<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[Daily DefSec Brief]]></title><description><![CDATA[<p>A daily podcast covering the important cyber security news that IT and security teams need to know.</p>]]></description><link>https://riverside.com</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Wed, 22 Jul 2026 05:35:23 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/oUoHi93O.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Jerry Bell]]></author><pubDate>Mon, 06 Jul 2026 13:47:09 GMT</pubDate><copyright><![CDATA[2026 Jerry Bell]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Technology]]></category><category><![CDATA[Tech News]]></category><itunes:author>Jerry Bell</itunes:author><itunes:summary>&lt;p&gt;A daily podcast covering the important cyber security news that IT and security teams need to know.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Jerry Bell</itunes:name><itunes:email>podcast@defensivesecurity.org</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Technology"/><itunes:category text="News"><itunes:category text="Tech News"/></itunes:category><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 21 2026]]></title><description><![CDATA[<pre><code>1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
3. Fake CAPTCHA lures trick users into running PowerShell — Sandworm (UAC-0145) — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself
4. Zimbra patches critical unauthenticated command injection and XSS flaws — CVE-2026-10631, CVE-2026-50054, CVE-2026-50055 — SecurityWeek — https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/
5. Gitea authorization bypass lets public tokens write to private repos and trigger Actions — CVE-2026-58443 — Cyber Security News — https://cybersecuritynews.com/gitea-vulnerability/
6. HollowGraph implant uses Microsoft 365 calendar events as its C2 channel — The Hacker News — https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
7. Telegram-bot backdoors planted in Middle Eastern government networks — Cyber Security News — https://cybersecuritynews.com/hackers-telegram-bots-secret-backdoor/
8. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — The Hacker News — https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
9. Exposed WebDAV server exposes AI-assisted malware "delivery lab" — CVE list to verify against primary report — Rapid7 — https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis
10. Sandbox escapes hit Cursor, Codex, Gemini CLI, and Antigravity — CVE-2026-48124 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
11. OpenSSL silently patches "HollowByte" pre-handshake memory-exhaustion DoS — SecurityWeek — https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/
12. Linux kernel ships 400+ CVE fixes in about 24 hours — CVE-2026-64122 and others (representative) — Cyber Security News — https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/</code></pre>]]></description><guid isPermaLink="false">8940c07d-f3ff-4683-9a65-b9b7fb637872</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Tue, 21 Jul 2026 12:04:28 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f758d7443f066c85a8208077f32455bb35da35dc3b6c15e4b6ad14ce394590b1/eyJlcGlzb2RlSWQiOiI4OTQwYzA3ZC1mM2ZmLTQ2ODMtOWE2NS1iOWI3ZmI2Mzc4NzIiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1ZjVmYmZkNTg3NDhkMDBmNTM3ODNhL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMjFfXzE0LTItNy5tcDMifQ==.mp3" length="8213046" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/8940c07d-f3ff-4683-9a65-b9b7fb637872/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
3. Fake CAPTCHA lures trick users into running PowerShell — Sandworm (UAC-0145) — Graham Cluley / Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself
4. Zimbra patches critical unauthenticated command injection and XSS flaws — CVE-2026-10631, CVE-2026-50054, CVE-2026-50055 — SecurityWeek — https://www.securityweek.com/zimbra-update-patches-critical-vulnerabilities/
5. Gitea authorization bypass lets public tokens write to private repos and trigger Actions — CVE-2026-58443 — Cyber Security News — https://cybersecuritynews.com/gitea-vulnerability/
6. HollowGraph implant uses Microsoft 365 calendar events as its C2 channel — The Hacker News — https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
7. Telegram-bot backdoors planted in Middle Eastern government networks — Cyber Security News — https://cybersecuritynews.com/hackers-telegram-bots-secret-backdoor/
8. FakeGit campaign uses 7,600 GitHub repos to push SmartLoader and StealC — The Hacker News — https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
9. Exposed WebDAV server exposes AI-assisted malware &quot;delivery lab&quot; — CVE list to verify against primary report — Rapid7 — https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis
10. Sandbox escapes hit Cursor, Codex, Gemini CLI, and Antigravity — CVE-2026-48124 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/
11. OpenSSL silently patches &quot;HollowByte&quot; pre-handshake memory-exhaustion DoS — SecurityWeek — https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/
12. Linux kernel ships 400+ CVE fixes in about 24 hours — CVE-2026-64122 and others (representative) — Cyber Security News — https://cybersecuritynews.com/linux-patches-400-kernel-vulnerabilities/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:17</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 21 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 20 2026]]></title><description><![CDATA[<pre><code>1. ServiceNow AI Platform RCE now under active exploitation — CVE-2026-6875 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
2. WP2Shell — WordPress core flaws exploited within hours — CVE-2026-60137, CVE-2026-63030 — SecurityWeek — https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/
3. Chrome 150 patches seven memory-safety bugs, three critical — SecurityWeek — https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/
4. SleeperGem — malicious RubyGems impersonate git_credential_manager — The Hacker News — https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
5. OTTERCOOKIE hides in SVG images in fake coding-test lure — Cyber Security News — https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/
6. Solo threat actor uses Gemini CLI to run a small botnet — The Hacker News — https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
7. Hugging Face breached by an autonomous AI agent — SecurityWeek — https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/ · The Hacker News — https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
8. GoldenEyeDog breach at DigiCert hijacks code-signing certificates — Cyber Security News — https://cybersecuritynews.com/goldeneyedog-behind-digicert-breach/
9. Microsoft confirms WSUS sync delays blocking patch deployment — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
10. Out-of-band update fixes Dell shutdown bug from July Windows update — KB5121767 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/
11. Windows 10 still on 17% of devices, most excluded from free ESU — Help Net Security — https://www.helpnetsecurity.com/2026/07/20/windows-10-support-risks-report/</code></pre>]]></description><guid isPermaLink="false">0673672d-3297-494e-97c5-1adce69a1def</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Mon, 20 Jul 2026 11:50:59 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/5b3ef9bb08acd977b317fc7d53866ae2ff6612e7544ededd2acc8536165c7554/eyJlcGlzb2RlSWQiOiIwNjczNjcyZC0zMjk3LTQ5NGUtOTdjNS0xYWRjZTY5YTFkZWYiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1ZTBhMjQxMTllNDdiYmUyZTNiNzFhL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMjBfXzEzLTQ0LTM2Lm1wMyJ9.mp3" length="7075361" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/0673672d-3297-494e-97c5-1adce69a1def/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. ServiceNow AI Platform RCE now under active exploitation — CVE-2026-6875 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
2. WP2Shell — WordPress core flaws exploited within hours — CVE-2026-60137, CVE-2026-63030 — SecurityWeek — https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/
3. Chrome 150 patches seven memory-safety bugs, three critical — SecurityWeek — https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/
4. SleeperGem — malicious RubyGems impersonate git_credential_manager — The Hacker News — https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
5. OTTERCOOKIE hides in SVG images in fake coding-test lure — Cyber Security News — https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/
6. Solo threat actor uses Gemini CLI to run a small botnet — The Hacker News — https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
7. Hugging Face breached by an autonomous AI agent — SecurityWeek — https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/ · The Hacker News — https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
8. GoldenEyeDog breach at DigiCert hijacks code-signing certificates — Cyber Security News — https://cybersecuritynews.com/goldeneyedog-behind-digicert-breach/
9. Microsoft confirms WSUS sync delays blocking patch deployment — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
10. Out-of-band update fixes Dell shutdown bug from July Windows update — KB5121767 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/
11. Windows 10 still on 17% of devices, most excluded from free ESU — Help Net Security — https://www.helpnetsecurity.com/2026/07/20/windows-10-support-risks-report/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:03:41</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 20 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 17 2026]]></title><description><![CDATA[<pre><code>1. FortiSandbox OS command injection added to CISA KEV, actively exploited — CVE-2026-25089 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. New HTTP/2 flow-control stall DoS — CVE-2019-9511, CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 — CERT/CC VU#885548 — https://kb.cert.org/vuls/id/885548
3. 7-Zip heap overflow in XZ decompression patched — CVE-2026-14266 — Cyber Security News — https://cybersecuritynews.com/7-zip-vulnerability-code-execution/
4. Researchers describe "agent data injection" (ADI) against AI agents — The Hacker News — https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
Also mentioned:
- ACR Stealer harvests M365 files and browser tokens via ClickFix — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- Sandworm uses fake CAPTCHA pages to trick Ukrainian targets into pasting malicious PowerShell — The Record — https://therecord.media/ukraine-sandworm-hacks-captcha-powershell
- SGLang expert-parallel backup subsystem unpatched pickle deserialization RCE — CERT/CC — https://kb.cert.org/vuls/id/326070</code></pre>]]></description><guid isPermaLink="false">2585facf-2fbd-43c8-b4f4-4e9c5c439d68</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Fri, 17 Jul 2026 11:49:16 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/ad35fb23bd303ee52b1222f8e241bfc385e99ba5077191221cfd035fca62365c/eyJlcGlzb2RlSWQiOiIyNTg1ZmFjZi0yZmJkLTQzYzgtYjRmNC00ZTljNWM0MzlkNjgiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1YTE0NDIyNWNhZmEyNDgwMWU1YjE4L2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTdfXzEzLTM4LTQyLm1wMyJ9.mp3" length="7972301" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/2585facf-2fbd-43c8-b4f4-4e9c5c439d68/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. FortiSandbox OS command injection added to CISA KEV, actively exploited — CVE-2026-25089 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. New HTTP/2 flow-control stall DoS — CVE-2019-9511, CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 — CERT/CC VU#885548 — https://kb.cert.org/vuls/id/885548
3. 7-Zip heap overflow in XZ decompression patched — CVE-2026-14266 — Cyber Security News — https://cybersecuritynews.com/7-zip-vulnerability-code-execution/
4. Researchers describe &quot;agent data injection&quot; (ADI) against AI agents — The Hacker News — https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
Also mentioned:
- ACR Stealer harvests M365 files and browser tokens via ClickFix — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- Sandworm uses fake CAPTCHA pages to trick Ukrainian targets into pasting malicious PowerShell — The Record — https://therecord.media/ukraine-sandworm-hacks-captcha-powershell
- SGLang expert-parallel backup subsystem unpatched pickle deserialization RCE — CERT/CC — https://kb.cert.org/vuls/id/326070&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:09</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 17 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 16 2026]]></title><description><![CDATA[<pre><code>1. CISA adds actively exploited Oracle E-Business Suite flaw to KEV, feds have until Saturday — CVE-2026-46817 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
2. Zoom patches critical Windows account-takeover flaw — CVE-2026-53412, CVE-2026-53409, CVE-2026-53410, CVE-2026-53411 — BleepingComputer https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ · The Hacker News https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html
3. F5 ships out-of-band patch for critical NGINX flaw — CVE-2026-42533 — SecurityWeek https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/
4. Russian-speaking group trojanizes WebEx, Zoom, MobaXterm installers to push Starland RAT — UAT-11795 — Cisco Talos https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ · BleepingComputer https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/
Also mentioned:
- New Spirals ransomware encrypts victim network in under 24 hours — BleepingComputer https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
- JetBrains patches six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA — Cyber Security News https://cybersecuritynews.com/jetbrains-patched-vulnerabilities/
- Cisco patches authenticated privilege-escalation chain in Catalyst SD-WAN — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx
- Firefox and Chrome ship critical patches, two Firefox bugs with public exploit code — The Hacker News https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html</code></pre>]]></description><guid isPermaLink="false">a2d6a811-4cee-492d-87aa-490877861e86</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Thu, 16 Jul 2026 13:38:08 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d1dac5d0f8f9b489a1459c0be79ea7f4f19bf5d331fdf72640597fac483df1a9/eyJlcGlzb2RlSWQiOiJhMmQ2YTgxMS00Y2VlLTQ5MmQtODdhYS00OTA4Nzc4NjFlODYiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1OGRiYzU2MDJjMzA3Y2FkZDQwNmFhL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTZfXzE1LTI1LTI1Lm1wMyJ9.mp3" length="8025800" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/a2d6a811-4cee-492d-87aa-490877861e86/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. CISA adds actively exploited Oracle E-Business Suite flaw to KEV, feds have until Saturday — CVE-2026-46817 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
2. Zoom patches critical Windows account-takeover flaw — CVE-2026-53412, CVE-2026-53409, CVE-2026-53410, CVE-2026-53411 — BleepingComputer https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/ · The Hacker News https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html
3. F5 ships out-of-band patch for critical NGINX flaw — CVE-2026-42533 — SecurityWeek https://www.securityweek.com/f5-patches-multiple-nginx-big-ip-vulnerabilities/
4. Russian-speaking group trojanizes WebEx, Zoom, MobaXterm installers to push Starland RAT — UAT-11795 — Cisco Talos https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/ · BleepingComputer https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware/
Also mentioned:
- New Spirals ransomware encrypts victim network in under 24 hours — BleepingComputer https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
- JetBrains patches six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA — Cyber Security News https://cybersecuritynews.com/jetbrains-patched-vulnerabilities/
- Cisco patches authenticated privilege-escalation chain in Catalyst SD-WAN — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx
- Firefox and Chrome ship critical patches, two Firefox bugs with public exploit code — The Hacker News https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:11</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 16 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 15 2026]]></title><description><![CDATA[<pre><code>1. CISA adds SharePoint and AD FS zero-days to KEV, deadline Friday — CVE-2026-56164, CVE-2026-56155 (also CVE-2026-32201, CVE-2026-45659, CVE-2026-58644, CVE-2026-55040) — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · CISA advisory https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations · Rapid7 https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed
2. SonicWall SMA1000 flaws added to KEV, same Friday deadline — CVE-2026-15409, CVE-2026-15410 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. Progress confirms ShareFile zero-day, patches out, service restored — CVE TBD (see Progress advisory) — BleepingComputer https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ · SecurityWeek https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/
4. Cursor IDE auto-runs a malicious git.exe on opening a repo — no CVE assigned — The Hacker News https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html · Dark Reading https://www.darkreading.com/application-security/cursor-ide-malicious-code-poisoned-repos
Also mentioned:
- RabbitMQ patches OAuth-secret and cross-tenant queue flaws — The Hacker News https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.html
- ESET finds 11 Microsoft-signed Linux UEFI shims bypassing Secure Boot — The Hacker News https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
- Compromised @asyncapi npm packages shipping a botnet loader — The Hacker News https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html
- Adobe patches eight critical ColdFusion vulnerabilities — SecurityWeek https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/</code></pre>]]></description><guid isPermaLink="false">dc5fe03d-c958-44c1-a162-ce39b8f8fbc5</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Wed, 15 Jul 2026 12:32:08 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/8fb2eaae1ff8d937eb1287cb7a207513372eeb9dd677b65ac38c74c1f14a5477/eyJlcGlzb2RlSWQiOiJkYzVmZTAzZC1jOTU4LTQ0YzEtYTE2Mi1jZTM5YjhmOGZiYzUiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1Nzc5OTczYzAxMjZiNmI0OTJmYzE2L2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTVfXzE0LTE0LTE0Lm1wMyJ9.mp3" length="8411158" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/dc5fe03d-c958-44c1-a162-ce39b8f8fbc5/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. CISA adds SharePoint and AD FS zero-days to KEV, deadline Friday — CVE-2026-56164, CVE-2026-56155 (also CVE-2026-32201, CVE-2026-45659, CVE-2026-58644, CVE-2026-55040) — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · CISA advisory https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations · Rapid7 https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed
2. SonicWall SMA1000 flaws added to KEV, same Friday deadline — CVE-2026-15409, CVE-2026-15410 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. Progress confirms ShareFile zero-day, patches out, service restored — CVE TBD (see Progress advisory) — BleepingComputer https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ · SecurityWeek https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/
4. Cursor IDE auto-runs a malicious git.exe on opening a repo — no CVE assigned — The Hacker News https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html · Dark Reading https://www.darkreading.com/application-security/cursor-ide-malicious-code-poisoned-repos
Also mentioned:
- RabbitMQ patches OAuth-secret and cross-tenant queue flaws — The Hacker News https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.html
- ESET finds 11 Microsoft-signed Linux UEFI shims bypassing Secure Boot — The Hacker News https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
- Compromised @asyncapi npm packages shipping a botnet loader — The Hacker News https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html
- Adobe patches eight critical ColdFusion vulnerabilities — SecurityWeek https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 15 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 14 2026]]></title><description><![CDATA[<pre><code>1. CISA adds 18-year-old Cisco IOS flaw to KEV catalog — CVE-2008-4128 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Microsoft maps a year of ShinyHunters-style OAuth abuse against Salesforce and SaaS apps — no CVE — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
3. SAP patches critical NetWeaver memory corruption flaw — CVE-2026-44747 (CVSS 9.9) — Cyber Security News — https://cybersecuritynews.com/sap-security-update-july-2026/
4. ServiceNow fixes unauthenticated sandbox-escape RCE in AI Platform — CVE-2026-6875 — Cyber Security News — https://cybersecuritynews.com/servicenow-remote-malicious-code/
Also mentioned:
- Google and Microsoft pull ModHeader extension over hidden history collector — The Hacker News — https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
- CISA GitHub leak: admin keys and credentials exposed for six months — Krebs on Security — https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
- 148 npm packages disguised as school Wi-Fi tools built a browser DDoS botnet — The Hacker News — https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html
- Forg365 phishing-as-a-service targets Microsoft 365 — The Hacker News — https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html
</code></pre>]]></description><guid isPermaLink="false">ecfd1817-e7f7-4f9f-8596-d53c2ecd6ae1</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Tue, 14 Jul 2026 13:31:01 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3565dc47ec2225eb013815e2ba367c7065d3b4ad3f97fa5895c5ac9ce84960ff/eyJlcGlzb2RlSWQiOiJlY2ZkMTgxNy1lN2Y3LTRmOWYtODU5Ni1kNTNjMmVjZDZhZTEiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1NjM5YTE4OTVkMjA2YTNmOWFlZjQ5L2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTRfXzE1LTI5LTUubXAzIn0=.mp3" length="9741940" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/ecfd1817-e7f7-4f9f-8596-d53c2ecd6ae1/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. CISA adds 18-year-old Cisco IOS flaw to KEV catalog — CVE-2008-4128 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Microsoft maps a year of ShinyHunters-style OAuth abuse against Salesforce and SaaS apps — no CVE — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
3. SAP patches critical NetWeaver memory corruption flaw — CVE-2026-44747 (CVSS 9.9) — Cyber Security News — https://cybersecuritynews.com/sap-security-update-july-2026/
4. ServiceNow fixes unauthenticated sandbox-escape RCE in AI Platform — CVE-2026-6875 — Cyber Security News — https://cybersecuritynews.com/servicenow-remote-malicious-code/
Also mentioned:
- Google and Microsoft pull ModHeader extension over hidden history collector — The Hacker News — https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
- CISA GitHub leak: admin keys and credentials exposed for six months — Krebs on Security — https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
- 148 npm packages disguised as school Wi-Fi tools built a browser DDoS botnet — The Hacker News — https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html
- Forg365 phishing-as-a-service targets Microsoft 365 — The Hacker News — https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html
&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:05:04</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 14 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 13 2026]]></title><description><![CDATA[<pre><code>1. Progress tells ShareFile customers to shut down Storage Zone Controller servers — CVE-2026-2699, CVE-2026-2701 — SecurityWeek — https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/
2. Zimbra patches critical zero-click code execution flaw — CVE not yet disclosed — SecurityWeek — https://www.securityweek.com/zimbra-patches-critical-code-execution-vulnerability/
3. Scanning campaign targeting MCP servers and AI assistant credentials — no CVE (SANS ISC research) — SANS ISC — https://isc.sans.edu/diary/rss/33150
Also mentioned:
- npm package jscrambler compromised via stolen publishing credential — Cyber Security News — https://cybersecuritynews.com/hackers-compromised-jscrambler/
- Misconfigured server exposes three Microsoft 365 Evilginx phishing operations — The Hacker News — https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
- WordPress miniOrange OAuth SSO plugin auth bypass — CVE-2026-57807 — Cyber Security News — https://cybersecuritynews.com/wordpress-plugin-vulnerability-miniorange/
- RedHook Android malware adds Wireless ADB abuse — BleepingComputer — https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/</code></pre>]]></description><guid isPermaLink="false">ccb8cdaf-6e50-421e-acd1-011ede8ff25f</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Mon, 13 Jul 2026 12:29:49 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/271b840660ded2e6419f0e31a26e2113138576eba3e42ccc6c70ef2f318082a1/eyJlcGlzb2RlSWQiOiJjY2I4Y2RhZi02ZTUwLTQyMWUtYWNkMS0wMTFlZGU4ZmYyNWYiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1NGQ5ZGMzOGQ5ZDVmODBkODk1MzRlL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTNfXzE0LTI4LTEyLm1wMyJ9.mp3" length="7785055" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/ccb8cdaf-6e50-421e-acd1-011ede8ff25f/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. Progress tells ShareFile customers to shut down Storage Zone Controller servers — CVE-2026-2699, CVE-2026-2701 — SecurityWeek — https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/
2. Zimbra patches critical zero-click code execution flaw — CVE not yet disclosed — SecurityWeek — https://www.securityweek.com/zimbra-patches-critical-code-execution-vulnerability/
3. Scanning campaign targeting MCP servers and AI assistant credentials — no CVE (SANS ISC research) — SANS ISC — https://isc.sans.edu/diary/rss/33150
Also mentioned:
- npm package jscrambler compromised via stolen publishing credential — Cyber Security News — https://cybersecuritynews.com/hackers-compromised-jscrambler/
- Misconfigured server exposes three Microsoft 365 Evilginx phishing operations — The Hacker News — https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
- WordPress miniOrange OAuth SSO plugin auth bypass — CVE-2026-57807 — Cyber Security News — https://cybersecuritynews.com/wordpress-plugin-vulnerability-miniorange/
- RedHook Android malware adds Wireless ADB abuse — BleepingComputer — https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:03</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 13 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[DefSec Brief week in review, July 11 2026]]></title><description><![CDATA[<pre><code>1. Langflow authorization bypass on KEV, plus the first fully autonomous LLM-driven ransomware campaign — CVE-2026-55255, CVE-2025-3248 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
2. Adobe ColdFusion path traversal added to KEV, actively exploited — CVE-2026-48282 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. CitrixBleed 2 chain confirmed as a path to Dragonforce ransomware — CVE-2025-5777, CVE-2023-4966, CVE-2026-4368 — Huntress https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
4. BeyondTrust patches critical pre-auth bypass flaws in Remote Support and PRA — CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141 — The Hacker News https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html
5. Progress orders on-prem ShareFile customers to shut down Storage Zone Controllers — CVE not confirmed by vendor — The Hacker News https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html · Cyber Security News https://cybersecuritynews.com/progress-sharefile-admins-shut-down-servers/
6. CISA adds four Joomla/WordPress extension file-upload flaws to KEV — CVE-2026-56291, CVE-2026-48939, CVE-2026-48908, CVE-2026-56290 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
7. Exposed WP-SHELLSTORM server reveals webshell brokerage hitting 1.4M sites — CVE-2026-48907, CVE-2026-3844 (among others) — The Hacker News https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
8. Suspected China-aligned group exploits Roundcube flaws against university research departments — CVE-2024-42009, CVE-2025-49113 — CyberScoop https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/ · The Hacker News https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html
9. Cisco patches RCE and file-read flaws in ISE and Catalyst Center — CVE-2026-20181, CVE-2026-20190, CVE-2026-20191 — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv · https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
10. 16-year-old Linux KVM use-after-free lets a guest VM escape to the host — CVE-2026-53359 "Januscape" — The Hacker News https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html</code></pre>]]></description><guid isPermaLink="false">5a0437ff-7d60-47ee-85f6-eb7d8d30ec3a</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Sat, 11 Jul 2026 15:11:50 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/07b49996f2463d8b04c0698f64a3bce94adcecfba00fcf8d7a226333080266a1/eyJlcGlzb2RlSWQiOiI1YTA0MzdmZi03ZDYwLTQ3ZWUtODVmNi1lYjdkOGQzMGVjM2EiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1MjViOWNiNzliMTNhY2QxMTYzYzAwL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTFfXzE3LTUtMC5tcDMifQ==.mp3" length="16670032" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/5a0437ff-7d60-47ee-85f6-eb7d8d30ec3a/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. Langflow authorization bypass on KEV, plus the first fully autonomous LLM-driven ransomware campaign — CVE-2026-55255, CVE-2025-3248 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
2. Adobe ColdFusion path traversal added to KEV, actively exploited — CVE-2026-48282 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
3. CitrixBleed 2 chain confirmed as a path to Dragonforce ransomware — CVE-2025-5777, CVE-2023-4966, CVE-2026-4368 — Huntress https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
4. BeyondTrust patches critical pre-auth bypass flaws in Remote Support and PRA — CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141 — The Hacker News https://thehackernews.com/2026/07/beyondtrust-patches-critical-auth.html
5. Progress orders on-prem ShareFile customers to shut down Storage Zone Controllers — CVE not confirmed by vendor — The Hacker News https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html · Cyber Security News https://cybersecuritynews.com/progress-sharefile-admins-shut-down-servers/
6. CISA adds four Joomla/WordPress extension file-upload flaws to KEV — CVE-2026-56291, CVE-2026-48939, CVE-2026-48908, CVE-2026-56290 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog
7. Exposed WP-SHELLSTORM server reveals webshell brokerage hitting 1.4M sites — CVE-2026-48907, CVE-2026-3844 (among others) — The Hacker News https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
8. Suspected China-aligned group exploits Roundcube flaws against university research departments — CVE-2024-42009, CVE-2025-49113 — CyberScoop https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/ · The Hacker News https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html
9. Cisco patches RCE and file-read flaws in ISE and Catalyst Center — CVE-2026-20181, CVE-2026-20190, CVE-2026-20191 — Cisco PSIRT https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv · https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
10. 16-year-old Linux KVM use-after-free lets a guest VM escape to the host — CVE-2026-53359 &quot;Januscape&quot; — The Hacker News https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:08:41</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>DefSec Brief week in review, July 11 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 10 2026]]></title><description><![CDATA[<pre><code>1. Initial access broker weaponizing CitrixBleed 2 to deploy Dragonforce ransomware — CVE-2025-5777 (referencing CVE-2023-4966, CVE-2026-4368) — Huntress — https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
2. Django SQL injection actively exploited in GeoDjango deployments — CVE-2026-1207 — Cyber Security News — https://cybersecuritynews.com/django-sql-injection-vulnerability-exploited/
3. Microsoft tells customers to shorten patch deployment windows because of AI — no CVE — Help Net Security — https://www.helpnetsecurity.com/2026/07/10/microsoft-windows-update-deployment-timelines/ ; BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-expects-more-windows-security-updates-from-ai-discovered-flaws/
4. Network of 200-plus GitHub repos delivering Windows malware (Operation Muck and Load) — no CVE — SecurityWeek — https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection/
Also mentioned:
- Injective SDK npm package compromised (v1.20.21) — BleepingComputer — https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/
- Dormant GitHub accounts reactivated to map corporate orgs via API — The Hacker News — https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html
- "HalluSquatting" turns AI hallucinations into botnet delivery — SecurityWeek — https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/
- Binarly finds six U-Boot signature verification flaws going back to 2013 — Cyber Security News — https://cybersecuritynews.com/u-boot-fit-signature-verification/
- Bitwarden authentication bypass https://ccb.belgium.be/advisories/warning-bitwarden-server-auth-bypass-allows-vault-takeover-patch-immediately

</code></pre>]]></description><guid isPermaLink="false">501201e2-5428-4d8e-b38f-1c640f7c2a5a</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Fri, 10 Jul 2026 12:52:12 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/16132c51441c3755a4e4c33a2d494809e0a42201675f2104cbb23eef2571fbf3/eyJlcGlzb2RlSWQiOiI1MDEyMDFlMi01NDI4LTRkOGUtYjM4Zi0xYzY0MGY3YzJhNWEiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE1MGVhNDY4ZjcxZmJjYjEzOTA0MGEyL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctMTBfXzE0LTQ5LTEwLm1wMyJ9.mp3" length="10337950" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/501201e2-5428-4d8e-b38f-1c640f7c2a5a/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. Initial access broker weaponizing CitrixBleed 2 to deploy Dragonforce ransomware — CVE-2025-5777 (referencing CVE-2023-4966, CVE-2026-4368) — Huntress — https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
2. Django SQL injection actively exploited in GeoDjango deployments — CVE-2026-1207 — Cyber Security News — https://cybersecuritynews.com/django-sql-injection-vulnerability-exploited/
3. Microsoft tells customers to shorten patch deployment windows because of AI — no CVE — Help Net Security — https://www.helpnetsecurity.com/2026/07/10/microsoft-windows-update-deployment-timelines/ ; BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-expects-more-windows-security-updates-from-ai-discovered-flaws/
4. Network of 200-plus GitHub repos delivering Windows malware (Operation Muck and Load) — no CVE — SecurityWeek — https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection/
Also mentioned:
- Injective SDK npm package compromised (v1.20.21) — BleepingComputer — https://www.bleepingcomputer.com/news/security/injective-sdk-on-npm-infected-with-cryptocurrency-wallet-stealer/
- Dormant GitHub accounts reactivated to map corporate orgs via API — The Hacker News — https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html
- &quot;HalluSquatting&quot; turns AI hallucinations into botnet delivery — SecurityWeek — https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/
- Binarly finds six U-Boot signature verification flaws going back to 2013 — Cyber Security News — https://cybersecuritynews.com/u-boot-fit-signature-verification/
- Bitwarden authentication bypass https://ccb.belgium.be/advisories/warning-bitwarden-server-auth-bypass-allows-vault-takeover-patch-immediately

&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:05:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 10 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily Defsec Brief - Cyber Security News for July 9 2026]]></title><description><![CDATA[<pre><code>Apologies for the dog barking.  She was mad that she had not yet received her morning allotment of cheese.

1. Microsoft patches the RoguePlanet Defender zero-day after a month of public exploit code — CVE-2026-50656 (related: CVE-2026-33825, CVE-2026-41091, CVE-2026-45498) — BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/ · SecurityWeek https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/
2. GodDamn ransomware uses a Microsoft-signed driver to blind EDR via BYOVD — no CVE — Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
3. Vishing campaign enrolls attacker-controlled passkeys on Microsoft 365 accounts — no CVE — BleepingComputer https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
4. Fake Paysafe, Skrill, and Neteller SDKs on npm and PyPI steal developer credentials — no CVE — BleepingComputer https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/
Also mentioned:
- Chrome 150 patches 27 vulnerabilities, including two critical use-after-free bugs — SecurityWeek https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities/
- GitLab patches eight Community and Enterprise Edition flaws, including a high-severity XSS — Cyber Security News https://cybersecuritynews.com/gitlab-patches-security-vulnerabilities/
- Lurking Lizard runs 230-plus lookalike domains pushing a trojanized 7-Zip installer that turns machines into residential proxy nodes — The Hacker News https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html
- Fake LetsVPN installer bundles a real signed VPN with a hidden RAT called GoodPersonRAT — Cyber Security News https://cybersecuritynews.com/goodpersonrat-uses-fake-letsvpn-installer/
</code></pre>]]></description><guid isPermaLink="false">7354a66f-64e2-485b-98be-797d4dac0d67</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Thu, 09 Jul 2026 13:20:33 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/b9c40f66f8326a50b06d44eb8ae15b6bab228058973a239ecc21d08850df8220/eyJlcGlzb2RlSWQiOiI3MzU0YTY2Zi02NGUyLTQ4NWItOThiZS03OTdkNGRhYzBkNjciLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0ZjlmOGMwMzQ4Yjg4ZjRkZGQ4ZTcyL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctOV9fMTUtMTgtNC5tcDMifQ==.mp3" length="9478626" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/7354a66f-64e2-485b-98be-797d4dac0d67/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;Apologies for the dog barking.  She was mad that she had not yet received her morning allotment of cheese.

1. Microsoft patches the RoguePlanet Defender zero-day after a month of public exploit code — CVE-2026-50656 (related: CVE-2026-33825, CVE-2026-41091, CVE-2026-45498) — BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/ · SecurityWeek https://www.securityweek.com/microsoft-patches-defender-rogueplanet-vulnerability/
2. GodDamn ransomware uses a Microsoft-signed driver to blind EDR via BYOVD — no CVE — Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
3. Vishing campaign enrolls attacker-controlled passkeys on Microsoft 365 accounts — no CVE — BleepingComputer https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
4. Fake Paysafe, Skrill, and Neteller SDKs on npm and PyPI steal developer credentials — no CVE — BleepingComputer https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/
Also mentioned:
- Chrome 150 patches 27 vulnerabilities, including two critical use-after-free bugs — SecurityWeek https://www.securityweek.com/chrome-150-update-patches-27-vulnerabilities/
- GitLab patches eight Community and Enterprise Edition flaws, including a high-severity XSS — Cyber Security News https://cybersecuritynews.com/gitlab-patches-security-vulnerabilities/
- Lurking Lizard runs 230-plus lookalike domains pushing a trojanized 7-Zip installer that turns machines into residential proxy nodes — The Hacker News https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.html
- Fake LetsVPN installer bundles a real signed VPN with a hidden RAT called GoodPersonRAT — Cyber Security News https://cybersecuritynews.com/goodpersonrat-uses-fake-letsvpn-installer/
&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:04:56</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily Defsec Brief - Cyber Security News for July 9 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 8 2026]]></title><description><![CDATA[<pre><code>1. CISA adds ColdFusion, Langflow, and two Joomla plugins to KEV — patch by Friday — CVE-2026-48282, CVE-2026-55255, CVE-2026-48908, CVE-2026-56290 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/ · SecurityWeek: https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/
2. Ubiquiti patches max-severity command injection in UniFi Connect — CVE-2026-50746 (plus CVE-2026-50747, -50748, -54400, -54402, -55115, -55116) — BleepingComputer: https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/
3. Critical Gitea auth bypass under active exploitation — CVE-2026-20896 — SecurityWeek: https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn/
4. GhostLock: 15-year-old Linux kernel flaw gives root and container escape — CVE-2026-43499 — The Hacker News: https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
Also mentioned:
- China-linked UAT-7810 expands ORB network with LONGLEASH malware via Ruckus routers — Cisco Talos via BleepingComputer: https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/
- GitLost prompt-injection leaks private GitHub repo data via public issues — The Hacker News: https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html
- Malvertising campaign drops Vidar stealer and XMRig miner via fake cracked software — Unit 42: https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/
- Hardcoded backdoor password in Tenda router firmware (CVE-2026-11405) — CERT/CC via BleepingComputer: https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/</code></pre>]]></description><guid isPermaLink="false">0e18a539-9a05-42fb-9f09-287c3a12518d</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Wed, 08 Jul 2026 12:18:17 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/67c9e996b35def3d583af2b7a03efe8717ab59b140a1cd01b1364495bb5ad354/eyJlcGlzb2RlSWQiOiIwZTE4YTUzOS05YTA1LTQyZmItOWYwOS0yODdjM2ExMjUxOGQiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0ZTNlYmE2OWY1ZmI1NGY1ZDZkMTUzL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctOF9fMTQtMTItNDIubXAzIn0=.mp3" length="9655005" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/0e18a539-9a05-42fb-9f09-287c3a12518d/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. CISA adds ColdFusion, Langflow, and two Joomla plugins to KEV — patch by Friday — CVE-2026-48282, CVE-2026-55255, CVE-2026-48908, CVE-2026-56290 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/ · SecurityWeek: https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-coldfusion-langflow-joomla-flaws/
2. Ubiquiti patches max-severity command injection in UniFi Connect — CVE-2026-50746 (plus CVE-2026-50747, -50748, -54400, -54402, -55115, -55116) — BleepingComputer: https://www.bleepingcomputer.com/news/security/ubiquiti-warns-of-new-max-severity-unifi-os-vulnerability/
3. Critical Gitea auth bypass under active exploitation — CVE-2026-20896 — SecurityWeek: https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn/
4. GhostLock: 15-year-old Linux kernel flaw gives root and container escape — CVE-2026-43499 — The Hacker News: https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
Also mentioned:
- China-linked UAT-7810 expands ORB network with LONGLEASH malware via Ruckus routers — Cisco Talos via BleepingComputer: https://www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/
- GitLost prompt-injection leaks private GitHub repo data via public issues — The Hacker News: https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html
- Malvertising campaign drops Vidar stealer and XMRig miner via fake cracked software — Unit 42: https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/
- Hardcoded backdoor password in Tenda router firmware (CVE-2026-11405) — CERT/CC via BleepingComputer: https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:05:02</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 8 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Daily DefSec Brief - Cyber Security News for July 7 2026]]></title><description><![CDATA[<pre><code>1. BeyondTrust patches critical auth-bypass flaws in Remote Support and Privileged Remote Access — CVE-2026-40138, CVE-2026-40139 — BleepingComputer — https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/
2. Fake Microsoft Teams IT-support calls deliver EtherRAT malware — no CVE (technique; Unit 42 / Palo Alto Networks) — BleepingComputer — https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/
3. Cisco patches RCE and info-disclosure flaws in Identity Services Engine — CVE-2026-20181, CVE-2026-20190 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv
4. "Januscape" Linux kernel flaw allows VM escape on Intel and AMD hosts — CVE-2026-53359 — SecurityWeek — https://www.securityweek.com/linux-kernel-vulnerability-allows-vm-escape-on-intel-and-amd-systems/</code></pre>]]></description><guid isPermaLink="false">2cb0beae-0253-4e5c-a467-c4e825a3e5f0</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Tue, 07 Jul 2026 16:23:24 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/8f99661e92c3d7b4b3a46daf4a090c5fe5cdee69ebacb1cbbe3d12e41eaf54b3/eyJlcGlzb2RlSWQiOiIyY2IwYmVhZS0wMjUzLTRlNWMtYTQ2Ny1jNGU4MjVhM2U1ZjAiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0ZDI2YzFjMjZlYjRjYTc3ZjJmOWRkL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctN19fMTgtMTgtOS5tcDMifQ==.mp3" length="9650825" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/2cb0beae-0253-4e5c-a467-c4e825a3e5f0/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. BeyondTrust patches critical auth-bypass flaws in Remote Support and Privileged Remote Access — CVE-2026-40138, CVE-2026-40139 — BleepingComputer — https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/
2. Fake Microsoft Teams IT-support calls deliver EtherRAT malware — no CVE (technique; Unit 42 / Palo Alto Networks) — BleepingComputer — https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/
3. Cisco patches RCE and info-disclosure flaws in Identity Services Engine — CVE-2026-20181, CVE-2026-20190 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv
4. &quot;Januscape&quot; Linux kernel flaw allows VM escape on Intel and AMD hosts — CVE-2026-53359 — SecurityWeek — https://www.securityweek.com/linux-kernel-vulnerability-allows-vm-escape-on-intel-and-amd-systems/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:05:02</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>Daily DefSec Brief - Cyber Security News for July 7 2026</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The Microsoft login page that phishing training can't save you from]]></title><description><![CDATA[<pre><code>1. Attackers phishing Microsoft's device-code login flow — no CVE (flow abuse) — Securelist (Kaspersky) — https://securelist.com/microsoft-device-code-phishing-attack/120350/
2. Unauthenticated PHP-FPM crash via TLS stream wrapper — CVE-2026-12184 — Cyber Security News — https://cybersecuritynews.com/multiple-php-vulnerabilities-dos/
3. ModSecurity WAF input-inspection bypass bugs — CVE-2026-52761, CVE-2026-52747 — Cyber Security News — https://cybersecuritynews.com/modsecurity-vulnerabilities/
4. Attackers abusing OpenAI's org-invite system — no CVE (feature abuse) — Cyber Security News (citing Push Security) — https://cybersecuritynews.com/hackers-use-openai-org-invites/
Also mentioned:
- ClamAV patches seven scanner bugs (update to 1.5.3 / 1.4.5 LTS) — Help Net Security — https://www.helpnetsecurity.com/2026/07/06/clamav-security-patch-versions/
- Cisco Catalyst Center arbitrary file read (CVE-2026-20191) — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
- Opera GX zero-click browser-mod / Gmail-address bug (update to 130.0.5847.89) — The Hacker News — https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html
- Gaslight North Korean-linked macOS malware — Cyber Security News — https://cybersecuritynews.com/gaslight-macos-malware-uses-prompt-injection/</code></pre>]]></description><guid isPermaLink="false">b53971e5-b91b-4eb7-94c1-e8c28af5e4cd</guid><dc:creator><![CDATA[Jerry Bell]]></dc:creator><pubDate>Mon, 06 Jul 2026 13:49:42 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/dfcd5f13de27793175795ca1a86040e5e2fe133461f5e3ea537014fcde0c64ee/eyJlcGlzb2RlSWQiOiJiNTM5NzFlNS1iOTFiLTRlYjctOTRjMS1lOGMyOGFmNWU0Y2QiLCJwb2RjYXN0SWQiOiJkMjFhMzBkMS1iNTAyLTQ3MGUtYjM0YS02MzgxNDU1NzVjNzIiLCJhY2NvdW50SWQiOiI2NzMwZWE2ODJhNzMyZWRiZWNmMWVlMzMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0YmFkYjIzZjJiYWMyMTE0ZDA0MGQxL2RhaWx5LWRlZnNlYy1jb21wb3Nlci0yMDI2LTctNl9fMTUtMjktMjIubXAzIn0=.mp3" length="10871266" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/episodes/b53971e5-b91b-4eb7-94c1-e8c28af5e4cd/transcripts.txt" type="text/plain"/><itunes:summary>&lt;pre&gt;&lt;code&gt;1. Attackers phishing Microsoft&apos;s device-code login flow — no CVE (flow abuse) — Securelist (Kaspersky) — https://securelist.com/microsoft-device-code-phishing-attack/120350/
2. Unauthenticated PHP-FPM crash via TLS stream wrapper — CVE-2026-12184 — Cyber Security News — https://cybersecuritynews.com/multiple-php-vulnerabilities-dos/
3. ModSecurity WAF input-inspection bypass bugs — CVE-2026-52761, CVE-2026-52747 — Cyber Security News — https://cybersecuritynews.com/modsecurity-vulnerabilities/
4. Attackers abusing OpenAI&apos;s org-invite system — no CVE (feature abuse) — Cyber Security News (citing Push Security) — https://cybersecuritynews.com/hackers-use-openai-org-invites/
Also mentioned:
- ClamAV patches seven scanner bugs (update to 1.5.3 / 1.4.5 LTS) — Help Net Security — https://www.helpnetsecurity.com/2026/07/06/clamav-security-patch-versions/
- Cisco Catalyst Center arbitrary file read (CVE-2026-20191) — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X
- Opera GX zero-click browser-mod / Gmail-address bug (update to 130.0.5847.89) — The Hacker News — https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.html
- Gaslight North Korean-linked macOS malware — Cyber Security News — https://cybersecuritynews.com/gaslight-macos-malware-uses-prompt-injection/&lt;/code&gt;&lt;/pre&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:05:40</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/podcasts/d21a30d1-b502-470e-b34a-638145575c72/logos/d8a2469c-4d27-4790-ac31-ecd6b8f6f449.png"/><itunes:title>The Microsoft login page that phishing training can&apos;t save you from</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>