<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Daily BlueTeamSec Briefing</title>
    <description>Daily security briefings for blue team professionals</description>
    <language>en-us</language>
    <copyright>© 2025 InfoSec Briefing Bot</copyright>
    <managingEditor>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</managingEditor>
    <webMaster>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</webMaster>
    <category>Technology</category>
    <generator>InfoSec Briefing Generator</generator>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <link>https://briefing.workshop1.net</link>
    <pubDate>Sun, 31 Aug 2025 16:05:46 +0000</pubDate>
    <lastBuildDate>Wed, 09 Sep 2026 06:06:15 +0000</lastBuildDate>
    <itunes:author>InfoSec Briefing Bot</itunes:author>
    <itunes:summary>Daily security briefings for blue team professionals</itunes:summary>
    <itunes:category>Technology</itunes:category>
    <itunes:image href="https://briefing.workshop1.net/assets/podcast-artwork.jpg"/>
    <itunes:owner>
      <itunes:name>InfoSec Briefing Bot</itunes:name>
      <itunes:email>podcast@briefing.workshop1.net</itunes:email>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:language>en-us</itunes:language>
    <item>
      <title>InfoSec Briefing - September 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-09.html</link>
      <pubDate>Wed, 09 Sep 2026 06:06:15 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260909_060615</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://kudelskisecurity.com/research/beyond-lazarus-organization-of-dprk-cyber-capabilities">Beyond Lazarus: Organization of DPRK Cyber Capabilities</a> <em>(Kudelski Security and Sekoia)</em></li><li><a href="https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/">Token Theft in Microsoft Entra ID (Part 2 of 4): Continuous Access Evaluation</a> <em>(ERNW)</em></li><li><a href="https://github.com/emirbyte/Remote-Mapping-Injection">Remote-Mapping-Injection: Remote Thread Hijacking + Remote Mapping Injection POC</a> <em>(emirbyte)</em></li><li><a href="https://github.com/S12cybersecurity/HandleRedirect">HandleRedirect: Handle Redirect via BYOVD Kernel Read/Write</a> <em>(S12cybersecurity)</em></li><li><a href="https://github.com/0x4D31/endpoint-ai-agent-abuse">endpoint-ai-agent-abuse: EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.</a> <em>(0x4D31)</em></li><li><a href="https://github.com/MatheuZSecurity/Dntry">Dntry: Fileless ELF execution via O_TMPFILE + execveat(AT_EMPTY_PATH)</a> <em>(MatheuZSecurity)</em></li><li><a href="https://github.com/0x574R/Darkcloak">Darkcloak: Linux process identity cloakingDarkcloak: Linux process identity cloaking</a> <em>(0x574R)</em></li><li><a href="https://github.com/i-am-shodan/OpenKustoExplorer">OpenKustoExplorer: A fast, native desktop workbench for Azure Data Explorer</a> <em>(i-am-shodan)</em></li><li><a href="https://github.com/microsoft/tgrep">tgrep: Trigram-indexed grep with a client/server architecture for fast regex search in large codebases locally</a> <em>(Microsoft)</em></li><li><a href="https://github.com/immanuwell/pktz">pktz: pktz - eBPF-powered network traffic monitor</a> <em>(Immanuwell)</em></li><li><a href="https://github.com/Yean-Sec/StrikeAgent_AtkBrain-Flash">StrikeAgent_AtkBrain-Flash: 由夜安团队研发的AI渗透测试平台，涵盖红队打点、SRC、CTF，特别是在红队领域有极为亮眼的存在 - The AI penetration testing platform developed by the Night An team covers Red Team Placement, SRC, and CTF</a> <em>(夜安团队)</em></li><li><a href="https://github.com/OrbitCurve/firmware-reverse-engineering">firmware-reverse-engineering: A full Claude and Codex skillsets for firmware reverse engineering.</a> <em>(OrbitCurve)</em></li><li><a href="https://spectra-vrg.org/hackers-handbook/AXD/x64/theartofexploitation.pdf">The Art of Exploit Development</a> <em>(Spectra Vulnerability Research Group)</em></li><li><a href="https://github.com/microsoft/mxc">mxc: Policy-driven, layered isolation and containment</a> <em>(Microsoft)</em></li><li><a href="https://www.youtube.com/watch?v=aI1bKMJQXAQ">Politie | Herken jij de stem van de Odido hack? | Landelijke Opsporing &amp; Interventies - Police | Do you recognize the voice from the Odido hack? | National Investigation &amp; Interventions - ShinyHunters</a> <em>(Politie)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-09.mp3" length="5119208" type="audio/mpeg"/>
      <itunes:duration>5:19</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-08.html</link>
      <pubDate>Tue, 08 Sep 2026 06:03:51 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260908_060351</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/">Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended</a> <em>(CERT Polska)</em></li><li><a href="https://blog.jetbrains.com/pycharm/2026/08/cadence-security-incident-august-2026/">Security Incident Affecting JetBrains Cadence - The JetBrains Blog</a> <em>(JetBrains s.r.o.)</em></li><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode">Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve</a> <em>(Genians)</em></li><li><a href="https://netaskari.substack.com/p/robobox-self-driven-malware-creation?r=q9u24">Robobox: Self driven malware creation and execution - made in China</a> <em>(NetAskari)</em></li><li><a href="https://xusheng.dev/posts/byotc/main/">Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)</a> <em>(Xusheng Li)</em></li><li><a href="https://github.com/DeathShotXD/0xM0nCrush">0xM0nCrush: Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.</a> <em>(DeathShotXD)</em></li><li><a href="https://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf">Frontier Models’ Vulnerability Patches are Often F.L.A.W.E.D. - Fix-Like Artifacts With Embedded Defects: Common failure modes of LLM-generated security patches</a> <em>(1password.com)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-08.mp3" length="2942476" type="audio/mpeg"/>
      <itunes:duration>3:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-07.html</link>
      <pubDate>Mon, 07 Sep 2026 06:05:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260907_060502</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>11</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/">ASCII smuggling crosses over from AI prompt injection to phishing evasion</a> <em>(Microsoft)</em></li><li><a href="https://www.ic3.gov/PSA/2026/PSA260901">Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing</a> <em>(Federal Bureau of Investigation)</em></li><li><a href="https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/">CVE-2026-9586: Sangoma Switchvox RCE</a> <em>(Horizon3.ai)</em></li><li><a href="https://www.huntress.com/blog/faronics-deploy-abuse">Daisy-Chaining Trust: Investigating Faronics Deploy Abuse</a> <em>(Huntress)</em></li><li><a href="https://www.techanarchy.net/from-patch-to-exploit-using-claude-code-to-reverse-engineer-a-zero-day-in-papercut-ng/">From Patch to Exploit; Using Claude Code to reverse engineer a zero-day in Papercut NG</a> <em>(Kev Breen)</em></li><li><a href="https://blog.nullze.net/posts/peeling-the-sentinel/">Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools</a> <em>(nullze)</em></li><li><a href="https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1/">Incident response guide for AWS CloudTrail investigations – Part 1</a> <em>(Amazon Web Services (AWS))</em></li><li><a href="https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-2/">Incident response guide for AWS CloudTrail investigations – Part 2</a> <em>(Amazon Web Services)</em></li><li><a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#entra-soc-identity-responder">New Entra role - Entra SOC Identity Responder</a> <em>(Microsoft)</em></li><li><a href="https://ccmexec.com/2026/08/windows-365-placing-a-cloud-pc-under-review/">Windows 365 - Placing a Cloud PC Under Review</a> <em>(Jörgen Nilsson)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508875&idx=1&sn=39ad939372621e4f7bc675dda5b0d7b3&chksm=f9c19082ceb61994ecb7e110b9ca94f1df5ff3a182547b84ffe4729acfee31d7514c8a20a27e&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">APT-C-56（透明部落）近期攻击活动分析 -Analysis of Recent Attack Activities by APT-C-56 (Transparent Tribe)</a> <em>(奇安信威胁情报中心 (QiAnXin Threat Intelligence Center))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-07.mp3" length="3707342" type="audio/mpeg"/>
      <itunes:duration>3:51</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-06.html</link>
      <pubDate>Sun, 06 Sep 2026 06:06:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260906_060602</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/">Password spraying campaign targets AWS root user accounts across 150+ organizations</a> <em>(Datadog)</em></li><li><a href="https://www.elastic.co/security-labs/threat-command/memfd-create-linux-fileless-execution">Linux Detection Engineering - Fileless Execution</a> <em>(Elastic)</em></li><li><a href="https://blog.thinkst.com/2026/09/getting-agents-to-tell-on-themselves.html">Getting Agents to tell on themselves</a> <em>(Thinkst Applied Research)</em></li><li><a href="https://blog.bushidotoken.net/2026/09/uk-cybercrime-journal-exfilsquad-emerges.html">UK Cybercrime Journal: ExfilSquad Emerges</a> <em>(BushidoToken)</em></li><li><a href="https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/">New backdoors from Toy Ghouls</a> <em>(Kaspersky Lab)</em></li><li><a href="https://asec.ahnlab.com/ko/95216/">Kim Sooki again? This time, disguised as a seafood purchase request.</a> <em>(AhnLab)</em></li><li><a href="https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/">DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors</a> <em>(Rapid7)</em></li><li><a href="https://github.com/BindsNET/bindsnet/security/advisories/GHSA-6f2q-w3r8-xxhj">Malicious code executed on clone between 2026-08-29 and 2026-09-02</a> <em>(BindsNET)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/">Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog</a> <em>(Microsoft)</em></li><li><a href="https://hawksley.dev/blog/get-free-arpa-domain">How to get a free .arpa domain</a> <em>(Ethan Hawksley)</em></li><li><a href="https://www.synacktiv.com/en/publications/simulating-legitimate-active-directory-services-on-the-network-the-case-of-gpo">Simulating legitimate Active Directory services on the network: the case of GPO exploitation</a> <em>(Synacktiv)</em></li><li><a href="https://www.netspi.com/blog/technical-blog/cloud-pentesting/modern-adventures-in-azure-privilege-escalation/">Modern Adventures in Azure Privilege Escalation</a> <em>(NetSPI)</em></li><li><a href="https://github.com/herosi/pstrings">pstrings: pstrings - Parallel strings extractor for very large files</a> <em>(herosi)</em></li><li><a href="https://github.com/aaron-kidwell/CouchPotato">CouchPotato: another PrivEsc potato - Patches ETW &amp; AMSI and uses indirect syscall to abuse SeImpersonatePrivilege.</a> <em>(Aaron Kidwell)</em></li><li><a href="https://github.com/n0qword/mythic_ornn">mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type and C2 Profiles.</a> <em>(n0qword)</em></li><li><a href="https://iretq.com/how-forza-horizon-6-breaks-your-ida/">How Forza Horizon 6 Breaks Your IDA</a> <em>(Radulf)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-06.mp3" length="6259400" type="audio/mpeg"/>
      <itunes:duration>6:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-05.html</link>
      <pubDate>Sat, 05 Sep 2026 06:05:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260905_060533</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>11</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cyber.gov.au/business-government/detecting-responding-to-threats/cyber-security-incident-response/communicating-under-pressure-best-practices-for-service-providers">Communicating under pressure: Best practices for service providers</a> <em>(Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC))</em></li><li><a href="https://github.com/MichaelS1011/ephemora-cell">ephemora-cell: Ephemora Cell — The execution layer for untrusted AI-generated code. Fast, capability-based WASM execution with explicit CPU, memory, time, I/O, and filesystem limits.</a> <em>(MichaelS1011)</em></li><li><a href="https://www.whisper.security/resources/blog/prince-of-persia-mapping-the-backend-and-a-reserve-of-domains-staged-for-what-comes-next">Prince of Persia: Detecting the Next C2</a> <em>(Whisper Security)</em></li><li><a href="https://citizenlab.ca/research/pegasus-spyware-infection-of-serbian-activist/">Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist - The Citizen Lab</a> <em>(University of Toronto)</em></li><li><a href="https://www.justice.gov/usao-ndca/pr/russian-national-indicted-exploiting-online-platform-used-freelance-employment-and">Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain</a> <em>(United States Department of Justice)</em></li><li><a href="https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65">Malicious Packages Served from Unauthorized Registry Server</a> <em>(Coder)</em></li><li><a href="https://www.huntress.com/blog/rogue-screenconnect-installations">Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity</a> <em>(Huntress)</em></li><li><a href="https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown">Sality Malware Disrupted in International Cyber Takedown</a> <em>(U.S. Attorney's Office, Central District of California)</em></li><li><a href="https://www.security.com/threat-intelligence/node-js-returns-ransomware">Node.js: Old Technique Makes a Comeback</a> <em>(Broadcom)</em></li><li><a href="https://rewardsforjustice.net/rewards/amir-yaryab/">Amir Yaryab – Rewards For Justice - a senior official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). Yaryab leads the IRGC-CEC’s Cyber Operations Command.</a> <em>(U.S. Department of State)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-05.mp3" length="4407005" type="audio/mpeg"/>
      <itunes:duration>4:35</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-04.html</link>
