans un premier temps dans des foyers et ils sont répartis à travers tout le pays. Mais chaque année, environ 2 500 personnes bénéficient d'un « asile religieux » et sont hébergées par des églises catholiques et protestantes parce qu'elles sont particulièrement vulnérables. De notre correspondant à Berlin, Antoine – qui a préféré ne pas donner son vrai nom – fait visiter l'appartement dans la paroisse de l'église protestante de Forst, dans le Brandebourg, où il est hébergé. Le jeune Camerounais partage cet appartement de trois pièces avec un Tchadien. Antoine est arrivé à la rentrée dernière en Allemagne. « Je viens du Cameroun, de Douala précisément. J'ai quitté le Cameroun parce que je suis homosexuel et l'homosexualité au Cameroun est très mal vue, témoigne-t-il, donc c'était très difficile. » Antoine est arrivé en Europe via la Roumanie. L'Allemagne avait six mois, conformément aux règles de Dublin, pour le renvoyer dans ce pays par lequel il est entré dans l'Union européenne. On a proposé au jeune homme de bénéficier du « Kirchenasyl », de l'asile religieux : une paroisse décide d'héberger un migrant dans une situation difficile pour le protéger. « La situation juridique est claire : on doit protéger les êtres humains, souligne Simon Klaas, le pasteur à Forst qui a accueilli Antoine. Ils ont le droit à l'asile politique. Une institution comme l'Église a le devoir de défendre ce droit. » À écouter dans Accents d'EuropeImmigration irrégulière: vers des expulsions massives en Allemagne et les Talibans à Bruxelles L'Église remplace l'État Cet asile religieux existe depuis une quarantaine d'années. Les autorités sont au courant, les paroisses doivent expliquer pourquoi les personnes accueillies sont particulièrement vulnérables, comme le fait pour Antoine d'être homosexuel. « Le fait d'être ici, à force, l'asile de l'Église m'a apporté la sécurité, confie Antoine. Déjà, parce qu'au camp, je n'étais pas vraiment en sécurité. La police vient souvent déporter les gens de Dublin vers leur pays d'origine. C'est un grand soulagement que les six mois de la procédure de Dublin soient passés. Je suis très content. » Cet accueil signifie que la paroisse remplace la puissance publique. Elle met un hébergement à disposition et Antoine reçoit 200 euros par mois de l'église de Forst pour se nourrir et pour ses autres frais. Dans le Brandebourg, région qui entoure Berlin, une quinzaine de paroisses sur 500 offrent un asile religieux. Toutes n'ont pas les capacités logistiques, bien sûr. Mais nous sommes aussi dans un Land où l'extrême droite séduit un tiers de l'électorat. Simon Klaas ne crie pas sur les toits qu'il héberge des migrants. « L'extrême droite réinterprète les valeurs chrétiennes. Aime ton prochain se réduit à la famille ou aux voisins et à ceux qui te ressemblent, mais pas aux autres, dénonce le pasteur. C'est une perversion. » Antoine n'a pas souffert du racisme à Forst où il séjourne encore. Il y a deux jours, sa procédure d'asile en Allemagne a débuté avec un entretien de plusieurs heures. Il devrait connaître la décision des autorités après l'été. À lire aussi«Nous y arriverons»: en Allemagne, l'intégration des réfugiés progresse dans une société polarisée
L'Allemagne accueille depuis une dizaine d'années des centaines de milliers de migrants, l'immense majorité est prise en charge dans un premier temps dans des foyers et ils sont répartis à travers tout le pays. Mais chaque année, environ 2 500 personnes bénéficient d'un « asile religieux » et sont hébergées par des églises catholiques et protestantes parce qu'elles sont particulièrement vulnérables. De notre correspondant à Berlin, Antoine – qui a préféré ne pas donner son vrai nom – fait visiter l'appartement dans la paroisse de l'église protestante de Forst, dans le Brandebourg, où il est hébergé. Le jeune Camerounais partage cet appartement de trois pièces avec un Tchadien. Antoine est arrivé à la rentrée dernière en Allemagne. « Je viens du Cameroun, de Douala précisément. J'ai quitté le Cameroun