<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CISO Talk by James Azar: CyberHub Podcast]]></title><description><![CDATA[Today’s top cybersecurity news and the latest from Practicing CISO James Azar, tune in to hear how practitioners read, view and work after hearing the latest headlines and how these stories help keep practitioners sharp and ready. ]]></description><link>https://www.cyberhubpodcast.com/s/cyberhub-podcast</link><image><url>https://substackcdn.com/image/fetch/$s_!r32m!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4fb3476-5e78-42fb-a02d-ffcc85932554_1280x1280.png</url><title>CISO Talk by James Azar: CyberHub Podcast</title><link>https://www.cyberhubpodcast.com/s/cyberhub-podcast</link></image><generator>Substack</generator><lastBuildDate>Sat, 27 Jun 2026 20:46:14 GMT</lastBuildDate><atom:link href="https://www.cyberhubpodcast.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[James Azar]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jamesazar@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jamesazar@substack.com]]></itunes:email><itunes:name><![CDATA[James Azar]]></itunes:name></itunes:owner><itunes:author><![CDATA[James Azar]]></itunes:author><googleplay:owner><![CDATA[jamesazar@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jamesazar@substack.com]]></googleplay:email><googleplay:author><![CDATA[James Azar]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[This Week in Cybersecurity #57]]></title><description><![CDATA[Your weekend catch-up on the most critical cybersecurity stories of the week, curated by James Azar and the CyberHub Security Gang.]]></description><link>https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-57</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-57</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Fri, 26 Jun 2026 21:28:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YhyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>Happy Friday, Security Gang!</strong></h3><p>Double espresso in hand. This week James returned to a theme that has defined 2026 in cybersecurity and it is not AI, not zero-days, and not nation-state sophistication. It is operational execution gaps. Attackers keep winning through problems we already know how to solve.</p><p>Splunk made CISA&#8217;s KEV for the first time ever days after disclosure, with public PoC code available within 48 hours. FortiBleed expanded to 86,644 verified Fortinet credentials across 194 countries, harvested not through a new vulnerability but through infostealer logs and stale default accounts. The Klue supply chain breach cascaded into HackerOne, Huntress, Recorded Future, Tanium, Snyk, LastPass, Jamf, OneTrust, and more tracing back to a pilot-project credential left active for four years after the pilot ended. Cisco Unified Communications Manager is being actively exploited despite a patch available for three weeks. And three Ubiquiti UniFi vulnerabilities carrying CVSS 10.0 scores were confirmed under automated mass exploitation with federal agencies facing a June 26 remediation deadline.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CISO Talk by James Azar is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Operation Endgame delivered the week&#8217;s most significant positive news disrupting Amadey and StealC infrastructure across 326 servers, 142 domains, $47 million in seized cryptocurrency, and 27 million recovered stolen credentials. The DOJ announced the largest healthcare fraud takedown in U.S. history. And the Five Eyes alliance issued a direct warning: AI-accelerated cyber attacks are not a future scenario, they are the present state.</p><blockquote><p>James&#8217;s through-line across all four episodes this week: <em>&#8220;The basics are still the battlefield. Default Fortinet credentials. Unauthenticated Postgres endpoints. OAuth tokens nobody scoped down. None of this is exotic. All of it is preventable.&#8221;</em></p></blockquote><p>Let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YhyX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YhyX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YhyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1101293,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/203760350?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YhyX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!YhyX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd980a5cc-0705-4ea2-a6ea-bc10de168153_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>&#127760; Infrastructure &amp; Network Exploitation</strong></h3><p><strong>Three Ubiquiti UniFi CVSS 10.0 Vulnerabilities: Automated Exploitation, June 26 Federal Deadline</strong></p><p>Three critical Ubiquiti UniFi OS vulnerabilities all carrying perfect CVSS 10.0 scores are now confirmed under active exploitation and added to CISA&#8217;s KEV with a federal remediation deadline of June 26. Bishop Fox demonstrated a complete unauthenticated RCE chain: authentication bypass &#8594; path traversal exposing credentials and configuration files &#8594; command injection granting root-level execution. Researchers are already observing automated scanning creating unauthorized administrator accounts named &#8220;John Sim,&#8221; indicating mass internet exploitation is underway. Patches have been available since May 21. Upgrade to UniFi OS 5.0.8 or later immediately, restrict management interfaces to dedicated administrative VLANs, block external access to UniFi controller ports, and use Bishop Fox&#8217;s published detection tools to identify exposed systems before attackers do.</p><p><strong>Cisco SD-WAN: Seventh Zero-Day &#8212; Mandiant Documents Full Enterprise Compromise</strong></p><blockquote><p><em>&#8220;Seven actively exploited zero-days in a single product line in six months isn&#8217;t bad luck. That&#8217;s structural failure.&#8221;</em></p></blockquote><p>Mandiant published a detailed forensic analysis of a Cisco SD-WAN compromise at a communications provider, documenting exactly how attackers converted multiple vulnerabilities into complete network control over several months. Stage one: authentication bypass to establish administrative access and extract full SD-WAN configuration covering controllers, edge devices, and network architecture. Stage two: command injection via malicious CSV upload through tenant management interface, creating a hidden root account named &#8220;Truth&#8221; and achieving unrestricted management plane control. Once the management plane was owned, attackers could push malicious configurations across every connected branch and edge device. This is the seventh actively exploited Cisco SD-WAN zero-day of 2026. Security teams operating Cisco SD-WAN should treat this as an active incident response, not a routine patch cycle investigate administrator accounts, unauthorized configuration changes, NetConf activity, and unexpected peering relationships now.</p><p><strong>Splunk CVE-2026-20253: First Splunk Vulnerability Added to CISA KEV</strong></p><p>Splunk Enterprise administrators face urgent remediation after CISA added CVE-2026-20253, affecting Splunk&#8217;s PostgreSQL sidecar service to the KEV catalog just days after public disclosure, with public PoC exploit code appearing within 48 hours. The flaw enables unauthenticated arbitrary file operations chainable into full RCE. Splunk often serves as the backbone of enterprise detection and response, a compromise could allow log manipulation, detection disabling, forensic evidence erasure, and environment pivoting. This marks the first time a Splunk vulnerability has been added to CISA&#8217;s KEV. Upgrade to supported versions immediately, review all Splunk activity since June 10, and treat any unpatched internet-accessible instances as potentially compromised.</p><p><strong>Cisco Unified Communications Manager CVE-2026-20230: Active Exploitation, Patch Available Three Weeks</strong></p><p>Cisco warned that CVE-2026-20230, a CVSS 8.6 SSRF vulnerability in the Unified Communications Manager Web Dialer component, is under active exploitation, despite a patch being available since June 3rd. Unauthenticated attackers can write arbitrary files to the OS through crafted HTTP requests, then escalate to root-level control. Attackers can obtain required hostname information directly from the system before exploitation, significantly lowering the barrier. Reconnaissance and test-file-creation activity is already observed. CUCM is deployed across enterprise voice, collaboration, and call center environments globally. If you haven&#8217;t patched yet, you are operating on borrowed time. Patch immediately and audit all internet-facing Web Dialer deployments.</p><p><strong>NGINX Critical Vulnerabilities: HTTP/3 Memory Corruption and Heap Buffer Overflow</strong></p><p>F5 released patches for two critical NGINX vulnerabilities (both CVSS 9.2), an HTTP/3 processing memory corruption flaw and a heap-based buffer overflow in proxy and gRPC modules under specific configurations. Both are remotely exploitable without authentication and may enable RCE. NGINX underpins a significant percentage of internet-facing applications, APIs, and cloud-native services. Patch immediately and disable HTTP/3 functionality where updates cannot be deployed quickly.</p><p><strong>Lantronix EDS5000 Added to CISA KEV: Legacy OT Bridge Devices</strong></p><p>A critical command injection vulnerability in Lantronix EDS5000 Serial-to-Ethernet servers was added to CISA&#8217;s KEV. These devices frequently bridge legacy industrial equipment into modern IP networks, creating OT exposure pathways. Update firmware immediately and isolate management interfaces.</p><p><strong>SolarWinds Serv-U CISA KEV: June 19 Federal Deadline</strong></p><p>SolarWinds Serv-U FTP software remains in the KEV with a June 19 federal deadline. Upgrade to version 15.5.4 Hotfix 1 and verify all internet-facing deployments are fully updated.</p><h3><strong>&#128293; Credential Exposure &amp; Authentication Failures</strong></h3><blockquote><p><em>&#8220;The basics are still the battlefield. Default Fortinet credentials. Unauthenticated Postgres endpoints. OAuth tokens nobody scoped down. None of this is exotic. All of it is preventable. And that&#8217;s the real warning. Patch what you can. Rotate what you should. Audit those third-party integrations. Security is ninety percent hygiene, ten percent fancy rules.&#8221;</em></p></blockquote><p><strong>FortiBleed: 86,644 Fortinet Devices Across 194 Countries &#8212; No New Vulnerability Required</strong></p><p>The FortiBleed campaign expanded dramatically a Russian-speaking threat actor compiled a verified database of 86,644 active Fortinet administrative and SSL VPN credentials across 194 countries, representing roughly half of all internet-facing Fortinet firewalls discoverable through Shodan. The methodology was sophisticated: automated credential stuffing + packet sniffers intercepting VPN authentication hashes in transit + dedicated 45-GPU password-cracking infrastructure recycling recovered credentials. The most alarming finding from Hudson Rock: many recovered passwords exceeded 25 characters and fully complied with complexity requirements. They were not cracked. They were harvested directly from infostealer logs. Password complexity does not protect credentials that have already been stolen. Rotate all Fortinet administrative and VPN credentials immediately, remove all default and generic administrator accounts, verify migration to stronger password hashing mechanisms, enforce phishing-resistant MFA on all internet-facing management interfaces, and rotate any Active Directory credentials potentially associated with perimeter devices.</p><p><strong>Scattered Spider Members Plead Guilty: Transport for London, &#163;39M Recovery Cost</strong></p><p>Two Scattered Spider members 20-year-old Tahala Jubair and 18-year-old Owen Flowers pleaded guilty to conspiracy charges related to the Transport for London attack. The breach forced password resets for 28,000 employees, exposed Oyster card refund data for approximately 10 million customers, and generated recovery costs estimated at &#163;29&#8211;39 million. Evidence included screenshots showing active system access and video recordings of portions of the intrusion. The demographics continue to be remarkable: Scattered Spider repeatedly demonstrates that some of the most damaging global cyberattacks are conducted by teenagers. Authorities estimate approximately one in five UK children aged 10&#8211;16 has engaged in activities technically violating computer misuse laws. The next generation of cybercrime talent is already forming.</p><h3><strong>&#129516; Supply Chain &amp; Third-Party Trust</strong></h3><p><strong>Klue/Icarus Supply Chain Campaign: LastPass, HackerOne, Huntress, Recorded Future, Tanium, Snyk, and More</strong></p><p>The Klue supply chain breach escalated into one of the most significant SaaS-based compromises of 2026. The initial compromise originated from a credential issued to a third party during a limited pilot project in 2022, left active for four years after the pilot ended. Attackers used the dormant credential to access Klue&#8217;s infrastructure, steal OAuth tokens connected to Salesforce and Gong, and pivot into customer environments extracting CRM data, business intelligence, pricing information, opportunity notes, and sales strategies. The Icarus extortion group has now claimed victims including HackerOne, Huntress, Recorded Future, Tanium, Snyk, Jamf, OneTrust, Gong, Sprout Social, and LastPass. LastPass confirmed attackers accessed customer contact information, phone numbers, email addresses, physical addresses, and support case information stored in Salesforce password vaults were not compromised, but the stolen contextual intelligence enables precision phishing, executive impersonation, and social engineering campaigns. This is the third major Salesforce OAuth supply chain attack in less than a year. Audit every Salesforce connected application and OAuth permission, remove any integration your team cannot explain the current business purpose of, and rotate all tokens associated with Klue integrations.</p><p><strong>North Korean npm Supply Chain: 60+ Packages Targeting Developer Credentials</strong></p><p>Microsoft attributed a supply chain attack involving more than 60 npm packages to North Korean threat actors in the Sapphire Sleet cluster targeting developer credentials and cryptocurrency wallets through typosquatted dependencies. Review development environments and dependency trees immediately.</p><p><strong>GentleKiller EDR-Killing Framework: 400+ Security Processes Across 48 Vendors</strong></p><p>Researchers identified GentleKiller, an EDR-killing framework used by the Gentleman ransomware operation. The malware disables more than 400 security processes across 48 vendors using vulnerable signed drivers in classic bring-your-own-vulnerable-driver attacks. Enable Microsoft&#8217;s vulnerable driver block list and implement strict driver allow-listing controls.</p><p><strong>Joomla JCE Editor and LiteSpeed Under Active Exploitation</strong></p><p>Attackers are actively exploiting critical vulnerabilities in Joomla&#8217;s JCE Editor and LiteSpeed cPanel plugins enabling RCE and privilege escalation. Patch immediately.</p><p><strong><a href="http://polyfill.io/">Polyfill.io</a> Resurfacing on Toshiba, Muji, Samsung Smart TV Sites</strong></p><p>The compromised <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> JavaScript CDN continues resurfacing on websites associated with major brands. Remove all remaining <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> references from web properties.</p><h3><strong>&#129302; AI Security &amp; Development Ecosystem</strong></h3><p><strong>Five Eyes Advisory: AI-Powered Cyberattacks Are Present State, Not Future Scenario</strong></p><p>The Five Eyes intelligence alliance; U.S., UK, Australia, Canada, and New Zealand issued a joint advisory stating that AI is already being used offensively and that frontier models will soon accelerate vulnerability discovery, exploitation development, reconnaissance, and attack automation at unprecedented speed. Unlike previous theoretical warnings, this advisory is direct: the organizations struggling with basic cybersecurity today will be the least prepared for AI-accelerated attacks. The advisory recommended five foundational focus areas: reduce attack surface exposure, accelerate patch management, eliminate unsupported legacy systems, strengthen identity controls, and regularly test incident response capabilities. The timing coincides with a reported 400% increase in cyber activity targeting satellite operators following geopolitical tensions. The message: prepare now or face disproportionate impact later.</p><p><strong>Trump Signs Post-Quantum Cryptography Executive Order</strong></p><p>President Trump signed Executive Order 14409 establishing federal deadlines for post-quantum cryptography migration: high-value federal systems must adopt quantum-resistant key establishment by December 31, 2030, and quantum-resistant digital signatures by December 31, 2031. Federal contractors will face similar expectations. Begin post-quantum cryptography inventory and planning immediately.</p><p><strong>Atomic macOS Stealer Expands ClickFix Campaigns Against Mac Users</strong></p><p>A new ClickFix campaign targets macOS users victims are tricked into opening Terminal and executing malicious commands installing the Atomic macOS Stealer, which targets browsers, cryptocurrency wallets, Apple Keychain, Telegram, Discord, and hardware wallet software. No legitimate website should ever instruct users to paste commands into Terminal or PowerShell. Train users on this specific social engineering pattern.</p><p><strong>OpenAI Daybreak Cybersecurity Initiative Expands</strong></p><p>OpenAI announced major updates to its Daybreak cybersecurity initiative through partnerships with HackerOne and Trail of Bits, focusing on patch deployment and open-source software security acceleration.</p><p><strong>OpenAI Custom AI Inference Chip &#8220;Jalape&#241;o&#8221; Introduced</strong></p><p>OpenAI unveiled its first internally designed inference processor built on TSMC&#8217;s 3-nanometer process. Custom AI silicon introduces new supply chain considerations for organizations evaluating AI infrastructure security.</p><p><strong>Anthropic Mythos Expands to 150 Organizations Including NATO</strong></p><p>Anthropic&#8217;s Project Glasswing added 150 organizations across 15 countries including NATO, ENISA, Samsung, healthcare providers, utilities, and critical infrastructure operators to the Mythos vulnerability discovery platform. AI-assisted vulnerability discovery is becoming a strategic defensive advantage.</p><h3><strong>&#128275; Data Breaches &amp; Identity Exposures</strong></h3><p><strong>Tata Electronics Breach: Apple and Tesla Supply Chain Intelligence Stolen</strong></p><p>Tata Electronics confirmed a breach by the WorldLeaks ransomware group allegedly stealing more than 630 gigabytes including Apple supplier documentation, Tesla manufacturing records, internal SAP data, corporate email communications, and operational engineering information. Tata assembles Apple products, supplies semiconductor components, and supports Tesla operations. As manufacturing ecosystems become more strategically important as part of China diversification strategies, they become more attractive cyber targets. Supply chain security now extends from software code to semiconductor fabrication and physical product assembly.</p><p><strong>Texas Parks and Wildlife: Three Million Records via Third-Party Vendor</strong></p><p>A third-party vendor supporting Texas Parks and Wildlife disclosed a breach exposing driver&#8217;s license numbers, passport information, email addresses, phone numbers, and physical addresses for more than three million individuals. The affected vendor has not yet been publicly identified, reinforcing ongoing third-party risk management challenges.</p><p><strong>iPhone Unpatchable BootROM Exploit: USBlitter-V8 Targeting A12/A13 Chipsets</strong></p><p>Paradigm Shift disclosed USBlitter-V8, a BootROM exploit targeting Apple&#8217;s SecureROM in A12 and A13 chipsets including iPhone XS, XR, and iPhone 11 lines and Apple cannot patch it, as the flaw resides in immutable silicon. Physical access and specialized hardware are required, limiting widespread exploitation. However, this represents a hardware lifecycle issue: devices approaching a decade in service carry risks that software updates can no longer address. Hardware refresh timelines matter as a security control.</p><p><strong>Oxford Career Connect: Second Breach This Year</strong></p><p>Oxford&#8217;s Career Connect platform suffered its second successful compromise of 2026, exposing student records, email addresses, degree information, and employment application history enabling highly targeted job-related phishing.</p><h3><strong>&#9878;&#65039; Law Enforcement, Policy &amp; Industry</strong></h3><p><strong>Operation Endgame: Amadey and StealC Infrastructure Dismantled</strong></p><p>International law enforcement, Europol, Microsoft, IBM X-Force, and Proofpoint dismantled infrastructure supporting the Amadey loader and StealC infostealer, disrupting 326 servers, seizing 142 malicious domains, identifying $47 million in criminal cryptocurrency assets, and recovering approximately 27 million stolen credentials from 385,000+ compromised systems. Microsoft&#8217;s Digital Crimes Unit used AI-assisted analysis to connect shared infrastructure, while Proofpoint and IBM X-Force identified weaknesses within the StealC C2 platform that law enforcement leveraged during the takedown. Operation Endgame&#8217;s strategy of targeting cybercrime infrastructure rather than individual actors is producing measurable, compounding results.</p><p><strong>SocGholish Infrastructure Disrupted: 106 Servers Seized, 15,000 WordPress Sites Remediated</strong></p><p>Authorities from the U.S., Canada, Germany, and Netherlands seized 106 servers and remediated nearly 15,000 compromised WordPress websites associated with SocGholish a major initial access broker feeding Evil Corp and RansomHub operations. Portions of the infrastructure are expected to reemerge.</p><p><strong>DOJ Healthcare Fraud Takedown: $6.5 Billion, 455 Defendants</strong></p><p>The DOJ announced charges against 455 defendants across 56 federal districts for more than $6.5 billion in fraudulent Medicare and Medicaid claims with $182 million in assets seized. Patient data breaches do not simply create privacy risks, they become raw material for organized financial crime at scale.</p><p><strong>DraftKings Credential Stuffing: 18-Month Prison Sentence</strong></p><p>A Minnesota man received an 18-month prison sentence for participating in the 2022 DraftKings credential stuffing campaign that compromised approximately 60,000 accounts and stole $600,000. Reinforces growing federal enforcement against credential stuffing fueled by breached password databases.</p><p><strong>International Cybercrime Marketplace Operator Extradited to U.S.</strong></p><p>Spanish authorities extradited Algerian national Abdullah Balami to the U.S. &#8212; accused of operating Market Zero Day and Spoxy cybercrime marketplaces facilitating stolen credentials, exploits, and cybercrime services.</p><p><strong>Google Workspace Passkey Mandatory Migration: September 30 Deadline</strong></p><p>Google announced all Workspace administrator accounts must transition to passkey-based authentication by September 30. Begin migration planning immediately to avoid last-minute operational challenges.</p><p><strong>Massachusetts Consumer Data Privacy Act Passes Unanimously</strong></p><p>Massachusetts unanimously passed the MCDPA with restrictions on geolocation tracking, biometric data collection, data minimization, and private rights of action. Assess compliance exposure for organizations with Massachusetts operations.</p><p><strong>UK NCSC: 200+ Critical Infrastructure Incidents, 75% Nation-State Linked</strong></p><p>The UK&#8217;s NCSC reported handling more than 200 critical infrastructure incidents over the past year, with approximately 75% linked to Russia, China, and Iran. Officials warned AI will accelerate vulnerability exploitation by 2028.</p><p><strong>Accenture Acquires Dragos, RunZero, and NetRise in $4.1B OT Security Expansion</strong></p><p>Accenture announced a $4.1 billion transaction combining a Dragos majority stake with RunZero and NetRise acquisitions. The deal signals growing institutional demand for integrated OT security as industrial environments face increasing cyber threats.</p><p><strong><a href="http://whynopasskeys.com/">WhyNoPasskeys.com</a> Launched by Scott Helme and Troy Hunt</strong></p><p>Security researchers launched <strong><a href="http://whynopasskeys.com/">WhyNoPasskeys.com</a></strong> highlighting major consumer platforms still not supporting passkey authentication, calling attention to password-only services that remain vulnerable to credential stuffing and phishing.</p><h3><strong>&#9989; This Week&#8217;s Priority Action List</strong></h3><p><strong>Immediate (Do This Now)</strong></p><ul><li><p>Upgrade Ubiquiti UniFi OS to 5.0.8 or later &#8212; CVSS 10.0 x3, CISA KEV June 26 federal deadline, mass automated exploitation confirmed with &#8220;John Sim&#8221; unauthorized admin accounts being created</p></li><li><p>Patch Cisco Unified Communications Manager CVE-2026-20230 immediately &#8212; patch available three weeks, active exploitation underway, recon activity already observed</p></li><li><p>Rotate all Fortinet administrative and VPN credentials without exception &#8212; 86,644 devices exposed, many via infostealer logs, complexity requirements are irrelevant if credentials are already stolen</p></li><li><p>Upgrade Splunk Enterprise &#8212; first Splunk KEV addition, public PoC within 48 hours, review all activity since June 10</p></li><li><p>Treat Cisco SD-WAN as active incident response &#8212; audit all admin accounts, investigate unauthorized configuration changes, NetConf activity, and unexpected peering relationships</p></li><li><p>Patch NGINX Open Source and NGINX Plus &#8212; CVSS 9.2, HTTP/3 memory corruption and heap buffer overflow, disable HTTP/3 where patches cannot be deployed immediately</p></li><li><p>Audit every Salesforce connected application and OAuth permission &#8212; revoke any the team cannot explain current business purpose for; rotate all tokens associated with Klue integrations</p></li><li><p>Remove all default and generic Fortinet administrator accounts and verify migration to current password hashing mechanisms</p></li><li><p>Patch Joomla JCE Editor and LiteSpeed environments under active exploitation</p></li><li><p>Update Lantronix EDS5000 firmware and isolate management interfaces &#8212; CISA KEV</p></li></ul><p><strong>Short-Term (This Month)</strong></p><ul><li><p>Enforce phishing-resistant MFA on all internet-facing management interfaces &#8212; Fortinet, Cisco, Splunk, and all perimeter devices</p></li><li><p>Restrict UniFi management interfaces to dedicated administrative VLANs with no internet exposure</p></li><li><p>Review all temporary vendor credentials and pilot program accounts &#8212; Klue breach traced to a four-year-old forgotten credential</p></li><li><p>Rotate dormant API keys and OAuth tokens across all SaaS integrations</p></li><li><p>Alert executives and customer-facing teams to phishing risks from Klue/Icarus breach &#8212; LastPass contact data and sales intelligence are in attacker hands</p></li><li><p>Audit npm dependencies for North Korean typosquatted packages &#8212; 60+ packages attributed to Sapphire Sleet</p></li><li><p>Enable Microsoft&#8217;s vulnerable driver block list &#8212; GentleKiller EDR-killing framework targets 400+ security processes across 48 vendors</p></li><li><p>Train users on ClickFix / Terminal-based social engineering &#8212; Atomic macOS Stealer is expanding</p></li><li><p>Remove all <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> references from web properties</p></li><li><p>Begin planning Google Workspace administrator passkey migration for September 30 deadline</p></li></ul><p><strong>Strategic (This Quarter)</strong></p><ul><li><p>Begin post-quantum cryptography inventory within the next 90 days &#8212; EO 14409 sets December 31, 2030 federal deadline for quantum-resistant key establishment</p></li><li><p>Assess hardware refresh timelines for older Apple A12/A13 devices &#8212; BootROM exploit is unpatchable through software</p></li><li><p>Develop third-party credential lifecycle management processes &#8212; Klue/Icarus and FortiBleed both trace to governance failures around stale credentials</p></li><li><p>Implement management plane segmentation across all network infrastructure &#8212; Cisco SD-WAN Mandiant analysis is the operational case study</p></li><li><p>Assess compliance exposure for Massachusetts Consumer Data Privacy Act</p></li><li><p>Train employees at all levels on Five Eyes AI advisory recommendations &#8212; reduce attack surface, patch faster, eliminate legacy systems, strengthen identity, test IR</p></li></ul><h3><strong>&#127897;&#65039; James Azar&#8217;s CISO&#8217;s Take</strong></h3><p>When I look across this week&#8217;s four episodes, the most consistent story is that attackers keep succeeding through problems we already know how to solve. FortiBleed wasn&#8217;t powered by a new exploit it was powered by default credentials and stale accounts. The Klue breach didn&#8217;t start with a sophisticated attack chain it started with a vendor offboarding process that never happened. Cisco CUCM is being exploited despite a patch available for three weeks. Ubiquiti UniFi systems with perfect-10 CVSS scores are being mass-scanned by automated tools. None of these failures require advanced adversary capabilities to exploit. They require only that defenders continue to deprioritize hygiene in favor of the next security tool on the evaluation list. The fundamentals are not optional. They are the floor. And right now, too many organizations are operating below it.</p><p>The second takeaway is structural: the attack surface has expanded permanently into third-party integrations, credential ecosystems, manufacturing supply chains, and hardware trust anchors in ways most security programs have not fully internalized. The Icarus/Klue cascade hitting LastPass, HackerOne, Huntress, and Recorded Future simultaneously demonstrates that one forgotten pilot-project credential can become a weapon against dozens of downstream organizations. The Five Eyes are not issuing theoretical warnings about AI-accelerated threats anymore, they are describing the present operational environment. The organizations that treat the fundamentals as survival requirements rather than aspirational best practices are the ones that will still be standing when AI compression of attack timelines becomes fully operational at scale.</p><p><strong>Stay Cyber Safe.</strong> &#128272;</p><h3><strong>&#128203; Week in Summary</strong></h3><p>This was the week the fundamentals asserted themselves as the defining variable in cybersecurity &#8212; not zero-days, not nation-state sophistication, not AI tools. The FortiBleed campaign compiled 86,644 valid credentials without exploiting a single new vulnerability. The Klue/Icarus cascade that compromised LastPass, HackerOne, Huntress, and Recorded Future began with a four-year-old forgotten pilot credential. Splunk made the CISA KEV for the first time with a vulnerability that received public PoC code within 48 hours of disclosure. Cisco CUCM is being actively exploited three weeks after a patch was available. And Ubiquiti UniFi systems with perfect-10 CVSS scores are being automatically scanned and compromised at internet scale with a federal remediation deadline of June 26.</p><p>Against that backdrop, Operation Endgame delivered one of the most significant positive enforcement outcomes of the year recovering 27 million stolen credentials, disrupting 326 servers, and seizing $47 million in criminal assets by targeting cybercrime infrastructure rather than individual actors. The Five Eyes issued their most direct AI cybersecurity warning to date. The Trump administration established federal post-quantum cryptography deadlines. And the DOJ announced the largest healthcare fraud takedown in U.S. history. Progress is real. But it remains outpaced by the volume of preventable failures that attackers continue to exploit with remarkable efficiency. The organizations that will navigate what is coming AI-accelerated exploitation, quantum cryptographic risks, cascading supply chain trust failures are the ones building their security programs on a foundation of executed fundamentals today.</p><p>Stay informed. Stay prepared. <strong>Stay Cyber Safe.</strong> &#128272;</p><p><em>&#169; CyberHub Podcast | Subscribe on Substack | Watch on YouTube | Follow on LinkedIn</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CISO Talk by James Azar is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Microsoft and Europol Smash Amadey and StealC Infrastructure in Operation Endgame, Mandiant Reveals How Cisco SD-WAN Zero-Day Created Rogue Root Accounts at Service Provider ]]></title><description><![CDATA[Why the next major breach will likely begin at the network edge, not the endpoint and what defenders must do to stay ahead.]]></description><link>https://www.cyberhubpodcast.com/p/microsoft-and-europol-smash-amadey</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/microsoft-and-europol-smash-amadey</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Thu, 25 Jun 2026 13:30:24 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203504321/d4488f68494c6e0f13867ab0b4c17b27.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s headlines were dominated by attacks against the network edge. Three critical Ubiquiti UniFi vulnerabilities with perfect CVSS scores are now being actively exploited just days before the federal remediation deadline. Mandiant released a detailed forensic analysis showing exactly how attackers compromised Cisco Catalyst SD-WAN environments and escalated to root access across enterprise management planes. Meanwhile, Operation Endgame delivered one of the largest coordinated law enforcement victories against the cybercrime ecosystem, dismantling hundreds of servers supporting the Amadey and StealC malware operations.</p><p>We also saw the Department of Justice announce the largest healthcare fraud takedown in U.S. history, highlighting how cybercrime, stolen identities, and financial fraud continue to converge.</p><p>The message throughout today&#8217;s show was clear: <strong>if attackers control your infrastructure, they control your business.</strong></p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s cybersecurity landscape focused almost entirely on infrastructure resilience.</p><p>Attackers continue concentrating their efforts against network edge devices, management platforms, and identity infrastructure because those systems provide the fastest route to enterprise-wide compromise. Cisco, Ubiquiti, and legacy industrial communication systems all demonstrated how weaknesses in centralized management platforms create disproportionate organizational risk.</p><p>On the positive side, Operation Endgame continues producing measurable disruption against cybercriminal ecosystems by targeting not individual threat actors, but the infrastructure enabling ransomware, credential theft, and malware-as-a-service operations.</p><p>The battle is increasingly shifting away from individual malware campaigns and toward dismantling the infrastructure that allows cybercrime to scale globally.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GcPl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GcPl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GcPl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:178617,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/203504321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GcPl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!GcPl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565c21b1-5b8d-4c98-82e1-4c33a56a1b8a_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128680; Three Critical Ubiquiti UniFi Vulnerabilities Now Under Active Exploitation</h2><p>The most urgent story today involves three critical vulnerabilities affecting Ubiquiti UniFi OS, all carrying perfect <strong>CVSS 10.0</strong> severity ratings and all now confirmed to be under active exploitation after their inclusion in CISA&#8217;s Known Exploited Vulnerabilities catalog. Federal agencies face a remediation deadline of <strong>June 26</strong>, underscoring the urgency of the situation.</p><p>Researchers at Bishop Fox demonstrated that the vulnerabilities can be chained together into a complete unauthenticated remote code execution attack. The exploit sequence begins with an authentication bypass, followed by a path traversal vulnerability that exposes sensitive configuration files and credentials, and concludes with a command injection flaw that grants full root-level execution on vulnerable systems.</p><p>Threat researchers have already observed automated attacks creating unauthorized administrator accounts named <strong>&#8220;John Sim,&#8221;</strong> suggesting mass internet scanning is well underway.</p><p>UniFi devices are widely deployed across enterprise campuses, branch offices, SMBs, and home office environments. That broad deployment significantly expands the potential attack surface.</p><p>The patches have been available since May 21, yet many organizations remain exposed. If UniFi management interfaces are still internet accessible, the opportunity for attackers is substantial.</p><p>Organizations should immediately upgrade to UniFi OS version <strong>5.0.8 or later</strong>, restrict management interfaces to dedicated administrative networks, block external access to UniFi controller ports, and leverage Bishop Fox&#8217;s published detection tools to identify vulnerable systems before attackers do.</p><h2>&#9888;&#65039; Mandiant Reveals How Cisco SD-WAN Zero-Day Became Full Enterprise Compromise</h2><p>Mandiant published one of the most detailed forensic analyses of a Cisco SD-WAN compromise to date, documenting exactly how attackers transformed multiple vulnerabilities into complete control of a communications provider&#8217;s network infrastructure.</p><blockquote><p><em><strong>&#8220;Seven actively exploited zero-days in a single product line in six months isn&#8217;t bad luck. That&#8217;s structural failure.&#8221; James Azar</strong></em></p></blockquote><p>The attack unfolded in multiple stages over several months. Threat actors first exploited authentication bypass vulnerabilities to establish administrative access, quietly changed default administrator passwords to avoid detection, and extracted SD-WAN configuration data covering controllers, edge devices, templates, and network architecture.</p><p>Months later, they leveraged a newly discovered command injection vulnerability by uploading a malicious CSV file through Cisco&#8217;s tenant management interface. That payload created a hidden root account named <strong>&#8220;Truth,&#8221;</strong> allowing attackers to obtain unrestricted administrative control over the SD-WAN management plane.</p><p>With management plane access established, attackers gained the ability to push malicious configurations across every connected branch office and edge device managed by the platform.</p><p>Perhaps the most concerning aspect of the investigation is the trend itself.</p><p>This represents the <strong>seventh actively exploited Cisco SD-WAN zero-day disclosed during 2026.</strong></p><p>At some point, organizations must ask whether repeated vulnerabilities within the same product family represent isolated software defects&#8212;or deeper architectural challenges.</p><p>Security teams operating Cisco SD-WAN environments should approach this as an active incident response effort rather than a routine patch cycle. Administrator accounts, unauthorized configuration changes, NetConf activity, and unexpected peering relationships all warrant immediate investigation.</p><h2>&#127757; Operation Endgame Strikes the Amadey and StealC Malware Ecosystem</h2><p>International law enforcement agencies, Europol, Microsoft, IBM X-Force, Proofpoint, and numerous private-sector partners announced another major success under <strong>Operation Endgame</strong>, dismantling infrastructure supporting the Amadey loader and StealC information-stealing malware.</p><p>The scale of the operation is remarkable.</p><p>Authorities disrupted <strong>326 servers</strong>, seized <strong>142 malicious domains</strong>, identified more than <strong>$47 million</strong> in criminal cryptocurrency assets, and recovered approximately <strong>27 million stolen credentials</strong> harvested from over <strong>385,000 compromised systems</strong> worldwide.</p><blockquote><p><em>&#8220;The cybercrime supply chain only works because the infrastructure behind it keeps operating. Break the infrastructure, and you break the business model.&#8221; James Azar</em></p></blockquote><p>The operation targeted an entire cybercrime business model rather than a single malware family.</p><p>Amadey functioned as an initial access platform, delivering secondary malware such as ransomware and remote access trojans. StealC then harvested browser credentials, session cookies, cryptocurrency wallets, messaging data, and authentication tokens that were sold to other criminal organizations or used to facilitate enterprise intrusions.</p><p>Microsoft&#8217;s Digital Crimes Unit even employed AI-assisted analysis to connect infrastructure shared between both malware families, while Proofpoint and IBM X-Force identified weaknesses within the StealC command-and-control platform itself that law enforcement ultimately leveraged during the takedown.</p><p>Rather than arresting individual operators, Operation Endgame continues attacking the infrastructure that makes cybercrime profitable.</p><p>That strategy appears to be producing meaningful results.</p><h2>&#127973; DOJ Announces Largest Healthcare Fraud Takedown in U.S. History</h2><p>The Department of Justice announced charges against <strong>455 defendants</strong> across <strong>56 federal districts</strong>, involving more than <strong>$6.5 billion</strong> in fraudulent Medicare and Medicaid claims. Authorities also seized approximately <strong>$182 million</strong> in assets connected to the schemes.</p><p>While primarily a financial crime story, the cybersecurity implications are significant.</p><p>Large-scale healthcare fraud increasingly depends upon compromised provider credentials, stolen patient identities, fraudulent billing systems, and automated digital infrastructure capable of processing enormous volumes of false claims.</p><p>Investigators highlighted the role of AI, cloud computing, and advanced analytics in identifying suspicious billing activity before payments were issued. Several defendants were arrested overseas, reflecting the increasingly international nature of healthcare fraud operations.</p><p>This case reinforces an important reality for healthcare security teams.</p><p>Patient data breaches do not simply create privacy risks.</p><p>They frequently become the raw material fueling organized financial crime.</p><h1>&#9889; Need to Know</h1><h3>&#128421;&#65039; Lantronix EDS5000 Vulnerability Carries Critical Risk</h3><p>A critical command injection vulnerability affecting Lantronix EDS5000 Serial-to-Ethernet servers is now included in CISA&#8217;s Known Exploited Vulnerabilities catalog. These systems frequently bridge legacy industrial equipment into modern IP networks, making them particularly important within operational technology environments. Organizations should update firmware immediately and isolate management interfaces wherever possible.</p><h3>&#127822; Atomic macOS Stealer Expands ClickFix Campaigns</h3><p>Researchers uncovered a new ClickFix campaign targeting macOS users with Atomic macOS Stealer. Victims are tricked into opening Terminal and executing malicious commands that install credential-stealing malware targeting browsers, cryptocurrency wallets, Apple Keychain, Telegram, and Discord. No legitimate website should ever instruct users to paste commands into Terminal.</p><h3>&#128272; Passkeys Still Lag Across Major Platforms</h3><p>Security researchers Scott Helme and Troy Hunt launched <strong>WhyNoPasskeys.com</strong>, highlighting major online services that still do not support passkey authentication. Despite growing adoption by Apple, Google, and Microsoft, several high-profile consumer platforms continue relying exclusively on passwords.</p><h3>&#129302; OpenAI Introduces Custom AI Inference Chip</h3><p>OpenAI unveiled its first internally designed inference processor, codenamed <strong>Jalape&#241;o</strong>, built using TSMC&#8217;s 3-nanometer manufacturing process. While primarily a business development story, custom AI silicon introduces new supply chain considerations for organizations evaluating AI infrastructure security.</p><h3>&#128646; German Rail Outage Traced to Equipment Failure</h3><p>Germany&#8217;s national rail communications network experienced a nationwide outage caused by failure during replacement of a GSM-R communications component. Authorities confirmed the incident was <strong>not</strong> the result of a cyberattack, although the disruption renewed attention on aging communications infrastructure supporting critical services.</p><h3>&#127919; DraftKings Credential Stuffing Case Ends in Prison Sentences</h3><p>A Minnesota man received an 18-month prison sentence for participating in the 2022 DraftKings credential stuffing campaign that compromised approximately 60,000 user accounts and stole roughly $600,000. The case reinforces growing federal enforcement against credential stuffing operations fueled by breached password databases.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s show wasn&#8217;t about malware.</p><p>It wasn&#8217;t about ransomware.</p><p>It was about infrastructure.</p><p>The routers.<br>The controllers.<br>The management planes.<br>The edge devices.<br>The systems responsible for connecting everything else.</p><p>When attackers compromise infrastructure, every downstream security control becomes less effective.</p><p>Protecting the management plane is no longer simply an operational best practice.</p><p>It&#8217;s one of the most important cybersecurity priorities organizations have.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is that nearly every major story revolved around infrastructure rather than endpoints. The UniFi vulnerabilities demonstrate how quickly attackers automate exploitation once proof-of-concept code becomes available. The Cisco SD-WAN investigation showed that management platforms remain among the highest-value targets in enterprise environments because they provide centralized control over hundreds or even thousands of devices. If an attacker owns your management plane, they&#8217;ve effectively inherited your network.</p><p>The second lesson is that we should pay close attention to what Operation Endgame is accomplishing. For years we&#8217;ve measured success by arrests, but today&#8217;s operation reminds us that dismantling cybercrime infrastructure often delivers greater long-term impact. Recovering millions of stolen credentials, disrupting malware distribution, and removing command-and-control servers directly raises operational costs for cybercriminals. Defenders need to adopt the same mindset internally focus less on reacting to individual attacks and more on eliminating the infrastructure weaknesses that allow attacks to succeed repeatedly.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch UniFi OS to version <strong>5.0.8 or later</strong> immediately</p></li><li><p>Restrict UniFi management interfaces to dedicated administrative VLANs</p></li><li><p>Use Bishop Fox detection tools to identify exposed UniFi deployments</p></li><li><p>Treat Cisco SD-WAN environments as active incident response investigations</p></li><li><p>Audit privileged NetAdmin accounts across SD-WAN infrastructure</p></li><li><p>Review configuration changes and unauthorized peering activity</p></li><li><p>Update Lantronix EDS5000 firmware where deployed</p></li><li><p>Train users to recognize ClickFix and Terminal-based social engineering</p></li><li><p>Review passkey adoption across enterprise applications</p></li><li><p>Rotate credentials recovered from previous breach datasets</p></li><li><p>Assess management plane segmentation for all network infrastructure</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/microsoft-and-europol-smash-amadey?