      <pubDate>Fri, 04 Sep 2026 06:01:51 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260904_060151</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/MSNightmare/FalconFlank">FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://www.lawfaremedia.org/article/persistent-engagement-and-the-illusion-of-cyber-equilibrium">Persistent Engagement and the Illusion of Cyber Equilibrium</a> <em>(The Lawfare Institute)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-04.mp3" length="987263" type="audio/mpeg"/>
      <itunes:duration>1:01</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-03.html</link>
      <pubDate>Thu, 03 Sep 2026 06:05:39 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260903_060539</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.plume.com/resources/superproxy-how-residential-proxy-networks-have-become-malware-delivery-platforms">SuperProxy: How Residential Proxy Networks Have Become Malware Delivery Platforms</a> <em>(Plume Design, Inc.)</em></li><li><a href="https://www.huntress.com/blog/faronics-deploy-abuse">Daisy-Chaining Trust: Investigating Faronics Deploy Abuse</a> <em>(Huntress)</em></li><li><a href="https://www.justice.gov/usao-ks/pr/fbi-investigation-leads-five-venezuelan-nationals-plead-guilty-attempting-jackpot-kansas">FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs</a> <em>(United States Attorney's Office for the District of Kansas)</em></li><li><a href="https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/">Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams</a> <em>(Palo Alto Networks)</em></li><li><a href="https://metr.org/blog/2026-08-31-security-update/">Update on Security at METR</a> <em>(METR)</em></li><li><a href="https://bgphorizon.com/blog/virtualizor-bgp-hijack-august-2026">The August 2026 Virtualizor Incident in BGPHorizon</a> <em>(BGPHorizon)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/">Financially Motivated Threat Actor BREEZE COMET Targets Brazil</a> <em>(Google)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/">Counterfeit installers to system compromise: Tracking a deceptive software download campaign</a> <em>(Microsoft)</em></li><li><a href="https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/">Mirage Kitten switches to Node.js and JavaScript malware</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://enclave.ai/hackingrace">Enclave: We Raced Seven AI Models to RCE</a> <em>(Enclave)</em></li><li><a href="https://github.com/TA1EEI/vhf-morse-transmitter-monitor">vhf-morse-transmitter-monitor: Set radio to 148.500 MHz, selct FM, USB, or CW, set squelch to 0 or 1. xtend your radio's antenna toward monitor's HDMI - now transmit in Morse code from your monitor!</a> <em>(Efe Işık)</em></li><li><a href="https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/">Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode</a> <em>(Check Point Research)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-03.mp3" length="4765614" type="audio/mpeg"/>
      <itunes:duration>4:57</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-02.html</link>
      <pubDate>Wed, 02 Sep 2026 06:08:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260902_060835</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>20</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://x.com/GrapheneOS/status/2094661263041134767">Good news about the Pixel 11. It still has at least bare minimum support for MTE at a hardware level - but disabled in Android firmware</a> <em>(GrapheneOS)</em></li><li><a href="https://github.com/nickdaria/wyze-bulb-color-pwned">wyze-bulb-color-pwned: No-open firmware exploit for the Wyze WLPA19CV2 color bulb - or how to implant a lightbulb</a> <em>(nickdaria)</em></li><li><a href="https://calif.io/research/oempocalypse">OEMpocalypse Now: A Generic Exploitation Strategy from Android untrusted app to root</a> <em>(Lukas Maar)</em></li><li><a href="https://www.anthropic.com/news/improving-alignment-security-efforts">Improving our alignment and security practices - 'By default, all cyber evaluations should run inside a hardened sandbox (an isolated computing environment) with no internet access'</a> <em>(Anthropic)</em></li><li><a href="https://lowendtalk.com/discussion/220625/urgent-virtualizor-compromised-31st-aug/p1">Virtualizor Compromised (31st AUG): Virtualizor has been compromised, their BGP hijack a few days ago seems to have a deployed a malicious package.</a> <em>(LowEndBox &amp; LowEndTalk)</em></li><li><a href="https://github.com/mnaza/pqc-embedded">pqc-embedded: Post-quantum signature verification on constrained parts: LMS/HSS in no_std Rust, measured flash/RAM/time budgets against ML-DSA, SLH-DSA, ECDSA and Ed25519</a> <em>(Andrey Mnatsakanov)</em></li><li><a href="https://github.com/nicologiuliani6/cavium-cn6640-snic10e-octeon-ii-nic">Out-of-tree Linux driver stack and boot tooling for the Cavium CN6640-SNIC10E (Octeon II, PCI 177d:0092), exposing as two independent 10 GbE interfaces (oct0/oct1) over a BAR2 shared-memory datapath</a> <em>(Nicolo Giuliani)</em></li><li><a href="https://schlarp.com/posts/everything-i-own-owned/">Everything I own, owned</a> <em>(Chaz Schlarp)</em></li><li><a href="https://mrt4ntr4.github.io/winheapbook/">Introduction - Windows Kernel Segment Heap Notes</a> <em>(mrT4ntr4)</em></li><li><a href="https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-inside-the-operator-behind-blind-eagles-github-loader">Still Circling: Inside the Operator Behind Blind Eagle's GitHub Loader</a> <em>(LevelBlue)</em></li><li><a href="https://www.spytalk.co/p/how-the-russians-got-inside-my-phone">How the Russians Got Inside My Phone</a> <em>(SpyTalk)</em></li><li><a href="https://www.cloudsek.com/blog/aurora-ransomware-affiliate-ai-attack-planning-crypto-payments">Caught in 4K: The Aurora Files</a> <em>(CloudSEK)</em></li><li><a href="https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/">Fire Ant Evolves: From Hypervisors to Trusted Infrastructure</a> <em>(Sygnia)</em></li><li><a href="https://securelist.com/valleyrat-backdoor-adware/121175/">ValleyRAT is spreading disguised as adware</a> <em>(Kaspersky Lab)</em></li><li><a href="https://blog.talosintelligence.com/javascript-obfuscation-from-party-trick-to-phishing-kit/">JavaScript obfuscation: From party trick to phishing kit</a> <em>(Cisco Talos Intelligence Group)</em></li><li><a href="https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/">The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution - "Approximately 97% of AI-enabled malware samples exist only in research repositories, sandbox environments and secu</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.reuters.com/world/russian-speaking-cybercriminals-used-spacexs-cursor-ai-tool-hack-seven-companies-2026-08-27/">Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies</a> <em>(Reuters)</em></li><li><a href="https://signalandsilence.substack.com/p/i-think-someone-hacked-the-commissary">I Think the Military Commissary Freezers Were Hacked - 'the Pentagon now acknowledging a “possible refrigeration disruption” at numerous DeCA commissaries.'</a> <em>(M. Elizabeth)</em></li><li><a href="https://i.blackhat.com/Asia-26/Presentations/BHAS26-Kozlov-Anufrienko-Qualcom-REV01.pdf">Qualcomm BootROM
code signing bypass CVE-2026-25262 - needs hardware replacements</a> <em>(Kaspersky)</em></li><li><a href="https://github.com/rabindra789/lych">lych: A monolithic ARM64 operating system written in Rust.</a> <em>(Rabindra789)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-02.mp3" length="7743573" type="audio/mpeg"/>
      <itunes:duration>8:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - September 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-09-01.html</link>
      <pubDate>Tue, 01 Sep 2026 06:12:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260901_061216</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>29</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.polyswarm.io/uat-10147-uses-ai-assisted-workflows-to-deploy-spectre-backdoor">UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor</a> <em>(Swarm Technologies, Inc.)</em></li><li><a href="https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-27-New-Passkey-Themed-Subdomains-Target-Numerous-Industries.txt?utm_campaign=tti_thecom-affiliate">recently identified a domain (passkeyconnect[.]com) that is likely associated with Com-affiliated threat actors</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.elastic.co/security-labs/threat-command/dll-search-order-hijacking-elastic-defend">Detect DLL search order hijacking with a single field</a> <em>(Elastic)</em></li><li><a href="https://github.com/socprime/logtotal-sanitizer">logtotal-sanitizer: Framework-agnostic log sanitizer for browsers and Node.js. Redacts secrets and infrastructure identifiers with stable HMAC tokens so event correlation still works.</a> <em>(SOC Prime)</em></li><li><a href="https://designingsecuresoftware.com/writings/ai-cyber-open-letter/">Questions about Collective action on cybersecurity</a> <em>(Loren Kohnfelder)</em></li><li><a href="https://safedep.io/mini-shai-hulud-openapi-react-query-codegen-compromised/">Mini Shai-Hulud Strikes Again: openapi-react-query-codegen</a> <em>(SafeDep)</em></li><li><a href="https://www.pc.co.il/news/security/457201/">חשיפה: ההאקר מאשקלון - עובד IT ומומחה סייבר - he was charged with violations of the Computer Law, wiretapping and invasion of privacy. As far as is known so far, the suspected hacker – who, at the sam</a> <em>(People and Computers (אנשים ומחשבים))</em></li><li><a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">The Hugging Face incident and the road ahead</a> <em>(OpenAI)</em></li><li><a href="https://ramimac.me/teampcp/#afp-arrests">Incident Timeline // TeamPCP Supply Chain Campaign</a> <em>(Rami McCarthy)</em></li><li><a href="https://github.com/dinosn/cve-2026-71362-magento-lab/blob/main/docs/ROOTCAUSE.md">Magneto CVE-2026-71362 — Root-cause walkthrough</a> <em>(dinosn)</em></li><li><a href="https://blog.securelayer7.net/cve-2026-63077-teamcity-rce/">CVE-2026-63077: TeamCity Pre-Auth RCE Explained</a> <em>(SecureLayer7)</em></li><li><a href="https://github.com/MSNightmare/PrettyPrague">PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://docs.jfrog.com/releases/docs/jfrog-security-advisories#cve-2026-82329---potential-authentication-bypass-leading-to-administrative-access-in-artifactory">JFrog Security Advisories: CVE-2026-82329 - Potential authentication bypass leading to administrative access in Artifactory -</a> <em>(JFrog)</em></li><li><a href="https://github.com/MSNightmare/GreenSection">GreenSection: Nvidia GreenSection Memory Corruption 0day vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://github.com/MSNightmare/HardBreacher">HardBreacher: Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/">TerminalFix campaign deploys a reverse tunnel through multistage intrusion</a> <em>(Microsoft)</em></li><li><a href="https://catchingphish.com/clickexfil-my-iteration-on-clickfix-and-filefix/">ClickExfil: My iteration on ClickFix and FileFix</a> <em>(jbellcode)</em></li><li><a href="https://iwa-tools.pkilla.pw/">iwa-tools — Offensive AD tradecraft in a browser tab</a> <em>(pkilla)</em></li><li><a href="https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers">Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets</a> <em>(GreyNoise, Inc.)</em></li><li><a href="https://www.huntress.com/blog/papercut-actively-exploited">PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE</a> <em>(Huntress)</em></li><li><a href="https://github.com/Azr43lKn1ght/DFIR-LABS">DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: DFIR, Malware Analysis and Threat Hunting.</a> <em>(Azr43lKn1ght)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-gryxa-ai-built-toolkit/">Gryxa: The AI-Built Toolkit That Watches How You Remove It</a> <em>(ReliaQuest)</em></li><li><a href="https://censys.com/blog/fake-mp4-file-carries-malicious-payload/">The Video That Plays You: Fake MP4 File Carries Malicious Payload</a> <em>(Censys)</em></li><li><a href="https://douglasmun.github.io/ClickFix%20ClearFake%20PowerShell%20Stager%20Malware%20Analysis%20Report%2020260828.html">ClickFix / ClearFake PowerShell Stager — Static Analysis Report</a> <em>(Douglas Mun)</em></li><li><a href="https://blog.ritsec.club/posts/vrig-fuzzillai/">VRIG - Fuzzillai -  goal of the project was to learn more about JavaScript engine fuzzing, V8 compiler internals, and the applications of AI systems to fuzzers like Fuzzilli.</a> <em>(RITSEC)</em></li><li><a href="https://github.com/visa/visa-vulnerability-agentic-harness">visa-vulnerability-agentic-harness: Visa Vulnerability Agentic Harness</a> <em>(Visa, Inc.)</em></li><li><a href="https://github.com/daffainfo/vol-rs">vol-rs: Volatility 3 ported to Rust. Same output, much faster.</a> <em>(daffainfo)</em></li><li><a href="https://t3l3m3try.medium.com/github-recon-find-secrets-on-github-6b7b886eed24">GitHub Recon — Find Secrets on GitHub</a> <em>(T3L3M3TRY)</em></li><li><a href="https://infosecwriteups.com/operation-repoghost-exposing-a-russian-linked-malware-campaign-hiding-in-githubs-open-source-85a5dd6fa01e">Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source…</a> <em>(Avyukt Security)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-09-01.mp3" length="12615724" type="audio/mpeg"/>
      <itunes:duration>13:08</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 31, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-31.html</link>
      <pubDate>Mon, 31 Aug 2026 06:09:00 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260831_060900</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.iverify.com/blog/android-intrusion-logging-forensics-analysis">Android Intrusion Logs - A First Look</a> <em>(iVerify)</em></li><li><a href="https://www.guidepointsecurity.com/blog/detecting-privilege-escalaction-through-adcs/">Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database</a> <em>(GuidePoint Security)</em></li><li><a href="https://aws.amazon.com/blogs/security/detecting-multi-stage-attacks-on-aws-a-guide-to-cross-service-signal-correlation/">Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation</a> <em>(Amazon Web Services (AWS))</em></li><li><a href="https://www.infostealers.com/article/inside-a-syrian-interrogation-room-the-detainee-files-an-infostealer-stole-from-a-military-police-unit/">Inside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police Unit</a> <em>(Hudson Rock)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-social-engineering-attempt-against-reliaquest-what-we-found/">A Social Engineering Attempt Against ReliaQuest: What We Found</a> <em>(ReliaQuest)</em></li><li><a href="https://eprint.iacr.org/2026/1319">A Real-World Law-Enforcement Hack: The Case of Encrochat</a> <em>(International Association for Cryptologic Research)</em></li><li><a href="https://zerotracelab.com/blog/qtfy-hunt-internet-sensor">The QTFY Hunt: How Chinese Hackers Were Tracked and How the Internet Became the Sensor</a> <em>(ZeroTrace Lab)</em></li><li><a href="https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation">Insights into Suspected DPRK Workers</a> <em>(Huntress)</em></li><li><a href="https://censys.com/blog/open-directory-exposes-moobot-source-code-and-activity/">Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption - Censys</a> <em>(Censys)</em></li><li><a href="https://blog.confiant.com/p/skimming-on-the-blockchain-a-magecart">Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning</a> <em>(Confiant)</em></li><li><a href="https://www.alteredsecurity.com/post/abusing-azure-vms-when-bitlocker-recovery-turns-into-an-attack-vector">Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector</a> <em>(Altered Security)</em></li><li><a href="https://unsecure.sh/blog/agentic-soc-scenario/">A scenario to evaluate your Agentic SOC</a> <em>(unsecure.sh)</em></li><li><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/">URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)</a> <em>(PaperCut Software)</em></li><li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-a-software-development-platform-within-australia">Active exploitation of a software development platform within Australia</a> <em>(Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC))</em></li><li><a href="https://higashi.blog/2026/08/23/api-use/">I spent $200 a month to SEO-poison Google search results</a> <em>(Steven (Dongze) Yue)</em></li><li><a href="https://www.cisa.gov/resources-tools/resources/logging-reference-architecture">Logging Reference Architecture</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights">768 Leaked Corporate AWS Keys Held Full Admin Rights</a> <em>(Truffle Security Co.)</em></li><li><a href="https://detect.fyi/online-false-positive-reduction-via-statistical-process-controls-8609e682c8af">Online False Positive Reduction via Statistical Process Controls</a> <em>(Nikolas Bielski)</em></li><li><a href="https://github.com/jprx/darwin-vm">darwin-vm: Run iOS/ macOS in Qemu. Virtual iPhone 17, 16, 15, 14, 13, 12 and M5-M1 Apple Si Macs supported.</a> <em>(jprx)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-31.mp3" length="8617944" type="audio/mpeg"/>
      <itunes:duration>8:58</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-30.html</link>
      <pubDate>Sun, 30 Aug 2026 06:07:42 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260830_060742</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.vulncheck.com/blog/zbt-darklantern-speakingstone">Chinese Implants in the Supply Chain</a> <em>(VulnCheck)</em></li><li><a href="https://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/">Cambodia-focused cluster uses multistage infection chain with localized lures</a> <em>(Acronis)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient">Carry-On Compromise: TA4922 Packs PackClient</a> <em>(Proofpoint)</em></li><li><a href="https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/">Dark Caracal Reloaded: New Malware, Same Hunting Grounds</a> <em>(Arctic Wolf)</em></li><li><a href="https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge">BlueDelta Targets Defense and Diplomacy with HOOKEDGE</a> <em>(Recorded Future)</em></li><li><a href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global">Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate | Australian Federal Police</a> <em>(Australian Federal Police)</em></li><li><a href="https://psirt.watchguard.com/CVE-2026-57910/">CVE-2026-57910 — WatchGuard Agent improper authentication allows unauthenticated remote code execution</a> <em>(WatchGuard)</em></li><li><a href="https://boschko.ca/g1-ble-rce/">UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range</a> <em>(Olivier Boschko)</em></li><li><a href="https://blog.amberwolf.com/blog/2026/august/sonicwall-gms-unauthenticated-rce-and-encrypted-password-hash-extraction/">SonicWall GMS - Unauthenticated RCE and Encrypted Password Hash Extraction (CVE-2026-66145)</a> <em>(AmberWolf)</em></li><li><a href="https://www.armadin.com/blog-posts/prtremote-extract-prt-cookies-remotely-with-interactivetoken-scheduled-task">PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks</a> <em>(www.armadin.com)</em></li><li><a href="https://www.mdsec.co.uk/2026/08/when-it-snows-it-pours-anatomy-of-a-servicenow-red-team/">When it Snows it Pours - Anatomy of a ServiceNow Red Team</a> <em>(MDSec)</em></li><li><a href="https://gputhor.com/">GPUThor</a> <em>(gputhor.com)</em></li><li><a href="https://github.com/idamcp/idamcp">idamcp: provides a Model Context Protocol (MCP) server for integrating IDA Pro with AI agents like Gemini, Claude, and Jetski.</a> <em>(Junfeng Yang)</em></li><li><a href="https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/inside-shadow-water-084-a-steganographic-loader-as-a-service-delivering-remcos-lxbase-and-more">Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More</a> <em>(TrendAI)</em></li><li><a href="https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation">Aurora ransomware targets ESXi abuses Cursor Agent for exploitation</a> <em>(Gambit Security)</em></li><li><a href="https://home.treasury.gov/news/press-releases/sb0615/">Treasury Announces the Quantum-Readiness Task Force</a> <em>(U.S. Department of the Treasury)</em></li><li><a href="https://medium.com/jigsaw/closing-a-critical-internet-privacy-gap-for-billions-of-users-android-17-rolls-out-ech-support-c52b49a62c04">Just aClosing a Critical Internet Privacy Gap for Billions of Users: Android 17 Rolls Out ECH Support</a> <em>(Jigsaw)</em></li><li><a href="https://dti.domaintools.com/research/threat-intelligence-report-university-leak-exposes-russias-military-cyber-training-pipeline">Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline</a> <em>(DomainTools)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-30.mp3" length="6926045" type="audio/mpeg"/>
      <itunes:duration>7:12</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-29.html</link>
      <pubDate>Sat, 29 Aug 2026 06:03:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260829_060302</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cert.at/en/blog/2026/8/increased-fraud-attempts-through-bec">CERT.at Increased fraud attempts through BEC</a> <em>(CERT.at)</em></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/">Declaring a National Emergency to Secure the United States Bulk-Power System</a> <em>(The White House)</em></li><li><a href="https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices">Disruptive cyber activity highlights risk from internet-exposed systems and edge devices</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://v12.sh/blog/signal">Compromising Signal's Contact Discovery Enclave</a> <em>(Verabit Labs Ltd)</em></li><li><a href="https://github.com/tailscale/tailcat">tailcat: like netcat, but over Tailscale's data plane, without Tailscale's control plane</a> <em>(Tailscale)</em></li><li><a href="https://aaroncti.com/osintclaw-part-2-can-an-ai-agent-threat-hunt/">OSINTClaw Part 2: Can an AI Agent Threat Hunt?</a> <em>(AaronCTI)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-29.mp3" length="2554192" type="audio/mpeg"/>
      <itunes:duration>2:39</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-28.html</link>
      <pubDate>Fri, 28 Aug 2026 06:08:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260828_060845</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.reuters.com/business/openai-report-says-its-network-was-hacked-by-its-own-rogue-ai-agents-2026-08-26/">OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find</a> <em>(Reuters)</em></li><li><a href="https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/">VMs won't contain cyber-capable agents - "The agent was started outside the VM, given SSH access into the VM environment, and permitted to do anything inside the VM."</a> <em>(Trail of Bits)</em></li><li><a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers">Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure</a> <em>(United States Department of Justice)</em></li><li><a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4583539/nsa-joins-fbi-in-issuing-warning-about-chinese-hacking-group-qtfy-cyber-activity/">NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity</a> <em>(National Security Agency/Central Security Service)</em></li><li><a href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model">Inside China-nexus cyber espionage infrastructure</a> <em>(Lumen Technologies)</em></li><li><a href="https://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/">Tortoiseshell: New Toolset and Operational Infrastructure Exposed</a> <em>(Group-IB)</em></li><li><a href="https://en.yna.co.kr/view/AEN20260820010900320">Chinese national gets 20 years for hacking accounts of BTS' Jungkook, others | Yonhap News Agency</a> <em>(Yonhap News Agency)</em></li><li><a href="https://github.com/hypnguyen1209/log4j2-rce">log4j2-rce: Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2</a> <em>(hypnguyen1209)</em></li><li><a href="https://www.pruva.dev/research/log4j2-serialized-event-filter-boundary">Not Another Log4Shell: A Serialized-Event Receiver Boundary</a> <em>(Pruva)</em></li><li><a href="https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52923-RHEL-6.12.0-211.7.3.el10_2">CyberMeowfia:  13-year-old UAF in Red Hat Enterprise Linux 10: CVE-2026-52923. - It was introduced in Jan 2013 and fixed upstream in May 2026, backported to RHEL on Aug 11 - local priv esc</a> <em>(NebuSec)</em></li><li><a href="https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-52933-Fedora-6.19.10-300">CyberMeowfia: Fedora 44, a signedness in io_uring, CVE-2026-52933 - It was introduced in Nov 2022 and fixed upstream in Apr 2026 - local priv esc</a> <em>(NebuSec)</em></li><li><a href="https://github.com/Sizeable-Bingus/MassDriver">MassDriver: Proxying sensitive API calls from shellcode to artifact for CET compatible clean call stacks.</a> <em>(Sizeable-Bingus)</em></li><li><a href="https://falconforce.nl/in-your-logs-now/">I'm in your logs now: deceiving analysts and blinding EDRs</a> <em>(FalconForce B.V.)</em></li><li><a href="https://securityjoes.com/blog/exploiting-smtp-with-unicode-bidi-override-spoofing-the-gap-between-auth-and-render">Exploiting SMTP with Unicode Bidi Override Spoofing: The Gap Between Auth &amp; Render</a> <em>(Security Joes)</em></li><li><a href="https://detect.fyi/threat-hunting-using-pair-probabilities-55194ddb8309">Threat Hunting using Pair Probabilities</a> <em>(Stamatis Chatzimangou)</em></li><li><a href="https://www.cisa.gov/resources-tools/resources/exposure-reduction">Internet Exposure Reduction Guidance</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://blog.tetrane.com/downloads/Tetrane_PatchGuard_Analysis_RS4_v1.00.pdf">Updated Analysis of PatchGuard on  Microsoft Windows 10 RS4: A use case of REVEN, the Timeless Analysis Tool</a> <em>(eShard)</em></li><li><a href="https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/">Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images</a> <em>(Xusheng Li)</em></li><li><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident</a> <em>(Model Evaluation and Threat Research (METR))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-28.mp3" length="9340177" type="audio/mpeg"/>
      <itunes:duration>9:43</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-27.html</link>
      <pubDate>Thu, 27 Aug 2026 06:04:18 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260827_060418</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.politico.eu/article/hackers-target-eu-officials-whatsapp/">State-backed hackers targeted EU officials on WhatsApp, document shows</a> <em>(Politico)</em></li><li><a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/">ClickFix, EtherHiding &amp; a DPRK Wallet Trail</a> <em>(Allsecure)</em></li><li><a href="https://www.justice.gov/usao-ne/pr/venezuelan-man-sentenced-8-years-prison-atm-jackpotting">Venezuelan Man Sentenced to 8 Years in Prison for ATM Jackpotting Following Homeland Security Task Force Initiative</a> <em>(United States Attorney's Office for the District of Nebraska)</em></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a">A Tale of Two SOCs: Insights From Two Red Team Assessments</a> <em>(Cybersecurity &amp; Infrastructure Security Agency (CISA))</em></li><li><a href="https://www.youtube.com/watch?v=0OQyA8LKJ8E">CYBERUK 2026 Tech Talk - How to justify security investments with actual evidence</a> <em>(Jawed Karim)</em></li><li><a href="https://objective-see.org/blog/blog_0x89.html?v=1">Detecting (Evil) Dylibs</a> <em>(Objective-See Foundation)</em></li><li><a href="https://github.com/airbus-cert/ditto">ditto: Powershell &amp; Javascript Obfuscator</a> <em>(Airbus)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-27.mp3" length="2809147" type="audio/mpeg"/>
      <itunes:duration>2:55</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-26.html</link>
