David

Security Stuff

Author

David

Category

Technology

Latest episode

Jul 2, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Hundreds of Internet-Facing VNC Servers Expose ICS/OT 29.04.2026

Cybersecurity firm Forescout has discovered that hundreds of industrial control systems and operational technology environments are dangerously exposed to the internet through unsecured VNC and RDP servers. Their research found 670 VNC servers providing direct access to ICS and OT control panels without any authentication, with nearly 60,000 VNC servers total lacking password protection and over 1...

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV 29.04.2026

CISA has added new ConnectWise and Windows vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming they are being actively exploited in the wild. Federal agencies are now required to patch these flaws within a specified deadline to protect their networks. The additions highlight ongoing risks to both enterprise software and the Windows operating system, as threat actors continue...

Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately 29.04.2026

A critical authentication vulnerability has been identified in cPanel, prompting security experts to urge immediate server updates. The flaw represents a serious security risk that could allow unauthorized access to systems running the popular web hosting control panel. Administrators are being advised to patch their servers without delay to prevent potential exploitation of this authentication by...

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks 29.04.2026

Zscaler is hosting a webinar focused on automating exposure validation to keep pace with AI-powered cyberattacks. The session comes as new research from their ThreatLabz team reveals that AI has significantly compressed response times for defenders while simultaneously making VPNs a vulnerable entry point for rapid breaches. The webinar aims to address how security teams can adapt their validation...

What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong) 29.04.2026

A new report from Zscaler ThreatLabz warns that VPNs have become a major vulnerability, with AI-powered attacks now moving so quickly through remote access points that they've effectively collapsed the window for human response. The research suggests that traditional VPN infrastructure is struggling to keep pace with AI-driven threats, making remote access one of the fastest routes to securit...

Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities 29.04.2026

A sophisticated cyberattack targeting Venezuelan energy firms and utilities in late 2025 deployed a new data-wiping malware called Lotus Wiper that systematically destroyed system recovery mechanisms, overwritten physical drives, and deleted files to leave systems unrecoverable. Security researchers at Kaspersky Lab found the attack used living-off-the-land techniques with two coordinated batch sc...

Alleged Chinese State Hacker Extradited to US 28.04.2026

A Chinese national accused of being part of the Silk Typhoon hacking group has been extradited from Italy to the US to face charges of cyberattacks on American universities and COVID-19 researchers. Xu Zewei allegedly worked for China's Ministry of State Security, targeting virologists and immunologists in 2020 and 2021, and participated in exploiting Microsoft Exchange Server vulnerabilities...

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi 28.04.2026

A new ransomware variant called VECT 2.0 has emerged with an unusually destructive approach, permanently destroying files larger than 131 kilobytes instead of encrypting them for potential recovery. The malware targets multiple operating systems including Windows, Linux, and ESXi, making it a cross-platform threat that eliminates the possibility of ransom payment and file restoration for affected...

Spectrum Security Emerges From Stealth Mode With $19 Million 28.04.2026

Spectrum Security has come out of stealth mode with 19 million dollars in seed funding led by TechOperators. The San Francisco-based startup, founded this year, offers an automated threat detection platform that works with existing security tools to identify and fix coverage gaps in real-time. The company says its solution reduces engineering hours while continuously monitoring environments to ens...

Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials 28.04.2026

Germany suspects Russia is behind a sophisticated phishing campaign on Signal that compromised around 300 accounts belonging to high-ranking officials, military personnel, and journalists. The attackers used a fake Signal security chatbot to trick users into scanning QR codes or entering PINs, which linked their accounts to devices controlled by the hackers, giving them access to past chats, ongoi...

No Patch for New PhantomRPC Privilege Escalation Technique in Windows 28.04.2026

Kaspersky researchers have discovered PhantomRPC, a new Windows privilege escalation technique that exploits architectural weaknesses in the operating system's Remote Procedure Call mechanism to allow attackers to gain System-level access. The vulnerability works by deploying fake RPC servers that impersonate legitimate Windows services, intercepting requests from high-privilege processes and...

Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable 28.04.2026

Sevii has launched Cyber Swarm Defense, a new pricing model for its AI-powered security platform that charges a fixed annual rate per protected asset rather than by AI token usage. This addresses a growing problem for security teams where unpredictable AI costs can spike during multiple simultaneous attacks, potentially exhausting budgets mid-incident and leaving organizations vulnerable. The serv...

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety 28.04.2026

Electric motorcycles and scooters from Zero Motorcycles and Yadea are vulnerable to hacking attacks that could pose serious safety risks to riders. Zero's vulnerability allows attackers within Bluetooth range to connect to bikes and upload malicious firmware that could manipulate critical safety systems like throttle response and braking, while Yadea's scooter flaw lets attackers interce...

