『Daily DefSec Brief』のカバーアート

Daily DefSec Brief

Daily DefSec Brief

著者: Jerry Bell
無料で聴く

A daily podcast covering the important cyber security news that IT and security teams need to know.

2026 Jerry Bell
政治・政府
エピソード
  • Cyber Security News for September 2 2026 - Daily DefSec Brief
    2026/09/02
    1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ 2. JFrog Artifactory authentication bypass exploited four days after the patch — CVE-2026-82329 — SC World — https://www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release 3. Langflow remote code execution used to harvest OpenAI and AWS keys — CVE-2026-0768 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/ 4. Twenty-two thousand Exchange servers still unpatched against a mailbox takeover flaw — CVE-2026-62911 — BleepingComputer — https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 5. AI agents ran a full ransomware intrusion in under ten hours — Unit 42 — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ 6. FBI warns of consent phishing that takes an account without a password — CyberScoop — https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/ 7. Sangoma Switchvox SQL injection is being exploited seven weeks after the fix — CVE-2026-9586 — The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html 8. GeoNetwork chain gives unauthenticated code execution on government geoportals — CVE-2026-63219 — The Hacker News — https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html 9. Counterfeit software download sites are installing malware that turns Defender off — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ 10. Phishing crew abuses a real endpoint-management platform to install ScreenConnect — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/ 11. Airport breach traced to admin keys sitting in the websites' own JavaScript — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/ 12. Stolen API key burned 600,000 dollars of model credits before anyone noticed — The Register — https://www.theregister.com/security/2026/09/01/attacker_stole_a_metr_api_key_used_600k_worth_of_credits_and_no_one_noticed_for_weeks/5293730 13. Hugging Face Transformers writes remote code to disk before asking permission — CVE-2026-80047 — CERT/CC — https://kb.cert.org/vuls/id/456290 14. SageMaker SDK leaves its signing key in cleartext where any account role can read it — CVE-2026-83551 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/ 15. Thirteen poisoned Composer packages on Packagist attack visitors of the sites that install them — CVE-2025-31277, CVE-2025-43398, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529 — The Hacker News — https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html 16. Attackers are installing Apache modules that quietly proxy visitors to phishing pages — Check Point Research — https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/
    続きを読む 一部表示
    5 分
  • Cyber Security News for September 1 2026 - Daily DefSec Brief
    2026/09/01
    1. OpenSearch SQL plugin deserialization flaw gives a read-only user code execution — CVE-2026-83497 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/ 2. BGP hijack pushed a malicious Virtualizor update onto hypervisor management servers — Virtualizor — https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ 3. McKesson breach ran from vishing calls through Okta into Salesforce and Snowflake — SC World — https://www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records 4. Password-spraying campaign hit AWS root accounts at more than 150 organizations — Datadog Security Labs — https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/ 5. Scanners are forging AI-crawler user agents to hunt for exposed credentials — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/ 6. A honeypot posing as a free LLM endpoint caught a real coding agent handing over its tools — SANS ISC — https://isc.sans.edu/diary/rss/33298 7. Mirage Kitten hides two new cross-platform RATs in trojanized coding-challenge archives — Securelist — https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/ 8. Researcher drops a working privilege-escalation exploit for Kaspersky Endpoint Security — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/ 9. Residential proxy networks rent out home connections with clean IP reputations — Ars Technica — https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/ 10. BREEZE COMET manipulates Brazilian banking software to move fraudulent transfers — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/ 11. Guildma delivery is geofenced to Brazil and hides its payload in an alternate data stream — SANS ISC — https://isc.sans.edu/diary/rss/33300 12. Boston Scientific outage leaves newly implanted heart devices without remote monitoring — The Register — https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537 13. OpenClaw 2.0 makes the agent harness easier to install and leaves security to the user — The Register — https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492 14. CrowdSec 1.8.0 ships two denial-of-service fixes alongside new bot detection — Help Net Security — https://www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/
    続きを読む 一部表示
    5 分
  • Cyber Security News for August 31 2026 - Daily DefSec Brief
    2026/08/31
    1. PaperCut ships a second emergency patch after attackers chain two zero-days — CVE-2026-82078, CVE-2026-81578 — SecurityWeek — https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/ 2. Ruby on Rails file-read flaw is being exploited for remote code execution — CVE-2026-66066 — SecurityWeek — https://www.securityweek.com/critical-ruby-on-rails-vulnerability-in-attackers-crosshairs/ 3. Self-spreading worm planted in an npm package with 150,000 weekly downloads — Cyber Security News — https://cybersecuritynews.com/popular-npm-package/ 4. China-linked Fire Ant moves into Cisco routers and TACACS servers to blind logging — The Hacker News — https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html 5. AWS Systems Manager agent path traversal lets a limited user write files as root — CVE-2026-81849 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-091-aws/ 6. TerminalFix pastes a fake CAPTCHA command into Windows Terminal and opens a reverse tunnel — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ 7. Fake IT help desk calls over external Teams accounts end in NTLM relay to the domain controller — Unit 42 — https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ 8. Infostealers are lifting live Claude sessions and walking past two-factor — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/ 9. Nineteen Chrome and Edge extensions were backdoored through automatic updates — The Hacker News — https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html 10. Russian operators embed a nuclear-weapons prompt in malware to make AI analysis tools refuse — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/ 11. A file that passes as an MP4 carries 6.5 MB of encrypted NetSupport RAT — Censys — https://censys.com/blog/fake-mp4-file-carries-malicious-payload/ 12. Voicemail-themed SVG attachments smuggled JavaScript past email filters at 5,527 organizations — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/ 13. ValleyRAT ships as signed adware so users add it to their own exclusion lists — Securelist — https://securelist.com/valleyrat-backdoor-adware/121175/ 14. Metasploit ships modules for Forgejo file read and a batch of other recent flaws — CVE-2026-59774, CVE-2026-3576 — Rapid7 — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners 15. Composer flaw lets a malicious package change permissions on files it does not own — CVE-2026-59944 — Cyber Security News — https://cybersecuritynews.com/composer-flaw-expose-ssh-keys/ 16. UK NCSC warns of rising OT targeting through internet-exposed systems and edge devices — Industrial Cyber — https://industrialcyber.co/control-device-security/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices/ 17. CISA red team walked one network to domain admin and struggled badly in the other — Cybersecurity Dive — https://www.cybersecuritydive.com/news/cisa-red-team-exercises-lessons-cloud-soc/828733/ 18. Microsoft tells everyone to ignore Defender alerts saying antivirus is off — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/
    続きを読む 一部表示
    6 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません