<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Daily BlueTeamSec Briefing</title>
    <description>Daily security briefings for blue team professionals</description>
    <language>en-us</language>
    <copyright>© 2025 InfoSec Briefing Bot</copyright>
    <managingEditor>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</managingEditor>
    <webMaster>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</webMaster>
    <category>Technology</category>
    <generator>InfoSec Briefing Generator</generator>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <link>https://briefing.workshop1.net</link>
    <pubDate>Sun, 31 Aug 2025 16:05:46 +0000</pubDate>
    <lastBuildDate>Wed, 22 Jul 2026 06:01:22 +0000</lastBuildDate>
    <itunes:author>InfoSec Briefing Bot</itunes:author>
    <itunes:summary>Daily security briefings for blue team professionals</itunes:summary>
    <itunes:category>Technology</itunes:category>
    <itunes:image href="https://briefing.workshop1.net/assets/podcast-artwork.jpg"/>
    <itunes:owner>
      <itunes:name>InfoSec Briefing Bot</itunes:name>
      <itunes:email>podcast@briefing.workshop1.net</itunes:email>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:language>en-us</itunes:language>
    <item>
      <title>InfoSec Briefing - July 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-22.html</link>
      <pubDate>Wed, 22 Jul 2026 06:01:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260722_060122</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li>The Morris Worm: The Internet's First Major Wake-Up Call <em>(Historical Archive)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-22.mp3" length="1426120" type="audio/mpeg"/>
      <itunes:duration>1:29</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-21.html</link>
      <pubDate>Tue, 21 Jul 2026 06:04:42 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260721_060442</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography">Contagious Interview malware in SVG images: DPRK campaign</a> <em>(Elastic)</em></li><li><a href="https://ddosier-disects.medium.com/the-one-chokepoint-to-rule-them-all-why-i-deleted-50-clickfix-detection-rules-and-replaced-them-7c532206d32d">The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them with One</a> <em>(Ddosier)</em></li><li><a href="https://github.com/optimuslabs-io/grokpatrol">grokpatrol: Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.</a> <em>(Optimus Labs)</em></li><li><a href="https://www.half-second.com/">Half a Second - The Backdoor That Almost Broke the Internet, and the Invisible Labor Beneath It</a> <em>(Adrian Mastronardi)</em></li><li><a href="https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/">OpenSSL HollowByte: A DoS Hiding in 11 Bytes</a> <em>(Okta)</em></li><li><a href="https://joshparnham.com/2026/07/accessing-sensitive-passwords-app-account-data-on-macos-cve-2025-24169/">Accessing sensitive Passwords app account data on macOS (CVE-2025-24169)</a> <em>(Josh Parnham)</em></li><li><a href="https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets">IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets</a> <em>(Bloomberg)</em></li><li><a href="https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/">Magnet Forensics, LLC v. Del Gaudio (1:26-cv-03781) - allegedly Magnet were exploiting usbliter8 BootROM exploit that Paradigm Shift published - said it was leaked</a> <em>(Free Law Project)</em></li><li><a href="https://www.aikido.dev/blog/benchmarking-ai-models-known-cves">Benchmarking 13 AI Models on Known CVE Detection</a> <em>(Aikido Security)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-21.mp3" length="3950176" type="audio/mpeg"/>
      <itunes:duration>4:06</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-20.html</link>
      <pubDate>Mon, 20 Jul 2026 06:11:53 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260720_061153</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>30</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster/">The RedLine Thread That Led to a Maritime BEC Infrastructure Cluster</a> <em>(VMRay)</em></li><li><a href="https://www.yahoo.com/news/world/articles/iran-reportedly-used-1970s-phone-162553330.html">Iran Reportedly Used a 1970s Phone Protocol to Track U.S. Troops Before Missile Strikes</a> <em>(Yahoo)</em></li><li><a href="https://www.fsec.or.kr/bbs/detail?menuNo=244&bbsNo=11990">금융보안원 - This report provides an in-depth analysis of attack and money laundering techniques employed by state-backed hacking organizations regarding cross-chain security threats among digital assets</a> <em>(금융보안원)</em></li><li><a href="https://opensourcemalware.com/blog/polinrider-blast-radius-grows">PolinRider Confirmed Footprint Grows 6.5x Since March</a> <em>(OpenSourceMalware)</em></li><li><a href="https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm">European Password Manager Shares Origins and Updates with State-Certified Russian Firm</a> <em>(Organized Crime and Corruption Reporting Project (OCCRP))</em></li><li><a href="https://www.graphika.com/reports/save-the-date-for-spamouflage">Save the Date for Spamouflage</a> <em>(Graphika)</em></li><li><a href="https://securelist.com/tr/hellonet-vipnet/120700/">HelloNet campaign: a threat via the ViPNet update system</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26014/?ref=metacurity.com">ZSB-26014: Zoom Workplace for Windows - Improper Input Validation</a> <em>(Zoom Video Communications, Inc.)</em></li><li><a href="https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/">Windows AppResolver LPE: From AppContainer to SYSTEM</a> <em>(David Carliez)</em></li><li><a href="https://aprl.pet/writing/cve-2026-58532">How I found an integer overflow in tcpip.sys</a> <em>(aprilpet)</em></li><li><a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/">wp2shell: Pre Authentication RCE in WordPress Core</a> <em>(Searchlight Cyber)</em></li><li><a href="https://blog.zsec.uk/wp2shell-code-trace-deep-dive/">wp2shell - Code Trace Deep Dive</a> <em>(ZephrFish (Andy Gill))</em></li><li><a href="https://github.com/Icex0/wp2shell-poc">wp2shell-poc: wp2shell - Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory.</a> <em>(Icex0)</em></li><li><a href="https://arxiv.org/abs/2607.05993">Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures</a> <em>(Zhouhao Ji, Kaikai Pan, and Wenyuan Xu)</em></li><li><a href="https://www.openwall.com/lists/oss-security/2026/07/14/10">CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read</a> <em>(Openwall)</em></li><li><a href="https://github.com/karollooool/CVE-2026-50416-writeup-and-poc">lCVE-2026-50416-writeup-and-poc: CVE-2026-50416: Windows 11 KASLR bypass</a> <em>(karollol)</em></li><li><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/">Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation</a> <em>(Volexity)</em></li><li><a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas">Report into preliminary inquiries of Qantas</a> <em>(Office of the Australian Information Commissioner)</em></li><li><a href="https://github.com/inclusionAI/SingGuard-NSFA">SingGuard-NSFA: Extensible Guardrails for Agentic AI via Generative Reasoning and Real-Time Classification</a> <em>(SingGuard Team, AI Security Lab, Ant Group)</em></li><li><a href="https://github.com/instavm/tarit">tarit: A hypervisor and sandbox cloud for self-hosted AI agents and RL</a> <em>(Instavm)</em></li><li><a href="https://github.com/secdev02/Incantation">Incantation: AI Deception Layer for  - containing adversarial context designed to redirect or confuse an LLM agent reading your own infrastructure</a> <em>(Casey)</em></li><li><a href="https://wojciechregula.blog/post/golden-gate-appdata-protection/">Crossing the Golden Gate: macOS's New Application Support Protection</a> <em>(Wojciech Reguła)</em></li><li><a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/">White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination</a> <em>(The White House)</em></li><li><a href="https://github.com/NetSPI/AD-PathFinder">AD-PathFinder: Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.</a> <em>(NetSPI)</em></li><li><a href="https://github.com/An0nUD4Y/Offensive-COM">Offensive-COM: Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research.</a> <em>(An0nUD4Y)</em></li><li><a href="https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft">DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft</a> <em>(eSentire)</em></li><li><a href="https://jsac.jpcert.or.jp/">JSAC2027 - January, Tokyo - CFP</a> <em>(JPCERT/CC)</em></li><li><a href="https://assets.sophos.com/X24WTUEQ/at/jbww7pmb8n3gp99wr6hfq4/sophos-state-ransomware-report-2026.pdf">The State of 
Ransomware 2026 - Stolen identities cause 79% of ransomware attacks</a> <em>(Sophos Ltd.)</em></li><li><a href="https://github.com/samyeyo/clx">clx: A cross-platform ahead-of-time Lua compiler and runtime, using C++20 backend</a> <em>(Tine Samir)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-20.mp3" length="10921735" type="audio/mpeg"/>
      <itunes:duration>11:22</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 19, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-19.html</link>
      <pubDate>Sun, 19 Jul 2026 06:01:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260719_060150</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://developer.chrome.com/blog/nhs-passkeys-case-study">How NHS England improved sign-in times and saved over £1m with passkeys</a> <em>(Google LLC)</em></li><li><a href="https://huggingface.co/blog/security-incident-july-2026">Security incident disclosure — July 2026 - "The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline."</a> <em>(Hugging Face)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-19.mp3" length="1421105" type="audio/mpeg"/>
      <itunes:duration>1:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-18.html</link>
      <pubDate>Sat, 18 Jul 2026 06:07:52 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260718_060752</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault">Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2</a> <em>(Genians)</em></li><li><a href="https://www.security.com/threat-intelligence/daxin-returns-stupig">Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor</a> <em>(Broadcom)</em></li><li><a href="https://www.occrp.org/en/project/the-pegasus-project/co-founder-of-controversial-spyware-firm-had-israeli-diplomatic-passport">Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport</a> <em>(Organized Crime and Corruption Reporting Project (OCCRP))</em></li><li><a href="https://www.theguardian.com/news/2026/jul/16/morocco-intelligence-insider-reveals-widespread-use-hacking-software-pegasus">Moroccan intelligence insider reveals widespread use of Pegasus hacking software</a> <em>(The Guardian)</em></li><li><a href="https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql">Detections for LegacyHive exploitation by GossiTheDog</a> <em>(GossiTheDog)</em></li><li><a href="https://www.gov.uk/government/publications/revised-telecommunications-security-code-of-practice-2026-version-11">Revised Telecommunications Security Code of Practice 2026 (version 1.1)</a> <em>(Department for Science, Innovation and Technology)</em></li><li><a href="https://media.defense.gov/2026/Jul/14/2003961238/-1/-1/0/260714-D-AB123-1001.PDF">Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers</a> <em>(media.defense.gov)</em></li><li><a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions">AsyncAPI Supply Chain Compromise via GitHub Actions</a> <em>(Wiz)</em></li><li><a href="https://www.bbc.co.uk/news/articles/c4gyg0y6yg2o">Teen hackers jailed after live streaming cyber attack on TfL - sentenced to five years and six months in prison.</a> <em>(BBC)</em></li><li><a href="https://github.com/Astharot15/COMLoaderAstharot/">COM Hijack for CLSID {9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</a> <em>(Astharot15)</em></li><li><a href="https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline">CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining</a> <em>(Tiziano Marra)</em></li><li><a href="https://medium.com/@s12deff/registry-snapshots-for-post-exploitation-enumeration-fbf5798091da">Registry Snapshots for Post Exploitation Enumeration</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://github.com/toneillcodes/UnwindRaven">UnwindRaven is a Windows x64 offensive research framework that constructs fully synthetic call stacks at thread startup time, making a newly created thread appear</a> <em>(toneillcodes)</em></li><li><a href="https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/">There and Back Again: An Operators Guide on NTLM Relaying Egress</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/toneillcodes/windows-process-injection">windows-process-injection: A collection of techniques for process injection on Windows</a> <em>(toneillcodes)</em></li><li><a href="https://speakerdeck.com/nttcom/ghost-in-the-7-zip-the-shadow-of-residential-proxies-creeping-into-your-life">Ghost in the 7‑Zip: The Shadow of Residential Proxies Creeping into Your Life</a> <em>(DOCOMO BUSINESS, Inc.)</em></li><li><a href="https://github.com/Sizeable-Bingus/BingusLdr">BingusLdr: BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.</a> <em>(Sizeable-Bingus)</em></li><li><a href="https://kirchware.com/Modular-PIC-Implant-Design">Modular PIC Implant Design</a> <em>(Kirchware)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-18.mp3" length="8920964" type="audio/mpeg"/>
      <itunes:duration>9:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-17.html</link>
