David
Security Stuff
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Incomplete Windows Patch Opens Door to Zero-Click Attacks 27.04.2026 0:47
Security researchers at Akamai have discovered that Microsoft's February patch for a Windows SmartScreen vulnerability was incomplete, creating a new zero-click flaw that allows attackers to steal credentials without any user interaction. The original vulnerability, CVE-2026-21510, was exploited by Russia's APT28 hacking group in attacks targeting Ukraine and EU countries, using weaponiz...
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware 27.04.2026 0:33
Cybersecurity researchers have discovered 73 malicious Visual Studio Code extensions on the official marketplace that were delivering GlassWorm v2 malware to unsuspecting developers. The fake extensions posed as legitimate tools to trick users into downloading them, highlighting ongoing security concerns with third-party software repositories. This discovery underscores the growing threat of suppl...
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side 27.04.2026 0:30
A new report from Zscaler ThreatLabz reveals that artificial intelligence has dramatically accelerated vulnerability discovery, collapsing the window for human response and making VPNs a particularly fast pathway for attackers. The report warns that while AI tools like Mythos have fundamentally changed the speed of threat detection, most security teams haven't adapted their remediation proces...
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks 27.04.2026 0:32
PhantomCore, a threat actor group, has been actively exploiting security vulnerabilities in TrueConf, a video conferencing platform, to infiltrate Russian networks. The attacks leverage flaws in the software to gain unauthorized access and establish a foothold within targeted systems. Security researchers have identified this campaign as a significant threat to organizations using the compromised...
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More 27.04.2026 0:41
Security researchers have uncovered Fast16 malware targeting systems through VPN vulnerabilities, as detailed in Zscaler's 2026 VPN Risk Report. The report highlights how AI-powered attacks have dramatically shortened the time between initial access and full breach, with remote access tools now representing one of the fastest attack vectors. Meanwhile, Georgetown University is promoting its o...
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack 27.04.2026 0:34
Checkmarx has confirmed that data from its GitHub repository was posted on the dark web following a cyberattack on March 23rd. The application security company is investigating the breach, which appears to have exposed source code and potentially sensitive information stored in the repository. This incident highlights ongoing concerns about the security of software development platforms and supply...
Parsing Agentic Offensive Security's Existential Threat 27.04.2026 0:34
While some experts worry that advanced AI models could pose an existential threat to cybersecurity, Ari Herbert-Voss suggests this concern may actually present an opportunity. The debate centers on whether frontier language models will fundamentally undermine digital security or whether they can be harnessed to strengthen defensive capabilities. This reflects the broader tension in the tech commun...
20-Year-Old Malware Rewrites History of Cyber Sabotage 27.04.2026 0:32
Cybersecurity researchers have discovered a malware framework called "fast16" that dates back to 2005, making it five years older than Stuxnet, the notorious cyberweapon previously thought to be among the earliest sophisticated state-sponsored malware. This finding is rewriting the timeline of advanced cyber sabotage operations and suggesting that nation-state actors were developing comp...
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation 27.04.2026 0:35
Security researchers have uncovered a serious architectural weakness in Windows' Remote Procedure Call mechanism dubbed PhantomRPC, which enables attackers to escalate their privileges on affected systems. The vulnerability stems from how Windows handles connections to unavailable RPC services, with researchers identifying five distinct exploit paths that take advantage of this flaw. The secu...
Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments 16.04.2026 0:53
Security researcher Aonan Guan has uncovered a prompt injection attack called Comment and Control that can hijack popular AI coding tools including Claude Code Security Review, Google's Gemini CLI, and GitHub Copilot Agent. The vulnerability allows attackers to use specially crafted GitHub comments or pull request titles to trick AI agents into executing malicious commands and exfiltrating cr...
Ransomware Hits Automotive Data Expert Autovista 16.04.2026 0:36
Autovista, a UK-based automotive data and analysis company, is working to restore services across Europe and Australia after being hit by a ransomware attack. The company, which provides vehicle valuations, specifications, and insights for dealers and professionals worldwide, has brought in third-party cybersecurity experts to investigate the incident but cannot provide a timeline for full restora...
Cisco Patches Critical Vulnerabilities in Webex, ISE 16.04.2026 0:37
Cisco has released patches for 15 security vulnerabilities, including critical flaws in its Webex and Identity Services Engine platforms. The most severe issue is in Webex single sign-on integration, which could allow unauthenticated attackers to impersonate any user due to improper certificate validation. Three critical vulnerabilities in Identity Services Engine could let authenticated attackers...
