<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Daily BlueTeamSec Briefing</title>
    <description>Daily security briefings for blue team professionals</description>
    <language>en-us</language>
    <copyright>© 2025 InfoSec Briefing Bot</copyright>
    <managingEditor>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</managingEditor>
    <webMaster>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</webMaster>
    <category>Technology</category>
    <generator>InfoSec Briefing Generator</generator>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <link>https://briefing.workshop1.net</link>
    <pubDate>Sun, 31 Aug 2025 16:05:46 +0000</pubDate>
    <lastBuildDate>Sat, 08 Aug 2026 06:01:35 +0000</lastBuildDate>
    <itunes:author>InfoSec Briefing Bot</itunes:author>
    <itunes:summary>Daily security briefings for blue team professionals</itunes:summary>
    <itunes:category>Technology</itunes:category>
    <itunes:image href="https://briefing.workshop1.net/assets/podcast-artwork.jpg"/>
    <itunes:owner>
      <itunes:name>InfoSec Briefing Bot</itunes:name>
      <itunes:email>podcast@briefing.workshop1.net</itunes:email>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:language>en-us</itunes:language>
    <item>
      <title>InfoSec Briefing - August 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-08.html</link>
      <pubDate>Sat, 08 Aug 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260808_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.enisa.europa.eu/news/enisa-scales-up-its-role-in-the-cve-program">ENISA scales up its role in the CVE Program | ENISA</a> <em>(European Union Agency for Cybersecurity (ENISA))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-08.mp3" length="907851" type="audio/mpeg"/>
      <itunes:duration>0:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-07.html</link>
      <pubDate>Fri, 07 Aug 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260807_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.fortinet.com/blog/threat-research/quickfox-supply-chain-attack-used-to-deploy-fdmtp-implant">QuickFox Supply Chain Attack Used to Deploy FDMTP Implant</a> <em>(Fortinet)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-07.mp3" length="814228" type="audio/mpeg"/>
      <itunes:duration>0:50</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-06.html</link>
      <pubDate>Thu, 06 Aug 2026 06:01:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260806_060131</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/lancejames221b/omp-re">omp-re: Reverse-engineering suite for omp: radare2 tools, evidence store, signed audit log, RE status band, and report generator.</a> <em>(lancejames221b)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-06.mp3" length="929167" type="audio/mpeg"/>
      <itunes:duration>0:58</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-05.html</link>
      <pubDate>Wed, 05 Aug 2026 06:04:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260805_060446</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/">OctLurk and SilkLurk: new Backdoors in Central Asia</a> <em>(Kaspersky)</em></li><li><a href="https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/">Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers</a> <em>(U.S. Department of State)</em></li><li><a href="https://trufflesecurity.com/blog/scanning-7-6-petabytes-of-ai-training-data-for-secrets">Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets - 221,000+ live creds</a> <em>(Truffle Security Co.)</em></li><li><a href="https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook">ENISA Secure by Design and Default Playbook | ENISA</a> <em>(ENISA (European Union Agency for Cybersecurity))</em></li><li><a href="https://arxiv.org/abs/2607.10315">Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis</a> <em>(Nanyang Technological University)</em></li><li><a href="https://memn0ps.github.io/rusty-windows-uefi-bootkit/">Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)</a> <em>(memN0ps)</em></li><li><a href="https://github.com/matteyeux/binja-diff">binja-diff: Binary Ninja diffing tool</a> <em>(matteyeux)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-05.mp3" length="2932027" type="audio/mpeg"/>
      <itunes:duration>3:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-04.html</link>
      <pubDate>Tue, 04 Aug 2026 06:02:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260804_060235</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.dataminr.com/resources/blog/implications-of-recent-cisa-disclosures-on-iranian-ot-targeting/">Implications of Recent CISA Disclosures on Iranian OT Targeting</a> <em>(Dataminr)</em></li><li><a href="https://cheri-alliance.org/a-new-etsi-standard-could-rewrite-the-memory-safety-debate/">A new ETSI standard could rewrite the memory-safety debate</a> <em>(CHERI Alliance)</em></li><li><a href="https://github.com/uber/ADR">ADR: ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.</a> <em>(Uber)</em></li><li><a href="https://warez.sl0p.foo/apple-screensharing-rce/">Apple Screen Sharing Pre-Auth RCE (macOS ≤ 26.5)</a> <em>(bl4sty)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-04.mp3" length="2375724" type="audio/mpeg"/>
      <itunes:duration>2:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-03.html</link>
      <pubDate>Mon, 03 Aug 2026 06:05:04 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260803_060504</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socradar.io/blog/snowlight-government-chinese-campaign/">Tracing SNOWLIGHT: A China-Nexus Campaign Against Government Infrastructure</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/">CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog</a> <em>(Microsoft)</em></li><li><a href="https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks">Uncovering the Fuyao Enterprise: A Shift in Modern Ad-Fraud</a> <em>(Bitsight)</em></li><li><a href="https://blog.coinkite.com/entropy-technical-backgrounder/">Technical Deep Dive into the Entropy Issue - in Coldcard bitcoin hardware wallet</a> <em>(Coinkite)</em></li><li><a href="https://tailscale.com/blog/hugging-face-intrusion">Tailscale in the Hugging Face intrusion: The good news and the bad news</a> <em>(Tailscale)</em></li><li><a href="https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys">Anthropic's Fever Dream: Claude's package anthropickit that stole real keys</a> <em>(Aikido Security)</em></li><li><a href="https://blog.talosintelligence.com/ir-trends-q2-2026/">IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains</a> <em>(Cisco Talos)</em></li><li><a href="https://github.com/radkawar/screenlogger">screenlogger: Private, searchable screen history for macOS.</a> <em>(radkawar)</em></li><li><a href="https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/">Inside the Falcon How CrowdStrike Catches You</a> <em>(0xDbgman)</em></li><li><a href="https://nkinternet.com/2026/08/01/a-new-silivaccine-north-koreas-antivirus/">A New SiliVaccine: North Korea’s Antivirus</a> <em>(Martyn Williams)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-03.mp3" length="5081173" type="audio/mpeg"/>
      <itunes:duration>5:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-02.html</link>
      <pubDate>Sun, 02 Aug 2026 06:01:47 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260802_060147</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db">CosmosEscape: Taking Over Every Azure Cosmos DB</a> <em>(Wiz)</em></li><li><a href="https://blog.google/security/chrome-stronger-with-every-update/">Stronger with every update: How we’re making Chrome and the web safer in the AI Era</a> <em>(Google)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-02.mp3" length="1458303" type="audio/mpeg"/>
      <itunes:duration>1:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - August 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-08-01.html</link>
      <pubDate>Sat, 01 Aug 2026 06:06:40 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260801_060640</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/">Amazon identifies North Korean hacker group behind open-source supply chain attacks</a> <em>(Amazon Web Services)</em></li><li><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a> <em>(Safedep)</em></li><li><a href="https://socket.dev/blog/joyfill-npm-beta-releases-compromised">Two Joyfill npm Beta Releases Compromised to Deliver DEV#POP...</a> <em>(Socket)</em></li><li><a href="https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises">PolinRider Caused Dozens of npm, Go, PHP Compromises</a> <em>(OpenSourceMalware)</em></li><li><a href="https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e?gi=e4e31ac9a9be">Adform compromised to serve crypto stealer via supply chain attack</a> <em>(Kevin Beaumont)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise">Mitigation Guidance for Supply Chain Compromise | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://asec.ahnlab.com/ko/94695/">-[Joint Cyber ​​Security Advisory] Operation Double Barrel (The Relationship Between State-Backed Hacking Organizations and the Gunra Ransomware Group)</a> <em>(AhnLab)</em></li><li><a href="https://image.ahnlab.com/atip/content/file/20260730/%5BAhnLab%5DOperation%20Double%20Barrel(ENG)(2026.07.30).pdf">Operation Double Barrel</a> <em>(AhnLab Security Intelligence Center (ASEC))</em></li><li><a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/">Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/">ClickFix, EtherHiding &amp; a DPRK Wallet Trail</a> <em>(AllSecure Corp)</em></li><li><a href="https://infrawatch.com/blog/73000-servers-selling-western-frontier-ai-into-china-transfer-stations#blogpost">The 73,000-server market reselling Western frontier AI into China - Infrawatch</a> <em>(InfraWatch)</em></li><li><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Investigating three real-world incidents in our cybersecurity evaluations</a> <em>(Anthropic)</em></li><li><a href="https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign">Credential Stuffing Campaign Hits SonicWall</a> <em>(Huntress)</em></li><li><a href="https://www.fbi.gov/news/press-releases/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions">Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions | Federal Bureau of Investigation</a> <em>(Federal Bureau of Investigation)</em></li><li><a href="https://www.silentpush.com/blog/danglegeddon/">Welcome to Danglegeddon</a> <em>(Silent Push Inc.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-08-01.mp3" length="7557582" type="audio/mpeg"/>
      <itunes:duration>7:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 31, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-31.html</link>
      <pubDate>Fri, 31 Jul 2026 06:02:30 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260731_060230</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit">Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US</a> <em>(Proofpoint)</em></li><li><a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident</a> <em>(Hugging Face)</em></li><li><a href="https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/">SakDriver: Reversing a Windows Kernel Driver Rootkit</a> <em>(oxfemale)</em></li><li><a href="https://github.com/DFE-Digital/power-pages-security-utils">power-pages-security-utils: power pages security utils to analyse and audit power page apps / sites</a> <em>(DfE Digital)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-31.mp3" length="2105304" type="audio/mpeg"/>
      <itunes:duration>2:11</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-30.html</link>
      <pubDate>Thu, 30 Jul 2026 06:01:34 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260730_060134</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://guard.io/labs/hermeticreader---the-vulnerability-that-turned-adobe-300m-install-extension-into-a-full-whatsapp-takeover">"HermeticReader" , The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover</a> <em>(Guardio)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-30.mp3" length="1006907" type="audio/mpeg"/>
      <itunes:duration>1:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-29.html</link>
      <pubDate>Wed, 29 Jul 2026 06:04:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260729_060423</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://muddy.vibecoded.systems/">Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS</a> <em>(digicat)</em></li><li><a href="https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/">Dear Diary, Today I found a Ghost in the Network</a> <em>(Intrusion Truth)</em></li><li><a href="https://netaskari.substack.com/p/puppeteers-chinese-hackers-still">Puppeteers: Chinese hackers still trick Claude into dirty work.</a> <em>(NetAskari)</em></li><li><a href="https://github.com/BushidoUK/Project-Orbital">Project-Orbital: Operational Relay Box Intelligence, Tracking, &amp; Analysis Lexicon (ORBITAL)</a> <em>(BushidoUK)</em></li><li><a href="https://www.lumen.com/blog/en-us/symbiotic-parasites-the-modern-proxy-ecosystem">Inside the growing residential proxy botnet threat</a> <em>(Lumen Technologies)</em></li><li><a href="https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/">Random Windows Things Part 2: Unexpected Clipboard Data Behaviour</a> <em>(Winsider Seminars &amp; Solutions Inc.)</em></li><li><a href="https://arxiv.org/pdf/2607.19742">An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Report</a> <em>(Cornell University)</em></li><li><a href="https://rust.cheriot.org/2026/07/06/technical-details.html">Technical Details: Const Evaluation and Data Layout - Rust on CHERI</a> <em>(CHERIoT Platform)</em></li><li><a href="https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/">The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS</a> <em>(Mohamed Alzhrani)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-29.mp3" length="4990894" type="audio/mpeg"/>
      <itunes:duration>5:11</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-28.html</link>
      <pubDate>Tue, 28 Jul 2026 06:05:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260728_060533</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis">APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT</a> <em>(Darkatlas Squad)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/">DNS Poisoning Tactics Expand to Hospitality Wi-Fi</a> <em>(ReliaQuest)</em></li><li><a href="https://unit42.paloaltonetworks.com/russian-webmail-espionage/">Russian Global Webmail Espionage</a> <em>(Palo Alto Networks)</em></li><li><a href="https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/">Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns</a> <em>(Seth Enoka)</em></li><li><a href="https://gist.github.com/f-bader/8c447a8f3b58cb8a85bcf013436e312b">Hunt for Certighost (CVE-2026-54121) exploitation</a> <em>(f-bader)</em></li><li><a href="https://medium.com/@s12deff/kernelcallbacktable-process-injection-22112a0d9822">KernelCallbackTable Process Injection</a> <em>(S12)</em></li><li><a href="https://github.com/sliverarmory/beignet">beignet: MacOS Shared Library to Shellcode Loader</a> <em>(sliverarmory)</em></li><li><a href="https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard">What Does Windows HyperGuard (SKPG) Protect in ntoskrnl?</a> <em>(0xflux)</em></li><li><a href="https://dev.to/dobybaxter127/reconstructing-cloud-identity-intrusions-from-o365-logs-an-open-engine-that-ranks-attack-paths-fe4">Reconstructing cloud identity intrusions from O365 and CloudTrail logs</a> <em>(Doby Baxter)</em></li><li><a href="https://github.com/MaorSabag/NaX">NaX: Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins</a> <em>(Maor Sabag)</em></li><li><a href="https://ayoub-faouzi.com/posts/virtualization-internals-part-5-kvm-internals-from-vm-creation-to-guest-execution/">Virtualization Internals Part 5 - KVM Internals: From VM Creation to Guest Execution</a> <em>(Ayoub Faouzi)</em></li><li><a href="https://github.com/panwnvda/SliverC2-Evasion-Suite/">SliverC2-Evasion-Suite: Four-kit defense evasion suite for Sliver C2: Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.</a> <em>(panwnvda)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-28.mp3" length="6264834" type="audio/mpeg"/>
      <itunes:duration>6:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-27.html</link>
      <pubDate>Mon, 27 Jul 2026 06:07:58 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260727_060758</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/">CheckPoint Security Advisory - Action Required - July 2026 Security Update - , we identified one of those in the wild, affecting a handful of customers.</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/">Cl0p Exploitation of PTC Windchill &amp; FlexPLM (CVE-2026-12569)</a> <em>(Ransom-ISAC)</em></li><li><a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week</a> <em>(Reuters)</em></li><li><a href="https://am.jpmorgan.com/gb/en/asset-management/institutional/insights/market-insights/eye-on-the-market/patchmageddon/">Patchmageddon</a> <em>(J.P. Morgan Asset Management)</em></li><li><a href="https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/">Inside a DPRK BlueNoroff ClickFix Kit</a> <em>(JUMPSEC)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system">Updated Cyber Threat Actor Naming System | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware">AgentBaiting: How Fake AI Skills Deliver Malware at Scale</a> <em>(Island)</em></li><li><a href="https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor">SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor - StepSecurity</a> <em>(StepSecurity)</em></li><li><a href="https://safedep.io/malicious-copilot-mcp-apex-npm-macos-infostealer/">@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown</a> <em>(SafeDep)</em></li><li><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">The Week of Sandbox Escapes</a> <em>(Pillar Security)</em></li><li><a href="https://mysk.blog/2026/07/23/macos-overwrite-app-executables/">Silent Replacement of Trusted macOS App Executables</a> <em>(Talal Haj Bakry and Tommy Mysk)</em></li><li><a href="https://github.com/Hashir14k/SiemQueryBuilder">SiemQueryBuilder: This repository is for the Threat Intelligence Analyst and The Threat Hunter for performing IOC sweeping on multiple SIEM Platform.</a> <em>(Hashir14k)</em></li><li><a href="https://github.com/svenseeberg/data-diode">data-diode: A Data Diode with 2 Raspberry Pi and OpenBSD</a> <em>(Sven Seeberg)</em></li><li><a href="https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure">Cisco's Transition to a Risk-Based Vulnerability Disclosure Model</a> <em>(Cisco)</em></li><li><a href="https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/">Next chapter: Restructuring GitHub's bug bounty program</a> <em>(GitHub)</em></li><li><a href="https://github.com/dinosn/raptor-loop-hunt">raptor-loop-hunt: RAPTOR autonomous looping multi-altitude security vulnerability hunt — Claude Code skill</a> <em>(dinosn)</em></li><li><a href="https://arxiv.org/abs/2607.19742">An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports</a> <em>(Cornell University)</em></li><li><a href="https://arxiv.org/abs/2607.20216">Small, Free, and Effective: Orchestrating Open-Weight Small Language Models to Outperform Single LLM for Malware Analysis</a> <em>(Adel ElZemity, Shujun Li, and Budi Arief)</em></li><li><a href="https://github.com/AlphaReasoning/The-Jinn-Guard">The-Jinn-Guard: Kernel-aware agent governance daemon. Tamper-evident hash-chained audit ledger, BPF-LSM enforcement, Z3-backed policy checks. Research prototype.</a> <em>(AlphaReasoning)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-27.mp3" length="7843466" type="audio/mpeg"/>
      <itunes:duration>8:10</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-26.html</link>
      <pubDate>Sun, 26 Jul 2026 06:09:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260726_060946</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>22</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508745&idx=1&sn=d2e8bf3bed50b91adf218cabe5be731c&cur_album_id=1955835290309230595&search_click_id=&poc_token=HDlNZGqjSqbC6ehY8CNen4hYySJdiJBFWpZNxJET">Analysis of the Latest Tactical and Technical Upgrades of the APT-C-00 (Ocean Lotus) Organization</a> <em>(腾讯 (Tencent))</em></li><li><a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent">Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged</a> <em>(Hunt.io and Bob Diachenko)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">Look What You Made Us Patch: 2025 Zero-Days in Review</a> <em>(Google)</em></li><li><a href="https://arxiv.org/abs/2607.20713">Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study</a> <em>(Shanna M. Kahn and John D. Hastings)</em></li><li><a href="https://blog.calif.io/p/dark-elevator-windows-install-service?hide_intro_popup=true">Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)</a> <em>(blog.calif.io)</em></li><li><a href="https://arxiv.org/abs/2512.17667">STAR: Semantic-Traffic Alignment and Retrieval for Zero-Shot HTTPS Website Fingerprinting</a> <em>(Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences; Institute for Network Sciences and Cyberspace, Tsinghua University)</em></li><li><a href="https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique">Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR</a> <em>(Bitdefender)</em></li><li><a href="https://github.com/AlloySecureGroup/BlinkLinkSentiennel">BlinkLinkSentiennel: A user-mode detection sensor prototype for bind-link abuse on Windows, the EDR-evasion class documented by Bitdefender</a> <em>(Alloy Secure Group)</em></li><li><a href="https://g3tsyst3m.com/initial%20access/Using-WebDav-to-Outsmart-Smartscreen,-MOTW,-and-that-OTHER-Alert/">Using WebDav to Outsmart Smartscreen, MOTW, and that OTHER Alert</a> <em>(R.B.C (g3tsyst3m))</em></li><li><a href="https://github.com/aniqfakhrul/CVE-2026-54121">CVE-2026-54121: Certighost POC</a> <em>(aniqfakhrul)</em></li><li><a href="https://github.com/xirtam2669/Shellph">Shellph: Shellph is a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode. Named after my cat (Belph)</a> <em>(xirtam2669)</em></li><li><a href="https://www.usenix.org/conference/osdi26/presentation/sharma">Mohabi: Disaggregating and Sandboxing the Firefox JavaScript Engine</a> <em>(USENIX Association)</em></li><li><a href="https://www.enisa.europa.eu/sites/default/files/2026-07/Procurement%20guidelines%20for%20the%20cybersecurity%20of%20hospitals%20and%20healthcare%20providers.pdf">Procurement guidelines for the cybersecurity of hospitals and healthcare providers</a> <em>(European Union Agency for Cybersecurity (ENISA))</em></li><li><a href="https://www.nist.gov/news-events/news/2026/07/security-guidelines-storage-infrastructure-draft-sp-800-209r1-available">Security Guidelines for Storage Infrastructure: Draft SP 800-209r1 Available for Public Comment</a> <em>(National Institute of Standards and Technology)</em></li><li><a href="https://github.com/oomol-lab/open-connector">open-connector: Open-source auth gateway connecting 1000+ SaaS providers to AI agents through SDK, CLI, MCP, HTTP, and OpenAPI.</a> <em>(OOMOL Lab)</em></li><li><a href="https://pwno.io/diff">We argue that the bottleneck in LLM vulnerability discovery is not model capability, but codebase decomposition. Along the research, we've discovered .diff are more interesting than we've presumed.</a> <em>(Pwno.io Inc.)</em></li><li><a href="https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/">Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?</a> <em>(SentinelOne)</em></li><li><a href="https://github.com/xxyyue/llm-observer-proxy-go">llm-observer-proxy-go: Run-scoped LLM observation proxy with an embedded Bifrost data plane</a> <em>(xxyyue)</em></li><li><a href="https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/">Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT</a> <em>(Rhys Downing)</em></li><li><a href="https://github.com/kaandemir993/Remus-Stealer-Fileless-Payload-Extraction-C2-Exfiltration-Analysis.git">Remus-Stealer-Fileless-Payload-Extraction-C2-Exfiltration-Analysis: "Reverse engineering analysis of Remus Stealer, uses fileless execution, clipboard theft, screen capture, and C2 communication.</a> <em>(kaandemir993)</em></li><li><a href="https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/">Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</a> <em>(Cisco Talos)</em></li><li><a href="https://mp.weixin.qq.com/s/G_WtGlwn_QXIhRb8dtg_aw">GCSA洞察：Fastjson 1.2.83 “Gadget-Free” 漏洞（0day）深度分析与防御指南 - In-depth Analysis and Defense Guide for the Fastjson 1.2.83 “Gadget-Free” Vulnerability (0day)</a> <em>(The information regarding the organization or individual that controls the content at the provided URL could not be retrieved.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-26.mp3" length="9689173" type="audio/mpeg"/>
      <itunes:duration>10:05</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-25.html</link>
      <pubDate>Sat, 25 Jul 2026 06:07:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260725_060731</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits">Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458</a> <em>(Proofpoint)</em></li><li><a href="https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/">JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake</a> <em>(Group-IB)</em></li><li><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant">Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant</a> <em>(ENKI)</em></li><li><a href="https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem">TAG-195 Upgrades MaaS Ecosystem with Modular Tools</a> <em>(Recorded Future)</em></li><li><a href="https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/">New BitLocker extortion activity: RDP, MSSQL, RMM Abuse</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation">Large-Scale GitHub Actions Abuse Powers a Distributed cPanel...</a> <em>(Socket)</em></li><li><a href="https://www.oracle.com/security-alerts/cpujul2026.html">Oracle Critical Patch Update Advisory - July 2026 - "This Critical Patch Update contains 1449 new security patches across the product families"</a> <em>(Oracle Corporation)</em></li><li><a href="https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/">Releases now reject new files after 14 days - The Python Package Index Blog</a> <em>(Python Software Foundation)</em></li><li><a href="https://www.gao.gov/products/gao-26-108606">U.S. GAO - Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements</a> <em>(U.S. Government Accountability Office)</em></li><li><a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign">UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations</a> <em>(National Cyber Security Centre (NCSC))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-25.mp3" length="4864671" type="audio/mpeg"/>
      <itunes:duration>5:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-24.html</link>
      <pubDate>Fri, 24 Jul 2026 06:01:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260724_060135</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-24.mp3" length="1006071" type="audio/mpeg"/>
      <itunes:duration>1:02</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-23.html</link>
      <pubDate>Thu, 23 Jul 2026 06:07:05 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260723_060705</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://ransom-isac.com/blog/muddywater-clickfix-patchagent/">MuddyWater: ClickFix to Telegram &amp; PatchAgent Backdoor</a> <em>(Ransom-ISAC)</em></li><li><a href="https://kienmanowar.wordpress.com/2026/07/13/quicknote-solidpdfcreator-mustang-panda-stage-1-backdoor-target-india/">[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)</a> <em>(kienmanowar)</em></li><li><a href="https://kienmanowar.wordpress.com/2026/07/21/quicknote-mustang-panda-toneshell-apt-s1239-beacon-shellcode-re-analysis/">[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis</a> <em>(Kienmanowar)</em></li><li><a href="https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/">Inside Pegasus: The evolution of the world's most notorious spyware system - Amnesty International Security Lab</a> <em>(Amnesty International's Security Lab)</em></li><li><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face partner to address security incident during model evaluation</a> <em>(OpenAI)</em></li><li><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25</a> <em>(Searchlight Cyber)</em></li><li><a href="https://login-securite.com/blog/cve-2026-50502-rce-via-le-service-windows-event-log-elfrbackupelfw">CVE-2026-50502 : RCE via le service Windows Event Log</a> <em>(Login Sécurité)</em></li><li><a href="https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve">Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blogs.cisco.com/ai/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization">Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization</a> <em>(Cisco)</em></li><li><a href="https://grandideastudio.com/portfolio/security/ledger-hardware-implant/">Grand Idea Studio: Reverse Engineering a Ledger Nano X Hardware Implant</a> <em>(Grand Idea Studio)</em></li><li><a href="https://github.com/MatheuZSecurity/Furtex">Furtex: Post-exploitation and evasion research toolkit for Linux.</a> <em>(MatheuZSecurity)</em></li><li><a href="https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/">DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign">ChainVeil and ViteVenom are DPRK’s PolinRider Campaign</a> <em>(OpenSourceMalware)</em></li><li><a href="https://www.chinadaily.com.cn/a/202607/20/WS6a5db910a310986e2b466326.html">Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam</a> <em>(China Daily)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service">Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service | Proofpoint US</a> <em>(Proofpoint)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-23.mp3" length="6673598" type="audio/mpeg"/>
      <itunes:duration>6:57</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-22.html</link>
      <pubDate>Wed, 22 Jul 2026 06:01:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260722_060122</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li>The Morris Worm: The Internet's First Major Wake-Up Call <em>(Historical Archive)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-22.mp3" length="1426120" type="audio/mpeg"/>
      <itunes:duration>1:29</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-21.html</link>