Dozens of Open VSX Extension Clones Linked to GlassWorm Malware 28.04.2026

Security researchers have discovered more than 70 suspicious extensions in the Open VSX marketplace linked to the GlassWorm malware campaign, which targets developer credentials and cryptocurrency. These extensions are clones of popular legitimate extensions, published by newly created accounts as "sleepers" that appear harmless initially but can deliver malware through future updates. A...

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks 28.04.2026

A Chinese national linked to the hacker group known as Silk Typhoon has been extradited to the United States to face charges related to cyberattacks targeting COVID-19 research institutions. The extradition marks a significant development in ongoing efforts to prosecute state-sponsored hackers who targeted critical healthcare and research infrastructure during the pandemic. Authorities allege the...

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE 28.04.2026

Security researchers have discovered a critical unpatched vulnerability in Hugging Face's LeRobot framework that could allow attackers to execute remote code without authentication. The flaw poses a significant risk to users of the popular robotics platform, and as of now, no patch has been released to address the security issue. Organizations using LeRobot are advised to take precautionary m...

After Mythos: New Playbooks For a Zero-Window Era 28.04.2026

Zscaler's ThreatLabz has released its 2026 VPN Risk Report highlighting how artificial intelligence has dramatically accelerated cyber attacks, essentially eliminating the time humans have to respond to security threats. The report emphasizes that traditional VPN remote access systems have become one of the fastest pathways for attackers to breach networks, as AI-powered threats now move at s...

Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About 28.04.2026

A new report from Zscaler ThreatLabz highlights that AI-driven attacks have dramatically shortened the time defenders have to respond, making traditional VPN-based remote access a critical vulnerability in zero trust architectures. The research suggests that attackers are now moving at AI-accelerated speeds, while legacy VPNs provide them with one of the fastest pathways to breach corporate networ...

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator 27.04.2026

The Trump administration has launched a major crackdown on Southeast Asian cyberscam operations, announcing sanctions against Cambodian senator Kok An and 28 others, while filing criminal charges against two Chinese nationals operating from Myanmar. The initiative, led by a new government Scam Center Strike Force, aims to combat operations that defrauded Americans of nearly 21 billion dollars in 2...

Firefox Vulnerability Allows Tor User Fingerprinting 27.04.2026

Researchers have discovered a vulnerability in Firefox that allows websites to fingerprint users even in Private Browsing mode and affects the Tor anonymity browser. The flaw, tracked as CVE-2026-6770, involves the IndexedDB browser API where database names are stored using internal UUID mappings that maintain consistent ordering across different sites during the same browser session, enabling unr...

Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access 27.04.2026

A critical Linux vulnerability dubbed "Pack2TheRoot" allows unprivileged users to gain root access by exploiting a flaw in PackageKit, the cross-distribution package management tool. The bug, which has existed for potentially 14 years and affects major distributions including Ubuntu, Debian, Fedora, and RHEL, is easily exploitable within seconds and allows attackers to install arbitrary...

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware 27.04.2026

A threat actor tracked as UNC6692 has been using email bombing combined with Microsoft Teams impersonation to trick victims into installing a sophisticated malware framework called Snow. The attackers overwhelm targets with emails, then pose as IT support offering a fake mailbox repair tool that actually deploys a browser-based backdoor, allowing them to harvest credentials, move laterally through...

Energy and Water Management Firm Itron Hacked 27.04.2026

Itron, a major energy and water management firm serving over 8,000 customers in 100 countries, has disclosed a cyberattack after detecting unauthorized access to some of its systems on April 13th. The company says it has removed the unauthorized activity and seen no further intrusions, with operations continuing normally and no compromise detected in customer-hosted systems. Itron told regulators...

Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google 27.04.2026

Google researchers have discovered a growing number of malicious AI prompt injection attacks on websites, with a 32 percent increase observed between November 2025 and February 2026, though the sophistication remains relatively low. These indirect prompt injection attempts involve planting malicious instructions on websites to trick AI assistants like Gemini and ChatGPT into stealing data or execu...

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years 27.04.2026

A 15-year-old vulnerability in OpenSSH has been discovered that could allow attackers to gain full root shell access to servers by exploiting a simple comma in certificate principal names. The bug, tracked as CVE-2026-35414, works because OpenSSH mistakenly treats the comma as a list separator, turning a low-privilege identity into a root credential, and the attack doesn't trigger authenticat...

Listen to the Security Stuff podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.