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/microsoft-and-europol-smash-amadey?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/microsoft-and-europol-smash-amadey?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Trump Signs Executive Order Mandating Federal Post-Quantum Cryptography Migration by 2030, Scattered Spider Members Plead Guilty, LastPass Confirms Customer Data Stolen in Klue Breach ]]></title><description><![CDATA[Why forgotten credentials, delayed patching, and unmanaged trust relationships remain cybersecurity's most expensive mistakes.]]></description><link>https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Wed, 24 Jun 2026 13:31:21 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203347189/561e001c7c5947513d54a32adecc7586.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode revolved around a theme that the cybersecurity industry knows all too well but still struggles to execute consistently:</p><p><strong>The gap between what we know we should do and what we actually do.</strong></p><p>Today&#8217;s stories weren&#8217;t centered around sophisticated nation-state tradecraft or groundbreaking zero-day discoveries. Instead, they highlighted familiar failures: unpatched systems, forgotten credentials, abandoned vendor integrations, poor access governance, and delayed remediation. A Cisco vulnerability patched three weeks ago is now under active exploitation. The Klue supply chain breach continues expanding, with LastPass becoming the latest confirmed victim. The Five Eyes alliance issued a stark warning that AI-driven cyberattacks are arriving faster than most organizations are prepared for. Meanwhile, members of the notorious Scattered Spider group pleaded guilty in connection with one of the most disruptive attacks in the United Kingdom&#8217;s recent history.</p><p>The lesson is straightforward. The fundamentals still determine outcomes.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape revealed a recurring pattern.</p><p>Organizations continue suffering significant incidents not because they lack security tools, but because known risks remain unresolved long after they&#8217;ve been identified. Whether it&#8217;s Cisco systems left unpatched for weeks, OAuth credentials surviving years after pilot projects end, or identity controls failing to keep pace with modern threats, attackers continue finding success through operational gaps rather than technical brilliance.</p><p>At the same time, governments are beginning to prepare for the next era of cybersecurity. The Five Eyes alliance warned that AI will dramatically accelerate offensive cyber operations, while the United States formally established deadlines for federal post-quantum cryptography adoption.</p><p>The future is arriving quickly.</p><p>The challenge is that many organizations are still struggling with yesterday&#8217;s security problems.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tfEL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tfEL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tfEL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:179394,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/203347189?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tfEL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!tfEL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd374da-7c1b-49b3-bf46-7293aa9119e0_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128680; Cisco Unified Communications Manager Vulnerability Under Active Exploitation</h2><p>Cisco issued an urgent warning that CVE-2026-20230, a high-severity server-side request forgery vulnerability affecting Unified Communications Manager and Unified Communications Manager Session Management Edition, is now being actively exploited in the wild. The vulnerability carries a CVSS score of 8.6 and was originally patched on June 3rd.</p><p>The flaw exists within the Web Dialer component and allows unauthenticated attackers to write arbitrary files to the underlying operating system through crafted HTTP requests. Once file write access is achieved, attackers can escalate privileges and gain root-level control of the server.</p><p>Researchers demonstrated that attackers can obtain required hostname information directly from the system before exploitation begins, significantly lowering the barrier to entry. Threat intelligence firms have already observed reconnaissance activity, including attempts to create test files designed to identify vulnerable targets.</p><p>What makes this story notable is not the vulnerability itself.</p><p>It&#8217;s the timing.</p><p>Organizations have had access to a patch for more than three weeks, yet attackers are still finding enough vulnerable systems to justify active exploitation campaigns. Given how widely Cisco Unified Communications Manager is deployed across enterprise voice, collaboration, and call center environments, the potential impact is significant.</p><p>If you&#8217;re running CUCM and haven&#8217;t patched yet, you&#8217;re operating on borrowed time.</p><h2>&#128279; Klue Supply Chain Breach Expands as LastPass Becomes Latest Victim</h2><p>The Klue supply chain incident continues to evolve into one of the most significant SaaS-based breaches of 2026. New details reveal that the initial compromise originated from a credential issued to a third party during a limited pilot project in 2022. The credential remained active for four years after the pilot ended and ultimately became the entry point for attackers.</p><p>Attackers used the dormant credential to access Klue&#8217;s infrastructure, steal OAuth tokens connected to Salesforce and Gong environments, and pivot into customer systems where they extracted sensitive CRM data.</p><p>Today&#8217;s major development is the confirmation that LastPass was among the impacted organizations.</p><blockquote><p><em>&#8220;The Klue breach didn&#8217;t start with Icarus. It started with a vendor offboarding process that never actually happened.&#8221; James Azar</em></p></blockquote><p>According to LastPass, attackers accessed customer contact information, phone numbers, email addresses, physical addresses, support case information, and sales-related records stored within Salesforce. The company emphasized that password vaults were not compromised.</p><p>However, that distinction may provide little comfort to affected customers.</p><p>The stolen information provides attackers with exactly the type of contextual intelligence needed to launch highly targeted phishing campaigns, executive impersonation attacks, and sophisticated social engineering operations.</p><p>This incident marks the third major Salesforce OAuth-focused supply chain attack in less than a year.</p><p>At some point, the issue is no longer the attackers.</p><p>It&#8217;s the industry&#8217;s inability to properly govern third-party trust relationships.</p><h2>&#9878;&#65039; Scattered Spider Members Plead Guilty in Transport for London Attack</h2><p>Two members of the notorious Scattered Spider cybercrime collective pleaded guilty on the opening day of their trial in the United Kingdom. Twenty-year-old Tahala Jubair and eighteen-year-old Owen Flowers admitted to conspiracy charges related to the cyberattack against Transport for London.</p><p>The attack caused widespread operational disruption, forced password resets for approximately 28,000 employees, exposed Oyster card refund data affecting roughly 10 million customers, and generated recovery costs estimated between &#163;29 million and &#163;39 million.</p><p>The evidence against the pair was substantial. Investigators recovered screenshots showing active access to Transport for London systems along with video recordings documenting portions of the intrusion.</p><p>The broader significance of this case lies in the demographics.</p><p>Scattered Spider continues to demonstrate that some of the most damaging cyberattacks globally are being conducted by individuals barely old enough to vote. Previous arrests and convictions have already impacted several core members of the group, including Tyler Buchanan and Noah Urban.</p><p>Yet despite these arrests, the pipeline remains active.</p><p>Authorities estimate that approximately one in five children between the ages of 10 and 16 in the United Kingdom have engaged in activities that technically violate computer misuse laws.</p><p>The next generation of cybercrime talent is already forming.</p><p>The question is whether defenders can adapt quickly enough.</p><h2>&#129302; Five Eyes Warns AI-Powered Cyberattacks Are Months Away, Not Years</h2><p>The Five Eyes intelligence alliance, consisting of the United States, United Kingdom, Australia, Canada, and New Zealand, issued a joint advisory warning that advanced AI systems are poised to fundamentally transform the cyber threat landscape.</p><p>Unlike previous warnings that focused on theoretical future risks, this advisory is remarkably direct.</p><blockquote><p><em>&#8220;The Five Eyes aren&#8217;t warning us about a future scenario. They&#8217;re describing the present state.&#8221; James Azar</em></p></blockquote><p>The agencies involved including CISA and the NSA state that AI is already being used offensively and that frontier models will soon accelerate vulnerability discovery, exploitation development, reconnaissance, and attack automation at unprecedented speed.</p><p>The advisory emphasizes that cybersecurity must be treated as a board-level business risk rather than solely an IT responsibility.</p><p>Organizations were urged to focus on five foundational areas:</p><ul><li><p>Reduce attack surface exposure</p></li><li><p>Accelerate patch management</p></li><li><p>Eliminate unsupported legacy systems</p></li><li><p>Strengthen identity controls</p></li><li><p>Regularly test incident response capabilities</p></li></ul><p>The timing of this advisory is notable given the reported 400% increase in cyber activity targeting satellite operators and space-sector organizations following recent geopolitical tensions involving Iran.</p><p>The message from Five Eyes is clear.</p><p>The organizations struggling with basic cybersecurity today will be the least prepared for AI-accelerated attacks tomorrow.</p><h1>&#9889; Need to Know</h1><h3>&#127822; New Atomic macOS Stealer Campaign Targets Apple Users</h3><p>Researchers identified a new ClickFix campaign targeting macOS users. Victims are tricked into opening Terminal and executing malicious commands that install the Atomic macOS Stealer. The malware targets browsers, cryptocurrency wallets, Apple Keychain, Telegram, Discord, and hardware wallet software. No legitimate website should ever instruct users to paste commands into Terminal.</p><h3>&#128272; Trump Signs Post-Quantum Cryptography Executive Order</h3><p>President Trump signed Executive Order 14409 establishing deadlines for federal migration to post-quantum cryptography. High-value federal systems must adopt quantum-resistant key establishment mechanisms by December 31, 2030, and quantum-resistant digital signatures by December 31, 2031. Federal contractors will face similar expectations.</p><h3>&#128736;&#65039; OpenAI Expands Cybersecurity Initiative</h3><p>OpenAI announced major updates to its Daybreak cybersecurity initiative, focusing on patch deployment and open-source software security. Through partnerships with HackerOne and Trail of Bits, the program aims to accelerate remediation efforts across critical open-source projects.</p><h3>&#127760; International Cybercrime Marketplace Operator Extradited</h3><p>Spanish authorities extradited Algerian national Abdullah Balami to the United States. He is accused of operating cybercrime marketplaces known as Market Zero Day and Spoxy, which allegedly facilitated the sale of stolen credentials, exploits, and cybercrime services.</p><h3>&#128663; Israeli Defense Sector Removes Chinese Vehicles</h3><p>Israeli defense contractor Elbit Systems has begun replacing Chinese-made vehicles within its corporate fleet due to concerns surrounding surveillance, connectivity, and supply chain risks. Other critical infrastructure operators in Israel are reviewing similar policies.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s show wasn&#8217;t about advanced persistent threats.</p><p>It wasn&#8217;t about artificial intelligence.</p><p>And it wasn&#8217;t even about zero-days.</p><p>It was about execution.</p><p>A Cisco patch available for three weeks.<br>A credential left active for four years.<br>An OAuth token nobody reviewed.<br>An identity relationship nobody questioned.</p><p>The cybersecurity industry spends enormous resources discussing emerging threats.</p><p>Yet attackers continue succeeding through problems we already know how to solve.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how many of these incidents trace back to governance failures rather than technology failures. The Cisco vulnerability had a patch. The Klue breach started with a credential that should have been removed years ago. The Scattered Spider intrusions repeatedly relied on social engineering rather than sophisticated exploitation. We continue investing heavily in advanced security technologies while leaving basic operational controls under-managed. Attackers notice that imbalance, and they exploit it relentlessly.</p><p>The second takeaway is that the timeline for cyber risk continues shrinking. The Five Eyes warning wasn&#8217;t written for future generations of security leaders. It was written for today&#8217;s leadership teams. AI-driven attack acceleration is happening now. Quantum-resistant cryptography deadlines are already being established. Organizations that cannot maintain credential hygiene, patch management discipline, and access governance today will struggle even more in an environment where attackers operate faster and at greater scale. The fundamentals are no longer simply best practices. They&#8217;re survival requirements.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating/comments"><span>Leave a comment</span></a></p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch Cisco Unified Communications Manager immediately</p></li><li><p>Audit all internet-facing Cisco Web Dialer deployments</p></li><li><p>Review temporary vendor credentials and pilot program accounts</p></li><li><p>Audit Salesforce OAuth integrations and connected applications</p></li><li><p>Rotate dormant API keys and OAuth tokens</p></li><li><p>Alert executives and customer-facing teams to phishing risks from the Klue breach</p></li><li><p>Strengthen help desk verification procedures against social engineering</p></li><li><p>Review organizational readiness for AI-assisted cyber threats</p></li><li><p>Begin post-quantum cryptography inventory and planning efforts</p></li><li><p>Train users against ClickFix and Terminal-based phishing attacks</p></li><li><p>Assess third-party trust relationships and vendor offboarding procedures</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/trump-signs-executive-order-mandating?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[FortiBleed Campaign Compromises 86K FortiGate Firewalls Across 194 Countries, Unpatchable Usbliter8 BootROM Exploit Bypasses Apple Secure Boot on Millions of iPhones, SocGholish Botnet Disrupted]]></title><description><![CDATA[FortiBleed Hits Half the World's Fortinet Firewalls, Icarus Expands Salesforce Supply Chain Attacks, and an Unpatchable iPhone Exploit Emerges]]></description><link>https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:31:37 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203236875/c0fe9842a8a383976e09b920062808c6.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s show highlighted a reality that every security leader needs to understand:</p><div class="callout-block" data-callout="true"><p><strong>The perimeter is no longer your firewall. It&#8217;s every credential, every OAuth token, every supplier, and every trust relationship connected to your organization.</strong></p></div><p>Today&#8217;s stories demonstrated just how interconnected cybersecurity risk has become. A Russian-speaking threat actor assembled a database containing working credentials for roughly half of the internet-facing Fortinet firewalls visible on Shodan. A new extortion group called Icarus expanded a Salesforce-focused supply chain campaign impacting multiple cybersecurity vendors. Researchers disclosed an unpatchable exploit affecting millions of older iPhones, while a major Apple and Tesla supplier confirmed a breach exposing hundreds of gigabytes of manufacturing and operational data.</p><p>The common thread across every story was trust. Attackers aren&#8217;t simply targeting vulnerabilities anymore. They&#8217;re targeting the trust relationships organizations depend on every day.</p><p>Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape revealed three major themes.</p><p>First, credentials remain one of the most valuable assets in cybersecurity. The FortiBleed campaign demonstrates that password complexity means little once credentials appear in infostealer databases.</p><p>Second, SaaS integrations continue becoming one of the largest unmanaged attack surfaces in enterprise environments. The Clu breach and resulting Icarus extortion campaign illustrate how a single third-party integration can provide access to dozens of downstream organizations.</p><p>Finally, supply chain security now extends well beyond software. Manufacturing ecosystems, hardware providers, semiconductor companies, and electronics suppliers increasingly represent attractive targets for adversaries seeking strategic intelligence.</p><p>The attack surface isn&#8217;t growing. It&#8217;s converging.</p><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128293; FortiBleed Exposes More Than 86,000 Active Fortinet Devices Across 194 Countries</h2><p>The biggest story of the day continues to be FortiBleed, and the latest details make the situation significantly worse than originally believed. Researchers now confirm that a Russian-speaking threat actor compiled a verified database containing 86,644 active Fortinet administrative and SSL VPN credentials affecting organizations across 194 countries.</p><p>The scale is extraordinary. Researchers estimate the affected devices represent roughly half of all internet-facing Fortinet firewalls discoverable through Shodan.</p><p>What makes this campaign unique is the methodology. Attackers didn&#8217;t simply rely on brute force attacks. Instead, they built an automated ecosystem that combined credential stuffing, password harvesting, packet sniffing, and infostealer data. Once attackers gained access to Fortinet devices, they deployed custom packet sniffers that intercepted VPN authentication hashes in transit. Those hashes were then cracked using a dedicated 45-GPU password-cracking environment before being recycled back into the attack framework.</p><p>Perhaps the most alarming finding came from Hudson Rock. Many of the recovered passwords exceeded 25 characters and fully complied with complexity requirements. They weren&#8217;t cracked at all. They were harvested directly from infostealer logs.</p><p>That&#8217;s a critical lesson for security leaders. Password complexity does not protect credentials that have already been stolen.</p><p>Fortinet emphasized that no new vulnerability was exploited. Technically, that&#8217;s true. Operationally, however, the distinction matters very little when attackers possess valid credentials capable of providing direct access to perimeter infrastructure.</p><p>Organizations should assume any internet-facing Fortinet environment is a target and immediately rotate administrative credentials, VPN passwords, and any Active Directory credentials potentially associated with those systems.</p><h2>&#127917; Icarus Expands Salesforce Supply Chain Campaign</h2><p>The fallout from the Clu breach continues to expand as a newly identified extortion group known as Icarus claims responsibility for stealing data from multiple organizations through compromised Salesforce integrations.</p><p>The list of confirmed victims now includes several major cybersecurity companies and SaaS providers, including HackerOne, Huntress, Recorded Future, Tanium, Snyk, Jamf, OneTrust, Gong, and Sprout Social.</p><p>The attack chain began with something remarkably simple: a forgotten testing account.</p><blockquote><p><em>&#8220;Attackers don&#8217;t need a zero-day when your Salesforce instance hands them a skeleton key through a vendor you forgot you onboarded.&#8221;</em></p></blockquote><p>Attackers gained access using a dormant credential that should have been decommissioned years earlier. From there, they inserted malicious code into Clu&#8217;s backend environment and harvested OAuth tokens connected to customer Salesforce instances and other SaaS applications.</p><p>Armed with those tokens, attackers launched large-scale extraction operations through Salesforce APIs, generating thousands of requests and pulling business intelligence, customer relationship information, pricing data, opportunity tracking notes, and sales strategy information.</p><p>This incident marks the third significant Salesforce OAuth supply chain attack in less than a year.</p><p>That statistic alone should concern every security leader.</p><p>Organizations spend enormous effort securing their Salesforce environments while often overlooking the dozens of third-party applications granted broad access through OAuth permissions. Those integrations frequently become the weakest link in the chain.</p><p>The lesson here is simple: if your team cannot explain why a connected application has access to Salesforce, that access should probably be removed.</p><h2>&#128241; Researchers Disclose Unpatchable iPhone BootROM Exploit</h2><p>Researchers at Paradigm Shift disclosed a new exploit known as USBlitter-V8 that targets Apple&#8217;s SecureROM, the foundational code executed when affected devices power on.</p><p>The significance of this vulnerability lies in one uncomfortable reality.</p><p>Apple cannot patch it.</p><p>Because the flaw resides within immutable silicon rather than software, no operating system update can fully remediate the issue.</p><p>The exploit impacts devices built on Apple&#8217;s A12 and A13 chipsets, including the iPhone XS, XR, and iPhone 11 product lines, along with certain Apple Watch models.</p><p>The attack requires physical access and specialized hardware, limiting widespread abuse. However, in the hands of nation-state actors, forensic specialists, or sophisticated adversaries, the exploit enables compromise of the device&#8217;s secure boot chain from the very first instruction executed during startup.</p><p>For most organizations, this is not an emergency.</p><p>But it does serve as another reminder that hardware lifecycle management remains a critical component of cybersecurity. Devices approaching a decade in service often carry risks that software updates can no longer address.</p><h2>&#127981; Tata Electronics Breach Impacts Apple and Tesla Supply Chain</h2><p>Tata Electronics confirmed a significant data breach after threat actors associated with the WorldLeaks ransomware group allegedly stole more than 630 gigabytes of internal information.</p><p>The breach has implications far beyond a single company.</p><p>Tata has become one of the most strategically important manufacturers in India&#8217;s technology ecosystem, assembling Apple products, supplying semiconductor components, and supporting Tesla operations.</p><p>Researchers reviewing samples from the leaked dataset identified:</p><ul><li><p>Apple supplier documentation</p></li><li><p>Tesla manufacturing records</p></li><li><p>Internal SAP data</p></li><li><p>Corporate email communications</p></li><li><p>Operational and engineering information</p></li></ul><p>Apple has reportedly launched an investigation while Tata continues evaluating the scope of the incident.</p><p>What makes this breach especially important is the broader context. Governments and corporations have spent years attempting to diversify manufacturing operations away from China. Tata has emerged as one of the largest beneficiaries of that transition.</p><p>As manufacturing ecosystems become more strategically important, they also become more attractive cyber targets.</p><p>Supply chain security increasingly extends from software code all the way to semiconductor fabrication and physical product assembly.</p><h1>&#9889; Need to Know</h1><h3>&#127760; International Law Enforcement Disrupts SocGholish Infrastructure</h3><p>Authorities from the United States, Canada, Germany, and the Netherlands seized 106 servers and remediated nearly 15,000 compromised WordPress websites associated with the SocGholish malware ecosystem. SocGholish has long served as an initial access broker feeding ransomware operations including Evil Corp and RansomHub. While the disruption is significant, researchers expect portions of the infrastructure to reemerge.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h3>&#128273; Gravity SMTP Plugin Under Active Exploitation</h3><p>Attackers are actively exploiting vulnerabilities in the Gravity SMTP WordPress plugin to steal API keys, credentials, and sensitive configuration information. Administrators should patch immediately and rotate any exposed secrets.</p><h3>&#128272; Google Sets Mandatory Passkey Deadline</h3><p>Google announced that all Workspace administrator accounts must transition to passkey-based authentication by September 30. Organizations should begin planning migration efforts immediately to avoid last-minute operational challenges.</p><h3>&#127911; Apple Patches Beats Bluetooth Vulnerability</h3><p>Apple released firmware updates addressing a high-severity Bluetooth pairing vulnerability affecting Beats Studio Buds. Organizations with large mobile workforces should encourage prompt updates.</p><h3>&#128421;&#65039; RemotePC Abused for Persistence</h3><p>Threat actors are increasingly abusing the legitimate RemotePC remote administration tool alongside PowerShell-based payloads to establish persistence inside enterprise environments. Security teams should monitor for unauthorized installations of remote management software.</p><h3>&#128680; False Emergency Alerts Trigger Panic in Brazil</h3><p>Authorities in Brazil are investigating a suspected cyber incident that triggered unauthorized emergency alerts nationwide, highlighting the ongoing fragility of public warning infrastructure and the importance of securing trusted communication systems.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t about malware.</p><p>It wasn&#8217;t about ransomware.</p><p>And it wasn&#8217;t even really about vulnerabilities.</p><p>It was about trust.</p><p>The trust organizations place in credentials.<br>The trust they place in SaaS integrations.<br>The trust they place in suppliers.<br>The trust they place in hardware platforms.</p><p>Every major breach discussed today succeeded because attackers found a trusted relationship and exploited it.</p><p>That&#8217;s increasingly where modern cybersecurity battles are won and lost.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how consistently trust relationships continue driving successful compromises. The FortiBleed campaign wasn&#8217;t powered by a breakthrough exploit. It was powered by credentials that should have been rotated years ago. The Clu breach wasn&#8217;t a Salesforce failure. It was an OAuth governance failure. The Tata breach wasn&#8217;t simply a ransomware incident. It was an attack against a strategically important manufacturing ecosystem. Every one of these stories demonstrates that attackers increasingly target relationships rather than technology.</p><p>The second takeaway is that security leaders need to rethink what constitutes critical infrastructure. For years we focused on servers, endpoints, and firewalls. Today, critical infrastructure includes SaaS integrations, supplier networks, manufacturing ecosystems, hardware trust anchors, and cloud identity platforms. If we continue defining our attack surface too narrowly, attackers will continue exploiting the areas we&#8217;ve chosen not to see. Visibility, governance, and trust validation are becoming just as important as patching and prevention.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Rotate all Fortinet administrative and SSL VPN credentials immediately</p></li><li><p>Review Active Directory accounts associated with perimeter devices</p></li><li><p>Enforce phishing-resistant MFA on administrative accounts</p></li><li><p>Audit all Salesforce connected applications and OAuth permissions</p></li><li><p>Remove unused or undocumented third-party integrations</p></li><li><p>Review supplier risk management programs for strategic vendors</p></li><li><p>Evaluate hardware refresh timelines for older Apple devices</p></li><li><p>Patch Gravity SMTP deployments and rotate associated secrets</p></li><li><p>Prepare Google Workspace administrators for passkey migration</p></li><li><p>Monitor environments for unauthorized RemotePC installations</p></li><li><p>Review supply chain security controls for manufacturing partners</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/fortibleed-campaign-compromises-86k?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Accenture Acquires Majority Stake in Dragos Plus runZero and NetRise for $4.2 Billion, Texas Government Breach Exposes 3 Million Driver's Licenses and Passports, Splunk Enterprise Pre-Auth RCE Exploit]]></title><description><![CDATA[Why basic security hygiene, not advanced tooling, continues to determine whether organizations withstand modern cyberattacks.]]></description><link>https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Mon, 22 Jun 2026 13:30:12 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203016881/d43c6bb49f7add5fe4581dbff46b8259.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode highlighted a harsh reality: attackers don&#8217;t need sophisticated zero-days when organizations continue struggling with the basics. Unpatched Splunk servers, stale Fortinet credentials, overprivileged SaaS integrations, and vulnerable web infrastructure are creating opportunities that threat actors continue exploiting at scale.</p><p>We also saw continued evidence that supply chain risk isn&#8217;t limited to software development environments. Business platforms, CRM systems, and third-party integrations have become high-value targets because they provide access to customer relationships, pricing strategies, and organizational intelligence.</p><p>If there was one theme that connected every story today, it was this: security hygiene remains the highest return-on-investment activity in cybersecurity.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><blockquote><p><em>&#8220;Security is ninety percent hygiene and ten percent fancy rules.&#8221; James Azar</em></p></blockquote><h1>&#129517; Executive Summary</h1><p>Today&#8217;s cybersecurity landscape highlighted three persistent challenges.</p><p>First, attackers continue weaponizing vulnerabilities within security products themselves. Splunk, Fortinet, and endpoint security platforms remain prime targets because compromising defensive infrastructure creates asymmetric advantages.</p><p>Second, third-party integrations continue expanding enterprise attack surfaces in ways many organizations fail to monitor effectively. OAuth permissions, API connections, and SaaS ecosystems increasingly represent soft entry points into sensitive environments.</p><p>Finally, organizations continue underestimating the value of basic operational security controls such as credential rotation, access reviews, and configuration management.</p><p>The technology is changing rapidly.</p><p>The fundamentals are not.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fp-Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:243739,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/203016881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Fp-Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F673f1f9c-39fe-46ab-898a-877e21b686ba_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128680; Splunk Vulnerability Added to CISA KEV Days After Disclosure</h2><p>Splunk Enterprise administrators face an urgent remediation requirement after CISA added CVE-2026-20253 to its Known Exploited Vulnerabilities catalog just days after public disclosure. The flaw affects Splunk&#8217;s PostgreSQL sidecar service and enables unauthenticated attackers to perform arbitrary file operations that can be chained into full remote code execution.</p><p>Researchers published proof-of-concept exploit code within forty-eight hours of disclosure, and Splunk confirmed active exploitation shortly afterward.</p><p>The vulnerability is particularly concerning because Splunk often serves as the backbone of enterprise detection and response programs. A successful compromise could allow attackers to manipulate logs, disable detections, erase forensic evidence, and pivot into additional environments.</p><p>This marks the first time a Splunk vulnerability has been added to CISA&#8217;s KEV catalog.</p><p>Organizations should immediately upgrade to supported versions, review all Splunk activity since June 10, and treat any unpatched internet-accessible instances as potentially compromised.</p><h2>&#128293; More Than 86,000 Fortinet Credentials Exposed</h2><p>CISA warned organizations that over 86,000 Fortinet devices now appear in attacker credential databases, creating a significant risk for organizations relying on VPN and perimeter security infrastructure. Importantly, this campaign does not rely on a new vulnerability.</p><p>Instead, attackers are leveraging default accounts, stale credentials, and passwords recovered from previous breaches. Researchers found that generic administrative accounts represented approximately 35% of exposed credentials, while another 28% involved built-in Fortinet accounts.</p><p>Many organizations upgraded to newer FortiOS versions supporting stronger password hashing algorithms but never required administrators to log in again, leaving older password hashes intact.</p><p>This is not a technology failure. It&#8217;s a fundamentals failure.</p><p>Organizations should terminate active sessions, rotate all administrative and VPN credentials, verify migration to stronger password hashing mechanisms, and enforce phishing-resistant MFA across all internet-facing management interfaces.</p><h2>&#128279; KlueSupply Chain Breach Impacts Huntress and Recorded Future</h2><p>Security vendors Huntress and Recorded Future confirmed they were impacted by a breach involving Klue, a market intelligence platform integrated into numerous sales and customer relationship workflows.</p><p>Attackers compromised Klue&#8217;s backend systems and distributed malicious code updates that harvested OAuth tokens connected to customer environments.</p><p>Affected integrations included:</p><ul><li><p>Salesforce</p></li><li><p>HubSpot</p></li><li><p>SharePoint</p></li><li><p>Zoom</p></li><li><p>Gong</p></li><li><p>Clari</p></li><li><p>Slack</p></li><li><p>Google Drive</p></li></ul><p>The attackers leveraged harvested tokens to query Salesforce environments and exfiltrate customer relationship data. While neither Huntress nor Recorded Future reported exposure of threat intelligence or engineering systems, the stolen data included customer contacts, pricing information, sales messaging, and contract details.</p><p>This incident reinforces an increasingly important lesson. Third-party SaaS integrations frequently hold broad permissions but receive limited security oversight. Organizations should audit OAuth scopes, review API access logs, and reassess the business necessity of every connected application.</p><h2> &#127760; Critical NGINX Vulnerabilities Could Enable Remote Code Execution</h2><p>F5 released patches for two critical vulnerabilities affecting NGINX Open Source and NGINX Plus deployments. Both flaws carry CVSS scores of 9.2 and impact core web infrastructure used across enterprise environments.</p><p>The first vulnerability affects HTTP/3 processing and can trigger memory corruption through crafted sessions. The second involves a heap-based buffer overflow affecting proxy and gRPC modules when specific configurations are enabled.</p><p>Both vulnerabilities are remotely exploitable without authentication and may allow remote code execution under certain conditions. NGINX underpins a significant percentage of internet-facing applications, APIs, and cloud-native services.</p><p>Recent history suggests attackers move quickly when critical NGINX vulnerabilities become public. Organizations should prioritize patching immediately and disable HTTP/3 functionality where updates cannot be deployed quickly.</p><h1>&#9889; Need to Know</h1><h3>&#128737;&#65039; GentleKiller Malware Targets EDR Platforms</h3><p>Researchers identified a new EDR-killing framework used by the Gentlemen ransomware operation. The malware disables more than 400 security processes across 48 vendors by exploiting vulnerable signed drivers in classic bring-your-own-vulnerable-driver attacks. Enable Microsoft&#8217;s vulnerable driver block list and implement strict driver allow-listing controls.</p><h3>&#128230; North Korea Targets npm Supply Chain</h3><p>Microsoft attributed a supply chain attack involving more than 60 npm packages to North Korean threat actors associated with Sapphire Sleet. The campaign targeted developer credentials and cryptocurrency wallets through typosquatted dependencies. Organizations should review development environments and dependency trees immediately.</p><h3>&#128421;&#65039; Joomla and LiteSpeed Vulnerabilities Under Active Exploitation</h3><p>Attackers are actively exploiting critical vulnerabilities affecting Joomla&#8217;s JCE Editor and LiteSpeed cPanel plugins. Both flaws enable remote code execution and privilege escalation against exposed hosting environments. Immediate patching is recommended.</p><h3>&#127966;&#65039; Texas Parks and Wildlife Breach Exposes 3 Million Records</h3><p>A third-party vendor supporting Texas Parks and Wildlife disclosed a breach exposing driver&#8217;s license numbers, passport information, email addresses, phone numbers, and physical addresses belonging to more than three million individuals. The affected vendor has not yet been publicly identified.</p><h3>&#127981; Accenture Expands Into OT Security</h3><p>Accenture announced a $4.1 billion transaction involving a majority stake in Dragos alongside acquisitions of RunZero and NetRise. The deal signals growing demand for integrated operational technology security capabilities as industrial environments face increasing cyber threats.</p><h3>&#127468;&#127463; UK Critical Infrastructure Faces Rising State Threats</h3><p>The UK&#8217;s National Cyber Security Centre reported handling more than 200 critical infrastructure incidents over the past year, with approximately 75 percent linked to nation-state actors associated with Russia, China, and Iran. Officials warned AI will accelerate exploitation of known vulnerabilities by 2028.</p><h3>&#129686; Defense Spending Increases Cybersecurity Requirements</h3><p>Proposed U.S. defense authorization legislation includes expanded CMMC requirements and additional AI security obligations for defense contractors, highlighting continued emphasis on supply chain security within the defense industrial base.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t about sophisticated attacks.</p><p>It was about neglected fundamentals.</p><p>Default credentials.<br>Overprivileged OAuth scopes.<br>Unpatched infrastructure.<br>Weak password hygiene.<br>Excessive third-party trust.</p><p>None of these problems require artificial intelligence to exploit.</p><p>They simply require defenders to ignore the basics long enough for attackers to notice.</p><div class="callout-block" data-callout="true"><p><em>"The basics are still the battlefield. Default Fortinet credentials. Unauthenticated Postgres endpoints. OAuth tokens nobody scoped down. None of this is exotic. All of it is preventable. And that's the real warning. Patch what you can. Rotate what you should. Audit those third-party integrations. Security is ninety percent hygiene, ten percent fancy rules." James Azar</em></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how consistently attackers continue winning through preventable failures. 86,000 Fortinet devices weren&#8217;t compromised because attackers discovered a revolutionary new technique. They succeeded because organizations failed to rotate credentials, remove default accounts, and validate upgrades. The Splunk issue reinforces the same lesson. Security tools themselves have become high-value targets, and defenders need to apply the same rigor to monitoring those platforms that they apply to every other critical asset.</p><p>The second takeaway is that third-party integrations have quietly become one of the largest unmanaged attack surfaces in enterprise environments. The Clu incident demonstrates how quickly OAuth tokens can become pathways into CRM systems, contract data, and customer intelligence. Organizations need to stop treating SaaS integrations as simple business enablement tools and start governing them like privileged infrastructure. Visibility into API permissions, token scopes, and application access is no longer optional.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch Splunk Enterprise instances immediately</p></li><li><p>Review Splunk activity logs dating back to June 10</p></li><li><p>Rotate all Fortinet administrative and VPN credentials</p></li><li><p>Remove default and generic administrator accounts</p></li><li><p>Enforce phishing-resistant MFA on perimeter devices</p></li><li><p>Audit all Salesforce and SaaS OAuth integrations</p></li><li><p>Review API access logs for unusual activity</p></li><li><p>Patch NGINX Open Source and NGINX Plus deployments</p></li><li><p>Enable Microsoft&#8217;s vulnerable driver block list</p></li><li><p>Audit npm dependencies for typosquatted packages</p></li><li><p>Patch Joomla JCE Editor and LiteSpeed environments</p></li><li><p>Review third-party vendor security requirements and data access permissions</p></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/accenture-acquires-majority-stake?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Iran's Handala Claims Hack of FBI Surveillance Drones and Threatens World Cup Teams With Hijacked FPVs, Chinese APT Targets Medical Military and AI Research Institutions Across North America]]></title><description><![CDATA[Palo Alto GlobalProtect Under Active Attack, China's UNC6508 Targets U.S. Research, and Cisco Faces Its Eighth SD-WAN Zero-Day]]></description><link>https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Tue, 16 Jun 2026 13:32:06 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/202227530/f2329617eb2f3b17f497d771f0892ba3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode delivered a stark reminder that cybersecurity isn&#8217;t a technology problem, it&#8217;s a trust problem.</p><p>Attackers continue targeting the systems we trust most: our VPNs, our SD-WAN controllers, our research platforms, our AI infrastructure, and the supply chains behind them all. Whether it&#8217;s a Chinese APT quietly siphoning medical and military research for years, threat actors exploiting Palo Alto VPN appliances to establish persistence inside enterprise networks, or attackers repeatedly targeting Cisco&#8217;s SD-WAN management plane, the common denominator remains the same.</p><p>They aren&#8217;t simply exploiting vulnerabilities.</p><p>They&#8217;re exploiting our reliance on critical infrastructure that was never designed to withstand this level of sustained adversarial pressure.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape highlighted three accelerating trends.</p><p>First, network edge devices remain one of the most attractive targets for attackers. Palo Alto GlobalProtect and Cisco SD-WAN continue to experience active exploitation because they provide direct pathways into enterprise environments.</p><p>Second, nation-state actors increasingly prioritize long-term intelligence collection over disruptive attacks. China&#8217;s UNC6508 campaign demonstrates the value adversaries place on medical research, military readiness data, AI development, and public health information.</p><p>Finally, organizations continue deploying AI technologies faster than they can secure them. New vulnerabilities affecting AI model proxies and orchestration frameworks show how quickly emerging technologies become part of the enterprise attack surface.</p><p>The challenge for defenders is no longer finding vulnerabilities.</p><p>It&#8217;s understanding which trusted systems attackers value most.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6EWW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6EWW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6EWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:176410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/202227530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6EWW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!6EWW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd050ec0f-5cbe-493b-8c0e-27095ae2fe71_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128680; Palo Alto GlobalProtect Authentication Bypass Under Active Exploitation</h2><p>Palo Alto Networks issued an urgent warning confirming active exploitation of CVE-2026-0257, an authentication bypass vulnerability affecting GlobalProtect portal and gateway components running on PAN-OS. CISA added the flaw to its Known Exploited Vulnerabilities catalog in late May, but exploitation activity continues to expand.</p><p>The vulnerability stems from improper handling of authentication override cookies. When organizations enable the authentication override feature while reusing certificates across multiple services, attackers can forge authentication cookies and establish fully authenticated VPN sessions without valid credentials.</p><p>No username.<br>No password.<br>No MFA prompt.</p><p>Once inside, attackers immediately begin post-exploitation activity consistent with credential harvesting and lateral movement. Researchers observed threat actors establishing IPSec tunnels, conducting SMB reconnaissance, and generating NTLM authentication traffic within minutes of obtaining access.</p><p>This is not opportunistic scanning. It&#8217;s operational intrusion activity designed to achieve persistence.</p><p>Organizations running physical or virtual PAN-OS firewalls with GlobalProtect enabled should patch immediately, disable authentication override functionality where possible, rotate associated certificates, and review logs for suspicious VPN activity dating back to May.</p><h2>&#9888;&#65039; Cisco SD-WAN Suffers Its Eighth Zero-Day of 2026</h2><p>Cisco released patches for CVE-2026-20262, another critical vulnerability affecting Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows low-privileged authenticated users to upload crafted files and achieve root-level code execution.</p><p>This marks at least the eighth actively exploited SD-WAN vulnerability disclosed by Cisco in 2026.</p><p>Researchers tracking the threat cluster UAT-5918, believed to overlap with China&#8217;s Nexus Orb infrastructure, observed attackers repeatedly targeting SD-WAN environments using remarkably consistent techniques. After gaining access, threat actors inject SSH keys, enable root accounts, downgrade software to reintroduce older vulnerabilities, and restore original versions to obscure forensic evidence.</p><p>At this point, the issue extends beyond individual vulnerabilities.</p><p>When a single product line experiences eight actively exploited vulnerabilities within six months many affecting the same management plane components, organizations must begin asking harder questions about architecture, secure development practices, and long-term platform risk.</p><p>Organizations should patch immediately, review authorized SSH keys, inspect configuration changes, and verify the integrity of routing policies pushed throughout the SD-WAN fabric.</p><h2>&#127464;&#127475; UNC6508 Spent Years Harvesting U.S. Medical, Military, and AI Research</h2><p>Google Threat Intelligence Group published details on UNC6508, a Chinese cyber espionage operation targeting medical providers, military health institutions, academic research organizations, and public health agencies across the United States and Canada.</p><p>The campaign focused heavily on organizations conducting:</p><ul><li><p>Clinical drug trials</p></li><li><p>Molecular research</p></li><li><p>Military health readiness programs</p></li><li><p>Public health initiatives</p></li><li><p>Artificial intelligence research</p></li></ul><p>Initial access appears tied to unpatched REDCap deployments, a widely used research platform supporting clinical databases and survey collection.</p><p>Once inside, UNC6508 demonstrated exceptional patience.</p><p>In one case, attackers waited more than three months before deploying custom malware known as InfiniteRed. The malware established persistence, harvested credentials, and enabled command-and-control communications.</p><p>Perhaps most concerning was the group&#8217;s use of legitimate email compliance features to silently exfiltrate sensitive communications matching predefined research topics.</p><p>One intrusion reportedly lasted more than two years.</p><p>The takeaway is straightforward: if your organization conducts high-value research, assume you are already a target.</p><h2>&#127806; Ransomware Halts Australia&#8217;s Sugar Harvest</h2><p>Australia&#8217;s second-largest sugar producer, Mackay Sugar, suffered a ransomware attack attributed to the group known as The Gentlemen, disrupting operations during the opening days of the country&#8217;s sugar crushing season.</p><p>The attack forced shutdowns across multiple processing facilities and disrupted logistics systems supporting approximately 1,300 family farms.</p><p>While business systems are slowly returning online, critical questions remain unanswered regarding potential impacts to operational technology environments.</p><p>Food production operates on unforgiving timelines. Sugarcane begins losing value immediately after harvest, meaning every day of downtime translates directly into financial losses for producers.</p><p>The incident underscores a growing trend.</p><p>Cyberattacks targeting food and agriculture increasingly create physical-world consequences that extend well beyond the directly affected organization.</p><p>If scheduling systems, logistics platforms, and industrial control environments share network connectivity, the resulting business impact can cascade rapidly.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share CISO Talk by James Azar&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share CISO Talk by James Azar</span></a></p><h1>&#9889; Need to Know</h1><h3>&#129302; LightLLM Vulnerabilities Expose AI Infrastructure</h3><p>Researchers disclosed multiple critical vulnerabilities affecting LightLLM, a popular proxy used to route traffic to AI models including ChatGPT and Claude. The flaws enable privilege escalation, remote code execution, command injection, and API key generation. Organizations should upgrade immediately to version 1.8.3.14-stable or later.</p><h3>&#128736;&#65039; SimpleHelp Authentication Bypass Carries Perfect CVSS Score</h3><p>CVE-2026-48558 affects SimpleHelp remote support deployments using OpenID Connect authentication. Attackers can forge identity tokens, bypass MFA, create technician accounts, and remotely access managed systems. Approximately 14,000 internet-facing instances remain exposed.</p><h3>&#127917; DOJ Seizes Deepfake Abuse Websites</h3><p>The Department of Justice seized two websites hosting hundreds of thousands of non-consensual deepfake images in the first major action under the Take It Down Act. International law enforcement partners in France and Italy assisted with the operation.</p><h3>&#127907; Ghostwriter Targets Polish Gmail Accounts</h3><p>Belarus-linked threat group Ghostwriter shifted operations toward personal Gmail accounts belonging to politicians, journalists, academics, and government personnel. The campaign uses adversary-in-the-middle techniques to bypass MFA protections.</p><h3>&#128230; npm Moves to Restrict Install Scripts</h3><p>npm version 12, expected next month, will disable automatic execution of dependency lifecycle scripts by default. The change directly addresses recent supply chain attacks involving Shai-Hulud and TeamTNT campaigns.</p><h3>&#128241; UK Plans Social Media Restrictions for Children</h3><p>The UK announced plans to restrict social media access for children under 16, creating significant implications for age verification, identity assurance, and privacy engineering.</p><h3>&#9917; Handala Claims FBI World Cup Drone Compromise</h3><p>Iran-linked group Handala claimed it breached FBI surveillance drones supporting FIFA World Cup security operations. While investigators dispute portions of the evidence provided, the claim reflects increasing interest in major global events as cyber targets.</p><h3>&#127760; FCC Relaxes Restrictions on Chinese Network Equipment</h3><p>The FCC announced changes allowing certain Chinese-manufactured networking equipment back into approved cable provider environments, reigniting debate around supply chain integrity and network hardware trust.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t really about vulnerabilities.</p><p>It was about persistence.</p><p>UNC6508 remained undetected for years.<br>Attackers exploiting GlobalProtect move immediately into credential harvesting.<br>Chinese actors repeatedly return to Cisco SD-WAN environments because the management plane remains valuable.<br>Ransomware groups understand exactly when operational disruption creates maximum leverage.</p><p>The organizations that succeed in this environment won&#8217;t necessarily be the ones that patch fastest.</p><p>They&#8217;ll be the ones that detect unauthorized access before attackers turn persistence into impact.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how consistently attackers target authentication infrastructure and management planes. GlobalProtect, SD-WAN controllers, REDCap systems, AI proxies, these are all systems designed to facilitate access. Once compromised, they become force multipliers for attackers. Security teams need to stop treating these technologies as routine infrastructure and start treating them as crown jewels because that&#8217;s exactly how adversaries view them.</p><p>The second takeaway is that patience continues to favor sophisticated threat actors. UNC6508 waited months before deploying malware and years before being discovered. UAT-5918 repeatedly returns to Cisco environments because they understand defenders often focus on patching individual vulnerabilities instead of addressing root causes. Detection engineering, behavioral monitoring, and threat hunting are no longer advanced capabilities reserved for mature organizations. They&#8217;re baseline requirements for operating securely in 2026.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi/comments"><span>Leave a comment</span></a></p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch PAN-OS GlobalProtect deployments immediately</p></li><li><p>Disable authentication override functionality where possible</p></li><li><p>Review GlobalProtect logs for suspicious activity dating back to May</p></li><li><p>Patch Cisco Catalyst SD-WAN Manager without delay</p></li><li><p>Audit authorized SSH keys and configuration changes</p></li><li><p>Inventory and patch all REDCap deployments</p></li><li><p>Hunt for InfiniteRed indicators of compromise</p></li><li><p>Verify segmentation between IT and OT environments</p></li><li><p>Upgrade LightLLM to supported versions</p></li><li><p>Review SimpleHelp deployments using OpenID Connect</p></li><li><p>Prepare development teams for npm install script changes</p></li><li><p>Increase phishing awareness ahead of World Cup events</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/irans-handala-claims-hack-of-fbi?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[US Government Orders Anthropic to Suspend Fable 5 and Mythos 5, Iran's Handala Claims Hack of Cal Water, 400+ Arch Linux AUR Packages Compromised With Rootkit and Infostealer ]]></title><description><![CDATA[Oracle PeopleSoft CVSS 9.8 Zero-Day Added to KEV After 14-Day Shiny Hunters Rampage | Splunk Enterprise Pre-Auth RCE | Iran Handala Hacks California Water Utility | 400+ Arch Linux Packages Rootkit]]></description><link>https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Mon, 15 Jun 2026 13:31:23 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/202065523/80f702625752cb607a01cb90031a1cc0.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode exposed a harsh reality many security teams are struggling to accept:</p><div class="callout-block" data-callout="true"><p><strong>Attackers are no longer exploiting vulnerabilities one at a time, they&#8217;re exploiting delays in disclosure, gaps in detection, and the operational complexity that slows defenders down.</strong></p></div><p>Today&#8217;s show featured two critical enterprise vulnerabilities with CVSS scores of 9.8 affecting platforms organizations rely on every day. Oracle&#8217;s PeopleSoft environments continue to be actively targeted by ShinyHunters, while Splunk Enterprise faces a pre-authentication remote code execution vulnerability that strikes at the heart of security operations infrastructure.</p><p>At the same time, Iranian hacktivists claimed responsibility for breaching a major California water utility, more than 400 Arch Linux packages were discovered distributing malware to developer environments, and a Chinese APT quietly maintained access to an air-gapped network for a decade.</p><p>If there was a single lesson from today&#8217;s show, it&#8217;s this: access remains the most valuable asset in cybersecurity. The question isn&#8217;t whether attackers can get in, it&#8217;s how quickly organizations can detect them before that access turns into impact.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape highlights three critical trends shaping cybersecurity in 2026.</p><p>First, enterprise software vendors continue struggling with timely vulnerability disclosure. Oracle&#8217;s PeopleSoft customers were exposed for two weeks before receiving official guidance, while Splunk customers are rushing to patch a vulnerability affecting the very platform used to monitor threats.</p><p>Second, attackers increasingly target identity and authentication systems because controlling access provides far more value than compromising individual endpoints.</p><p>Finally, supply chain attacks continue moving deeper into developer ecosystems, while geopolitical tensions increasingly influence cyber operations against critical infrastructure.</p><p>The result is a threat environment where defenders must assume attackers are already exploiting newly disclosed vulnerabilities long before patches become widely deployed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!59EC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!59EC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!59EC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!59EC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!59EC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!59EC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170724,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/202065523?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!59EC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!59EC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!59EC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!59EC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3417d7c1-474f-4575-a4b7-7b13e174544c_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#127963;&#65039; ShinyHunters Exploits PeopleSoft Zero-Day Across More Than 100 Organizations</h2><p>Oracle released an emergency out-of-band patch for CVE-2026-44712, a critical 9.8-rated remote code execution vulnerability affecting PeopleSoft Update Environment Management Hub. The flaw allows unauthenticated attackers to execute code over HTTP without credentials or user interaction.</p><p>The concern is not simply the vulnerability itself, it&#8217;s the timeline.</p><p>Threat intelligence researchers confirmed active exploitation began on May 27, yet Oracle&#8217;s advisory did not arrive until June 10, providing attackers with a fourteen-day head start. During that period, ShinyHunters reportedly compromised more than 300 PeopleSoft instances spanning over 100 organizations.</p><p>Nearly seventy percent of confirmed victims are higher education institutions. The University of Nottingham publicly acknowledged a breach after student and alumni records appeared on ShinyHunters&#8217; leak site.</p><p>PeopleSoft environments frequently contain payroll information, financial aid records, employee data, student records, and other highly sensitive information. Researchers also identified evidence of outbound SMB traffic from compromised servers, suggesting attackers may be capturing NetNTLM hashes for credential relay attacks and lateral movement.</p><p>This incident reinforces a difficult truth for organizations operating large ERP platforms: vendor disclosure timelines rarely align with attacker timelines.</p><p>Organizations should assume compromise if their PeopleSoft instances were exposed between May 27 and June 10 and immediately begin incident response activities.</p><h2>&#128680; Splunk Enterprise Faces Critical Pre-Authentication Remote Code Execution</h2><p>Splunk disclosed CVE-2026-44787, a critical vulnerability with a CVSS score of 9.8 that allows unauthenticated remote code execution through exposed backup and recovery endpoints.</p><p>Researchers demonstrated that attackers can abuse PostgreSQL sidecar services to perform arbitrary file operations and overwrite Python scripts executed by Splunk itself, transforming a file write capability into full server compromise.</p><p>Affected versions include Splunk Enterprise 10.0.0 through 10.0.6 and 10.2.0 through 10.2.3.</p><p>The irony is difficult to ignore.</p><p>Splunk serves as the security monitoring platform for countless organizations. A successful compromise could allow attackers to disable logging, tamper with detections, erase evidence, or use the platform as a pivot point into additional environments.</p><p>Organizations running AWS-hosted Splunk Enterprise deployments face elevated risk because the PostgreSQL sidecar service is enabled by default.</p><p>This vulnerability highlights an ongoing challenge across cybersecurity: the tools organizations rely on for defense increasingly represent high-value targets themselves.</p><p>Immediate patching should be considered mandatory.</p><h2>&#128167; Iran-Linked Handala Claims Breach of California Water Utility</h2><p>The Iran-linked hacktivist group Handala claimed responsibility for breaching California Water Service, one of the largest investor-owned water utilities in the United States, serving approximately two million customers.</p><p>The group published approximately five gigabytes of allegedly stolen data and framed the attack as retaliation for recent geopolitical developments involving Iran and the United States.</p><p>Analysis of the leaked material suggests attackers accessed customer billing databases and internal RTK base systems used for centimeter-level GPS positioning by field crews.</p><p>The leaked data reportedly includes customer names, addresses, account numbers, payment histories, administrative credentials, and GPS correction infrastructure information.</p><p>Importantly, researchers found no evidence that operational technology or industrial control systems were compromised.</p><p>Handala claims it could have disrupted water services but intentionally chose not to. While there is currently no evidence supporting those claims, the incident demonstrates how critical infrastructure operators continue facing elevated risk from ideologically motivated threat actors.</p><p>The greater concern may not be service disruption but rather the exposure of operational information that could facilitate future targeting efforts.</p><h2>&#128039; More Than 400 Arch Linux Packages Distribute Malware</h2><p>Researchers discovered that more than 400 packages in the Arch User Repository were compromised to distribute Linux rootkits and credential-stealing malware.</p><p>The Arch User Repository remains one of the most popular community-driven package ecosystems for developers, researchers, and security practitioners.</p><p>The malware includes rootkits designed for persistence and infostealers targeting:</p><ul><li><p>Cloud credentials</p></li><li><p>Session tokens</p></li><li><p>Source code repositories</p></li><li><p>CI/CD environments</p></li><li><p>Developer authentication secrets</p></li></ul><p>Developer workstations have become increasingly attractive targets because they provide access to production environments, cloud infrastructure, and software supply chains.</p><p>Compromising a developer endpoint often delivers significantly more value than compromising a traditional user workstation.</p><p>Organizations should treat any credentials recently used on affected Arch Linux systems as compromised and immediately rotate associated secrets.</p><h1>&#9889; Need to Know</h1><h3>&#127464;&#127475; Velvet Ant Maintained Access to Air-Gapped Networks for Ten Years</h3><p>Researchers disclosed that Chinese threat actor Velvet Ant maintained access to an organization&#8217;s authentication infrastructure for more than a decade, providing visibility into administrative activity across isolated environments. The case demonstrates that air gaps alone do not provide meaningful security without monitoring and authentication integrity controls.</p><h3>&#127907; FBI Dismantles Massive AI-Powered Phishing Platform</h3><p>The FBI, working alongside Google and Black Lotus Labs, disrupted &#8220;LabHost,&#8221; a phishing-as-a-service operation responsible for more than one million malicious URLs and thousands of credential theft sites. The platform leveraged AI to accelerate phishing infrastructure deployment at scale.</p><h3>&#128137; Novo Nordisk Discloses Clinical Trial Data Breach</h3><p>Pharmaceutical giant Novo Nordisk confirmed attackers accessed systems containing pseudonymized patient data related to clinical trials. Exposed information includes patient identifiers, participation details, biomarkers, and lifestyle information. Core business operations remain unaffected.</p><h3>&#127472;&#127479; South Korea Issues Record Privacy Fine</h3><p>South Korea&#8217;s privacy regulator imposed a record $409 million fine against e-commerce platform Coupang after a former employee allegedly stole authentication signing keys, exposing the personal information of more than 33 million individuals.</p><h3>&#128221; Maine Breach Reporting Portal Abused</h3><p>Maine&#8217;s public breach notification database was temporarily taken offline after unknown actors submitted fabricated breach reports falsely attributing incidents to major platforms. The incident raises concerns regarding the integrity of public breach reporting systems.</p><h3>&#129302; U.S. Restricts Access to Advanced AI Models</h3><p>The U.S. government directed Anthropic to suspend access to its advanced Fable 5 and Mythos 5 models for certain foreign nationals due to national security and jailbreak concerns. The move reflects a broader trend toward treating frontier AI models as controlled technologies.</p><h3>&#9917; FBI Warns of World Cup Ticket Scams</h3><p>With the FIFA World Cup underway, the FBI warned of increased activity involving fake ticket websites, fraudulent domains, and employment scams targeting fans and job seekers. Officials recommend purchasing tickets exclusively through FIFA&#8217;s official application.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t fundamentally about vulnerabilities.</p><p>It was about access.</p><p>Who has access.<br>Who shouldn&#8217;t.<br>How long attackers maintain that access.<br>And how quickly defenders can identify the difference.</p><p>Whether it was ShinyHunters exploiting PeopleSoft, Velvet Ant compromising authentication infrastructure, or Handala stealing utility credentials, the common thread remains unchanged.</p><p>Access without visibility becomes persistence.<br>Persistence without detection becomes impact.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how consistently attackers focused on identity, authentication, and administrative control. ShinyHunters captured credentials through outbound SMB traffic. Velvet Ant compromised authentication systems directly. Handala targeted administrative access to utility infrastructure. Even the Arch Linux compromise focused on stealing developer credentials and session tokens. The lesson is clear: attackers increasingly care less about individual endpoints and more about the systems controlling trust.</p><p>The second takeaway is that organizations can no longer afford to operate on vendor timelines. Oracle&#8217;s delayed disclosure gave attackers a two-week advantage. Splunk customers are now rushing to patch the very platforms responsible for monitoring threats. AI models are becoming matters of national security, and supply chain attacks continue targeting developer ecosystems. Security teams must prioritize proactive threat hunting, independent validation, and rapid response capabilities because waiting for official guidance is increasingly becoming a losing strategy.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to/comments"><span>Leave a comment</span></a></p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Immediately patch Oracle PeopleSoft CVE-2026-44712</p></li><li><p>Hunt for indicators of compromise dating back to May 27</p></li><li><p>Review outbound SMB traffic from PeopleSoft environments</p></li><li><p>Upgrade Splunk Enterprise to supported fixed versions</p></li><li><p>Restrict network access to Splunk management interfaces</p></li><li><p>Rotate credentials associated with affected Arch Linux systems</p></li><li><p>Audit authentication infrastructure for unauthorized persistence</p></li><li><p>Validate phishing-resistant MFA deployment across critical systems</p></li><li><p>Review segmentation between IT and OT environments</p></li><li><p>Monitor World Cup-related phishing and fraud campaigns</p></li><li><p>Assess AI governance policies for emerging export control requirements</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/us-government-orders-anthropic-to?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[This Week in Cybersecurity #56]]></title><description><![CDATA[No Patch Available: When the Answer Is Monitoring, Segmentation, and Living on Attacker Timelines, Your weekend catch-up on the most critical cybersecurity stories of the week, curated by James Azar]]></description><link>https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Fri, 12 Jun 2026 17:51:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Itm4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>Good Morning, Security Gang!</strong></h3><p>Double espresso poured. This week&#8217;s briefing may be the most operationally dense we&#8217;ve produced in recent memory, four full episodes covering a threat landscape James described plainly: <em>&#8220;Defenders are increasingly operating on attacker timelines rather than vendor timelines.&#8221;</em></p><p>This week that was not rhetorical. A federal whistleblower complaint alleged IBM and AT&amp;T concealed APT10 federal cloud intrusions affecting billions in government contracts. Cisco disclosed its seventh SD-WAN zero-day of 2026, this time with no patch available. Hugging Face Transformers with 232 million installations received a critical RCE vulnerability disclosure where exploitation bypasses the control specifically designed to prevent it. The Miasma supply chain worm expanded into AI developer toolchains including Claude Code, Gemini CLI, and VS Code AI extensions. Check Point VPN attackers moved from initial access to domain controller compromise in under four hours. And researcher Nightmare Eclipse dropped &#8220;Rogue Planet,&#8221; a privilege escalation exploit achieving SYSTEM on fully patched Windows 10 and 11 effective even after June&#8217;s Patch Tuesday.</p><p>By the end of the week: Chrome logged its fifth actively exploited zero-day of 2026. SAP released a CVSS 9.9 NetWeaver SAML forgery vulnerability. ServiceNow disclosed unauthenticated API data access then revised its account. Veeam backup servers were found vulnerable to RCE by any authenticated domain user. ShinyHunters launched a large-scale PeopleSoft campaign hitting 300+ instances across 100+ organizations. And North Korea was attributed with 47% of all state-sponsored hands-on-keyboard intrusions in the technology sector.</p><p>The phrase that appeared more than any other across the week: &#8220;no patch currently available.&#8221;</p><blockquote><p>James&#8217;s response: <em>&#8220;Forget all the shiny tools. If we can&#8217;t do the fundamentals well, none of those tools are going to help. That&#8217;s the reality.&#8221;</em></p></blockquote><p>Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Itm4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Itm4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Itm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1145013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/201778200?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Itm4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!Itm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bd72de9-6046-440e-8cc1-f86a8695a828_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>&#127760; Infrastructure &amp; Network Exploitation</strong></h3><p><strong>Cisco SD-WAN: Seventh Zero-Day of 2026 &#8212; Root Code Execution, No Patch</strong></p><p>Cisco disclosed another critical SD-WAN vulnerability enabling root-level code execution &#8212; the seventh SD-WAN zero-day disclosed this year. No patch is currently available. SD-WAN platforms control routing, connectivity, segmentation, and network visibility across enterprises. Seven zero-days targeting one product line in six months raises legitimate questions about attack surface management, secure development practices, and long-term vendor strategy. Restrict management plane access immediately, implement all published compensating controls, and review long-term vendor strategy for this infrastructure tier.</p><p><strong>SolarWinds Serv-U Added to CISA KEV: Federal Deadline June 19</strong></p><p>CISA added SolarWinds Serv-U FTP software to the KEV catalog following confirmed active exploitation. The vulnerability allows unauthenticated denial-of-service through crafted requests. Federal agencies face a June 19 remediation deadline. Upgrade to Serv-U version 15.5.4 Hotfix 1 and verify all internet-facing deployments are updated.</p><p><strong>Chrome CVE-2026-111645: Fifth Actively Exploited Zero-Day of 2026</strong></p><p>Google released an emergency update addressing CVE-2026-111645, a high-severity out-of-bounds memory flaw in Chrome&#8217;s V8 JavaScript engine actively exploited in the wild enabling arbitrary code execution through nothing more than a victim visiting a compromised webpage. This is Chrome&#8217;s fifth actively exploited zero-day of 2026. The browser is now the operating system for modern work, holding SaaS access, authentication tokens, cloud credentials, and financial systems. Deploy Chrome version 149.0.7827.102 or later immediately and ensure browsers are actually restarted, not just updated in the background.</p><p><strong>Chrome 149 Ships 429 Security Fixes Including CVSS 9.6 Sandbox Escape</strong></p><p>Alongside the emergency zero-day patch, Google&#8217;s Chrome 149 delivered 429 total security fixes including a critical sandbox escape vulnerability carrying a CVSS score of 9.6. Force browser updates across all managed endpoints and verify deployment.</p><p><strong>CISA KEV Additions: Cisco SD-WAN, Chrome V8, Arista EOS Tunnel Bypass</strong></p><p>CISA added three actively exploited vulnerabilities this week. The Arista EOS flaw is particularly notable: it allows unexpected tunneled traffic to bypass intended protocol validation controls in tunnel endpoint configurations and Arista&#8217;s mitigation guidance relies entirely on access control lists because no patch is currently planned. No patch. No timeline. ACLs only.</p><p><strong>Oracle WebLogic Added to CISA KEV: Cobalt Strike and Ransomware Deployment Confirmed</strong></p><p>CISA confirmed active exploitation of CVE-2024-21182 in Oracle WebLogic attackers are using it to deploy Cobalt Strike and ransomware. Patch immediately and review exposed WebLogic services.</p><p><strong>ASUS Router Critical Vulnerabilities: Patches Expected End of June</strong></p><p>Two critical ASUS Wave 7 mesh router vulnerabilities expose credentials and allow persistent backdoor installation. No patches until later this month. Restrict management interfaces to trusted IP ranges and implement network segmentation as interim controls.</p><h3><strong>&#127464;&#127475; Chinese Threat Activity</strong></h3><p><strong>IBM and AT&amp;T Accused of Concealing APT10 Federal Cloud Intrusions &#8212; 56,000 Breaches Alleged</strong></p><p>A newly unsealed federal whistleblower complaint filed by former IBM security analyst William Barlow alleges that IBM and AT&amp;T concealed extensive APT10 intrusions affecting federal cloud infrastructure between 2013 and 2016. The complaint claims APT10 breached IBM systems more than 56,000 times while targeting subsidiaries managing sensitive federal healthcare and financial workloads, and that IBM leadership chose not to disclose the activity in order to protect federal business relationships worth billions of dollars. These remain allegations in a whistleblower filing. However, if proven true, the implications extend far beyond a breach disclosure potentially involving deliberate concealment of nation-state compromises affecting federal systems and reshaping expectations around vendor transparency, breach notification, and federal contractor accountability. Vendor risk is not simply about security controls. It is also about disclosure culture and governance.</p><p><strong>UNC5221 / Verdant Bamboo: 18 Months Inside Microsoft 365, Re-Compromise After Remediation</strong></p><p>Researchers documented UNC5221 maintaining access inside Microsoft 365 environments for more than 18 months while deploying two previously undocumented malware families: Pleanit (.NET-based backdoor blending into legitimate Microsoft communications) and AgentPSD (Python-based reverse shell disguised as a PowerShell diagnostic utility). One victim was re-compromised after a complete remediation effort suggesting credentials were not fully rotated, persistence mechanisms were missed, or alternate pathways were retained. The campaign also leveraged MSP relationships, potentially expanding downstream exposure. MSP security reviews, tenant monitoring, identity hardening, and comprehensive credential rotation following IR are essential.</p><p><strong>OP512: 75-Day ICS Persistence Before Primary Operation Phase</strong></p><p>ReliaQuest documented OP512, a newly tracked Chinese threat cluster that maintained access to an IIS web server for 75 days before initiating its primary operation. The group targeted end-of-life .NET environments and deployed cryptographically unique web shells, timestamp manipulation, memory-only payloads, privilege escalation tooling, and in-memory persistence mechanisms including malware files designed to appear years older than they actually were to complicate forensic timeline reconstruction. Chinese operators continue winning not because of advanced exploits but because organizations continue running unsupported internet-facing infrastructure long after it should have been retired.</p><p><strong>JDY Botnet Doubles: 1,500 Compromised Devices Feeding Chinese Intelligence Reconnaissance</strong></p><p>A China-linked botnet known as JDY expanded from approximately 650 to more than 1,500 compromised devices targeting Ubiquiti, Hikvision, DrayTek, Linksys, and other internet-connected infrastructure, rapidly scanning newly disclosed vulnerabilities and feeding reconnaissance data to threat actors linked to Chinese intelligence operations.</p><h3><strong>&#129302; AI Infrastructure Under Attack</strong></h3><blockquote><p><em>&#8220;If vendors won&#8217;t compete on transparency voluntarily, make it a procurement requirement.&#8221;</em></p></blockquote><p><strong>Hugging Face Transformers CVE-2026-4372: 232 Million Installations, Exploit Bypasses Safety Control</strong></p><p>CVE-2026-4372 in Hugging Face Transformers (versions 4.56.0 through 5.2.x) allows arbitrary code execution through a maliciously crafted configuration file during model loading &#8212; and exploitation remains possible even when &#8220;trust_remote_code&#8221; is explicitly disabled, the control specifically intended to prevent these scenarios. This is one of the most significant AI security disclosures of the year given 232 million affected installations. AI models, configuration files, dependencies, and repositories are software supply chain assets requiring the same governance as traditional applications. Upgrade to Transformers version 5.3.0 and review all model ingestion workflows for externally sourced AI artifacts.</p><p><strong>Miasma Worm Expands Into AI Developer Toolchains: Claude Code, Gemini CLI, VS Code AI Extensions</strong></p><p>The Miasma supply chain worm expanded its targeting to include AI developer toolchains including Claude Code, Gemini CLI, and VS Code AI extensions. Once installed through a compromised npm package, Miasma harvests API keys, session tokens, local credentials, and development secrets, then propagates by modifying additional projects found on the infected machine and pushing malicious commits upstream under the victim&#8217;s legitimate identity. Modern AI development environments contain direct cloud infrastructure access, source code repositories, CI/CD pipelines, and production credentials. A single infected developer workstation can cascade into an entire organization&#8217;s software supply chain.</p><p><strong>Langflow CVE-2026-5027: 7,000 Internet-Accessible AI Agent Instances Under Active Attack</strong></p><p>Attackers are actively exploiting CVE-2026-5027 in Langflow, a path traversal vulnerability enabling arbitrary file writes combined with the platform&#8217;s default unauthenticated auto-login behavior. Approximately 7,000 internet-accessible Langflow instances were identified. Langflow deployments typically contain AI model credentials, API tokens, cloud service access, development secrets, and proprietary business logic. Upgrade immediately, disable auto-login, implement authentication controls, and inventory whether development teams are running unauthorized AI infrastructure.</p><p><strong>OpenClaw AI Agent: Five Zero-Days Patched</strong></p><p>Five vulnerabilities in OpenClaw&#8217;s AI agent framework integrating with Slack, Teams, and Discord allowing user impersonation through identity handling weaknesses were patched. All updates applied.</p><p><strong>OpenAI ChatGPT Lockdown Mode Launched</strong></p><p>OpenAI introduced ChatGPT Lockdown Mode, disabling outbound communications and browsing capabilities to mitigate prompt injection and data exfiltration attacks for sensitive use cases including government, legal, and financial workloads.</p><p><strong>OpenSSL Patches AI-Discovered Vulnerability</strong></p><p>OpenSSL patched 18 vulnerabilities including CVE-2026-45447, a high-severity use-after-free in PKCS#7 verification discovered with assistance from Anthropic&#8217;s Claude AI. Update OpenSSL dependencies across all enterprise applications.</p><p><strong>Anthropic Claude Fable 5 Jailbreak via Multi-Agent Decomposition</strong></p><p>Researchers bypassed safety controls in Claude Fable 5 using multi-agent decomposition, Unicode manipulation, and narrative framing, exposing system instructions and generating exploit-related content. Highlights ongoing challenges in AI safety engineering as capabilities advance.</p><h3><strong>&#129516; Supply Chain &amp; Developer Ecosystem</strong></h3><p><strong>Shai-Hulud Evolves: Miasma (npm) and Hades (PyPI) Infect 100+ Packages and 500+ Artifacts</strong></p><p>Two new Shai-Hulud derivatives Miasma targeting npm via weaponized binding.gyp files that bypass post-install detection, and Hades targeting PyPI environments including machine learning, bioinformatics, and MCP ecosystems have infected more than 100 packages and nearly 500 compromised artifacts. A single infected developer workstation or CI/CD runner becomes a malware distribution point for countless downstream organizations. Hunt for Miasma and Hades indicators, restrict package installation scripts in CI/CD, and prepare for npm version 12&#8217;s upcoming default disabling of install scripts and remote dependency resolution.</p><p><strong>Red Hat npm Miasma &#8220;Miasma&#8221; Campaign: 32 Packages, 117,000 Weekly Downloads</strong></p><p>The &#8220;Miasma&#8221; campaign compromised 32 official Red Hat npm packages originating through a compromised Red Hat employee GitHub account, then leveraging GitHub Actions OIDC workflows to distribute malware through trusted pipelines. AWS, Azure, GCP credentials, GitHub tokens, SSH keys, and npm tokens harvested. Rotate all cloud and development credentials from affected packages and review all build pipelines for compromise indicators.</p><p><strong>Gogs Zero-Day: Self-Hosted Git Repositories Vulnerable to Arbitrary Command Execution</strong></p><p>A critical argument injection vulnerability in Gogs allows attackers to execute arbitrary commands as the Git user, potentially accessing every repository on the platform. Gogs is frequently deployed by development teams without the governance applied to enterprise platforms, yet hosted repositories often contain source code, IaC, API keys, credentials, and internal documentation. Update to version 0.14.3 and audit all self-hosted code repositories.</p><p><strong><a href="http://polyfill.io/">Polyfill.io</a> Supply Chain Threat Returns on Toshiba, Muji, Samsung Smart TV Sites</strong></p><p>The compromised JavaScript CDN <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> resurfaced on websites associated with Toshiba, Muji, and Samsung Smart TV platforms, presenting fake authentication prompts. Supply chain compromises can persist long after initial disclosure. Remove all remaining references to <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> from web properties.</p><h3><strong>&#128165; Ransomware &amp; Destructive Operations</strong></h3><p><strong>ShinyHunters PeopleSoft Campaign: 300+ Instances, 100+ Organizations, ERP Data Theft</strong></p><p>ShinyHunters is actively targeting Oracle PeopleSoft environments through chained vulnerabilities combined with exposed administrative credentials attacking more than 300 PeopleSoft instances across 100+ organizations globally, including educational institutions. PeopleSoft contains employee records, payroll, tax data, financial operations, and student administration data. Attackers are establishing remote access via MeshCentral, running credential spraying against PSOFT/Oracle/Linux admin accounts, and creating long-term operational footholds not simply stealing data and leaving. Review published indicators of compromise, audit administrative accounts, search for unauthorized MeshCentral installations, and remove unnecessary PeopleSoft internet exposure immediately.</p><p><strong>SAP NetWeaver CVE-2026-44748 CVSS 9.9: SAML Identity Forgery</strong></p><p>SAP&#8217;s June patch day delivered 15 security notes including CVE-2026-44748 an XML Signature Wrapping vulnerability in NetWeaver&#8217;s SAML authentication framework allowing authenticated attackers to forge identity assertions while maintaining signature validation. Also notable: CVE-2026-27671 (CVSS 9.8), a memory corruption vulnerability in the SAP Kernel exploitable remotely without authentication. SAP systems control finance, procurement, logistics, and regulatory reporting. Prioritize these patches immediately and review SAML authentication configurations.</p><p><strong>Veeam Backup CVE-2026-44963: Any Authenticated Domain User Achieves RCE</strong></p><p>Veeam disclosed a CVSS 9.4 vulnerability in Backup &amp; Replication servers any authenticated domain user can potentially achieve remote code execution against domain-joined backup infrastructure. Ransomware operators specifically target backup platforms to eliminate recovery options. Patch immediately.</p><p><strong>NightSpire Ransomware: 175 Organizations, 28 Industries, Legitimate Tools Only</strong></p><p>NightSpire continues through legitimate tooling only exposed RDP and FortiOS for entry; Chrome Remote Desktop, AnyDesk for persistence; MegaSync for exfiltration. No custom malware, no EDR triggers. Audit exposed RDP, unauthorized remote administration software, and FortiOS patching status.</p><h3><strong>&#128275; Data Breaches &amp; Identity Exposures</strong></h3><blockquote><p><em>&#8220;Let&#8217;s say I&#8217;m a threat actor with this access and I can unlock all your doors. Now I can sell that access to a local crime group. They come in at midnight, raid your office, take everything they want and walk out. If I do that on a Friday night, you&#8217;re not going to find out until Monday morning. The connection between cyber threats and local gang monetization is one hundred percent real. Talk to your threat hunting team about this.&#8221;</em></p></blockquote><p><strong>ServiceNow Unauthenticated API Data Exposure &#8212; Then Narrative Revision</strong></p><p>ServiceNow disclosed attackers queried customer data through an improperly configured API endpoint before a June 5 security update was deployed. Depending on organizational use, exposed data could include employee records, asset inventories, security incidents, support tickets, operational workflows, and credentials shared during troubleshooting. ServiceNow&#8217;s disclosure remained largely behind customer login portals while practitioners reconstructed attack paths through public forums. Later, ServiceNow revised its position attributing observed activity to bug bounty researchers rather than malicious actors though questions about disclosure timelines and transparency remain. Review logs, investigate API endpoint access, and rotate credentials that may have been shared through support cases.</p><p><strong>Windows &#8220;Rogue Planet&#8221;: SYSTEM Privileges on Fully Patched Windows 10/11, No Patch Available</strong></p><p>Researcher Nightmare Eclipse released &#8220;Rogue Planet,&#8221; a proof-of-concept privilege escalation exploit achieving SYSTEM on fully patched Windows 10 and Windows 11 systems through a race condition involving Microsoft Defender effective even after June Patch Tuesday updates. Multiple independent researchers validated successful exploitation. No patch is available. Previous disclosures from Nightmare Eclipse (Green Plasma, Yellow Key, Red Sun, Blue Hammer, Undefend) have subsequently appeared in active exploitation campaigns. Assume any successful local code execution could escalate to full SYSTEM-level compromise and adjust EDR monitoring accordingly.</p><p><strong>Silent Ransom Group Targets Law Firms via Teams, Voice Phishing, 18-Country DNS Fast Flux</strong></p><p>The Silent Ransom Group (Luna Moth) combined Microsoft Teams messaging, voice phishing, and DNS Fast Flux infrastructure spanning 18 countries to target law firms for data theft and extortion. Law firms hold M&amp;A information, litigation strategies, attorney-client communications, and regulatory matters making them high-leverage targets. Security awareness programs focused exclusively on email are no longer aligned with today&#8217;s threat landscape. Teams-based phishing is an active, underdefended attack vector.</p><p><strong>French Government Messaging Platform Tchap Breached: 650,000 Messages, 73,000 Users</strong></p><p>France&#8217;s secure government messaging platform Tchap was compromised through a single account, allegedly exposing over 650,000 messages and 73,000 user records. One compromised identity creating disproportionate risk within centralized collaboration environments is a recurring pattern.</p><p><strong>Oxford Career Connect: Second Breach This Year</strong></p><p>Oxford University&#8217;s Career Connect platform suffered its second successful compromise of 2026, with attackers accessing student records, email addresses, degree information, and employment application history enabling highly targeted job-related phishing.</p><h3><strong>&#127760; Geopolitical &amp; Nation-State Threats</strong></h3><p><strong>Check Point VPN: Domain Controller Compromise in Under Four Hours</strong></p><p>Investigators documented attackers moving from Check Point VPN access to Domain Controller compromise in less than four hours. Historically, organizations measured dwell time in days or weeks. Sophisticated operators now achieve complete domain compromise within a single shift. Patch immediately, review logs, and implement additional authentication controls. VPN infrastructure must be treated as critical security infrastructure, not routine network equipment.</p><p><strong>Ubiquiti Unifi Vulnerability Chain: Unauthenticated Root Access + Physical Security Convergence</strong></p><p>Researchers disclosed a three-vulnerability chain in Ubiquiti Unifi OS allowing unauthenticated root-level access to controllers on the same network segment. Many organizations use Unifi to manage wireless networks, switching, security cameras, and physical access control systems simultaneously. Compromising the controller can provide operational control over doors, surveillance systems, and physical access infrastructure &#8212; not just network visibility. The convergence of cyber and physical security is no longer a future concern. Apply firmware updates, isolate management networks, and evaluate whether physical security systems share infrastructure with general IT operations.</p><p><strong>Gamaredon Deploys USB Worm, Telegram C2, and Wiper Against Ukraine</strong></p><p>Russia&#8217;s FSB-linked Gamaredon continued its WinRAR CVE-2025-8088 exploitation campaign delivering GammaLoad (downloader), GammaWorm (USB-propagating worm hiding via NTFS alternate data streams), GammaSteal (exfiltration to AWS S3 via Telegram C2), and GammaWipe (destructive wiper). Patch WinRAR for CVE-2025-8088, monitor Telegram outbound traffic, and watch for unexpected S3 uploads from endpoints.</p><p><strong>Five Eyes Advisory: China Systematically Recruiting Government Insiders via LinkedIn</strong></p><p>A joint advisory from intelligence agencies across the U.S., Canada, UK, Australia, and New Zealand documented Chinese intelligence systematically recruiting government employees, military personnel, contractors, and critical infrastructure workers through LinkedIn, Indeed, and Upwork &#8212; gradually escalating from harmless research to sensitive tasking, compensating through cryptocurrency and wire transfers, then migrating communications to Signal and Telegram. Classified access is not required. Facility layouts, contract details, budget information, and vendor relationships have significant intelligence value when aggregated. Communicate this advisory to all staff with sensitive access.</p><p><strong>Mustang Panda Returns with PlugX via Fake Adobe Prompts</strong></p><p>Chinese APT Mustang Panda resurfaced with fake Adobe Acrobat update prompts delivering PlugX malware using signed binaries and memory-only execution. Hunt for PlugX indicators across endpoints.</p><p><strong>North Korea Attributed with 47% of State-Sponsored Tech Sector Intrusions</strong></p><p>CrowdStrike attributed 47% of state-sponsored hands-on-keyboard intrusions against the technology sector to North Korean operators &#8212; many using deepfakes, stolen identities, and forged documentation to secure employment. Review hiring controls for remote technical positions and contractor onboarding procedures.</p><p><strong>SafeLove Stealer: Ukrainian Intelligence Targets Russian Military Through Romantic Personas</strong></p><p>Researchers disclosed SafeLove Stealer, targeting Russian military personnel through fake romantic personas to steal files, capture location data, access Telegram accounts, and activate microphones remotely for battlefield intelligence collection.</p><h3><strong>&#9878;&#65039; Policy, Privacy &amp; Industry</strong></h3><p><strong>Anthropic Mythos Expands to 150 Organizations Including NATO, Critical Infrastructure</strong></p><p>Anthropic&#8217;s Project Glasswing added 150 organizations across 15 countries &#8212; including NATO, ENISA, Samsung, healthcare providers, utilities, and critical infrastructure operators &#8212; to the Mythos vulnerability discovery platform. Mythos has identified 23,000+ potential vulnerabilities including thousands previously unknown. AI-assisted vulnerability discovery is becoming a strategic defensive advantage for organizations with access &#8212; and a structural risk for those without.</p><p><strong>Trump Signs Voluntary AI Security Review Executive Order</strong></p><p>President Trump signed an executive order establishing a voluntary 30-day federal review framework for advanced AI models, with national security risk evaluation, AI cybersecurity capability benchmarking, and an AI cybersecurity clearinghouse. The practical value depends on whether government oversight can evolve at the pace of AI development.</p><p><strong>Massachusetts Consumer Data Privacy Act Passes Unanimously</strong></p><p>Massachusetts unanimously passed the MCDPA introducing restrictions on geolocation tracking, biometric data collection, data minimization requirements, and private rights of action. Begin assessing compliance exposure for organizations operating in Massachusetts.</p><p><strong>European Commission Tech Sovereignty Package: Cloud and AI Localization Requirements</strong></p><p>The European Commission unveiled a technology sovereignty initiative including expanded semiconductor investments and new cloud and AI localization requirements designed to reduce European dependence on foreign infrastructure providers. Organizations operating across U.S. and European markets should prepare for data residency requirements, regional architecture segmentation, and regulatory divergence.</p><p><strong>Palantir CTO Reportedly Under Consideration for CISA Director</strong></p><p>Reports indicate Shyam Sankar, Palantir CTO, is being considered for the long-vacant CISA Director position. CISA has operated without Senate-confirmed leadership since January 2025 while facing some of the most active threat periods in recent memory.</p><p><strong>Proposal for Independent U.S. Cyber Force: 30,000 Personnel, $11 Billion</strong></p><p>A policy report recommended creating a dedicated U.S. Cyber Force. Supporters argue cyber operations have grown sufficiently large to justify their own military branch.</p><p><strong>WhatsApp v. NSO: Court Finds NSO in Contempt of Discovery Orders</strong></p><p>NSO Group was found in contempt of court for failing to provide required technical documentation about Pegasus spyware operations. WhatsApp also alleges it identified additional NSO activity occurring during the discovery process itself.</p><p><strong>NSA Appoints David Imbordino as Cyber Director, Bruce Jones to Lead CCC</strong></p><p>NSA formally filled key leadership positions ending a prolonged gap and restoring continuity for government-private sector cybersecurity partnerships.</p><p><strong>Adobe Patches 123 Vulnerabilities; ColdFusion Remains Highest Priority</strong></p><p>Adobe released fixes for 123 vulnerabilities across 11 products &#8212; 57 affecting Experience Manager alone, two critical RCE vulnerabilities. ColdFusion remains the highest-priority remediation target given its exploitation history.</p><h3><strong>&#9989; This Week&#8217;s Priority Action List</strong></h3><p><strong>Immediate (Do This Now)</strong></p><ul><li><p>Deploy Chrome 149.0.7827.102 or later and force restarts &#8212; fifth actively exploited zero-day of 2026</p></li><li><p>Patch SAP NetWeaver CVE-2026-44748 (CVSS 9.9 SAML forgery) and CVE-2026-27671 (CVSS 9.8 kernel RCE) &#8212; prioritize SAML configuration review</p></li><li><p>Patch Veeam Backup &amp; Replication CVE-2026-44963 immediately &#8212; any domain user achieves RCE against backup infrastructure</p></li><li><p>Patch SolarWinds Serv-U to 15.5.4 Hotfix 1 &#8212; CISA KEV, June 19 federal deadline</p></li><li><p>Upgrade Hugging Face Transformers to version 5.3.0 &#8212; 232 million installs, exploit bypasses trust_remote_code control</p></li><li><p>Patch Oracle WebLogic CVE-2024-21182 &#8212; CISA KEV, Cobalt Strike and ransomware deployment confirmed</p></li><li><p>Upgrade Langflow immediately and disable auto-login &#8212; 7,000 internet-accessible instances under active attack</p></li><li><p>Patch WordPress Kirki plugin to version 6.0.7 or disable &#8212; CVSS 9.8, one million sites, no credentials required</p></li><li><p>Apply Check Point VPN patches immediately &#8212; domain controller compromise documented in under four hours</p></li><li><p>Apply Ubiquiti Unifi firmware updates and isolate management networks &#8212; three-vulnerability root access chain with physical security implications</p></li><li><p>Patch WinRAR CVE-2025-8088 &#8212; Gamaredon actively exploiting for USB worm and wiper deployment</p></li><li><p>Update Gogs to version 0.14.3 &#8212; arbitrary command execution as Git user</p></li><li><p>Review PeopleSoft environments for MeshCentral installations and ShinyHunters IOCs &#8212; 300+ instances actively targeted</p></li></ul><p><strong>Short-Term (This Month)</strong></p><ul><li><p>Upgrade Cisco SD-WAN with all available compensating controls &#8212; seventh zero-day, no patch, root code execution</p></li><li><p>Hunt for UNC5221 / Verdant Bamboo indicators within Microsoft 365 tenants &#8212; rotate all credentials following any IR</p></li><li><p>Implement Arista EOS ACL mitigations &#8212; no patch planned, exploit active, tunnel bypass in production</p></li><li><p>Monitor for Miasma and Hades supply chain worm indicators &#8212; rotate all npm and PyPI-related credentials</p></li><li><p>Remove all <strong><a href="http://polyfill.io/">Polyfill.io</a></strong> references from web properties &#8212; resurfaced on Toshiba, Muji, Samsung platforms</p></li><li><p>Patch Adobe ColdFusion &#8212; highest-priority given exploitation history</p></li><li><p>Update OpenSSL dependencies across enterprise applications &#8212; AI-discovered use-after-free in PKCS#7</p></li><li><p>Review ServiceNow instance logs and rotate credentials shared through support cases</p></li><li><p>Restrict ASUS router management interfaces to trusted networks &#8212; patches expected end of June</p></li><li><p>Remove ATG fuel monitoring systems from internet exposure</p></li><li><p>Brief all staff with sensitive access on Five Eyes China LinkedIn insider recruitment advisory</p></li><li><p>Train employees on Teams-based phishing and voice phishing &#8212; email-only awareness programs are misaligned with current threat landscape</p></li></ul><p><strong>Strategic (This Quarter)</strong></p><ul><li><p>Assess governance controls around AI model ingestion and deployment &#8212; Transformers exploit bypasses the dedicated safety control</p></li><li><p>Treat &#8220;no patch available&#8221; scenarios as requiring elevated compensating controls and monitoring &#8212; Cisco SD-WAN, Arista EOS, Rogue Planet are all current examples</p></li><li><p>Begin compliance assessment for Massachusetts Consumer Data Privacy Act and European Tech Sovereignty localization requirements</p></li><li><p>Prepare for npm version 12 security changes &#8212; test compatibility now before mandatory rollout</p></li><li><p>Expand insider threat monitoring to include financial market abuse, prediction markets, and LinkedIn recruitment scenarios</p></li><li><p>Evaluate physical security and IT infrastructure separation &#8212; Unifi root access with door/camera control convergence is the operational model for why this matters</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56/comments"><span>Leave a comment</span></a></p><h3><strong>&#127897;&#65039; James Azar&#8217;s CISO&#8217;s Take</strong></h3><p>When I look across this week&#8217;s four episodes, the most important shift is the phrase that kept appearing: &#8220;no patch currently available.&#8221; Cisco&#8217;s seventh SD-WAN zero-day. Rogue Planet on fully patched Windows. Arista EOS with ACLs as the only mitigation. ASUS routers waiting until end of June. This is not occasional, it is becoming a recurring operational condition. Security programs built entirely around the patch-it-and-move-on model are increasingly operating in a world that no longer exists. Organizations must mature disciplines that have historically been secondary: network segmentation, behavioral monitoring, compensating controls, and rapid detection because when the patch doesn&#8217;t exist yet, those capabilities are all you have. The fundamentals have always mattered. They matter more now than they ever have.</p><p>The second major takeaway is that the attack surface has expanded permanently in ways that most security programs have not fully internalized. The Ubiquiti vulnerability chain demonstrates that a network compromise can now become a physical security incident unlocking doors, disabling cameras, and enabling physical theft. Miasma expanding into Claude Code and Gemini CLI demonstrates that AI development toolchains are now primary attack surfaces indistinguishable from traditional software supply chains. The IBM/AT&amp;T whistleblower allegations demonstrate that vendor risk is also about disclosure culture whether your trusted partners will tell you the truth when something goes wrong. These are not edge cases. They are the operational reality security leaders need to be managing today.</p><h3><strong>&#128203; Week in Summary</strong></h3><p>This was the week &#8220;no patch available&#8221; became a defining operational condition rather than an exception. Cisco SD-WAN logged its seventh zero-day of 2026 with no remediation path. Rogue Planet achieved SYSTEM on fully patched Windows through a race condition Microsoft hadn&#8217;t addressed. Arista&#8217;s EOS tunnel bypass received ACLs as the permanent mitigation because no patch is planned. And Hugging Face Transformers with 232 million installations received a critical RCE disclosure where exploitation bypasses the safety control specifically designed to prevent it. Against that backdrop, Chrome logged its fifth actively exploited zero-day of 2026, ShinyHunters hit 300-plus PeopleSoft instances, SAP released a CVSS 9.9 SAML forgery vulnerability, and Veeam backup servers were found vulnerable to RCE by any authenticated domain user.</p><p>The human and physical dimensions were equally significant. Check Point VPN attackers moved from initial access to domain controller compromise in under four hours demonstrating that attacker velocity in 2026 is measured in hours, not days. A federal whistleblower alleged that IBM and AT&amp;T concealed APT10 intrusions affecting federal systems for years to protect billion-dollar contracts, a reminder that vendor risk is also about disclosure culture. Ubiquiti&#8217;s three-vulnerability chain showed that compromising a network controller can mean unlocking doors. And a Five Eyes advisory documented China&#8217;s systematic LinkedIn recruitment of government insiders at scale. The attack surface is fully multi-domain. The organizations that adapt their security programs to that reality will be the ones that remain standing.</p><p>Stay informed. Stay prepared. <strong>Stay Cyber Safe.</strong> &#128272;</p><p><em>&#169; CyberHub Podcast | Subscribe on Substack | Watch on YouTube | Follow on LinkedIn</em></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-56?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Nightmare Eclipse Drops 7th Windows Zero-Day RoguePlanet, CrowdStrike: North Korea Behind 47% of All State-Backed Tech Sector Attacks, ShinyHunters Hack Oracle PeopleSoft Servers at 100+ Orgs ]]></title><description><![CDATA[Nightmare Eclipse Drops Another Windows 0-Day, ShinyHunters Targets 100+ PeopleSoft Organizations, and North Korea Dominates Global Cyber Intrusions]]></description><link>https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Thu, 11 Jun 2026 13:30:35 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201549347/07705b40b73d050f34e3e270257bd74a.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode reinforced a trend we&#8217;ve been discussing for months:</p><p><strong>Attackers are industrializing the gap between disclosure, patching, and remediation faster than defenders can close it.</strong></p><p>Today&#8217;s show featured four major stories demanding immediate attention before lunch. ShinyHunters is actively exploiting Oracle PeopleSoft environments through a sophisticated zero-day chain affecting more than 100 organizations. The researcher known as Nightmare Eclipse has released yet another Windows privilege escalation zero-day called Rogue Planet that works on fully patched Windows systems. CISA expanded its Known Exploited Vulnerabilities catalog with active Cisco, Chrome, and Arista vulnerabilities, while attackers continue exploiting vulnerable Langflow AI deployments exposed to the internet.</p><p>Layered on top of those developments were emerging threats targeting AI platforms, critical infrastructure systems, developer ecosystems, and remote hiring processes. If yesterday&#8217;s theme was concentration of risk, today&#8217;s theme is operational tempo. Attackers are moving faster, exploiting faster, and scaling their operations faster than many organizations are prepared to respond.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape revealed a cybersecurity ecosystem under sustained pressure from both criminal and nation-state actors.</p><p>ShinyHunters continues expanding its campaign against Oracle PeopleSoft environments using chained zero-days and legitimate administration tools. Meanwhile, Microsoft&#8217;s ongoing public dispute with security researcher Nightmare Eclipse has produced yet another publicly released Windows zero-day with no available patch. Organizations are also facing active exploitation of AI development platforms, growing reconnaissance activity from Chinese botnets, and an increasing number of situations where vendors are telling customers that no patch is currently available.</p><p>The challenge facing security teams is no longer simply identifying vulnerabilities. It is managing an environment where attackers are often weaponizing flaws before defenders have practical remediation options.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cjzi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cjzi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cjzi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:213507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/201549347?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cjzi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!cjzi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5f17bf-61f7-4c73-b8fd-97cf55f66893_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#127963;&#65039; ShinyHunters Launches Large-Scale PeopleSoft Data Theft Campaign</h2><p>The biggest story of the day involves the ShinyHunters extortion group actively targeting Oracle PeopleSoft environments through a sophisticated chain of old and new vulnerabilities. Researchers report attacks affecting more than 300 PeopleSoft instances across over 100 organizations globally.</p><p>PeopleSoft remains one of the most widely deployed enterprise resource planning platforms in the world, supporting human resources, payroll, finance, procurement, and student administration systems. In many organizations, PeopleSoft contains some of the most sensitive data available, including employee records, payroll information, tax data, and financial operations.</p><p>Researchers discovered evidence suggesting attackers are leveraging multiple vulnerabilities combined with exposed administrative credentials and configuration weaknesses rather than relying on a single flaw. Evidence recovered from exposed attacker infrastructure revealed MeshCentral remote management tools, credential spraying scripts, and automated shell scripts targeting common administrative accounts such as PSOFT, Oracle, and Linux administration accounts.</p><p>Several educational institutions appear to be among the victims, with Nottingham University publicly acknowledging an incident after its data appeared on ShinyHunters&#8217; leak site.</p><p>The broader concern here is persistence. These attackers are not simply stealing data and leaving. They are establishing remote access, maintaining footholds, and creating long-term operational access into business-critical ERP environments.</p><p>Organizations should immediately review published indicators of compromise, audit administrative accounts, search for unauthorized MeshCentral installations, and remove unnecessary internet exposure from PeopleSoft environments.</p><h2>&#128680; Rogue Planet Gives Attackers SYSTEM Access on Fully Patched Windows Machines</h2><p>Security researcher Nightmare Eclipse released a new proof-of-concept exploit known as Rogue Planet that enables local privilege escalation to SYSTEM privileges on fully patched Windows 10 and Windows 11 systems.</p><p>The vulnerability exploits a race condition involving Microsoft Defender and remains effective even after organizations deployed Microsoft&#8217;s June 2026 Patch Tuesday updates. Multiple independent researchers have reportedly validated successful exploitation.</p><p>What makes this disclosure particularly significant is the context surrounding it. Rogue Planet follows a series of highly publicized disclosures from Nightmare Eclipse, including Green Plasma, Yellow Key, Red Sun, Blue Hammer, and Undefend. Several of those vulnerabilities were later observed in active exploitation campaigns.</p><p>At the center of the controversy is an increasingly public disagreement between Microsoft and the researcher regarding vulnerability disclosure processes. Microsoft previously suspended the researcher&#8217;s GitHub account, only to see the exploit quickly reappear elsewhere.</p><p>For defenders, the practical challenge remains straightforward. There is currently no patch available.</p><p>Organizations should assume any successful local code execution could potentially become full SYSTEM-level compromise and adjust endpoint detection and response monitoring accordingly.</p><h2>&#128203; CISA Adds Cisco, Chrome, and Arista Vulnerabilities to KEV Catalog</h2><p>CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog, highlighting continued attacker focus on browsers and network infrastructure.</p><p>The first vulnerability affects Cisco Catalyst SD-WAN Manager and allows authenticated attackers to execute arbitrary commands as root through crafted file uploads. The second is Chrome&#8217;s recently disclosed V8 out-of-bounds memory vulnerability, which allows arbitrary code execution through malicious web content.</p><p>The third vulnerability may be the most operationally challenging. Affecting Arista EOS deployments configured as tunnel endpoints, the flaw allows unexpected tunneled traffic to bypass intended protocol validation controls. Arista&#8217;s mitigation guidance relies entirely on access control lists because no patch is currently planned.</p><p>This story reinforces an uncomfortable trend emerging throughout 2026. Increasingly, organizations are being told to rely on mitigations because patches either do not exist or may never arrive.</p><p>Security leaders should ensure KEV remediation timelines receive executive-level visibility because attackers continue prioritizing vulnerabilities after they are added to the catalog.</p><h2>&#129302; Attackers Actively Exploiting Langflow AI Platform</h2><p>Langflow, the popular open-source platform used to build AI agents and Retrieval Augmented Generation workflows, is now under active attack. Researchers observed exploitation of CVE-2026-5027, a path traversal vulnerability allowing arbitrary file writes to vulnerable servers.</p><p>The vulnerability stems from improper filename sanitization within Langflow&#8217;s file upload functionality. Combined with the platform&#8217;s default unauthenticated auto-login behavior, attackers can obtain valid session tokens and begin exploitation without authentication.</p><p>Security researchers identified approximately 7,000 internet-accessible Langflow instances during the past year, creating a substantial attack surface for adversaries.</p><p>The risk extends beyond simple file manipulation. Langflow deployments frequently contain:</p><ul><li><p>AI model credentials</p></li><li><p>API tokens</p></li><li><p>Cloud service access</p></li><li><p>Development secrets</p></li><li><p>Workflow data</p></li><li><p>Proprietary business logic</p></li></ul><p>As organizations rush to deploy AI tooling, many continue doing so outside traditional security governance processes. That creates exactly the type of environment attackers prefer.</p><p>Organizations should upgrade immediately, disable auto-login, implement authentication controls, and determine whether development teams are running unauthorized AI infrastructure.</p><h1>&#9889; Need to Know</h1><h3>&#128260; ServiceNow Revises Its Earlier Security Incident Narrative</h3><p>ServiceNow updated its position regarding recently disclosed customer data access concerns. The company now attributes observed activity to security researchers participating in bug bounty activities rather than malicious attackers, though questions remain regarding disclosure timelines and communication practices. Organizations should still review logs and understand their exposure.</p><h3>&#127981; Critical Data Center Infrastructure Vulnerabilities Disclosed</h3><p>Researchers identified critical vulnerabilities affecting Vertiv UPS network management cards and Trane HVAC management systems commonly deployed in data centers. The vulnerabilities include authentication bypass and remote code execution capabilities. Organizations should remember that operational technology and facilities systems remain part of the cyber attack surface.</p><h3>&#127464;&#127475; Chinese JDY Botnet Doubles in Size</h3><p>A China-linked botnet known as JDY has expanded from roughly 650 compromised devices to more than 1,500. The botnet targets Ubiquiti, Hikvision, DrayTek, Linksys, and other internet-connected infrastructure, rapidly scanning newly disclosed vulnerabilities and feeding reconnaissance information to threat actors including groups linked to Chinese intelligence operations.</p><h3>&#128230; npm Tightens Supply Chain Security</h3><p>Upcoming npm version 12 will disable automatic execution of install scripts and restrict remote dependency resolution by default. These changes would have significantly reduced the effectiveness of recent Shai-Hulud supply chain campaigns. Organizations should begin testing compatibility now.</p><h3>&#129302; Anthropic&#8217;s Claude Faces Another Jailbreak</h3><p>Researchers successfully bypassed safety controls in Anthropic&#8217;s Claude Fable 5 model using multi-agent decomposition techniques, Unicode manipulation, and narrative framing approaches. The attack exposed significant portions of the model&#8217;s system instructions and generated exploit-related content.</p><h3>&#127852; Australian Sugar Producer Hit by Cyberattack</h3><p>Mackay Sugar, Australia&#8217;s second-largest sugar producer, suffered a cyber incident that disrupted harvesting operations and impacted production facilities. While ransomware has not been confirmed, the event demonstrates the immediate operational consequences cyber incidents can have within industrial environments.</p><h3>&#127472;&#127477; North Korea Responsible for Nearly Half of Technology Intrusions</h3><p>CrowdStrike&#8217;s latest threat report attributes 47% of state-sponsored hands-on-keyboard intrusions against the technology sector to North Korean operators. Many campaigns involve fake remote workers using deepfakes, stolen identities, and forged documentation to secure employment while collecting data and generating revenue for the regime.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode highlighted a reality that many security teams are already experiencing.</p><p>The traditional sequence of disclosure, patch development, testing, deployment, and remediation is increasingly being compressed or bypassed entirely. Attackers are exploiting vulnerabilities before patches exist, targeting platforms where mitigations are the only available option, and scaling operations through automation and supply chain compromise.</p><p>Defenders are increasingly operating on attacker timelines rather than vendor timelines.</p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how often we heard the phrase &#8220;no patch available.&#8221; Whether it was Rogue Planet, the Arista EOS issue, or the broader challenges around AI infrastructure, organizations are increasingly being asked to rely on monitoring, segmentation, hardening, and compensating controls rather than traditional patching. That&#8217;s a significant shift in defensive strategy. For years we&#8217;ve taught security teams that patching is the answer. Increasingly, patching isn&#8217;t immediately available, forcing organizations to mature operational security disciplines that many have historically neglected.</p><p>The second takeaway is the growing industrialization of cyber operations. ShinyHunters isn&#8217;t manually targeting organizations one at a time. Chinese reconnaissance infrastructure isn&#8217;t casually scanning the internet. North Korean operators aren&#8217;t running isolated campaigns. These are highly organized, repeatable, scalable operations designed to identify opportunities and exploit them at speed. Defenders must begin thinking at the same scale because the attackers already are.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows/comments"><span>Leave a comment</span></a></p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Review PeopleSoft environments for published indicators of compromise</p></li><li><p>Audit administrative credentials and remove unnecessary PeopleSoft internet exposure</p></li><li><p>Increase monitoring for SYSTEM-level process creation on Windows endpoints</p></li><li><p>Patch Chrome immediately and review Cisco SD-WAN exposure</p></li><li><p>Apply Arista mitigation guidance where applicable</p></li><li><p>Upgrade Langflow deployments and disable auto-login functionality</p></li><li><p>Review ServiceNow advisory information and instance logs</p></li><li><p>Patch Vertiv and Trane management infrastructure</p></li><li><p>Inventory internet-facing IoT and edge devices</p></li><li><p>Prepare development teams for upcoming npm security changes</p></li><li><p>Review hiring controls for remote technical positions and contractor onboarding</p></li></ul><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/nightmare-eclipse-drops-7th-windows?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[June Patch Tuesday: Microsoft Fixes 200 Flaws Including 3 Publicly Disclosed Zero-Days,| Google Patches 5th Chrome Zero-Day of 2026, ServiceNow Discloses Security Incident Exposing Customer Data ]]></title><description><![CDATA[Patch Tuesday Delivers 200 Fixes, Chrome's 5th Zero-Day of 2026, and ServiceNow Faces Tough Questions on Transparency]]></description><link>https://www.cyberhubpodcast.com/p/june-patch-tuesday-microsoft-fixes</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/june-patch-tuesday-microsoft-fixes</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Wed, 10 Jun 2026 13:30:31 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201399967/f85fbbca7b2e0c991673e10a71a3bff4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today was one of those days where cybersecurity professionals everywhere should be paying very close attention.</p><p>Patch Tuesday arrived with more than 200 Microsoft fixes, three publicly disclosed zero-days, SAP released multiple critical vulnerabilities affecting some of the most sensitive business systems on the planet, Google patched its fifth actively exploited Chrome zero-day of the year, and ServiceNow disclosed a customer data exposure incident that raises serious questions about how enterprise software vendors communicate security events to their customers.</p><p>At the same time, supply chain attacks continue evolving at an alarming pace. New variants of the Shai-Hulud worm are actively spreading across npm and PyPI ecosystems, infecting hundreds of packages and targeting the very developers responsible for building and maintaining modern applications. If there was a common theme throughout today&#8217;s show, it was concentration of risk. The browser, the ERP platform, the IT service management system, the package repository, the backup platform&#8212;these shared pieces of infrastructure have become some of the most attractive targets in cybersecurity.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s cybersecurity landscape was dominated by patching priorities and software ecosystem risk.</p><p>Google addressed another actively exploited Chrome vulnerability, bringing the total number of Chrome zero-days exploited in the wild this year to five. SAP released several critical vulnerabilities affecting NetWeaver and Commerce environments that sit at the heart of many global enterprises. Microsoft delivered more than 200 security fixes, including three publicly disclosed zero-days. Meanwhile, ServiceNow confirmed attackers accessed customer data through an improperly exposed API endpoint, sparking concerns over disclosure practices and transparency.</p><p>Layered on top of those issues, new variants of the Shai-Hulud supply chain worm are spreading aggressively across software development ecosystems, demonstrating once again that attackers increasingly prefer targeting the systems used to build software rather than the software itself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Et6Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Et6Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Et6Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180432,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/201399967?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Et6Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Et6Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2a28e18-b2f1-47ce-a017-e7c33d366cb1_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#127760; Chrome Patches Fifth Actively Exploited Zero-Day of 2026</h2><p>Google released an emergency security update addressing seventy-four vulnerabilities, including CVE-2026-111645, a high-severity out-of-bounds memory flaw in Chrome&#8217;s V8 JavaScript and WebAssembly engine. The vulnerability is actively being exploited in the wild and allows attackers to execute arbitrary code through a malicious webpage with nothing more than a victim visiting a compromised website.</p><p>This vulnerability carries a CVSS score of 8.8 and was responsibly disclosed by researcher 303f6e3, who received a $55,000 bounty for the discovery. What makes this story significant isn&#8217;t simply the vulnerability itself&#8212;it&#8217;s the pattern. This marks Google&#8217;s fifth actively exploited Chrome zero-day of 2026, and we&#8217;re only halfway through the year.</p><p>The browser has effectively become the operating system for modern work. It holds access to SaaS platforms, authentication tokens, cloud environments, financial systems, and collaboration tools. An exploited browser vulnerability is no longer simply a browser problem, it is often the first step toward enterprise compromise.</p><p>Organizations should immediately deploy Chrome version 149.0.7827.102 or later and ensure browsers are actually restarted, not simply updated in the background.</p><h2>&#127970; SAP Releases Critical NetWeaver and Commerce Security Updates</h2><p>SAP&#8217;s June Security Patch Day delivered fifteen security notes, including four critical vulnerabilities affecting NetWeaver, Commerce Cloud, and Data Hub environments. The most severe issue, CVE-2026-44748, received a CVSS score of 9.9 and involves XML Signature Wrapping within NetWeaver&#8217;s SAML authentication framework.</p><p>The vulnerability allows an authenticated attacker to manipulate identity assertions while maintaining signature validation, effectively enabling identity forgery within SAP environments. Also notable is CVE-2026-27671, a 9.8-rated memory corruption vulnerability affecting the SAP Kernel that can be exploited remotely by unauthenticated attackers.</p><p>These vulnerabilities matter because SAP systems often sit at the center of enterprise operations. Finance, procurement, logistics, supply chain management, customer transactions, and regulatory reporting frequently depend on SAP infrastructure. Historically, SAP vulnerabilities have transitioned from disclosure to active exploitation remarkably quickly.</p><p>Organizations should prioritize these patches immediately and review SAML authentication configurations while remediation is underway.</p><h2>&#128680; ServiceNow Customer Data Exposure Raises Transparency Questions</h2><p>One of the most important stories of the day involved ServiceNow&#8217;s disclosure that attackers successfully queried customer data through an improperly configured API endpoint before a security update was deployed on June 5th.</p><p>The exposed endpoint reportedly allowed unauthenticated access under certain configurations and may have provided access to information stored within customer ServiceNow instances. Depending on how organizations use ServiceNow, exposed data could include employee records, asset inventories, security incidents, support tickets, operational workflows, and potentially credentials or API tokens shared during troubleshooting processes.</p><p>The issue extends beyond the vulnerability itself. ServiceNow&#8217;s disclosure remains largely behind customer login portals, while practitioners on public forums such as Reddit have been forced to reconstruct the attack path, identify indicators of compromise, and determine what logs should be reviewed.</p><p>For many security leaders, this raises an increasingly common concern. Enterprise software vendors often hold enormous amounts of customer data, yet public disclosure practices frequently lag behind expectations for transparency and incident response communication.</p><blockquote><p><em>&#8220;If vendors won&#8217;t compete on transparency voluntarily, make it a procurement requirement.&#8221; James Azar</em></p></blockquote><p>Organizations should review ServiceNow logs immediately, investigate access to API endpoints, and rotate credentials that may have been shared through support cases.</p><h2>&#129516; Shai-Hulud Worm Evolves Into Miasma and Hades</h2><p>Supply chain attacks continue evolving with the emergence of two new Shai-Hulud derivatives: Miasma and Hades. Researchers report that these campaigns have already infected more than one hundred packages across npm and PyPI ecosystems.</p><blockquote><p><em>&#8220;The browser is now the front door to every SaaS app, credential, and session token your workforce touches.&#8221; James Azar</em></p></blockquote><p>Miasma focuses on npm environments and executes during package installation through a weaponized binding.gyp file, bypassing many traditional post-install detection mechanisms. Once executed, it scans local systems, cloud environments, API credentials, and authentication tokens before propagating into additional packages that the victim is capable of publishing.</p><p>The PyPI variant, Hades, operates similarly and has targeted machine learning, bioinformatics, graph analysis, and Model Context Protocol (MCP) ecosystems. Researchers have already identified hundreds of malicious package versions and nearly five hundred compromised artifacts across both ecosystems.</p><p>The significance of this attack lies in its self-propagating nature. A single infected developer workstation or CI/CD runner can rapidly become a distribution point for malware affecting countless downstream organizations.</p><h1>&#9889; Need to Know</h1><h3>&#129695; Microsoft Patch Tuesday Delivers More Than 200 Fixes</h3><p>Microsoft released patches for more than 200 vulnerabilities, including three publicly disclosed zero-days. Notable vulnerabilities include the CTFMON privilege escalation flaw, the HTTP/2 Bomb denial-of-service issue, and the BitLocker bypass vulnerability known as Yellow Key. Organizations should prioritize Active Directory, Exchange, Office, and Windows infrastructure updates.</p><h3>&#128190; Veeam Backup Servers Exposed to Remote Code Execution</h3><p>Veeam disclosed CVE-2026-44963, a critical 9.4-rated vulnerability affecting Backup &amp; Replication servers. Any authenticated domain user can potentially achieve remote code execution against domain-joined backup infrastructure. Since backup platforms remain one of ransomware operators&#8217; favorite targets, immediate patching is strongly recommended.</p><h3>&#127912; Adobe Patches 123 Vulnerabilities</h3><p>Adobe released fixes for 123 vulnerabilities across eleven products. Fifty-seven of those vulnerabilities affect Experience Manager alone. Two critical remote code execution flaws received maximum severity ratings. ColdFusion remains the highest-priority remediation target due to its history of exploitation.</p><h3>&#128274; OpenSSL Fixes AI-Discovered Vulnerability</h3><p>OpenSSL patched eighteen vulnerabilities, including CVE-2026-45447, a high-severity use-after-free vulnerability within PKCS#7 verification processes. Notably, the vulnerability was discovered with assistance from Anthropic&#8217;s Claude AI, highlighting how AI is increasingly contributing to vulnerability discovery efforts.</p><h3>&#127467;&#127479; French Government Messaging Platform Breached</h3><p>France&#8217;s secure government messaging platform, Tchap, suffered a breach through a compromised account that allegedly exposed over 650,000 messages and information relating to more than 73,000 user accounts. The incident demonstrates how a single compromised identity can create disproportionate risk within centralized collaboration environments.</p><h3>&#127919; Ukrainian Intelligence Uses Romance-Themed Mobile Malware</h3><p>Researchers disclosed a campaign known as SafeLove Stealer, which targets Russian military personnel through fake romantic personas. The malware steals files, captures location information, accesses Telegram accounts, and can remotely activate microphones. The operation appears designed to collect battlefield intelligence and operational information.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t really about Patch Tuesday.</p><p>It was about concentration risk.</p><p>Organizations have centralized enormous amounts of trust into browsers, ERP systems, ticketing platforms, package repositories, backup infrastructure, and collaboration tools. Attackers understand this. Rather than attacking thousands of individual systems, they increasingly target the shared infrastructure everyone depends on.</p><p>That strategy continues proving remarkably effective.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Deploy Chrome 149.0.7827.102 or later across all endpoints</p></li><li><p>Force browser restarts after Chrome updates</p></li><li><p>Prioritize SAP NetWeaver and Commerce patch deployment</p></li><li><p>Review ServiceNow logs for unauthorized API activity</p></li><li><p>Rotate credentials stored within support tickets and workflows</p></li><li><p>Hunt for indicators of Miasma and Hades package infections</p></li><li><p>Restrict package installation scripts in CI/CD environments</p></li><li><p>Patch Microsoft June Patch Tuesday vulnerabilities</p></li><li><p>Upgrade Veeam Backup &amp; Replication immediately</p></li><li><p>Prioritize Adobe ColdFusion remediation</p></li><li><p>Update OpenSSL dependencies across enterprise applications</p></li><li><p>Review centralized collaboration platforms for excessive privilege assignments</p></li></ul><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how concentrated cybersecurity risk has become. Whether we&#8217;re talking about Chrome, SAP, ServiceNow, npm, Veeam, or OpenSSL, we&#8217;re discussing technologies that sit at the center of thousands of organizations simultaneously. Attackers no longer need to target every company individually. They simply need to identify the shared platforms that everyone relies upon and focus their efforts there. The economics of cybercrime increasingly favor concentration, and that&#8217;s exactly what we&#8217;re seeing.</p><p>The second takeaway is that transparency continues to matter just as much as technology. The ServiceNow incident raises difficult questions about how vendors communicate security events. Security leaders depend on accurate, timely information to make risk decisions. When disclosure is delayed, hidden behind portals, or lacks publicly available guidance, defenders lose valuable time. As customers, we need to start making transparency part of our procurement process because incident communication is now a security control in its own right.</p><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/june-patch-tuesday-microsoft-fixes?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/june-patch-tuesday-microsoft-fixes?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/june-patch-tuesday-microsoft-fixes?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[WhatsApp Catches NSO Group Defying Court Injunction, Microsoft Open Source Developer Tools Hacked, Point Links VPN Zero-Day Attacks to Qilin Ransomware Gang ]]></title><description><![CDATA[WhatsApp Catches NSO Defying Court Orders, AI Developer Supply Chains Under Siege, and Europe Accelerates Tech Sovereignty]]></description><link>https://www.cyberhubpodcast.com/p/whatsapp-catches-nso-group-defying</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/whatsapp-catches-nso-group-defying</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Tue, 09 Jun 2026 13:30:41 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201237480/e5f33a43de17e8f593f7c90c364b3a74.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s show highlighted a reality many organizations are still struggling to accept:</p><div class="callout-block" data-callout="true"><p><strong>The attack surface is no longer limited to infrastructure it now includes developers, collaboration platforms, AI tooling, physical security systems, legal firms, and even regulatory frameworks.</strong></p></div><p>Today&#8217;s stories painted a picture of an ecosystem under pressure from every direction. We saw AI developer environments targeted by self-propagating supply chain malware, VPN vulnerabilities being weaponized for rapid domain compromise, Chinese threat actors quietly persisting inside internet-facing servers for months at a time, and criminal groups blending Teams-based phishing with global botnet infrastructure to extort law firms.</p><p>At the same time, governments are moving aggressively on privacy, technology sovereignty, and cybersecurity governance. Massachusetts passed what may become the most impactful state privacy law in the country, while Europe unveiled a sweeping plan designed to reduce dependence on foreign cloud providers, semiconductor manufacturers, and AI infrastructure.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape reveals three dominant trends.</p><p>First, developer ecosystems have become primary targets. Attackers increasingly recognize that compromising the tools developers use provides access to source code, secrets, cloud infrastructure, AI environments, and software supply chains.</p><p>Second, nation-state actors continue demonstrating extraordinary patience. Chinese operators are spending months inside environments before taking action, leveraging custom tooling, memory-only execution, and persistence techniques that routinely evade traditional detection methods.</p><p>Finally, governments are no longer treating privacy and digital sovereignty as optional policy discussions. Regulatory requirements around data handling, localization, and infrastructure ownership are becoming strategic business issues with significant operational implications.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OBu3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OBu3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OBu3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171277,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/201237480?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OBu3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!OBu3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09be2969-475b-4bb6-97aa-c8c2fd56937d_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#129516; Miasma Worm Expands Into AI Developer Toolchains</h2><p>The most significant supply chain story today involves the continued evolution of the Miasma worm. While we discussed Miasma last week, researchers now report that the malware has expanded its targeting to include AI developer ecosystems such as Claude Code, Gemini CLI, VS Code AI extensions, and other AI-assisted coding environments.</p><p>Unlike traditional malicious packages, Miasma behaves as a true worm. Once installed through a compromised npm package, it begins harvesting API keys, session tokens, local credentials, and development secrets. It then propagates itself by modifying additional projects found on the compromised machine and pushing malicious commits upstream under the victim&#8217;s legitimate identity.</p><p>The significance of this attack cannot be overstated. Modern development environments increasingly contain direct access to:</p><ul><li><p>Cloud infrastructure</p></li><li><p>Source code repositories</p></li><li><p>CI/CD pipelines</p></li><li><p>AI models</p></li><li><p>Production credentials</p></li></ul><p>A single infected developer workstation can rapidly become an entry point into an entire organization&#8217;s software supply chain.</p><p>This is precisely why software supply chain security has become one of the most critical areas of cybersecurity investment. Attackers are no longer attacking applications, they&#8217;re attacking the people and tools responsible for building them.</p><h2>&#128680; Check Point VPN Vulnerability Enables Domain Takeover in Under Four Hours</h2><p>Check Point issued emergency guidance for a critical vulnerability affecting VPN infrastructure after investigators documented attackers moving from VPN access to Domain Controller compromise in less than four hours.</p><p>The attack chain demonstrates how dramatically attacker speed has evolved. Historically, organizations measured dwell time in days, weeks, or even months. Today, sophisticated operators can move from initial access to complete domain compromise during a single shift.</p><p>The vulnerability is particularly concerning because VPN appliances remain one of the most attractive targets available to attackers. They sit directly on the network edge, often possess privileged connectivity, and frequently serve as the first point of entry into enterprise environments.</p><p>Organizations that still treat VPN infrastructure as routine network equipment rather than critical security infrastructure are increasingly taking unnecessary risk.</p><p>Immediate patching, log review, and additional authentication controls should be considered mandatory.</p><h2>&#128275; Ubiquiti Unifi Vulnerabilities Create Both Cyber and Physical Risk</h2><p>Researchers disclosed a three-vulnerability chain affecting Ubiquiti Unifi OS that allows an unauthenticated attacker on the same network segment to gain root-level access to Unifi controllers.</p><p>What makes this story particularly important is the convergence of cyber and physical security.</p><div class="pullquote"><p>"Let's say I'm a threat actor with this access and I can unlock all your doors. Now I can sell that access to a local crime group. They come in at midnight, raid your office, take everything they want and walk out. If I do that on a Friday night, you're not going to find out until Monday morning. The connection between cyber threats and local gang monetization is one hundred percent real. Talk to your threat hunting team about this." James Azar</p></div><p>Many organizations use Unifi infrastructure to manage:</p><ul><li><p>Wireless networks</p></li><li><p>Switching infrastructure</p></li><li><p>Security cameras</p></li><li><p>Physical access control systems</p></li><li><p>Building security devices</p></li></ul><p>Compromising the controller doesn&#8217;t simply provide network visibility. It can potentially provide operational control over doors, surveillance systems, and physical access infrastructure.</p><p>For years we&#8217;ve discussed the convergence of cyber and physical security as a future concern. It is no longer a future concern.</p><p>A network compromise increasingly has the potential to become a physical security incident.</p><p>Organizations should immediately apply firmware updates, isolate management networks, and evaluate whether physical security systems share infrastructure with general IT operations.</p><h2>&#128187; Gogs Zero-Day Places Self-Hosted Git Repositories at Risk</h2><blockquote><p><em>&#8220;The supply chain around our code is under active attack.&#8221;</em></p></blockquote><p>Researchers disclosed a critical argument injection vulnerability affecting Gogs, a popular self-hosted Git platform often deployed as a lightweight alternative to GitHub.</p><p>The flaw allows attackers to execute arbitrary commands as the Git user, potentially providing access to every repository hosted on the platform.</p><p>What makes this especially dangerous is deployment behavior. Gogs is frequently installed by development teams for convenience, often without the same governance, monitoring, or security oversight applied to enterprise platforms.</p><p>The repositories hosted on these systems frequently contain:</p><ul><li><p>Source code</p></li><li><p>Infrastructure-as-code</p></li><li><p>API keys</p></li><li><p>Credentials</p></li><li><p>Internal documentation</p></li></ul><p>In many environments, a compromised Git repository effectively becomes a roadmap to the rest of the enterprise.</p><p>Organizations should immediately update to version 0.14.3 and audit all self-hosted code repositories, not just the officially supported ones.</p><h2>&#127464;&#127475; OP512 Demonstrates the Patience of Modern Chinese Espionage Operations</h2><p>ReliaQuest researchers disclosed a newly tracked Chinese threat cluster known as OP512, which maintained access to an IIS web server for seventy-five days before initiating the primary phase of its operation.</p><p>The group targeted end-of-life .NET environments and deployed a highly customized toolkit featuring:</p><ul><li><p>Cryptographically unique web shells</p></li><li><p>Timestamp manipulation</p></li><li><p>Memory-only payloads</p></li><li><p>Privilege escalation tooling</p></li><li><p>In-memory persistence mechanisms</p></li></ul><p>One particularly interesting finding involved malware files designed to appear years older than they actually were, complicating forensic investigations and timeline reconstruction.</p><p>The broader lesson here is simple.</p><p>Nation-state operators are increasingly winning not because of advanced exploits but because organizations continue operating unsupported internet-facing infrastructure long after it should have been retired.</p><p>Legacy systems remain one of the most reliable attack vectors available to sophisticated adversaries.</p><h2>&#9878;&#65039; Silent Ransom Group Targets Law Firms Through Teams and Voice Phishing</h2><p>The Silent Ransom Group, also known as Luna Moth, continues evolving its attack methodology by combining Microsoft Teams messaging, voice phishing, and a DNS Fast Flux infrastructure spanning eighteen countries.</p><p>Their preferred target remains law firms.</p><p>The logic is straightforward. Law firms possess:</p><ul><li><p>M&amp;A information</p></li><li><p>Litigation strategies</p></li><li><p>Attorney-client communications</p></li><li><p>Regulatory matters</p></li><li><p>Sensitive corporate data</p></li></ul><p>Rather than deploying ransomware, the attackers frequently focus on direct data theft followed by extortion.</p><p>The use of Teams-based phishing is particularly important because many organizations continue focusing awareness efforts on email while attackers increasingly migrate toward collaboration platforms.</p><p>Security awareness programs that focus exclusively on email are no longer aligned with today&#8217;s threat landscape.</p><h1>&#9889; Need to Know</h1><h3>&#128039; Linux Kernel Container Escape Receives Public Exploit</h3><p>Public exploit code is now available for a Linux kernel vulnerability affecting Kubernetes and multi-tenant environments. The flaw enables container escape and host-level privilege escalation. Organizations should prioritize kernel updates and node isolation strategies.</p><h3>&#128241; WhatsApp Catches NSO Violating Court Discovery Orders</h3><p>In the ongoing WhatsApp versus NSO Group litigation, a federal court found NSO in contempt after failing to provide required technical documentation regarding Pegasus spyware operations. WhatsApp also alleges it identified additional NSO activity occurring during the discovery process itself, escalating an already contentious legal battle.</p><h3>&#127891; Oxford Suffers Another Data Breach</h3><p>Oxford University&#8217;s Career Connect platform experienced its second successful compromise this year. Attackers reportedly accessed student records, email addresses, degree information, and employment application history data that could fuel highly targeted job-related phishing campaigns.</p><h3>&#127963;&#65039; Massachusetts Passes Landmark Privacy Legislation</h3><p>Massachusetts unanimously passed the Massachusetts Consumer Data Privacy Act, introducing restrictions on geolocation tracking, biometric data collection, data minimization, and private rights of action. The legislation may become one of the most consequential privacy laws in the United States.</p><h3>&#127466;&#127482; Europe Launches Tech Sovereignty Package</h3><p>The European Commission unveiled a major technology sovereignty initiative including expanded semiconductor investments and new cloud and AI localization requirements. The package is designed to reduce European dependence on foreign cloud providers, chip manufacturers, and digital infrastructure.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t really about vulnerabilities.</p><p>It was about control.</p><p>Control of software supply chains.<br>Control of developer ecosystems.<br>Control of physical infrastructure.<br>Control of sensitive legal information.<br>Control of national technology ecosystems.</p><p>The organizations that succeed over the next decade will be those capable of understanding that cybersecurity is no longer simply about protecting systems, it&#8217;s about protecting the interconnected relationships that power modern business.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Audit npm packages and AI development tool dependencies</p></li><li><p>Rotate API keys and credentials potentially exposed through development environments</p></li><li><p>Patch Check Point VPN infrastructure immediately</p></li><li><p>Apply Ubiquiti Unifi firmware updates across all deployments</p></li><li><p>Review physical security systems sharing IT infrastructure</p></li><li><p>Update Gogs instances to version 0.14.3</p></li><li><p>Retire or isolate end-of-life IIS and .NET deployments</p></li><li><p>Train users on Teams-based phishing and voice phishing attacks</p></li><li><p>Patch Linux kernel vulnerabilities affecting Kubernetes environments</p></li><li><p>Review readiness for Massachusetts privacy requirements</p></li><li><p>Assess exposure to emerging EU localization and sovereignty requirements</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how clearly attackers have shifted their focus toward the systems that enable organizations to operate. The Miasma worm isn&#8217;t targeting finished software, it&#8217;s targeting developers. OP512 isn&#8217;t chasing flashy ransomware headlines, it&#8217;s quietly sitting inside infrastructure for months. The Silent Ransom Group isn&#8217;t encrypting files&#8212;they&#8217;re stealing sensitive legal information and weaponizing trust. The common denominator is that attackers increasingly understand where value is created inside organizations and are attacking those areas directly.</p><p>The second takeaway is that we&#8217;re entering an era where cybersecurity, privacy, and technology sovereignty are becoming inseparable. Massachusetts&#8217; privacy legislation and Europe&#8217;s Tech Sovereignty Package demonstrate that governments are no longer waiting for industry to self-regulate. At the same time, organizations are being forced to manage increasingly fragmented compliance requirements across regions and jurisdictions. Security leaders must begin viewing cybersecurity not just as a technical function, but as a strategic business capability tied directly to governance, operations, and competitive advantage.</p><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/whatsapp-catches-nso-group-defying?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/whatsapp-catches-nso-group-defying?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/whatsapp-catches-nso-group-defying?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Whistleblower Accuses IBM & AT&T of Covering Up 5Chinese APT10 Intrusions on Federal Cloud Systems, Cisco Warns of 7th SD-WAN Zero-Day Exploited, Trump Considers Palantir CTO Shyam Sankar to Lead CISA]]></title><description><![CDATA[IBM Accused of Hiding 56,000 Chinese Intrusions, Cisco Faces Its 7th SD-WAN Zero-Day, and AI Supply Chain Risks Continue to Escalate]]></description><link>https://www.cyberhubpodcast.com/p/whistleblower-accuses-ibm-and-at</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/whistleblower-accuses-ibm-and-at</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Mon, 08 Jun 2026 13:31:36 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/201066352/f96a9ac9a9ea51407d36b0edbf722af3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode delivered one of the most consequential collections of stories we&#8217;ve seen this year. From allegations that IBM and AT&amp;T concealed years of Chinese nation-state intrusions into federal cloud environments, to yet another Cisco SD-WAN zero-day, to critical vulnerabilities affecting AI development platforms used hundreds of millions of times, the message is becoming impossible to ignore:</p><p><strong>The attack surface is expanding faster than organizations can realistically defend it, and nation-state actors are taking full advantage of that gap.</strong></p><p>Today&#8217;s show wasn&#8217;t just about vulnerabilities. It was about trust. Trust in vendors. Trust in cloud providers. Trust in software supply chains. Trust in AI platforms. And perhaps most importantly, trust in the transparency of organizations responsible for protecting some of the world&#8217;s most sensitive information.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape demonstrates a growing convergence between nation-state espionage, software supply chain compromise, AI infrastructure vulnerabilities, and critical infrastructure targeting. Chinese threat actors continue expanding operations across government, enterprise, cloud, and development environments, while defenders face mounting pressure from both unpatched systems and accelerating vulnerability discovery driven by AI.</p><p>Several stories today highlight a troubling reality: vulnerabilities are no longer remaining hidden for years because researchers are finding them faster than ever. Yet organizations continue struggling to patch, monitor, and govern increasingly complex environments. The result is a widening gap between attacker capability and defender readiness.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZSMr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZSMr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZSMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b26c1da2-2e38-4838-828e-b5d389572934_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:173811,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/201066352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZSMr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!ZSMr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb26c1da2-2e38-4838-828e-b5d389572934_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#127464;&#127475; IBM and AT&amp;T Accused of Concealing Massive APT10 Federal Cloud Intrusions</h2><p>The biggest story of the day came from a newly unsealed federal whistleblower complaint that could have significant implications for both federal contracting and cybersecurity disclosure practices. According to the complaint, former IBM security analyst William Barlow alleges that IBM and AT&amp;T concealed extensive Chinese APT10 intrusions affecting federal cloud infrastructure between 2013 and 2016.</p><p>The allegations are staggering. The complaint claims that APT10 breached IBM systems more than 56,000 times, targeting IBM subsidiaries responsible for sensitive federal healthcare and financial workloads while also leveraging AT&amp;T infrastructure connected to government contracts. According to the whistleblower, IBM leadership was aware of the activity and chose not to fully disclose it in order to protect federal business relationships worth billions of dollars.</p><p>It is important to emphasize that these remain allegations contained within a whistleblower filing. However, if proven true, the implications extend far beyond a typical breach disclosure story. This would potentially involve the deliberate concealment of nation-state compromises affecting federal systems and could fundamentally reshape expectations around vendor transparency, breach notification obligations, and federal contractor accountability.</p><p>For security leaders, the story serves as a reminder that vendor risk is not simply about security controls. It is also about disclosure culture, governance, and transparency when incidents occur.</p><h2>&#128680; Cisco Faces Its Seventh SD-WAN Zero-Day of 2026</h2><p>Cisco disclosed another critical vulnerability affecting SD-WAN infrastructure, marking the seventh SD-WAN zero-day disclosed this year alone. The flaw allows attackers to achieve root-level code execution on vulnerable systems, and while Cisco has published indicators of compromise and mitigation guidance, no patch is currently available.</p><p>The concern here goes far beyond a single vulnerability. SD-WAN platforms sit directly within the traffic flow of many enterprises, controlling routing, connectivity, segmentation, and network visibility. A compromise at this layer provides attackers the ability to intercept, reroute, inspect, or completely disrupt enterprise communications.</p><p>The broader trend should be concerning for network architects and CISOs alike. Seven zero-days targeting a single product line within six months raises legitimate questions about attack surface management, secure development practices, and long-term vendor strategy.</p><p>Organizations running affected deployments should immediately restrict management plane access, review Cisco&#8217;s published indicators, and implement all available compensating controls while awaiting a patch.</p><h2>&#127774; SolarWinds Serv-U Added to CISA&#8217;s Known Exploited Vulnerabilities Catalog</h2><p>CISA added SolarWinds Serv-U FTP software to the Known Exploited Vulnerabilities catalog following confirmation of active exploitation. The vulnerability allows unauthenticated denial-of-service attacks through crafted requests targeting exposed Serv-U servers. Federal agencies now face a remediation deadline of June 19th.</p><p>While denial-of-service vulnerabilities often receive less attention than remote code execution flaws, they can still create significant operational disruption when they impact file transfer infrastructure supporting business-critical processes.</p><p>Organizations should upgrade immediately to Serv-U version 15.5.4 Hotfix 1 and verify that internet-facing deployments are fully updated before attackers begin broader exploitation campaigns.</p><h2>&#128373;&#65039; Chinese APT Maintains Persistence Inside Microsoft 365 for 18 Months</h2><p>Researchers disclosed new findings involving UNC5221, also known as Verdant Bamboo, a Chinese threat actor that maintained access inside Microsoft 365 environments for more than eighteen months while deploying previously undocumented malware families.</p><p>The campaign introduced two notable malware variants. The first, called Pleanit, is a .NET-based backdoor designed to blend into legitimate Microsoft communications. The second, AgentPSD, is a Python-based reverse shell disguised as a PowerShell diagnostic utility.</p><p>Perhaps the most concerning detail is that one victim was reportedly re-compromised after a complete remediation effort. That suggests either credentials were not fully rotated, persistence mechanisms were missed, or the attackers retained access through alternate pathways.</p><p>The campaign also leveraged managed service provider relationships, potentially increasing exposure across multiple downstream organizations. This continues reinforcing the importance of MSP security reviews, tenant monitoring, identity hardening, and comprehensive credential rotation following incident response efforts.</p><h2>&#129302; Critical Hugging Face Transformers Vulnerability Impacts 232 Million Installs</h2><p>One of the most significant AI security stories of the year emerged with disclosure of CVE-2026-4372, a critical remote code execution vulnerability affecting Hugging Face Transformers. The flaw impacts versions 4.56.0 through 5.2.x and exposes an estimated 232 million installations globally.</p><p>The vulnerability allows arbitrary code execution through a maliciously crafted configuration file during model loading. Most concerning is that exploitation remains possible even when &#8220;trust_remote_code&#8221; is explicitly disabled&#8212;the very control intended to prevent these scenarios.</p><p>This issue highlights a growing challenge within AI ecosystems. Security teams often focus on protecting AI outputs, but increasingly the greater risk lies within model supply chains themselves. AI models, configuration files, dependencies, and repositories are becoming software supply chain assets that require the same governance and scrutiny as traditional applications.</p><p>Organizations should immediately upgrade to Transformers version 5.3.0 and review model ingestion workflows for any externally sourced AI artifacts.</p><h1>&#9889; Need to Know</h1><h3>&#128039; Linux Kernel Container Escape Added to KEV</h3><p>CISA added a long-standing Linux kernel privilege escalation vulnerability to the Known Exploited Vulnerabilities catalog following evidence of active exploitation targeting Kubernetes and containerized environments. The vulnerability allows container escape and host-level compromise under certain conditions. Organizations should prioritize patching Linux hosts and review privilege escalation controls across container environments.</p><h3>&#9981; Federal Agencies Warn of Fuel Infrastructure Attacks</h3><p>CISA, FBI, NSA, TSA, DOE, USDA, and several other agencies jointly warned about active attacks targeting Automatic Tank Gauge systems used across fuel stations, transportation infrastructure, and chemical facilities. Many exposed systems remain accessible via default credentials and internet-facing management interfaces.</p><h3>&#129302; Five Zero-Days Patched in OpenClaw AI Agent Platform</h3><p>Researchers disclosed five vulnerabilities affecting OpenClaw, an AI agent framework integrating with Slack, Teams, Discord, and other collaboration tools. The flaws allowed attackers to impersonate trusted users through identity handling weaknesses. All vulnerabilities have been patched.</p><h3>&#128225; ASUS Router Vulnerabilities Await Fixes</h3><p>Two critical vulnerabilities affecting ASUS Wave 7 mesh routers expose credentials and allow persistent backdoor deployment. Patches are not expected until later this month, leaving organizations dependent on access restrictions and network segmentation as interim controls.</p><h3>&#127757; TA4922 Expands Into Europe and Africa</h3><p>Proofpoint identified TA4922 as one of the most active cybercrime operators currently tracked. The group continues expanding operations into Europe and Africa while leveraging malware families including Atlas RAT, Valley RAT, and Romulus Loader. Researchers also noted evidence suggesting LLM-assisted malware development.</p><h3>&#128123; Polyfill.io Supply Chain Threat Returns</h3><p>The long-running Polyfill.io saga continues. The compromised JavaScript CDN has resurfaced on websites associated with Toshiba, Muji, and Samsung Smart TV platforms, presenting users with fake authentication prompts. While credential theft has not yet been confirmed, the incident demonstrates how supply chain compromises can persist long after initial disclosure.</p><h3>&#127760; Chrome 149 Ships Record-Breaking Security Release</h3><p>Google released Chrome 149 with an unprecedented 429 security fixes, including a critical sandbox escape vulnerability carrying a CVSS score of 9.6. Organizations should prioritize browser updates immediately given the continued prevalence of browser-based attacks and drive-by exploitation techniques.</p><h3>&#128274; OpenAI Launches ChatGPT Lockdown Mode</h3><p>OpenAI introduced ChatGPT Lockdown Mode, a new security feature designed to mitigate prompt injection and data exfiltration attacks. The mode disables outbound communications and browsing capabilities, creating a more controlled environment for sensitive use cases such as government, legal, and financial workloads.</p><h3>&#127963;&#65039; Palantir CTO Reportedly Under Consideration for CISA Director</h3><p>Reports indicate the Trump Administration is considering Palantir CTO Shyam Sankar to fill the long-vacant CISA Director position. The agency has operated without Senate-confirmed leadership since January 2025 during one of the most active periods for cyber threats in recent memory.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode reinforced a difficult reality: cybersecurity risk is no longer isolated to individual vulnerabilities or individual attacks.</p><p>The threat environment now spans cloud providers, AI platforms, software supply chains, browsers, routers, critical infrastructure, developer ecosystems, and even the vendors organizations trust to protect them.</p><p>The challenge for defenders isn&#8217;t simply finding vulnerabilities anymore.</p><p>It&#8217;s deciding which of the hundreds of critical risks deserves immediate attention before attackers do.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Review exposure to Cisco SD-WAN infrastructure and implement compensating controls</p></li><li><p>Patch SolarWinds Serv-U to version 15.5.4 Hotfix 1</p></li><li><p>Conduct threat hunting for UNC5221 indicators within Microsoft 365 environments</p></li><li><p>Upgrade Hugging Face Transformers to version 5.3.0 immediately</p></li><li><p>Patch Linux kernel vulnerabilities affecting containerized workloads</p></li><li><p>Remove internet exposure from Automatic Tank Gauge systems</p></li><li><p>Review AI agent framework authorization and identity controls</p></li><li><p>Restrict ASUS router management interfaces to trusted networks</p></li><li><p>Remove any remaining references to Polyfill.io from web properties</p></li><li><p>Force deployment of Chrome 149 across managed endpoints</p></li><li><p>Evaluate AI governance controls around model ingestion and deployment</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is the continued convergence of nation-state activity and supply chain risk. The IBM whistleblower allegations, the Chinese persistence inside Microsoft 365 environments, the AI model supply chain vulnerabilities, and the reappearance of Polyfill.io all point to the same reality: attackers increasingly prefer compromising trusted relationships rather than attacking organizations directly. Trust has become one of the most valuable assets in cybersecurity, and it is under constant assault.</p><p>The second takeaway is that AI is now impacting cybersecurity at every level simultaneously. AI is discovering vulnerabilities faster than researchers ever could. Threat actors appear to be leveraging AI to accelerate malware development and campaign operations. At the same time, organizations are rushing AI platforms into production without fully understanding the security implications of model supply chains and agent frameworks. Security leaders must begin treating AI ecosystems with the same rigor applied to cloud infrastructure and software development pipelines because the risk profile is rapidly becoming just as significant.</p><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/whistleblower-accuses-ibm-and-at?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/whistleblower-accuses-ibm-and-at?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/whistleblower-accuses-ibm-and-at?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[This Week in Cybersecurity #55]]></title><description><![CDATA[The Speed Gap: Why Attackers Are Winning the Race and What Security Leaders Must Do About It, Your weekend catch-up on the most critical cybersecurity stories of the week, curated by James Azar]]></description><link>https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-55</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-55</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Fri, 05 Jun 2026 16:01:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YwsI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>Good Morning, Security Gang!</strong></h3><p>Double espresso ready. This week&#8217;s briefing covers four full episodes and represents some of the most operationally significant coverage we&#8217;ve produced in months.</p><div class="pullquote"><p>James opened the week with a line that defines the entire landscape right now: <em>&#8220;The organizations that are going to weather this environment are the ones that match the attacker&#8217;s operational speed. Patch fast. Detect faster. Train your people because Carnival&#8217;s six million victims and Charter&#8217;s five million victims both started with one employee and one phone call.&#8221;</em></p></div><p>By the end of four episodes, that framing was validated at every level. A Palo Alto GlobalProtect VPN vulnerability went from disclosure to CISA KEV with a June 1 federal deadline. A FlowWise AI platform zero-day received public exploit code enabling root access through a single malicious import. The HTTP/2 Bomb vulnerability discovered autonomously by OpenAI&#8217;s Codex could crash major web servers globally in under a minute. A VS Code zero-day with no patch available steals GitHub OAuth tokens through a one-click Jupyter notebook attack. Anthropic&#8217;s Mythos expanded to 150 more organizations across 15 countries including NATO and critical infrastructure operators. And Gamaredon deployed a USB-propagating worm with a Telegram-controlled C2 and built-in wiper module against Ukraine.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><p>On the human side: Six million Carnival cruise customers exposed after one successful voice phishing call. A Google security engineer was charged with using confidential search data to place $1 million in prediction market bets. China&#8217;s intelligence services are systematically recruiting government insiders through LinkedIn at scale documented in a Five Eyes joint advisory. And attackers spent five months quietly extracting a stock exchange executive&#8217;s entire Outlook mailbox in small batches, using Microsoft-owned IP addresses to bypass DNS monitoring.</p><blockquote><p>The week closed with a reminder James keeps returning to: <em>&#8220;Forget all the shiny tools. If we can&#8217;t do the fundamentals well, none of those tools are going to help. That&#8217;s the reality.&#8221;</em></p></blockquote><p>Let&#8217;s get into all of it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YwsI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YwsI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YwsI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1145266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/200781427?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YwsI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!YwsI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F60fb5553-3324-42cb-a493-53eeea2e0aa4_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>&#127760; Infrastructure &amp; Network Exploitation</strong></h3><p><strong>Palo Alto GlobalProtect VPN CVE-2026-3401: CISA KEV, June 1 Federal Deadline</strong></p><p>Active exploitation of CVE-2026-3401 in Palo Alto Networks&#8217; GlobalProtect VPN platform targeting local administrator accounts was confirmed by CISA, which added the flaw to the KEV catalog with a June 1 federal remediation deadline. The vulnerability continues the 2026 pattern of edge devices VPNs, firewalls, and remote access appliances serving as primary entry points for ransomware operators and nation-state actors. If immediate patching is not possible, Palo Alto recommends separating the GlobalProtect authentication cookie certificate from the HTTP service certificate to disrupt the attack path. Internet-facing security infrastructure is now one of the highest-priority attack surfaces in enterprise environments.</p><p><strong>HTTP/2 Bomb CVE-2026-49975: One Client Can Crash a Server in Twenty Seconds</strong></p><p>Researchers disclosed the &#8220;HTTP/2 Bomb&#8221;, a remote denial-of-service vulnerability affecting Apache HTTP Server, Microsoft IIS, Envoy Proxy, and Cloudflare&#8217;s Pingora. The attack combines HPACK compression abuse to force servers into allocating massive memory while processing small malicious traffic, with Slowloris-style techniques to prevent memory release. A single client on a residential connection can consume and hold approximately 32 gigabytes of memory on vulnerable Apache and Envoy servers in roughly twenty seconds. Researchers estimate more than 880,000 public websites are potentially affected by default configurations. Nginx patched earlier this year; Apache released fixes in late May; Microsoft IIS, Envoy, and Cloudflare&#8217;s Pingora remained unpatched at publication. The vulnerability was discovered using OpenAI&#8217;s Codex platform the second AI-assisted vulnerability disclosure this week. Patch Apache and Nginx immediately, implement strict connection limits, enforce HPACK restrictions, and review mitigation options at load balancer and WAF layers.</p><p><strong>ClickFix Campaign: Harvard, Oxford, 700+ Trusted Websites as Malware Delivery Infrastructure</strong></p><p>The ClickFix campaign continues expanding, actively exploiting Ghost CMS vulnerabilities to compromise over 700 websites including Harvard University, Oxford University, Auburn University, and DuckDuckGo-powered properties. Injected JavaScript presents visitors with fake CAPTCHA or browser verification prompts instructing them to press Windows+R and execute commands that launch PowerShell payloads. This bypasses traditional security awareness training entirely users trust browser prompts on legitimate, well-known domains in ways they no longer trust email attachments. Patch Ghost CMS to version 6.20.0 immediately and train users that no legitimate website will ever ask them to paste commands into a terminal.</p><p><strong>Oracle WebLogic Added to CISA KEV: Cobalt Strike and Ransomware Payload Deployment</strong></p><p>CISA added CVE-2024-21182, a critical Oracle WebLogic RCE vulnerability to the KEV catalog after confirming attackers are using it to deploy Cobalt Strike and ransomware. Patch immediately and review exposed WebLogic services.</p><p><strong>ASUS Router Vulnerabilities: No Patch Until End of June</strong></p><p>Two critical vulnerabilities in ASUS Wave 7 mesh routers expose credentials and allow persistent backdoor installation. Patches are not expected until late June. Organizations should restrict management interfaces to trusted IP ranges and implement compensating controls in the interim.</p><p><strong>WordPress Kirki Plugin CVE-2026-8206 CVSS 9.8: One Million Sites, No Credentials Required</strong></p><p>A critical authentication bypass in the Kirki WordPress page builder plugin allows attackers to substitute their own email during password reset, generating legitimate reset links sent directly to the attacker no credentials required, no user interaction, one request. Over one million WordPress installations are affected. Once access is gained, attackers install malicious plugins, create rogue admin accounts, inject SEO spam, and deploy backdoors. Update to version 6.0.7 or disable the plugin entirely.</p><h3><strong>&#129302; AI as Discovery Engine, Target, and Threat Multiplier</strong></h3><p><strong>Anthropic Mythos Expands to 150 Organizations Across 15 Countries Including NATO</strong></p><p>Anthropic announced Project Glasswing expansion adding 150 organizations across 15 countries to the Mythos vulnerability discovery platform including NATO, ENISA, Samsung, healthcare providers, utilities, communications providers, and critical infrastructure operators. Mythos has already identified 23,000-plus potential vulnerabilities, 10,000-plus high and critical issues, and thousands of previously unknown flaws. The announcement coincided directly with the Trump AI executive order signed the same day. Mythos is functioning as an autonomous vulnerability discovery platform operating at a scale no human team can match. The future of cybersecurity increasingly depends on whether organizations gain access to tools like Mythos or become targets discovered by them.</p><p><strong>Trump Signs AI Security Vetting Executive Order: Voluntary Review Framework</strong></p><p>President Trump signed an executive order establishing a voluntary federal review framework for advanced AI models, assessing national security risks before public release. The order stepped back from an earlier proposal requiring mandatory 90-day reviews, replacing it with a 30-day voluntary government evaluation process. The framework introduces AI cybersecurity capability benchmarking, national security risk evaluations, an AI cybersecurity clearinghouse, and government-industry collaboration mechanisms. The voluntary structure creates incentives for collaboration rather than compliance-driven resistance the practical question is whether government oversight can evolve quickly enough to remain relevant.</p><p><strong>FloWise AI Platform CVE-2026-40933: Public Exploit, Root Access via Single Import</strong></p><p>Public working exploit code was released for a critical RCE vulnerability in FloWise, the popular open-source AI orchestration platform used to build LLM workflows and AI agents. One malicious chat flow import triggers OS-level code execution with the privileges assigned to the FlowWise process often root. FloWise deployments are commonly connected to databases, cloud services, API keys, internal applications, and AI development environments. Compromising FloWise means compromising everything connected to it. Patch immediately, restrict import permissions, review administrative access, and rotate all connected credentials.</p><p><strong>OpenAI Codex Token Theft via npm Package: 26,000 Weekly Downloads</strong></p><p>A malicious npm package called codex-ui-android silently exfiltrated OpenAI Codex OAuth tokens including long-lived refresh tokens before detection. Accumulated 26,000 weekly downloads. Revoke and reissue all Codex credentials immediately for any organization that may have had the package installed.</p><p><strong>Russian GreyVibe Uses AI Across Entire Kill Chain</strong></p><p>Researchers documented GreyVibe, a previously unknown Russian-linked threat group targeting Ukrainian organizations since August 2025, using generative AI throughout nearly every operational stage: Ideogram for phishing imagery, ChatGPT for lure development and malware support, Google Gemini for obfuscation and backend infrastructure. Attack chains include fake CAPTCHA pages, spear phishing, fraudulent charity websites, and TrickBot ecosystem malware families. This is one of the clearest documented cases of a threat actor integrating generative AI into operational workflows rather than experimentally. Defenders should expect phishing campaigns and social engineering to become increasingly personalized, scalable, and indistinguishable from legitimate communications.</p><p><strong>AI Discovers Redis Zero-Day CVE-2026-23479 Missed for Two Years</strong></p><p>An autonomous security tool identified a use-after-free vulnerability in Redis that had existed unnoticed since 2023. Public exploit code is now available. Redis Cloud patched; self-hosted deployments require immediate upgrade.</p><p><strong>Chinese TA-4922 Uses LLM-Assisted Malware Development</strong></p><p>Proofpoint reported that TA-4922, a Chinese cybercrime group targeting Europe, appears to be using LLM-assisted techniques to accelerate malware creation and campaign generation. AI-assisted offensive development is no longer exclusive to well-resourced nation-state programs.</p><p><strong>GitLab Emergency Patch: Duo AI Identity Confusion Enables Privilege Escalation</strong></p><p>GitLab released emergency updates for a flaw allowing an authenticated user to trigger AI-assisted workflows under another user&#8217;s identity enabling privilege escalation and lateral movement within development environments. <strong><a href="http://gitlab.com/">GitLab.com</a></strong> patched; self-managed instances must upgrade immediately.</p><h3><strong>&#129516; Supply Chain &amp; Developer Ecosystem</strong></h3><p><strong>VS Code Zero-Day: GitHub OAuth Token Theft via One-Click Jupyter Notebook &#8212; No Patch</strong></p><p>Security researcher Amar Askar publicly disclosed a VS Code zero-day with no patch available that steals GitHub OAuth tokens through a single malicious Jupyter notebook. By delivering a notebook file, attackers execute JavaScript inside a WebView iframe, which silently installs a malicious extension via synthetic keyboard shortcuts and exploits GitHub&#8217;s automatic authentication between <strong><a href="http://github.com/">GitHub.com</a></strong> and <strong><a href="http://github.dev/">GitHub.dev</a></strong>. The extension intercepts and exfiltrates OAuth tokens before they reach GitHub. These tokens provide access to every private repository the victim can access. No patch is available. Review installed VS Code extensions, restrict use of untrusted Jupyter notebooks, and disable notebook functionality on systems where it is not required.</p><p><strong>Red Hat npm Supply Chain Attack &#8220;Miasma&#8221;: 32 Packages, 117,000 Weekly Downloads</strong></p><p>The &#8220;Miasma&#8221; campaign compromised 32 official Red Hat npm packages with over 117,000 combined weekly downloads, originating after a Red Hat employee&#8217;s GitHub account was compromised. Attackers injected malicious code into repositories and leveraged GitHub Actions OIDC workflows to distribute malware through trusted package pipelines, harvesting AWS, Azure, and GCP credentials, GitHub tokens, SSH keys, and npm authentication tokens. The malware represents an evolution of the Mini Shai-Hulud campaign. Rotate all cloud and development credentials from affected packages immediately and review build pipelines for signs of compromise.</p><p><strong>Microsoft Dispute With Nightmare Eclipse Researcher &#8212; Then Reversed</strong></p><p>Microsoft formally stated that publishing working exploit code without coordinated disclosure is &#8220;never justifiable&#8221; and signaled potential Digital Crimes Unit action against Nightmare Eclipse, who disclosed six Windows zero-days, three already in CISA KEV, three unpatched with public PoC available. Within 24 hours, Microsoft reversed course and clarified it has no plans to pursue legal action against independent security researchers, following significant community backlash. The episode highlights the enduring tension between bug bounty program fairness, researcher incentives, and responsible disclosure.</p><p><strong>Container and Kubernetes Attacks Growing: Exposed Docker APIs and Weak RBAC</strong></p><p>Researchers warned about active exploitation of container and Kubernetes misconfigurations exposed Docker APIs, weak RBAC permissions, and poisoned container images with campaigns specifically targeting cloud-native infrastructure and Kubernetes secrets.</p><p><strong>Dashlane Detects Brute Force Campaign Against Customer Accounts</strong></p><p>Dashlane confirmed detection and mitigation of a brute-force campaign attempting to register unauthorized devices. Some encrypted vaults were copied; no master passwords exposed. Customers should review registered devices and account activity.</p><h3><strong>&#128165; Ransomware &amp; Destructive Operations</strong></h3><p><strong>NightSpire Ransomware: 175 Organizations Across 28 Industries</strong></p><p>NightSpire continues expanding with 175 organizations impacted across 28 industries including hospitals, schools, financial institutions, and government agencies. The group operates exclusively through legitimate tools: exposed RDP and FortiOS vulnerabilities for entry; Chrome Remote Desktop, AnyDesk for persistence; MegaSync for exfiltration; 7-Zip for compression. No custom malware, no EDR triggers. Audit exposed RDP access, FortiOS patching status, and unauthorized remote administration software across all environments.</p><h3><strong>&#128275; Data Breaches &amp; Identity Exposures</strong></h3><p><strong>Carnival Cruise Lines: Six Million Victims, One Phone Call</strong></p><p>Carnival Cruise Lines confirmed nearly six million individuals affected by an April breach originating from a single social engineering attack against an employee account. ShinyHunters claimed responsibility. Exposed data includes names, email addresses, phone numbers, dates of birth, driver&#8217;s license numbers, and passport information. Credit monitoring does not protect against identity fraud involving passport data. Frontline employees remain one of the most critical attack surfaces in any organization.</p><p><strong>Charter Communications: 42 Million Records via Voice Phishing</strong></p><p>Charter Communications confirmed approximately 42 million customer records exposed following a voice phishing attack against a Microsoft Entra account, which became the Salesforce pivot point. The ShinyHunters SaaS playbook, vishing targets identity provider, becomes Salesforce access, becomes large-scale data extraction has now been executed against Charter, Carnival, 7-Eleven, Cushman &amp; Wakefield, Aman Resorts, and dozens of others in 2026 alone.</p><p><strong>UK Visa Portal: 100,000 Biometric Identity Documents Leaked</strong></p><p>A third-party UK visa processing portal leaked more than 100,000 passport scans and biometric selfies. When journalists reported the exposure, the company responded with lawyers before engineers. At time of reporting, the leak remained unresolved. Passport scans combined with biometric selfies enable KYC bypasses, fake identity creation, and fraudulent financial account openings. This perfectly captures the industry&#8217;s most persistent operational failure: organizations still treating cybersecurity incidents as communications crises rather than technical emergencies.</p><p><strong>Meta AI Support Bot Enabled Instagram Account Takeover</strong></p><p>Meta&#8217;s AI support chatbot was exploited by attackers who discovered it could be used to request account recovery actions on behalf of victims adding an attacker-controlled email address, triggering legitimate password resets, and gaining full account control without the owner&#8217;s involvement. Victims included high-profile government, military, and cybersecurity community accounts. Meta fixed the issue, but the incident establishes a new category: AI systems granted administrative authority without sufficient identity verification become privileged attack surfaces. This is not the last AI trust-boundary failure we will see.</p><p><strong>Five-Month Espionage Campaign Extracts Stock Exchange Executive&#8217;s Outlook Mailbox</strong></p><p>Symantec documented a five-month operation quietly extracting a senior executive&#8217;s Outlook mailbox in carefully staged increments. Attackers used malware disguised as Adobe and OneDrive services, exfiltrated through Dropbox and personal OneDrive accounts, and used hardcoded Microsoft-owned IP addresses to bypass DNS monitoring. Small date-based data batches avoided triggering large-transfer alerts. Market-moving information, regulatory discussions, merger activity, and strategic correspondence represent intelligence value far exceeding the cost of a disruptive attack. The most dangerous adversaries aren&#8217;t making noise they&#8217;re remaining invisible.</p><h3><strong>&#127760; Geopolitical &amp; Nation-State Threats</strong></h3><p><strong>Gamaredon Deploys USB Worm with Telegram C2 and Wiper Module Against Ukraine</strong></p><p>Russia&#8217;s FSB-linked Gamaredon exploited WinRAR CVE-2025-8088 to deploy a multi-stage infection chain including GammaLoad (downloader), GammaWorm (USB-propagating worm hiding via NTFS alternate data streams), GammaSteal (exfiltration to AWS S3 using Telegram channels for C2), and GammaWipe (destructive wiper module). Telegram-based C2 blends malicious communications into legitimate enterprise traffic. Gamaredon is distinct from many threat groups for sustained operational patience campaigns remain active for months, continuously adapting. Organizations with Ukrainian partners or shared infrastructure should patch WinRAR immediately and monitor for suspicious Telegram outbound traffic and unexpected S3 uploads.</p><p><strong>Five Eyes Joint Advisory: China Systematically Recruiting Government Insiders via LinkedIn</strong></p><p>A joint advisory from U.S., Canadian, UK, Australian, and New Zealand intelligence agencies documented Chinese intelligence services systematically recruiting government employees, military personnel, contractors, and critical infrastructure workers through LinkedIn, Indeed, and Upwork. The recruitment funnel: initial contact through professional platforms &#8594; access and value evaluation &#8594; harmless research requests &#8594; gradually sensitive tasking. Compensation through PayPal, Payoneer, cryptocurrency, and wire transfers. Once trust is established, communications migrate to Signal and Telegram, moving activity outside organizational visibility. Classified access is not required to be a target facility layouts, contract details, budget information, and vendor relationships have significant intelligence value when aggregated. Use this advisory to review insider threat awareness programs and LinkedIn exposure policies immediately.</p><p><strong>Mustang Panda Returns with New PlugX Delivery via Fake Adobe Prompts</strong></p><p>Chinese APT Mustang Panda resurfaced using fake Adobe Acrobat update prompts to deliver PlugX malware, leveraging signed binaries and memory-only execution techniques to reduce detection. Hunt for Mustang Panda PlugX indicators across endpoints.</p><p><strong>Iranian APT Expands Across Nine Countries, Adds Aviation Supply Chain Targeting</strong></p><p>MuddyWater campaigns across nine countries in Q1 2026 refined DLL side-loading tradecraft through trusted executables including fmap.exe and SentinelOne Memory Scanner components. A separate Iranian cluster simultaneously targeted aviation software providers through credential harvesting pre-positioning for downstream pivot into airlines, airports, and aerospace organizations.</p><h3><strong>&#128272; Identity, Authentication &amp; Insider Threats</strong></h3><p><strong>Kali365 MFA Bypass: FBI IC3 Warning, OAuth Device Code Abuse at Scale</strong></p><p>The FBI warned about Kali365, a phishing-as-a-service platform bypassing Microsoft 365 MFA through OAuth device code flow abuse the authentication flow designed for smart TVs and printers. Victims authenticate normally. MFA fires successfully. Attackers capture live tokens and gain full account access. The platform includes AI-generated phishing lures, real-time victim dashboards, and Telegram-based infrastructure. Hundreds of attacks across manufacturing, healthcare, education, government, and financial sectors. Restrict or disable device code authentication flows through Microsoft Entra conditional access policies where operationally feasible.</p><p><strong>Windows Netlogon CVE-2026-21176: &#8220;The New Zerologon&#8221; &#8212; Pre-Auth, Zero-Click, Domain Controller RCE</strong></p><p>A critical Netlogon vulnerability affecting Windows Domain Controllers requiring only a single specially crafted network packet to achieve system-level code execution, no credentials, no user interaction was compared by researchers to Zerologon in operational severity. Microsoft patched during May&#8217;s Patch Tuesday. Organizations that have not yet updated Domain Controllers remain vulnerable. Domain Controllers are the crown jewels of Windows environments compromise here enables full forest takeover. Verify patch deployment, confirm Netlogon protections, and ensure SMB and RPC are not externally exposed.</p><p><strong>Linux Kernel Privilege Escalation: 19-Year Flaw Now Has Public Exploit</strong></p><p>A proof-of-concept exploit is publicly available for the recently disclosed 19-year-old Linux kernel privilege escalation vulnerability. Organizations that delayed patching now face significantly elevated risk. Patch Linux systems immediately across all distributions.</p><p><strong>Android Zero-Day CVE-2025-48595: June Security Update</strong></p><p>Google&#8217;s June Android security update addressed 124 vulnerabilities including CVE-2025-48595, a privilege escalation flaw confirmed under limited active exploitation. Accelerate patch deployment through MDM platforms across all managed Android devices.</p><p><strong>Google Security Engineer Charged: Prediction Market Insider Trading via Search Data</strong></p><p>Federal prosecutors charged a Google security engineer with fraud and money laundering for allegedly using confidential internal search trend data to place highly profitable prediction market bets on Polymarket, generating over $1 million in cryptocurrency profits. This is not a traditional cyberattack but it highlights an expanding insider threat vector. Insider access can increasingly be monetized through financial instruments, prediction markets, and cryptocurrency ecosystems. Insider risk monitoring programs may need to expand to address these evolving scenarios.</p><p><strong>Federal ATG Fuel Monitoring Systems Under Active Attack: Seven Agency Warning</strong></p><p>CISA, FBI, NSA, DOE, TSA, EPA, and other agencies jointly warned about active attacks targeting Automatic Tank Gauge systems used at fuel stations, transportation hubs, and chemical facilities exploiting internet-exposed systems protected only by default passwords. Remove ATG systems from direct internet exposure immediately.</p><h3><strong>&#9878;&#65039; Law Enforcement, Policy &amp; Industry</strong></h3><p><strong>Netherlands Dismantles ASOC Residential Proxy Botnet: 17 Million Devices</strong></p><p>Dutch law enforcement dismantled the ASOC residential proxy botnet tied to more than one million infected devices and leveraging over 17 million compromised endpoints globally. Access was sold for five dollars per month for credential stuffing, DDoS, phishing, and proxy services. Residential proxy networks remain valuable because consumer IP traffic appears legitimate to most security controls.</p><p><strong>NSA Appoints David Imbordino as Cyber Director, Bruce Jones to CCC</strong></p><p>The NSA formally appointed David Imbordino as Cyber Director and Bruce Jones to lead the Cybersecurity Collaboration Center, ending a prolonged leadership gap and restoring continuity for government-private sector cybersecurity partnerships.</p><p><strong>Spain Arrests Government Data Hacker</strong></p><p>Spanish authorities arrested an individual accused of publishing sensitive information belonging to national police, intelligence personnel, and Spain&#8217;s cybersecurity agency. Cybersecurity professionals increasingly face physical-world targeting through doxxing campaigns.</p><p><strong>Proposal for Independent U.S. Cyber Force: 30,000 Personnel, $11 Billion</strong></p><p>A new policy report recommends creation of a dedicated U.S. Cyber Force. Supporters argue cyber operations have grown large enough to justify their own military branch.</p><p><strong>CISA Remains Significantly Understaffed</strong></p><p>Homeland Security leadership confirmed CISA is operating with approximately 2,200 employees despite authorization for substantially more. Efforts to rebuild the agency continue during a period of elevated threat activity.</p><p><strong>Dragos Acquires Phosphorus: OT and IoT Security Convergence</strong></p><p>Dragos announced acquisition of Phosphorus, expanding its ability to secure IoT devices within OT environments reflecting the continued convergence of traditional OT security and connected device management.</p><p><strong>Cyera Raises at $12 Billion Valuation</strong></p><p>AI security company Cyera is reportedly raising $300 million at a $12 billion valuation on approximately $150 million ARR, reflecting the extraordinary premium investors continue placing on AI security and automation platforms.</p><h3><strong>&#9989; This Week&#8217;s Priority Action List</strong></h3><p><strong>Immediate (Do This Now)</strong></p><ul><li><p>Patch Palo Alto GlobalProtect immediately &#8212; CISA KEV, June 1 federal deadline, active exploitation confirmed</p></li><li><p>Patch Apache HTTP Server and Nginx for HTTP/2 Bomb vulnerability &#8212; 880,000 potentially affected sites, active exploitation risk</p></li><li><p>Patch Oracle WebLogic CVE-2024-21182 &#8212; CISA KEV, Cobalt Strike and ransomware payloads confirmed</p></li><li><p>Verify Windows Domain Controller patch deployment for Netlogon CVE-2026-21176 &#8212; pre-auth zero-click RCE, &#8220;the new Zerologon&#8221;</p></li><li><p>Patch GitLab self-managed instances for Duo AI identity confusion vulnerability immediately</p></li><li><p>Update or disable WordPress Kirki plugin &#8212; CVSS 9.8, one million sites, no credentials required for account takeover</p></li><li><p>Patch FlowWise immediately and restrict import permissions &#8212; public exploit enables root access via single malicious import</p></li><li><p>Revoke and reissue OpenAI Codex credentials if codex-ui-android npm package was present</p></li><li><p>Patch WinRAR for CVE-2025-8088 &#8212; Gamaredon is actively exploiting this for USB worm and wiper deployment</p></li><li><p>Restrict or disable Microsoft Entra device code authentication flows &#8212; Kali365 FBI IC3 warning, active MFA bypass at scale</p></li><li><p>Patch Linux systems for 19-year privilege escalation vulnerability &#8212; public exploit now available</p></li><li><p>Deploy June Android security updates through MDM for CVE-2025-48595 active exploitation</p></li></ul><p><strong>Short-Term (This Month)</strong></p><ul><li><p>Audit VS Code extensions and restrict untrusted Jupyter notebook execution &#8212; GitHub OAuth token theft zero-day has no patch</p></li><li><p>Rotate cloud and development credentials associated with Red Hat npm Miasma campaign</p></li><li><p>Hunt for Mustang Panda PlugX indicators across endpoints</p></li><li><p>Hunt for suspicious Dropbox and OneDrive exfiltration activity in small date-batched increments &#8212; five-month stock exchange espionage model</p></li><li><p>Monitor for Telegram-based outbound C2 traffic and unexpected AWS S3 uploads from endpoints &#8212; Gamaredon GammaSteal indicators</p></li><li><p>Remove ATG fuel monitoring systems from any direct internet exposure</p></li><li><p>Brief employees on LinkedIn-based intelligence recruitment following Five Eyes joint advisory</p></li><li><p>Enforce voice phishing verification procedures &#8212; Carnival and Charter both started with one phone call</p></li><li><p>Implement connection limits and HPACK protections on all internet-facing web servers</p></li><li><p>Review GitHub Actions OIDC trust policies and restrict secrets access from external fork triggers</p></li><li><p>Patch Redis if self-hosted &#8212; CVE-2026-23479 use-after-free, public exploit available</p></li><li><p>Restrict ASUS router management interfaces to trusted IP ranges until end-of-June patches arrive</p></li></ul><p><strong>Strategic (This Quarter)</strong></p><ul><li><p>Evaluate AI-assisted vulnerability management &#8212; Mythos, AI-discovered Redis zero-day, and HTTP/2 Bomb discovery all demonstrate autonomous discovery at operational scale</p></li><li><p>Expand insider threat monitoring to include financial market abuse, prediction markets, and cryptocurrency monetization scenarios</p></li><li><p>Accelerate migration to FIDO2 and passkeys &#8212; OAuth device code MFA bypass and real-time OTP interception are at industrial scale</p></li><li><p>Compress vulnerability remediation SLAs for internet-facing systems to match actual exploitation timelines</p></li><li><p>Review organizational LinkedIn exposure policies and communicate Five Eyes insider recruitment advisory to all staff with sensitive access</p></li><li><p>Require CVE assignment and public changelog disclosure from all AI vendors with privileged developer environment access</p></li><li><p>Establish physical social engineering tabletop exercises incorporating front desk, USB device, and visitor management scenarios</p></li></ul><h3><strong>&#127897;&#65039; James Azar&#8217;s CISO&#8217;s Take</strong></h3><p>When I look across this week&#8217;s four episodes, the defining theme is operational speed and the widening gap between how fast attackers are moving and how fast most organizations are structured to respond. Palo Alto GlobalProtect went from disclosure to CISA KEV with a federal deadline of June 1. FlowWise received public root exploit code the same day. The HTTP/2 Bomb can crash major web servers in twenty seconds. The Netlogon vulnerability requires one network packet and no credentials. Against that backdrop, organizations still operating on 30-day patch cycles for internet-facing critical infrastructure are not just behind they are accepting risk they have not explicitly acknowledged. The fundamentals are the battle. Not dashboards, not AI tools, not frameworks. Patch fast. Detect faster. Train your people. That&#8217;s it.</p><p>The second major takeaway is that AI has become a fully operational force multiplier on both sides simultaneously. Mythos is autonomously discovering vulnerabilities at a scale no human team can match and is now deployed across NATO, critical infrastructure, and major technology organizations. GreyVibe is using ChatGPT and Gemini throughout its kill chain as operational infrastructure, not experiments. OpenAI&#8217;s Codex discovered the HTTP/2 Bomb autonomously. And attackers are selling AI-generated phishing campaigns as subscription services. Security leaders who are still treating AI as a future challenge rather than a present operational reality are working with an incomplete picture of the battlefield they are operating on today.</p><p><strong>Stay Cyber Safe.</strong> &#128272;</p><h3><strong>&#128203; Week in Summary</strong></h3><p>This was the week speed proved itself the defining variable in cybersecurity not sophistication, not resources, not tooling. The HTTP/2 Bomb crashes servers in twenty seconds. A single Jupyter notebook steals GitHub OAuth tokens before a user closes the window. Gamaredon deployed a USB worm, infostealer, and wiper capability through one WinRAR vulnerability in one coordinated operation. And Carnival&#8217;s six million victims trace back to a single voice phishing call against a single employee. The velocity of modern attacks does not leave time for 30-day governance workflows, approval chains, or scheduled patch cycles. The organizations matching attacker speed will survive. The ones that don&#8217;t will keep providing the case studies.</p><p>The intelligence and human-layer stories this week were equally significant. A Five Eyes joint advisory documented China&#8217;s systematic LinkedIn recruitment of government insiders at scale using professional networking platforms as intelligence collection infrastructure. A five-month espionage campaign extracted an executive&#8217;s entire strategic communications in small batches designed to be invisible to monitoring systems. A Google security engineer allegedly used privileged access to prediction markets rather than exfiltrating data. These are not technical problems with technical solutions. They are operational, human, and institutional challenges that require awareness programs, monitoring expansion, and cultural change in addition to security tooling. The battlefield has always been both technical and human. This week made that undeniably clear.</p><p>Stay informed. Stay prepared. <strong>Stay Cyber Safe.</strong> &#128272;</p><p><em>&#169; CyberHub Podcast | Subscribe on Substack | Watch on YouTube | Follow on LinkedIn</em></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-55?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-55?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-55?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[HTTP/2 Bomb Exploit Discovered by Codex AI Knocks Major Web Servers Offline in Seconds, Comm Proposes $11 Billion US Cyber Force With 30K Personnel, 2-Year-Old RCE in Redis Missed by Human Code Review]]></title><description><![CDATA[HTTP/2 Bomb Threatens Global Web Infrastructure, China Expands Human Intelligence Recruitment, and AI Discovers Another Critical Zero-Day]]></description><link>https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Thu, 04 Jun 2026 13:31:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200554068/423e3ef91675e7b781ed467a741d1e4f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>If there was one theme that dominated today&#8217;s show, it was this:</p><p><strong>The pace of cyber operations is accelerating faster than our institutions, infrastructure, and security programs were designed to handle.</strong></p><p>Today&#8217;s episode delivered one of the most diverse threat landscapes we&#8217;ve covered all year. We examined a newly disclosed HTTP/2 denial-of-service exploit capable of taking down major web servers in seconds, a publicly disclosed VS Code zero-day that steals GitHub OAuth tokens with a single click, a five-month espionage campaign that silently drained the mailbox of a senior stock exchange executive, and a Five Eyes intelligence warning revealing how China is actively recruiting government insiders through platforms many professionals use every day.</p><p>At the same time, AI continues reshaping cybersecurity at unprecedented speed. This week alone, AI systems discovered critical vulnerabilities in both Redis and web infrastructure while organizations continue struggling to patch vulnerabilities discovered years ago. The message is becoming increasingly clear: attackers are accelerating, AI is accelerating, and defenders must adapt or risk falling behind.</p><p>Double espresso in hand, coffee cup cheers, gang. Let&#8217;s dive in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape revealed four converging realities that every security leader should be paying attention to.</p><p>First, AI-assisted vulnerability discovery is dramatically compressing the timeline between identifying weaknesses and operational exploitation. Second, developer environments and software supply chains continue emerging as some of the most valuable attack surfaces available to threat actors. Third, nation-state intelligence services are increasingly blending traditional espionage techniques with cyber operations, targeting both technical systems and human assets simultaneously. Finally, critical infrastructure and internet-facing services remain dangerously exposed due to patching delays, misconfigurations, and operational complexity.</p><p>Every story today reinforced the same conclusion: speed is now the defining factor in cybersecurity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HHb9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HHb9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HHb9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:212209,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/200554068?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HHb9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!HHb9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F474a2267-cd3d-4f10-b872-f446b9d74da3_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><blockquote><p><em>&#8220;The pace of cyber operations is accelerating faster than our institutions were designed to handle.&#8221; James Azar</em></p></blockquote><h2>&#128163; HTTP/2 Bomb Can Crash Major Web Servers in Under a Minute</h2><p>The most urgent technical story today involved the disclosure of CVE-2026-49975, a remote denial-of-service vulnerability researchers are calling the &#8220;HTTP/2 Bomb.&#8221; The flaw impacts several of the world&#8217;s most widely deployed web server technologies, including Apache HTTP Server, Microsoft&#8217;s IIS, Envoy Proxy, and Cloudflare&#8217;s Pingora infrastructure.</p><p>The attack combines two previously understood concepts into a highly effective denial-of-service technique. First, attackers abuse HPACK compression mechanisms to force servers into allocating enormous amounts of memory while decompressing relatively small amounts of malicious traffic. Then, by combining the attack with slow connection techniques similar to Slowloris, the server is prevented from releasing that memory once allocated.</p><p>The results are staggering. Researchers demonstrated that a single client connected through a standard residential internet connection could consume and hold approximately 32 gigabytes of memory on vulnerable Apache and Envoy servers in roughly twenty seconds.</p><p>What makes this especially concerning is the scale. Researchers estimate more than 880,000 public websites are potentially affected by default configurations. Nginx quietly patched the issue earlier this year, while Apache released fixes in late May. However, Microsoft IIS, Envoy, and Cloudflare&#8217;s Pingora remained unpatched as of publication.</p><p>The broader significance of this story is equally important. The vulnerability was discovered using OpenAI&#8217;s Codex platform, marking the second major AI-assisted vulnerability discovery disclosed this week. That trend is no longer theoretical, it is operational.</p><p>Organizations should immediately patch Apache and Nginx deployments, implement strict connection limits, enforce HPACK restrictions, and review mitigation options at load balancer and web application firewall layers.</p><h2>&#128187; VS Code Zero-Day Steals GitHub Tokens With a Single Click</h2><p>The developer community was rocked this week after security researcher Amar Askar publicly disclosed a VS Code zero-day vulnerability capable of stealing GitHub OAuth tokens through a remarkably simple attack chain.</p><p>The vulnerability exploits several behaviors within VS Code&#8217;s notebook and extension ecosystem. By delivering a malicious Jupyter notebook file, attackers can execute JavaScript inside a WebView iframe. The script then silently installs a malicious extension by triggering synthetic keyboard shortcuts and exploiting GitHub&#8217;s automatic authentication behavior between GitHub.com and GitHub.dev.</p><p>Once the extension is installed, it intercepts OAuth tokens before they reach GitHub&#8217;s web environment and exfiltrates them to the attacker.</p><p>The most alarming aspect is the blast radius. These tokens do not simply grant access to a single repository. They provide access to every private repository the victim can access through GitHub.</p><p>No patch is currently available.</p><p>This story continues reinforcing what we&#8217;ve seen throughout 2026: developer environments have become one of the highest-value targets in cybersecurity. Developers often hold privileged access to source code, cloud infrastructure, secrets, CI/CD systems, and deployment pipelines, making them prime targets for sophisticated attackers.</p><p>Organizations should immediately review installed VS Code extensions, restrict use of untrusted Jupyter notebooks, and consider disabling notebook functionality on systems where it is not required.</p><h2>&#128200; Five-Month Espionage Campaign Targets Global Stock Exchange Executive</h2><p>One of the most fascinating espionage reports of the year came from Symantec&#8217;s threat hunting team, which documented a highly disciplined operation targeting a senior executive at a major global stock exchange.</p><blockquote><p><em>&#8220;The gap between attacker tempo and institutional response time is becoming the defining characteristic of this threat environment.&#8221; James Azar</em></p></blockquote><p>Unlike many modern attacks focused on disruption or ransomware, this campaign was remarkably restrained. Over a period of five months, attackers quietly extracted the executive&#8217;s Outlook mailbox in carefully staged increments.</p><p>The attackers used malware disguised as Adobe and OneDrive services while leveraging legitimate tools and cloud services to avoid detection. Exfiltration occurred through Dropbox and personal OneDrive accounts. Particularly noteworthy was their use of hardcoded Microsoft-owned IP addresses rather than normal OneDrive hostnames, effectively bypassing DNS-based monitoring controls.</p><p>The attackers avoided large data transfers, instead stealing information in smaller date-based batches. The result was complete visibility into the executive&#8217;s communications, calendar data, strategic discussions, and market-related correspondence.</p><p>For intelligence services, this type of access can be far more valuable than a disruptive attack. Market-moving information, regulatory discussions, merger activity, and strategic planning all carry significant intelligence value.</p><p>The report serves as a reminder that some of the most dangerous adversaries aren&#8217;t trying to make noise, they&#8217;re trying to remain invisible.</p><h2>&#127464;&#127475; Five Eyes Warn China Is Recruiting Government Insiders Through LinkedIn</h2><p>One of the most significant geopolitical stories today came through a joint advisory issued by intelligence agencies from the United States, Canada, the United Kingdom, Australia, and New Zealand. The warning outlines how Chinese intelligence services are systematically recruiting government employees, military personnel, contractors, and critical infrastructure workers through professional networking platforms.</p><p>The process follows a surprisingly structured methodology. Targets are initially approached through platforms like LinkedIn, Indeed, and Upwork. Once contact is established, recruiters evaluate the individual&#8217;s access, responsibilities, and potential value. Victims are often asked to produce seemingly harmless research reports before gradually being tasked with increasingly sensitive topics.</p><p>Compensation is typically provided through:</p><ul><li><p>PayPal</p></li><li><p>Payoneer</p></li><li><p>Wise</p></li><li><p>Skrill</p></li><li><p>Cryptocurrency</p></li><li><p>Traditional wire services</p></li></ul><p>The advisory stresses that classified access is not required to become a target. Information such as facility layouts, contract details, budget planning, vendor relationships, and internal policies may appear harmless individually but can become extraordinarily valuable when aggregated.</p><p>Perhaps most concerning is the migration path. Once trust is established, communications move from public platforms to encrypted services such as Signal and Telegram, effectively moving activity outside organizational visibility.</p><p>This campaign strongly resembles North Korea&#8217;s long-running use of fake recruiters and employment opportunities to collect intelligence. China appears to be adapting that model at scale.</p><p>Security leaders should use this advisory as a catalyst for reviewing insider threat awareness programs and LinkedIn exposure policies.</p><h1>&#9889; Need to Know</h1><div class="callout-block" data-callout="true"><p>"This is something I'm hammering home with my team all day long. Forget all the shiny tools that are coming out right now. Forget about all of them. If we can't do the fundamentals well, none of those tools are going to help. That's the reality." James Azar</p></div><h3>&#129302; AI Discovers Redis Zero-Day Missed for Two Years</h3><p>An autonomous security tool identified CVE-2026-23479, a use-after-free vulnerability in Redis that had existed unnoticed since 2023. Public exploit code is now available. Redis Cloud has been patched, but self-hosted deployments require immediate upgrades.</p><h3>&#9981; Federal Agencies Warn of Fuel Monitoring System Attacks</h3><p>CISA, FBI, NSA, DOE, TSA, EPA, and several other agencies jointly warned about active attacks targeting Automatic Tank Gauge (ATG) systems used at fuel stations, transportation hubs, and chemical facilities. Attackers are exploiting internet-exposed systems protected only by default passwords.</p><h3>&#129302; Five AI Agent Zero-Days Patched</h3><p>Researchers disclosed five vulnerabilities affecting OpenClaw, an AI agent framework integrating with Slack, Teams, Discord, and other collaboration platforms. The flaws allowed attackers to impersonate authorized users through display-name manipulation. All issues have been patched.</p><h3>&#128225; ASUS Router Vulnerabilities Await Fixes</h3><p>Two critical vulnerabilities affecting ASUS Wave 7 mesh routers expose credentials and allow persistent backdoor installation. No patches are expected until the end of June, leaving organizations reliant on compensating controls in the interim.</p><h3>&#127464;&#127475; Chinese Threat Actors Using LLM-Assisted Malware</h3><p>Proofpoint reported that TA-4922, a Chinese cybercrime group targeting Europe, appears to be using LLM-assisted development techniques to accelerate malware creation and campaign generation.</p><h3>&#129686; Proposal Calls for Independent U.S. Cyber Force</h3><p>A new policy report recommends creation of a dedicated U.S. Cyber Force consisting of approximately 30,000 personnel and costing an estimated $11 billion. Supporters argue cyber operations have grown large enough to justify their own military branch.</p><h3>&#127963;&#65039; CISA Staffing Shortages Remain a Challenge</h3><p>Homeland Security leadership confirmed that CISA remains significantly understaffed, operating with approximately 2,200 employees despite authorization for substantially more. Efforts to rebuild the agency continue.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode highlighted a cybersecurity environment where AI is accelerating vulnerability discovery, nation-state actors are blending human intelligence and cyber operations, and critical infrastructure remains exposed through basic operational weaknesses.</p><p>The challenge isn&#8217;t simply identifying threats anymore.</p><p>The challenge is keeping pace with them.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch Apache and Nginx deployments vulnerable to HTTP/2 Bomb attacks</p></li><li><p>Implement connection limits and HPACK protections on internet-facing web servers</p></li><li><p>Audit VS Code extensions and restrict untrusted Jupyter notebook execution</p></li><li><p>Review GitHub OAuth exposure and developer workstation security</p></li><li><p>Hunt for suspicious Dropbox and OneDrive exfiltration activity</p></li><li><p>Brief employees on LinkedIn-based intelligence recruitment risks</p></li><li><p>Patch Redis environments immediately if self-hosted</p></li><li><p>Remove ATG systems from direct internet exposure</p></li><li><p>Restrict ASUS router management interfaces to trusted IP ranges</p></li><li><p>Review AI agent authorization controls and identity validation processes</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is that every major story reflected the same underlying problem: speed. AI discovered vulnerabilities that sat unnoticed for years. Attackers leveraged trusted developer environments to steal credentials in under a minute. Nation-state operators quietly extracted executive communications for months without detection. The common thread isn&#8217;t sophistication&#8212;it&#8217;s velocity. Threat actors are moving faster than many organizations are structured to respond.</p><p>The second takeaway is that cybersecurity can no longer be viewed purely as a technical discipline. Today&#8217;s Five Eyes advisory demonstrates that nation-state intelligence operations increasingly blend cyber activity with human recruitment, social engineering, and insider targeting. Meanwhile, AI is becoming a force multiplier for both attackers and defenders. Organizations that continue separating technology risk from human risk will increasingly find themselves defending only half the battlefield.</p><p>&#128293; Stay Cyber Safe.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/http2-bomb-exploit-discovered-by?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Trump Signs Executive Order Establishing Voluntary Federal Vetting of Frontier AI Models, Android June Update Patches Exploited Zero-Day, Spain Arrests Hacker Who Published Data on Sensitive Govt Work]]></title><description><![CDATA[Trump Signs AI Vetting Executive Order, Russian APT Deploys USB Worm, and Anthropic Expands Mythos to NATO]]></description><link>https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Wed, 03 Jun 2026 13:30:25 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200395241/2eb3ae86d2401e69e2f48648b7bbb813.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s episode highlighted one reality that defenders can no longer ignore:</p><p><strong>The pace of cyber operations is now significantly outpacing the pace of institutional response.</strong></p><p>Whether it was Russian threat actors deploying self-propagating malware against Ukrainian targets, AI models identifying vulnerabilities faster than organizations can patch them, actively exploited WordPress vulnerabilities impacting more than a million websites, or governments attempting to establish AI oversight frameworks while the technology evolves in real time, every story today pointed to the same conclusion.</p><p>Attackers are moving faster. AI is moving faster. Exploit development is moving faster. And many organizations are still trying to respond with processes built for a much slower era.</p><p>Double espresso in hand, today&#8217;s special Elite coffee capsule from Israel was an absolute winner, coffee cup cheers, gang. Let&#8217;s get into it.</p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s cybersecurity landscape showcased the collision between emerging AI governance, accelerating nation-state cyber operations, and increasingly automated attack infrastructure.</p><p>Russian APT operators are weaponizing zero-day vulnerabilities to deliver modular malware frameworks capable of propagating through USB devices, network shares, Telegram infrastructure, AWS services, and destructive wiper capabilities. At the same time, Anthropic is expanding its Mythos vulnerability discovery platform to critical infrastructure operators worldwide, while the U.S. government introduces a voluntary AI review process aimed at balancing innovation with national security concerns.</p><p>The common denominator across every story is speed. Attackers are automating discovery, exploitation, persistence, and exfiltration. Defenders are increasingly being asked to operate at machine speed in environments that still rely heavily on human processes.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oX9G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oX9G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oX9G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:224976,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/200395241?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oX9G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!oX9G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15683c76-2e60-479c-9fa2-35a3c5b3b441_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#127479;&#127482; Gamaredon Exploits WinRAR Vulnerability to Deploy USB Worm Against Ukraine</h2><p>One of the most significant nation-state stories today came from researchers at Seqrite, who detailed a new campaign from Gamaredon, the Russian FSB-linked threat group known for sustained attacks against Ukrainian government, military, and critical infrastructure organizations.</p><p>The group is actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to initiate a multi-stage infection chain delivering several malware families. The initial compromise deploys &#8220;GammaLoad,&#8221; which acts as a downloader for additional tooling. From there, victims receive GammaWorm, a USB-propagating worm capable of spreading through removable media and network shares while hiding itself using NTFS alternate data streams to avoid detection.</p><p>The campaign becomes particularly dangerous because the worm retrieves command-and-control instructions through public Telegram channels, blending malicious communications into otherwise legitimate enterprise traffic. A second payload, GammaSteal, focuses on information theft and exfiltrates targeted files directly into attacker-controlled AWS S3 buckets.</p><p>Researchers also noted the framework&#8217;s ability to deploy GammaWipe, a destructive wiper module previously observed throughout the Russia-Ukraine conflict.</p><p>What makes Gamaredon different from many threat groups is persistence. These campaigns are not smash-and-grab operations. They often remain active for months, continuously adapting and evolving while maintaining long-term access to targeted environments.</p><p>Organizations with Ukrainian partners, shared infrastructure, or cross-border collaboration should review WinRAR patching status immediately and monitor for suspicious Telegram-related outbound traffic and unexpected S3 uploads originating from endpoints.</p><h2>&#129302; Trump Signs Executive Order Establishing AI Security Vetting Framework</h2><p>President Donald Trump signed a new executive order establishing a voluntary federal review framework for advanced AI models intended to assess national security risks prior to public release.</p><p>The order marks a significant shift from an earlier draft proposal that would have imposed mandatory ninety-day reviews. Instead, organizations developing frontier AI models can voluntarily submit systems for government evaluation, with agencies expected to complete assessments within thirty days.</p><p>The framework introduces several key initiatives:</p><ul><li><p>AI cybersecurity capability benchmarking</p></li><li><p>National security risk evaluations</p></li><li><p>Creation of an AI cybersecurity clearinghouse</p></li><li><p>Government-industry collaboration mechanisms</p></li><li><p>Information sharing related to AI vulnerabilities and threats</p></li></ul><p>The practical significance here isn&#8217;t necessarily regulatory. It&#8217;s operational.</p><p>Governments historically struggle to move at the pace of technology. Making participation voluntary creates incentives for collaboration rather than compliance-driven resistance. If implemented correctly, it may allow federal agencies to gain visibility into rapidly evolving AI capabilities without slowing innovation.</p><p>The larger question remains whether government oversight can evolve quickly enough to remain relevant as AI systems continue advancing at unprecedented speed.</p><h2>&#127760; WordPress Plugin Vulnerability Actively Exploited Across One Million Sites</h2><p>A critical vulnerability affecting the popular Kirki page builder plugin is now under active exploitation. The flaw, tracked as CVE-2026-8206, impacts more than one million WordPress installations and carries a CVSS score of 9.8.</p><p>The vulnerability stems from a broken password reset mechanism that allows attackers to substitute their own email address during account recovery. By submitting a target username and an attacker-controlled email address, the plugin generates legitimate password reset links and sends them directly to the attacker.</p><p>No credentials are required.<br>No user interaction is required.<br>One request is enough.</p><p>Once attackers gain administrative access, they are installing malicious plugins, creating rogue administrator accounts, injecting SEO spam, and deploying persistent backdoors.</p><p>This incident highlights a recurring problem within the WordPress ecosystem: a single plugin vulnerability can simultaneously expose hundreds of thousands of websites because of the platform&#8217;s massive deployment footprint.</p><p>Organizations running affected versions should immediately update to version 6.0.7 or disable the plugin entirely.</p><h2>&#129504; Anthropic Expands Mythos Vulnerability Discovery Platform</h2><p>Perhaps the most strategically important story of the day involved Anthropic&#8217;s expansion of Project Glasswing and its Mythos vulnerability discovery platform. Anthropic announced that another 150 organizations across fifteen countries will gain access to Mythos, including NATO, ENISA, Samsung, healthcare providers, utilities, communications providers, and critical infrastructure operators.</p><p>Mythos previously identified more than:</p><ul><li><p>23,000 potential vulnerabilities</p></li><li><p>10,000+ high and critical issues</p></li><li><p>Thousands of previously unknown flaws</p></li></ul><p>This isn&#8217;t simply AI-assisted code review.</p><p>Mythos is increasingly functioning as an autonomous vulnerability discovery platform capable of identifying weaknesses at a scale no human team could reasonably match.</p><p>The timing is particularly interesting because the announcement coincides with the AI executive order signed the same day. While governments discuss frameworks for evaluating AI security risks, AI is already being deployed at scale to identify vulnerabilities throughout critical infrastructure environments.</p><p>The future of cybersecurity may increasingly depend on whether organizations gain access to tools like Mythos&#8212;or become targets discovered by them.</p><h1>&#9889; Need to Know</h1><blockquote><p><em>&#8220;The gap between attacker tempo and institutional response time is becoming the defining characteristic of this threat environment.&#8221;</em></p></blockquote><h3>&#127963;&#65039; Oracle WebLogic Added to CISA KEV Catalog</h3><p>CISA added CVE-2024-21182, a critical Oracle WebLogic remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers are using the flaw to deploy Cobalt Strike and ransomware payloads. Organizations should patch immediately and review exposed WebLogic services.</p><h3>&#128241; Android Patches Active Zero-Day</h3><p>Google released Android&#8217;s June security updates, addressing 124 vulnerabilities, including CVE-2025-48595, a privilege escalation flaw confirmed under limited active exploitation. Organizations managing Android fleets should accelerate patch deployment through MDM platforms.</p><h3>&#127464;&#127475; Mustang Panda Returns</h3><p>Chinese APT Mustang Panda resurfaced with a new PlugX malware delivery campaign using fake Adobe Acrobat update prompts. The malware leverages signed binaries and memory-only execution techniques to reduce detection.</p><h3>&#128176; Sierra Reaches $12 Billion Valuation</h3><p>AI security company Sierra is reportedly raising an additional $300 million at a $12 billion valuation despite generating approximately $150 million in annual recurring revenue. The valuation reflects the extraordinary premium investors continue placing on AI security and automation platforms.</p><h3>&#127466;&#127480; Spain Arrests Government Data Hacker</h3><p>Spanish authorities arrested an individual accused of publishing sensitive information belonging to national police, intelligence personnel, and Spain&#8217;s cybersecurity agency. The incident serves as a reminder that cybersecurity professionals increasingly face physical-world targeting through doxxing campaigns.</p><h3>&#127479;&#127482; Russia Makes New Espionage Claims</h3><p>Russia&#8217;s FSB issued claims regarding a large-scale foreign espionage operation targeting senior officials through mobile devices but provided little technical evidence supporting the allegations. The announcement appears consistent with ongoing information operations surrounding cyber activity and geopolitical tensions.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t really about vulnerabilities, AI, or government policy.</p><p>It was about speed.</p><p>Gamaredon is operating faster than international cyber norms can be debated.<br>Mythos is finding vulnerabilities faster than organizations can patch them.<br>Attackers are exploiting WordPress plugins faster than administrators can update them.<br>AI capabilities are evolving faster than governments can regulate them.</p><p>The defining challenge of cybersecurity in 2026 isn&#8217;t a lack of tools or information.</p><p>It&#8217;s the widening gap between attacker tempo and institutional response.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch WinRAR for CVE-2025-8088 immediately</p></li><li><p>Monitor for suspicious Telegram-related outbound traffic</p></li><li><p>Review AWS S3 uploads originating from endpoints</p></li><li><p>Update or disable vulnerable Kirki WordPress plugin deployments</p></li><li><p>Patch Oracle WebLogic environments added to the KEV catalog</p></li><li><p>Deploy June Android security updates across managed devices</p></li><li><p>Hunt for Mustang Panda PlugX indicators</p></li><li><p>Review doxxing exposure for cybersecurity leadership and staff</p></li><li><p>Evaluate AI-assisted vulnerability management capabilities</p></li><li><p>Reassess patching timelines for internet-facing infrastructure</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how clearly every story reflects the same underlying trend. Whether we&#8217;re discussing Russian cyber operations, AI-driven vulnerability discovery, WordPress exploitation, or federal AI oversight, the common denominator is acceleration. The speed of discovery, exploitation, and operational deployment continues increasing while many organizations remain constrained by traditional governance models, approval processes, and remediation timelines. That mismatch creates risk regardless of industry or geography.</p><p>The second takeaway is that AI is no longer a future cybersecurity issue&#8212;it is a present cybersecurity force multiplier. Mythos is already identifying vulnerabilities at scales impossible for human teams. Threat actors are already using AI to enhance phishing, malware development, and reconnaissance. Governments are now attempting to create frameworks around technologies that are already operational. Organizations that treat AI as tomorrow&#8217;s challenge rather than today&#8217;s reality are likely underestimating both the opportunity and the risk.</p><p>&#128293; Stay Cyber Safe.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/trump-signs-executive-order-establishing?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Critical Windows Netlogon Zero-Click RCE Now Actively Exploited, Hackers Trick Meta AI Support Chatbot Into Handing Over Instagram Accounts , Microsoft Walks Back Threat to Sue Security Researchers ]]></title><description><![CDATA[Windows NetLogon Zero-Click RCE Exploited (ZeroLogon 2.0), Meta AI Chatbot Handing Out Instagram Account Resets, Miasma Worm Hits 32 Red Hat npm Packages, ClickFix Hijacks Harvard, Oxford]]></description><link>https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Tue, 02 Jun 2026 13:31:52 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200223662/57ecd9d6d071f147fbc7e50f3973a876.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h3>&#9749; Good Morning Security Gang,</h3><p>Today&#8217;s show highlights something we&#8217;ve been discussing repeatedly throughout the year: trust itself is becoming the primary attack surface.</p><p>Whether it&#8217;s trust in Active Directory, trust in AI support agents, trust in open-source software packages, trust in websites from Harvard and Oxford, or trust in software supply chains, attackers are increasingly targeting the systems and relationships we depend on most. The technical vulnerabilities matter, but what we&#8217;re really seeing is the systematic erosion of digital trust across every layer of enterprise technology.</p><p>Today&#8217;s episode featured eleven major stories spanning actively exploited Windows vulnerabilities, AI-powered account takeovers, software supply chain compromises, large-scale website hijacking campaigns, cloud security concerns, and several important developments in the security research community. The pace of both attacks and defensive responses continues to accelerate, forcing organizations to rethink how quickly they can identify, prioritize, and mitigate risk.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TklV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TklV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!TklV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!TklV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!TklV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TklV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/edcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209992,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/200223662?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TklV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!TklV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!TklV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!TklV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedcdc1d9-b8cf-4c85-b83d-8b9782c6929c_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories</h1><blockquote><p><em>&#8220;The attacker playbook has converged on trust infrastructure as the attack surface.&#8221; James Azar</em></p></blockquote><h2>&#128680; Windows Netlogon Vulnerability Being Compared to Zerologon</h2><p>The most urgent story of the day centered on CVE-2026-21176, a critical Netlogon vulnerability affecting Windows Domain Controllers that security researchers are already comparing to the infamous Zerologon flaw.</p><p>The vulnerability is a pre-authentication, zero-click, stack-based buffer overflow within the Netlogon service. Attackers require only a single specially crafted network packet to achieve system-level code execution directly on a Domain Controller. No credentials, no user interaction, and no prior access are required. Microsoft patched the issue during May&#8217;s Patch Tuesday release, but organizations that have not yet updated their Domain Controllers remain vulnerable today.</p><p>This vulnerability is particularly dangerous because Domain Controllers remain the crown jewels of most Windows environments. Once an attacker gains control of a Domain Controller, the path to full forest compromise becomes significantly easier. The attack continues a broader trend we&#8217;ve observed throughout 2026 where identity infrastructure has become the primary target for both ransomware operators and nation-state actors.</p><p>Organizations should immediately verify patch deployment, confirm Netlogon protections are enabled, and ensure critical services such as SMB and RPC are not exposed externally.</p><h2>&#129302; Meta AI Accidentally Handed Out Instagram Accounts</h2><p>One of the most talked-about stories today involved Meta&#8217;s AI-powered support assistant inadvertently helping attackers take over Instagram accounts.</p><p>According to researchers, attackers discovered they could interact directly with Meta&#8217;s support chatbot and request account recovery actions on behalf of victims. By providing a target account, adding a new email address, and completing a verification process controlled entirely through the chatbot, attackers could effectively reset passwords and gain control of accounts without the legitimate owner&#8217;s involvement. Victims reportedly included high-profile government, military, and cybersecurity community accounts.</p><p>Meta has since fixed the issue, but the incident highlights a growing challenge facing AI deployments. When AI systems are granted administrative authority without sufficient identity verification controls, they become privileged attack surfaces. The chatbot wasn&#8217;t vulnerable because it was AI&#8212;it was vulnerable because it was trusted to perform sensitive account functions without properly validating who was making the request.</p><p>This won&#8217;t be the last AI trust-boundary failure we see.</p><h2>&#128230; Red Hat Supply Chain Attack Compromises 32 npm Packages</h2><p>The software supply chain attacks continue.</p><p>Researchers uncovered a campaign dubbed &#8220;Miasma&#8221; that compromised thirty-two official Red Hat npm packages with a combined weekly download count exceeding 117,000. The attack originated after a Red Hat employee&#8217;s GitHub account was compromised, allowing attackers to inject malicious code into repositories and leverage GitHub Actions OIDC workflows to distribute malware through trusted package pipelines.