      <pubDate>Tue, 21 Jul 2026 06:04:42 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260721_060442</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography">Contagious Interview malware in SVG images: DPRK campaign</a> <em>(Elastic)</em></li><li><a href="https://ddosier-disects.medium.com/the-one-chokepoint-to-rule-them-all-why-i-deleted-50-clickfix-detection-rules-and-replaced-them-7c532206d32d">The One Chokepoint to Rule Them All: Why I Deleted 50 ClickFix Detection Rules and Replaced Them with One</a> <em>(Ddosier)</em></li><li><a href="https://github.com/optimuslabs-io/grokpatrol">grokpatrol: Open-source, offline forensic scanner CLI tool designed to detect evidence of git repo collection or upload by the Grok Build CLI to xAI infrastructure.</a> <em>(Optimus Labs)</em></li><li><a href="https://www.half-second.com/">Half a Second - The Backdoor That Almost Broke the Internet, and the Invisible Labor Beneath It</a> <em>(Adrian Mastronardi)</em></li><li><a href="https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/">OpenSSL HollowByte: A DoS Hiding in 11 Bytes</a> <em>(Okta)</em></li><li><a href="https://joshparnham.com/2026/07/accessing-sensitive-passwords-app-account-data-on-macos-cve-2025-24169/">Accessing sensitive Passwords app account data on macOS (CVE-2025-24169)</a> <em>(Josh Parnham)</em></li><li><a href="https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets">IPhone Hacking Firm Sues Ex-Worker Over Alleged Theft of Secrets</a> <em>(Bloomberg)</em></li><li><a href="https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/">Magnet Forensics, LLC v. Del Gaudio (1:26-cv-03781) - allegedly Magnet were exploiting usbliter8 BootROM exploit that Paradigm Shift published - said it was leaked</a> <em>(Free Law Project)</em></li><li><a href="https://www.aikido.dev/blog/benchmarking-ai-models-known-cves">Benchmarking 13 AI Models on Known CVE Detection</a> <em>(Aikido Security)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-21.mp3" length="3950176" type="audio/mpeg"/>
      <itunes:duration>4:06</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-20.html</link>
      <pubDate>Mon, 20 Jul 2026 06:11:53 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260720_061153</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>30</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.vmray.com/the-redline-thread-that-led-to-a-maritime-bec-infrastructure-cluster/">The RedLine Thread That Led to a Maritime BEC Infrastructure Cluster</a> <em>(VMRay)</em></li><li><a href="https://www.yahoo.com/news/world/articles/iran-reportedly-used-1970s-phone-162553330.html">Iran Reportedly Used a 1970s Phone Protocol to Track U.S. Troops Before Missile Strikes</a> <em>(Yahoo)</em></li><li><a href="https://www.fsec.or.kr/bbs/detail?menuNo=244&bbsNo=11990">금융보안원 - This report provides an in-depth analysis of attack and money laundering techniques employed by state-backed hacking organizations regarding cross-chain security threats among digital assets</a> <em>(금융보안원)</em></li><li><a href="https://opensourcemalware.com/blog/polinrider-blast-radius-grows">PolinRider Confirmed Footprint Grows 6.5x Since March</a> <em>(OpenSourceMalware)</em></li><li><a href="https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm">European Password Manager Shares Origins and Updates with State-Certified Russian Firm</a> <em>(Organized Crime and Corruption Reporting Project (OCCRP))</em></li><li><a href="https://www.graphika.com/reports/save-the-date-for-spamouflage">Save the Date for Spamouflage</a> <em>(Graphika)</em></li><li><a href="https://securelist.com/tr/hellonet-vipnet/120700/">HelloNet campaign: a threat via the ViPNet update system</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26014/?ref=metacurity.com">ZSB-26014: Zoom Workplace for Windows - Improper Input Validation</a> <em>(Zoom Video Communications, Inc.)</em></li><li><a href="https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/">Windows AppResolver LPE: From AppContainer to SYSTEM</a> <em>(David Carliez)</em></li><li><a href="https://aprl.pet/writing/cve-2026-58532">How I found an integer overflow in tcpip.sys</a> <em>(aprilpet)</em></li><li><a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/">wp2shell: Pre Authentication RCE in WordPress Core</a> <em>(Searchlight Cyber)</em></li><li><a href="https://blog.zsec.uk/wp2shell-code-trace-deep-dive/">wp2shell - Code Trace Deep Dive</a> <em>(ZephrFish (Andy Gill))</em></li><li><a href="https://github.com/Icex0/wp2shell-poc">wp2shell-poc: wp2shell - Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory.</a> <em>(Icex0)</em></li><li><a href="https://arxiv.org/abs/2607.05993">Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures</a> <em>(Zhouhao Ji, Kaikai Pan, and Wenyuan Xu)</em></li><li><a href="https://www.openwall.com/lists/oss-security/2026/07/14/10">CVE-2026-49488: Apache OpenMeetings: Arbitrary File Read</a> <em>(Openwall)</em></li><li><a href="https://github.com/karollooool/CVE-2026-50416-writeup-and-poc">lCVE-2026-50416-writeup-and-poc: CVE-2026-50416: Windows 11 KASLR bypass</a> <em>(karollol)</em></li><li><a href="https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/">Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation</a> <em>(Volexity)</em></li><li><a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas">Report into preliminary inquiries of Qantas</a> <em>(Office of the Australian Information Commissioner)</em></li><li><a href="https://github.com/inclusionAI/SingGuard-NSFA">SingGuard-NSFA: Extensible Guardrails for Agentic AI via Generative Reasoning and Real-Time Classification</a> <em>(SingGuard Team, AI Security Lab, Ant Group)</em></li><li><a href="https://github.com/instavm/tarit">tarit: A hypervisor and sandbox cloud for self-hosted AI agents and RL</a> <em>(Instavm)</em></li><li><a href="https://github.com/secdev02/Incantation">Incantation: AI Deception Layer for  - containing adversarial context designed to redirect or confuse an LLM agent reading your own infrastructure</a> <em>(Casey)</em></li><li><a href="https://wojciechregula.blog/post/golden-gate-appdata-protection/">Crossing the Golden Gate: macOS's New Application Support Protection</a> <em>(Wojciech Reguła)</em></li><li><a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/">White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination</a> <em>(The White House)</em></li><li><a href="https://github.com/NetSPI/AD-PathFinder">AD-PathFinder: Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.</a> <em>(NetSPI)</em></li><li><a href="https://github.com/An0nUD4Y/Offensive-COM">Offensive-COM: Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research.</a> <em>(An0nUD4Y)</em></li><li><a href="https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft">DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft</a> <em>(eSentire)</em></li><li><a href="https://jsac.jpcert.or.jp/">JSAC2027 - January, Tokyo - CFP</a> <em>(JPCERT/CC)</em></li><li><a href="https://assets.sophos.com/X24WTUEQ/at/jbww7pmb8n3gp99wr6hfq4/sophos-state-ransomware-report-2026.pdf">The State of 
Ransomware 2026 - Stolen identities cause 79% of ransomware attacks</a> <em>(Sophos Ltd.)</em></li><li><a href="https://github.com/samyeyo/clx">clx: A cross-platform ahead-of-time Lua compiler and runtime, using C++20 backend</a> <em>(Tine Samir)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-20.mp3" length="10921735" type="audio/mpeg"/>
      <itunes:duration>11:22</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 19, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-19.html</link>
      <pubDate>Sun, 19 Jul 2026 06:01:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260719_060150</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://developer.chrome.com/blog/nhs-passkeys-case-study">How NHS England improved sign-in times and saved over £1m with passkeys</a> <em>(Google LLC)</em></li><li><a href="https://huggingface.co/blog/security-incident-july-2026">Security incident disclosure — July 2026 - "The intrusion started where AI platforms are uniquely exposed: the data-processing pipeline."</a> <em>(Hugging Face)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-19.mp3" length="1421105" type="audio/mpeg"/>
      <itunes:duration>1:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-18.html</link>
      <pubDate>Sat, 18 Jul 2026 06:07:52 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260718_060752</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault">Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2</a> <em>(Genians)</em></li><li><a href="https://www.security.com/threat-intelligence/daxin-returns-stupig">Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor</a> <em>(Broadcom)</em></li><li><a href="https://www.occrp.org/en/project/the-pegasus-project/co-founder-of-controversial-spyware-firm-had-israeli-diplomatic-passport">Co-Founder of Controversial Spyware Firm Had Israeli Diplomatic Passport</a> <em>(Organized Crime and Corruption Reporting Project (OCCRP))</em></li><li><a href="https://www.theguardian.com/news/2026/jul/16/morocco-intelligence-insider-reveals-widespread-use-hacking-software-pegasus">Moroccan intelligence insider reveals widespread use of Pegasus hacking software</a> <em>(The Guardian)</em></li><li><a href="https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql">Detections for LegacyHive exploitation by GossiTheDog</a> <em>(GossiTheDog)</em></li><li><a href="https://www.gov.uk/government/publications/revised-telecommunications-security-code-of-practice-2026-version-11">Revised Telecommunications Security Code of Practice 2026 (version 1.1)</a> <em>(Department for Science, Innovation and Technology)</em></li><li><a href="https://media.defense.gov/2026/Jul/14/2003961238/-1/-1/0/260714-D-AB123-1001.PDF">Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers</a> <em>(media.defense.gov)</em></li><li><a href="https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions">AsyncAPI Supply Chain Compromise via GitHub Actions</a> <em>(Wiz)</em></li><li><a href="https://www.bbc.co.uk/news/articles/c4gyg0y6yg2o">Teen hackers jailed after live streaming cyber attack on TfL - sentenced to five years and six months in prison.</a> <em>(BBC)</em></li><li><a href="https://github.com/Astharot15/COMLoaderAstharot/">COM Hijack for CLSID {9FC8E510-A27C-4B3B-B9A3-BF65F00256A8}</a> <em>(Astharot15)</em></li><li><a href="https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline">CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining</a> <em>(Tiziano Marra)</em></li><li><a href="https://medium.com/@s12deff/registry-snapshots-for-post-exploitation-enumeration-fbf5798091da">Registry Snapshots for Post Exploitation Enumeration</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://github.com/toneillcodes/UnwindRaven">UnwindRaven is a Windows x64 offensive research framework that constructs fully synthetic call stacks at thread startup time, making a newly created thread appear</a> <em>(toneillcodes)</em></li><li><a href="https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/">There and Back Again: An Operators Guide on NTLM Relaying Egress</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/toneillcodes/windows-process-injection">windows-process-injection: A collection of techniques for process injection on Windows</a> <em>(toneillcodes)</em></li><li><a href="https://speakerdeck.com/nttcom/ghost-in-the-7-zip-the-shadow-of-residential-proxies-creeping-into-your-life">Ghost in the 7‑Zip: The Shadow of Residential Proxies Creeping into Your Life</a> <em>(DOCOMO BUSINESS, Inc.)</em></li><li><a href="https://github.com/Sizeable-Bingus/BingusLdr">BingusLdr: BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.</a> <em>(Sizeable-Bingus)</em></li><li><a href="https://kirchware.com/Modular-PIC-Implant-Design">Modular PIC Implant Design</a> <em>(Kirchware)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-18.mp3" length="8920964" type="audio/mpeg"/>
      <itunes:duration>9:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-17.html</link>
      <pubDate>Fri, 17 Jul 2026 06:05:38 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260717_060538</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://go.rewardsforjustice.net/cyber-medialand-en/">REWARD UP TO $10,000,000 USD - FOR INFORMATION ON Russian Malicious Cyber Actors</a> <em>(U.S. Department of State)</em></li><li><a href="https://www.reuters.com/world/alleged-russian-cyber-spy-boston-case-previously-worked-kaspersky-source-says-2026-07-15/">Alleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show</a> <em>(Thomson Reuters)</em></li><li><a href="https://s2w.inc/en/resource/detail/1096">BirdCall: ScarCruft Malware Masquerading as Zangi Messenger</a> <em>(S2W)</em></li><li><a href="https://mp.weixin.qq.com/s/6hjjsEuuOTk8_FJrXWe9Ew">Analysis of attack actions suspected to be from the APT-C-26 (Lazarus) group upgrading its monitoring program</a> <em>(奇安信威胁情报中心)</em></li><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a> <em>(Hunt.io)</em></li><li><a href="https://expel.com/blog/introducing-cylindricalcanine/">Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident</a> <em>(Expel, Inc.)</em></li><li><a href="https://www.cyderes.com/howler-cell/tracking-donot-apt-c-35-bangladesh-military-intrusion">DoNot (APT-C-35) Intrusion Targeting Bangladesh Military Personnel</a> <em>(Cyderes)</em></li><li><a href="https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix">TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains</a> <em>(Elastic)</em></li><li><a href="https://tailscale.com/security-bulletins#ts-2026-009">Tailscale: Tailscale SSH previously accepted usernames that contained a leading - character. On Linux platforms these usernames were passed as arguments to getent(1) leading to ACL bypass</a> <em>(Tailscale Inc.)</em></li><li><a href="https://github.com/secdev02/cyber-decoy">cyber-decoy: Experimental Decoy Broker</a> <em>(secdev02)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-17.mp3" length="4488925" type="audio/mpeg"/>
      <itunes:duration>4:40</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-16.html</link>
      <pubDate>Thu, 16 Jul 2026 06:07:24 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260716_060724</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.justice.gov/usao-ndoh/pr/three-russian-nationals-indicted-international-cybercrimes-resulting-more-62m-losses">Three Russian Nationals Indicted for International Cybercrimes Resulting in More Than $62M in Losses to Victims</a> <em>(U.S. Attorney's Office for the Northern District of Ohio)</em></li><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blogs.jpcert.or.jp/en/2026/07/apt-c-60_2026.html">Update on Attacks by Threat Group APT-C-60 in 2026</a> <em>(JPCERT/CC)</em></li><li><a href="https://cip.gov.ua/en/news/cert-ua-opracyuvala-3309-kiberincidentiv-v-pershomu-pivrichchi-2026-roku">CERT-UA Handled 3,309 Cyber Incidents in the First Half of 2026</a> <em>(State Service of Special Communications and Information Protection of Ukraine)</em></li><li><a href="https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/">Malicious GitHub Campaign: Fake "Arctic Wolf" and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer</a> <em>(Arctic Wolf)</em></li><li><a href="https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026">Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026</a> <em>(DomainTools)</em></li><li><a href="https://www.bbc.co.uk/news/articles/cp3x37lw1ndo">Public to be told how to prepare for cyber-attack and weather emergencies</a> <em>(British Broadcasting Corporation)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/">Forgotten UEFI shims undermining Secure Boot</a> <em>(ESET)</em></li><li><a href="https://github.com/MSNightmare/LegacyHive">LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008">SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade</a> <em>(SonicWall)</em></li><li><a href="https://research.jfrog.com/post/miasma-worm-returns-to-npm/">Miasma Worm Returns to npm</a> <em>(JFrog)</em></li><li><a href="https://research.jfrog.com/post/lucide-proxy-npm-malware-campaign/">Lucide Proxy: Turning Student Web Proxies into DDoS Bots</a> <em>(JFrog)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy">OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration</a> <em>(Proofpoint)</em></li><li><a href="https://ctrlaltintel.com/research/VoidBlizzard/">Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links</a> <em>(Hunt.io)</em></li><li><a href="https://trustedsec.com/blog/pandoras-container-part-1-unpacking-azure-container-security?hss_channel=tw-403811306">Pandora’s Container Part 1: Unpacking Azure Container Security</a> <em>(TrustedSec)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-16.mp3" length="6039136" type="audio/mpeg"/>