      <pubDate>Wed, 26 Aug 2026 06:04:37 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260826_060437</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/">BengalSEO Part 1: Anatomy of the Operation</a> <em>(The DFIR Report)</em></li><li><a href="https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce">Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck</a> <em>(VulnCheck)</em></li><li><a href="https://dhakal-ananda.com.np/misc/more-criticals-less-dopamine/">More Criticals, Less Dopamine</a> <em>(Ananda Dhakal)</em></li><li><a href="https://dadrian.io/blog/posts/whack-a-mole-is-losing/">Playing whack-a-mole is losing</a> <em>(David Adrian)</em></li><li><a href="https://github.com/AlloySecureGroup/MADHATTER/">MADHATTER: Gradient-Guided Token Perturbation for Qwen - MadHatter can be used as a defensive disruption layer against an offensive Qwen-based AI agent by introducing small, targeted token changes</a> <em>(AlloySecureGroup)</em></li><li><a href="https://github.com/Paradoxis/DNSRPC-BOF">DNSRPC-BOF: Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by using MS-DNSP.</a> <em>(Paradoxis)</em></li><li><a href="https://sigreturn.com/papers/time-as-a-key/">Time as a Key: Breaking Rhysida Ransomware with the Attacker's Own Ciphertext</a> <em>(Adam Taguirov)</em></li><li><a href="https://github.com/VollRagm/ghostdebug/">ghostdebug: Debugger utilizing stealth hooks to hide from debugger detection</a> <em>(VollRagm)</em></li><li><a href="https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/">SLEEPWALKER: A Passive Backdoor With Its Own Command Language</a> <em>(Dominik Reichel)</em></li><li><a href="https://securitylabs.datadoghq.com/articles/detection-primitives-for-ebpf-rootkits/">Detection primitives for eBPF rootkits</a> <em>(Datadog Security Labs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-26.mp3" length="3734091" type="audio/mpeg"/>
      <itunes:duration>3:53</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-25.html</link>
      <pubDate>Tue, 25 Aug 2026 06:05:44 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260825_060544</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ncsc.govt.nz/news/new-zealanders-urged-to-take-care-as-cyber-security-incidents-become-more-complex/">New Zealanders urged to take care as cyber security incidents become more complex</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://www.synacktiv.com/en/publications/aws-eks-forensics-data-sources-and-investigation-tooling">AWS EKS forensics: data sources and investigation tooling</a> <em>(Synacktiv)</em></li><li><a href="https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/">Auditing Microsoft Defender and Intune Configuration Changes</a> <em>(Jeffrey Appel)</em></li><li><a href="https://www.irregular.com/research/assessing-kimi-k3-against-offensive-security-benchmarks">Assessing Kimi K3 Against Offensive Security Benchmarks</a> <em>(Irregular)</em></li><li><a href="https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/redc2-ai-powered-linux-implant">Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant</a> <em>(TrendAI)</em></li><li><a href="https://www.cloudsek.com/blog/bridgehead-npm-typosquatting-wsl-windows-crypto-wallet-stealer">BRIDGEHEAD : An npm typosquatting campaign that crosses from WSL into Windows to plant a crypto-wallet stealer</a> <em>(CloudSEK)</em></li><li><a href="https://github.com/ThisIsTFS/Rogue-Framework">GitHub - ThisIsTFS/Rogue-Framework: The Exploit Developers BurpSuite</a> <em>(ThisIsTFS)</em></li><li><a href="https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026">We burned 11.7bn tokens to find the best cyber AI model | GLM5.3 and DeepSeek are now frontier</a> <em>(Aikido)</em></li><li><a href="https://tmpout.sh/5/">tmpout_v</a> <em>(genetix)</em></li><li><a href="https://corelight.com/blog/the-cure-for-exceptional-zeek-package-testing-part-3">The Cure for Exceptional Zeek Package Testing (Part 3) | Corelight</a> <em>(Corelight)</em></li><li><a href="https://corelight.com/blog/the-cure-for-exceptional-zeek-package-testing-part-2">The Cure for Exceptional Zeek Package Testing (Part 2) | Corelight</a> <em>(Corelight)</em></li><li><a href="https://corelight.com/blog/the-cure-for-exceptional-zeek-package-testing-part-1">The Cure for Exceptional Zeek Package Testing (Part 1) | Corelight</a> <em>(Corelight)</em></li><li><a href="https://github.com/evets007/natural-language-nmap">natural-language-nmap: Experimental SLM fine tune project. CPU only local model converts natural language into nmap commands.</a> <em>(evets007)</em></li><li><a href="https://blog.n0p.me/2026/08/2026-08-21-fortitool-fortios-decryption/">fortitool: cracking FortiOS firmware end to end, and a key nobody had</a> <em>(Ali Mosajjal)</em></li><li><a href="https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html">Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding</a> <em>(NetbyteSEC Sdn. Bhd.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-25.mp3" length="4553709" type="audio/mpeg"/>
      <itunes:duration>4:44</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-24.html</link>
      <pubDate>Mon, 24 Aug 2026 06:08:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260824_060823</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>21</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/">N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it</a> <em>(Datadog)</em></li><li><a href="https://securelist.com/android-head-unit-malware/121106/">First Android malware targeting automotive head units</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://kfhsgw.hateblo.jp/entry/2025/08/04/185654">无糖信息(NoSugarTech): about Chinese company  NoSugarTech has been featured in multiple past reports, and analysis and investigation of i-SOON's leaked data have also mentioned its connection to China</a> <em>(misaki)</em></li><li><a href="https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia">Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia</a> <em>(ENKI WhiteHat)</em></li><li><a href="https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack">Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack</a> <em>(Aikido)</em></li><li><a href="https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/">Supply chain attack on arrayref | Rust Blog</a> <em>(The Rust Project)</em></li><li><a href="https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/">Malicious Rust Crate arrayref Runs a Build-Time Payload</a> <em>(SafeDep)</em></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a">Defending Against an Active Threat to Siemens S7 Series PLCs</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://www.esentire.com/blog/malware-as-a-service-cocktail-errtraffic-and-cruciferra-killing-your-edr-since-2025">Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025</a> <em>(eSentire)</em></li><li><a href="https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/">SynkLoader: when you throw in everything but the kitchen sink</a> <em>(Expel)</em></li><li><a href="https://sibouzitoun.tech/articles/smap-is-pre-disarmed/">SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn't Work Revealed a Kernel-Wide Design Compromise</a> <em>(Youssef Charfeddine)</em></li><li><a href="https://blog.amberwolf.com/blog/2026/august/weaponising-windows-mdm/">NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment</a> <em>(AmberWolf)</em></li><li><a href="https://github.com/Dovughs/mora-hwbp">mora-hwbp: Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking &amp; telemetry instrumentation engine (AMSI, WLDP &amp; ETW PoC).</a> <em>(Dovughs)</em></li><li><a href="https://blog.amberwolf.com/blog/2026/august/tag-youre-managed---executing-code-via-googles-own-signed-installer/">Tag, You're Managed - Executing Code via Google's Own Signed Installer</a> <em>(AmberWolf)</em></li><li><a href="https://github.com/mgreen27/DetectRaptor/blob/master/vql/ChromiumExtensionPersistence.yaml">VQL: Hunts Chromium profiles for enabled unpacked extensions and Native Messaging Host registrations associated with Chromium extension persistence</a> <em>(Matt Green)</em></li><li><a href="https://github.com/sunlife3/needre">needre: Self-made toy EDR project using AYA the Rust eBPF library</a> <em>(sunlife3)</em></li><li><a href="https://arxiv.org/abs/2608.17154">Beyond the Hype: Evaluating LLM Integration and Practical Limitations in Security Operation Centers</a> <em>(Elnaz Rabieinejad, Ali Dehghantanha, Fattane Zarrinkalam, and Sarina Dastgerdy)</em></li><li><a href="https://github.com/xoreaxeaxeax/hexcymatix">hexcymatix: patterns hiding in plain byte - You want similarity without specification.</a> <em>(Christopher Domas)</em></li><li><a href="https://github.com/horsicq/XPEViewer">XPEViewer: PE file viewer/editor for Windows, Linux and MacOS.</a> <em>(horsicq)</em></li><li><a href="https://github.com/Whispergate/lldp">lldp: Mythic Peer to Peer (P2P) Communication Protocol via. LLDP</a> <em>(Whispergate)</em></li><li><a href="https://www.nccgroup.com/media/1mzfvyzl/nccgroup_cve-2025-22226.pdf">Vulnerability Analysis of CVE-2025-22226: Information Disclosure Due to OOB Read in VMware’s HGFS</a> <em>(NCC Group)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-24.mp3" length="8299041" type="audio/mpeg"/>
      <itunes:duration>8:38</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-23.html</link>
      <pubDate>Sun, 23 Aug 2026 06:04:34 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260823_060434</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/">UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities</a> <em>(Cisco Talos Intelligence Group)</em></li><li><a href="https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/">UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations</a> <em>(Cisco)</em></li><li><a href="https://arxiv.org/abs/2608.17671">Benchmarking Automated Security Patch Backporting: How Far Are We?</a> <em>(Cornell University)</em></li><li><a href="https://arxiv.org/abs/2608.18686">Improving LLM-Based SSH Honeypots Through Prompting and Fine-Tuning</a> <em>(Muris Sladić, Veronica Valeros, Eman Alibalić, and Sebastian Garcia)</em></li><li><a href="https://arxiv.org/abs/2608.19011">From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation</a> <em>(Sepehr Ghaffarzadegan, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, and Chadi Assi)</em></li><li><a href="https://arxiv.org/abs/2608.19938">From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs</a> <em>(Cornell University)</em></li><li><a href="https://lina.sh/blog/hijacking-e164-arpa">I accidentally logged hundreds of thousands of phone calls to military bases</a> <em>(Lina)</em></li><li><a href="https://arxiv.org/abs/2608.18613">CTIFoundry: An Agent-Native Corpus Scaffold for Cyber Threat Intelligence</a> <em>(Yutong Cheng, Changze Li, Qian Cui, Wei Ding, Lingzhi Wang, Yan Chen, and Peng Gao)</em></li><li><a href="https://zerotistic.blog/posts/find-my-people-linux/">Reverse-engineering Find My People to stalk  ̶m̶y̶ ̶e̶x̶  a friend, cause I can</a> <em>(Zerotistic)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-23.mp3" length="3874525" type="audio/mpeg"/>
      <itunes:duration>4:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-22.html</link>
      <pubDate>Sat, 22 Aug 2026 06:04:18 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260822_060418</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ibm.com/think/x-force/trapping-a-mustang-panda">Trapping a Mustang Panda</a> <em>(IBM)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia">Distinct Clusters Target Individuals of Interest to Russia</a> <em>(Google)</em></li><li><a href="https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-overlap-with-dprk-campaigns">Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns | Wiz Blog</a> <em>(Wiz)</em></li><li><a href="https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/">A revisit of remote Spectre attacks on Cloudflare Workers</a> <em>(Cloudflare)</em></li><li><a href="https://bitbison.io/blog/langflow-rce-exposure/">Langflow RCE: 34 minutes to server compromise</a> <em>(Bitbison)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai">Managing the cyber risk of agentic AI</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://www.bloomberg.com/news/newsletters/2026-08-19/t-mobile-cyber-staff-chopped-cable-after-finding-chinese-hack">T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network</a> <em>(Bloomberg)</em></li><li><a href="https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/">BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://weedhashpeddler.medium.com/every-antivirus-and-edr-product-depends-on-freshness-28b0fa9c810d">MS-Nightmare Un-defend v2 — What Happens When Signatures Can’t Land</a> <em>(WeedHashPeddler)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-22.mp3" length="3655097" type="audio/mpeg"/>
      <itunes:duration>3:48</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-21.html</link>
      <pubDate>Fri, 21 Aug 2026 06:03:18 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260821_060318</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.rusi.org/explore-our-research/publications/research-papers/north-korean-crypto-fiat-activity">North Korean Crypto-to-Fiat Activity</a> <em>(Royal United Services Institute (RUSI))</em></li><li><a href="https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia">SilkParasite: Tracking a China-Nexus APT Across Central Asia</a> <em>(Bitdefender)</em></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a">Defending Against an Active Threat to Siemens S7 Series PLCs</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/">BOFScale: A CDN-Fronted Tailnet from a BOF-PE</a> <em>(NetSPI)</em></li><li><a href="https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/">Describing attacks with crime script analysis</a> <em>(Cisco Talos)</em></li><li><a href="https://arxiv.org/abs/2606.21037">Honeyquest for LLMs: Rethinking Cyber Deception for AI Attackers</a> <em>(Horizon3.ai)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-21.mp3" length="2884798" type="audio/mpeg"/>
      <itunes:duration>3:00</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-20.html</link>
      <pubDate>Thu, 20 Aug 2026 06:08:10 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260820_060810</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ic3.gov/CSA/2026/260818.pdf">#StopRansomware: Medusa Ransomware</a> <em>(Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, and Department of Health and Human Services)</em></li><li><a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary">17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities</a> <em>(United States Department of Justice)</em></li><li><a href="https://go.rewardsforjustice.net/mabna-en/">$10,000,000 USD FOR INFORMATION ON  Iranian Hackers</a> <em>(U.S. Department of State)</em></li><li><a href="https://www.seqrite.com/blog/operation-quicsilver-china-nexus-actor-targets-myanmar-diplomats-via-vhd-delivered-go-backdoor/">Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor | Seqrite</a> <em>(Quick Heal Technologies Limited)</em></li><li><a href="https://github.com/blackorbird/APT_REPORT/blob/master/group123/20260727-Threat-Report-Analysis-Samples-APT37-Strikes-Again-This-Time-with-NarwhalRAT.pdf">APT37 Strikes Again, This Time with NarwhalRAT</a> <em>(blackorbird)</em></li><li><a href="https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations">PurpleDelta's Fraudulent Employment Operations</a> <em>(Recorded Future)</em></li><li><a href="https://insights.bridewell.com/hubfs/Reports/Defending%20Against%20DPRK%20IT%20Workers%20-%20An%20Implementation%20and%20Operational%20Guide.pdf">Defending Against DPRK IT Workers – An Implementation and Operational Guide</a> <em>(Bridewell)</em></li><li><a href="https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/">Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect - Check Point Research</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://arma.gov.ua/news/typical/sogodni-serveri-arma-zaznali-hakerskoi-ataki-vedetsya-slidstvo">Сьогодні сервери АРМА зазнали хакерської атаки. Ведеться слідство - Today, ARMA servers were attacked by hackers. An investigation is underway.</a> <em>(Агентство з розшуку та менеджменту активів)</em></li><li><a href="https://www.computerweekly.com/news/366649396/Revealed-Cyber-spies-used-malware-from-GitHub-to-hack-EncroChat-cryptophone-network">Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network</a> <em>(TechTarget)</em></li><li><a href="https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/">Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 &amp; Azure</a> <em>(Ontinue)</em></li><li><a href="https://msil.re/posts/reversing-malwarebytes-browser-guard.html">Reverse engineering Malwarebytes Browser Guard | msil.re</a> <em>(miltinh0c)</em></li><li><a href="https://github.com/PatchRequest/BusyWork">BusyWork: Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems</a> <em>(PatchRequest)</em></li><li><a href="https://github.com/loosehose/DutchOven">DutchOven: Application-scoped Windows network brownouts in native C and BOF form</a> <em>(loosehose)</em></li><li><a href="https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii">smiiiiiiiiiiiiiiii: Exploiting System Management Mode with a very very very very very very very long interrupt.</a> <em>(Christopher Domas)</em></li><li><a href="https://www.exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11">IDT Table Hijacking under VBS/HVCI/kCET in Windows 11</a> <em>(Exploit Pack)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-20.mp3" length="5616161" type="audio/mpeg"/>
      <itunes:duration>5:50</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 19, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-19.html</link>
      <pubDate>Wed, 19 Aug 2026 06:01:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260819_060131</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-hunts-for-shell-command-obfuscation-vmware-esx/">Threat Hunts for Shell Command Obfuscation on VMware ESX</a> <em>(CrowdStrike)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-19.mp3" length="847247" type="audio/mpeg"/>
      <itunes:duration>0:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-18.html</link>
      <pubDate>Tue, 18 Aug 2026 06:08:37 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260818_060837</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.usenix.org/system/files/usenixsecurity26-ablove.pdf">Technical Analysis of the Geedge Networks Firewall Source Code Leak</a> <em>(USENIX Association)</em></li><li><a href="https://www.picussecurity.com/resource/blog/dragon-breath-apt-q-27-roningloader-and-gh0st-rat-explained">Dragon Breath (APT-Q-27): RONINGLOADER and Gh0st RAT Explained</a> <em>(Picus Security)</em></li><li><a href="https://plausible-deniability.co/blog/PullingTheThread-LeroyMerlin/">Pulling the Thread: APT should not usurp the identity of Leroy Merlin or there will be consequences</a> <em>(Axel Z.)</em></li><li><a href="https://blog.bushidotoken.net/2026/07/uk-cybercrime-journal-qilin-ransomware.html">UK Cybercrime Journal: Qilin Ransomware Rampage in H1 2026</a> <em>(BushidoToken)</em></li><li><a href="https://pushsecurity.com/blog/browser-threat-landscape-mid-year-update-2026">How browser attacks are evolving in 2026 so far</a> <em>(Push Security)</em></li><li><a href="https://github.com/kevingosse/windbg-bridge">windbg-bridge: windbg-bridge connects a live WinDbg session to AI agents like Claude Code or Codex through a named pipe. The agent can run debugger commands, read your command history, and watch outpu</a> <em>(Kevin Gosse)</em></li><li><a href="https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/">Signed, sealed, injected: The mechanics of DCRat in 2026</a> <em>(Trellix)</em></li><li><a href="https://www.vmray.com/deleting-the-defenders-a-commodity-byovd-toolkit-that-erases-host-safeguards/">Deleting the Defenders: A Commodity BYOVD Toolkit That Erases Host Safeguards</a> <em>(VMRay)</em></li><li><a href="https://www.gendigital.com/blog/insights/research/the-phishing-link-that-died-on-purpose">The phishing link that died on purpose</a> <em>(Gen Digital)</em></li><li><a href="https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data">ExfilSquad: New Data Extortion Group Leaks Microsoft D365 Data, Likely Linked to Misconfigured Power Pages</a> <em>(Fortra)</em></li><li><a href="https://www.varonis.com/blog/ws-trust-autologon-endpoint">WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking</a> <em>(Varonis)</em></li><li><a href="https://ridgelinecyber.com/blog/mac-with-no-malware-consent-attack-path/">The Mac With No Malware On It: When Consent Is the Attack Path</a> <em>(Ridgeline Cyber Defence)</em></li><li><a href="https://systemweakness.com/detecting-macos-gatekeeper-quarantine-attribute-removal-with-sigma-ae27fc60814c">Detecting macOS Gatekeeper Quarantine Attribute Removal with Sigma</a> <em>(Medium)</em></li><li><a href="https://academy.bluraven.io/blog/device-roles-in-microsoft-defender-xdr">Device Roles in Microsoft Defender XDR: Better Context for Threat Hunting and Detection Engineering</a> <em>(Blu Raven Academy)</em></li><li><a href="https://www.stark4n6.com/2026/08/consensual-forensics-with-android.html">Consensual Forensics with Android Intrusion Logging</a> <em>(Kevin Pagano)</em></li><li><a href="https://github.com/r3nzsec/irflow-timeline/releases/tag/v1.0.10">Release IRFlow Timeline 1.0.10 · adds ChatGPT Computer History as a new forensic artifact family,</a> <em>(r3nzsec)</em></li><li><a href="https://www.cke-ltd.com/blog-1/announcement-nist-artcat">NIST Digital Forensics Artifact Catalog: Where Digital Evidence Becomes Forensic Science</a> <em>(CKE Ltd.)</em></li><li><a href="https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/">ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act</a> <em>(ETSI)</em></li><li><a href="https://words.filippo.io/128-bits/">Quantum Computers Are Not a Threat to 128-bit Symmetric Keys</a> <em>(Filippo Valsorda)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-18.mp3" length="7358215" type="audio/mpeg"/>
      <itunes:duration>7:39</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-17.html</link>
      <pubDate>Mon, 17 Aug 2026 06:10:12 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260817_061012</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>26</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/">Expired Malicious Domains Bring New Threats to Life</a> <em>(Infoblox)</em></li><li><a href="https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/?kaspr=sv8c">CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://www.youtube.com/watch?v=a5hvDNZeRIw">ETW for Security Research: Providers, Sessions, and Detection Engineering</a> <em>(Idov31)</em></li><li><a href="https://github.com/seifreed/CipherRun">CipherRun: A Fast, Modular, and Scalable TLS/SSL Security Scanner Written in Rust</a> <em>(Marc Rivero)</em></li><li><a href="https://github.com/Cloud-Architekt/AzurePrivilegedIAM">AzurePrivilegedIAM: Docs and samples for privileged identity and access management in Microsoft Azure and Microsoft Entra.</a> <em>(Cloud-Architekt)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and-devices">How BitLocker PINs help protect your data and devices</a> <em>(National Cyber Security Centre)</em></li><li><a href="https://github.com/FoxIO-LLC/ja4/tree/main/zeek">JA4+ for Zeek  - A compiled Zeek plugin implementing JA4+ network fingerprinting. Replaces the pure-script implementation with C++ BiF functions for performance-critical fingerprints.</a> <em>(FoxIO-LLC)</em></li><li><a href="https://e.vnexpress.net/news/news/how-a-self-taught-vietnamese-high-schooler-built-the-malware-that-infected-94-000-computers-worldwide-5055184.html">How a self-taught Vietnamese high schooler built the malware that infected 94,000 computers worldwide - VnExpress International</a> <em>(VnExpress)</em></li><li><a href="https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward">Addressing Recent Incidents: Ongoing Findings and Path Forward - Irregular</a> <em>(Irregular)</em></li><li><a href="https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia">Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia</a> <em>(Dream)</em></li><li><a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr">Akira Hits Safe Mode: Ransomware Rebooting Around EDR</a> <em>(Huntress)</em></li><li><a href="https://www.pillar.security/blog/lose-control-flow-unauthenticated-tool-execution-in-dolt-mcp">Lose Control Flow: Unauthenticated Tool Execution in Dolt MCP</a> <em>(Pillar Security)</em></li><li><a href="https://github.com/Exploit-Garbage/0day-Rubbish">0day-Rubbish: Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly</a> <em>(Exploit-Garbage)</em></li><li><a href="https://github.com/lem0nSec/SgrmFault">SgrmFault: Process Impairment Exploit Chain.</a> <em>(Angelo Frasca Caccia and Alejandro Pinna)</em></li><li><a href="https://zerotracelab.com/blog/chrome-remote-desktop-red-ops">Turning Chrome Remote Desktop into Pure Red Team Ops</a> <em>(ZeroTrace Lab)</em></li><li><a href="https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse">Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse</a> <em>(Akamai)</em></li><li><a href="https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/">AmnesiaStealer: macOS Infostealer That Hijacks Browsers</a> <em>(Jamf)</em></li><li><a href="https://www.gendigital.com/blog/insights/research/kb-backdoor">A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace</a> <em>(Gen Digital)</em></li><li><a href="https://github.com/0xaled/Vipere">Vipere: BOF exploiting the Visual Studio Installer Elevation Service for SYSTEM LPE and persistence via AppDomainManager hijacking, with native ETW evasion. For Cobalt Strike &amp; Adaptix.</a> <em>(0xaled)</em></li><li><a href="https://github.com/splintersfury/KernelSight">KernelSight: Windows kernel driver exploitation knowledge base — 28 case studies organized by driver type, grounded in real CVEs with build numbers and PoC references</a> <em>(splintersfury)</em></li><li><a href="https://github.com/bugbasesecurity/pentest-copilot">pentest-copilot: Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.</a> <em>(Bugbase)</em></li><li><a href="https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/">Kimwolf v7: An Evolution of the Kimwolf Botnet</a> <em>(Palo Alto Networks)</em></li><li><a href="https://github.com/sh1katagana1/ai/blob/main/using-codex-for-email-investigations/codex-tutorial.md">Using Codex for Email Investigations</a> <em>(sh1katagana1)</em></li><li><a href="https://www.straitstimes.com/asia/taiwan-throttles-mobile-internet-speeds-in-defence-drill">Taiwan’s internet blackout drill tests cyberattack readiness</a> <em>(SPH Media Trust)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/water-sector-example-added-to-the-ncscs-secure-connectivity-principles">Water sector example added to the NCSC’s Secure connectivity principles</a> <em>(National Cyber Security Centre)</em></li><li><a href="https://connormcgarr.github.io/securitytrace-etw-ppl/">Windows Internals: Check Your Privilege - The Curious Case of ETW’s SecurityTrace Flag</a> <em>(Connor McGarr)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-17.mp3" length="9635257" type="audio/mpeg"/>
      <itunes:duration>10:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-16.html</link>