</p><p>The malicious packages harvested:</p><ul><li><p>AWS credentials</p></li><li><p>Azure credentials</p></li><li><p>Google Cloud credentials</p></li><li><p>GitHub tokens</p></li><li><p>SSH keys</p></li><li><p>npm authentication tokens</p></li></ul><p>The malware itself represents an evolution of the Mini Shai-Hulud campaign that has been repeatedly appearing throughout recent software supply chain incidents.</p><p>What makes this attack notable is that the attackers didn&#8217;t compromise npm directly. Instead, they compromised trust within the CI/CD process itself. That distinction matters because many organizations continue focusing on package integrity while overlooking the pipelines responsible for building and publishing those packages.</p><p>Any organization using affected packages should immediately rotate credentials and review build pipelines for signs of compromise.</p><h2>&#127760; ClickFix Campaign Hijacks Hundreds of Trusted Websites</h2><p>The ClickFix campaign continues to evolve and expand.</p><p>Attackers are actively exploiting vulnerabilities in Ghost CMS installations to compromise over 700 websites, including prominent institutions such as Harvard University, Oxford University, Auburn University, and DuckDuckGo-powered properties. Once compromised, attackers inject malicious JavaScript that presents visitors with fake CAPTCHA or browser verification prompts.</p><p>Instead of solving a challenge, users are instructed to press Windows+R and execute commands manually. Those commands launch PowerShell payloads that download malware directly onto victim systems.</p><blockquote><p><em>&#8220;When Harvard, Oxford, and your own software supply chain can all become malware delivery platforms, trust becomes your most valuable asset.&#8221; James Azar</em></p></blockquote><p>What makes ClickFix effective is that it bypasses traditional security awareness training. Most users have learned to distrust email attachments, but many still trust browser prompts appearing on legitimate websites.</p><p>This campaign demonstrates how attackers continue adapting social engineering tactics to exploit trust relationships users rarely question.</p><h1>&#9889; Security Leaders Need to Know</h1><h3>&#128275; OpenAI Codex Token Theft Campaign</h3><p>Researchers discovered a popular npm package called <code>codex-ui-android</code> that was secretly exfiltrating OpenAI Codex OAuth tokens, including long-lived refresh tokens. The package accumulated over 26,000 weekly downloads before detection. Organizations using OpenAI development environments should immediately revoke and reissue Codex credentials.</p><h3>&#128273; Dashlane Stops Brute Force Attack</h3><p>Password manager provider Dashlane confirmed it detected and mitigated a brute-force campaign attempting to register unauthorized devices against customer accounts. While some encrypted vaults were copied, no master passwords were exposed, limiting the impact. Customers should still review registered devices and account activity.</p><h3>&#9878;&#65039; Microsoft Backs Down From Threats Against Security Researchers</h3><p>Just one day after suggesting legal action against researchers releasing uncoordinated vulnerabilities, Microsoft reversed course and clarified that it has no plans to pursue legal action against independent security researchers. The move follows significant backlash from the cybersecurity community and appears aimed at reducing tensions surrounding recent disclosures from Nightmare Eclipse.</p><h3>&#9729;&#65039; Container and Kubernetes Attacks Continue Growing</h3><p>Researchers warned about active exploitation of container and Kubernetes misconfigurations, including exposed Docker APIs, weak RBAC permissions, and poisoned container images. Several campaigns are now specifically targeting cloud-native infrastructure and Kubernetes secrets.</p><h3>&#128039; Linux Kernel Privilege Escalation Gets Public Exploit</h3><p>A proof-of-concept exploit is now publicly available for the recently disclosed nineteen-year-old Linux kernel privilege escalation vulnerability. Organizations that delayed patching now face significantly elevated risk as exploitation becomes easier for attackers.</p><h3>&#127981; Dragos Acquires Phosphorus</h3><p>Industrial cybersecurity leader Dragos announced its acquisition of Phosphorus, expanding its ability to secure IoT devices within operational technology environments. The move reflects the continued convergence between traditional OT security and connected device management.</p><h3>&#127482;&#127480; NSA Fills Key Cybersecurity Leadership Roles</h3><p>The NSA formally appointed David Imbordino as Cyber Director and Bruce Jones to lead the Cybersecurity Collaboration Center, ending a prolonged leadership gap and restoring continuity for government-private sector cybersecurity partnerships.</p><h1>&#127919; Key Takeaway</h1><p>Today&#8217;s episode wasn&#8217;t really about vulnerabilities.</p><p>It was about trust.</p><p>Trust in your Domain Controllers.<br>Trust in your AI assistants.<br>Trust in your package repositories.<br>Trust in your websites.<br>Trust in your software supply chain.</p><p>Attackers increasingly understand that compromising trust creates significantly greater impact than compromising individual systems. As organizations adopt AI, cloud-native development, and increasingly interconnected ecosystems, protecting those trust relationships becomes just as important as protecting infrastructure itself.</p><h1>&#128736;&#65039; Action Items</h1><ul><li><p>Patch all Windows Domain Controllers immediately</p></li><li><p>Verify Netlogon protections and firewall exposure</p></li><li><p>Audit Instagram and Meta-linked accounts for unauthorized recovery changes</p></li><li><p>Rotate cloud and development credentials if affected Red Hat packages were installed</p></li><li><p>Review GitHub Actions OIDC trust policies</p></li><li><p>Patch Ghost CMS deployments immediately</p></li><li><p>Train users to recognize ClickFix-style social engineering prompts</p></li><li><p>Revoke OpenAI Codex tokens if affected packages were present</p></li><li><p>Review Dashlane account device registrations</p></li><li><p>Audit Kubernetes and Docker environments for exposed APIs and excessive privileges</p></li><li><p>Patch Linux systems vulnerable to newly weaponized privilege escalation exploits</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how consistently attackers are targeting systems that sit at the center of organizational trust. Domain Controllers establish identity trust. AI assistants establish user trust. Package repositories establish software trust. Websites establish content trust. Every major story today involved an attacker exploiting one of those relationships rather than simply exploiting a technical vulnerability. That&#8217;s an important distinction because fixing trust failures requires more than patching software&#8212;it requires rethinking how we validate, authorize, and monitor critical interactions.</p><p>The second takeaway is that the pace of cybersecurity continues accelerating. Yesterday&#8217;s controversy involving Microsoft and security researchers was largely resolved within twenty-four hours. Public exploit code is now appearing almost immediately after disclosures. Supply chain attacks are moving from one ecosystem to another in days rather than months. Security leaders need operating models that can respond to events at this speed because attackers are no longer waiting for quarterly patch cycles or annual security reviews.</p><p>&#128293; Stay Cyber Safe.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/critical-windows-netlogon-zero-click?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Palo Alto GlobalProtect VPN Auth Bypass Now Actively Exploited, Carnival Cruise Breach Exposes 6 Million Records, Microsoft Threatens Legal Action After Researcher Nightmare-Eclipse Drops Six Windows ]]></title><description><![CDATA[GlobalProtect 0-Day Under Active Attack, AI Infrastructure Exploits Go Public, and Russian Threat Actors Fully Embrace Generative AI]]></description><link>https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Mon, 01 Jun 2026 13:31:42 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200059156/ea3bb8f07715d8aacdc2f054d5fcbcc3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h1>&#9749; Good Morning Security Gang,</h1><p>Today&#8217;s show highlighted a reality that every security leader needs to accept: the pace of cyber operations is accelerating faster than many organizations can adapt. We have an actively exploited Palo Alto GlobalProtect VPN vulnerability with a federal remediation deadline of today, public exploit code for a critical AI platform remote code execution flaw, an escalating dispute between Microsoft and a zero-day researcher releasing vulnerabilities into the wild, a newly identified Russian threat actor using AI throughout its attack lifecycle, and confirmation that Carnival Cruise Lines joined the growing list of organizations compromised through a single successful social engineering attack.</p><p>The common theme throughout every story today was speed. Attackers are moving faster. Exploit development is moving faster. AI is accelerating both offense and defense. Meanwhile, organizations that still rely on traditional thirty-day patch cycles and legacy response models are finding themselves increasingly exposed.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s dive in.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s cybersecurity landscape demonstrates that attackers are no longer relying solely on technical sophistication. They are combining AI, social engineering, public exploit releases, supply chain targeting, and infrastructure attacks into highly efficient operational campaigns.</p><p>At the same time, defenders face mounting pressure from shrinking remediation windows. Vulnerabilities that once took weeks or months to weaponize are now being exploited within hours. AI development platforms have become attractive targets. VPN infrastructure remains one of the most common initial access vectors. And insider threat risks are expanding into entirely new areas, including prediction markets and cryptocurrency platforms.</p><p>The organizations that will succeed in this environment are those capable of matching attacker speed through rapid patching, continuous monitoring, strong identity controls, and relentless employee education.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6kgJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6kgJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6kgJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/200059156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6kgJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!6kgJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ee51210-e9a9-4d86-a5b3-abf69dde96d0_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><div class="callout-block" data-callout="true"><p>"The organizations that are going to weather this environment are the ones that match the attacker's operational speed. Patch fast. Detect faster. Train your people, because Carnival's six million victims and Charter's five million victims both started with one employee and one phone call." James Azar</p></div><h2>&#128680; Palo Alto GlobalProtect VPN Vulnerability Under Active Exploitation</h2><p>The most urgent story of the day centers on Palo Alto Networks&#8217; GlobalProtect VPN platform. Security researchers have confirmed active exploitation of CVE-2026-3401, a vulnerability affecting GlobalProtect gateways and specifically targeting local administrator accounts. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 1st, meaning today is the day agencies must complete mitigation efforts.</p><p>This vulnerability fits a pattern we&#8217;ve seen repeatedly throughout 2026. Edge devices including VPNs, firewalls, and remote access appliances&#8212;continue serving as primary entry points for both ransomware groups and nation-state operators. The concern isn&#8217;t simply that a vulnerability exists. The concern is that attackers are already exploiting it before many organizations have completed testing and deployment of patches.</p><p>Organizations running affected versions of PAN-OS should immediately upgrade to supported releases. If immediate patching is not possible, Palo Alto recommends separating the certificate used for GlobalProtect authentication cookies from the HTTP service certificate to disrupt the attack path.</p><p>The lesson remains consistent: internet-facing security infrastructure has become one of the highest-priority attack surfaces in enterprise environments.</p><h2>&#129302; Public Exploit Released for Critical FlowWise AI Platform Vulnerability</h2><p>The AI security conversation continues to intensify. Researchers published working exploit code for CVE-2026-40933, a critical remote code execution vulnerability affecting FlowWise, the popular open-source AI orchestration platform used to build large language model workflows and AI agents.</p><p>FlowWise has become extremely popular among developers because it allows organizations to visually build AI workflows without extensive coding. Unfortunately, that popularity also makes it an attractive target.</p><p>The exploit requires only a single user interaction. By importing a malicious chat flow, an attacker can trigger operating-system-level code execution with the privileges assigned to the FlowWise process. In many deployments, that means root-level access.</p><p>What makes this especially dangerous is where FlowWise sits within the enterprise ecosystem. These deployments are commonly connected to:</p><ul><li><p>Databases</p></li><li><p>Cloud services</p></li><li><p>API keys</p></li><li><p>Internal applications</p></li><li><p>AI development environments</p></li></ul><p>Compromising FlowWise often means compromising everything connected to it.</p><p>Organizations using self-hosted FlowWise instances should patch immediately, restrict import permissions, review administrative access, and rotate credentials connected to the platform.</p><h2>&#9878;&#65039; Microsoft Escalates Dispute With Zero-Day Researcher</h2><p>One of the more controversial stories today involves Microsoft&#8217;s ongoing battle with a researcher operating under the name Nightmare Eclipse. Microsoft formally responded to a series of public vulnerability disclosures and exploit releases, stating that the publication of working exploit code without coordinated disclosure is &#8220;never justifiable&#8221; and signaling that its Digital Crimes Unit may pursue legal action against those enabling cybercrime.</p><p>The dispute centers around six Windows zero-day vulnerabilities disclosed since April. Three are already actively exploited and listed in CISA&#8217;s Known Exploited Vulnerabilities catalog. Three others remain unpatched, with proof-of-concept exploit code publicly available.</p><p>The researcher alleges Microsoft terminated access to its vulnerability reporting program and withheld bounty payments. Microsoft disputes those claims.</p><p>This story highlights a longstanding tension within cybersecurity. Independent researchers play a critical role in vulnerability discovery, but public disclosure without available patches creates immediate risk for defenders. At the same time, bug bounty programs only succeed when researchers feel their work is treated fairly and transparently.</p><p>The cybersecurity community will be watching closely as this dispute unfolds.</p><h2>&#127760; Google Patches 151 Chrome Vulnerabilities</h2><p>Google released Chrome version 148, addressing 151 vulnerabilities, including 22 classified as critical and 123 rated high severity. Use-after-free bugs accounted for a significant portion of the fixes, representing one of the most commonly exploited browser vulnerability classes.</p><p>While Google reports no active exploitation of these specific flaws at the time of release, recent industry data shows that over 20% of vulnerabilities are exploited within twenty-four hours of disclosure. Some security vendors report seeing proof-of-concept weaponization within less than thirty minutes.</p><p>This means browser patching can no longer be treated as a routine maintenance task. Browsers have effectively become operating systems themselves, holding credentials, session tokens, cloud access, and corporate data.</p><p>Organizations should force browser updates immediately and verify successful deployment across all managed endpoints.</p><h2>&#127479;&#127482; Russian Threat Group GreyVibe Uses AI Across Entire Kill Chain</h2><p>Researchers documented a previously unknown Russian-linked threat actor known as GreyVibe that has been targeting Ukrainian military, government, civilian, and business organizations since August 2025. What makes Gray Vibe particularly notable is its extensive use of generative AI throughout nearly every stage of its operations.</p><p>The group reportedly uses:</p><ul><li><p>Ideogram for phishing imagery</p></li><li><p>ChatGPT for lure development and malware support</p></li><li><p>Google Gemini for obfuscation and backend infrastructure</p></li><li><p>AI-generated phishing campaigns</p></li><li><p>AI-assisted payload development</p></li></ul><p>GreyVibe&#8217;s attack chains include fake CAPTCHA pages, spear phishing operations, fraudulent charity websites, and malware families tied to the TrickBot ecosystem.</p><p>This represents one of the clearest examples yet of threat actors integrating generative AI directly into operational workflows rather than using it experimentally.</p><p>The implication is significant: defenders should expect phishing campaigns, malware, and social engineering operations to become increasingly personalized, scalable, and difficult to distinguish from legitimate communications.</p><h2>&#127475;&#127473; Dutch Authorities Dismantle Massive Residential Proxy Botnet</h2><p>Dutch law enforcement and the National Cyber Security Centre successfully dismantled the ASOC residential proxy botnet, taking down infrastructure tied to more than one million infected devices and a network that leveraged over seventeen million compromised endpoints globally.</p><p>The botnet sold access to residential IP addresses for as little as five dollars per month. Criminals used the infrastructure for:</p><ul><li><p>Credential stuffing</p></li><li><p>DDoS attacks</p></li><li><p>Phishing campaigns</p></li><li><p>Spam operations</p></li><li><p>Proxy services</p></li></ul><p>Residential proxy networks remain highly valuable because traffic originating from consumer IP addresses often appears legitimate to security controls.</p><p>This operation continues a recent trend of successful law enforcement actions targeting the infrastructure that enables cybercrime rather than focusing solely on individual actors.</p><h2>&#128295; GitLab Issues Emergency Patch for Duo AI Identity Confusion Vulnerability</h2><p>GitLab released emergency security updates addressing several vulnerabilities affecting Duo AI workflows. The most significant flaw allows an authenticated user to trigger AI-assisted workflows under another user&#8217;s identity, potentially enabling privilege escalation and lateral movement within development environments.</p><p>The vulnerability is particularly concerning because AI tooling increasingly sits inside trusted development pipelines. If authorization controls fail, attackers may gain access to repositories, code, secrets, or workflows they should never see.</p><p>GitLab.com has already been patched, but organizations running self-managed instances must upgrade immediately.</p><p>As AI becomes integrated into development processes, identity validation and authorization controls around these tools become critical security boundaries.</p><h2>&#128674; Carnival Cruise Lines Confirms Six Million Victims in April Breach</h2><p>Carnival Cruise Lines confirmed that nearly six million individuals were affected by an April data breach originating from a successful social engineering attack against an employee account. ShinyHunters has claimed responsibility.</p><blockquote><p><em>&#8220;One employee, one phone call, and millions of records can disappear overnight.&#8221; James Azar</em></p></blockquote><p>Exposed information reportedly includes:</p><ul><li><p>Names</p></li><li><p>Email addresses</p></li><li><p>Phone numbers</p></li><li><p>Dates of birth</p></li><li><p>Driver&#8217;s license numbers</p></li><li><p>Passport information</p></li></ul><p>This breach follows a pattern we&#8217;ve seen repeatedly throughout 2026. One successful social engineering attack leads to millions of compromised records.</p><p>What makes this especially concerning is the inclusion of passport data. While organizations often offer credit monitoring after breaches, credit monitoring does not protect against identity fraud involving passport information.</p><p>Security leaders should remember that frontline employees remain one of the most important attack surfaces in any organization.</p><h2>&#127922; Google Security Engineer Charged in Insider Trading Scheme</h2><p>Federal prosecutors charged a Google security engineer with fraud, money laundering, and related offenses after allegedly using access to confidential internal search trend information to place highly profitable bets on prediction markets.</p><p>According to the allegations, the engineer used confidential search data to predict market outcomes on Polymarket and generated more than $1 million in cryptocurrency profits.</p><p>While this story is not a traditional cyberattack, it highlights an emerging challenge for insider threat programs. Organizations have traditionally focused on data theft, intellectual property loss, and espionage. Increasingly, insider access can also be monetized through financial instruments, prediction markets, and cryptocurrency ecosystems.</p><p>Security teams may need to expand insider risk monitoring programs to address these evolving threats.</p><h1>&#127919; Key Takeaway</h1><p>&#128073; The attack surface continues shifting faster than many security programs can adapt. VPNs are under active attack, AI platforms are becoming both targets and weapons, exploit development cycles are shrinking, and social engineering remains one of the most effective attack techniques in existence.</p><h1>&#128736;&#65039; Action Items for Security Leaders</h1><ul><li><p>&#128680; Patch Palo Alto GlobalProtect immediately and review exposure of internet-facing VPN infrastructure</p></li><li><p>&#129302; Update FlowWise deployments and restrict import permissions</p></li><li><p>&#9878;&#65039; Monitor disclosures related to Nightmare Eclipse vulnerabilities and apply mitigations promptly</p></li><li><p>&#127760; Force Chrome updates across all managed endpoints</p></li><li><p>&#127479;&#127482; Enhance detection capabilities for AI-assisted phishing and malware campaigns</p></li><li><p>&#127475;&#127473; Review outbound traffic for residential proxy network indicators</p></li><li><p>&#128295; Patch self-managed GitLab instances and review Duo AI authorization controls</p></li><li><p>&#128674; Educate employees on voice phishing and social engineering tactics</p></li><li><p>&#127922; Expand insider threat monitoring to include financial abuse scenarios</p></li><li><p>&#9889; Reevaluate patching timelines for internet-facing systems and critical applications</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how clearly speed has become the defining characteristic of modern cybersecurity. Whether it&#8217;s VPN vulnerabilities moving from disclosure to exploitation, AI platform exploits receiving public proof-of-concept code, or Chrome vulnerabilities being weaponized within hours, the traditional timelines many organizations still operate under simply don&#8217;t match reality anymore. Security teams that continue treating critical vulnerabilities as thirty-day projects are increasingly exposing their organizations to unnecessary risk.</p><p>The second major takeaway is the role AI is beginning to play across every part of the threat landscape. Gray Vibe&#8217;s systematic use of ChatGPT and Gemini shows that AI is no longer experimental for threat actors, it is operational. At the same time, platforms like FlowWise and GitLab Duo AI are becoming targets themselves. Security leaders need to stop thinking about AI as a future challenge and start treating it as a current operational risk that requires governance, visibility, and dedicated defensive strategies.</p><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/palo-alto-globalprotect-vpn-auth?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[This Week in Cybersecurity #54]]></title><description><![CDATA[Good Morning, Security Gang!]]></description><link>https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Fri, 29 May 2026 20:59:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aUqF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3><strong>Good Morning, Security Gang!</strong></h3><p>Double espresso ready. This week was one of the most operationally significant we have covered in months and the theme James kept returning to across all four episodes was speed. The speed of attacker exploitation. The speed of supply chain propagation. The speed at which traditional defensive timelines are becoming operationally obsolete.</p><p>This was the week a watering hole campaign turned Harvard and Oxford websites into malware delivery infrastructure. A single supply chain attack injected malicious workflows into 5,561 GitHub repositories in six hours. Anthropic&#8217;s Mythos AI autonomously discovered and exploited a 17-year-old FreeBSD root vulnerability &#8212; start to finish, without human guidance. Ubiquiti dropped emergency patches for three CVSS 10 vulnerabilities while researchers documented nearly 100,000 internet-exposed management interfaces. And GitHub introduced mandatory 2FA-gated npm publishing in direct response to the Megalodon and TeamPCP supply chain campaigns.</p><p>But the story that may define the week came in the final episode: Iranian-linked attackers reached LA Metro&#8217;s rail yard control display systems. Criminals are physically entering offices carrying USB drives when digital attacks get blocked. Chinese phishing-as-a-service platforms are bypassing MFA in real time with live OTP interception dashboards. AI chatbots are being poisoned to recommend malware. India&#8217;s CERT issued a twelve-hour critical vulnerability patching mandate. And Anthropic quietly patched Claude Code sandbox escapes without assigning CVEs &#8212; prompting a pointed industry debate about whether AI vendors are being held to the same disclosure standards as any other privileged software.</p><div class="callout-block" data-callout="true"><p>James summarized it better than anyone could in a briefing: <em>&#8220;The attack surface has gone fully multi-domain. Iran&#8217;s inside LA&#8217;s transit control displays. Cybercriminals are walking through your front door. Chinese phishing-as-a-service operators are defeating MFA in real time. AI chatbots are recommending malware. Developer tooling is a deliberate supply chain target. The old defensive cadences were built for a world that no longer exists.&#8221;</em></p></div><p>Coffee cup cheers. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aUqF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aUqF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aUqF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1146569,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/199796627?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aUqF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!aUqF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28381fab-df8e-472a-9508-b614a80c663a_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>&#127760; Infrastructure &amp; Network Exploitation</strong></h3><p><strong>Ghost CMS Exploited in Massive ClickFix Watering Hole Campaign: Harvard, Oxford, DuckDuckGo</strong></p><p>A large-scale Ghost CMS exploitation campaign is actively compromising trusted institutional websites including Harvard, Oxford, Auburn University, and DuckDuckGo-linked domains using a sophisticated ClickFix watering hole attack. Attackers exploit vulnerable Ghost CMS versions to steal admin keys through unauthenticated Ghost API access, then inject lightweight JavaScript loaders into legitimate articles. Visitors are presented with a fake Cloudflare CAPTCHA prompt instructing them to paste a verification command into their Windows terminal which downloads malicious loaders and backdoors. This social engineering flow bypasses traditional phishing awareness training entirely, because users believe they are on a trusted, well-known domain. Trusted browsing is no longer a reliable safety signal. Patch Ghost CMS to version 6.20.0 immediately and train users that no legitimate website will ever ask them to paste commands into a terminal.</p><p><strong>Ubiquiti Emergency Patches: Three CVSS 10 UniFi Vulnerabilities</strong></p><p>Ubiquiti issued emergency patches for five UniFi OS vulnerabilities, including three carrying the maximum CVSS score of 10.0 improper access control enabling unauthorized changes, path traversal enabling arbitrary file reads, and unauthenticated command injection enabling full remote code execution. Approximately 100,000 internet-exposed UniFi OS endpoints are currently accessible globally, with nearly half in the United States. No administrator credentials required. Attacker needs only an IP address to begin exploitation. Patch immediately and move all UniFi management interfaces behind VPNs or isolated management VLANs.</p><p><strong>Underminer CDN Technique: C2 Traffic Hidden Behind 88 Million Trusted Domains</strong></p><p>Researchers disclosed &#8220;Underminer,&#8221; a CDN-based command-and-control evasion technique hiding malicious traffic behind approximately 88 million legitimate domains. Unlike classic domain fronting, Underminer abuses shared CDN infrastructure by presenting trusted domain names in SNI and HTTP host fields while routing traffic to attacker-controlled infrastructure underneath. DNS resolution appears legitimate, TLS certificates validate correctly, firewall rules see trusted domains and malicious C2 traffic tunnels silently through. Organizations relying on domain allowlists, proxy filtering, or DNS-based trust enforcement now have a structural blind spot. Visibility must extend below the domain layer to include certificate analysis, routing anomalies, and behavioral inspection.</p><p><strong>Huawei VRP: National Telecom Outage, No CVE, No Confirmed Patch</strong></p><p>A Huawei VRP vulnerability confirmed as the cause of a nationwide Luxembourg telecom outage was disclosed nearly ten months ago with no public CVE and no confirmed patch. Organizations still running Huawei networking infrastructure should treat this as an unresolved operational trust concern requiring architectural review.</p><h3><strong>&#129302; AI as Weapon, Tool, and Attack Surface</strong></h3><p><strong>Anthropic Mythos AI: 23,000 Vulnerabilities, 17-Year FreeBSD Root Exploit &#8212; Autonomously</strong></p><p>Anthropic&#8217;s Mythos AI model, operating through Project Glasswing alongside AWS, Google, Microsoft, NVIDIA, Cisco, CrowdStrike, Apple, and Palo Alto Networks, scanned over 1,000 open-source projects and identified 23,019 vulnerabilities &#8212; 6,202 high or critical &#8212; with 1,094 confirmed by human reviewers. The most significant finding: Mythos autonomously identified and fully exploited a 17-year-old FreeBSD remote root vulnerability without human guidance, performing discovery, analysis, exploit generation, and successful root compromise independently. Anthropic confirmed Mythos-class capabilities will eventually be available beyond the current curated partner model. The traditional patching timeline built around human-paced exploit development is no longer a valid operational assumption. Organizations operating with 30-day vulnerability SLAs for internet-facing systems are already behind.</p><p><strong>Anthropic Quietly Patches Claude Code Sandbox Escapes &#8212; No CVEs Assigned</strong></p><p>Anthropic silently patched two major Claude Code sandbox bypass vulnerabilities without assigning CVEs or documenting the issues in public changelogs: a hostname null-byte injection flaw present since October 2025, and a hardcoded 50-subcommand limit that caused configured deny rules to silently stop being enforced above the threshold &#8212; a full sandbox escape hiding in plain sight. If agentic AI tools have privileged access to file systems, shells, and CI/CD environments, they must be held to the same CVE disclosure standards as any other privileged software. This is not a nuanced governance question. It is a foundational requirement for operational trust.</p><p><strong>Russian Operator Weaponizes Jailbroken Gemini AI for Credential Cracking and Influence Ops</strong></p><p>Russian-speaking operator &#8220;BenCamPro&#8221; weaponized a jailbroken Google Gemini CLI instance across a multi-year campaign, building a self-reinforcing jailbreak system where Gemini retained prior jailbreak instructions across sessions. The AI was used to generate password mutations, crack WordPress admin accounts, analyze stolen infostealer logs, and assist operational decision-making. Researchers linked the activity to 29 compromised WordPress accounts, MAGA-themed influence operations, crypto wallet theft, and Telegram channels with over 17,000 subscribers. AI is materially lowering the skill barrier for cybercrime operations. Audit all AI API key exposure across CI/CD environments and repositories immediately.</p><p><strong>AI Chatbots Recommending Malware-Infected Downloads</strong></p><p>Microsoft researchers documented an active cryptojacking campaign where attackers poison AI chatbot knowledge to redirect users toward malware-infected versions of legitimate utilities CrystalDiskInfo, HWMonitor, FurMark, Display Driver Uninstaller, and K-Lite Codec Pack. Payloads establish persistence via ScreenConnect and provide remote access capable of escalating to ransomware or data theft. AI-generated recommendations are increasingly treated as authoritative by users giving attackers a high-trust distribution channel. Enforce policies requiring software downloads only from official vendor domains and monitor for unauthorized remote management tools.</p><p><strong>Malicious npm Package Stealing Anthropic Claude AI Session Files</strong></p><p>Aikido Security discovered a malicious npm package (mouse5212-superformatter) specifically designed to steal Anthropic Cloud AI session files from developer environments authenticating into GitHub repositories, recursively uploading AI session data, and harvesting cloud code session outputs. The attacker accidentally embedded their own GitHub token into the malware, suggesting the package itself may have been AI-assisted without proper OPSEC review. AI development environments hold deeply trusted positions with broad filesystem and credential access. One malicious dependency can expose everything the AI tooling has ever touched.</p><h3><strong>&#129516; Supply Chain &amp; Developer Ecosystem</strong></h3><p><strong>Megalodon Supply Chain Attack: 5,561 GitHub Repositories in Six Hours</strong></p><p>The &#8220;Megalodon&#8221; campaign injected malicious GitHub Actions workflows into 5,561 open-source repositories using developer credentials harvested from infostealer infections &#8212; confirmed by Hudson Rock researchers who matched hundreds of affected GitHub accounts to previously compromised infostealer logs. Attackers used bot personas and maintenance-style commit messages to blend into normal CI activity. Once merged into repositories lacking strong branch protections, the malicious workflows silently exfiltrated AWS, Azure, and GCP credentials, SSH private keys, Kubernetes configurations, GitHub OIDC tokens, API keys, and database connection strings. The npm package @tiledesk/server was also poisoned across multiple versions. Audit CI/CD logs for Megalodon-related commits since May 18th and rotate all exposed deployment credentials immediately.</p><p><strong>GitHub Introduces 2FA-Gated npm Publishing: &#8220;Proof of Presence&#8221;</strong></p><p>GitHub rolled out staged npm publishing requiring maintainers to complete a two-factor authentication challenge before package releases become installable. Even CI/CD pipelines using OIDC trusted publishing require a human to approve the release before distribution. This creates friction attackers cannot bypass through credential automation alone. The challenge is adoption the feature is currently opt-in, not mandatory. Organizations should begin requiring 2FA-gated publishing from critical open-source dependencies.</p><p><strong>Trend Micro Apex One Zero-Day: CISA KEV, June 4 Federal Deadline</strong></p><p>Trend Micro confirmed active exploitation of a critical Apex One vulnerability added to CISA&#8217;s KEV with a June 4th federal remediation deadline. The flaw allows an attacker with administrative access to an Apex One server to manipulate a key distribution table used to push code to managed endpoints one compromised admin account becomes a force multiplier capable of distributing malicious code to every endpoint managed by the server. Security management infrastructure continues to be the preferred attacker pivot point in 2026.</p><p><strong>npm Supply Chain Campaign Hides Linux Backdoor as SSH Daemon</strong></p><p>Researchers uncovered an npm campaign hiding a Linux backdoor disguised as a fake SSH daemon named .sshd inside /tmp, distributed through malicious postinstall scripts in package.json files. The naming convention is deliberate /tmp/.sshd can appear benign during initial incident response. The campaign targets mixed PHP and JavaScript monorepo environments. Review npm lifecycle scripts before any production deployment and monitor for SSH-like processes running from temporary directories.</p><h3><strong>&#128165; Ransomware &amp; Destructive Operations</strong></h3><blockquote><p><em>&#8220;Today&#8217;s stories read as one coherent threat picture: the attackers are faster, cheaper, and harder to detect than they were twelve months ago. CVSS perfect ten in Ubiquiti. MFA bypassed by a two hundred and fifty dollar subscription service. A North Korean RAT that lives purely in memory. An AI that jailbreaks itself and cracks passwords for a low-skilled Russian actor. These are not theoretical risks anymore, they are Tuesday morning&#8217;s operational realities.&#8221;</em></p></blockquote><p><strong>NightSpire Ransomware: 175 Organizations, 28 Industries &#8212; Using Only Legitimate Tools</strong></p><p>The NightSpire ransomware group has impacted 175 organizations across 28 industries since early 2025, including hospitals, schools, financial institutions, and government agencies relying almost entirely on legitimate software rather than custom malware. Entry vectors: exposed RDP, FortiOS vulnerabilities. Persistence tools: Chrome Remote Desktop, AnyDesk. Exfiltration: MegaSync. Compression: 7-Zip. By operating exclusively within legitimate tooling, NightSpire avoids triggering traditional EDR alerts. Audit exposed RDP, unauthorized remote administration software, unexpected cloud synchronization tools, and FortiOS patching status across all environments.</p><p><strong>VECT Ransomware Confirmed as Wiper: No Recovery Path Regardless of Payment</strong></p><p>VECT ransomware&#8217;s encryption process is confirmed to discard critical data by design, making recovery impossible even after payment. This is not extortion it is destruction disguised as extortion. Prevention and validated offline backups are the only defenses.</p><h3><strong>&#128275; Data Breaches &amp; Exposures</strong></h3><p><strong>Charter Communications: 42 Million Records via Voice Phishing &#8594; Microsoft Entra &#8594; Salesforce</strong></p><p>Charter Communications confirmed a ShinyHunters breach affecting approximately 42 million customer records following a voice phishing attack targeting an employee&#8217;s Microsoft Entra account. Attackers used the compromised account to access Salesforce environments and export consumer and business data. The attack chain is now fully established: vishing targets the identity provider, which becomes the Salesforce pivot, which becomes the large-scale data extraction event. Voice phishing defense requires moving beyond SMS authentication to managed authenticator applications with identity verification prompts sent to corporate-managed devices.</p><p><strong>UK Visa Portal: 100,000 Passport Scans and Biometric Selfies Leaked</strong></p><p>A third-party UK visa processing portal leaked more than 100,000 passport scans, selfies, and personal identity documents online. When journalists contacted the company, the organization responded with lawyers before engineers and the leak remained unresolved at time of reporting. Passport scans combined with biometric selfies create premium-grade fraud material enabling KYC bypasses, fake identity creation, and fraudulent financial account openings. Biometric identity data leaks should be treated as permanent compromise events requiring long-term monitoring.</p><p><strong>Knowledge Deliver LMS: Shared <a href="http://asp.net/">ASP.NET</a> Machine Keys Enable Mass Exploitation</strong></p><p>A critical zero-day in the Knowledge Deliver LMS is actively deploying memory-resident Cobalt Strike payloads through watering hole attacks exploiting shared identical hardcoded <strong><a href="http://asp.net/">ASP.NET</a></strong> machine keys across all deployments for unauthenticated RCE via ViewState deserialization. Organizations do not need to wait for a vendor patch: rotating <strong><a href="http://asp.net/">ASP.NET</a></strong> machine keys to unique cryptographic values immediately closes the attack path. Compromised LMS platforms are being turned into active malware distribution infrastructure targeting every site visitor.</p><p><strong>Community Bank AI Shadow Exposure: SEC Disclosure</strong></p><p>A community bank disclosed to the SEC that an employee&#8217;s use of an unauthorized AI chatbot exposed customer names, dates of birth, and Social Security numbers. This is among the first formal regulatory disclosure events attributable to shadow AI use and it will not be the last. Employees are integrating AI tools faster than organizations can create governance policies. Without DLP enforcement and explicit AI tool approval frameworks, this incident type will proliferate across every regulated sector.</p><p><strong>Charter + 7-Eleven + Cushman &amp; Wakefield: The ShinyHunters SaaS Playbook Scales</strong></p><p>The Charter breach joins 7-Eleven, Cushman &amp; Wakefield, Aman Resorts, McGraw-Hill, and dozens of others in the same ShinyHunters Salesforce campaign. The playbook is now fully documented: voice phishing or credential theft &#8594; identity provider access &#8594; Salesforce pivot &#8594; large-scale CRM data extraction &#8594; ransom demand &#8594; public leak deadline. Salesforce environments are being systematically targeted because they contain high-value business records with weaker conditional access policies than core enterprise infrastructure.</p><h3><strong>&#127760; Geopolitical &amp; Nation-State Threats</strong></h3><blockquote><p><em>&#8220;This breaks the assumption that cyber threats are remote only. When the digital door is closed, these actors will walk through the physical one knowing a physical confrontation is unlikely. Your traditional security controls like firewalls, EDR, and MFA provide zero protection against someone walking through your front door with a convincing story and a USB drive.&#8221;</em></p></blockquote><p><strong>Iranian APT Reaches LA Metro Rail Yard Control Display Systems</strong></p><p>The March Los Angeles Metro cyberattack has been attributed to the Iranian-linked Black Shadow group, connected directly to Iran&#8217;s Ministry of Intelligence and Security. Attackers exfiltrated more than 700 gigabytes of data and reached rail yard control display systems &#8212; crossing from IT compromise into operational technology territory. OT access at a major transit system means operational disruption becomes the likely next escalation point. Segment OT and IT aggressively, remove operational systems from any internet exposure, and treat OT visibility as a crown jewel security priority.</p><p><strong>MuddyWater Expands Across Nine Countries, Adds Aviation Targeting</strong></p><p>Microsoft Threat Intelligence documented MuddyWater campaigns across nine countries in Q1 2026, using DLL side-loading through trusted executables including fmap.exe and SentinelOne Memory Scanner components to evade signature-based detection. A separate Iranian cluster simultaneously targeted aviation software providers through credential harvesting and social engineering &#8212; the strategy being supply chain pre-positioning: compromise the vendor first, then pivot into airlines, airports, and aerospace organizations downstream.</p><p><strong>China-Linked Router Implant Turns Edge Devices Into Surveillance Infrastructure</strong></p><p>A China-linked threat actor deployed a custom Linux implant (router.elf) onto edge routers across Southeast Asia, communicating over DNS-over-HTTPS, manipulating internal DNS systems, and enabling selective traffic interception through a dynamically updated targeting list called evil_fix. This is strategic surveillance infrastructure, not financially motivated malware. Compromised routers function as silent collection platforms for every device behind them. Validate router firmware integrity, monitor DNS modifications, and review unusual encrypted outbound traffic from network appliances.</p><p><strong>Lazarus Group Deploys RemotePE Fileless RAT</strong></p><p>North Korea&#8217;s Lazarus Group deployed a new fileless RAT called &#8220;RemotePE&#8221; targeting cryptocurrency and financial organizations. The malware executes entirely in memory, never writes to disk, uses Windows DPAPI tied to the victim environment, and dynamically loads additional DLL capabilities post-compromise. Initial access relies on Telegram social engineering, fake trading firms, cloned Calendly domains, and fraudulent meeting invitations targeting developers and analysts. Traditional file-hash-based detection is largely useless against memory-only malware. Runtime memory analysis capability is now a required detection component.</p><p><strong>InvisibleFerret Evolves to Compiled Binaries to Evade Detection</strong></p><p>The DPRK Void Dokkaebi cluster upgraded &#8220;Invisible Ferret&#8221; from readable Python scripts into compiled Cython binaries disguised as .pyd and .so files, bypassing many detections previously focused on Python script patterns. Distribution continues through fake developer interview technical assessment packages. Developers remain among the highest-priority targets for nation-state operations.</p><p><strong>Europol Operation Saffron: FirstVPN Seized, 25 Ransomware Groups Disrupted</strong></p><p>Europol&#8217;s Operation Saffron seized 33 servers tied to &#8220;FirstVPN,&#8221; allegedly used by more than 25 ransomware groups for anonymization infrastructure. The alleged Ukrainian administrator was arrested and 500 user profiles shared with international law enforcement partners. This reflects growing coordination across Europol, FBI, and international task forces operating as an increasingly coordinated operational network.</p><p><strong>Netherlands Seizes 800 Servers From Russian Bulletproof Host</strong></p><p>Dutch authorities seized 800 servers from Russian-linked bulletproof hosting provider &#8220;Stark Industries&#8221; (later rebranded as Work Titans / <strong><a href="http://d.hosting/">D.Hosting</a></strong>), tied to cyberattacks, election interference, and disinformation operations. The provider was founded April 10th, 2022, just 14 days before Russia&#8217;s invasion of Ukraine. European willingness to aggressively target state-adjacent criminal cyber infrastructure is accelerating.</p><p><strong>Europe Accelerates Digital Sovereignty: Dutch Block U.S. Cloud Acquisition</strong></p><p>The Dutch government blocked a U.S. IT company from acquiring Solvinity, a Dutch cloud provider hosting national digital identity infrastructure, citing concerns over digital sovereignty and exposure to U.S. legal reach. This is the third major European intervention this quarter tied to U.S. cloud ownership concerns. Organizations operating across U.S. and European markets should prepare for increased data residency requirements, regional infrastructure segmentation, and regulatory divergence. This is becoming an operational architecture issue, not political background noise.</p><h3><strong>&#128272; Identity &amp; Authentication</strong></h3><p><strong>Kali365 MFA Bypass Platform: OAuth Device Code Abuse at Scale</strong></p><p>The FBI issued an IC3 warning about &#8220;Kali365,&#8221; a phishing-as-a-service platform bypassing Microsoft 365 MFA through OAuth device authorization flow abuse the same flow designed for smart TVs and IoT devices. Victims authenticate normally through legitimate-looking Microsoft prompts. MFA fires successfully. Nothing appears suspicious. The attacker captures the live authentication token and gains full account access. The platform includes AI-generated phishing lures, real-time victim dashboards, automated token capture, and Telegram-based operator infrastructure. Hundreds of attacks have already targeted manufacturing, healthcare, education, government, and financial sectors. Restrict or disable device code authentication flows through Microsoft Entra conditional access policies immediately where operationally feasible.</p><p><strong>Chinese Phishing-as-a-Service: Real-Time MFA Interception with AI Localization</strong></p><p>Google&#8217;s Threat Intelligence Group documented Chinese-language phishing-as-a-service platforms with live OTP interception dashboards victims enter credentials, attackers receive them instantly, MFA requests are triggered in real time, OTP codes are intercepted before expiration, and payment cards are immediately provisioned into attacker-controlled digital wallets for contactless payments and ATM withdrawals. AI-driven localization removes the cultural inconsistencies that historically exposed phishing attempts, enabling region-specific language, local slang, and context-aware messages. Time-based OTP MFA is increasingly ineffective against these operations. Organizations must accelerate migration to FIDO2 authentication, passkeys, and hardware-backed authentication models.</p><p><strong>SonicWall SMA MFA Bypass: Logs Show Success While Attackers Operate</strong></p><p>Attackers exploiting SonicWall SMA appliances through an MFA bypass produce authentication logs that misleadingly show successful MFA validation even while unauthorized access occurs because many organizations installed the required firmware update but failed to complete the separate manual LDAP reconfiguration for full mitigation. Verify the complete remediation procedure, not just firmware version.</p><p><strong>FBI Warns: Silent Ransom Group Physically Entering Offices</strong></p><p>The FBI warned that the Silent Ransom Group (Luna Moth / UNC3753) is physically dispatching actors to victim organizations when digital attacks are blocked. The attack begins with someone posing as IT support requesting remote access. If refused, a person may physically arrive at the office with a USB drive to plug directly into workstations. No ransomware, no encryption direct theft followed by extortion. Firewalls, EDR, MFA, and email filtering provide zero protection against someone walking through the front door with a believable story. Physical social engineering exercises, visitor management procedures, badge systems, and USB device restrictions must now be treated as cybersecurity controls.</p><h3><strong>&#9883;&#65039; Quantum, Cryptography &amp; Policy</strong></h3><p><strong>U.S. Government Commits $2 Billion to Quantum Computing Acceleration</strong></p><p>The Trump administration announced approximately $2 billion in grants to accelerate quantum computing development, with IBM expected to receive nearly half the funding. Researchers now estimate cryptographically relevant quantum capabilities could emerge as early as 2027&#8211;2030. Banking infrastructure, military communications, TLS encryption, VPNs, secure messaging, and cryptocurrency all rely on cryptographic systems vulnerable to quantum attacks. NIST finalized post-quantum cryptographic standards last year. Organizations still treating post-quantum migration as future planning are underestimating how quickly this timeline is compressing. Begin crypto-agility inventory and post-quantum migration planning now.</p><p><strong>India Mandates 12-Hour Critical Vulnerability Patching</strong></p><p>India&#8217;s CERT issued a framework mandating 12-hour patching timelines for critical internet-facing vulnerabilities, explicitly citing AI-assisted exploit generation and automated attack surface mapping as justification. Critical internet-facing vulnerabilities: patch within one day. High-value internal systems: three days. High-severity vulnerabilities: five days. This directly reflects the operational reality practitioners are experiencing: the 30-day patching model is becoming obsolete. Organizations should begin compressing remediation timelines for internet-facing critical systems to match the actual exploitation windows they are now operating within.</p><p><strong>Supreme Court Prepares to Rule on Digital Privacy: Chatrie v. United States</strong></p><p>The U.S. Supreme Court is expected to rule within weeks on Chatrie v. United States, a case centered on geofence warrants. The core question: can law enforcement compel technology companies to identify every user present in a geographic area during a specific timeframe? The ruling could fundamentally shape future legality around reverse keyword searches, search history warrants, AI conversation history access, and bulk behavioral surveillance requests. This may become the most consequential digital privacy ruling since Carpenter v. United States. Review organizational data retention policies ahead of evolving digital privacy requirements.</p><p><strong>KimWolf Botnet Operator Arrested in Canada: 1 Million Devices, 30 Terabit Attacks</strong></p><p>Canadian authorities arrested 23-year-old Jacob Butler, alleged operator of the KimWolf DDoS-for-hire botnet over one million infected devices globally, attacks exceeding 30 terabits per second, individual victim losses exceeding $1 million. Case built through IP address correlation, financial transaction tracing, messaging platform analysis, and infrastructure linkage. Attribution sophistication in cybercrime enforcement continues improving globally.</p><p><strong>FIFA World Cup Ghost Stadium Fraud: 3,500 Malicious Domains</strong></p><p>Researchers uncovered &#8220;Ghost Stadium&#8221; over 3,500 malicious domains targeting FIFA World Cup fans globally with fake login portals, fraudulent ticket sales, counterfeit merchandise, fake streaming sites, and credential harvesting campaigns. Over 2,500 FIFA account credentials already circulating; 170,000 infostealer logs reference FIFA-related accounts. The phishing kits support eleven languages and leverage Meta advertising infrastructure. Security teams should proactively educate employees and customers about official ticketing channels, fake streaming scams, and credential reuse risks before the tournament begins.</p><p><strong>CrowdStrike and Google Disrupt GlassWorm Botnet</strong></p><p>CrowdStrike, Google, and ShadowServer Foundation successfully disrupted all four GlassWorm C2 channels. The botnet spreading through trojanized VS Code extensions using Unicode variation selectors to hide malicious code in legitimate source files leveraged VPS infrastructure, Google Calendar covert channels, BitTorrent P2P communication, and Solana blockchain backup channels. Attribution evidence suggests Russian operational origins. Modern botnet infrastructure is increasingly multi-channel, decentralized, and blockchain-aware.</p><p><strong>Void Botnet: Ethereum Smart Contracts as C2 &#8212; Second Blockchain-Based Architecture This Year</strong></p><p>The &#8220;Void&#8221; malware-as-a-service platform uses Ethereum smart contracts for C2 infrastructure, making the command layer decentralized and resistant to traditional takedown operations. This is the second blockchain-based C2 architecture identified this year. Ethereum RPC monitoring must be added to network detection programs.</p><h3><strong>&#9989; This Week&#8217;s Priority Action List</strong></h3><p><strong>Immediate (Do This Now)</strong></p><ul><li><p>Patch Ghost CMS to version 6.20.0 and audit all content for injected scripts &#8212; Harvard, Oxford, and major institutional domains are confirmed compromised</p></li><li><p>Patch Ubiquiti UniFi OS across all deployments and move all management interfaces behind VPNs or isolated management VLANs immediately</p></li><li><p>Restrict or disable Microsoft Entra device code authentication flows via conditional access policies &#8212; Kali365 is actively exploiting this at scale</p></li><li><p>Apply Trend Micro Apex One patch before the June 4 CISA KEV federal deadline and review privileged admin access paths</p></li><li><p>Rotate <strong><a href="http://asp.net/">ASP.NET</a></strong> machine keys on all Knowledge Deliver LMS deployments &#8212; this closes the active exploitation path without waiting for a vendor patch</p></li><li><p>Apply Microsoft SharePoint out-of-band patch CVE-2026-45659 within 48 hours &#8212; authenticated any-user RCE via deserialization</p></li><li><p>Audit CI/CD logs for Megalodon-related commits since May 18 and rotate all exposed AWS, Azure, GCP, SSH, Kubernetes, and database credentials</p></li><li><p>Deploy runtime memory analysis capabilities &#8212; Lazarus RemotePE fileless RAT has zero disk footprint and bypasses file-hash detection entirely</p></li><li><p>Develop FIFA World Cup security awareness materials for employees and customers before tournament begins`</p></li></ul><p><strong>Short-Term (This Month)</strong></p><ul><li><p>Implement USB device restrictions and physical visitor management protocols &#8212; Silent Ransom Group is physically entering offices</p></li><li><p>Enable 2FA-gated npm publishing for all critical package dependencies and begin requiring it from upstream maintainers</p></li><li><p>Restrict software downloads to official vendor domains only and monitor for unauthorized ScreenConnect or AnyDesk installations</p></li><li><p>Audit npm dependencies across all AI development environments for unauthorized packages targeting AI session files</p></li><li><p>Migrate financial and high-value workflows toward FIDO2 and passkeys &#8212; time-based OTP MFA is being defeated in real time</p></li><li><p>Audit exposed RDP and FortiOS patching status specifically targeting NightSpire ransomware entry vectors</p></li><li><p>Validate router firmware integrity and monitor DNS configuration changes for China-linked router implant indicators</p></li><li><p>Monitor DLL side-loading activity involving signed binaries from SentinelOne, Fortinet, and other trusted vendors</p></li><li><p>Establish AI governance framework including shadow AI detection and DLP controls targeting AI chatbot interactions</p></li></ul><p><strong>Strategic (This Quarter)</strong></p><ul><li><p>Begin crypto-agility inventory and post-quantum cryptography migration planning &#8212; $2 billion U.S. quantum investment signals accelerating timeline</p></li><li><p>Compress vulnerability remediation SLAs for internet-facing critical systems &#8212; India&#8217;s 12-hour mandate reflects current actual exploitation windows</p></li><li><p>Require CVE assignment and public disclosure from all AI vendors with privileged developer environment access &#8212; Anthropic&#8217;s silent Claude Code patches set the wrong precedent</p></li><li><p>Conduct physical social engineering tabletop exercises including front desk verification procedures and USB device handling</p></li><li><p>Prepare board-level briefings on European digital sovereignty risk and potential data residency requirements affecting transatlantic operations</p></li><li><p>Build peer-to-peer lateral communication hunting capability &#8212; Turla Kazuar and GlassWorm both use P2P to stay invisible to outbound-only monitoring</p></li><li><p>Review organizational data retention policies ahead of imminent Supreme Court digital privacy ruling in Chatrie v. United States</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54/comments"><span>Leave a comment</span></a></p><h3><strong>&#127897;&#65039; James Azar&#8217;s CISO&#8217;s Take</strong></h3><p>When I look across all four episodes this week, the defining story is operational speed and the widening gap between how fast attackers are moving and how fast most organizations are structured to respond. Megalodon hit 5,561 repositories in six hours. Mythos exploited a 17-year-old vulnerability autonomously from discovery to root access. Ubiquiti pushed three perfect-10 CVEs that require no credentials and minimal effort. And Kali365 is selling 24/7 MFA bypass as a subscription service. The organizations that will survive this environment are the ones that have accepted the old 30-day remediation model is no longer operationally valid and have rebuilt their patch and response cadences around the actual exploitation timelines they are facing. India&#8217;s 12-hour mandate is not aspirational it is a description of the current reality for internet-facing critical infrastructure.</p><p>The second takeaway is that the attack surface has genuinely gone multi-domain in ways that security programs built for purely digital threats are not designed to handle. Iranian actors are inside transit control systems. Criminals are physically entering offices with USB drives when digital vectors fail. AI chatbots are recommending malware. And the Lazarus Group&#8217;s fileless RAT has no disk presence at all &#8212; meaning endpoint security programs built around file detection are structurally blind to it. The organizations that adapt will be the ones that extend security thinking across physical access, runtime memory analysis, AI governance, supply chain validation, and developer ecosystem hygiene simultaneously. Because attackers are already operating across all of those domains at once.</p><p><strong>Stay Cyber Safe.</strong> &#128272;</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/this-week-in-cybersecurity-54?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Iranian MOIS Hackers Behind LA Metro Breach, CrowdStrike Google and Shadowserver Disrupt GlassWorm, FBI Warns of Silent Ransom Group Conducting In-Person Data Theft Attacks ]]></title><description><![CDATA[Iran State Hackers Hit LA Metro, 700GB Stolen, Reached Rail Yard Controls, Silent Ransom Group Sending Physical Actors to Law Firms, Ghost Stadium: 3,500 Fake FIFA World Cup Domains, GlassWorm Botnet]]></description><link>https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Thu, 28 May 2026 13:31:13 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/199555391/0339379b8350a2068dd2758daad9346e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h1>&#9749; Good Morning Security Gang,</h1><p>We&#8217;re approaching the halfway point of the year, and honestly, from a cybersecurity perspective, the outlook isn&#8217;t getting any prettier.</p><p>Today&#8217;s episode had one major theme running through nearly every story we covered:<br>&#128073; The attack surface has officially gone fully multi-domain.</p><p>We&#8217;re no longer talking about isolated phishing emails or standalone ransomware attacks. We&#8217;re talking about Iranian state actors inside transit systems, criminals physically showing up at law firms with USB drives, Chinese phishing platforms intercepting MFA in real time, AI chatbots unknowingly recommending malware, and supply chain compromises specifically targeting AI development environments.</p><p>Meanwhile, governments are responding with increasingly aggressive policies from India mandating twelve-hour patching timelines to U.S. Cyber Command reviewing its operational structure as the gap between vulnerability disclosure and exploitation continues collapsing.</p><p>Double espresso in hand this morning, using Caf&#233; Elite capsules straight from Israel, by the way, and coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape demonstrates that cybersecurity is no longer confined to digital-only operations. Threat actors are blending cyber intrusion, physical access operations, AI-assisted exploitation, real-time MFA interception, and infrastructure targeting into coordinated attack campaigns that move far faster than traditional enterprise defense cycles were designed to handle.</p><p>At the same time, AI is becoming both an offensive and defensive force multiplier. Attackers are leveraging AI for phishing localization, malware generation, and social engineering enhancement, while defenders are struggling to operationalize security fast enough to keep pace. The organizations that survive the next phase of cyber conflict will be the ones capable of compressing detection, patching, and response timelines dramatically.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wErZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wErZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wErZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:148493,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/199555391?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wErZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!wErZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a2a145b-b441-4489-a62f-66aa5f44a25c_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128647; Iranian State-Linked Hackers Connected to LA Metro Cyberattack</h2><p>One of the biggest stories today involved the cyberattack against Los Angeles Metro back in March, which has now been attributed by Israeli cyber resilience firm Gambit to the Iranian-linked threat group Black Shadow. Israeli intelligence and the National Cyber Directorate have tied the group directly to Iran&#8217;s Ministry of Intelligence and Security, the same ecosystem associated with MuddyWater operations.</p><p>The attackers reportedly exfiltrated more than 700 gigabytes of data and reached rail yard control display systems, meaning this was not simply an IT compromise, it crossed directly into operational technology territory.</p><p>That distinction matters because once attackers touch transit control environments, operational disruption becomes the likely next escalation point. Transit systems, utilities, and public infrastructure are increasingly becoming strategic targets because disruption there creates both economic and psychological impact simultaneously.</p><p>The lesson here for critical infrastructure operators is painfully clear:</p><ul><li><p>Segment OT and IT aggressively</p></li><li><p>Remove operational systems from direct internet exposure</p></li><li><p>Use data diodes or unidirectional gateways where possible</p></li><li><p>Treat OT visibility as a crown jewel priority</p></li></ul><p>If attackers can reach control systems, the conversation is no longer about data theft, it becomes about operational disruption and public safety.</p><h2>&#128682; FBI Warns of Criminals Physically Entering Offices to Steal Data</h2><p>The FBI issued a warning that the Silent Ransom Group&#8212;also known as Luna Moth or UNC3753&#8212;is escalating beyond traditional phone-based phishing attacks and now physically dispatching actors to victim organizations.</p><p>The attack flow begins with someone posing as internal IT support requesting remote access. If the target refuses, attackers may then send a person physically to the office carrying a USB drive to plug directly into workstations and steal data onsite.</p><p>No ransomware. No encryption.<br>Just direct theft followed by extortion.</p><p>This completely breaks the assumption that cyber threats are purely remote. Organizations invest heavily in:</p><ul><li><p>Firewalls</p></li><li><p>EDR</p></li><li><p>MFA</p></li><li><p>Email filtering</p></li></ul><p>But none of those controls stop someone walking through the front door with a believable story and a malicious USB device.</p><blockquote><p><em>"This breaks the assumption that cyber threats are remote only. When the digital door is closed, these actors will walk through the physical one knowing a physical confrontation is unlikely. Your traditional security controls like firewalls, EDR, and MFA provide zero protection against someone walking through your front door with a convincing story and a USB drive." James Azar</em></p></blockquote><p>This is where physical security and cybersecurity finally converge operationally. Front desk procedures, visitor management, badge systems, camera coverage, and employee verification training become cybersecurity controls now, not just facilities functions.</p><p>Security teams should strongly consider running physical social engineering exercises as part of tabletop scenarios moving forward.</p><h2>&#128179; Chinese Phishing-as-a-Service Platforms Bypassing MFA in Real Time</h2><p>Google&#8217;s Threat Intelligence Group published research showing Chinese-language phishing-as-a-service platforms have evolved into fully operational real-time MFA interception systems targeting digital wallet fraud. The way these attacks work is operationally sophisticated:</p><ul><li><p>Victims enter credentials into phishing portals</p></li><li><p>Attackers instantly receive them through live admin dashboards</p></li><li><p>MFA requests are triggered in real time</p></li><li><p>OTP codes are intercepted before expiration</p></li><li><p>Payment cards are immediately provisioned into attacker-controlled digital wallets</p></li></ul><p>The result is instant fraud capability through:</p><ul><li><p>Contactless payments</p></li><li><p>ATM withdrawals</p></li><li><p>High-value transactions</p></li></ul><p>What&#8217;s accelerating these campaigns further is AI-driven localization. AI now removes the awkward phrasing, cultural inconsistencies, and translation artifacts that historically exposed many phishing attempts. Attackers can now generate:</p><ul><li><p>Region-specific language</p></li><li><p>Local slang</p></li><li><p>Native writing styles</p></li><li><p>Context-aware social engineering messages</p></li></ul><p>This is why time-based OTP MFA is rapidly losing effectiveness against sophisticated phishing operations. Organizations should aggressively move toward:</p><ul><li><p>FIDO2 authentication</p></li><li><p>Passkeys</p></li><li><p>Hardware-backed authentication models</p></li></ul><p>because traditional OTP workflows are increasingly being defeated at scale.</p><h2>&#9917; FIFA World Cup Fraud Campaign Expands Across 3,500 Domains</h2><p>With the FIFA World Cup only weeks away, researchers uncovered a massive fraud ecosystem called &#8220;Ghost Stadium&#8221; involving over 3,500 malicious domains targeting fans worldwide. The operation includes:</p><ul><li><p>Fake FIFA login portals</p></li><li><p>Fraudulent ticket sales</p></li><li><p>Counterfeit merchandise stores</p></li><li><p>Fake streaming sites</p></li><li><p>Betting scams</p></li><li><p>Credential harvesting campaigns</p></li></ul><p>Researchers identified more than:</p><ul><li><p>2,500 FIFA account credentials already circulating</p></li><li><p>170,000 InfoStealer logs referencing FIFA-related accounts</p></li></ul><p>The sophistication of the phishing kits is significant. They are pixel-perfect clones supporting eleven languages and multiple Chinese dialect variants while leveraging Meta advertising infrastructure to drive traffic.</p><p>This matters operationally because global events like the World Cup create emotional urgency and excitement that attackers weaponize extremely effectively.</p><p>Security teams should proactively educate employees and customers about:</p><ul><li><p>Official ticketing channels</p></li><li><p>Fake streaming scams</p></li><li><p>Credential reuse risks</p></li><li><p>Financial fraud patterns</p></li></ul><p>This is a major opportunity for security teams to build trust with users through practical education instead of fear-based awareness alone.</p><h2>&#129302; AI Chatbots Recommending Malware-Infected Software</h2><p>Microsoft researchers documented an active cryptojacking campaign where attackers poison AI chatbot recommendations to steer users toward malware-laced software downloads. Victims asking AI tools for download recommendations are redirected toward malicious versions of:</p><ul><li><p>CrystalDiskInfo</p></li><li><p>HWMonitor</p></li><li><p>FurMark</p></li><li><p>Display Driver Uninstaller</p></li><li><p>K-Lite Codec Pack</p></li></ul><p>The targeting is deliberate because these utilities are popular among users with high-performance GPUs, ideal systems for cryptocurrency mining malware. The payloads establish persistence using ScreenConnect and provide remote access capabilities that can later escalate into:</p><ul><li><p>Data theft</p></li><li><p>Ransomware deployment</p></li><li><p>Additional malware staging</p></li></ul><p>This is a major shift:<br>&#128073; AI chatbots themselves are becoming attack surface infrastructure.</p><p>Users increasingly trust AI-generated recommendations as authoritative, which gives attackers a new high-trust distribution channel.</p><p>Organizations should reinforce policies requiring software downloads only from official vendor domains and aggressively monitor for unauthorized remote management tools like ScreenConnect.</p><h2>&#128230; Malicious npm Package Stealing Anthropic Cloud AI Session Files</h2><p>Researchers at Aikido Security discovered a malicious npm package called <code>mouse5212-superformatter</code> specifically engineered to steal Anthropic Cloud AI session files from developer environments. Once installed, the malware:</p><ul><li><p>Authenticates into GitHub repositories</p></li><li><p>Recursively uploads AI session data</p></li><li><p>Steals cloud code session information</p></li><li><p>Harvests outputs and uploads directories</p></li></ul><p>The package was downloaded hundreds of times before detection. What&#8217;s especially interesting is that the attacker accidentally embedded their own GitHub token into the malware, leading researchers to speculate the package itself may have been AI-assisted malware generated without proper operational security review.</p><p>This highlights a rapidly emerging risk:<br>&#128073; AI development environments now sit in deeply trusted positions with broad filesystem and credential access.</p><p>Compromising one malicious dependency can expose everything the AI tooling has ever touched.</p><p>Organizations building AI workflows should aggressively audit:</p><ul><li><p>npm dependencies</p></li><li><p>AI development environments</p></li><li><p>File access patterns within <code>/mnt/userdata</code> directories</p></li></ul><h2>&#128737;&#65039; CrowdStrike and Google Disrupt GlassWorm Botnet</h2><p>In one of the few positive stories today, CrowdStrike, Google, and the ShadowServer Foundation successfully disrupted all four command-and-control channels tied to the GlassWorm botnet.</p><p>GlassWorm originally spread through trojanized VS Code extensions and used Unicode variation selectors to invisibly hide malicious code inside seemingly legitimate source files. The infrastructure was remarkably resilient, leveraging:</p><ul><li><p>VPS infrastructure</p></li><li><p>Google Calendar covert channels</p></li><li><p>BitTorrent peer-to-peer communication</p></li><li><p>Solana blockchain backup channels</p></li></ul><p>Attribution evidence strongly suggests Russian operational origins. The story is important because it demonstrates how modern malware is increasingly:</p><ul><li><p>Multi-channel</p></li><li><p>Decentralized</p></li><li><p>Blockchain-aware</p></li><li><p>Supply-chain-focused</p></li></ul><p>Botnets are evolving operational resilience faster than many traditional detection models are adapting.</p><h2>&#127470;&#127475; India Mandates 12-Hour Critical Vulnerability Patching</h2><p>India&#8217;s CERT issued a new cybersecurity framework mandating twelve-hour patching timelines for critical internet-facing vulnerabilities. The guidance specifically cites:</p><ul><li><p>AI-assisted exploit generation</p></li><li><p>Automated attack surface mapping</p></li><li><p>AI-enhanced phishing</p></li><li><p>Rapid exploit weaponization</p></li></ul><p>as justification for dramatically compressed remediation timelines. The framework now requires:</p><ul><li><p>Critical internet-facing vulnerabilities patched within one day</p></li><li><p>High-value internal systems within three days</p></li><li><p>High-severity vulnerabilities within five days</p></li></ul><p>This directly aligns with what many practitioners are already experiencing operationally:<br>&#128073; The old thirty-day patching model is becoming operationally obsolete.</p><p>Attackers are exploiting vulnerabilities far too quickly for traditional remediation cadences to remain effective.</p><h1>&#127919; Key Takeaway</h1><p>&#128073; The attack surface has evolved into a fully blended cyber, physical, AI-assisted, and operational battlefield&#8212;and traditional defensive timelines are collapsing under the pressure.</p><div class="callout-block" data-callout="true"><p><em>"Today's show has a clear monolithic through line: the attack surface has gone fully multi-domain. Iran's inside LA's transit control displays. Cybercriminals are walking through your front door. Chinese phishing-as-a-service operators are defeating MFA in real time. AI chatbots are recommending malware. Developer tooling is a deliberate supply chain target. India's twelve-hour patching mandate and US Cyber Command's MITRE review are two governments acknowledging the same reality, we are operating in an environment where the time between vulnerability and exploitation is collapsing fast. The old defensive cadences were built for a world that no longer exists."</em></p></div><h1>&#128736;&#65039; Action Items for Security Leaders</h1><ul><li><p>&#128647; Segment OT and IT environments aggressively in critical infrastructure</p></li><li><p>&#128682; Implement stronger visitor verification and USB device restrictions</p></li><li><p>&#128179; Move financial workflows toward FIDO2 and passkey authentication</p></li><li><p>&#9917; Educate employees and customers about FIFA-related fraud campaigns</p></li><li><p>&#129302; Restrict software downloads to official vendor domains only</p></li><li><p>&#128230; Audit npm dependencies across AI development environments</p></li><li><p>&#128737;&#65039; Monitor developer tooling for unauthorized VS Code extensions</p></li><li><p>&#127470;&#127475; Compress vulnerability remediation timelines for internet-facing systems</p></li><li><p>&#128269; Conduct physical social engineering tabletop exercises</p></li><li><p>&#9889; Treat AI chatbot recommendations as untrusted input unless validated</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how quickly the definition of cybersecurity is changing operationally. We&#8217;re no longer dealing with isolated technical attacks. We&#8217;re seeing blended operations involving AI-assisted phishing, physical intrusion attempts, operational technology targeting, and supply chain compromise all happening simultaneously. Attackers are adapting faster than many enterprise security programs are structurally capable of responding.</p><p>The second major takeaway is around speed. India&#8217;s twelve-hour patching mandate reflects what many security practitioners already know internally but haven&#8217;t fully operationalized yet: the time between vulnerability disclosure and active exploitation is collapsing. Organizations still operating on thirty-day remediation cycles for critical systems are increasingly taking on unacceptable operational risk. Security programs need to evolve toward rapid-response operational models because attackers already have.</p><p>&#128293; Stay Cyber Safe.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/iranian-mois-hackers-behind-la-metro?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[ShinyHunters Breach Charter Communications via Vishing, Iran's Nimbus Manticore Targets Aviation and Software Companies, Lithuania Investigates Suspected Russian Theft of 600K State Registry Records ]]></title><description><![CDATA[Charter 42M Records Breached, Knowledge Deliver LMS Zero-Day Deploying Cobalt Strike, SharePoint Ad-Band RCE, Two Iranian APT Campaigns, Lithuania 600K State Records Stolen, UK Visa Portal Leaks]]></description><link>https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications</link><guid isPermaLink="false">https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications</guid><dc:creator><![CDATA[James Azar]]></dc:creator><pubDate>Wed, 27 May 2026 13:30:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/199410995/02475ddeaebd7e2987b9e6ab5363c1a0.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h1>&#9749; Good Morning Security Gang,</h1><p>Welcome to episode 1,114 of the podcast, and honestly, seeing that number this morning felt pretty surreal. Over a thousand episodes later, and the cyber world still somehow finds new ways to make us all question humanity before our first espresso.</p><p>Today&#8217;s episode painted a very consistent picture across every single story we covered. Attackers are operating faster, more aggressively, and with clearer operational discipline than many organizations defending against them. Whether it was ShinyHunters putting Charter Communications on a ticking leak deadline, Iranian APTs quietly expanding campaigns across aviation and enterprise environments, or Chinese operators turning routers into silent surveillance platforms, the underlying issue remains the same: defenders are still treating many cyber incidents like administrative processes while attackers are treating them like wartime operations.</p><p>And somewhere in the middle of all of that, Europe continues accelerating toward digital sovereignty separation from the United States, creating a geopolitical and operational challenge that security leaders can no longer afford to ignore.</p><p>Double espresso in hand. Coffee cup cheers, gang. Let&#8217;s get into it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/subscribe?"><span>Subscribe now</span></a></p><h1>&#129517; Executive Summary</h1><p>Today&#8217;s threat landscape reflects an operational speed problem more than a technology problem. Organizations continue struggling with:</p><ul><li><p>Slow remediation cycles</p></li><li><p>Weak identity verification controls</p></li><li><p>Legacy trust assumptions</p></li><li><p>Poor visibility into edge infrastructure</p></li><li><p>Overreliance on communication management instead of technical containment</p></li></ul><p>Meanwhile, attackers are chaining together social engineering, cloud compromise, remote administration tooling, DLL side-loading, and infrastructure persistence with increasing efficiency.</p><p>The result is a cybersecurity environment where vulnerabilities are becoming twenty-four-hour operational crises while many enterprises still manage them through thirty-day governance workflows.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ca-O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ca-O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ca-O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:231417,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberhubpodcast.com/i/199410995?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ca-O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Ca-O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8191ce-b59a-4808-bb41-2a0240d8140f_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>&#128240; Top Stories &amp; Deep Dive Analysis</h1><h2>&#128225; Charter Communications Confirms Massive ShinyHunters Breach</h2><p>Charter Communications confirmed that the ShinyHunters extortion group breached company systems and allegedly stole approximately 42 million customer records following a voice phishing attack targeting an employee&#8217;s Microsoft Entra account.</p><p>According to Charter, the attackers leveraged the compromised account to access Salesforce environments and export large amounts of consumer and business data. While the company claims that highly sensitive customer proprietary network information was not exposed, ShinyHunters disputes that assessment and issued a public leak deadline tied to extortion negotiations.</p><p>Even if highly sensitive data was excluded, the exposed information still represents a major operational risk. Names, emails, phone numbers, and account-related details become highly effective fuel for:</p><ul><li><p>Credential stuffing</p></li><li><p>SIM swap targeting</p></li><li><p>Spear phishing</p></li><li><p>Social engineering campaigns</p></li></ul><p>One of the most important lessons here is around voice phishing defense. Many organizations still rely on weak help desk verification processes and SMS-based authentication. Managed authenticator applications combined with identity verification prompts sent directly to corporate-managed devices significantly reduce the success rate of these attacks.</p><p>This is another reminder that identity workflows remain one of the weakest operational links inside many enterprises today.</p><h2>&#127891; Knowledge Deliver LMS Zero-Day Deploying Cobalt Strike</h2><p>A critical zero-day vulnerability affecting the Knowledge Deliver learning management platform is actively being exploited to deploy memory-resident Cobalt Strike payloads through watering hole attacks.</p><p>The vulnerability exists because every deployment shared identical hardcoded ASP.NET machine keys. That means attackers can perform unauthenticated remote code execution across virtually every vulnerable deployment through ViewState deserialization.</p><p>The attack chain itself is layered:</p><ul><li><p>Initial unauthenticated RCE</p></li><li><p>In-memory Godzilla webshell deployment</p></li><li><p>Malicious JavaScript injection into the front end</p></li><li><p>Fake browser security warning overlays</p></li><li><p>User tricked into installing a &#8220;security plugin&#8221;</p></li><li><p>Cobalt Strike beacon deployment</p></li></ul><p>The result is that compromised LMS platforms become active malware distribution infrastructure targeting every visitor to the site.</p><p>What makes this especially frustrating is that organizations do not need to wait for a vendor patch cycle to mitigate the issue. Immediate rotation of ASP.NET machine keys to strong unique cryptographic values effectively closes the attack path.</p><p>This story highlights how devastating configuration management failures continue to be across enterprise environments.</p><h2>&#127970; Microsoft Drops Emergency SharePoint RCE Patch</h2><p>Microsoft released an out-of-band patch for CVE-2026-45659, a SharePoint Server remote code execution vulnerability affecting:</p><ul><li><p>SharePoint Server Subscription Edition</p></li><li><p>SharePoint 2019</p></li><li><p>SharePoint 2016</p></li></ul><p>The flaw stems from unsafe deserialization of untrusted data and can be triggered by any authenticated user with basic &#8220;site member&#8221; permissions.</p><blockquote><p><em>&#8220;Attackers are treating vulnerabilities like twenty-four-hour opportunities while too many organizations still treat them like thirty-day tickets.&#8221; James Azar</em></p></blockquote><p>That detail matters enormously because in many enterprises, &#8220;site member&#8221; effectively means almost every employee.</p><p>No administrator privileges are required, no user interaction is necessary after authentication, and Microsoft&#8217;s decision to release the patch outside its normal cycle strongly suggests elevated exploitation concern.</p><p>Organizations with internet-facing SharePoint deployments should prioritize remediation immediately, while internally exposed environments should still be patched within forty-eight hours. Monitoring SharePoint ULS logs for deserialization-related anomalies should also become a priority.</p><p>The larger issue here is operational exposure created by over-trusted internal users. Modern enterprise attack surfaces increasingly assume authenticated insider access as the starting point, not the endpoint.</p><h2>&#128128; NightSpire Ransomware Expands Across 28 Industries</h2><p>The NightSpire ransomware group has now impacted 175 organizations across twenty-eight industries since early 2025, including hospitals, schools, financial institutions, and government agencies.</p><p>What stands out about NightSpire is how operationally efficient the group has become by relying almost entirely on legitimate software rather than noisy custom malware.</p><p>Their typical intrusion path includes:</p><ul><li><p>Exposed RDP services</p></li><li><p>Exploitation of FortiOS vulnerabilities</p></li><li><p>Chrome Remote Desktop</p></li><li><p>AnyDesk</p></li><li><p>7-Zip</p></li><li><p>MegaSync cloud exfiltration</p></li></ul><p>The group&#8217;s strategy is simple but effective:<br>&#128073; Blend into legitimate operational activity and avoid triggering traditional EDR alerts.</p><p>This reflects a larger trend across ransomware operations where attackers increasingly weaponize trusted enterprise tools rather than deploying easily identifiable malware families. Organizations should aggressively audit:</p><ul><li><p>Externally exposed RDP</p></li><li><p>Unauthorized remote administration software</p></li><li><p>Unexpected cloud synchronization tooling</p></li><li><p>FortiOS patching status</p></li></ul><h2>&#127470;&#127479; Iranian APT Activity Expands Across Enterprise and Aviation Targets</h2><p>Microsoft Threat Intelligence published updated findings on MuddyWater campaigns targeting organizations across nine countries during the first quarter of 2026. The group refined its DLL side-loading tradecraft using trusted executables such as:</p><ul><li><p><code>fmap.exe</code></p></li><li><p>SentinelOne Memory Scanner components</p></li></ul><p>to load malicious DLLs while avoiding many traditional signature-based endpoint detections. The attackers also expanded use of:</p><ul><li><p>Chrome credential theft tooling</p></li><li><p>Node.js-based payload delivery</p></li><li><p>PowerShell execution chains</p></li></ul><p>At the same time, a separate Iranian threat cluster launched targeted campaigns against aviation software providers through credential harvesting and social engineering operations.</p><p>The strategy appears focused on supply chain pre-positioning:<br>&#128073; Compromise the software vendor first, then pivot downstream into airlines, airports, and aerospace organizations later.</p><p>DLL side-loading continues to represent one of the hardest detection problems for many enterprises because attackers operate inside otherwise legitimate processes.</p><p>Behavioral monitoring and parent-child process analysis become essential in this type of environment.</p><h2>&#127464;&#127475; China-Linked Linux Implant Turns Routers Into Surveillance Infrastructure</h2><p>A China-linked threat actor deployed a custom Linux implant called <code>router.elf</code> onto edge routers across Southeast Asia.</p><p>Once installed, the implant:</p><ul><li><p>Communicates over DNS-over-HTTPS</p></li><li><p>Manipulates internal DNS systems</p></li><li><p>Redirects downstream traffic</p></li><li><p>Enables selective interception and surveillance</p></li></ul><p>The malware reportedly references a dynamically updated targeting list called <code>evil_fix</code>, allowing operators to selectively hijack traffic destined for specific services or users.</p><p>This is not financially motivated malware.<br>This is strategic surveillance infrastructure.</p><p>Compromised routers effectively become silent collection platforms for every device and connection behind them. Organizations should validate firmware integrity, monitor DNS modifications carefully, and review unusual outbound encrypted traffic originating from network appliances.</p><h2>&#127475;&#127473; Europe Accelerates Digital Sovereignty Separation</h2><p>The Dutch government blocked a U.S. IT company from acquiring Solvinity, a Dutch cloud provider hosting the country&#8217;s national digital identity infrastructure, citing concerns over digital sovereignty and exposure to U.S. legal reach.</p><p>This marks the third major European intervention this quarter tied directly to concerns over U.S. ownership of sensitive cloud infrastructure. The geopolitical implications are becoming increasingly important for CISOs and enterprise leadership teams. Organizations operating across both U.S. and European markets should begin preparing for:</p><ul><li><p>Increased data residency requirements</p></li><li><p>Regional infrastructure segmentation</p></li><li><p>Regulatory divergence</p></li><li><p>Potential restrictions around transatlantic cloud ownership</p></li></ul><p>This is no longer theoretical political discussion&#8212;it is becoming an operational architecture issue.</p><h2>&#128196; UK Visa Portal Leaks 100,000 Passports and Selfies</h2><p>A third-party UK visa processing portal leaked more than 100,000 passport scans, selfies, and personal identity documents online.</p><p>The most infuriating detail in the story was the company&#8217;s response. When journalists contacted them regarding the exposure, the organization reportedly responded with lawyers instead of engineers.</p><blockquote><p><em>&#8220;When a company responds to a breach with lawyers before engineers, you already know the problem is bigger than the leak.&#8221; James Azar</em></p></blockquote><p>At the time of reporting, the leak remained unresolved.</p><p>Passport scans combined with biometric selfies create premium-grade fraud material capable of supporting:</p><ul><li><p>KYC bypasses</p></li><li><p>Fake identity creation</p></li><li><p>Fraudulent financial account openings</p></li><li><p>Long-term identity theft</p></li></ul><p>This story perfectly captures one of the industry&#8217;s biggest operational failures:<br>Too many organizations still treat cybersecurity incidents as communications crises first and technical crises second.</p><p>Attackers move at machine speed. Lawyers do not patch servers.</p><h1>&#127919; Key Takeaway</h1><p>&#128073; The organizations succeeding in cybersecurity today are treating vulnerabilities and incidents like operational emergencies&#8212;not governance exercises.</p><h1>&#128736;&#65039; Action Items for Security Leaders</h1><ul><li><p>&#128225; Deploy managed authenticator workflows to reduce voice phishing exposure</p></li><li><p>&#127891; Rotate ASP.NET machine keys immediately on vulnerable LMS deployments</p></li><li><p>&#127970; Patch SharePoint environments within forty-eight hours or less</p></li><li><p>&#128128; Restrict unauthorized remote administration tooling like AnyDesk and Chrome Remote Desktop</p></li><li><p>&#127470;&#127479; Monitor DLL side-loading behaviors involving trusted binaries</p></li><li><p>&#9992;&#65039; Audit aviation-related vendor access and third-party software trust chains</p></li><li><p>&#127464;&#127475; Validate router firmware integrity and DNS configuration changes</p></li><li><p>&#127473;&#127481; Review sensitive government and property database access logging</p></li><li><p>&#127757; Begin board-level conversations around European data sovereignty risk</p></li><li><p>&#128196; Treat biometric identity data leaks as permanent compromise events requiring monitoring</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications/comments"><span>Leave a comment</span></a></p><h1>&#129504; James Azar&#8217;s CISOs Take</h1><p>What stood out to me today is how operationally disciplined attackers have become compared to many enterprises defending against them. Whether it&#8217;s ShinyHunters, Iranian APTs, or Chinese surveillance operators, these groups are moving quickly, chaining together trusted tooling, cloud access, remote administration software, and infrastructure persistence with clear intent and urgency. Meanwhile, many organizations are still struggling to operationalize rapid containment and response at the same pace.</p><p>The second major takeaway is that cybersecurity is increasingly becoming tied directly to geopolitics and infrastructure sovereignty. Europe&#8217;s movement toward digital separation from U.S. cloud ownership isn&#8217;t just regulatory theater anymore, it&#8217;s beginning to influence enterprise architecture, acquisition strategy, and long-term operational planning. Security leaders should be preparing their organizations now for a future where technology trust boundaries may increasingly align with political and geographic borders.</p><p>&#128293; <strong>Stay Cyber Safe.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading CISO Talk by James Azar! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberhubpodcast.com/p/shinyhunters-breach-charter-communications?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item></channel></rss>