Podcasts about vuln

exploitable weakness in a computer system

  • 656PODCASTS
  • 1,200EPISODES
  • 30mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Aug 30, 2026LATEST
vuln

POPULARITY

20192020202120222023202420252026


Best podcasts about vuln

Show all podcasts related to vuln

Latest podcast episodes about vuln

Le Gratin par Pauline Laigneau
[Extrait] Pourquoi les meilleurs leaders assument leur vulnérabilité avec Maud Bailly

Le Gratin par Pauline Laigneau

Play Episode Listen Later Aug 30, 2026 2:38


✨ Ce dimanche, je partage avec vous un extrait de ma conversation avec Maud Bailly.Pendant longtemps, on nous a fait croire qu'un bon dirigeant ne doutait jamais. Maud Bailly défend une vision radicalement différente : la vulnérabilité n'est pas une faiblesse, c'est peut-être même l'une des plus grandes forces d'un leader. Une réflexion qui, je pense, parlera à beaucoup d'entre vous.La suite dès lundi matin !Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 27, 2026 7:41


Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 21, 2026 7:21


Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Datestable
Sarah Hamel: La maturité affective

Datestable

Play Episode Listen Later Aug 17, 2026 108:58


Et si nos relations amoureuses en disaient beaucoup plus sur notre maturité affective qu'on le pense?

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 13, 2026 7:06


Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ California law puts digital fingerprints on AI fakes https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Paul's Security Weekly
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

Paul's Security Weekly

Play Episode Listen Later Aug 11, 2026 69:11


Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-395

discovery llm vuln rishi sharma
Paul's Security Weekly TV
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

Paul's Security Weekly TV

Play Episode Listen Later Aug 11, 2026 69:11


Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Show Notes: https://securityweekly.com/asw-395

discovery llm vuln rishi sharma
Application Security Weekly (Audio)
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

Application Security Weekly (Audio)

Play Episode Listen Later Aug 11, 2026 69:11


Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-395

discovery llm vuln rishi sharma
Application Security Weekly (Video)
Using LLMs for Vuln Discovery - Rishi Sharma - ASW #395

Application Security Weekly (Video)

Play Episode Listen Later Aug 11, 2026 69:11


Finding flaws has always been a focus of appsec. And now with open source projects and open weight models orgs have modern tools to review code and conduct pentests. Rishi Sharma describes the motivation behind creating a platform of LLM-driven security tools and the effective ways to keep the tools in scope, on budget, and for engineering teams. We talk about how prompts influence LLM activity, as well as the external constraints to keep the LLMs on task. And even if finding flaws is a major focus of appsec, its goal should be delivering secure software and systems. We touch on some of the ways to keep bugs from creeping back into software and why it's more important to care about vuln classes than vuln counts. Episode Resources: https://projectdiscovery.io/research/ai-coding-impact-report https://projectdiscovery.io/blog/oh-my-rogue-agent Show Notes: https://securityweekly.com/asw-395

discovery llm vuln rishi sharma
Fr. Paul Adrien, L'Amour Vaincra !
Se faire proche des petits, des plus vulnérables • mardi 11 août • Évangile du jour & commentaire

Fr. Paul Adrien, L'Amour Vaincra !

Play Episode Listen Later Aug 11, 2026 3:50


COMMENTAIRE DE L'ÉVANGILE DU JOURMt 18, 1-5.10.12-14À ce moment-là, les disciples s'approchèrent de Jésus et lui dirent : « Qui donc est le plus grand dans le royaume des Cieux ? » Alors Jésus appela un petit enfant ; il le plaça au milieu d'eux, et il déclara : « Amen, je vous le dis : si vous ne changez pas pour devenir comme les enfants, vous n'entrerez pas dans le royaume des Cieux. Mais celui qui se fera petit comme cet enfant, celui-là est le plus grand dans le royaume des Cieux. Et celui qui accueille un enfant comme celui-ci en mon nom, il m'accueille, moi. Gardez-vous de mépriser un seul de ces petits, car, je vous le dis, leurs anges dans les cieux voient sans cesse la face de mon Père qui est aux cieux. Quel est votre avis ? Si un homme possède cent brebis et que l'une d'entre elles s'égare, ne va-t-il pas laisser les 99 autres dans la montagne pour partir à la recherche de la brebis égarée ? Et, s'il arrive à la retrouver, amen, je vous le dis : il se réjouit pour elle plus que pour les 99 qui ne se sont pas égarées. Ainsi, votre Père qui est aux cieux ne veut pas qu'un seul de ces petits soit perdu. »

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 10, 2026 8:03


Linux Shell Forensic: Let s Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able N-Central Issues https://www.n-able.com/blog/n-central-security-update-august-6-2026 Metabase Unauthenticated SQL injection https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Datestable
Kate Moya & Rémi Desgagné: Vulnérabilité et traumas en amour

Datestable

Play Episode Listen Later Aug 10, 2026 79:20


SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Aug 7, 2026 16:29


22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/ Ill Bloom: Crypto Wallet Vulnerability https://illbloom.org Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

TOPFM MAURITIUS
Trafic de drogue entre Maurice et La Réunion : la vulnérabilité des côtes mauriciennes sous la loupe des experts

TOPFM MAURITIUS

Play Episode Listen Later Aug 5, 2026 1:47


Trafic de drogue entre Maurice et La Réunion : la vulnérabilité des côtes mauriciennes sous la loupe des experts by TOPFM MAURITIUS

L'invité politique
Incendies : « Notre vulnérabilité territoriale met des gens en danger, notamment les pompiers », selon la spécialiste Pauline Vilain-Carlotti

L'invité politique

Play Episode Listen Later Aug 3, 2026 16:38


Dans cet épisode de "L'invité de la matinale", Pierre Pillet reçoit Pauline Vilain-Carlotti, géographe spécialiste des incendies de forêt et auteure de l'ouvrage "L'épreuve du feu, habiter autrement la terre". Ensemble, ils explorent les enjeux liés à la gestion des feux de forêt en France et les pistes pour mieux y faire face.L'invitée commence par revenir sur le débat autour du terme "mégafeu", souvent utilisé pour qualifier les incendies de grande ampleur comme celui qui a ravagé 42 000 hectares en Gironde cette année. Elle explique que ce terme n'est pas vraiment adapté au contexte français, où les feux dépassant 10 000 hectares sont rares. En revanche, elle souligne que l'incendie girondin illustre bien la problématique des "feux convectifs", qui s'autonomisent et deviennent ingérables pour les pompiers.La spécialiste insiste ensuite sur la nécessité de changer de regard sur le feu, en le considérant non plus uniquement comme un fléau, mais aussi comme un outil potentiellement bénéfique pour la gestion des espaces naturels. Elle évoque notamment les pratiques de "brûlage dirigé" développées aux États-Unis et dans certaines régions d'Europe méditerranéenne, qui permettent d'entretenir la végétation et de limiter la propagation des grands incendies.Pauline Vilain-Carlotti pointe également les limites des dispositifs réglementaires actuels, comme l'Obligation Légale de Débroussaillement (OLD), qu'elle juge "intéressante mais inopérante". Selon elle, ces outils restent trop individuels et ne prennent pas suffisamment en compte les dynamiques collectives et territoriales. Elle plaide pour une meilleure intégration de la prévention des incendies dans l'aménagement du territoire, à travers notamment les Plans de prévention des risques d'incendie de forêt (PPRIF).Au-delà des aspects techniques, elle insiste sur la nécessité d'un changement de paradigme dans notre rapport au feu. "Nous ne sommes ni dans la gestion ni dans l'anticipation mais dans la réaction", regrette-t-elle, soulignant que nos territoires restent trop vulnérables face à ce risque. Selon elle, il faudra apprendre à "vivre avec le feu" en réduisant cette vulnérabilité, par exemple en limitant l'urbanisation en zone forestière.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

Ecoute le Yoga
Ecoute le Yoga | Les coulisses de ma retraite à Ibiza (2) : rendre un projet public, entre joie et vulnérabilité

Ecoute le Yoga

Play Episode Listen Later Aug 2, 2026 15:17


Dans ce deuxième épisode des coulisses de ma retraite à Ibiza, je te partage un moment charnière : celui où le projet quitte le silence pour devenir public.Après le temps à construire, penser, structurer dans l'ombre, vient le moment de l'annonce. Et je réalise que cette étape est aussi intense que la création elle-même. Perdre le contrôle sur la réception, ressentir à la fois la joie de partager et la vulnérabilité de s'exposer, apprendre à avancer sans tout verrouiller : voilà ce que j'explore avec vous aujourd'hui.Un épisode sincère sur ce que ça fait de rendre un projet personnel réel pour les autres, et sur cette oscillation entre confiance et doute qui accompagne toute création.

Les Sens de la Danse
Un pas de côté — Corps vulnérables, corps dansants : une autre histoire de la danse

Les Sens de la Danse

Play Episode Listen Later Jul 29, 2026 3:12


Pourquoi la danse est-elle aujourd'hui présente dans les hôpitaux, les maisons de retraite ou les lieux de soin ?Dans ce Pas de côté des Sens de la Danse, Myriam Sellam retrace les grandes étapes de cette évolution à travers quelques repères historiques et internationaux.Des expérimentations d'Anna Halprin aux États-Unis dans les années 1960 jusqu'au développement de la community dance au Royaume-Uni, découvrez comment la danse a progressivement quitté les scènes traditionnelles pour rencontrer des corps fragilisés, sans jamais perdre sa dimension artistique.Une capsule pour mieux comprendre pourquoi, aujourd'hui, le mouvement est reconnu comme un langage accessible à tous les corps, quels que soient l'âge, la maladie ou les capacités physiques.

Les matins
Incendies : les causes de la vulnérabilité / Nucléaire civil saoudien / Vinciane Despret, en festival dans le Luberon

Les matins

Play Episode Listen Later Jul 27, 2026 122:47


durée : 02:02:47 - Les Matins de France Culture - par : Bérengère Bonte - Ce matin à 7 h 38, Bérengère Bonte reçoit Philippe Grandcolas et Christine Bouisset pour revenir sur la vulnérabilité de nos territoires face aux incendies et interroger les implications politiques de ceux-ci. - équipe : Félicie Faugère, Mathilde Thon-Fourcade, Victoria Géraut-Velmont, Inès Bouffartigue Sebastia, Rodi Eken, Anouk Seveno, Salomé Erbs, Romain Rincon Hernandez Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France

Les matins
Incendies : la France a-t-elle provoqué sa vulnérabilité ?

Les matins

Play Episode Listen Later Jul 27, 2026 39:15


durée : 00:39:15 - Les Matins de France Culture - par : Bérengère Bonte - 98 000 hectares brûlés depuis janvier... Les flammes ont atteint ce week-end les portes de Bordeaux et 200 000 personnes ont été évacuées. Le climat amplifie le risque : que révèle cette vulnérabilité de nos choix d'aménagement et de nos politiques environnementales ? - équipe : Phane Montet, Mathilde Thon-Fourcade, Victoria Géraut-Velmont, Inès Bouffartigue Sebastia, Rodi Eken, Romain Rincon Hernandez, Salomé Erbs - invités : Christine Bouisset Géographe, professeure à l'université de Pau, membre du réseau régional de recherche sur le changement climatique Futurs-Act, Philippe Grandcolas Directeur de recherche au CNRS, directeur adjoint scientifique national pour l'écologie et l'environnement au CNRS, Philippe Grandcolas écologue, directeur adjoint scientifique national pour l'Écologie et l'Environnement au CNRS Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France

Appels sur l'actualité
Royaume-Uni: Londres tourne-t-il le dos aux États africains les plus vulnérables?

Appels sur l'actualité

Play Episode Listen Later Jul 27, 2026 3:20


Le Royaume-Uni a confirmé des coupes budgétaires massives dans son aide au développement destinée à plusieurs pays africains, conséquence de la réduction progressive de l'effort d'aide de 0,5% à 0,3% du PIB d'ici 2027. Selon les détails publiés, le Mozambique, le Malawi, le Kenya et la Tanzanie verront leurs versements britanniques diminuer de 90% d'ici 2029, tandis que la Somalie et le Soudan du Sud subiront des réductions de près de 50%, malgré des contextes marqués par les conflits et les crises humanitaires. Comment expliquer cette décision ? À quel point les pays africains peuvent-ils en être impactés ? Londres avait promis de remplacer une partie de ces financements directs par une « assistance technique » via des ONG et des consultants. Ce système peut-il compenser les coupes budgétaires ? Avec Emeline Vin, correspondante de RFI à Londres. 

Absolute AppSec
Episode 328 - Wordpress RCE, Vuln Prioritization, AI memory exfiltration

Absolute AppSec

Play Episode Listen Later Jul 21, 2026


In episode 328 of Absolute AppSec, sponsored by GuardSquare (guardsquare.com), Seth and Ken start by highlighting a newly disclosed, pre-authentication WordPress core Remote Code Execution (RCE) vulnerability ("WP2Shell"). The core discussion centers on Alex Gaynor's article regarding the influx of AI-assisted vulnerability disclosures. Gaynor and the hosts argue that attempting to fix bugs case-by-case is a "fool's errand"; instead, engineering teams must eradicate entire vulnerability classes through systemic, framework-level safe functions (such as parameterized queries) and automated CI/CD guardrails. They dive into the complexities of bug prioritization—debating reachability analysis, runtime verification, and business asset criticality—while noting that metrics and measurement remain among the lowest-scoring activities in OWASP SAMM assessments. Later, Ken and Seth examine a "Memory Heist" attack on Claude AI where indirect prompt injection tricked the assistant into exfiltrating user memory and corporate details letter-by-letter through web navigation. They conclude that because transformer models were originally designed for next-token prediction rather than secure system boundaries, defending LLM architectures behaves more like stopping social engineering than traditional software fuzzing.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 17, 2026 5:35


German Federal Information Security Office Analyzes Windows Hello for Business https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7 NGINX Vulnerability https://my.f5.com/manage/s/article/K000162097 7-Zip XZ Decompression CVE-2026-14266 https://www.zerodayinitiative.com/advisories/ZDI-26-444/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 14, 2026 7:16


Someone Is Scanning for Your MCP Servers and AI Assistant Credentials https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofing https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 https://www.veeam.com/kb4869 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Absolute AppSec
Episode 327 - w/Coffee, Chaos, and ProdSec - ASPM Consolidation, Vuln Prioritization