      <pubDate>Sun, 16 Aug 2026 06:09:05 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260816_060905</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.antonlovesdnb.com/blog/aten">ATEN: Endpoint Telemetry for AI Coding Agents | Anton Ovrutsky</a> <em>(Anton Ovrutsky)</em></li><li><a href="https://dirkjan.ochtman.nl/writing/2026/08/13/announcing-oxish.html">OxiSH: a modern, memory-safe SSH server – Dirkjan Ochtman</a> <em>(Dirkjan Ochtman)</em></li><li><a href="https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/">Microsoft SharePoint JWT Token Authentication Bypass Technical Analysis (CVE-2026-55040)</a> <em>(Rapid7)</em></li><li><a href="https://blog.viettelcybersecurity.com/sharepoint-cve-2026-55040/">CVE-2026-55040: SharePoint Server Subscription Edition improper JWT validation lead to Arbitrary Account Login</a> <em>(Viettel Group)</em></li><li><a href="https://github.com/MSNightmare/ShieldBreak">ShieldBreak: Windows Defender 0day vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/">IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay</a> <em>(mysk.blog)</em></li><li><a href="https://testbnull.medium.com/hunting-exchange-server-0day-like-a-detective-3fd5e0dc9779">Hunting Exchange Server 0day like a detective</a> <em>(Jang &amp; Mugmug of MB VRED)</em></li><li><a href="https://www.nist.gov/blogs/cybersecurity-insights/shaping-nvd-future-we-need-your-feedback-ai-enabled-vulnerability">Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management</a> <em>(National Institute of Standards and Technology)</em></li><li><a href="https://andrewkwong.org/docs/keytar-camera.pdf">KeyTAR: Practical Keystroke Timing Attacks and Input Reconstruction</a> <em>(University of North Carolina at Chapel Hill)</em></li><li><a href="https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/">Return of the Cookie Monster</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/KriyosArcane/TrustMeBro">TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types etc.</a> <em>(KriyosArcane)</em></li><li><a href="https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence/">Attack of The Extensions</a> <em>(SpecterOps)</em></li><li><a href="https://portswigger.net/research/css-the-bomb-inside-your-inbox">CSS:the bomb inside your inbox</a> <em>(PortSwigger)</em></li><li><a href="https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware">Fake CCleaner installs GhostDesk Chrome spyware</a> <em>(Malwarebytes)</em></li><li><a href="https://z.ai/blog/glm-5.3">GLM-5.3: Frontier Coding with Emergent Cyber Capabilities</a> <em>(Z.AI Co., Ltd.)</em></li><li><a href="https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/">Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders</a> <em>(SpecterOps)</em></li><li><a href="https://minorimpact.dev/posts/dark-agent-coff-loader/">Dark: A Mythic C2 Agent with In-Memory BOF Execution on macOS and Linux, Part 1 · Minor Impact</a> <em>(Royce Davis)</em></li><li><a href="https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/">Dissecting the JWR phishing framework</a> <em>(Cisco Talos)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-16.mp3" length="7224050" type="audio/mpeg"/>
      <itunes:duration>7:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-15.html</link>
      <pubDate>Sat, 15 Aug 2026 06:02:56 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260815_060256</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.quarkslab.com/bypassing-android-hardware-attestation.html">Bypassing Android Hardware Attestation from the Analyst's Chair - Quarkslab's blog</a> <em>(Quarkslab)</em></li><li><a href="https://hackers-arise.com/digital-forensics-attacking-sam-and-extracting-hashes-with-7z/">Digital Forensics: Attacking SAM and Extracting Hashes With 7z</a> <em>(Master OTW (Occupy the Web))</em></li><li><a href="https://cseweb.ucsd.edu/~savage/papers/UsenixSec26-429.pdf">Design and Implementation of a Physical Implant Attack on the Boeing 737</a> <em>(Stefan Savage)</em></li><li><a href="https://github.com/xoreaxeaxeax/skitter-creek-bath-salts">skitter-creek-bath-salts: Unlocking _everything_ on the CPU with DRAM scrambling</a> <em>(Christopher Domas)</em></li><li><a href="https://www.recordedfuture.com/research/malware-crypting-services-threat-actors">Malware Crypting Services and the Threat Actors Who Sell Them</a> <em>(Recorded Future)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-15.mp3" length="2191404" type="audio/mpeg"/>
      <itunes:duration>2:16</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-14.html</link>
      <pubDate>Fri, 14 Aug 2026 06:02:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260814_060216</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign">Deadbugz: Currently Active MCP Supply-Chain Campaign</a> <em>(Pillar Security)</em></li><li><a href="https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa">Bybit Sues North Korea and Lazarus Group, Secures Preliminary Injunction Freezing Stolen Assets in Landmark Crypto Asset Recovery Effort</a> <em>(Bybit)</em></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/">Expanding Capabilities to Combat Transnational Cyber-Enabled Crime</a> <em>(The White House)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-14.mp3" length="1569062" type="audio/mpeg"/>
      <itunes:duration>1:37</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-13.html</link>
      <pubDate>Thu, 13 Aug 2026 06:03:19 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260813_060319</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide">Com group member sentenced for campaign of abuse against 117 victims worldwide</a> <em>(National Crime Agency)</em></li><li><a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/">Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack - Check Point Research</a> <em>(Check Point Research)</em></li><li><a href="https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/">Updated GPG key for signing Firefox and Thunderbird Releases – Mozilla Security Blog</a> <em>(Mozilla)</em></li><li><a href="https://blog.deception.pro/blog/clickfix-spacex1337-hok-2026">[Op Report] From ClickFix SpaceX1337 to Hands-on-Keyboard AD Attack</a> <em>(PKB Communications LLC)</em></li><li><a href="https://www.youtube.com/watch?v=QV0C-NQSjsg">Fabian Mosch: The Art of Evasion</a> <em>(Fabian Mosch)</em></li><li><a href="https://github.com/AlloySecureGroup/Horcrux">Horcrux: AI Agent Skill to build secure, resilient , recoverable storage using Tahoe-LFS</a> <em>(AlloySecureGroup)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-13.mp3" length="2365275" type="audio/mpeg"/>
      <itunes:duration>2:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-12.html</link>
      <pubDate>Wed, 12 Aug 2026 06:03:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260812_060302</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://zakird.com/papers/ip_sharing.pdf">IP sharing has steadily increased over the past decade, with fewer than 0.2% of domains using a unique IPv4 address and up to millions of domains co-located on single IP addresses.</a> <em>(Zakir Durumeric)</em></li><li><a href="https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads">Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads</a> <em>(Sonatype)</em></li><li><a href="https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit">Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a">#StopRansomware: Gunra Ransomware</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/">Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed</a> <em>(ANY.RUN)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-12.mp3" length="2463913" type="audio/mpeg"/>
      <itunes:duration>2:33</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-11.html</link>
      <pubDate>Tue, 11 Aug 2026 06:07:15 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260811_060715</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://aws.amazon.com/blogs/security/securing-your-amazon-s3-buckets-identifying-and-remediating-over-permissioned-access/">Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access | Amazon Web Services</a> <em>(Amazon Web Services (AWS))</em></li><li><a href="https://github.com/cracken-ai/blacksea">blacksea: Blacksea is an active honeypot and canary-bait control system built to detect and drown LLM-driven attackers. Blacksea doesn't stop at watching LLM attacks.</a> <em>(Cracken)</em></li><li><a href="https://www.youtube.com/watch?v=Q_pjxyQRAZ8">CYBERCOM 2.0</a> <em>(Department of War)</em></li><li><a href="https://github.com/alpha-omega-security/threat-model">threat-model: Agent skill for producing threat models for open-source projects</a> <em>(OpenSSF)</em></li><li><a href="https://github.com/semperis-community/resetnightmare">ResetNightmare: POC tool for ResetNightmare (CVE-2026-27912)</a> <em>(Semperis)</em></li><li><a href="https://www.safebreach.com/blog/python-in-excel-vulnerability-root-escalation-cve-2026-45459/">Python in Excel Vulnerability: Root Privilege Escalation &amp; Trusted Records Bypass</a> <em>(SafeBreach)</em></li><li><a href="https://specterops.io/blog/2026/08/05/weaponizing-windows-updates-with-notwsuspicious/">Weaponizing Windows Updates with NotWSUSpicious</a> <em>(SpecterOps)</em></li><li><a href="https://plugandpwn.com/">plugandpwn.com :: Plug and Pwn</a> <em>(Alejandro Hernando and Borja Martinez)</em></li><li><a href="https://shells.systems/abusing-extended-attributes-to-bypass-application-control-for-business/">Abusing Extended Attributes to Bypass Application Control For Business - Shells.Systems</a> <em>(Ian)</em></li><li><a href="https://www.dotsec.com/insecure-deserialisation-app-control-bypass/">Bypassing Windows application whitelisting | dotSec</a> <em>(DotSec)</em></li><li><a href="https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/">Head Mare доставляет бэкдоры PhantomCore и PhantomGraph через необновленный сервер TrueConf - The Head Mare APT group exploits vulnerabilities in an unupdated TrueConf server to deliver PhantomCore</a> <em>(АО «Лаборатория Касперского»)</em></li><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm">Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM</a> <em>(Genians)</em></li><li><a href="https://speakerdeck.com/sumeshi/forensia-rokarullmhuorenzitukuhanesu">FORENSIA: ローカルLLMフォレンジックハーネス - FORENSIA: Local LLM Forensics Harness</a> <em>(S.Nakano)</em></li><li><a href="https://github.com/icedracon/adhammer">adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack.</a> <em>(icedracon)</em></li><li><a href="https://github.com/0xwilliamortiz/claude-red">claude-red: claude-red is a curated library of offensive security skills designed for the Claude skills system.</a> <em>(William Ortiz)</em></li><li><a href="https://github.com/HotStartLabs/sift">sift: Credential and sensitive-data exposure triage for file shares</a> <em>(Panos Gkatziroulis)</em></li><li><a href="https://github.com/tadmaddad/Washizukami-Collector">Washizukami-Collector: Rust-based Fast Forensics Tool for Windows</a> <em>(tadmaddad)</em></li><li><a href="https://www.metabase.com/blog/security-update">Security update available for Metabase - Please upgrade now - We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58</a> <em>(Metabase)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-11.mp3" length="6307466" type="audio/mpeg"/>
      <itunes:duration>6:34</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-10.html</link>
      <pubDate>Mon, 10 Aug 2026 06:01:59 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260810_060159</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.riotgames.com/en/news/vanguard-on-demand">Incoming: Vanguard On-Demand - Microsoft built a Runtime Driver Attestation Report that lets Vanguard verify driver integrity without needing to be present at boot.</a> <em>(Riot Games)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-10.mp3" length="871906" type="audio/mpeg"/>
      <itunes:duration>0:54</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-09.html</link>
      <pubDate>Sun, 09 Aug 2026 06:07:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260809_060746</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://unn.ua/en/news/chinese-espionage-platform-active-in-13-countries-study">Chinese espionage platform active in 13 countries – study</a> <em>(Ukrainian National News (UNN))</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments">UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments</a> <em>(Google)</em></li><li><a href="https://www.news1.kr/society/court-prosecution/6251494">해커와 손잡고 랜섬웨어 피해자 상대 영업…데이터복구업체 대표 실형 - Data recovery company CEO sentenced to prison for partnering with hackers to target ransomware victims</a> <em>(News1)</em></li><li><a href="https://www.justice.gov/opa/pr/canadian-man-pleads-guilty-hacking-us-cloud-storage-provider-and-extorting-its-customers">Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions</a> <em>(U.S. Department of Justice)</em></li><li><a href="https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection">Coding agent security: Claude Code, tunnels and LaunchAgents</a> <em>(Elastic)</em></li><li><a href="https://www.promptarmor.com/resources/atlassian-rovo-exfiltrates-data">Atlassian Rovo Exfiltrates Data, Bypassing Controls</a> <em>(PromptArmor)</em></li><li><a href="https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/">AD Research: Two new vulnerabilities could lead to full domain takeover</a> <em>(Semperis)</em></li><li><a href="https://www.vulncheck.com/blog/zbt-endlessdoors">ENDLESSDOORS Is Phoning Home. Pick Up.</a> <em>(VulnCheck)</em></li><li><a href="https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/">OT Security Analysis: Exposed Devices Attacked in US Water Systems</a> <em>(Forescout)</em></li><li><a href="https://github.com/Meowmycks/EkkoNtProtect">EkkoNtProtect: Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks</a> <em>(Meowmycks)</em></li><li><a href="https://dirkjanm.io/borrowing-windows-hello-keys/">Borrowing Windows Hello keys for authentication and persistence</a> <em>(Dirk-jan Mollema)</em></li><li><a href="https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-2/">Turning Enterprise Update Servers Into Backdoor Factories (0_o) - Part 2</a> <em>(SpecterOps)</em></li><li><a href="https://detect.fyi/when-attackers-hijack-your-inbox-detecting-mailbox-forwarding-rules-with-microsoft-defender-xdr-56a71567c6f2">When Attackers Hijack Your Inbox: Detecting Mailbox Forwarding Rules with Microsoft Defender XDR</a> <em>(detect.fyi)</em></li><li><a href="https://www.elastic.co/security-labs/agentic-soc-alert-triage-alertzero">Alert Zero: Automate alert triage for the agentic SOC</a> <em>(Elastic)</em></li><li><a href="https://github.com/dmcxblue/ANIMO">ANIMO: ANIMO Azure Network Intel &amp; Mission Ops a C2 based on Azure/Entra assessments</a> <em>(dmcxblue)</em></li><li><a href="https://github.com/mverschu/SOCKSRelayd/">SOCKSRelayd: SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.</a> <em>(mverschu)</em></li><li><a href="https://github.com/Poly0n/WinGuard">WinGuard: A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.</a> <em>(Poly0n)</em></li><li><a href="https://www.justice.gov/usao-edva/pr/belarusian-leader-international-ransomware-scheme-known-ransom-cartel-sentenced-16">Belarusian leader of international ransomware scheme known as “Ransom Cartel” sentenced to 16 years in prison</a> <em>(U.S. Attorney's Office for the Eastern District of Virginia)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-09.mp3" length="7977213" type="audio/mpeg"/>