      <pubDate>Fri, 17 Jul 2026 06:05:38 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260717_060538</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://go.rewardsforjustice.net/cyber-medialand-en/">REWARD UP TO $10,000,000 USD - FOR INFORMATION ON Russian Malicious Cyber Actors</a> <em>(U.S. Department of State)</em></li><li><a href="https://www.reuters.com/world/alleged-russian-cyber-spy-boston-case-previously-worked-kaspersky-source-says-2026-07-15/">Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show</a> <em>(Thomson Reuters)</em></li><li><a href="https://s2w.inc/en/resource/detail/1096">BirdCall: ScarCruft Malware Masquerading as Zangi Messenger</a> <em>(S2W)</em></li><li><a href="https://mp.weixin.qq.com/s/6hjjsEuuOTk8_FJrXWe9Ew">Analysis of attack actions suspected to be from the APT-C-26 (Lazarus) group upgrading its monitoring program</a> <em>(奇安信威胁情报中心)</em></li><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a> <em>(Hunt.io)</em></li><li><a href="https://expel.com/blog/introducing-cylindricalcanine/">Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident</a> <em>(Expel, Inc.)</em></li><li><a href="https://www.cyderes.com/howler-cell/tracking-donot-apt-c-35-bangladesh-military-intrusion">DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel</a> <em>(Cyderes)</em></li><li><a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix">TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains</a> <em>(Elastic)</em></li><li><a href="https://tailscale.com/security-bulletins#ts-2026-009">Tailscale: Tailscale SSH previously accepted usernames that contained a leading - character. On Linux platforms these usernames were passed as arguments to getent(1) leading to ACL bypass</a> <em>(Tailscale Inc.)</em></li><li><a href="https://github.com/secdev02/cyber-decoy">cyber-decoy: Experimental Decoy Broker</a> <em>(secdev02)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-17.mp3" length="4488925" type="audio/mpeg"/>
      <itunes:duration>4:40</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-16.html</link>
      <pubDate>Thu, 16 Jul 2026 06:07:24 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260716_060724</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses">Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims</a> <em>(U.S. Attorney's Office for the Northern District of Ohio)</em></li><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blogs.jpcert.or.jp/en/2026/07/apt-c-60_2026.html">Update on Attacks by Threat Group APT-C-60 in 2026</a> <em>(JPCERT/CC)</em></li><li><a href="https://cip.gov.ua/en/news/cert-ua-opracyuvala-3309-kiberincidentiv-v-pershomu-pivrichchi-2026-roku">CERT-UA Handled 3,309 Cyber Incidents in the First Half of 2026</a> <em>(State Service of Special Communications and Information Protection of Ukraine)</em></li><li><a href="https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/">Malicious GitHub Campaign: Fake "Arctic Wolf" and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer</a> <em>(Arctic Wolf)</em></li><li><a href="https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026">Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026</a> <em>(DomainTools)</em></li><li><a href="https://www.bbc.co.uk/news/articles/cp3x37lw1ndo">Public to be told how to prepare for cyber-attack and weather emergencies</a> <em>(British Broadcasting Corporation)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/">Forgotten UEFI shims undermining Secure Boot</a> <em>(ESET)</em></li><li><a href="https://github.com/MSNightmare/LegacyHive">LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade</a> <em>(SonicWall)</em></li><li><a href="https://research.jfrog.com/post/miasma-worm-returns-to-npm/">Miasma Worm Returns to npm</a> <em>(JFrog)</em></li><li><a href="https://research.jfrog.com/post/lucide-proxy-npm-malware-campaign/">Lucide Proxy: Turning Student Web Proxies into DDoS Bots</a> <em>(JFrog)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy">OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration</a> <em>(Proofpoint)</em></li><li><a href="https://ctrlaltintel.com/research/VoidBlizzard/">Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links</a> <em>(Hunt.io)</em></li><li><a href="https://trustedsec.com/blog/pandoras-container-part-1-unpacking-azure-container-security?hss_channel=tw-403811306">Pandora’s Container Part 1: Unpacking Azure Container Security</a> <em>(TrustedSec)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-16.mp3" length="6039136" type="audio/mpeg"/>
      <itunes:duration>6:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-15.html</link>
      <pubDate>Wed, 15 Jul 2026 06:04:04 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260715_060404</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/">Targeting and Compromise of French Entities Using the Turla Intrusion Set</a> <em>(Agence nationale de la sécurité des systèmes d'information (ANSSI))</em></li><li><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting">UK and Allies urge critical sectors to improve defences against Russian intelligence targeting</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF">Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.aol.com/articles/russian-man-pleads-not-guilty-213052000.html">Russian man pleads not guilty in US cyber espionage case</a> <em>(AOL Media LLC)</em></li><li><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions">UK and EU strike Russian cyber networks with new sanctions</a> <em>(Foreign, Commonwealth &amp; Development Office)</em></li><li><a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/">Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension</a> <em>(Stripe OLT)</em></li><li><a href="https://socket.dev/blog/jscrambler-supply-chain-attack">jscrambler npm Package Compromised in Supply Chain Attack</a> <em>(Socket)</em></li><li><a href="https://www.cyber.gc.ca/en/news-events/sharpviewstateking-stealthy-implant-framework">SharpViewStateKing: The stealthy implant framework - Canadian Centre for Cyber Security</a> <em>(Canadian Centre for Cyber Security)</em></li><li><a href="https://github.com/penberg/chimera">chimera: Sandbox untrusted code with safe access to the host.</a> <em>(Pekka Enberg)</em></li><li><a href="https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident">Lessons from CISA’s Cyber Incident</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-15.mp3" length="4082251" type="audio/mpeg"/>
      <itunes:duration>4:15</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-14.html</link>
      <pubDate>Tue, 14 Jul 2026 06:08:11 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260714_060811</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.lexfo.fr/opendir-to-phishing-operator.html">One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators</a> <em>(Ambionics)</em></li><li><a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/">How WP-SHELLSTORM Exposed 1.4M WordPress Sites</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html?unlocked_article_code=1.xFA.a_dB.AaB0wEs-NI-X&referringSource=articleShare">How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist</a> <em>(The New York Times)</em></li><li><a href="https://www.asahi.com/sp/ajw/articles/16703618">Teen accused of using ChatGPT to delete 46,000 anime accounts</a> <em>(The Asahi Shimbun Company)</em></li><li><a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification">Unfit to Boot: Breaking U-Boot's FIT Signature Verification</a> <em>(Binarly)</em></li><li><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/">Patch Release Update: Zimbra 10.1.19 - 'security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened'</a> <em>(Synacor)</em></li><li><a href="https://www.synacktiv.com/en/publications/the-sql-server-unicode-problem-why-your-data-might-not-be-what-you-think-it-is">The SQL Server Unicode problem: why your data might not be what you</a> <em>(Synacktiv)</em></li><li><a href="https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency">Man Serving Federal Prison Sentence Charged with Theft of Forfeited Cryptocurrency</a> <em>(United States Department of Justice)</em></li><li><a href="https://x.com/i/status/2075606692335956016">AnyDesk forensic artefacts</a> <em>(Ayush Anand)</em></li><li><a href="https://cloudbrothers.info/en/unified-sign-logs-advanced-hunting/">Use Unified Sign-In logs in Advanced Hunting</a> <em>(Fabian Bader)</em></li><li><a href="https://specterops.io/blog/2026/07/09/finding-socks-with-proxywatch/">Finding SOCKS with Proxywatch</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/0x4D31/stinger">stinger: Unprivileged endpoint deception for macOS and Linux workstations. Uses FIFO baits, other local traps, and protected sessions to detect secret collection as it happens.</a> <em>(0x4D31)</em></li><li><a href="https://msendpointmgr.com/2026/07/03/epm-part-3-writing-intune-endpoint-privilege-management-rules-for-the-real-world-file-hash-certificate-and-when-each-one-is-the-wrong-choice/">EPM Part 3: Writing Intune Endpoint Privilege Management rules for the real world: File hash, certificate, and when each one is the wrong choice - MSEndpointMgr</a> <em>(MSEndpointMgr)</em></li><li><a href="https://gist.github.com/AlloySecureGroup/5062355dc48f1e333223f0dda90e7cda">Scheme Hunter - Enumerate URI schemes and prototype invocation - WDAC / AppLocker Bypass Recon Scripts</a> <em>(AlloySecureGroup)</em></li><li><a href="https://github.com/ssteelfactor-oss/Kestrel">Kestrel: Passive Active Directory security enumeration via native ADSI/COM interfaces.</a> <em>(ssteelfactor-oss)</em></li><li><a href="https://github.com/ail-project/tempolocus">tempolocus: Tempolocus is a time-series activity patterns and approximate location inference</a> <em>(CIRCL)</em></li><li><a href="https://trainsec.net/library/windows-internals/how-windows-app-execution-aliases-work-and-how-to-read-them-in-c/">How Windows App Execution Aliases Work (and How to Read Them in C++)</a> <em>(Pavel Yosifovich)</em></li><li><a href="https://trustedsec.com/blog/jq-for-hackers">JQ for Hackers</a> <em>(TrustedSec)</em></li><li><a href="https://github.com/IceCubeSandwich/CaddySmith">CaddySmith: Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.</a> <em>(IceCubeSandwich)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-14.mp3" length="7672520" type="audio/mpeg"/>
      <itunes:duration>7:59</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-13.html</link>
      <pubDate>Mon, 13 Jul 2026 06:04:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260713_060450</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://intel.webamon.com/blog/tracking-a-k8-branded-web-cluster/">Tracking a K8-Branded Web Cluster Across 10,156 Domains</a> <em>(Webamon)</em></li><li><a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand">GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses</a> <em>(Broadcom)</em></li><li><a href="https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/">Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)</a> <em>(AmberWolf)</em></li><li><a href="https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation">RedWing: A Mobile Malware-as-a-Service Operation</a> <em>(Zimperium)</em></li><li><a href="https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor/">nodemon-sudo: an npm Backdoor With No Install Script</a> <em>(SafeDep)</em></li><li><a href="https://medium.com/@omgAPT/adversarial-intelligence-local-llms-for-automated-attacks-3bf684c51544">Adversarial Intelligence: Local LLMs for Automated Attacks</a> <em>(Mike Scutt)</em></li><li><a href="https://jakeotte.com/posts/klist-revisited.html">klist.exe Revisited: Internals and Further Use Cases</a> <em>(Jake Otte)</em></li><li><a href="https://github.com/Chaelsoo/nimcrypt">nimcrypt: Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.</a> <em>(Chaelsoo)</em></li><li><a href="https://github.com/jakeotte/klist2ccache">klist2ccache: Dump TGTs remotely and convert Windows' klist binary output to ccache.</a> <em>(jakeotte)</em></li><li><a href="https://github.com/bkerler/ida_rpc">ida_rpc: IDA Pro RPC for assisted RE-tasks</a> <em>(B.Kerler)</em></li><li><a href="https://arxiv.org/abs/2607.05916">Beyond the Syntax: Do Security Experts Trust LLMs for NIDS Rule Engineering?</a> <em>(arXiv)</em></li><li><a href="https://github.com/Corgea/Sighthound/">Sighthound: rule-based SAST scanner</a> <em>(Corgea)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-13.mp3" length="4945755" type="audio/mpeg"/>
      <itunes:duration>5:09</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-12.html</link>
      <pubDate>Sun, 12 Jul 2026 06:02:13 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260712_060213</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.extrahop.com/blog/anatomy-of-an-attack-darkspectre">DarkSpectre — a Chinese state-sponsored threat actor, maintains persistent access to enterprise environments by weaponizing legitimate browser extensions after establishing a trusted user</a> <em>(ExtraHop)</em></li><li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms">Large-scale exploitation campaign targeting website content management systems (CMS)</a> <em>(Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC))</em></li><li><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/10/nederland-doelwit-van-russische-spionageoperatie-via-ip-cameras">Nederland doelwit van Russische spionageoperatie via IP-camera’s | The Netherlands targeted by Russian espionage operation via IP cameras</a> <em>(Rijksoverheid)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-12.mp3" length="1841990" type="audio/mpeg"/>
      <itunes:duration>1:55</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-11.html</link>
      <pubDate>Sat, 11 Jul 2026 06:05:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260711_060550</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/">One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement</a> <em>(SentinelOne)</em></li><li><a href="https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network">Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories</a> <em>(Socket)</em></li><li><a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html">Onderzoek naar hack Odido wijst op mogelijke betrokkenheid Nederlanders | Investigation into Odido hack points to possible involvement of the Dutch</a> <em>(Politie Nederland)</em></li><li><a href="https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/">Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor</a> <em>(Datadog)</em></li><li><a href="https://opensourcemalware.com/blog/cybersecurity-startup-publishes-infostealers-to-npm">Cybersecurity Startup Publishes Infostealers to NPM</a> <em>(Paul McCarty)</em></li><li><a href="https://github.com/V4bel/Januscape">Januscape: Guest-to-Host Escape in KVM/x86</a> <em>(Hyunwoo Kim)</em></li><li><a href="https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions">XRING: Crashing XQUIC with spec-compliant QPACK instructions</a> <em>(FoxIO)</em></li><li><a href="https://zwclose.github.io/2026/07/08/rtsper2.html">Vulnerabilities of Realtek SD card reader driver, part2</a> <em>(zwclose)</em></li><li><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware">CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware</a> <em>(Huntress)</em></li><li><a href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps">Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps</a> <em>(Socket)</em></li><li><a href="https://sites.google.com/view/agentic-botnets/home">Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting</a> <em>(Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/">GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware</a> <em>(Microsoft)</em></li><li><a href="https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/">Random Windows Things Part 1: PreviousMode Mitigation</a> <em>(Winsider Seminars &amp; Solutions Inc.)</em></li><li><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">Evolving Windows vulnerability management to meet the speed of AI-powered discovery</a> <em>(Microsoft)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-11.mp3" length="5545944" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-10.html</link>
      <pubDate>Fri, 10 Jul 2026 06:02:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260710_060227</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cotool.ai/research">AI Research in Security Operations Pushing the frontier of AI agents for real security work</a> <em>(Cotool)</em></li><li><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/">Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed - or written another way AI slower than most ransomware crews</a> <em>(Sygnia)</em></li><li><a href="https://sensepost.com/blog/2026/process-parameter-poisoning/">Process Parameter Poisoning</a> <em>(Orange Cyberdefense)</em></li><li><a href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/">GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos</a> <em>(Noma Labs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-10.mp3" length="2155459" type="audio/mpeg"/>
      <itunes:duration>2:14</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-09.html</link>
      <pubDate>Thu, 09 Jul 2026 06:04:15 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260709_060415</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.mjib.gov.tw/news/Details/1/1196">The Investigation Bureau has cracked a case involving the Chinese Communist Party's cyber army, which impersonated international journalists to conduct social engineering attacks</a> <em>(Ministry of Justice Investigation Bureau)</em></li><li><a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/">Cavern Manticore: Exposing Iran-Linked Modular C2 Framework</a> <em>(Check Point Research)</em></li><li><a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16937">The National Police have arrested a suspected collaborator of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest.</a> <em>(Dirección General de la Policía)</em></li><li><a href="https://blog.talosintelligence.com/uat-7810/">UAT-7810 continues building ORB networks using new malware</a> <em>(Cisco Systems, Inc.)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation">One Email Closer to the Edge: UNK_MassTraction &amp; the Physics of Exploitation</a> <em>(Proofpoint)</em></li><li><a href="https://github.com/AlloySecureGroup/PhantomFS">PhantomFS: PhantomFS is a Windows honeypot that projects convincing decoy files — credentials, financials, SSH keys — into a virtual directory via ProjFS, then fires instant Event Log</a> <em>(Alloy Secure)</em></li><li><a href="https://www.semperis.com/blog/windows-privilege-abuse-can-lead-to-active-directory-compromise/">Windows Privilege Abuse: Attackers' Path to Active Directory Compromise</a> <em>(Semperis)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/">Recovering Active ADFS Signing Keys via Machine DPAPI | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://github.com/SmtimesIWndr/gdid-reversal">Full writeup of the Windows GDID - Global Device Identifier fully reverse engineered</a> <em>(SmtimesIWndr)</em></li><li><a href="https://github.com/SmtimesIWndr/GDID-Disabler/">GDID Disabler - Windows</a> <em>(SmtimesIWndr)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-09.mp3" length="3977761" type="audio/mpeg"/>
      <itunes:duration>4:08</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-08.html</link>
      <pubDate>Wed, 08 Jul 2026 06:01:44 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260708_060144</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://rastamouse.me/cpl-hook-chains/">Hook Chains (how I built Crystal Kit incorrectly*)</a> <em>(Rasta Mouse)</em></li><li><a href="https://github.com/secdev02/EasyTokens">EasyTokens: Kali365 - EvilTokens Replica</a> <em>(Casey Smith)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-08.mp3" length="1308256" type="audio/mpeg"/>
      <itunes:duration>1:21</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-07.html</link>
      <pubDate>Tue, 07 Jul 2026 06:07:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260707_060746</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>17</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.trendmicro.com/en_us/research/26/f/tonresolver.html">TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry</a> <em>(Trend Micro)</em></li><li><a href="https://sapirxfed.com/2026/07/05/does-anyone-even-use-github-for-federated-authentication/">Does anyone even use GitHub for federated authentication?</a> <em>(Sapir)</em></li><li><a href="https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168">Multiple Local Privilege Escalation Vulnerabilities in Little Orbit GFAC Driver (GFAC_Sys_x64.sys)</a> <em>(FzRsLLaSheR)</em></li><li><a href="https://dl.acm.org/doi/10.1145/3779208.3785387">Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</a> <em>(Association for Computing Machinery (ACM))</em></li><li><a href="https://practicalsecurityanalytics.com/improved-rpcghosting/">Improved RpcGhosting</a> <em>(Practical Security Analytics)</em></li><li><a href="https://securitylog.sva.de/2026/offsec/escalating-from-on-prem-to-entra-through-mitm-attacks/">Escalating from On-prem to Entra through MITM Attacks</a> <em>(SVA System Vertrieb Alexander GmbH)</em></li><li><a href="https://www.synacktiv.com/en/publications/exploring-cross-domain-cross-forest-rbcd-part-2">Exploring cross-domain &amp; cross-forest RBCD: part 2</a> <em>(Synacktiv)</em></li><li><a href="https://safedep.io/marketfront-dependency-confusion-campaign/">@marketfront: 25 npm Packages Reuse a Known Lure</a> <em>(Safedep)</em></li><li><a href="https://dmpdump.github.io/posts/Backdoor_iKuai_Routers/">Linux Backdoor Targeting iKuai Routers</a> <em>(dmpdump)</em></li><li><a href="https://github.com/iss4cf0ng/NebulaPulsar">NebulaPulsar: NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of the Alien project.</a> <em>(iss4cf0ng)</em></li><li><a href="https://github.com/CodeXTF2/GeoLocation_BOF">GeoLocation_BOF: Cobalt Strike BOF to obtain location data</a> <em>(CodeXTF2)</em></li><li><a href="https://justruss.tech/index.php/2026/06/21/hunting-sleeping-giants-detecting-encrypted-beacon-sleep-obfuscation/">Hunting Sleeping Giants: Detecting Encrypted Beacon Sleep Obfuscation</a> <em>(Russell Allen)</em></li><li><a href="https://github.com/pIat0n/BareMetal-RAM-Dumper">BareMetal-RAM-Dumper: A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.</a> <em>(pIat0n)</em></li><li><a href="https://github.com/kernelstub/Nox">Nox: Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning.</a> <em>(kernelstub)</em></li><li><a href="https://github.com/elder-plinius/T3MP3ST">T3MP3ST: autonomous red teaming platform; multi-agent offensive-security meta-harness</a> <em>(elder-plinius)</em></li><li><a href="https://www.zetter-zeroday.com/arrest-of-iranian-hacker-spotlights-irans-movement-into-economic-espionage-and-ip-theft/">Arrest of Iranian Hacker Spotlights Iran’s Movement into Economic Espionage and IP Theft</a> <em>(Kim Zetter)</em></li><li><a href="https://blog.synapticsystems.de/inside-kimsukys-chm-tradecraft-multi-stage-execution-and-selective-payload-delivery/">Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery</a> <em>(Synaptic Systems)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-07.mp3" length="6969931" type="audio/mpeg"/>
      <itunes:duration>7:15</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-06.html</link>
      <pubDate>Mon, 06 Jul 2026 06:07:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260706_060727</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>21</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc">Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public</a> <em>(GreyNoise, Inc.)</em></li><li><a href="https://securelist.com/the-gentlemen-raas/120447/">The Gentlemen RaaS: rapid growth and a new ransomware variant</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://sigreturn.com/blog/rhysida-analysis-decryption/">How I broke Rhysida ransomware encryption</a> <em>(Sigreturn Labs)</em></li><li><a href="https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/">From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks</a> <em>(Arctic Wolf)</em></li><li><a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/">Armored Likho's new weapon: BusySnake Stealer - "tied to a previously unknown APT group that we dubbed Armored Likho (also known as Eagle Werewolf based on circumstantial evidence)."</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://lab52.io/blog/gru-military-unit-67606/">GRU: military unit 67606</a> <em>(S2 Grupo)</em></li><li><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023">WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication -</a> <em>(WatchGuard Technologies)</em></li><li><a href="https://infosecwriteups.com/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9-1-10-cvss-8-8-high-e4bf33e67e82">Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High (CVE-2026–10525)</a> <em>(Sai Krishna Kothapalli)</em></li><li><a href="https://github.com/J-jaeyoung/bad-epoll">Bad Epoll: The bug missed by Mythos</a> <em>(Jaeyoung Chung)</em></li><li><a href="https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families">Fake Google and Cloudflare verification pages spread multiple malware families</a> <em>(Malwarebytes)</em></li><li><a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/">PamStealer: macOS Malware Posing as Clipboard Manager App</a> <em>(Jamf)</em></li><li><a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/">FBI Seizes NetNut Proxy Platform, Popa Botnet</a> <em>(Brian Krebs)</em></li><li><a href="https://detect.fyi/the-blind-spot-in-the-watchtower-detections-for-when-someone-attacks-your-sentinel-897709f0dcd9">The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel</a> <em>(Alex Teixeira)</em></li><li><a href="https://www.praetorian.com/blog/knossos-decoy-environments/">Knossos: Procedurally Generated Decoy Environments</a> <em>(Praetorian)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/building-more-resilient-cni-what-industry-pen-testers-told-us">Building more resilient CNI: what industry penetration testers told us</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://bishopfox.com/blog/on-favicons-from-browser-icons-to-attack-surface-intelligence">On Favicons: From Browser Icons to Attack Surface Intelligence</a> <em>(Bishop Fox)</em></li><li><a href="https://github.com/CodeXTF2/OpenUDC2">OpenUDC2: This is an open source implementation of the UDC2 spec used in Cobalt Strike</a> <em>(CodeXTF2)</em></li><li><a href="https://github.com/qmadev/tf-mythic-azure">tf-mythic-azure: Automatically deploying Mythic C2 in Azure using Terraform</a> <em>(qmadev)</em></li><li><a href="https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/">Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs</a> <em>(Expel)</em></li><li><a href="https://labs.k7computing.com/index.php/boss-scam-dont-trust-every-urgent-message-from-your-boss/">Boss Scam: Don’t Trust Every “Urgent” Message from Your Boss! - "It runs in the background till it finds an active WhatsApp Web session in Chromium-based browsers"</a> <em>(K7 Labs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-06.mp3" length="8789725" type="audio/mpeg"/>
