『Daily DefSec Brief』のカバーアート

Daily DefSec Brief

Daily DefSec Brief

著者: Jerry Bell
無料で聴く

A daily podcast covering the important cyber security news that IT and security teams need to know.

2026 Jerry Bell
政治・政府
エピソード
  • Cyber Security News for August 19 2026 - Daily DefSec Brief
    2026/08/19
    1. Windows IKE Extension RCE added to CISA KEV, now exploited — CVE-2026-33824 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. macOS Screen Sharing auth bypass added to CISA KEV — CVE-2026-65400 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 3. MLflow SSRF and FUXA auth-bypass under active exploitation — CVE-2026-64849, CVE-2026-25895 — The Hacker News — https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html 4. Cursor IDE zero-day runs code on repo open — Cyber Security News — https://cybersecuritynews.com/cursor-0-day-vulnerability/ 5. CoSnitch: one-click Copilot data exfiltration — CVE-2026-24301, CVE-2026-24299 — The Hacker News — https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html 6. Chrome ships two critical graphics-component fixes — CVE-2026-76034, CVE-2026-76036 — Chrome Releases — http://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html 7. Firefox 154 patches 58 flaws, 20 high-severity — SecurityWeek — https://www.securityweek.com/chrome-firefox-updates-patch-dozens-of-vulnerabilities/ 8. Oracle August CSPU ships 943 patches for 925 CVEs — Tenable — https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves 9. TWINLOOT runs C2 inside Microsoft cloud services — The Hacker News — https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html 10. NASA AIT-GUI flaw lets unauthenticated spacecraft commands — GHSA-p9r8-2q67-fp86 — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/ 11. BeyondTrust EPM for Windows privilege-escalation flaws — CVE-2026-40144, CVE-2026-40145 — Cyber Security News — https://cybersecuritynews.com/beyondtrust-windows-epm-vulnerabilities/ 12. 50,000 Stripe merchant API keys leaked in public code — Security Affairs — https://securityaffairs.com/197504/cyber-crime/50000-stripe-secrets-leaked-in-public-code.html 13. Slovakia finds Russian SMS-triggered backdoor in traffic cameras — Risky Business News — https://news.risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/ 14. Rapid7 report: volume and speed outpace traditional patch cycles — SecurityWeek — https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/ 15. Self-propagating payloads spread between AI agents via shared prompt files — The Hacker News — https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html
    続きを読む 一部表示
    4 分
  • Cyber Security News for August 18 2026 - Daily DefSec Brief
    2026/08/18
    1. Windows Task Host privesc actively exploited by ransomware gangs — CVE-2025-60710 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/ 2. Ray unauthenticated RCE via DNS rebinding, actively exploited — CVE-2025-62593 — The Hacker News — https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html 3. GitLab GraphQL flaw lets unauth attackers delete public projects — CVE-2026-19478, CVE-2026-19650 — SecurityWeek — https://www.securityweek.com/gitlab-patches-critical-code-injection-vulnerability/ 4. Certighost: low-priv AD user coerces Enterprise CA into issuing a cert — CVE-2026-54121 — BleepingComputer — https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/ 5. Unisoc modem chain gives Android kernel access via VoLTE video call — CVE-2022-20210, CVE-2025-31718 — The Hacker News — https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html 6. Claude Code drives nearly every stage of a ransomware intrusion — Cyber Security News — https://cybersecuritynews.com/claude-code-helps-ransomware-operator/ 7. C2Looper: Rust backdoor delivered via ClickFix, GitHub C2 — Zscaler — https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2 8. Cavern C2 uses DNS A-records and Google Apps Script — The Hacker News — https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html 9. Storm-0501 hijacks Azure tenants for cloud-native ransomware — Tenable — https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response 10. Attackers use AI to identify high-value files worth stealing — Help Net Security — https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/ 11. Microsoft removes WMIC LOLBin from Windows 11 24H2/25H2 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/ 12. Operation ASTERIX: crypto-fraud kit built with AI coding assistants — Rapid7 — https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing 13. Windows Server 2022 hits end of mainstream support Oct 13, 2026 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/
    続きを読む 一部表示
    4 分
  • Cyber Security News for August 17 2026 - Daily DefSec Brief
    2026/08/17
    1. macOS Screen Sharing auth-bypass exploited to root Macs and drop Monero miners — CVE-2026-65400 — SecurityWeek — https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks/ 2. Microsoft SCCM flaw chain enables RCE on primary site server — Cyber Security News — https://cybersecuritynews.com/microsoft-sccm-vulnerability/ 3. Roundcube webmail patches RCE and SSRF flaws — Cyber Security News — https://cybersecuritynews.com/roundcube-1-6-18-and-1-7-3-released-with-fix/ 4. Wireshark 4.6.8 fixes 28 vulnerabilities — SANS ISC — https://isc.sans.edu/diary/rss/33248 5. TheHatman selling Azure/Entra data allegedly stolen from Fortune 500 tenants — SecurityWeek — https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/ 6. Fake Web3 job interview delivers NeedleStealer and hVNC RAT via signed ClickOnce — Cyber Security News — https://cybersecuritynews.com/fake-web3-interview/ 7. APT36-linked PATCHCORD backdoor uses fake VPN installers and Google Sheets C2 — Security Affairs — https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html 8. Infostealers harvested 1.7 billion credentials in six months — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/infostealers-17-billion/ 9. Dropcatch domains: attackers buying expired domains for malware and C2 — The Hacker News — https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html 10. Prompt injection hidden in a court filing draws first known sanction — Security Affairs — https://securityaffairs.com/197370/ai/invisible-ai-prompts-trigger-court-sanctions.html 11. Clop claims data theft at Philips and GE; Philips confirms a contained breach — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/ 12. Microsoft delays an Exchange update and won't give a new date — The Register — https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-delayed-exchange-update-cant-say-when-it-will-arrive/5288227
    続きを読む 一部表示
    4 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません