David

Security Stuff

Author

David

Category

Technology

Latest episode

Jul 2, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Two Vulnerabilities Patched in Ivanti Neurons for ITSM 15.04.2026

Ivanti has patched two medium-severity vulnerabilities in its Neurons for ITSM product that affect both on-premises and cloud deployments. The first flaw could allow authenticated attackers to retain access even after their accounts are disabled, while the second is a cross-site scripting vulnerability that could leak limited session information. Cloud customers were automatically updated on Decem...

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities 15.04.2026

Microsoft has released its latest security update addressing 169 vulnerabilities, including a critical SharePoint zero-day that was being actively exploited in the wild. The patch bundle represents one of the company's larger monthly security releases, highlighting the ongoing challenges in securing enterprise software. Organizations using SharePoint are urged to apply these patches immediate...

Mirax RAT Targeting Android Users in Europe 15.04.2026

A new Android malware called Mirax RAT has been targeting users across Europe through malicious ads on Facebook and Instagram, reaching more than 200,000 users with fake IPTV app promotions. The sophisticated remote access trojan not only steals credentials and allows full device control, but can also turn infected phones into residential proxy nodes for routing malicious traffic. Security firm Cl...

Microsoft, Salesforce Patch AI Agent Data Leak Flaws 15.04.2026

Cybersecurity researchers discovered dangerous prompt injection vulnerabilities in both Salesforce Agentforce and Microsoft Copilot that could have allowed attackers to steal sensitive data from outside the systems. Both tech giants have now patched these security flaws in their AI agent platforms. The vulnerabilities highlight growing security concerns as companies rapidly deploy AI assistants th...

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities 14.04.2026

CISA has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, including two Windows privilege escalation flaws from 2023 and 2025, and a five-year-old Adobe Acrobat bug that allows arbitrary code execution. The warning also covers recent zero-day exploits in Adobe Reader and Fortinet FortiClient, plus an Exchange vulnerability linked to the Medusa ransomware gang and a 2012...

Nightclub Giant RCI Hospitality Reports Data Breach 14.04.2026

RCI Hospitality Holdings, one of the largest adult nightclub operators in the U.S., has disclosed a data breach affecting numerous independent contractors after a simple web vulnerability exposed sensitive personal information including names, Social Security numbers, and driver's license numbers. The incident stemmed from an insecure direct object reference vulnerability on an IIS web server...

Google Adds Rust DNS Parser to Pixel Phones for Better Security 14.04.2026

Google is integrating a Rust-based DNS parser into the modem firmware of its Pixel phones, starting with the Pixel 10 series, to address mounting security concerns around cellular modems. The move is part of Google's broader push to replace memory-unsafe C and C++ code with Rust, a language that eliminates entire classes of vulnerabilities that attackers have increasingly exploited in cellula...

Triad Nexus Evades Sanctions to Fuel Cybercrime 14.04.2026

Despite federal sanctions, the cybercrime operation Triad Nexus continues to evade restrictions by using front companies, account mules, and major cloud services from Amazon, Cloudflare, Google, and Microsoft to maintain legitimacy for their scams. The group, linked to Asian organized crime and responsible for over 200 million dollars in losses through pig butchering scams and brand impersonation,...

SAP Patches Critical ABAP Vulnerability 14.04.2026

SAP has released 20 security patches in its April 2026 update, with the most critical being a SQL injection vulnerability in ABAP programs used by Business Planning and Consolidation software, scored at 9.9 out of 10 on the severity scale. The flaw allows low-privileged users to upload files with malicious SQL code that could lead to arbitrary code execution, potentially letting attackers extract...

Europe’s Largest Gym Chain Says Data Breach Impacts 1 Million Members 14.04.2026

Basic-Fit, Europe's largest gym chain with over 5 million members, has disclosed a data breach affecting approximately 1 million members across the Netherlands, Spain, Germany, France, Belgium, and Luxembourg. The company says it detected and blocked unauthorized access within minutes, but hackers managed to download personal information including names, email addresses, physical addresses, p...

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users 14.04.2026

Security researchers have discovered 108 malicious Chrome extensions that were designed to steal sensitive data from Google accounts and Telegram, affecting approximately 20,000 users. The extensions operated as a sophisticated data-theft campaign, targeting login credentials and other private information from unsuspecting Chrome browser users. This discovery highlights the ongoing security risks...

Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report) 14.04.2026

Zscaler's 2026 VPN Risk Report reveals a fourfold increase in critical security risks based on analysis of 216 million security findings. The report highlights that artificial intelligence has dramatically shortened the window for human response to threats, effectively transforming remote access systems like VPNs into one of the fastest paths for attackers to breach networks. Security experts...

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads 14.04.2026

Cybersecurity researchers have discovered that the Mirax Android malware has infected over 220,000 devices after being distributed through Meta advertising platforms. The malicious remote access trojan converts infected Android devices into SOCKS5 proxies, which can be used to route internet traffic and potentially hide cybercriminal activities. This case highlights growing concerns about malware...

Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users 13.04.2026

Google has rolled out end-to-end encryption for Gmail to enterprise users on Android and iOS devices, expanding on last year's desktop implementation. The feature uses client-side encryption, allowing organizations to control their own encryption keys while users can now read and compose encrypted messages directly within the mobile Gmail app. It's currently available for Google Workspac...

CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads 13.04.2026

The CPUID website was hacked to serve trojanized versions of popular hardware monitoring tools CPU-Z and HWMonitor, infecting over 150 victims across multiple sectors including manufacturing and telecommunications. Attackers compromised a secondary feature on the site for up to six hours, delivering legitimate software bundled with malware designed to deploy STX RAT, which steals browser credentia...

Fake Claude Website Distributes PlugX RAT 13.04.2026

Cybersecurity researchers at Malwarebytes have discovered a fake Claude AI website distributing PlugX malware, a remote access trojan that's been used in espionage campaigns for nearly a decade. The sophisticated attack lures victims with a fake "pro version" of Anthropic's Claude chatbot, which installs the legitimate app but also deploys malicious files through a hidden VBScr...

International Operation Targets Multimillion-Dollar Crypto Theft Schemes 13.04.2026

An international law enforcement operation involving the US, UK, and Canada has successfully disrupted sophisticated cryptocurrency theft schemes, freezing 12 million dollars of the more than 45 million dollars in stolen funds identified during the week-long effort dubbed Operation Atlantic. The investigation uncovered over 20,000 compromised crypto wallet addresses across 30 countries and shut do...

OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack 13.04.2026

OpenAI has confirmed it was affected by a North Korea-linked supply chain attack targeting Axios, a popular JavaScript library with over 100 million weekly downloads. Attackers compromised an Axios maintainer's account and published malicious packages that infiltrated OpenAI's Mac app-signing process, potentially exposing the certificate used to verify legitimate ChatGPT Desktop and othe...

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware 13.04.2026

North Korea's APT37 hacking group is using Facebook to spread RokRAT malware through sophisticated social engineering tactics. The campaign demonstrates how state-sponsored cyber actors are leveraging popular social media platforms to trick users into downloading malicious software. This latest activity highlights the growing threat of nation-state hackers using mainstream social networks as...

Your MTTD Looks Great. Your Post-Alert Gap Doesn't 13.04.2026

A new Zscaler ThreatLabz report reveals that while organizations have improved their mean time to detect threats, they're struggling with what happens after an alert is triggered. The report highlights that AI-powered attacks have dramatically shortened the window for human response, with VPNs becoming a critical vulnerability as attackers exploit remote access infrastructure to move laterall...

Listen to the Security Stuff podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.