Tushar Vartak

CyberPulse

Arts EN ↓ 74 episodes

Your daily dose of cybersecurity intelligence — from AI-powered attacks and quantum preparedness to cloud breaches and emerging digital risks. Narrated by a digital voice.

Author

Tushar Vartak

Category

Arts

Podcast website

techentangle.github.io

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

The Door That Pretended to Be Guarded 01.06.2026

Classification: Operational Threat Intelligence Summary: Today’s edition focuses on active exploitation at the remote access edge, web platform administrator account creation, local privilege escalation, agent-assisted post-exploitation, trusted-interface phishing, and botnet infrastructure disruption.

When Cloud Break-Ins Move at AI Speed 01.06.2026

When Cloud Break-Ins Move at AI Speed

When Your AI Agent Becomes the Attack Surface 01.06.2026

When Your AI Agent Becomes the Attack Surface

When the Lights Go Out 01.06.2026

Ballistic missiles struck targets across multiple Gulf states this weekend in retaliatory strikes following a coordinated military operation that included the largest cyber operation in recorded history. Gulf-wide airspace closures grounded major airlines, the US Navy declared a maritime warning zone across the Strait of Hormuz, and GPS jamming is disrupting nearly a thousand vessels per day. Behi...

Your AI Read Your Secrets 01.06.2026

Your AI Read Your Secrets

Your AI Takes Instructions From Strangers 01.06.2026

Your AI Takes Instructions From Strangers

Your Face Is Not Your Own 01.06.2026

Your Face Is Not Your Own

Your Vendor Is Your Perimeter 01.06.2026

A board-level strategic briefing synthesizing the defining lesson of April 2026: the most consequential attacks did not breach organizational perimeters — they arrived through trusted vendors. A vulnerability scanner was compromised twice, reaching a major password manager's distribution. A WordPress plugin's official update delivered a backdoor to 800K installations. A JavaScript library poisoned...

The Ghost With Admin Access 01.06.2026

The Ghost With Admin Access

The Lights Went Dark at the Utility 01.06.2026

A global utility infrastructure vendor disclosed unauthorized access to its corporate IT systems via SEC 8-K filing, creating potential supply chain exposure for electricity, gas, and water utilities running its smart metering and grid management products. A new threat group (UNC6692) is deploying the three-component Snow malware suite — Snowbelt browser extension, Snowglaze tunneler, and Snowbasi...

The Machine Underground 01.06.2026

The Machine Underground

The Machines Are Choosing Sides 01.06.2026

A board-level strategic briefing synthesizing the week that confirmed the AI cyber arms race is live. Two frontier AI companies shipped cyber-specialized models within nine days of each other. A twelve-company coalition committed $100M. Mandiant M-Trends reports 22-second adversary handoff times while CrowdStrike tracks 29-minute eCrime breakout — both shrinking. A CVSS 9.8 authentication bypass i...

The Malware That Thinks 01.06.2026

The Malware That Thinks

The Only Weapon Left 01.06.2026

With conventional military options destroyed in this weekend's coordinated strikes, threat intelligence firms assess that cyber operations are now the sole remaining instrument of asymmetric retaliation — and state-linked cyber units were activated before the kinetic trigger was pulled. This briefing reveals that the wiper malware scenario already happened: a Shamoon 4.0 variant struck Gulf energy...

The Password Change That Didnt Need a Password 01.06.2026

Cisco patched CVE-2026-20093 (CVSS 9.8) in the Integrated Management Controller — an authentication bypass that allows an unauthenticated attacker to change any user's password, including the administrator, and gain full system control via a single crafted HTTP request. This continues the management plane attack pattern tracked since March across Intune, Cisco FMC, SD-WAN, and FortiClient EMS. A m...

The Script Kiddie Who Brought an AI 01.06.2026

A low-skill, Russian-speaking hacker used commercial AI services to breach over 600 enterprise firewalls across 55 countries in five weeks. No zero-days required. Amazon just showed us what the automation of mediocrity looks like at scale.

The Second Exploit Kit 01.06.2026

DarkSword, a second nation-state-grade iOS exploit kit, has been disclosed — this one targeting current iOS versions (18.4–18.7) with six vulnerabilities including four zero-days, deployed by three separate operators since November 2025. Unlike Coruna which targeted legacy iOS, DarkSword compromises fully patched modern devices. A critical SharePoint deserialization flaw (CVE-2026-20963) patched i...

The Update Was the Backdoor 01.06.2026

Attackers hijacked the update infrastructure for Smart Slider 3 Pro (800K+ WordPress installations) and pushed a fully weaponized remote access toolkit through the official update channel for approximately six hours. Adobe released an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution flaw in Acrobat Reader under active exploitation via malicious PDFs. The GlassWorm campaign evol...

The Weapons Are Loose 01.06.2026

Google Threat Intelligence Group and iVerify published simultaneous research on Coruna, a nation-state-grade iOS exploit kit containing 23 exploits across five full attack chains targeting iOS 13 through 17.2.1. The kit proliferated from a commercial surveillance vendor to state-linked espionage operations to mass criminal deployment in under twelve months — marking the first observed mass exploit...

The Week the Layers Peeled Back 01.06.2026

This week revealed pre-positioned access across every infrastructure layer simultaneously. Google and iVerify exposed Coruna, a nation-state iOS exploit kit with 23 exploits that proliferated from surveillance to espionage to mass criminal deployment in twelve months. Cisco disclosed a CVSS 10.0 SD-WAN zero-day exploited since 2023 with a three-year dwell time. Akamai traced APT28's exploitation o...

The Wiper Landed 01.06.2026

A state intelligence-linked hacktivist group deployed wiper malware against a $25 billion medical technology and defense industrial base supplier, causing a global network disruption that sent over 5,000 workers home, triggered an SEC filing, and temporarily disrupted emergency medical communications in at least one state. The group claims to have erased data from 200,000+ devices and exfiltrated...

They Came Back for More 01.06.2026

Cisco confirmed active exploitation of two additional SD-WAN Manager vulnerabilities (CVE-2026-20122 and CVE-2026-20128) — bringing the total to four exploited Cisco SD-WAN flaws in eight days. The company also patched two maximum-severity (CVSS 10.0) Secure Firewall Management Center flaws enabling unauthenticated remote code execution as root. Hikvision and Rockwell Automation legacy vulnerabili...

They Hit the Same Door Twice 01.06.2026

Fortinet released an emergency out-of-band patch for CVE-2026-35616 (CVSS 9.1), a pre-authentication API access bypass in FortiClient EMS exploited as a zero-day — the second critical FortiClient EMS vulnerability in weeks after CVE-2026-21643. The bloc's cybersecurity service attributed a major continental government cloud breach to TeamPCP, exposing data from 29 additional institutional entities...

They Poisoned the Bot That Guards the Code 01.06.2026

CyberPulse — February 24, 2026: "They Poisoned the Bot That Guards the Code" A supply chain attack on the Cline AI coding assistant used prompt injection against an AI triage bot to steal npm publishing credentials and silently install the OpenClaw autonomous agent on ~4,000 developer machines in an 8-hour window. The first real-world case of prompt injection weaponized into a software supply chai...

They Were Already Inside 01.06.2026

Broadcom's Symantec and Carbon Black confirmed that a state intelligence-linked threat group compromised a bank, an airport, nonprofits, and a defense aerospace software supplier starting in early February 2026 — weeks before the kinetic strikes began on February 28. The group deployed the previously unknown Dindoor backdoor using the Deno JavaScript runtime and attempted data exfiltration via Rcl...

Listen to the CyberPulse podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.