      <itunes:duration>6:17</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-15.html</link>
      <pubDate>Wed, 15 Jul 2026 06:04:04 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260715_060404</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/">Targeting and Compromise of French Entities Using the Turla Intrusion Set</a> <em>(Agence nationale de la sécurité des systèmes d'information (ANSSI))</em></li><li><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting">UK and Allies urge critical sectors to improve defences against Russian intelligence targeting</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF">Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.aol.com/articles/russian-man-pleads-not-guilty-213052000.html">Russian man pleads not guilty in US cyber espionage case</a> <em>(AOL Media LLC)</em></li><li><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions">UK and EU strike Russian cyber networks with new sanctions</a> <em>(Foreign, Commonwealth &amp; Development Office)</em></li><li><a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/">Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension</a> <em>(Stripe OLT)</em></li><li><a href="https://socket.dev/blog/jscrambler-supply-chain-attack">jscrambler npm Package Compromised in Supply Chain Attack</a> <em>(Socket)</em></li><li><a href="https://www.cyber.gc.ca/en/news-events/sharpviewstateking-stealthy-implant-framework">SharpViewStateKing: The stealthy implant framework - Canadian Centre for Cyber Security</a> <em>(Canadian Centre for Cyber Security)</em></li><li><a href="https://github.com/penberg/chimera">chimera: Sandbox untrusted code with safe access to the host.</a> <em>(Pekka Enberg)</em></li><li><a href="https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident">Lessons from CISA’s Cyber Incident</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-15.mp3" length="4082251" type="audio/mpeg"/>
      <itunes:duration>4:15</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-14.html</link>
      <pubDate>Tue, 14 Jul 2026 06:08:11 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260714_060811</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.lexfo.fr/opendir-to-phishing-operator.html">One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators</a> <em>(Ambionics)</em></li><li><a href="https://socradar.io/blog/wp-shellstorm-expose-1-4m-wordpress-sites/">How WP-SHELLSTORM Exposed 1.4M WordPress Sites</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html?unlocked_article_code=1.xFA.a_dB.AaB0wEs-NI-X&referringSource=articleShare">How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist</a> <em>(The New York Times)</em></li><li><a href="https://www.asahi.com/sp/ajw/articles/16703618">Teen accused of using ChatGPT to delete 46,000 anime accounts</a> <em>(The Asahi Shimbun Company)</em></li><li><a href="https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification">Unfit to Boot: Breaking U-Boot's FIT Signature Verification</a> <em>(Binarly)</em></li><li><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-19/">Patch Release Update: Zimbra 10.1.19 - 'security issue in the Classic Web Client where a specially crafted email could run malicious code when the email is opened'</a> <em>(Synacor)</em></li><li><a href="https://www.synacktiv.com/en/publications/the-sql-server-unicode-problem-why-your-data-might-not-be-what-you-think-it-is">The SQL Server Unicode problem: why your data might not be what you</a> <em>(Synacktiv)</em></li><li><a href="https://www.justice.gov/opa/pr/man-serving-federal-prison-sentence-charged-theft-forfeited-cryptocurrency">Man Serving Federal Prison Sentence Charged with Theft of Forfeited Cryptocurrency</a> <em>(United States Department of Justice)</em></li><li><a href="https://x.com/i/status/2075606692335956016">AnyDesk forensic artefacts</a> <em>(Ayush Anand)</em></li><li><a href="https://cloudbrothers.info/en/unified-sign-logs-advanced-hunting/">Use Unified Sign-In logs in Advanced Hunting</a> <em>(Fabian Bader)</em></li><li><a href="https://specterops.io/blog/2026/07/09/finding-socks-with-proxywatch/">Finding SOCKS with Proxywatch</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/0x4D31/stinger">stinger: Unprivileged endpoint deception for macOS and Linux workstations. Uses FIFO baits, other local traps, and protected sessions to detect secret collection as it happens.</a> <em>(0x4D31)</em></li><li><a href="https://msendpointmgr.com/2026/07/03/epm-part-3-writing-intune-endpoint-privilege-management-rules-for-the-real-world-file-hash-certificate-and-when-each-one-is-the-wrong-choice/">EPM Part 3: Writing Intune Endpoint Privilege Management rules for the real world: File hash, certificate, and when each one is the wrong choice - MSEndpointMgr</a> <em>(MSEndpointMgr)</em></li><li><a href="https://gist.github.com/AlloySecureGroup/5062355dc48f1e333223f0dda90e7cda">Scheme Hunter - Enumerate URI schemes and prototype invocation - WDAC / AppLocker Bypass Recon Scripts</a> <em>(AlloySecureGroup)</em></li><li><a href="https://github.com/ssteelfactor-oss/Kestrel">Kestrel: Passive Active Directory security enumeration via native ADSI/COM interfaces.</a> <em>(ssteelfactor-oss)</em></li><li><a href="https://github.com/ail-project/tempolocus">tempolocus: Tempolocus is a time-series activity patterns and approximate location inference</a> <em>(CIRCL)</em></li><li><a href="https://trainsec.net/library/windows-internals/how-windows-app-execution-aliases-work-and-how-to-read-them-in-c/">How Windows App Execution Aliases Work (and How to Read Them in C++)</a> <em>(Pavel Yosifovich)</em></li><li><a href="https://trustedsec.com/blog/jq-for-hackers">JQ for Hackers</a> <em>(TrustedSec)</em></li><li><a href="https://github.com/IceCubeSandwich/CaddySmith">CaddySmith: Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.</a> <em>(IceCubeSandwich)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-14.mp3" length="7672520" type="audio/mpeg"/>
      <itunes:duration>7:59</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-13.html</link>
      <pubDate>Mon, 13 Jul 2026 06:04:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260713_060450</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://intel.webamon.com/blog/tracking-a-k8-branded-web-cluster/">Tracking a K8-Branded Web Cluster Across 10,156 Domains</a> <em>(Webamon)</em></li><li><a href="https://www.security.com/threat-intelligence/goddamn-ransomware-beast-rebrand">GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses</a> <em>(Broadcom)</em></li><li><a href="https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/">Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)</a> <em>(AmberWolf)</em></li><li><a href="https://zimperium.com/blog/redwing-a-mobile-malware-as-a-service-operation">RedWing: A Mobile Malware-as-a-Service Operation</a> <em>(Zimperium)</em></li><li><a href="https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor/">nodemon-sudo: an npm Backdoor With No Install Script</a> <em>(SafeDep)</em></li><li><a href="https://medium.com/@omgAPT/adversarial-intelligence-local-llms-for-automated-attacks-3bf684c51544">Adversarial Intelligence: Local LLMs for Automated Attacks</a> <em>(Mike Scutt)</em></li><li><a href="https://jakeotte.com/posts/klist-revisited.html">klist.exe Revisited: Internals and Further Use Cases</a> <em>(Jake Otte)</em></li><li><a href="https://github.com/Chaelsoo/nimcrypt">nimcrypt: Nim-based encryption tool for obfuscating shellcode and payloads for evading Windows Defender.</a> <em>(Chaelsoo)</em></li><li><a href="https://github.com/jakeotte/klist2ccache">klist2ccache: Dump TGTs remotely and convert Windows' klist binary output to ccache.</a> <em>(jakeotte)</em></li><li><a href="https://github.com/bkerler/ida_rpc">ida_rpc: IDA Pro RPC for assisted RE-tasks</a> <em>(B.Kerler)</em></li><li><a href="https://arxiv.org/abs/2607.05916">Beyond the Syntax: Do Security Experts Trust LLMs for NIDS Rule Engineering?</a> <em>(arXiv)</em></li><li><a href="https://github.com/Corgea/Sighthound/">Sighthound: rule-based SAST scanner</a> <em>(Corgea)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-13.mp3" length="4945755" type="audio/mpeg"/>