parce que je suis homosexuel et l'homosexualité au Cameroun est très mal vue, témoigne-t-il, donc c'était très difficile. » Antoine est arrivé en Europe via la Roumanie. L'Allemagne avait six mois, conformément aux règles de Dublin, pour le renvoyer dans ce pays par lequel il est entré dans l'Union européenne. On a proposé au jeune homme de bénéficier du « Kirchenasyl », de l'asile religieux : une paroisse décide d'héberger un migrant dans une situation difficile pour le protéger. « La situation juridique est claire : on doit protéger les êtres humains, souligne Simon Klaas, le pasteur à Forst qui a accueilli Antoine. Ils ont le droit à l'asile politique. Une institution comme l'Église a le devoir de défendre ce droit. » À écouter dans Accents d'EuropeImmigration irrégulière: vers des expulsions massives en Allemagne et les Talibans à Bruxelles L'Église remplace l'État Cet asile religieux existe depuis une quarantaine d'années. Les autorités sont au courant, les paroisses doivent expliquer pourquoi les personnes accueillies sont particulièrement vulnérables, comme le fait pour Antoine d'être homosexuel. « Le fait d'être ici, à force, l'asile de l'Église m'a apporté la sécurité, confie Antoine. Déjà, parce qu'au camp, je n'étais pas vraiment en sécurité. La police vient souvent déporter les gens de Dublin vers leur pays d'origine. C'est un grand soulagement que les six mois de la procédure de Dublin soient passés. Je suis très content. » Cet accueil signifie que la paroisse remplace la puissance publique. Elle met un hébergement à disposition et Antoine reçoit 200 euros par mois de l'église de Forst pour se nourrir et pour ses autres frais. Dans le Brandebourg, région qui entoure Berlin, une quinzaine de paroisses sur 500 offrent un asile religieux. Toutes n'ont pas les capacités logistiques, bien sûr. Mais nous sommes aussi dans un Land où l'extrême droite séduit un tiers de l'électorat. Simon Klaas ne crie pas sur les toits qu'il héberge des migrants. « L'extrême droite réinterprète les valeurs chrétiennes. Aime ton prochain se réduit à la famille ou aux voisins et à ceux qui te ressemblent, mais pas aux autres, dénonce le pasteur. C'est une perversion. » Antoine n'a pas souffert du racisme à Forst où il séjourne encore. Il y a deux jours, sa procédure d'asile en Allemagne a débuté avec un entretien de plusieurs heures. Il devrait connaître la décision des autorités après l'été. À lire aussi«Nous y arriverons»: en Allemagne, l'intégration des réfugiés progresse dans une société polarisée
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Adding some Automation to the favicon.ico method of Host Recon https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110 Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626 Google Gemini CLI Vulnerability CVE-2026-12537 https://github.com/advisories/GHSA-jj69-4grx-fqj5 IPv6 Frag Escape https://github.com/sgkdev/ipv6_frag_escape My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
durée : 00:02:29 - Debout la Terre - La SNCF affiche partout à bord que "choisir le train, c'est agir pour la planète". Mais qui agit pour le train ? Beaucoup trop vulnérable face à la crise climatique. C'est le résultat d'années de sous-investissements et de manque d'anticipation. Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Le discours de Pauline Hanson, dirigeante du parti One Nation, devant le National Press Club, a été condamné pour ses attaques contre les migrants, les personnes transgenres, les jeunes parents et les médias publics. Accusée de ne proposer aucune solution crédible, la sénatrice Hanson a vu son discours jugé inquiétant et irresponsable par ses détracteurs.
Le discours de Pauline Hanson, dirigeante du parti One Nation, devant le National Press Club, a été condamné pour ses attaques contre les migrants, les personnes transgenres, les jeunes parents et les médias publics. Accusée de ne proposer aucune solution crédible, la sénatrice Hanson a vu son discours jugé inquiétant et irresponsable par ses détracteurs.