      <itunes:duration>9:09</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-05.html</link>
      <pubDate>Sun, 05 Jul 2026 06:02:26 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260705_060226</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/">Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab</a> <em>(The Citizen Lab)</em></li><li><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/">Accelerating EDR Evasion with LLM-Driven Analysis</a> <em>(SpecterOps)</em></li><li><a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/">ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365</a> <em>(Cisco Talos)</em></li><li><a href="https://github.com/ZakiPedio/GadgetSniper">GadgetSniper: Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler</a> <em>(ZakiPedio)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-05.mp3" length="2209794" type="audio/mpeg"/>
      <itunes:duration>2:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-04.html</link>
      <pubDate>Sat, 04 Jul 2026 06:03:17 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260704_060317</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands">PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems</a> <em>(Socket)</em></li><li><a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat">Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool</a> <em>(Recorded Future)</em></li><li><a href="https://discuss.elastic.co/t/kibana-7-17-15-8-11-1-security-update-esa-2026-53/387449">Kibana 7.17.15, 8.11.1 Security Update (ESA-2026-53) - Improper Output Neutralization for Logs in Kibana can lead to log injection via Log Injection-Tampering-Forging</a> <em>(Elastic)</em></li><li><a href="https://github.com/JVBotelho/skewrun">skewrun: Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.</a> <em>(JVBotelho)</em></li><li><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/dont-pay-the-ransom-warning-to-organisations-to-protect-themselves-from-ransomware-attacks-as-more-than-320-businesses-affected-last-year/">Don’t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year</a> <em>(City of London Police)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-04.mp3" length="2356497" type="audio/mpeg"/>
      <itunes:duration>2:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-03.html</link>
      <pubDate>Fri, 03 Jul 2026 06:05:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260703_060522</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/">How the ToddyCat APT group gains access to Gmail accounts</a> <em>(Kaspersky Lab)</em></li><li><a href="https://research.jfrog.com/post/rollup-polyfill-masquerading/">Lazarus-Linked npm Malware Masquerades as Rollup Polyfills</a> <em>(JFrog)</em></li><li><a href="https://nsfocusglobal.com/ai-security-incident-case-miasma-worm-attacked-microsoft-github/">AI Security Incident Case: Miasma Worm Attacked Microsoft GitHub</a> <em>(NSFOCUS)</em></li><li><a href="https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">JADEPUFFER: Agentic ransomware for automated database extortion</a> <em>(Sysdig)</em></li><li><a href="https://github.com/RedByte1337/CredSpy">CredSpy: Entra ID user enumeration and auth method discovery via the public GetCredentialType API</a> <em>(Keanu Nys)</em></li><li><a href="https://www.esentire.com/blog/fortinet-vulnerability-cve-2026-35616-and-ekz-stealer-attacking-obfuscating-compilers-with-binary-ninja-workflows">Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers with Binary Ninja Workflows</a> <em>(eSentire, Inc.)</em></li><li><a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/">ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365</a> <em>(Cisco Talos)</em></li><li><a href="https://www.extrahop.com/blog/vipertunnel">Anatomy of an Attack: VIPERTUNNEL</a> <em>(ExtraHop)</em></li><li><a href="https://github.com/Chaelsoo/Hollow">Hollow: hollow is a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.</a> <em>(Chaelsoo)</em></li><li><a href="https://github.com/NirvanaOn/SpotifyC2/">SpotifyC2: SpotifyC2 is a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery</a> <em>(NirvanaOn)</em></li><li><a href="https://blog.xlab.qianxin.com/rustduck-en/">RustDuck: An In-Depth Analysis of a Two-Stage Botnet</a> <em>(Qianxin XLAB)</em></li><li><a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited">Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States</a> <em>(United States Department of Justice)</em></li><li><a href="https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/">A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain</a> <em>(Blackpoint Cyber)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-03.mp3" length="5550124" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-02.html</link>
      <pubDate>Thu, 02 Jul 2026 06:01:37 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260702_060137</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li>The Morris Worm: When a Graduate Student Broke the Internet <em>(Historical Archive)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-02.mp3" length="1026551" type="audio/mpeg"/>
      <itunes:duration>1:04</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-01.html</link>
      <pubDate>Wed, 01 Jul 2026 06:05:24 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260701_060524</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/">Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON</a> <em>(Acronis)</em></li><li><a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/">SOCRadar has attributed FortiBleed to the Lynx / INC ransomware group</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira - The DFIR Report</a> <em>(The DFIR Report)</em></li><li><a href="https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/">Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer</a> <em>(JFrog)</em></li><li><a href="https://www.darknavy.org/blog/the_biometric_authtoken_heist/">The Biometric AuthToken Heist: Cracking PINs and Bypassing CE via a Long-Ignored Attack Surface (Android)</a> <em>(DARKNAVY)</em></li><li><a href="https://github.com/douglasmun/pagecache-lpe-containment-kit">pagecache-lpe-containment-kit: defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation</a> <em>(Douglas Mun)</em></li><li><a href="https://github.com/sgkdev/ipv6_frag_escape">ipv6_frag_escape: Linux LPE - Reliable Jail/Container Escape</a> <em>(sgkdev)</em></li><li><a href="https://practicalsecurityanalytics.com/dumping-lsass-without-touching-disk-improvements-to-shadowdumper/">Dumping LSASS Without Touching Disk: Improvements to ShadowDumper</a> <em>(Practical Security Analytics LLC)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/hypervisor-cheats-part-2-ept-npt-split-views-and-second-stage-fault-evidence/">About Hypervisor Cheats, Part 2: EPT/NPT, Split Views, and Second-Stage Fault Evidence</a> <em>(Kernullist)</em></li><li><a href="https://www.nextron-systems.com/2026/06/26/anatomy-of-a-whql-signed-windows-filtering-platform-wfp-kernel-resident-network-backdoor/">Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor</a> <em>(www.nextron-systems.com)</em></li><li><a href="https://notpayloads.blob.core.windows.net/slides/Azure_PrivEsc_Troopers-2026.pdf">Modern Adventures in Azure 
Privilege Escalation</a> <em>(NetSPI)</em></li><li><a href="https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/">Mark-of-the-Web: the rules changed, the tools didn’t</a> <em>(Maxim Suhanov)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-01.mp3" length="4919841" type="audio/mpeg"/>
      <itunes:duration>5:07</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-30.html</link>
      <pubDate>Tue, 30 Jun 2026 06:05:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260630_060516</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.youtube.com/watch?v=-ueCcEdDjOM">Understanding Trends &amp; Patterns In Insider Threat: Analysis Of 1,000+ Cases</a> <em>(Jawed Karim)</em></li><li><a href="https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/">Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment</a> <em>(Seqrite)</em></li><li><a href="https://censys.com/blog/asyncrat-family-threat-overview/">AsyncRAT Family Threat Overview</a> <em>(Censys)</em></li><li><a href="https://www.goblinloot.net/2026/06/adversaries-in-proxmox.html">Proxmox and Adversaries</a> <em>(ZombieLucy)</em></li><li><a href="https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/">Control who and what triggers GitHub Actions workflows - GitHub Changelog</a> <em>(GitHub)</em></li><li><a href="https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf">Inside StegoAd: How a Threat Actor Evolved to Fuel Silent Ad Fraud and Credential Theft at Scale</a> <em>(Orenda Security LLC)</em></li><li><a href="https://www.fortinet.com/blog/threat-research/from-ci-cd-to-cloud-data-how-shai-hulud-persistence-leads-to-redshift-breach">From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach</a> <em>(Fortinet, Inc.)</em></li><li><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html">CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus</a> <em>(ManageEngine)</em></li><li><a href="https://github.com/licitrasimone/CrystalSliver">CrystalSliver: Crystal Palace Evasion kit for Sliver</a> <em>(Simone Licitra)</em></li><li><a href="https://github.com/28Zaaky/khaos-c2">khaos-c2: KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.</a> <em>(28Zaaky)</em></li><li><a href="https://specterops.io/blog/2026/06/26/time-travel-debugging-with-codex/">Time Travel Debugging with Codex</a> <em>(SpecterOps)</em></li><li><a href="https://blog.zsec.uk/harnessing-harnesses/">Harnessing Harnesses - Climbing the LLM Hills</a> <em>(ZephrSec)</em></li><li><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">Customer &amp; Partner Updates: Remote Code Execution Vulnerability in PTC’s Windchill and FlexPLM Solutions | June 2026 | PTC</a> <em>(PTC)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-30.mp3" length="6060870" type="audio/mpeg"/>
      <itunes:duration>6:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-29.html</link>
      <pubDate>Mon, 29 Jun 2026 06:03:36 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260629_060336</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>8</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ic3.gov/PSA/2026/PSA260626">Internet Crime Complaint Center (IC3) | Russian Intelligence Services Continue to Target Commercial Messaging Applications</a> <em>(Internet Crime Complaint Center (IC3))</em></li><li><a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/">LOTSを活用して進化を続けるKimJongRAT – KimJongRAT continues to evolve by utilizing LOTS</a> <em>(Internet Initiative Japan Inc. (IIJ))</em></li><li><a href="https://github.com/cloudflare/security-audit-skill">security-audit-skill: A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings</a> <em>(Cloudflare)</em></li><li><a href="https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/">a CVE dispute</a> <em>(Daniel Stenberg)</em></li><li><a href="https://github.com/hawktrace/CVE-2026-45504/">CVE-2026-45504: CVE-2026-45504 Microsoft Exchange File Read -  allows an authenticated low-privileged user to read arbitrary local files from the Exchange server by creating an EWS ReferenceAttachment</a> <em>(Hawktrace)</em></li><li><a href="https://github.com/sbousseaden/gluegate">gluegate: Memory API proxy via signed mozglue.dll - Detection research PoC: proxy memory operations (memory mapping, local memory allocation) through Mozilla's signed mozglue.dll</a> <em>(sbousseaden)</em></li><li><a href="https://blog.otterpwn.com/projects/heavener">heavener: This is what happens when you can't afford EDR licenses</a> <em>(Otter)</em></li><li><a href="https://bl4ckarch.github.io/posts/One-Bool.-Six-Shells.-AMSI's-Design-Problem/">One Bool. Six Shells. AMSI’s Design Problem.</a> <em>(Evariste (bl4ckarch))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-29.mp3" length="3796785" type="audio/mpeg"/>
      <itunes:duration>3:57</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-28.html</link>
      <pubDate>Sun, 28 Jun 2026 06:01:40 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260628_060140</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/788-nca-report-cyber-prevent-reoffending/file">Cyber Prevent: A descriptive evaluation of cohort reoffending</a> <em>(National Crime Agency)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-28.mp3" length="837216" type="audio/mpeg"/>
      <itunes:duration>0:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-27.html</link>
      <pubDate>Sat, 27 Jun 2026 06:11:38 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260627_061138</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>29</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-solution">Using SASE in a Modern TIC 3.0 Solution</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://t.me/SBUkr/17916?embed=1&mode=tme">SBU and FBI exposed Russian special services in systematic attempts to "hack" messengers of officials in Ukraine, Europe and the USA</a> <em>(Служба безпеки України)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/">Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances</a> <em>(ESET)</em></li><li><a href="https://blog.synapticsystems.de/from-winrar-ads-to-reflective-loading-reversing-a-new-uac-0226-giftedcrook-chain/">Tracking UAC-0226 Tooling Evolution: From WinRAR ADS to Reflective GIFTEDCROOK Loading</a> <em>(Robin Dost)</em></li><li><a href="https://rewardsforjustice.net/rewards/unc5792/">UNC5792 – Rewards For Justice</a> <em>(U.S. Department of State)</em></li><li><a href="https://citizenlab.ca/research/russia-breaks-into-human-rights-activists-phone-with-cellebrite/">Russia Breaks Into Human Rights Activist's Phone With Cellebrite - The Citizen Lab</a> <em>(The Citizen Lab)</em></li><li><a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/">CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure</a> <em>(Palo Alto Networks)</em></li><li><a href="https://securelist.com/strikeshark-campaign/120326/">StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon</a> <em>(Kaspersky)</em></li><li><a href="https://mp.weixin.qq.com/s/jXkbq0oWxu4D5yH46TQybg">Analysis of APT-C-36's Recent Activities in Colombia</a> <em>(Intelligence-Group)</em></li><li><a href="https://www.cognyte.com/blog/lazarus-targets-the-financial-sector-with-memory-only-malware-toolset/">Lazarus Targets the Financial Sector with Memory-Only Malware Toolset</a> <em>(Cognyte Software Ltd.)</em></li><li><a href="https://www.sonatype.com/blog/miasma-returns-leo-platform-compromise-in-npm">Miasma Returns: Leo Platform Compromise in npm</a> <em>(Sonatype Security Research Team)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/">Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access</a> <em>(Microsoft)</em></li><li><a href="https://www.asio.gov.au/resources/speeches-and-statements/director-generals-annual-threat-assessment-2026">Director-General's Annual Threat Assessment 2026 - "We discovered nation state hackers had compromised the network of an Australian critical infrastructure provider."</a> <em>(Australian Security Intelligence Organisation)</em></li><li><a href="https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat">Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker</a> <em>(Broadcom)</em></li><li><a href="https://www.infoblox.com/blog/threat-intelligence/from-san-pedro-to-salinas-how-a-chinese-framework-dcloud-uni-app-powers-a-global-scam-economy/">DCloud Uni-App: One Framework, 236,000+ Scam Sites</a> <em>(Infoblox)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/">Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</a> <em>(Google Cloud (Mandiant))</em></li><li><a href="https://whereisk0shl.top/post/From%20context_handle%20to%20type%20confusion/">From context_handle to type confusion - A Type Confusion Vulnerability Pattern in Windows RPC Servers</a> <em>(Whereisk0Shl)</em></li><li><a href="https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action">codfish/semantic-release-action GitHub Action has been compromised</a> <em>(StepSecurity)</em></li><li><a href="https://darkatlas.io/blog/loaderclient-malware-analysis-how-weedhack-uses-ethereum-smart-contracts-for-resilient-c2-infrastructure">LoaderClient Malware Analysis: How WeedHack Uses Ethereum Smart Contracts for Resilient C2 Infrastructure</a> <em>(Buguard)</em></li><li><a href="https://www.threatray.com/blog/kuinaextractor-six-months-of-a-rust-infostealers-evolution">KuinaExtractor: Six Months of a Rust Infostealer's Evolution</a> <em>(Threatray)</em></li><li><a href="https://specterops.io/blog/2026/06/24/disposable-tooling-building-llm-generated-mythic-agents-from-prompt-to-deployment/">Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment</a> <em>(SpecterOps)</em></li><li><a href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/">Trust No One: Automating macOS Privilege Escalation at Scale</a> <em>(XM Cyber)</em></li><li><a href="https://0xmaz.me/posts/LACUNA-Chain-Ghost-Frames-defeats-All-EDR-layers-of-call-stack-based-detection/">LACUNA Chain: Ghost Frames — defeats all EDR layers of call-stack-based detection</a> <em>(Mohamed Alzhrani)</em></li><li><a href="https://whiteknightlabs.com/2026/06/15/harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion-part-3/">Harnessing the Power of Cobalt Strike Profiles for EDR Evasion</a> <em>(White Knight Labs)</em></li><li><a href="https://github.com/x86byte/Obfusk8/releases/tag/v1.5">Release Obfusk8 v1.5</a> <em>(x86byte)</em></li><li><a href="https://security.apple.com/bounty/target-flags/">Target Flags - Apple Security Research - "Target Flags are a new security research capability in Apple operating systems that make it easier to objectively demonstrate your findings"</a> <em>(Apple)</em></li><li><a href="https://detect.fyi/testing-ai-threat-hunting-against-real-world-kql-a-side-by-side-test-4cdda76a5772">Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test</a> <em>(Alex Teixeira)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/">The Latest Addition to Turla’s Intelligence Gathering Apparatus</a> <em>(Google)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-27.mp3" length="13148204" type="audio/mpeg"/>
      <itunes:duration>13:41</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-26.html</link>
      <pubDate>Fri, 26 Jun 2026 06:01:51 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260626_060151</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://open.substack.com/pub/nattothoughts/p/reconnaissance-scanning-tools-used?r=q9u24">Reconnaissance Scanning Tools Used by Chinese Threat Actors and Those Available in Open Source</a> <em>(Natto Team)</em></li><li><a href="https://github.com/youssefnoob003/SindriKit">SindriKit: A foundational C library for building operationally credible offensive capabilities</a> <em>(youssefnoob003)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-26.mp3" length="1440749" type="audio/mpeg"/>
      <itunes:duration>1:29</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-25.html</link>
      <pubDate>Thu, 25 Jun 2026 06:03:52 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260625_060352</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf">Dismantling Fortibleed: Inside a Russian Fortinet compromise operation</a> <em>(socradar.io)</em></li><li><a href="https://github.com/andreicscs/HoneyWire">HoneyWire: HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.</a> <em>(Andrea Termine)</em></li><li><a href="https://github.com/0xABCD01/CVE-2026-41089">CVE-2026-41089: CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - only a Denial of Service PoC not RCE</a> <em>(0xABCD01)</em></li><li><a href="https://labs.infoguard.ch/posts/ghost-sender/">Ghost-Sender - Universal Email Spoofing against Exchange Online</a> <em>(InfoGuard AG)</em></li><li><a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/">macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox</a> <em>(SentinelOne)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html">From Langflow to Monero: Inside CVE-2026-33017 Cryptominer</a> <em>(Trend Micro)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-25.mp3" length="2978003" type="audio/mpeg"/>
      <itunes:duration>3:06</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-24.html</link>
      <pubDate>Wed, 24 Jun 2026 06:05:49 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260624_060549</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure">CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices">Analysis of Reported Credential Compromise of FortiGate Devices</a> <em>(Fortinet, Inc.)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/">From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet</a> <em>(Microsoft)</em></li><li><a href="https://www.jamf.com/blog/klue-incident/">Klue Third-Party Cybersecurity Incident</a> <em>(Jamf)</em></li><li><a href="https://www.bbc.co.uk/news/articles/czx5yp9qy0do">Two men plead guilty over £39m Transport for London cyber attack</a> <em>(BBC)</em></li><li><a href="https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/">From PostCSS Masquerading to Windows RAT</a> <em>(JFrog)</em></li><li><a href="https://spur.us/blog/smart-tv-apps-residential-proxy-sdks">Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs</a> <em>(Spur Intelligence Labs)</em></li><li><a href="https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/">Bypassing Conditional Access policies that have a resource exclusion</a> <em>(Dirk-jan Mollema)</em></li><li><a href="https://aws.amazon.com/blogs/security/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads/">Prevent data exfiltration: AWS egress controls for cloud workloads | Amazon Web Services</a> <em>(Amazon Web Services)</em></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">Securing the Nation Against Advanced Cryptographic Attacks</a> <em>(The White House)</em></li><li><a href="https://squiblydoo.blog/2026/06/22/using-the-cert-graveyard/">Using the Cert Graveyard</a> <em>(Rogue Authority LLC)</em></li><li><a href="https://blog.synapticsystems.de/ghostshell-mb-0009-targeting-ukraines-uav-operations-and-defense-supply-chain/">GhostShell (MB-0009): Targeting Ukraine’s UAV Operations and Defense Supply Chain</a> <em>(Synaptic Systems)</em></li><li><a href="https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/">Security Update: Tanium’s Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium</a> <em>(Tanium)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-24.mp3" length="5551795" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-23.html</link>
      <pubDate>Tue, 23 Jun 2026 06:26:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260623_062627</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>22</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.bushidotoken.net/2026/06/uk-cybercrime-journal-sustained.html">UK Cybercrime Journal: Sustained DragonForce Campaign</a> <em>(BushidoToken)</em></li><li><a href="https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/">Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework</a> <em>(Sekoia.io)</em></li><li><a href="https://www.bridewell.com/insights/blogs/detail/the-booking.com-phishing-campaign-targeting-hotels-and-customers">The Booking.com Phishing Campaign Targeting Hotels and Customers</a> <em>(Bridewell)</em></li><li><a href="https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous">Mind the Gap: GCP serviceData in Logs Explorer vs. Exported Logs</a> <em>(Permiso Security)</em></li><li><a href="https://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection">Azure AD Graph Activity Logs: detecting directory enumeration</a> <em>(Elastic)</em></li><li><a href="https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/">Reduce Microsoft Sentinel Costs with Summary Rules</a> <em>(NVISO)</em></li><li><a href="https://www.nextron-systems.com/2026/06/19/oss-artifact-scanning-at-scale/">OSS Artifact Scanning at Scale Without Burning Your Token Budget</a> <em>(Nextron Systems)</em></li><li><a href="https://klue.com/blog/an-update-on-recent-klue-security-incident">An Update on the Recent Klue Security Incident - Klue</a> <em>(Klue)</em></li><li><a href="https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/">A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope</a> <em>(Snyk)</em></li><li><a href="https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind">Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind</a> <em>(CloudSEK)</em></li><li><a href="https://github.com/NirvanaOn/NOW">NOW: NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.</a> <em>(Nirvana)</em></li><li><a href="https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion/">GhostPack Necromancy: Reforging C# Tools with WasmForge</a> <em>(Praetorian)</em></li><li><a href="https://whiteknightlabs.com/2026/06/15/harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion-part-3/">Harnessing the Power of Cobalt Strike Profiles for EDR Evasion – Part 3</a> <em>(White Knight Labs)</em></li><li><a href="https://www.levelblue.com/blogs/spiderlabs-blog/rogueplanet-and-greatxml-detecting-local-privilege-escalation-and-bitlocker-security-boundary-abuse">RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse</a> <em>(LevelBlue)</em></li><li><a href="https://unit42.paloaltonetworks.com/large-scale-credential-attacks/">Threat Brief: Mitigating Large-Scale Credential Attacks</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.netskope.com/blog/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat">macOS ClickFix Lures Deploy AppleScript Stealer &amp; Persistent RAT</a> <em>(Netskope)</em></li><li><a href="https://github.com/OALabs/asftriage">asftriage: LLM Agent Session Forensics Tool - A forensic investigation tool for AI agent session logs (Claude Code and Codex CLI).</a> <em>(OA Labs)</em></li><li><a href="https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer">OXLOADER: new loader evading detection to drop infostealer</a> <em>(Elastic)</em></li><li><a href="https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf">Composer &amp; Packagist
Supply Chain Security in 2026</a> <em>(Nils Adermann)</em></li><li><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/man-jailed-for-role-in-sms-blaster-fraud-operation-following-city-of-london-police-investigation/">Man jailed for role in “SMS Blaster” fraud operation following City of London Police investigation</a> <em>(City of London Police)</em></li><li><a href="https://www.gendigital.com/blog/insights/research/inside-vidar-abe-bypass">Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections</a> <em>(Gen Digital)</em></li><li><a href="https://blog.talosintelligence.com/scripting-the-disassembler/">Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model</a> <em>(Cisco Talos)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-23.mp3" length="8066238" type="audio/mpeg"/>
      <itunes:duration>8:24</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-22.html</link>
      <pubDate>Mon, 22 Jun 2026 06:07:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260622_060745</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.graphistry.com/blog/fables-and-mythos-conceptions-the-defenders-perspective-with-receipts">Fable 5 Cybersecurity benchemark</a> <em>(Graphistry)</em></li><li><a href="https://safedep.io/astro-config-blockchain-c2-supply-chain/">astro.config.mjs Supply Chain Attack via Blockchain C2</a> <em>(SafeDep)</em></li><li><a href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html">Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies</a> <em>(OALABS)</em></li><li><a href="https://www.recordedfuture.com/blog/klue-security-incident">The Klue Security Incident and Its Impact on Recorded Future</a> <em>(Recorded Future)</em></li><li><a href="https://www.dell.com/support/kbdoc/en-uk/000453482/dsa-2026-197-security-update-for-dell-client-platform-bios-for-a-weak-encoding-for-password-vulnerability">DSA-2026-197: Security Update for Dell Client Platform BIOS for a Weak Encoding for Password Vulnerability</a> <em>(Dell Technologies)</em></li><li><a href="https://ps.tc/pages/blog-usbliter8.html">Introducing usbliter8: Apple iPhone A12/A13 SecureROM exploit</a> <em>(Paradigm Shift)</em></li><li><a href="https://blog.calif.io/p/squidbleed-cve-2026-47729">Squidbleed (CVE-2026-47729)</a> <em>(Calif.io)</em></li><li><a href="https://github.com/Print3M/MyTalks/blob/main/2026_06_x33fcon_Bring_Your_Own_Everything_-_The_Final_Approach.pdf">Bring Your Own Everything: Traitorware</a> <em>(Print3M)</em></li><li><a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/">More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers</a> <em>(QiAnXin XLab)</em></li><li><a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys">Multiple JetBrains IDE plugins caught stealing AI keys</a> <em>(Aikido)</em></li><li><a href="https://synthient.com/blog/popa-from-sourcing-to-distribution">Popa: From Sourcing to Distribution</a> <em>(Synthient)</em></li><li><a href="https://synthesis.to/presentations/recon26_agentic_deobfuscation.pdf">Deobfuscation in the Age of Agentic Reverse Engineering</a> <em>(Tim Blazytko and Nicolò Altamura)</em></li><li><a href="https://github.com/struppigel/hedgehog-tools/tree/main/ktrace">ktrace: Speakeasy-based Windows kernel-mode driver API tracer</a> <em>(struppigel)</em></li><li><a href="https://github.com/allthingsida/allthingsida/blob/main/presentations/select_from_binary_vibe_re/vibe_re_xsql.pdf">SELECT * FROM binary - Vibe Reversing Across IDA, Ghidra, and Binary Ninja</a> <em>(Elias Bachaalany)</em></li><li><a href="https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker/">From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker</a> <em>(Check Point Research)</em></li><li><a href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline">Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline – Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol</a> <em>(Europol)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-22.mp3" length="6651446" type="audio/mpeg"/>
      <itunes:duration>6:55</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-21.html</link>
      <pubDate>Sun, 21 Jun 2026 06:04:07 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260621_060407</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://book.yunzhan365.com/tkgd/knru/mobile/index.html">APT Organization Research Yearbook (2026 Edition)  - Chinese</a> <em>(绿盟科技、广州大学网络空间安全学院)</em></li><li><a href="https://www.huntress.com/blog/klue-breach-investigation">Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress</a> <em>(Huntress)</em></li><li><a href="https://www.ibm.com/think/x-force/operationalizing-browser-exploits-to-bypass-wdac">Operationalizing browser exploits to bypass Windows Defender Application Control (WDAC)</a> <em>(IBM)</em></li><li><a href="https://github.com/nmht3t/RawHive">RawHive: Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.</a> <em>(nmht3t)</em></li><li><a href="https://github.com/r3xmax/PhantomCtx">PhantomCtx: Activation Context Hijacking Evasion Tool</a> <em>(r3xmax)</em></li><li><a href="https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/">Using Slack links-preview to smuggle C2 in locked-down environments.</a> <em>(RWXstoned)</em></li><li><a href="https://github.com/RootUp/git-clean-filter">git-clean-filter: This is a proof-of-work for abusing git's clean filter against IDEs &amp; Sublime.</a> <em>(RootUp)</em></li><li><a href="https://www.ic3.gov/PSA/2026/PSA260618">Internet Crime Complaint Center (IC3) | Cyber Criminals Redirecting Users to Fraudulent Websites with Malicious Traffic Distribution Systems</a> <em>(Federal Bureau of Investigation (FBI))</em></li><li><a href="https://www.secm8.com/posts/contentops-detection-pipeline/">Building a Modern Detection Pipeline with ContentOps</a> <em>(Gianni Castaldi)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-21.mp3" length="4257376" type="audio/mpeg"/>
      <itunes:duration>4:26</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-20.html</link>
      <pubDate>Sat, 20 Jun 2026 06:02:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260620_060231</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html">International law enforcement initiate hunt on malware group SocGholish</a> <em>(Dutch police (Politie))</em></li><li><a href="https://github.com/0xHossam/UnCanny">UnCanny: Another new coercion primitive with LPE 0day - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution experiments</a> <em>(0xHossam)</em></li><li><a href="https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas">Bluekit Phishing as a Service (PhaaS)</a> <em>(CloudSEK)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/">Killing me gently: Inside Gentlemen’s EDR killer framework</a> <em>(ESET)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-20.mp3" length="2143338" type="audio/mpeg"/>
      <itunes:duration>2:13</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 19, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-19.html</link>
      <pubDate>Fri, 19 Jun 2026 06:05:39 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260619_060539</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.fct-cf.ca/Content/assets/pdf/base/2026-06-15-EN-Decision-C-6-24.pdf">Counsel for the AGC and the affiant described the Cyber Threat Reduction Measures Warrant as necessary to protect critical infrastructure from foreign adversaries that have infected certain SOHO IoT</a> <em>(Federal Court)</em></li><li><a href="https://dti.domaintools.com/research/threat-intelligence-report-russia-router-dns-and-messaging-layer-collection-operations">Threat Intelligence Report: Russia, Router, DNS, and Messaging-Layer Collection Operations</a> <em>(DomainTools)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research">Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://www.cloudsek.com/blog/operation-escaneo-mexican-government-financial-institutions-cyberattack">Operation Escaneo: Infrastructure Exposure, TTP Analysis, and Attribution Assessment of an Advanced Intrusion Campaign Against Mexican Federal Agencies and Financial Institutions | CloudSEK</a> <em>(CloudSEK)</em></li><li><a href="https://www.rapid7.com/blog/post/tr-malware-tracking-dropping-elephant-tradecraft-china-themed-loader-chain/">Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain</a> <em>(Rapid7)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508669&idx=1&sn=045cca89facb1bc6be4e565bc6fa09d8&chksm=f9c191b4ceb618a2363fb312de8c489722824e2b348586eeff078715e34b0d3e8c566bc42494&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">Analysis Report on Recent Phishing Attacks by the APT-C-48 (CNC) Group</a> <em>(奇安信威胁情报中心)</em></li><li><a href="https://www.hudsonrock.com/blog/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure">FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed – Claim Your Ethical Disclosure</a> <em>(Hudson Rock)</em></li><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ">Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability</a> <em>(Cisco Systems, Inc.)</em></li><li><a href="https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js">Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat</a> <em>(StepSecurity)</em></li><li><a href="https://asec.ahnlab.com/ko/94163/">정상 이력서처럼 보이지만 실행 순간 감염 시작 - It looks like a normal resume, but the infection starts the moment it is executed.</a> <em>(AhnLab)</em></li><li><a href="https://offsec.cypfer.com/blog/Honeypot-detection">Hunting Honey Pots as Red Teamers</a> <em>(CYPFER)</em></li><li><a href="https://dl.acm.org/doi/10.1145/3800506.3803487">VSMEx: A Collection Tool and a Dataset of Malicious VS Code Extensions: Data/Toolset Paper</a> <em>(Association for Computing Machinery)</em></li><li><a href="https://www.catonetworks.com/blog/cato-ctrl-operation-poisson-analyzing-a-cybercriminals-entire-operation/">Operation Poisson – Analyzing a Cybercriminal’s Entire Operation</a> <em>(Cato Networks)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-19.mp3" length="5543854" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-18.html</link>
      <pubDate>Thu, 18 Jun 2026 06:02:18 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260618_060218</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://jamestown.org/chinese-grid-operators-maintain-offensive-cyber-programs/">Chinese Grid Operators Maintain Offensive Cyber Programs - Jamestown</a> <em>(The Jamestown Foundation)</em></li><li><a href="https://socket.dev/blog/glasswasm-malware-open-vsx-extensions">GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions</a> <em>(Socket)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/">FishMonger’s arsenal upgraded: SprySOCKS for Windows</a> <em>(ESET)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-18.mp3" length="1943554" type="audio/mpeg"/>
      <itunes:duration>2:01</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-17.html</link>
      <pubDate>Wed, 17 Jun 2026 06:02:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260617_060222</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://hunt.io/blog/ababil-of-minab-iranian-hackers-exposed-la-metro-breach-open-directory">Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blog.bushidotoken.net/2026/06/ransomware-tool-matrix-project-updates.html">Ransomware Tool Matrix Project Updates: Three Groups To Track</a> <em>(BushidoUK)</em></li><li><a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026">SBOM Adoption State of Play - 2026 | ENISA</a> <em>(European Union Agency for Cybersecurity)</em></li><li><a href="https://github.com/Zypherion-Technologies/HallWatch">HallWatch: Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls &amp; Many more.</a> <em>(Adam Zypherion)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-17.mp3" length="2222333" type="audio/mpeg"/>
      <itunes:duration>2:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-16.html</link>
      <pubDate>Tue, 16 Jun 2026 06:06:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260616_060633</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://kmsec.uk/blog/dprk-google-docs/">Hunting North Korea's job adverts on Google Docs</a> <em>(Kieran Miyamoto)</em></li><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat">Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2</a> <em>(Genians)</em></li><li><a href="https://www.ndss-symposium.org/ndss-paper/actively-understanding-the-dynamics-and-risks-of-the-threat-intelligence-ecosystem/">Actively Understanding the Dynamics and Risks of the Threat Intelligence Ecosystem - NDSS Symposium</a> <em>(Internet Society)</em></li><li><a href="https://csrc.nist.gov/pubs/sp/800/126/r4/final">NIST Special Publication (SP) 800-126 Rev. 4, Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.4</a> <em>(National Institute of Standards and Technology (NIST))</em></li><li><a href="https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/">Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does</a> <em>(Guillaume Ross)</em></li><li><a href="https://aws.amazon.com/blogs/security/well-architected-best-practices-for-software-supply-chain-security/">Well-architected best practices for software supply chain security | Amazon Web Services</a> <em>(Amazon Web Services (AWS))</em></li><li><a href="https://mp.weixin.qq.com/s/EM0NQSITmCJ7syHxg5Ig-g">反入侵 Pipeline 2.0 (Agentic) -Anti-intrusion Pipeline 2.0 (Agentic) (Chinese)</a> <em>(奇安信攻防社区)</em></li><li><a href="https://arxiv.org/abs/2605.17380">ADR: An Agentic Detection System for Enterprise Agentic AI Security</a> <em>(Uber Technologies, Inc.)</em></li><li><a href="https://sha0coder.github.io/scales/">Scales — carving an embedded eBPF rootkit</a> <em>(jolmos)</em></li><li><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster supply chain attack hits 1.2 million sites</a> <em>(Sansec)</em></li><li><a href="https://aretiq.ai/research/vul260531-cve-2026-45454-microsoft-sharepoint-server-upload-page-folder-path-traversal/">CVE-2026-45454 — Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution</a> <em>(Aretiq AI)</em></li><li><a href="https://arxiv.org/abs/2604.04805">Unpacking .zip: A First Look at Domain and File Name Confusion</a> <em>(Oregon State University, Georgia Institute of Technology)</em></li><li><a href="https://mp.weixin.qq.com/s/ynnTKDpktqgX-XDpVJOLyw">After applying AI to perform a deep audit of ActiveMQ patches, two new high-risk vulnerabilities were discovered (Chinese)</a> <em>(腾讯安全应急响应中心)</em></li><li><a href="https://www.sygnia.co/blog/operation-highland-velvet-ant/">Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected</a> <em>(Sygnia)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-16.mp3" length="6100158" type="audio/mpeg"/>
