Marc Frédéric GOMEZ
RadioCSIRT - English Edition
🎙 Marc Frédéric Gomez, cybersecurity expert, brings you daily insights into the latest threats, attacks, and defense strategies you need to know. 🔎 On the agenda: ✔️ Analysis of cyberattacks and critical vulnerabilities ✔️ Strategic intelligence for CSIRTs, CERTs, and cybersecurity professionals ✔️ Sources and references to dive deeper into each topic 💡 Why listen to RadioCSIRT? 🚀 Stay up to date in just a few minutes a day 🛡️ Anticipate threats with reliable, technical information 📢 An essential intelligence source for IT and security professionals 🔗 Listen, share, and secure your enviro...
Author
Marc Frédéric GOMEZ
Category
Podcast website
Latest episode
Apr 12, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
RadioCSIRT English Edition – Your cybersecurity News for Wednesday, December 17, 2025 (Ep.53) 17.12.2025 5:48
Welcome to your daily cybersecurity podcast. CISA adds CVE-2025-59718 to its Known Exploited Vulnerabilities catalog on December 16th. The flaw affects Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb through improper cryptographic signature verification in FortiCloud SSO SAML authentication. Unauthenticated attackers can bypass authentication via crafted SAML messages. Active exploit...
RadioCSIRT English Edition – Your cybersecurity News for Tuesday, December 16, 2025 (Ep.52) 16.12.2025 12:13
Welcome to your daily cybersecurity podcast. QNAP discloses a high-severity authentication bypass vulnerability tracked as CVE-2025-59385 . The flaw allows remote attackers to spoof authentication mechanisms and access protected resources without credentials. The issue affects QTS and QuTS hero systems and is remotely exploitable with no user interaction. Patches are available in QTS 5.2.7.3297 an...
RadioCSIRT English Edition – Your cybersecurity News for Monday, December 15, 2025 (Ep.51) 15.12.2025 12:52
Welcome to your daily cybersecurity podcast. Horizon3.ai exposes three critical FreePBX vulnerabilities. The most severe, CVE-2025-66039 scored 9.3, enables complete authentication bypass via simple forged Authorization header. Two additional flaws provide SQL injection and PHP web shell upload for remote code execution. Patches available but require manual CLI configuration and audit of instances...
RadioCSIRT – Your Cyber Security News for Sunday, December 14, 2025 (Ep.50) 14.12.2025 8:08
Welcome to your daily cybersecurity podcast. Apple and Google rush to fix actively exploited Zero-Day flaws. CISA has added CVE-2025-14174 to its KEV catalog, flagging a critical memory corruption vulnerability in the Chromium engine that affects Chrome, Edge, and Brave. Simultaneously, Apple has deployed patches for this same flaw alongside CVE-2025-43529, a WebKit Use-After-Free bug. Discovered...
RadioCSIRT English Edition – Saturday, December 13, 2025 (Ep.49) 13.12.2025 8:54
Welcome to your daily cybersecurity podcast. Palo Alto Networks Unit 42 exposes Ashen Lepus, a Hamas-affiliated APT actor active since 2018 . The group deploys a new .NET modular malware suite named AshTag, targeting governmental and diplomatic entities across the Middle East with confirmed geographic expansion toward Oman and Morocco. The multi-stage infection chain initiates through Arabic-langu...
RadioCSIRT English Edition – Top 25 CWE 2025 Deep Dive – Friday, 12 December 2025 (Special Episode) 12.12.2025 9:00
Welcome to this special RadioCSIRT cybersecurity briefing. In this episode, we take an in-depth look at the MITRE Top 25 Common Weakness Enumerations (CWE) for 2025 , moving beyond a simple ranking to analyze the structural weaknesses that continue to drive real-world compromises. This analysis focuses on how recurring flaws such as cross-site scripting, sql injection, missing authorization, memor...
RadioCSIRT English Edition – Your Cybersecurity Update for Thursday, December 11th, 2025 (Ep.47) 11.12.2025 4:57
Welcome to your daily cybersecurity podcast. The Linux kernel 5.4 officially reaches end-of-life . After years of LTS support, this version—massively deployed across Ubuntu, Android, and embedded systems—will no longer receive upstream security patches. This creates a critical risk for industrial and network equipment remaining on this version without a rapid migration path. Check Point dissects t...