Eliot Deval revient pendant deux heures, sans concession, sur tous les sujets qui font l'actualité. Vous voulez réagir ? Appelez le 01.80.20.39.21 (numéro non surtaxé) ou rendez-vous sur les réseaux sociaux d'Europe 1 pour livrer votre opinion et débattre sur les grandes thématiques développées dans l'émission du jour.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
Dans le Rhône, à Mornant, tout est fait pour protéger les personnes les plus vulnérables. À la mairie, les employés appellent régulièrement les personnes âgées. Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
From a VHDX File to a Remcos RAT https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080 A backdoor in a LinkedIn job offer https://roman.pt/posts/linkedin-backdoor/ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html Copilot M365 Data Leakage https://www.varonis.com/blog/searchleak My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Pascal Praud et ses invités dressent un constat accablant : la justice française peine à protéger les plus fragiles. Entre la relaxe d'un animateur parisien accusé d'agressions sexuelles sur mineurs, le drame de Lyhanna, le calvaire d'une grand-mère agressée dans une église, et le témoignage glaçant du père de Yann, adolescent suicidé après une agression sexuelle, l'émission explore les failles d'un système judiciaire souvent perçu comme défaillant.Vous voulez réagir ? Appelez-le 01.80.20.39.21 (numéro non surtaxé) ou rendez-vous sur les réseaux sociaux d'Europe 1 pour livrer votre opinion et débattre sur grandes thématiques développées dans l'émission du jour.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ A Fake Bug Report Hijacks Your AI Coding Agent and Nothing Catches It. https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.
Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
Avec : Carine Galli, journaliste RMC. Yael Mellul, ancienne avocate. Et Frédéric Hermel, journaliste et écrivain. - Accompagnée de Charles Magnien et sa bande, Estelle Denis s'invite à la table des français pour traiter des sujets qui font leur quotidien. Société, conso, actualité, débats, coup de gueule, coups de cœurs… En simultané sur RMC Story.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
New Wave Of Phishing Emails with SVG Files https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040 Android 2026-06-01 security patch level vulnerability details https://source.android.com/docs/security/bulletin/2026/2026-06-01 Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826 https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083 https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/ Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
AI Unraveled: Latest AI News & Trends, Master GPT, Gemini, Generative AI, LLMs, Prompting, GPT Store
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Announcing Bitskrieg https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html Vulnerability in Gogs https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/ Oracle Critical Security Patch Update Advisory - May 2026 https://www.oracle.com/security-alerts/cspumay2026.html GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257 https://security.paloaltonetworks.com/CVE-2026-0257
(Presented by Ent.ai: Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined.) Three Buddy Problem - Episode 99: Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? Costin plays reluctant defender, JAGS says the damage was done years ago, and Ryan reopens the long history of silent fixes and stolen bounties. Plus, on the 10th anniversary of the Shadow Brokers leak, we discuss some enduring mysteries, theories on attribution and an interesting trail that leads to Edward Snowden. We also unpack Rob Joyce's warning that China's cyber explosives are already planted in US infrastructure, and the Pope's warnings about around artificial intelligence. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 2:03 - The Pope's AI paper 3:35 - New sponsor: Brandon Dixon's Ent Security 9:34 - Costin's Chinese-model OSINT rabbit hole 13:34 - Codex, GPT-5.5, and the "American AI welfare state" 23:20 - Microsoft threatens vulnerability researchers 27:06 - Is it extortion or retribution? The disclosure fight 40:48 - How Microsoft's consultant class broke MSRC and MSTIC 48:42 - Silent fixes, stolen bounties, and the marketing machine 1:02:29 - Ten years of the Shadow Brokers 1:14:20 - The Snowden theory 1:32:34 - Rob Joyce: China's cyber explosives are in place 1:53:26 - Shout-outs
Dans un esprit narrativisé par un discours interiorisé NÉGATIF et plein de JUGEMENT, il devient facile de vouloir s'éviter, voir de se détéster. Pour retourner ton monde intérieur, je t'invite dans cet épisode de podcast à apprendre à embrasser ta vulnérabilité, ma douce soeur.Si tu veux atteindre ton plein potentiel et devenir la meilleure version de toi-même : rejoins mon programe "Devenir 'Elle' I Révèle ton Potentiel"Mon Instagramhttps://www.instagram.com/bestofherself/Mon Programmehttps://www.bestofherself.com/formation/devenir/elle/revele/ton/potentielMon Site Webhttps://www.bestofherself.com/Ma Newsletterhttps://www.bestofherself.com/newsletter Hébergé par Acast. Visitez acast.com/privacy pour plus d'informations.