      <itunes:duration>6:21</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-15.html</link>
      <pubDate>Mon, 15 Jun 2026 06:05:57 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260615_060557</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/threathunters-io/tracebit_x33fcon_2026">tracebit_x33fcon_2026: a POC sensor aiming to fingerprint implants in memory using only lowlevel runtime telemetry.</a> <em>(ThreatHunting.io)</em></li><li><a href="https://github.com/0xjbb/ModuleStomped">ModuleStomped: Proof of concept to detect module stomping detection by looking for modified .pdata sections.</a> <em>(0xjbb)</em></li><li><a href="https://blog.helsing.ai/posts/trusting-trust-bootstrapping-nix-from-source/">Trusting trust - building Nix from a manually verified seed</a> <em>(Helsing)</em></li><li><a href="https://github.com/sbousseaden/EDRUnChoker">EDRUnChoker: EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies</a> <em>(sbousseaden)</em></li><li><a href="https://trustedsec.com/blog/hardening-intune-the-implementation-guide">Hardening Intune: The Implementation Guide</a> <em>(TrustedSec, LLC)</em></li><li><a href="https://github.com/e-fin/ADWS-BOF">ADWS-BOF: Beacon Object File for LDAP Queries Through ADWS</a> <em>(Ethan)</em></li><li><a href="https://github.com/ar0x4/tunnel-vision-toolkit">tunnel-vision-toolkit: Offensive security toolkit for Microsoft Global Secure Access (GSA), Microsoft's Zero Trust Network Access (ZTNA) solution.</a> <em>(Arshia Reisi)</em></li><li><a href="https://www.varonis.com/blog/openclaw-phishing">Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets</a> <em>(Varonis)</em></li><li><a href="https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/">Roughly 400 AUR (Arch User Repository) packages compromised</a> <em>(Arch Linux)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit">ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog</a> <em>(Google Cloud)</em></li><li><a href="https://github.com/HexRaysSA/rax">rax: rax is a CPU emulator that does not trust itself.</a> <em>(Hex-Rays SA)</em></li><li><a href="https://github.com/atomiczsec/Noradrenaline">Noradrenaline: Offensive macOS and Linux shared library modules for Poseidon and other agent frameworks. Designed to be small and quick for automation.</a> <em>(atomiczsec)</em></li><li><a href="https://ioctl.fail/preliminary-analysis-of-aur-malware/">Preliminary analysis of AUR malware</a> <em>(Codex)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/covert-kernel-user-communication-channels-on-windows/">Covert Kernel/User Communication Channels on Windows: Rootkits, Game Cheats, and Detection</a> <em>(kernullist)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-15.mp3" length="6095978" type="audio/mpeg"/>
      <itunes:duration>6:20</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-14.html</link>
      <pubDate>Sun, 14 Jun 2026 06:02:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260614_060216</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem">Interlock and Rhysida within the Ransomware Ecosystem | IBM</a> <em>(IBM)</em></li><li><a href="https://www.papermtn.co.uk/detecting-misuse-with-the-claude-compliance-api-the-threat-is-in-the-content/">Detecting Misuse with the Claude Compliance API: The Threat Is in the Content</a> <em>(PaperMtn)</em></li><li><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/">Factoring "short-sleeve" RSA keys with polynomials</a> <em>(Trail of Bits)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-14.mp3" length="1812315" type="audio/mpeg"/>
      <itunes:duration>1:53</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-13.html</link>
      <pubDate>Sat, 13 Jun 2026 06:07:41 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260613_060741</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">BOD 26-04: Prioritizing Security Updates Based on Risk</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/">Behind Khmer Shadow: Targeted espionage against Cambodian government entities</a> <em>(Acronis)</em></li><li><a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation">Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation</a> <em>(Lumen Technologies)</em></li><li><a href="https://binarydefense.com/resources/blog/bluerabbit-a-golang-based-backdoor-with-ransomware-and-destructive-capabilities">BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive…</a> <em>(Binary Defense)</em></li><li><a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/">APT28, an evolution of tradecraft</a> <em>(Sekoia.io)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/">OceanLotus: From external espionage to domestic targeting</a> <em>(ESET)</em></li><li><a href="https://blog.itochuci.co.jp/entry/2026/06/11/110000">ホテル業界を標的とした不審メールの分析（パート1: キャンペーン概要編）- Analysis of suspicious emails targeting the hotel industry (Part 1: Campaign Overview)</a> <em>(ITOCHU Cyber &amp; Intelligence Inc.)</em></li><li><a href="https://blog.itochuci.co.jp/entry/2026/06/11/111500">ホテル業界を標的とした不審メールの分析（パート2: 技術詳細編） - Analysis of Suspicious Emails Targeting the Hotel Industry (Part 2: Technical Details)</a> <em>(ITOCHU Cyber &amp; Intelligence Inc.)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508668&idx=1&sn=1ec03eafb27735e2f5e3b7ea02e77d42&chksm=f9c191b5ceb618a3a101b03fdfd83de445d8e33839d01840374c7e7035d9e245ecba854efb4d&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">APT-C-08（蔓灵花）近期钓鱼网站攻击活动分析 - Analysis of Recent Phishing Website Attacks by APT-C-08 (Manlinghua)</a> <em>(WgpSec)</em></li><li><a href="https://www.nccoe.nist.gov/news-insights/now-available-practical-guidelines-preventing-and-mitigating-ransomware">Now Available: Practical Guidelines for Preventing and Mitigating Ransomware</a> <em>(www.nccoe.nist.gov)</em></li><li><a href="https://trustedsec.com/blog/hardening-intune-the-implementation-guide">Hardening Intune: The Implementation Guide</a> <em>(TrustedSec)</em></li><li><a href="https://bumsrake.de/">BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.</a> <em>(Bumsrakete)</em></li><li><a href="https://deadeclipse666.blogspot.com/2026/06/greatxml-bitlocker-that-seems-to-only.html?m=1">GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan</a> <em>(NightmareEclipse)</em></li><li><a href="https://specterops.io/blog/2026/06/09/user-to-user-authentication-down-the-rabbit-hole-part-1/">User-to-User Authentication: Down the Rabbit Hole - Part 1</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/synacktiv/DCOMIllusionist">DCOMIllusionist: DCOM in memory and fileless lateral movement techniques through .Net deserilization</a> <em>(Synacktiv)</em></li><li><a href="https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-mssql-2025/">Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/S3cur3Th1sSh1t/NimSyscallPacker">NimSyscallPacker: This Packer can be used to pack any C# Assembly, PE-File or Shellcode into a Nim binary. It will encrypt the target payload, build the corresponding Nim source code accordingly</a> <em>(Fabian Mosch)</em></li><li><a href="https://aff-wg.org/2026/06/10/a-long-running-bof-component-contract/">A Long-running BOF Component Contract</a> <em>(Raphael Mudge)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-13.mp3" length="6201304" type="audio/mpeg"/>
      <itunes:duration>6:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-12.html</link>
      <pubDate>Fri, 12 Jun 2026 06:01:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260612_060146</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.deception.pro/blog/xworm-sc-hok-may-2026">[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion</a> <em>(MalBeacon)</em></li><li><a href="https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137">On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface)</a> <em>(Arista Networks)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-12.mp3" length="1368860" type="audio/mpeg"/>
      <itunes:duration>1:25</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-11.html</link>
      <pubDate>Thu, 11 Jun 2026 06:03:17 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260611_060317</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://arxiv.org/abs/2606.07158">Synthetic APTs: the Collapse of TTP-Based Attribution</a> <em>(Alias Robotics)</em></li><li><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-now-monitors-rpc-activity/4523368">Microsoft Defender now monitors RPC activity</a> <em>(Microsoft)</em></li><li><a href="https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html">Whoops! I did it again. I patched Windows Kernel at Milan0day 2026</a> <em>(Ethical Hacker)</em></li><li><a href="https://github.com/MSNightmare/RoguePlanet">RoguePlanet: RoguePlanet Windows Defender Vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://magic-box.dev/blog/patch-tuesday/">Benchmarking n-day exploit generation [via AI]</a> <em>(Josh Merrill)</em></li><li><a href="https://bindinghook.com/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility/">Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility</a> <em>(Virtual Routes Community)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-11.mp3" length="2533712" type="audio/mpeg"/>
      <itunes:duration>2:38</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-10.html</link>
      <pubDate>Wed, 10 Jun 2026 06:04:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260610_060445</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/">Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257</a> <em>(Palo Alto Networks)</em></li><li><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/">Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) - Check Point Blog</a> <em>(Check Point Software Technologies Ltd.)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html">Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,</a> <em>(Trend Micro)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal">Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency</a> <em>(Proofpoint)</em></li><li><a href="https://www.numerique.gouv.fr/sinformer/espace-presse/incident-tchap/">Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users</a> <em>(Direction interministérielle du numérique (DINUM))</em></li><li><a href="https://blog.bushidotoken.net/2026/05/uk-cybercrime-journal-british.html">UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season</a> <em>(BushidoToken)</em></li><li><a href="https://github.com/dtrizna/QuasarNix">QuasarNix: Reverse Shell Detection with Machine Learning</a> <em>(Dmitrijs Trizna)</em></li><li><a href="https://helm.sh/blog/security-notice-baltocdn/">Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement | Helm</a> <em>(Cloud Native Computing Foundation)</em></li><li><a href="https://code.visualstudio.com/updates/v1_123#_delayed-extension-autoupdates">Visual Studio Code 1.123: Delayed extension auto-updates</a> <em>(Microsoft)</em></li><li><a href="https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/">Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.</a> <em>(Meta)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-10.mp3" length="5305199" type="audio/mpeg"/>
      <itunes:duration>5:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-09.html</link>
      <pubDate>Tue, 09 Jun 2026 06:04:59 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260609_060459</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/princessauroraj/Chinese-Cybercrime-Research">Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.</a> <em>(aurora)</em></li><li><a href="https://github.com/ByteRay-Labs/Query-Hub">Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale</a> <em>(ByteRay-Labs)</em></li><li><a href="https://openai.com/index/building-codex-windows-sandbox/">Building a safe, effective sandbox to enable Codex on Windows</a> <em>(OpenAI)</em></li><li><a href="https://github.com/Division-36/Z-Jail">Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine) for secure, auditable code execution.</a> <em>(Division-36)</em></li><li><a href="https://github.com/Sbharadwaj05/ot-sentinel-rules">ot-sentinel-rules: Open-source ICS/OT detection rules (Wazuh + Sigma) for Modbus, DNP3, IEC 104, MQTT, and OPC-UA — tested against a real OpenPLC + GNS3 digital twin lab.</a> <em>(Subhash Bharadwaj)</em></li><li><a href="https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/">On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited by unauthorized third parties</a> <em>(Maine Office of the Attorney General)</em></li><li><a href="https://blog.nns.ee/2026/06/03/katana-badusb/">Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee</a> <em>(Rasmus Moorats)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/pcie-dma-cheats/">About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection</a> <em>(kernullist)</em></li><li><a href="https://patchi.fyi/blog/busywork-sleep-replacement/">BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection</a> <em>(m4n0w4r)</em></li><li><a href="https://github.com/SpacePlant/UPnPHostFileRead">UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.</a> <em>(SpacePlant)</em></li><li><a href="https://github.com/TwoSevenOneT/EDRChoker">EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.</a> <em>(Two Seven One Three)</em></li><li><a href="https://github.com/tjnull/cygor">cygor: An modular asset discovery framework written in python to automate the repeating manual work</a> <em>(tjnull)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-09.mp3" length="5464024" type="audio/mpeg"/>