      <itunes:duration>8:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-08.html</link>
      <pubDate>Sat, 08 Aug 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260808_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.enisa.europa.eu/news/enisa-scales-up-its-role-in-the-cve-program">ENISA scales up its role in the CVE Program | ENISA</a> <em>(European Union Agency for Cybersecurity (ENISA))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-08.mp3" length="907851" type="audio/mpeg"/>
      <itunes:duration>0:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-07.html</link>
      <pubDate>Fri, 07 Aug 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260807_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">QuickFox Supply Chain Attack Used to Deploy FDMTP Implant</a> <em>(Fortinet)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-07.mp3" length="814228" type="audio/mpeg"/>
      <itunes:duration>0:50</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-06.html</link>
      <pubDate>Thu, 06 Aug 2026 06:01:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260806_060131</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/lancejames221b/omp-re">omp-re: Reverse-engineering suite for omp: radare2 tools, evidence store, signed audit log, RE status band, and report generator.</a> <em>(lancejames221b)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-06.mp3" length="929167" type="audio/mpeg"/>
      <itunes:duration>0:58</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-05.html</link>
      <pubDate>Wed, 05 Aug 2026 06:04:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260805_060446</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/">OctLurk and SilkLurk: new Backdoors in Central Asia</a> <em>(Kaspersky)</em></li><li><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/">Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers</a> <em>(U.S. Department of State)</em></li><li><a href="https://trufflesecurity.com/blog/scanning-7-6-petabytes-of-ai-training-data-for-secrets">Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets - 221,000+ live creds</a> <em>(Truffle Security Co.)</em></li><li><a href="https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook">ENISA Secure by Design and Default Playbook | ENISA</a> <em>(ENISA (European Union Agency for Cybersecurity))</em></li><li><a href="https://arxiv.org/abs/2607.10315">Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis</a> <em>(Nanyang Technological University)</em></li><li><a href="https://memn0ps.github.io/rusty-windows-uefi-bootkit/">Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)</a> <em>(memN0ps)</em></li><li><a href="https://github.com/matteyeux/binja-diff">binja-diff: Binary Ninja diffing tool</a> <em>(matteyeux)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-05.mp3" length="2932027" type="audio/mpeg"/>
      <itunes:duration>3:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-04.html</link>
      <pubDate>Tue, 04 Aug 2026 06:02:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260804_060235</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/">Implications of Recent CISA Disclosures on Iranian OT Targeting</a> <em>(Dataminr)</em></li><li><a href="https://cheri-alliance.org/a-new-etsi-standard-could-rewrite-the-memory-safety-debate/">A new ETSI standard could rewrite the memory-safety debate</a> <em>(CHERI Alliance)</em></li><li><a href="https://github.com/uber/ADR">ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.</a> <em>(Uber)</em></li><li><a href="https://warez.sl0p.foo/apple-screensharing-rce/">Apple Screen Sharing Pre-Auth RCE (macOS ≤ 26.5)</a> <em>(bl4sty)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-04.mp3" length="2375724" type="audio/mpeg"/>
      <itunes:duration>2:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-03.html</link>
      <pubDate>Mon, 03 Aug 2026 06:05:04 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260803_060504</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socradar.io/blog/snowlight-government-chinese-campaign/">Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/">CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog</a> <em>(Microsoft)</em></li><li><a href="https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks">Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud</a> <em>(Bitsight)</em></li><li><a href="https://blog.coinkite.com/entropy-technical-backgrounder/">Technical Deep Dive into the Entropy Issue - in Coldcard bitcoin hardware wallet</a> <em>(Coinkite)</em></li><li><a href="https://tailscale.com/blog/hugging-face-intrusion">Tailscale in the Hugging Face intrusion: The good news and the bad news</a> <em>(Tailscale)</em></li><li><a href="https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys">Anthropic's Fever Dream: Claude's package anthropickit that stole real keys</a> <em>(Aikido Security)</em></li><li><a href="https://blog.talosintelligence.com/ir-trends-q2-2026/">IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains</a> <em>(Cisco Talos)</em></li><li><a href="https://github.com/radkawar/screenlogger">screenlogger: Private, searchable screen history for macOS.</a> <em>(radkawar)</em></li><li><a href="https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/">Inside the Falcon How CrowdStrike Catches You</a> <em>(0xDbgman)</em></li><li><a href="https://nkinternet.com/2026/08/01/a-new-silivaccine-north-koreas-antivirus/">A New SiliVaccine: North Korea’s Antivirus</a> <em>(Martyn Williams)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-03.mp3" length="5081173" type="audio/mpeg"/>
      <itunes:duration>5:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-02.html</link>
      <pubDate>Sun, 02 Aug 2026 06:01:47 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260802_060147</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db">CosmosEscape: Taking Over Every Azure Cosmos DB</a> <em>(Wiz)</em></li><li><a href="https://blog.google/security/chrome-stronger-with-every-update/">Stronger with every update: How we’re making Chrome and the web safer in the AI Era</a> <em>(Google)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-02.mp3" length="1458303" type="audio/mpeg"/>
      <itunes:duration>1:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-01.html</link>
      <pubDate>Sat, 01 Aug 2026 06:06:40 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260801_060640</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">Amazon identifies North Korean hacker group behind open-source supply chain attacks</a> <em>(Amazon Web Services)</em></li><li><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a> <em>(Safedep)</em></li><li><a href="https://socket.dev/blog/joyfill-npm-beta-releases-compromised">Two Joyfill npm Beta Releases Compromised to Deliver DEV#POP...</a> <em>(Socket)</em></li><li><a href="https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises">PolinRider Caused Dozens of npm, Go, PHP Compromises</a> <em>(OpenSourceMalware)</em></li><li><a href="https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e?gi=e4e31ac9a9be">Adform compromised to serve crypto stealer via supply chain attack</a> <em>(Kevin Beaumont)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise">Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://asec.ahnlab.com/ko/94695/">-[Joint Cyber ​​Security Advisory] Operation Double Barrel (The Relationship Between State-Backed Hacking Organizations and the Gunra Ransomware Group)</a> <em>(AhnLab)</em></li><li><a href="https://image.ahnlab.com/atip/content/file/20260730/%5BAhnLab%5DOperation%20Double%20Barrel(ENG)(2026.07.30).pdf">Operation Double Barrel</a> <em>(AhnLab Security Intelligence Center (ASEC))</em></li><li><a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/">Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/">ClickFix, EtherHiding &amp; a DPRK Wallet Trail</a> <em>(AllSecure Corp)</em></li><li><a href="https://infrawatch.com/blog/73000-servers-selling-western-frontier-ai-into-china-transfer-stations#blogpost">The 73,000-server market reselling Western frontier AI into China - Infrawatch</a> <em>(InfraWatch)</em></li><li><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Investigating three real-world incidents in our cybersecurity evaluations</a> <em>(Anthropic)</em></li><li><a href="https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign">Credential Stuffing Campaign Hits SonicWall</a> <em>(Huntress)</em></li><li><a href="https://www.fbi.gov/news/press-releases/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions">Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions | Federal Bureau of Investigation</a> <em>(Federal Bureau of Investigation)</em></li><li><a href="https://www.silentpush.com/blog/danglegeddon/">Welcome to Danglegeddon</a> <em>(Silent Push Inc.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-01.mp3" length="7557582" type="audio/mpeg"/>
      <itunes:duration>7:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 31, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-31.html</link>
      <pubDate>Fri, 31 Jul 2026 06:02:30 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260731_060230</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit">Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US</a> <em>(Proofpoint)</em></li><li><a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</a> <em>(Hugging Face)</em></li><li><a href="https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/">SakDriver: Reversing a Windows Kernel Driver Rootkit</a> <em>(oxfemale)</em></li><li><a href="https://github.com/DFE-Digital/power-pages-security-utils">power-pages-security-utils: power pages security utils to analyse and audit power page apps / sites</a> <em>(DfE Digital)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-31.mp3" length="2105304" type="audio/mpeg"/>
      <itunes:duration>2:11</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-30.html</link>
      <pubDate>Thu, 30 Jul 2026 06:01:34 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260730_060134</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover">"HermeticReader" , The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover</a> <em>(Guardio)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-30.mp3" length="1006907" type="audio/mpeg"/>
      <itunes:duration>1:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-29.html</link>
      <pubDate>Wed, 29 Jul 2026 06:04:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260729_060423</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://muddy.vibecoded.systems/">Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS</a> <em>(digicat)</em></li><li><a href="https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/">Dear Diary, Today I found a Ghost in the Network</a> <em>(Intrusion Truth)</em></li><li><a href="https://netaskari.substack.com/p/puppeteers-chinese-hackers-still">Puppeteers: Chinese hackers still trick Claude into dirty work.</a> <em>(NetAskari)</em></li><li><a href="https://github.com/BushidoUK/Project-Orbital">Project-Orbital: Operational Relay Box Intelligence, Tracking, &amp; Analysis Lexicon (ORBITAL)</a> <em>(BushidoUK)</em></li><li><a href="https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem">Inside the growing residential proxy botnet threat</a> <em>(Lumen Technologies)</em></li><li><a href="https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/">Random Windows Things Part 2: Unexpected Clipboard Data Behaviour</a> <em>(Winsider Seminars &amp; Solutions Inc.)</em></li><li><a href="https://arxiv.org/pdf/2607.19742">An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Report</a> <em>(Cornell University)</em></li><li><a href="https://rust.cheriot.org/2026/07/06/technical-details.html">Technical Details: Const Evaluation and Data Layout - Rust on CHERI</a> <em>(CHERIoT Platform)</em></li><li><a href="https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/">The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS</a> <em>(Mohamed Alzhrani)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-29.mp3" length="4990894" type="audio/mpeg"/>
      <itunes:duration>5:11</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-28.html</link>
      <pubDate>Tue, 28 Jul 2026 06:05:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260728_060533</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis">APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT</a> <em>(Darkatlas Squad)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/">DNS Poisoning Tactics Expand to Hospitality Wi-Fi</a> <em>(ReliaQuest)</em></li><li><a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">Russian Global Webmail Espionage</a> <em>(Palo Alto Networks)</em></li><li><a href="https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/">Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns</a> <em>(Seth Enoka)</em></li><li><a href="https://gist.github.com/f-bader/8c447a8f3b58cb8a85bcf013436e312b">Hunt for Certighost (CVE-2026-54121) exploitation</a> <em>(f-bader)</em></li><li><a href="https://medium.com/@s12deff/kernelcallbacktable-process-injection-22112a0d9822">KernelCallbackTable Process Injection</a> <em>(S12)</em></li><li><a href="https://github.com/sliverarmory/beignet">beignet: MacOS Shared Library to Shellcode Loader</a> <em>(sliverarmory)</em></li><li><a href="https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard">What Does Windows HyperGuard (SKPG) Protect in ntoskrnl?</a> <em>(0xflux)</em></li><li><a href="https://dev.to/dobybaxter127/reconstructing-cloud-identity-intrusions-from-o365-logs-an-open-engine-that-ranks-attack-paths-fe4">Reconstructing cloud identity intrusions from O365 and CloudTrail logs</a> <em>(Doby Baxter)</em></li><li><a href="https://github.com/MaorSabag/NaX">NaX: Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins</a> <em>(Maor Sabag)</em></li><li><a href="https://ayoub-faouzi.com/posts/virtualization-internals-part-5-kvm-internals-from-vm-creation-to-guest-execution/">Virtualization Internals Part 5 - KVM Internals: From VM Creation to Guest Execution</a> <em>(Ayoub Faouzi)</em></li><li><a href="https://github.com/panwnvda/SliverC2-Evasion-Suite/">SliverC2-Evasion-Suite: Four-kit defense evasion suite for Sliver C2: Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.</a> <em>(panwnvda)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-28.mp3" length="6264834" type="audio/mpeg"/>