Absolute AppSec

Play Episode Listen Later Jul 14, 2026


In episode 327 of Absolute AppSec, co-hosts Ken Johnson and Seth Law present a highly anticipated quarterly crossover episode with Cameron and Kurt from the Coffee, Chaos, and ProdSec podcast. Sponsored by GuardSquare, the group begins with lighthearted banter about their personal footwear choices before tackling heavy architectural debates. The primary focus shifts to Application Security Posture Management (ASPM) consolidation. Cameron strongly advocates for utilizing ASPM as a distinct, single pane of glass dashboard to deduplicate vulnerabilities and streamline executive reporting by product suite. However, the hosts contrast this ideal against the messy reality of organizations dealing with a "Frankenstein" mix of loosely bootstrapped open-source scanning tools and competing vendor plugins. The discussion deepens into prioritization strategies amid a massive, AI-driven surge in vulnerability research that threatens to double annual CVE counts. Cameron and Kurt stress the necessity of shifting away from abstract CVSS scores toward custom, runtime-informed risk appetites and impact analysis—prioritizing the hardening of high-risk corporate assets over low-reachability internal flaws. They also examine the critical line separating standard software bugs from intentionally malicious open-source packages that target developer endpoint systems. Ultimately, the panel laments that AppSec teams are effectively functioning as corporate incident responders because Security Operations Center (SOC) analysts lack product-level insight. The episode concludes with a review of automated agent statistics and a fun look ahead to the future emergence of meta OWASP top-ten risk lists.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 13, 2026 5:32


Progress Sharefile Emergency Shutdown Notice https://status.sharefile.com https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/ https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/ U-Boot Vulnerabilities https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification Nightmare Eclipse Releases Next Microsoft Defender Exploit https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/ Cisco Increases Patch Cadence https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jul 2, 2026 6:15


Why Ask Credentials If There Are Secret Codes? https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118 Adobe Patches and Updated Patch Release Policy https://helpx.adobe.com/security/Home.html https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery Google Chrome Update (link had issues loading while recording) https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Vlan!
[Solo] La vraie violence est celle dont on ne parle pas

Vlan!

Play Episode Listen Later Jul 2, 2026 28:49


Dans cet épisode solo, je pars d'un concours de circonstances de la semaine dernière avec le partage de deux stories Instagram publiées l'une à la suite de l'autre, l'une avec une citation de Romain Lemire sur l'inceste ("le silence, c'est ce qui permet aux prédateurs d'agir"), l'autre avec un carrousel tiré de mon épisode avec Frédéric Semama sur l'inaction climatique. Des dizaines de personnes m'ont écrit pour me dire que les deux se faisaient écho et cam'a amené à réfléchir car ils avaient raison.Dans cet épisode, je parle de la violence invisible, je questionne pourquoi 61 672 morts en un seul été européen ne génèrent pas le même niveau d'urgence politique que ce qu'on appelle "l'insécurité". J'ai exploré trois concepts qui m'ont aidé à mettre des mots sur ce malaise : la violence symbolique de Bourdieu, la violence lente de Rob Nixon et l'homéopathisation de la violence de Maffesoli. Et à la fin, je plaide pour une seule chose : nommer. Parce que ce qui n'a pas de mot n'existe pas dans les institutions.CITATIONS MARQUANTES"Le silence, c'est ce qui permet aux prédateurs d'agir." — Romain Lemire, sur Vlan!"La vraie violence, en 2026, n'est pas uniquement celle dont on parle mais plutôt celle qu'on tait et que souvent on ne classe pas dans la bonne case." — Gregory Pouy"Il n'y a pas de monstre, il n'y a que des personnes qui font des choses monstrueuses." — Un juge, sur Vlan!"Ce qui n'a pas de mot pour le définir n'existe pas. Les mots créent de la réalité institutionnelle." — Gregory Pouy"Intégrer l'animalité permet d'éviter la bestialité." — Michel Maffesoli (rapporté par Gregory Pouy)IDÉES CENTRALES Big Idea 1 — La violence visible capte tout, la violence systémique tue en silenceExplication : L'agression dans le métro, la vitrine brisée font de bonnes images et définissent un "monstre". Les 61 672 morts européens de l'été 2022 (= 20x les homicides en France sur une décennie 2010-2020) ne font pas d'image et n'ont pas de coupable identifiable. Le débat politique, les lois et les budgets suivent les images, pas les chiffres. Pourquoi c'est important : C'est un mécanisme de détournement qui a des effets politiques réels et mesurables. Position : Section 2 (La violence que les caméras aiment)Big Idea 2 — La violence symbolique (Bourdieu) : le système qui se rend légitime aux yeux de ses victimesExplication : La domination la plus efficace est celle que les dominés perçoivent comme naturelle ou méritée. Pour l'inceste : silence institutionnel pendant des décennies. Pour le climat : dissémination de la responsabilité individuelle égale pour dédouaner les vrais auteurs. Pourquoi c'est important : Elle n'est pas un ajout à la violence physique, elle en est la condition de possibilité. Position : Section 3Big Idea 3 — La violence lente (Rob Nixon) : le crime parfaitExplication : Les violences environnementales sont graduelles et invisibles. Nos mécanismes cognitifs, médiatiques et politiques sont calibrés pour l'instantané. La canicule sera oubliée dans 3 semaines. Les pauvres meurent 2x plus que les riches lors des pics de chaleur, à Madrid comme à Varsovie. Pourquoi c'est important : La violence lente frappe d'abord les corps déjà fragilisés par d'autres formes de violences, sans laisser de scène de crime claire. Position : Section 4Big Idea 4 — Nommer crée des obligations politiquesExplication : Le mot "féminicide" a permis de compter séparément, d'analyser les schémas, de former les gendarmes et de changer les procédures. "Violence climatique" et "insécurité climatique" forcerait les politiques et les journalistes à traiter le sujet autrement qu'en relégation de fin de journal. Pourquoi c'est important : Ce qui n'a pas de mot n'existe pas dans le droit, donc pas dans la politique, donc pas dans le budget. Position : Section 5Big Idea 5 — L'homéopathisation de la violence (Maffesoli) : ritualiser pour éviter la bestialitéExplication : La violence est structurelle à ce que nous sommes. Ni l'éliminer ni la nier, mais lui donner un cadre. Le carnaval, le duel codifié, les jeux de l'amphithéâtre avaient cette fonction. Quand une société refuse de nommer certaines violences, elle les refoule. Et un refoulement à grande échelle produit des symptômes : colères politiques diffuses, agressivité en ligne, défiance dans les institutions. Pourquoi c'est important : La canicule génère une violence psychique collective réelle : la conscience diffuse qu'une injustice se passe, sans mot pour la dire, sans coupable désigné, sans recours. Position : Section 6Big Idea 6 — Inceste et climat : deux applications du même principeExplication : Le prédateur familial compte sur la honte, la loyauté et l'absence de mots. L'industrie pétrolière compte sur le silence politique, la dissémination du doute et l'absence de catégories juridiques. Ce ne sont pas deux phénomènes sans rapport : la violence survit grâce à son invisibilité, activement maintenue par ceux qui ont le pouvoir de nommer. Pourquoi c'est important : C'est le cadrage central de toute la newsletter, et un cadrage est déjà un acte politique. Position : Section 8 (conclusion)RÉFÉRENCES CITÉESPersonnes (invités ou cités dans le podcast / newsletter)Romain Lemire — invité Vlan!, sur le silence comme condition de l'inceste et de la prédation. Citation centrale de la newsletter.Frédéric Semama — invité Vlan!, épisode "Pourquoi on sait tout sur le climat et on ne fait rien". Point de départ de la réflexion.Un juge (anonyme) — invité Vlan!, citation : "Il n'y a pas de monstre, il n'y a que des personnes qui font des choses monstrueuses."Catherine Turner — actrice, analyse des "menaces invisibles" subies par les femmes. Citée sur la notion de zone grise entre préjudice réel et non-reconnu par le droit.Penseurs et théoriciensPierre Bourdieu — concept de violence symbolique : la domination intériorisée comme légitime et naturelle par les dominés. Section 3.Rob Nixon — théoricien littéraire américain, concept de "violence lente" (slow violence) appliqué aux violences environnementales. Section 4.Michel Maffesoli — sociologue français, "Essai sur la violence". Concept d'homéopathisation de la violence : ritualiser l'agressivité pour éviter la bestialité. Section 6.René Girard — philosophe français, désir mimétique et mécanisme du bouc émissaire. Cité en parallèle de Maffesoli. Section 6.Gaston Bachelard — philosophe français, citation : "les révolutions conceptuelles se font toujours contre les mots de la génération précédente." Section 5.Livres citésEcotopia — Ernest Callenbach, roman utopique. Imagination de jeux de guerre rituels codifiés entre communautés comme gestion de la violence. Section 6. (Recommandé vivement par Gregory Pouy)Essai sur la violence — Michel Maffesoli. Cité directement.Études et donnéesNature Medicine (2023) — étude sur les 61 672 morts de la chaleur en été 2022 en Europe. Données par pays : Italie 18 010, Espagne 11 324, Allemagne 8 173. Vulnérabilité double dans les quartiers défavorisés. Section 2.Études sur la mortalité climatique différentielle — Recherches entre Madrid et Varsovie sur la surmortalité des pauvres lors des canicules (2x). Section 4.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