NIST Prioritizes NVD Enrichment for CVEs in CISA KEV, Critical Software 16.04.2026 0:48
NIST is overhauling how it handles the National Vulnerability Database due to a massive surge in CVE submissions, which jumped 263% between 2020 and 2025. Under the new risk-based approach, NIST will prioritize enriching CVEs that are in CISA's Known Exploited Vulnerabilities catalog, affect federal agency software, or impact critical infrastructure, while other vulnerabilities will be marked...
Microsoft Paid Out $2.3 Million at Zero Day Quest 2026 Hacking Contest 16.04.2026 0:43
Microsoft paid out 2.3 million dollars to white-hat hackers at its Zero Day Quest 2026 hacking competition, where researchers from over 20 countries submitted 700 security findings. The contest uncovered 80 high-impact vulnerabilities in Microsoft's cloud and AI services, particularly in areas like identity controls and tenant isolation that could allow unauthorized cross-tenant access. This...
Artemis Emerges From Stealth With $70 Million in Funding 16.04.2026 0:47
New York-based cybersecurity startup Artemis has emerged from stealth mode with 70 million dollars in combined seed and Series A funding to tackle AI-powered threats. The company's platform uses artificial intelligence to detect and contain security threats across applications, users, machines, and cloud workloads by combining behavioral log data with business context to identify abnormal beh...
Splunk Enterprise Update Patches Code Execution Vulnerability 16.04.2026 0:38
Splunk has released patches for multiple security vulnerabilities across its product line, including a high-severity flaw in Splunk Enterprise and Cloud Platform that could allow low-privileged users to upload malicious files and execute remote code. The company also fixed a separate high-severity issue in its MCP Server app that could expose users' session tokens and authorization data to au...
Data Breach at Tennessee Hospital Affects 337,000 16.04.2026 0:38
Cookeville Regional Medical Center in Tennessee disclosed a ransomware attack discovered in July of last year that has affected over 337,000 patients. The Rhysida ransomware group stole approximately 500 gigabytes of sensitive data including social security numbers, financial information, and medical records, attempting to sell it for 10 bitcoin before ultimately releasing it for free online when...
Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu 16.04.2026 0:32
A security researcher discovered that Taboola, a popular content recommendation platform used by many websites, was potentially routing logged-in banking session data through its network before redirecting users to shopping site Temu. The vulnerability raised serious concerns about user privacy and financial data security, as sensitive banking sessions could be exposed to third-party tracking netw...
Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks 16.04.2026 0:39
A new malware campaign is targeting financial and cryptocurrency sectors by weaponizing a plugin for Obsidian, the popular note-taking application. Attackers are deploying PHANTOMPULSE RAT, a remote access trojan, through malicious Obsidian plugins to gain unauthorized access to victims' systems. The campaign represents an emerging trend where threat actors exploit legitimate productivity too...
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution 16.04.2026 0:32
Cisco has issued patches for four critical security vulnerabilities affecting its Identity Services Engine and Webex platforms that could allow attackers to execute malicious code. The flaws represent serious security risks as they could enable unauthorized access and remote code execution on affected systems. Organizations using these Cisco products are urged to apply the security updates immedia...
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment 16.04.2026 0:39
This appears to be promotional content for a webinar focused on identifying and removing orphaned non-human identities, which are automated accounts or service credentials that may have been abandoned or improperly managed in an organization's systems. The content also references a Zscaler report highlighting how AI has accelerated attack speeds through VPN vulnerabilities, making traditional...
ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories 15.04.2026 0:39
Eight major industrial technology companies including Siemens, Schneider Electric, and Rockwell Automation have released new security advisories addressing vulnerabilities in critical infrastructure systems. The advisories cover a range of issues from critical flaws in Wi-Fi devices and industrial control software to high-severity vulnerabilities that could allow unauthorized access and privilege...
Fortinet Patches Critical FortiSandbox Vulnerabilities 15.04.2026 0:38
Fortinet has issued patches for 27 vulnerabilities across its product line, including two critical flaws in FortiSandbox with CVSS scores of 9.1 that could allow unauthenticated attackers to bypass authentication and execute arbitrary commands via specially crafted HTTP requests. The company also addressed a high-severity buffer overflow in FortiAnalyzer Cloud and SQL injection bugs in FortiDDoS-F...
Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections 15.04.2026 0:48
President Trump is calling for an 18-month extension of Section 702 of the Foreign Intelligence Surveillance Act, a controversial program that allows U.S. spy agencies to collect foreigners' communications without warrants but also incidentally sweeps up Americans' data. While Trump previously opposed the program and once posted "KILL FISA" on social media, he now says it'...
$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks 15.04.2026 0:53
Researchers at Huntress discovered that malware disguised as adware from Dragon Boss Solutions had evolved to disable antivirus software and disable security updates on over 25,000 compromised computers worldwide. The most alarming finding was that the malware's update domain was unregistered, meaning anyone could have purchased it for as little as $10 to take complete control of infected sys...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.