      <itunes:duration>5:41</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-08.html</link>
      <pubDate>Mon, 08 Jun 2026 06:14:28 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260608_061428</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>30</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems">CISA and Partners Urge Hardening Automatic Tank Gauge Systems</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/">Ongoing Targeted Campaign Against US Law Firms</a> <em>(Google)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512">New China-Linked Cluster OP-512</a> <em>(ReliaQuest)</em></li><li><a href="https://bluecyber.hashnode.dev/mustang-panda-x-plugx-analysis-of-the-january-2026-sample-a-multi-layer-execution-chain">MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain</a> <em>(BlueCyber)</em></li><li><a href="https://www.lac.co.jp/lacwatch/report/20260604_004759.html">PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver</a> <em>(株式会社ラック)</em></li><li><a href="https://threatreviewjournals.blogspot.com/2026/06/investigation-into-apt-5-and-their.html">Investigation into APT 5 and their inner workings of PLA Troop 61786</a> <em>(The author of the content on the Threat Review Journal blog is not explicitly named.)</em></li><li><a href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/">From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services</a> <em>(Arctic Wolf)</em></li><li><a href="https://www.ox.security/blog/six-stages-deep-and-an-endless-loop-shai-hulud-is-getting-sophisticated/">Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated - OX Security</a> <em>(OX Security)</em></li><li><a href="https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm">Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - StepSecurity</a> <em>(StepSecurity)</em></li><li><a href="https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat">Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim</a> <em>(Cyderes)</em></li><li><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/">Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns</a> <em>(McAfee)</em></li><li><a href="https://m4lcode.github.io/unmasking-quellostanco-how-a-git-commit-exposed-a-threat-actor-targeting-egyptian-infrastructure">Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)</a> <em>(M4lcode)</em></li><li><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/">The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy</a> <em>(Include Security)</em></li><li><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts">Security advisory: Brute force attack on Dashlane user accounts</a> <em>(Dashlane)</em></li><li><a href="https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis">Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection &amp; Analysis</a> <em>(Bishop Fox)</em></li><li><a href="https://depthfirst.com/research/21-zero-days-in-ffmpeg">21 Zero-Days in FFmpeg</a> <em>(Depthfirst)</em></li><li><a href="https://beyondmemory.io/blog/json-formatter-data-exposure">Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS</a> <em>(beyondmemory.io)</em></li><li><a href="https://trustedsec.com/blog/the-privileged-roles-nobody-talks-about">The Privileged Roles Nobody Talks About</a> <em>(TrustedSec)</em></li><li><a href="https://blog.nviso.eu/2026/06/04/the-detection-response-chronicles-covert-operations-through-qemu/">The Detection &amp; Response Chronicles: Covert Operations Through QEMU</a> <em>(NVISO)</em></li><li><a href="https://detect.fyi/the-interesting-case-of-wsl-for-payload-staging-bfaa0f69329a">The Interesting Case of WSL for Payload Staging</a> <em>(Daniel Koifman)</em></li><li><a href="https://www.praetorian.com/blog/wasmforge-sliver-webassembly/">Enter the WasmForge: Compiling Sliver into WebAssembly</a> <em>(Praetorian)</em></li><li><a href="https://github.com/kasturixbm5/staged-DLL-Injection-SMB-">staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).</a> <em>(kasturixbm5)</em></li><li><a href="https://matheuzsecurity.github.io/hacking/trendmicro-bmhook-tmhook-reload-bypass/">Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window</a> <em>(Matheuz Security)</em></li><li><a href="https://rastamouse.me/bof-cocktails-in-cobalt-strike/">BOF Cocktails in Cobalt Strike</a> <em>(Rasta Mouse)</em></li><li><a href="https://sansec.io/research/stripe-api-skimmer-infrastructure">Magecart skimmer turns Stripe into a malware command server</a> <em>(Sansec)</em></li><li><a href="https://www.blackhillsinfosec.com/auditing-gitlab-the-ci-cd-kill-chain/">Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...</a> <em>(Black Hills Information Security, Inc.)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/etw-internals-deep-dive/">About ETW Internals: Architecture, Hooking, Tampering, and Detection</a> <em>(kernullist)</em></li><li><a href="https://www.nccgroup.com/research/async-picos-and-custom-beacon-wakeups-in-cobalt-strike/">Async PICOs and Custom Beacon Wakeups in Cobalt Strike</a> <em>(NCC Group)</em></li><li><a href="https://anduinbrian.github.io/posts/blogs/address-translation/">Address Translation</a> <em>(reisen_1943)</em></li><li><a href="https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/">The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer</a> <em>(Positive Technologies)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-08.mp3" length="17802179" type="audio/mpeg"/>
      <itunes:duration>18:32</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-07.html</link>
      <pubDate>Sun, 07 Jun 2026 06:02:20 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260607_060220</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://opensourcemalware.com/blog/miasma-reaches-azure">The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds</a> <em>(OpenSourceMalware)</em></li><li><a href="https://blog.ammaraskar.com/github-token-stealing/">1-Click GitHub Token Stealing via a VSCode Bug</a> <em>(Ammar Askar)</em></li><li><a href="https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html">Enhance your Supply Chain Security with our Package Proxy Tool</a> <em>(Thinkst)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-07.mp3" length="1976991" type="audio/mpeg"/>
      <itunes:duration>2:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-06.html</link>
      <pubDate>Sat, 06 Jun 2026 06:04:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260606_060433</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/">VerdantBamboo: Just Another BRICKSTORM in the Firewall</a> <em>(Volexity)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a> <em>(National Cyber Security Centre)</em></li><li><a href="https://www.ox.security/blog/ironworm-supply-chain-malware-hits-npm/">IronWorm Supply Chain Malware Hits npm - OX Security</a> <em>(OX Security)</em></li><li><a href="https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser">You do surprise me.exe: An unexpected executable in Hola Browser</a> <em>(Sophos X-Ops)</em></li><li><a href="https://managedpriv.com/blog/acl-canonical-order-and-security/">The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory</a> <em>(Robin Granberg)</em></li><li><a href="https://github.com/Mr-Un1k0d3r/AzureRedOps">AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID</a> <em>(Mr.Un1k0d3r (TrueCyber Inc.))</em></li><li><a href="https://github.com/zmap/zannotate">zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)</a> <em>(ZMap)</em></li><li><a href="https://www.originhq.com/research/mxc-execution-containers-internals">MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code | Origin</a> <em>(Origin)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/">FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel</a> <em>(Sekoia.io)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/">FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad</a> <em>(Sekoia.io)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-06.mp3" length="4349745" type="audio/mpeg"/>
      <itunes:duration>4:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-05.html</link>
      <pubDate>Fri, 05 Jun 2026 06:05:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260605_060545</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-45247.html">CVE-2026-45247</a> <em>(CISA KEV)</em></li><li><a href="https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/">Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://www.huntress.com/blog/malspam-to-deskcvb-rat-delivery-chain-analysis">Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT | Huntress</a> <em>(Huntress)</em></li><li><a href="https://medium.com/@s12deff/bring-your-own-rwx-region-dll-byorwxdll-0283951d34e9">Bring Your Own RWX Region DLL (BYORWXDLL)</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://tierzerosecurity.co.nz/2026/06/02/nuget-code-execution.html">NuGet Code Execution As A Service</a> <em>(Tier Zero Security)</em></li><li><a href="https://github.com/0xsp-SRD/aether">aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET</a> <em>(0xsp)</em></li><li><a href="https://blog.checkpoint.com/security/the-server-seizure-that-affects-also-irans-cyber-operations/">The Server Seizure That Affects Also Iran's Cyber Operations</a> <em>(Check Point Research)</em></li><li><a href="https://open.substack.com/pub/nattothoughts/p/how-chinas-cyber-operations-and-the-610?r=q9u24">How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad</a> <em>(Natto Team)</em></li><li><a href="https://www.security.com/blog-post/stock-exchange-espionage">Espionage Campaign Targeted Stock Exchange Executive for Five Months</a> <em>(Broadcom)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global">TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US</a> <em>(Proofpoint)</em></li><li><a href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse">HazyBeacon and AWS Lambda Function URL Abuse</a> <em>(Qualys)</em></li><li><a href="https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/">Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor</a> <em>(Palo Alto Networks)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508667&idx=1&sn=3557c4427627029226bda2a9de3a81ca&chksm=f9c191b2ceb618a4b288a4cf57d9813f2b425ed24a11848bee8d34ec2f53ed9bbde180cac3be&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component</a> <em>(上海市浦东新区人民法院)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-05.mp3" length="5645418" type="audio/mpeg"/>
      <itunes:duration>5:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-04.html</link>
      <pubDate>Thu, 04 Jun 2026 06:05:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260604_060523</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.exatrack.com/Tracking_APT28_PixyNetLoader/">Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026</a> <em>(Exatrack)</em></li><li><a href="https://idanmalihi.com/tracking-north-korea-nation-state-apt-infrastructure-kimsuky/">Tracking North Korea Nation-State APT Infrastructure: Kimsuky</a> <em>(Idan Malihi)</em></li><li><a href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/">From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services</a> <em>(Arctic Wolf)</em></li><li><a href="https://interisle.net/insights/cybercriminaldomaindemand">Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand</a> <em>(Interisle Consulting Group, LLC)</em></li><li><a href="https://cooldowns.dev/">Dependency Cooldowns - Dependency Cooldowns</a> <em>(People Can Fly)</em></li><li><a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb">Codex Discovered a Hidden HTTP/2 Bomb</a> <em>(Calif.io)</em></li><li><a href="https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris/">Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs</a> <em>(SafeBreach)</em></li><li><a href="https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler">Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix | Huntress</a> <em>(Huntress)</em></li><li><a href="https://asec.ahnlab.com/ko/93931/">새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn</a> <em>(AhnLab)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-04.mp3" length="4750150" type="audio/mpeg"/>
      <itunes:duration>4:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-03.html</link>
      <pubDate>Wed, 03 Jun 2026 06:03:48 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260603_060348</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages">Miasma: Supply Chain Attack Targeting RedHat npm Packages</a> <em>(Wiz)</em></li><li><a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages</a> <em>(Socket)</em></li><li><a href="https://www.stepsecurity.io/blog/multiple-redhat-cloud-services-npm-packages-compromised">Multiple redhat-cloud-services npm Packages compromised</a> <em>(StepSecurity)</em></li><li><a href="https://blog.calif.io/p/redsun-exploiting-windows-defenders">RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation</a> <em>(blog.calif.io)</em></li><li><a href="https://docbox.etsi.org/CYBER/EUSR/Open/EN_304-627_V1.0.0_2026-06-01_Routers-Modems-Switches_Final-draft.pdf">Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches</a> <em>(ETSI)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/">Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm</a> <em>(Sekoia.io)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-03.mp3" length="2244484" type="audio/mpeg"/>
      <itunes:duration>2:20</itunes:duration>
    </item>
  </channel>
</rss>