Vous voulez réagir ? Appelez-le 01.80.20.39.21 (numéro non surtaxé) ou rendez-vous sur les réseaux sociaux d'Europe 1 pour livrer votre opinion et débattre sur grandes thématiques développées dans l'émission du jour.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be told
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex. Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Perri Adams. Timestamps: 0:00 — Introductory banter 1:09 — Why LLMs just made formal methods relevant again 4:03 — Proof engines, explained 8:43 — Can a layman grab this fire? The calculus problem 11:58 — Vuln researchers are scrappy kids with a trust fund 14:55 — Pitching AIxCC inside DARPA: hard sell or easy sell? 18:00 — Designing a challenge that's allowed to fail 22:06 — Inside Team Atlanta's 150-page winning system 24:00 — Why this is bigger for defense than for offense 31:49 — Mythos, safeguards, and "every LLM bug is a public bug"
Près de cinq mois après leur libération, les élèves et le staff de l'école Saint Mary de Papiri ont tous retrouvés leurs proches. Situé dans l'État de Niger au Nigeria, cet établissement scolaire primaire et secondaire n'a toujours pas rouvert ses portes. Les victimes de ce spectaculaire kidnapping de masse ne bénéficient d'aucun accompagnement psychologique et vivent toujours dans une zone extrêmement volatile et dangereuse. Une opération de sécurité impliquant l'armée et la police, baptisée « Opération Savannah Shield », est en cours dans le nord-ouest du Nigeria. Reportage dans cette zone voisine du département de Borgou au nord du Bénin. De notre correspondant dans la région, De son mois de captivité, Bako est revenu choqué par le matériel technologique en possession des groupes extrémistes. Cet enseignant de l'école Saint Mary ne comprend toujours pas comment salafistes et bandits ont pu s'enraciner dans les forêts de l'État de Niger. L'ultra violence de ces criminels hante toujours Bako : « Des enfants meurent dans les cachots de ces ravisseurs. Des femmes y meurent aussi. Des milliers de personnes y sont otages. Des gens du Bénin et du Nigeria... Il y a des infirmières là-bas. Des sages-femmes sont prises aussi au piège. Au Bénin, ces groupes extrémistes ont l'habitude d'aller dans des hôpitaux pour enlever des gens. Ils savent qu'ils obtiennent de plus grosses rançons en kidnappant des personnels de santé. » Lydia est une aide cuisinière de Saint Mary. Elle aussi a été otage comme Bako. Ses deux fils âgés de moins de 5 ans ont vécu cette expérience avec elle, dans la forêt de Kainji. Ces deux bambins ne lâchent plus d'une semelle leur maman depuis leur retour. Car même libre, le quotidien de cette famille est un cauchemar : « Ce qui me préoccupe encore aujourd'hui, c'est que les meurtres n'ont pas cessé ; je n'ai donc pas l'esprit tranquille. Parfois, nous ne pouvons pas dormir chez nous parce qu'ils rôdent dans les environs ; nous devons aller dormir dans la brousse, et c'est pour cette raison que je n'ai pas l'esprit tranquille. » « Nous courons dans le noir avec nos enfants » Le jour du kidnapping de Saint Mary, Emmanuel rendait visite à son épouse, enseignante de cette école. Depuis son retour à la liberté, une nuit sur deux, le hameau où vivent Emmanuel et sa famille subit des attaques de bandits. Et comme Lydia et ses enfants, Emmanuel et sa compagne se cachent jusqu'au matin en brousse. En étouffant les pleurs de leurs deux nourrissons : « Nous courons dans l'obscurité en espérant qu'ils ne voient pas où nous nous cachons. Nous courons dans le noir avec nos enfants. Parfois, les enfants pleurent, alors nous faisons de notre mieux. Nous les choyons juste pour faire cesser les pleurs, afin que, si les bandits sont dans les parages, ils ne puissent pas découvrir où nous nous cachons. » Au bord de la rupture nerveuse, Emmanuel s'accroche à la vie. Surtout quand il se souvent de tous ces otages qu'il a croisés. Il se demande en permanence combien d'entre eux sont encore vivants. À lire aussiNigeria: la fermeture de l'école Saint Mary prolongée en raison de l'insécurité dans le nord-ouest [1/3]