Reportage International
En Allemagne, un «asile religieux» pour les personnes particulièrement vulnérables

Reportage International

Play Episode Listen Later Jul 2, 2026 2:30


L'Allemagne accueille depuis une dizaine d'années des centaines de milliers de migrants, l'immense majorité est prise en charge dans un premier temps dans des foyers et ils sont répartis à travers tout le pays. Mais chaque année, environ 2 500 personnes bénéficient d'un « asile religieux » et sont hébergées par des églises catholiques et protestantes parce qu'elles sont particulièrement vulnérables.  De notre correspondant à Berlin, Antoine – qui a préféré ne pas donner son vrai nom – fait visiter l'appartement dans la paroisse de l'église protestante de Forst, dans le Brandebourg, où il est hébergé. Le jeune Camerounais partage cet appartement de trois pièces avec un Tchadien. Antoine est arrivé à la rentrée dernière en Allemagne. « Je viens du Cameroun, de Douala précisément. J'ai quitté le Cameroun parce que je suis homosexuel et l'homosexualité au Cameroun est très mal vue, témoigne-t-il, donc c'était très difficile. » Antoine est arrivé en Europe via la Roumanie. L'Allemagne avait six mois, conformément aux règles de Dublin, pour le renvoyer dans ce pays par lequel il est entré dans l'Union européenne. On a proposé au jeune homme de bénéficier du « Kirchenasyl », de l'asile religieux : une paroisse décide d'héberger un migrant dans une situation difficile pour le protéger. « La situation juridique est claire : on doit protéger les êtres humains, souligne Simon Klaas, le pasteur à Forst qui a accueilli Antoine. Ils ont le droit à l'asile politique. Une institution comme l'Église a le devoir de défendre ce droit. » À écouter dans Accents d'EuropeImmigration irrégulière: vers des expulsions massives en Allemagne et les Talibans à Bruxelles L'Église remplace l'État Cet asile religieux existe depuis une quarantaine d'années. Les autorités sont au courant, les paroisses doivent expliquer pourquoi les personnes accueillies sont particulièrement vulnérables, comme le fait pour Antoine d'être homosexuel. « Le fait d'être ici, à force, l'asile de l'Église m'a apporté la sécurité, confie Antoine. Déjà, parce qu'au camp, je n'étais pas vraiment en sécurité. La police vient souvent déporter les gens de Dublin vers leur pays d'origine. C'est un grand soulagement que les six mois de la procédure de Dublin soient passés. Je suis très content. » Cet accueil signifie que la paroisse remplace la puissance publique. Elle met un hébergement à disposition et Antoine reçoit 200 euros par mois de l'église de Forst pour se nourrir et pour ses autres frais.  Dans le Brandebourg, région qui entoure Berlin, une quinzaine de paroisses sur 500 offrent un asile religieux. Toutes n'ont pas les capacités logistiques, bien sûr. Mais nous sommes aussi dans un Land où l'extrême droite séduit un tiers de l'électorat. Simon Klaas ne crie pas sur les toits qu'il héberge des migrants. « L'extrême droite réinterprète les valeurs chrétiennes. Aime ton prochain se réduit à la famille ou aux voisins et à ceux qui te ressemblent, mais pas aux autres, dénonce le pasteur. C'est une perversion. » Antoine n'a pas souffert du racisme à Forst où il séjourne encore. Il y a deux jours, sa procédure d'asile en Allemagne a débuté avec un entretien de plusieurs heures. Il devrait connaître la décision des autorités après l'été.  À lire aussi«Nous y arriverons»: en Allemagne, l'intégration des réfugiés progresse dans une société polarisée

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 30, 2026 5:24


Adding some Automation to the favicon.ico method of Host Recon https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110 Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626 Google Gemini CLI Vulnerability CVE-2026-12537 https://github.com/advisories/GHSA-jj69-4grx-fqj5 IPv6 Frag Escape https://github.com/sgkdev/ipv6_frag_escape My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Camille passe au vert
Le train beaucoup trop vulnérable face au dérèglement climatique

Camille passe au vert

Play Episode Listen Later Jun 25, 2026 2:29


durée : 00:02:29 - Debout la Terre - La SNCF affiche partout à bord que "choisir le train, c'est agir pour la planète". Mais qui agit pour le train ? Beaucoup trop vulnérable face à la crise climatique. C'est le résultat d'années de sous-investissements et de manque d'anticipation. Vous aimez ce podcast ? Pour écouter tous les épisodes sans limite, rendez-vous sur Radio France

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 24, 2026 6:48


CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SBS French - SBS en français
Semaine politique: Le discours de Hanson condamné pour ses attaques contre les Australiens vulnérables

SBS French - SBS en français

Play Episode Listen Later Jun 22, 2026 8:12


Le discours de Pauline Hanson, dirigeante du parti One Nation, devant le National Press Club, a été condamné pour ses attaques contre les migrants, les personnes transgenres, les jeunes parents et les médias publics. Accusée de ne proposer aucune solution crédible, la sénatrice Hanson a vu son discours jugé inquiétant et irresponsable par ses détracteurs.

On marche sur la tête
Affaire Lyhanna : «Quand l'Etat n'est plus capable de protéger les plus vulnérable, il faut que des responsabilités soient dégagées » selon Me Jean Sannier

On marche sur la tête

Play Episode Listen Later Jun 21, 2026 3:40


Eliot Deval revient pendant deux heures, sans concession, sur tous les sujets qui font l'actualité. Vous voulez réagir ? Appelez le 01.80.20.39.21 (numéro non surtaxé) ou rendez-vous sur les réseaux sociaux d'Europe 1 pour livrer votre opinion et débattre sur les grandes thématiques développées dans l'émission du jour.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 17, 2026 8:07


From a VHDX File to a Remcos RAT https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080 A backdoor in a LinkedIn job offer https://roman.pt/posts/linkedin-backdoor/ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html Copilot M365 Data Leakage https://www.varonis.com/blog/searchleak My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Pascal Praud et vous
Justice et impunité : la société française face à l'insécurité des plus vulnérables

Pascal Praud et vous

Play Episode Listen Later Jun 16, 2026 10:00


Pascal Praud et ses invités dressent un constat accablant : la justice française peine à protéger les plus fragiles. Entre la relaxe d'un animateur parisien accusé d'agressions sexuelles sur mineurs, le drame de Lyhanna, le calvaire d'une grand-mère agressée dans une église, et le témoignage glaçant du père de Yann, adolescent suicidé après une agression sexuelle, l'émission explore les failles d'un système judiciaire souvent perçu comme défaillant.Vous voulez réagir ? Appelez-le 01.80.20.39.21 (numéro non surtaxé) ou rendez-vous sur les réseaux sociaux d'Europe 1 pour livrer votre opinion et débattre sur grandes thématiques développées dans l'émission du jour.Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 15, 2026 6:50


Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ A Fake Bug Report Hijacks Your AI Coding Agent and Nothing Catches It. https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Resilient Cyber
AI Industrialized the Vuln Lifecycle and Broke the System of Record

Resilient Cyber

Play Episode Listen Later Jun 15, 2026 40:43


VulnCheck's Patrick Garrity on the NVD collapse, the first real AI disclosure wave, and why remediation, not finding bugs, is the bottleneck.DescriptionVulnerability management spent years as the chore everyone dreaded, and now it is one of the hottest topics in security because attackers made exploitation the number one way in. Patrick Garrity of VulnCheck rejoins the show to separate what is real from what is marketing. We get into the honest state of the NIST National Vulnerability Database after CISA pulled its funding, the new AI executive order that wants a clearinghouse for AI-discovered vulnerabilities, the first measurable wave of AI-assisted disclosures, and Patrick's audit of Anthropic's Glasswing ledger. We also dig into why cheap AI discovery makes the remediation bottleneck worse, how AI is raising the security poverty line, and whether the 90-day disclosure model still holds.Key takeawaysVulnerability management is hot again because attackers made it the top way in. As Patrick puts it, attention flows to wherever the attacker goes, and right now that is exploitation.The NIST NVD breakdown was worse than a backlog. A recent report confirmed CISA had stopped funding the NVD and NIST lost about half its funding, with no real plan to clear the backlog, which quietly hurts every defender who relies on enriched CVE data.A new AI executive order wants a clearinghouse for AI-discovered vulnerabilities, reportedly under Treasury. Patrick's reaction is that we already have a vulnerability database, the program is optional, and it may turn into a marketing race more than a coordination win.The first measurable AI disclosure wave is real. CVE volumes are up 563 percent for Chrome and GitHub advisories up 470 percent year to date, and Patrick separated genuine AI-assisted discovery from AI slop and from bugs that merely live in AI software by correlating researchers, domains, and email addresses across multiple advisory sources.Patrick audited Anthropic's Glasswing ledger and found the transparency lacking. He had around 80 vulnerabilities in his own database while the public ledger listed 27, several items had blown past their own 90-day disclosure window, and the ledger had not been updated in two weeks.Finding vulnerabilities is not the bottleneck, remediation is. AI makes discovery cheap, but the coordinated disclosure and fix process takes enormous human effort, and the median time to remediate even known exploited bugs is still measured in weeks.Exploitation looks like it is sustaining rather than surging. CISA KEV and VulnCheck KEV are tracking similar year-over-year volumes, partly because attackers already have more than enough to target and partly because you can only count the exploitation you can actually detect.AI is raising the security poverty line, at least for now. Token costs and access-restricted tools concentrate the most powerful discovery capabilities among well-funded teams, while smaller organizations lack the expertise to turn open-weight models into working vulnerability harnesses.The economics are circular. AI drives the surge in findings and attacker velocity, and AI is then sold as the fix, so teams pay to surface the problem and pay again to remediate it, all on consumption-based pricing against finite budgets.The 90-day disclosure norm mostly holds, though it may tighten. VulnCheck runs a strict 120-day policy with no exceptions and averages 45 to 48 days to fix and disclose, and for open source the fixing commit often makes the flaw public anyway.

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, June 3rd, 2026: SVG Phishing; Android Patches; Poly Voice Vuln; Ivanti Neurons Priv Escelation

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 3, 2026 3:59


New Wave Of Phishing Emails with SVG Files https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040 Android 2026-06-01 security patch level vulnerability details https://source.android.com/docs/security/bulletin/2026/2026-06-01 Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826 https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083 https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/ Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Monday, June 1st, 2026: Bitskrieg; Gogs Unpatched Vuln; Oracle Critical Updates; PAN-OS Exploited;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Jun 1, 2026 4:58


Announcing Bitskrieg https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html Vulnerability in Gogs https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/ Oracle Critical Security Patch Update Advisory - May 2026 https://www.oracle.com/security-alerts/cspumay2026.html GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257 https://security.paloaltonetworks.com/CVE-2026-0257

Security Conversations
Microsoft Threatens Vuln Researchers; Shadow Brokers Revisited

Security Conversations

Play Episode Listen Later May 30, 2026 119:45


(Presented by Ent.ai: Ent delivers intent-aware security that protects every action, adapts to every workflow, and works for every user. Enterprise threat detection, reimagined.) Three Buddy Problem - Episode 99: Microsoft is now threatening legal action against researchers who drop zero-days. We debate whether it's a fair line against extortion, or amateur-hour PR from a company that already torched its own research community? Costin plays reluctant defender, JAGS says the damage was done years ago, and Ryan reopens the long history of silent fixes and stolen bounties. Plus, on the 10th anniversary of the Shadow Brokers leak, we discuss some enduring mysteries, theories on attribution and an interesting trail that leads to Edward Snowden. We also unpack Rob Joyce's warning that China's cyber explosives are already planted in US infrastructure, and the Pope's warnings about around artificial intelligence. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. Timestamps: 0:00 - Introductory banter 2:03 - The Pope's AI paper 3:35 - New sponsor: Brandon Dixon's Ent Security 9:34 - Costin's Chinese-model OSINT rabbit hole 13:34 - Codex, GPT-5.5, and the "American AI welfare state" 23:20 - Microsoft threatens vulnerability researchers 27:06 - Is it extortion or retribution? The disclosure fight 40:48 - How Microsoft's consultant class broke MSRC and MSTIC 48:42 - Silent fixes, stolen bounties, and the marketing machine 1:02:29 - Ten years of the Shadow Brokers 1:14:20 - The Snowden theory 1:32:34 - Rob Joyce: China's cyber explosives are in place 1:53:26 - Shout-outs