RadioCSIRT – Your Cybersecurity News for Wednesday, December 10th, 2025 (Ep.46) 10.12.2025 8:33
Welcome to your daily cybersecurity podcast. Microsoft refuses to fix a critical RCE vulnerability in the .NET framework affecting the SoapHttpClientProtocol class. Revealed at Black Hat Europe by researcher Piotr Bazydło from WatchTowr, the flaw enables arbitrary file writes through SOAP URL manipulation. Exploitation relies on unexpected support for FILE and FTP protocols by a class designed to...
RadioCSIRT - Pro-Russia Hacktivists Targeting Global Critical Infrastructure 10.12.2025 3:22
🚨 CRITICAL ALERT: CISA, FBI, and NSA issue joint advisory AA25-343A on December 9, 2025, warning of active campaigns by four pro-Russia hacktivist groups exploiting VNC vulnerabilities in OT/ICS systems worldwide. THREAT ACTORS IDENTIFIED: Cyber Army of Russia Reborn (CARR) - GRU Unit 74455 linked NoName057(16) - Kremlin CISM creation Z-Pentest - CARR/NoName merger, OT-specialized Sector16 - Eme...
RadioCSIRT - Your Cybersecurity Update for Tuesday, 9 December 2025 (Ep.45) 09.12.2025 10:49
Welcome to your daily cybersecurity briefing. The UK’s NCSC has released critical guidance regarding Generative AI security, warning that treating Prompt Injection like SQL Injection is a dangerous misconception. Unlike traditional databases, LLMs lack a rigid boundary between instructions and data, creating an "Inherently Confusable Deputy" problem. The agency advises that the only effective miti...
RadioCSIRT English Edition – Your Cybersecurity Update for Monday, 8 December 2025 (Ep.44) 08.12.2025 6:56
Welcome to your daily cybersecurity briefing. CERT-FR has issued a security advisory regarding a vulnerability affecting the MISP threat-intelligence platform. Under specific configurations, the flaw may allow unauthorized access to internal components or data. Organizations relying on MISP are strongly encouraged to apply the recommended patches without delay to mitigate potential exploitation. C...
RadioCSIRT English Edition – Your Cybersecurity Update for Sunday, 7 December 2025 (Ep.43) 07.12.2025 9:02
Welcome to your daily cybersecurity briefing. The FBI has issued a public service announcement regarding the evolution of "virtual kidnapping" scams, where criminals are now using AI-altered images from social media to fabricate proof-of-life. By manipulating photos to depict physical harm or captivity, threat actors are successfully pressuring families into paying ransoms for loved ones who are a...
RadioCSIRT English Edition – Your Cybersecurity Update for Saturday, 6 December 2025 (Ep.42) 06.12.2025 12:40
Welcome to your daily cybersecurity briefing. The Australian Cyber Security Centre has released new guidance for critical infrastructure regarding the secure integration of Artificial Intelligence into Operational Technology environments. This strategic framework aims to help organizations anticipate physical safety risks caused by algorithmic automation in industrial systems. CERT-FR (ANSSI) has...
RadioCSIRT - Your Cybersecurity Update for Friday, 5 December 2025 (Ep.41) 05.12.2025 10:53
Welcome to your daily cybersecurity briefing. Cloudflare has attributed today's major service outage to the deployment of an emergency patch intended to mitigate the critical "React2Shell" vulnerability. The incident highlights the delicate balance between security responsiveness and operational stability: the attempt to rapidly mitigate an active flaw resulted in a global software regression, ser...
RadioCSIRT English Edition – Your Cybersecurity Update for Thursday, 4 December 2025 (Ep.40) 04.12.2025 6:54
Welcome to your daily cybersecurity briefing. Russia has blocked access to Apple’s FaceTime platform and Snap’s Snapchat service, citing their alleged use in coordinating terrorist operations, recruiting criminal actors, and facilitating large-scale fraud against Russian citizens. The decision follows a pattern of escalating restrictions targeting foreign communication platforms, including recent...
RadioCSIRT English Edition – Your Cybersecurity Update for Wednesday, 3 December 2025 (Ep.39) 03.12.2025 8:07
Welcome to your daily cybersecurity briefing. DeepSeek Releases V3.2 Open Source Model Rivaling GPT-5 The Chinese AI startup DeepSeek has officially released its V3.2 and V3.2-Speciale models under a fully permissive MIT license. Claiming to outperform GPT-5 in reasoning tasks, the release utilizes a novel "Sparse Attention" architecture to maximize efficiency, marking a significant shift in the o...