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Tearing apart website fraud to see how it works. (@sans_edu) https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958 Simple bypass of the link preview function in Outlook Junk folder https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990 NGINX Vulnerability https://depthfirst.com/nginx-rift Cisco SDWan 0-Day https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
(00:46) «Vulnérabilités – Verletzlichkeiten» lautet das Motto der diesjährigen Bieler Fototage unter der neuen Leitung. Weitere Themen: (05:09) «Auawirleben»: Das Berner Theaterfestival bringt Widerständiges auf die Bühne. (09:33) «I dreamt of you in colours»: Eine farbenfrohe Ausstellung der nigerianischen Künstlerin in Lausanne – verstörend und schön. (13:48) Markus Orths legt mit «Die Enthusiasten» einen Roman über Künstliche Intelligenz und schöpferische Grenzen vor.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
An Adaptive Cyber Analytics UI for Web Honeypot Logs https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962 Ivanti May Patchday https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631] https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/ @sans_edu research paper: Marcio Enriquez [link will be added once the paper has been published]
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
DShield Honeypot Update https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948 MOVEit Automation Critical Security Alert Bulletin April 2026 (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 Apache httpd http2 vulnerability https://seclists.org/oss-sec/2026/q2/387
durée : 00:05:50 - Entendez-vous l'éco ? - par : Anne-Laure Chouin - Depuis le premier choc pétrolier en 1974, la France importe trois fois moins de pétrole brut et sa provenance a aussi beaucoup évolué. La réduction est donc colossale, mais nous restons malgré tout à la merci des crises pétrolières. Or cette vulnérabilité n'est pas que passagère. - réalisation : Caroline Bennetot, Éric Chaverou, Marie Viennot Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Danger of Libredtail https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936 FreeBSD dhclient vulnerability https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc Linux Copy-Fail Vulnerability CVE-2026-31431 https://copy.fail Bryan Nice Research Paper https://www.linkedin.com/in/bryannice/ https://www.sans.edu/cyber-research/detecting-ai-pickling
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930 GitHub Vulnerability CVE-2026-3854 https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Microsoft RDP Notification Bug https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883
YoutubeThe boys get honest! Chuck dives deep into his insecurities (fun!) related to a recent incident with creative partners. Brad gets into his improv history and what drove him away for a long time. Get ready for some emotion!Video Edit by Craig Depina of the Needless to Say podcast@funbearablepod / funbearablepod.com#friends #insecurities #comedy #honesty
Many cybersecurity conversations of late are discussing the impending “vuln-pocalypse” — a term used to describe a scenario in which AI-powered tools are used to discover and exploit vulnerabilities faster than defenders can patch them. It's a valid concern. Even without advanced AI algorithms, researchers can build tools to automate the vulnerability discovery process. Now, the rise of increasingly sophisticated AI models is rapidly expanding the volume of vulnerabilities defenders will need to handle. “I've been saying since November, we're looking at three to nine months until a massive influx of zero-day vulnerabilities,” Adam says in this conversation. Which begs the question: Are we cooked? No, he says, but it's getting hot in here. In this episode, Adam and Cristian explore the vuln-pocalypse from the defender's perspective. They dive into the economics of this shift and explain how organizations should approach their patching strategy going forward. This isn't an “end of the world” problem, they say, but it will require a more thoughtful approach to which vulnerabilities are patched, how they're patched, and when. Tune in for this timely conversation as adversaries and defenders alike explore the potential of AI.