Security Conversations
Find 50,000 Bugs, Fix Zero: Gabriel Bernadett-Shapiro on the AI Vuln Trap

Security Conversations

Play Episode Listen Later May 26, 2026 49:37


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be told

Security Conversations
Perri Adams on Proof Engines, LLMs, and the New Era of Verifiable Code

Security Conversations

Play Episode Listen Later May 26, 2026 40:27


(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential. We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex. Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Perri Adams. Timestamps: 0:00 — Introductory banter 1:09 — Why LLMs just made formal methods relevant again 4:03 — Proof engines, explained 8:43 — Can a layman grab this fire? The calculus problem 11:58 — Vuln researchers are scrappy kids with a trust fund 14:55 — Pitching AIxCC inside DARPA: hard sell or easy sell? 18:00 — Designing a challenge that's allowed to fail 22:06 — Inside Team Atlanta's 150-page winning system 24:00 — Why this is bigger for defense than for offense 31:49 — Mythos, safeguards, and "every LLM bug is a public bug"

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, May 21st, 2026: GitHub Breach; Agentic Threat Intel Feed; NGINX Vuln; YellowKey Fix; Incomplete SonicWall Patch

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 21, 2026 5:39


GitHub Breach https://x.com/github/status/2056949168208552080 Agentic Threat Intelligence Feed - VS Code Extensions https://agentmesh.knostic.ai/extensions More NGINX Vulnerabilities https://x.com/nebusecurity/status/2057071579876753643 https://my.f5.com/manage/s/article/K000161307 Microsoft Publishes YellowKey Mitigation CVE-2026-45585 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Incomplete Sonicwall Patch CVE-2024-12802 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, May 15th, 2026: Website Fraud; Outlook Link Preview Bug; NGINX Vuln; Cisco 0-Day

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 15, 2026 6:54


Tearing apart website fraud to see how it works. (@sans_edu) https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958 Simple bypass of the link preview function in Outlook Junk folder https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990 NGINX Vulnerability https://depthfirst.com/nginx-rift Cisco SDWan 0-Day https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, May 8th, 2026: AI Generated Dashboard; Ivanti Patches; Redis Vuln; @sans_edu Marcio Enriquez

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 8, 2026 14:54


An Adaptive Cyber Analytics UI for Web Honeypot Logs https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962 Ivanti May Patchday https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631] https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/ @sans_edu research paper: Marcio Enriquez [link will be added once the paper has been published]

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Tuesday, May 5th, 2026: Honeypot Update; MOVEit Patches; Apache http2 Vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 5, 2026 5:05


DShield Honeypot Update https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948 MOVEit Automation Critical Security Alert Bulletin April 2026 (CVE-2026-4670, CVE-2026-5174) https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 Apache httpd http2 vulnerability https://seclists.org/oss-sec/2026/q2/387

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Friday, May 1st, 2026: Libredtail; FreeBSD dhclient vuln; Linux Copy-Fail; @sans_edu Detecting AI Pickling

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later May 1, 2026 14:42


Danger of Libredtail https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936 FreeBSD dhclient vulnerability https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc Linux Copy-Fail Vulnerability CVE-2026-31431 https://copy.fail Bryan Nice Research Paper https://www.linkedin.com/in/bryannice/ https://www.sans.edu/cyber-research/detecting-ai-pickling

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Wednesday, April 29th, 2026: Odd Vercel Header Usage; GitHub Vuln Patches; MSFT RDP Notification Bug

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 29, 2026 5:26


HTTP Requests with X-Vercel-Set-Bypass-Cookie Header https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930 GitHub Vulnerability CVE-2026-3854 https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Microsoft RDP Notification Bug https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883

Funbearable
#196 - Vuln-bearable II

Funbearable

Play Episode Listen Later Apr 29, 2026 87:54


YoutubeThe boys get honest! Chuck dives deep into his insecurities (fun!) related to a recent incident with creative partners. Brad gets into his improv history and what drove him away for a long time. Get ready for some emotion!Video Edit by Craig Depina of the Needless to Say podcast@funbearablepod / funbearablepod.com#friends #insecurities #comedy #honesty

needless vuln video edit
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Apr 9, 2026 7:40


Honeypot Fingerprinting https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878 Microsoft Locks Accounts for Privacy/Encryption Related Developers https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943 https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/ Remote Code Execution in Apache ActiveMQ (CVE-2026-34197) https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/