RadioCSIRT English Edition – Your Cybersecurity Update for Tuesday, 2 December 2025 (Ep.38) 02.12.2025 4:33
Welcome to your daily cybersecurity briefing. Raspberry Pi Raises Prices Amid Rising Production Costs Raspberry Pi has announced a price increase across several models, citing sustained rises in manufacturing and component costs. The company explains that it can no longer absorb global supply chain pressures. The adjustment will particularly impact integrators, IoT builders, and embedded system de...
RadioCSIRT English Edition – Your Cybersecurity Update for Monday, 1 December 2025 (Ep.37) 01.12.2025 4:50
Welcome to your daily cybersecurity briefing. Mattermost Patches Silent Security Flaw CERT-FR reports an "unspecified security issue" in Mattermost Server (MMSA-2025-00545). While technical details remain undisclosed by the vendor, the vulnerability impacts multiple branches including 10.11, 10.12, 11.0, and 11.1. Given the platform's role in centralizing sensitive internal communications, adminis...
RadioCSIRT English Edition – Your Cybersecurity Update for Sunday, 30 November 2025 (Ep.36) 30.11.2025 10:24
Welcome to your daily cybersecurity briefing. Cato CTRL Discloses "HashJack" Prompt Injection Cato Networks has revealed a new indirect prompt injection technique called "HashJack" that hides malicious payloads within URL fragments. This method blindsides perimeter WAFs but is fully processed by client-side AI browsers like Copilot and Gemini, enabling zero-click data exfiltration and callback phi...
RadioCSIRT – Your Cybersecurity Update for Saturday, 29 November 2025 (Ep.35) 29.11.2025 8:04
Welcome to your daily cybersecurity briefing. CVSS v4.0 – Understanding the New Vulnerability Scoring Model A new analysis from Malwarebytes provides a clear breakdown of CVSS v4.0, detailing how the updated framework shifts focus toward exploitability, environmental modifiers, and attacker utility. The article highlights changes in severity interpretation, granularity in attack requirements, and...
RadioCSIRT – Your Cybersecurity Update for Friday, 28 November 2025 (Ep.34) 28.11.2025 12:44
Welcome to your daily cybersecurity briefing. CISA & Commercial Spyware Targeting Messaging Apps Following a joint alert by CISA, a technical breakdown reveals how multiple threat actors use QR-based session hijacking, zero-click exploits, and fake apps to compromise end-to-end encrypted messaging platforms such as Signal and WhatsApp. Victims include senior officials and civil society actors...
RadioCSIRT – Your Cybersecurity Update for Thursday, 27 November 2025 (Ep.33) 27.11.2025 7:21
Welcome to your daily cybersecurity briefing. CERT-FR: Advisory 2025-AVI-1042 CERT-FR has issued a new advisory describing several critical vulnerabilities impacting Gitlab. RomCom via SocGholish Arctic Wolf reports a campaign in which the RomCom threat group leveraged the SocGholish delivery infrastructure for the first time to deploy a targeted Mythic loader. The intrusion targeted a U.S. compan...
RadioCSIRT – Your Cybersecurity Update for Wednesday, 26 November 2025 (Ep.32) 26.11.2025 16:06
Welcome to your daily cybersecurity briefing. 💻 JackFix: Fake Windows Update Malwar e – A new campaign is distributing the JackFix malware through fake Windows Update pop-ups, enabling payload execution and stealthy installation of persistent backdoors. 🇫🇷 CERT-FR: PrimX Targeted – CERT-FR has issued an advisory detailing a compromise affecting PrimX, involving a vulnerability that allows securit...
RadioCSIRT – Your Cybersecurity Update for Tuesday, 25 November 2025 (Ep.31) 25.11.2025 7:42
Welcome to your daily cybersecurity briefing. 💸 FBI: Bank Impersonation Alert – The FBI reports that cybercriminals have stolen $262 million since January by impersonating bank support teams through sophisticated vishing and smishing campaigns. 📉 Microsoft: Exchange Online Outage – A major service disruption in North America is blocking access to Outlook mailboxes, caused by a configuration chan...
RadioCSIRT – Your Cybersecurity Update for Monday, 24 November 2025 (Ep.30) 24.11.2025 6:30
Welcome to your daily cybersecurity briefing. 🛡️ CERT-UA Alert: official update released – CERT-UA publishes an expanded update detailing malicious activity targeting educational and public-sector infrastructures, including new technical insights and reinforced hardening recommendations. 🧪 CERT-FR: new security advisory – CERT-FR issues a refreshed advisory regarding ongoing vulnerability analysi...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.