Segment 1: We cover the weekly enterprise news! Segment 2: RSAC interviews from ArmorCode and Filigran ArmorCode: AI Exposure Management and Governing Shadow AI AI is moving faster than most governance models can keep up. As organizations race to adopt new AI tools, developer workflows, agents and MCP servers, security leaders must enable innovation without losing control over risk, accountability and oversight. In this segment, ArmorCode will discuss its new AI Exposure Management (AIEM) solution, as part of the ArmorCode Agentic AI Platform. ArmorCode will highlight how AIEM gives enterprises clearer visibility into where AI is being used, who owns it and the potential risks it introduces across heterogeneous environments. By turning AI usage and signals from existing security and IT systems into governed, auditable outcomes, AIEM helps organizations reduce shadow AI risk, assign accountability and accelerate AI adoption with stronger control and board-ready governance. ArmorCode will also share findings from its new 2026 State of AI Risk Management report, developed in partnership with The Purple Book Community and based on responses from more than 650 enterprise security leaders. The discussion will connect ArmorCode's latest product innovation to the broader industry need for scalable, enterprise-ready AI risk governance. ArmorCode AI Exposure Management is available now as a solution deployed on the ArmorCode Agentic AI Platform. To learn more, visit https://securityweekly.com/armorcodersac. Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence In a time where the ability to turn intelligence into decisive action is a true competitive advantage, organizations must move beyond reactive alert triage to a proactive, threat-informed defense. This segment explores how unifying threat intelligence with adversarial attack simulation enables a Continuous Threat Exposure Management (CTEM) framework that replaces hype with measurable outcomes. We will discuss why these are no longer just technical security conversations, but critical business strategies that provide the board and C-suite with the clarity and confidence to reduce risk and focus resources where they matter most. This segment is sponsored by Filigran. Visit https://securityweekly.com/filigranrsac to learn more about them! Segment 3: RSAC interviews with Sekioa and Fortra Agentic AI: Don't Make Your SOC Faster at Being Wrong Adding AI agents to an unprepared SOC doesn't make it smarter; it just makes it "faster at being wrong." Georges Bossert challenges the industry hype to explain why true autonomy relies on reliable context and structured runbooks, not just prompts. He will discuss how to build the necessary foundations to automate rapidly without losing control. This segment is sponsored by Sekoia.io. Visit https://securityweekly.com/sekoiarsac to discover their AI SOC Platform! Scripted Sparrow: A Prolific BEC Group In December, Fortra Intelligence and Research Experts (FIRE) released a major report exposing Scripted Sparrow, one of the most active Business Email Compromise (BEC) collectives operating today. The group sends an estimated 6 million highly targeted scam emails each month, impersonating executive coaching firms and leveraging spoofed reply chains, missing attachment lures, and evolving multilingual campaigns. FIRE's investigation links the collective to 119 domains, 245 webmail accounts, and 256 bank accounts, with members operating across three continents and continually refining their fraud techniques at scale. This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrarsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-454
Segment 1: We cover the weekly enterprise news! Segment 2: RSAC interviews from ArmorCode and Filigran ArmorCode: AI Exposure Management and Governing Shadow AI AI is moving faster than most governance models can keep up. As organizations race to adopt new AI tools, developer workflows, agents and MCP servers, security leaders must enable innovation without losing control over risk, accountability and oversight. In this segment, ArmorCode will discuss its new AI Exposure Management (AIEM) solution, as part of the ArmorCode Agentic AI Platform. ArmorCode will highlight how AIEM gives enterprises clearer visibility into where AI is being used, who owns it and the potential risks it introduces across heterogeneous environments. By turning AI usage and signals from existing security and IT systems into governed, auditable outcomes, AIEM helps organizations reduce shadow AI risk, assign accountability and accelerate AI adoption with stronger control and board-ready governance. ArmorCode will also share findings from its new 2026 State of AI Risk Management report, developed in partnership with The Purple Book Community and based on responses from more than 650 enterprise security leaders. The discussion will connect ArmorCode's latest product innovation to the broader industry need for scalable, enterprise-ready AI risk governance. ArmorCode AI Exposure Management is available now as a solution deployed on the ArmorCode Agentic AI Platform. To learn more, visit https://securityweekly.com/armorcodersac. Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence In a time where the ability to turn intelligence into decisive action is a true competitive advantage, organizations must move beyond reactive alert triage to a proactive, threat-informed defense. This segment explores how unifying threat intelligence with adversarial attack simulation enables a Continuous Threat Exposure Management (CTEM) framework that replaces hype with measurable outcomes. We will discuss why these are no longer just technical security conversations, but critical business strategies that provide the board and C-suite with the clarity and confidence to reduce risk and focus resources where they matter most. This segment is sponsored by Filigran. Visit https://securityweekly.com/filigranrsac to learn more about them! Segment 3: RSAC interviews with Sekioa and Fortra Agentic AI: Don't Make Your SOC Faster at Being Wrong Adding AI agents to an unprepared SOC doesn't make it smarter; it just makes it "faster at being wrong." Georges Bossert challenges the industry hype to explain why true autonomy relies on reliable context and structured runbooks, not just prompts. He will discuss how to build the necessary foundations to automate rapidly without losing control. This segment is sponsored by Sekoia.io. Visit https://securityweekly.com/sekoiarsac to discover their AI SOC Platform! Scripted Sparrow: A Prolific BEC Group In December, Fortra Intelligence and Research Experts (FIRE) released a major report exposing Scripted Sparrow, one of the most active Business Email Compromise (BEC) collectives operating today. The group sends an estimated 6 million highly targeted scam emails each month, impersonating executive coaching firms and leveraging spoofed reply chains, missing attachment lures, and evolving multilingual campaigns. FIRE's investigation links the collective to 119 domains, 245 webmail accounts, and 256 bank accounts, with members operating across three continents and continually refining their fraud techniques at scale. This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrarsac to learn more about them! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-454
Segment 1: We cover the weekly enterprise news! Segment 2: RSAC interviews from ArmorCode and Filigran ArmorCode: AI Exposure Management and Governing Shadow AI AI is moving faster than most governance models can keep up. As organizations race to adopt new AI tools, developer workflows, agents and MCP servers, security leaders must enable innovation without losing control over risk, accountability and oversight. In this segment, ArmorCode will discuss its new AI Exposure Management (AIEM) solution, as part of the ArmorCode Agentic AI Platform. ArmorCode will highlight how AIEM gives enterprises clearer visibility into where AI is being used, who owns it and the potential risks it introduces across heterogeneous environments. By turning AI usage and signals from existing security and IT systems into governed, auditable outcomes, AIEM helps organizations reduce shadow AI risk, assign accountability and accelerate AI adoption with stronger control and board-ready governance. ArmorCode will also share findings from its new 2026 State of AI Risk Management report, developed in partnership with The Purple Book Community and based on responses from more than 650 enterprise security leaders. The discussion will connect ArmorCode's latest product innovation to the broader industry need for scalable, enterprise-ready AI risk governance. ArmorCode AI Exposure Management is available now as a solution deployed on the ArmorCode Agentic AI Platform. To learn more, visit https://securityweekly.com/armorcodersac. Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence In a time where the ability to turn intelligence into decisive action is a true competitive advantage, organizations must move beyond reactive alert triage to a proactive, threat-informed defense. This segment explores how unifying threat intelligence with adversarial attack simulation enables a Continuous Threat Exposure Management (CTEM) framework that replaces hype with measurable outcomes. We will discuss why these are no longer just technical security conversations, but critical business strategies that provide the board and C-suite with the clarity and confidence to reduce risk and focus resources where they matter most. This segment is sponsored by Filigran. Visit https://securityweekly.com/filigranrsac to learn more about them! Segment 3: RSAC interviews with Sekioa and Fortra Agentic AI: Don't Make Your SOC Faster at Being Wrong Adding AI agents to an unprepared SOC doesn't make it smarter; it just makes it "faster at being wrong." Georges Bossert challenges the industry hype to explain why true autonomy relies on reliable context and structured runbooks, not just prompts. He will discuss how to build the necessary foundations to automate rapidly without losing control. This segment is sponsored by Sekoia.io. Visit https://securityweekly.com/sekoiarsac to discover their AI SOC Platform! Scripted Sparrow: A Prolific BEC Group In December, Fortra Intelligence and Research Experts (FIRE) released a major report exposing Scripted Sparrow, one of the most active Business Email Compromise (BEC) collectives operating today. The group sends an estimated 6 million highly targeted scam emails each month, impersonating executive coaching firms and leveraging spoofed reply chains, missing attachment lures, and evolving multilingual campaigns. FIRE's investigation links the collective to 119 domains, 245 webmail accounts, and 256 bank accounts, with members operating across three continents and continually refining their fraud techniques at scale. This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrarsac to learn more about them! Show Notes: https://securityweekly.com/esw-454
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Honeypot Fingerprinting https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878 Microsoft Locks Accounts for Privacy/Encryption Related Developers https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943 https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/ Remote Code Execution in Apache ActiveMQ (CVE-2026-34197) https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208) https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860 OpenSSH 10.3 Release https://seclists.org/oss-sec/2026/q2/7 Claude Code Vulnerability https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Scans for "adminer" https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808 Background Security Improvement for WebKit https://support.apple.com/en-us/126604 Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC) https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html ScreenConnect 26.1 Security Hardening https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin
I want to hear your thoughts about the show and this episode. Text us here...Leadership development, emotional intelligence, feedback culture, and small business leadership — this episode of Casa De Confidence dives deep into what it truly means to lead in today's evolving workplace.Julie DeLucca-Collins sits down with leadership strategist and fractional HR partner Lindsay White to unpack how vulnerability, authenticity, and emotional intelligence shape effective leadership — whether you're a corporate executive, a first-time supervisor, or a small business owner building your team.If you've ever struggled with:Asking for feedbackManaging your inner critic or saboteurLeading new or high-performing team membersCreating culture intentionallyScaling your business without losing your humanityThis conversation will challenge and equip you.Lindsay shares:The essential traits of a great leader (not a perfect one)Why feedback is the fastest path to growthHow situational leadership changes everythingHow to manage your internal saboteurWhy leadership is a daily practice, not a titleYou'll also hear powerful insights about emotional intelligence, Brené Brown's research on vulnerability, Simon Sinek's purpose-driven leadership philosophy, and how small habits create leadership momentum.This episode is for entrepreneurs, executives, founders, HR professionals, and emerging leaders who want to lead with clarity, courage, and culture.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SmartApeSG campaign uses ClickFix page to push Remcos RAT https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796 A React-based phishing page with credential exfiltration via EmailJS https://isc.sans.edu/diary/32794 Google Chrome announced two zero-day fixes, then removed one. https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html AdGuard Vulnerability https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
YARA-X 1.14.0 Release https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774 INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/ Announcing the Node.js LTS Upgrade and Modernization Program https://openjsf.org/blog/nodejs-lts-upgrade-program nginx UI Vulnerability https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
Fake Fedex Email Delivers Donuts! https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754 Abusing .ARPA: The TLD that isn t supposed to host anything https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/ MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection https://mc.merill.net/message/MC1179154 SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026 https://success.trendmicro.com/en-US/solution/KA-0022458 Special Webcast: AirSnitch How Worried Should You Be? https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be