エピソード

  • 146 - Invisible Threats: The Risks of Automatic Code Execution
    2026/07/13

    Send us Fan Mail

    We track the thread running through the biggest security stories of the week: automatic execution paths that get trusted too far and monitored too little. We break down what went wrong across legacy servers, the software supply chain, edge devices, and AI platforms, then land on one practical way to reduce risk fast.
    • ColdFusion path traversal leading to unauthenticated remote code execution under risky RDS settings
    • Legacy exposure driven by forgotten toggles, missing ownership, and incomplete asset inventory
    • JS Crambler NPM compromise using real publisher credentials and a cross-platform info stealer
    • Attacker pivot from preinstall hooks to imported code that executes at runtime
    • ORB relay networks built from compromised routers to hide espionage origins
    • AI tooling risks where “small” permissions reach across tenants and managed runtimes
    • NPM v12 turning install scripts off by default and winding down weak publisher tokens
    • Typosquat payment SDKs and fake aged GitHub repos undermining trust heuristics
    All of that is in this week's written issue at InfoSec.watch.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    11 分
  • 138 - Security Leverage Points
    2026/05/18

    Send us Fan Mail

    We track the security stories that give attackers the most leverage, from AI-assisted exploit development to SaaS platform compromise, manufacturing ransomware, and high-impact vulnerabilities. We end with a practical defensive check: a short control plane exposure register that shows exactly which systems could change trust, access, routing, revenue, or production at scale.
    • AI-assisted zero-day exploit and why admin tools move to the top of the patch queue
    • Phishing-resistant MFA and reviewing trusted path assumptions for bypass risk
    • Canvas incident and the need for tenant-level SaaS impact assessment
    • Manufacturing ransomware as business disruption strategy across logistics and production
    • Cisco Catalyst SD-WAN controller authentication bypass and control plane blast radius
    • Exchange OWA KEV-driven mitigations and using deadlines for escalation
    • WordPress FunnelKit exploit leading to WooCommerce checkout skimming and script audits
    • Leverage-point thinking for modern asset inventory and exposure management
    • Control plane exposure register fields, owners, logs, rollback paths, review cadence
    If you want daily updates between episodes, you can find us on X, Facebook, and LinkedIn. Just search InfoSecWatch. And if you haven't already, head over to InfoSec.watch and grab the free weekly newsletter. It's concise, it's practitioner focused, and it lands every week.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    11 分
  • 147 - The Evidence Gap
    2026/07/21

    Send us Fan Mail

    We track a single failure pattern across patching, supply chain security, SOC triage, and ransomware recovery: confusing a status label with proof. Using SonicWall SMA 1000 exploitation, an async API NPM compromise with valid provenance, and Fairlife’s production disruption, we lay out what “closure evidence” actually looks like when consequences are real.
    • the evidence gap between having a control and trusting its result
    • SonicWall SMA 1000 vulnerabilities, exploited-in-the-wild context, and why patching is not a compromise verdict
    • what to preserve and review after updating an internet-facing remote access appliance
    • async API supply chain compromise mechanics using GitHub Actions to publish to NPM
    • why OIDC provenance and build attestations prove lineage, not intent
    • scoping guidance that separates lock file exposure from module execution evidence
    • Fairlife ransomware disruption as a reminder that restored systems are not the same as restored production
    • DHS HSIN false positive dismissals and why closure confidence must match asset consequence
    • risk-based vulnerability management notes for Siemens RuggedCom ROCS 2, Microsoft ADFS, and Cisco Room OS
    • a practical model for designing deliberate closure evidence across vuln management, CI pipelines, SOC cases, and resilience testing

    One thing to do this week is run a bounded false positive quality review.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    13 分
  • 130 - When Trusted Tools Turn On You
    2026/03/26

    Send us Fan Mail

    We track how trust boundaries fail across the modern stack, from CI/CD supply chain compromise to phishing-driven account takeover and remote assistance abuse. We also break down actively exploited vulnerabilities and a practical tier 0 validation loop that treats patching like incident response, not routine maintenance.
    • supply chain compromise risk when trusted CI/CD tooling is abused for credential theft
    • behavior-based hunting on build systems, including anomalous execution and network egress
    • phishing campaigns against Signal and WhatsApp framed as identity compromise at scale
    • Microsoft Teams social engineering path to Quick Assist remote access and intrusion expansion
    • vulnerability triage for active exploitation, including Cisco FMC CVE-2026-20131 and rapid weaponization of new disclosures
    • mobile exploit kit reporting and why device takeover belongs in tier 0 thinking
    • IoT botnet disruption as a prompt to inventory unmanaged devices and validate network visibility
    • one-week tier 0 validation loop: verify versions, remove exposure, review logs, rotate secrets
    Follow the show on X, Facebook, and LinkedIn, and subscribe at https://infosec.watch.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    18 分
  • 129 - Quick Assist, Slow Panic
    2026/03/20

    Send us Fan Mail

    We track how attackers keep turning trusted channels into reliable intrusion paths, from extension marketplaces to chat platforms and developer dependencies. We also lay out what defenders should patch first and how to validate fixes so security work actually reduces risk.
    • Glasswarm escalation against Open VSX using a modular loader for stealthier propagation
    • Why defenders need full intrusion chain telemetry across execution, persistence and C2
    • Microsoft Teams phishing that impersonates IT and abuses Quick Assist for remote access
    • Living off the land detection focused on behaviors rather than specific malware files
    • Astronata backdooring React Native packages to steal crypto wallets and developer credentials
    • Software supply chain hygiene through provenance checks and dependency trust path reviews
    • Chrome vulnerabilities exploited in the wild and why pre-patch hunting matters
    • Veeam critical flaws and treating backup infrastructure as a tier zero asset
    • VPN credential theft campaigns and enforcing MFA across every authentication path
    • Post-patching rigor with version checks, exposure validation, log review and secret rotation


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    9 分
  • 128 - AI Malware Floods And Patch Tsunamis
    2026/03/12

    Send us Fan Mail

    We track a clear theme across this week’s security headlines: everything is getting bigger, faster, and harder to manage, from AI-generated malware to massive patch waves. We focus on cutting blast radius with risk-based patching, resilience-first strategy, and automation that can keep up with machine-scale attacks.

    • AI-assisted malware as a volume play that strains signature-based detection
    • CISA KEV additions affecting physical security tech and industrial OT environments
    • Cisco firewall patch surge and why perfect-10 bugs demand rapid edge triage
    • Risk-based prioritization starting with the most exposed internet-facing devices
    • VMware ARIA Operations auth bypass as a high-impact management-plane risk
    • Nginx UI remote code execution as a supply chain style weak link
    • Resilience mindset built on detection, response, and rehearsed incident response plans
    • Automated sandboxing and modern EDR to counter high-volume malware
    • Continuous security awareness training that teaches and builds security culture

    Don't forget to follow us on X, Facebook, or LinkedIn, and be sure to subscribe to our newsletter at infosec.watch for the latest updates.


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    9 分
  • 127 - From Cisco To EV Chargers: Active Exploits And Urgent Patches
    2026/03/06

    Send us Fan Mail

    A wave of edge and control‑plane threats drives urgent patching and smarter validation across Cisco SD‑WAN, EV charging, FileZen, and Serve‑U. We map real exploits, spotlight APT28 tradecraft, unpack Google risk shifts, and share a post‑patch playbook that assumes breach.

    • Cisco SD‑WAN 10.0 authentication bypass and active exploitation
    • CISA KEV update for FileZen and patch prioritization
    • EV charging platform flaws enabling session hijack and station impersonation
    • APT28 targeting MSHTML and legacy components as modern vectors
    • One Uptime 10.0 root‑level exploit via traceroute probes
    • Google localhost WebSocket risk and policy reversals on token proxying
    • Governance for agentic AI with supervised fine‑tuning and oversight
    • Quick hits on North Korean air‑gap tools and UNC2814 disruption
    • Serve‑U critical updates and file transfer exposure
    • EU CRA impacts on open source supply chains
    • Post‑patch validation: verify versions, confirm exposure is gone, hunt logs, rotate secrets
    • Continuous exposure management for control planes and edge systems

    For more in-depth analysis and links to everything we discussed today, be sure to subscribe to our newsletter at infosec.watch

    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    10 分
  • 126: Click The CAPTCHA, Adopt Malware, Regret Everything
    2026/02/23

    Send us Fan Mail

    We track a wave of high-impact vulnerabilities and social engineering campaigns that target management planes and edge devices, then lay out a concrete four-step validation playbook. The theme is simple: initial access is cheap, but control plane compromise multiplies damage.

    • Windows Admin Center privilege escalation and urgent patching
    • IceWarp critical flaws enabling total takeover paths
    • Fake CAPTCHA campaigns delivering Letrodyctus, Supers, and new RATs
    • BeyondTrust RCE exploited in the wild with VShell and SparkRat
    • Grandstream VoIP unauthenticated buffer overflow and asset hygiene
    • Dell RecoverPoint zero day linked to suspected state activity
    • CISA KEV additions signaling active exploitation and patch deadlines
    • Fake adversary-built RMM tools and software due diligence
    • Device code phishing abusing OAuth to bypass MFA
    • Four-step patch validation and assumed-breach log review
    • Final theme: protect control planes and edge surfaces

    Be sure to follow us on X, Facebook, or LinkedIn for daily updates
    And don't forget to subscribe to our newsletter for all this and more right in your inbox
    You can find that at infosec.watch


    Support the show

    Thanks for listening to InfoSec.Watch! Subscribe to our newsletter for in-depth analysis: https://infosec.watch Follow us for daily updates: - X (Twitter) - LinkedIn - Facebook - Stay secure out there!


    続きを読む 一部表示
    14 分