      <itunes:duration>6:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-27.html</link>
      <pubDate>Mon, 27 Jul 2026 06:07:58 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260727_060758</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/">CheckPoint Security Advisory - Action Required - July 2026 Security Update - , we identified one of those in the wild, affecting a handful of customers.</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/">Cl0p Exploitation of PTC Windchill &amp; FlexPLM (CVE-2026-12569)</a> <em>(Ransom-ISAC)</em></li><li><a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week</a> <em>(Reuters)</em></li><li><a href="https://am.jpmorgan.com/gb/en/asset-management/institutional/insights/market-insights/eye-on-the-market/patchmageddon/">Patchmageddon</a> <em>(J.P. Morgan Asset Management)</em></li><li><a href="https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/">Inside a DPRK BlueNoroff ClickFix Kit</a> <em>(JUMPSEC)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system">Updated Cyber Threat Actor Naming System | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware">AgentBaiting: How Fake AI Skills Deliver Malware at Scale</a> <em>(Island)</em></li><li><a href="https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor">SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor - StepSecurity</a> <em>(StepSecurity)</em></li><li><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a> <em>(SafeDep)</em></li><li><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">The Week of Sandbox Escapes</a> <em>(Pillar Security)</em></li><li><a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/">Silent Replacement of Trusted macOS App Executables</a> <em>(Talal Haj Bakry and Tommy Mysk)</em></li><li><a href="https://github.com/Hashir14k/SiemQueryBuilder">SiemQueryBuilder: This repository is for the Threat Intelligence Analyst and The Threat Hunter for performing IOC sweeping on multiple SIEM Platform.</a> <em>(Hashir14k)</em></li><li><a href="https://github.com/svenseeberg/data-diode">data-diode: A Data Diode with 2 Raspberry Pi and OpenBSD</a> <em>(Sven Seeberg)</em></li><li><a href="https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure">Cisco's Transition to a Risk-Based Vulnerability Disclosure Model</a> <em>(Cisco)</em></li><li><a href="https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/">Next chapter: Restructuring GitHub's bug bounty program</a> <em>(GitHub)</em></li><li><a href="https://github.com/dinosn/raptor-loop-hunt">raptor-loop-hunt: RAPTOR autonomous looping multi-altitude security vulnerability hunt — Claude Code skill</a> <em>(dinosn)</em></li><li><a href="https://arxiv.org/abs/2607.19742">An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports</a> <em>(Cornell University)</em></li><li><a href="https://arxiv.org/abs/2607.20216">Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis</a> <em>(Adel ElZemity, Shujun Li, and Budi Arief)</em></li><li><a href="https://github.com/AlphaReasoning/The-Jinn-Guard">The-Jinn-Guard: Kernel-aware agent governance daemon. Tamper-evident hash-chained audit ledger, BPF-LSM enforcement, Z3-backed policy checks. Research prototype.</a> <em>(AlphaReasoning)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-27.mp3" length="7843466" type="audio/mpeg"/>
      <itunes:duration>8:10</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-26.html</link>
      <pubDate>Sun, 26 Jul 2026 06:09:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260726_060946</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>22</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508745&idx=1&sn=d2e8bf3bed50b91adf218cabe5be731c&cur_album_id=1955835290309230595&search_click_id=&poc_token=HDlNZGqjSqbC6ehY8CNen4hYySJdiJBFWpZNxJET">Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization</a> <em>(腾讯 (Tencent))</em></li><li><a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent">Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged</a> <em>(Hunt.io and Bob Diachenko)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">Look What You Made Us Patch: 2025 Zero-Days in Review</a> <em>(Google)</em></li><li><a href="https://arxiv.org/abs/2607.20713">Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study</a> <em>(Shanna M. Kahn and John D. Hastings)</em></li><li><a href="https://blog.calif.io/p/dark-elevator-windows-install-service?hide_intro_popup=true">Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)</a> <em>(blog.calif.io)</em></li><li><a href="https://arxiv.org/abs/2512.17667">STAR: Semantic-Traffic Alignment and Retrieval for Zero-Shot HTTPS Website Fingerprinting</a> <em>(Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences; Institute for Network Sciences and Cyberspace, Tsinghua University)</em></li><li><a href="https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique">Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR</a> <em>(Bitdefender)</em></li><li><a href="https://github.com/AlloySecureGroup/BlinkLinkSentiennel">BlinkLinkSentiennel: A user-mode detection sensor prototype for bind-link abuse on Windows, the EDR-evasion class documented by Bitdefender</a> <em>(Alloy Secure Group)</em></li><li><a href="https://g3tsyst3m.com/initial%20access/Using-WebDav-to-Outsmart-Smartscreen,-MOTW,-and-that-OTHER-Alert/">Using WebDav to Outsmart Smartscreen, MOTW, and that OTHER Alert</a> <em>(R.B.C (g3tsyst3m))</em></li><li><a href="https://github.com/aniqfakhrul/CVE-2026-54121">CVE-2026-54121: Certighost POC</a> <em>(aniqfakhrul)</em></li><li><a href="https://github.com/xirtam2669/Shellph">Shellph: Shellph is a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode. Named after my cat (Belph)</a> <em>(xirtam2669)</em></li><li><a href="https://www.usenix.org/conference/osdi26/presentation/sharma">Mohabi: Disaggregating and Sandboxing the Firefox JavaScript Engine</a> <em>(USENIX Association)</em></li><li><a href="https://www.enisa.europa.eu/sites/default/files/2026-07/Procurement%20guidelines%20for%20the%20cybersecurity%20of%20hospitals%20and%20healthcare%20providers.pdf">Procurement guidelines for the cybersecurity of hospitals and healthcare providers</a> <em>(European Union Agency for Cybersecurity (ENISA))</em></li><li><a href="https://www.nist.gov/news-events/news/2026/07/security-guidelines-storage-infrastructure-draft-sp-800-209r1-available">Security Guidelines for Storage Infrastructure: Draft SP 800-209r1 Available for Public Comment</a> <em>(National Institute of Standards and Technology)</em></li><li><a href="https://github.com/oomol-lab/open-connector">open-connector: Open-source auth gateway connecting 1000+ SaaS providers to AI agents through SDK, CLI, MCP, HTTP, and OpenAPI.</a> <em>(OOMOL Lab)</em></li><li><a href="https://pwno.io/diff">We argue that the bottleneck in LLM vulnerability discovery is not model capability, but codebase decomposition. Along the research, we've discovered .diff are more interesting than we've presumed.</a> <em>(Pwno.io Inc.)</em></li><li><a href="https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/">Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</a> <em>(SentinelOne)</em></li><li><a href="https://github.com/xxyyue/llm-observer-proxy-go">llm-observer-proxy-go: Run-scoped LLM observation proxy with an embedded Bifrost data plane</a> <em>(xxyyue)</em></li><li><a href="https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/">Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT</a> <em>(Rhys Downing)</em></li><li><a href="https://github.com/kaandemir993/Remus-Stealer-Fileless-Payload-Extraction-C2-Exfiltration-Analysis.git">Remus-Stealer-Fileless-Payload-Extraction-C2-Exfiltration-Analysis: "Reverse engineering analysis of Remus Stealer, uses fileless execution, clipboard theft, screen capture, and C2 communication.</a> <em>(kaandemir993)</em></li><li><a href="https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/">Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</a> <em>(Cisco Talos)</em></li><li><a href="https://mp.weixin.qq.com/s/G_WtGlwn_QXIhRb8dtg_aw">GCSA洞察：Fastjson 1.2.83 “Gadget-Free” 漏洞（0day）深度分析与防御指南 - In-depth Analysis and Defense Guide for the Fastjson 1.2.83 “Gadget-Free” Vulnerability (0day)</a> <em>(The information regarding the organization or individual that controls the content at the provided URL could not be retrieved.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-26.mp3" length="9689173" type="audio/mpeg"/>
      <itunes:duration>10:05</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-25.html</link>
      <pubDate>Sat, 25 Jul 2026 06:07:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260725_060731</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits">Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458</a> <em>(Proofpoint)</em></li><li><a href="https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/">JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake</a> <em>(Group-IB)</em></li><li><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant">Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant</a> <em>(ENKI)</em></li><li><a href="https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem">TAG-195 Upgrades MaaS Ecosystem with Modular Tools</a> <em>(Recorded Future)</em></li><li><a href="https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/">New BitLocker extortion activity: RDP, MSSQL, RMM Abuse</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation">Large-Scale GitHub Actions Abuse Powers a Distributed cPanel...</a> <em>(Socket)</em></li><li><a href="https://www.oracle.com/security-alerts/cpujul2026.html">Oracle Critical Patch Update Advisory - July 2026 - "This Critical Patch Update contains 1449 new security patches across the product families"</a> <em>(Oracle Corporation)</em></li><li><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/">Releases now reject new files after 14 days - The Python Package Index Blog</a> <em>(Python Software Foundation)</em></li><li><a href="https://www.gao.gov/products/gao-26-108606">U.S. GAO - Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements</a> <em>(U.S. Government Accountability Office)</em></li><li><a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign">UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations</a> <em>(National Cyber Security Centre (NCSC))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-25.mp3" length="4864671" type="audio/mpeg"/>
      <itunes:duration>5:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-24.html</link>
      <pubDate>Fri, 24 Jul 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260724_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-24.mp3" length="1006071" type="audio/mpeg"/>
      <itunes:duration>1:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-23.html</link>
      <pubDate>Thu, 23 Jul 2026 06:07:05 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260723_060705</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://ransom-isac.com/blog/muddywater-clickfix-patchagent/">MuddyWater: ClickFix to Telegram &amp; PatchAgent Backdoor</a> <em>(Ransom-ISAC)</em></li><li><a href="https://kienmanowar.wordpress.com/2026/07/13/quicknote-solidpdfcreator-mustang-panda-stage-1-backdoor-target-india/">[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)</a> <em>(kienmanowar)</em></li><li><a href="https://kienmanowar.wordpress.com/2026/07/21/quicknote-mustang-panda-toneshell-apt-s1239-beacon-shellcode-re-analysis/">[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis</a> <em>(Kienmanowar)</em></li><li><a href="https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/">Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab</a> <em>(Amnesty International's Security Lab)</em></li><li><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face partner to address security incident during model evaluation</a> <em>(OpenAI)</em></li><li><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25</a> <em>(Searchlight Cyber)</em></li><li><a href="https://login-securite.com/blog/cve-2026-50502-rce-via-le-service-windows-event-log-elfrbackupelfw">CVE-2026-50502 : RCE via le service Windows Event Log</a> <em>(Login Sécurité)</em></li><li><a href="https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve">Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blogs.cisco.com/ai/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization">Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization</a> <em>(Cisco)</em></li><li><a href="https://grandideastudio.com/portfolio/security/ledger-hardware-implant/">Grand Idea Studio: Reverse Engineering a Ledger Nano X Hardware Implant</a> <em>(Grand Idea Studio)</em></li><li><a href="https://github.com/MatheuZSecurity/Furtex">Furtex: Post-exploitation and evasion research toolkit for Linux.</a> <em>(MatheuZSecurity)</em></li><li><a href="https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/">DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign">ChainVeil and ViteVenom are DPRK’s PolinRider Campaign</a> <em>(OpenSourceMalware)</em></li><li><a href="https://www.chinadaily.com.cn/a/202607/20/WS6a5db910a310986e2b466326.html">Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam</a> <em>(China Daily)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service">Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US</a> <em>(Proofpoint)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-23.mp3" length="6673598" type="audio/mpeg"/>
      <itunes:duration>6:57</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-22.html</link>
      <pubDate>Wed, 22 Jul 2026 06:01:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260722_060122</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li>The Morris Worm: The Internet's First Major Wake-Up Call <em>(Historical Archive)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-22.mp3" length="1426120" type="audio/mpeg"/>
      <itunes:duration>1:29</itunes:duration>
    </item>
  </channel>
</rss>