      <itunes:duration>5:09</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-12.html</link>
      <pubDate>Sun, 12 Jul 2026 06:02:13 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260712_060213</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.extrahop.com/blog/anatomy-of-an-attack-darkspectre">DarkSpectre — a Chinese state-sponsored threat actor, maintains persistent access to enterprise environments by weaponizing legitimate browser extensions after establishing a trusted user</a> <em>(ExtraHop)</em></li><li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploitation-campaign-targeting-website-content-management-systems-cms">Large-scale exploitation campaign targeting website content management systems (CMS)</a> <em>(Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC))</em></li><li><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/10/nederland-doelwit-van-russische-spionageoperatie-via-ip-cameras">Nederland doelwit van Russische spionageoperatie via IP-camera’s | The Netherlands targeted by Russian espionage operation via IP cameras</a> <em>(Rijksoverheid)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-12.mp3" length="1841990" type="audio/mpeg"/>
      <itunes:duration>1:55</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-11.html</link>
      <pubDate>Sat, 11 Jul 2026 06:05:50 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260711_060550</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/">One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement</a> <em>(SentinelOne)</em></li><li><a href="https://socket.dev/blog/malicious-go-module-exposes-github-malware-lure-network">Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories</a> <em>(Socket)</em></li><li><a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html">Onderzoek naar hack Odido wijst op mogelijke betrokkenheid Nederlanders | Investigation into Odido hack points to possible involvement of the Dutch</a> <em>(Politie Nederland)</em></li><li><a href="https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor/">Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor</a> <em>(Datadog)</em></li><li><a href="https://opensourcemalware.com/blog/cybersecurity-startup-publishes-infostealers-to-npm">Cybersecurity Startup Publishes Infostealers to NPM</a> <em>(Paul McCarty)</em></li><li><a href="https://github.com/V4bel/Januscape">Januscape: Guest-to-Host Escape in KVM/x86</a> <em>(Hyunwoo Kim)</em></li><li><a href="https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions">XRING: Crashing XQUIC with spec-compliant QPACK instructions</a> <em>(FoxIO)</em></li><li><a href="https://zwclose.github.io/2026/07/08/rtsper2.html">Vulnerabilities of Realtek SD card reader driver, part2</a> <em>(zwclose)</em></li><li><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware">CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware</a> <em>(Huntress)</em></li><li><a href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps">Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps</a> <em>(Socket)</em></li><li><a href="https://sites.google.com/view/agentic-botnets/home">Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting</a> <em>(Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/">GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware</a> <em>(Microsoft)</em></li><li><a href="https://windows-internals.com/random-windows-things-part-1-previousmode-mitigation/">Random Windows Things Part 1: PreviousMode Mitigation</a> <em>(Winsider Seminars &amp; Solutions Inc.)</em></li><li><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">Evolving Windows vulnerability management to meet the speed of AI-powered discovery</a> <em>(Microsoft)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-11.mp3" length="5545944" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-10.html</link>
      <pubDate>Fri, 10 Jul 2026 06:02:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260710_060227</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cotool.ai/research">AI Research in Security Operations Pushing the frontier of AI agents for real security work</a> <em>(Cotool)</em></li><li><a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/">Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed - or written another way AI slower than most ransomware crews</a> <em>(Sygnia)</em></li><li><a href="https://sensepost.com/blog/2026/process-parameter-poisoning/">Process Parameter Poisoning</a> <em>(Orange Cyberdefense)</em></li><li><a href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/">GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos</a> <em>(Noma Labs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-10.mp3" length="2155459" type="audio/mpeg"/>
      <itunes:duration>2:14</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-09.html</link>
      <pubDate>Thu, 09 Jul 2026 06:04:15 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260709_060415</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.mjib.gov.tw/news/Details/1/1196">The Investigation Bureau has cracked a case involving the Chinese Communist Party's cyber army, which impersonated international journalists to conduct social engineering attacks</a> <em>(Ministry of Justice Investigation Bureau)</em></li><li><a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/">Cavern Manticore: Exposing Iran-Linked Modular C2 Framework</a> <em>(Check Point Research)</em></li><li><a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16937">The National Police have arrested a suspected collaborator of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest.</a> <em>(Dirección General de la Policía)</em></li><li><a href="https://blog.talosintelligence.com/uat-7810/">UAT-7810 continues building ORB networks using new malware</a> <em>(Cisco Systems, Inc.)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation">One Email Closer to the Edge: UNK_MassTraction &amp; the Physics of Exploitation</a> <em>(Proofpoint)</em></li><li><a href="https://github.com/AlloySecureGroup/PhantomFS">PhantomFS: PhantomFS is a Windows honeypot that projects convincing decoy files — credentials, financials, SSH keys — into a virtual directory via ProjFS, then fires instant Event Log</a> <em>(Alloy Secure)</em></li><li><a href="https://www.semperis.com/blog/windows-privilege-abuse-can-lead-to-active-directory-compromise/">Windows Privilege Abuse: Attackers' Path to Active Directory Compromise</a> <em>(Semperis)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/">Recovering Active ADFS Signing Keys via Machine DPAPI | Google Cloud Blog</a> <em>(Google)</em></li><li><a href="https://github.com/SmtimesIWndr/gdid-reversal">Full writeup of the Windows GDID - Global Device Identifier fully reverse engineered</a> <em>(SmtimesIWndr)</em></li><li><a href="https://github.com/SmtimesIWndr/GDID-Disabler/">GDID Disabler - Windows</a> <em>(SmtimesIWndr)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-09.mp3" length="3977761" type="audio/mpeg"/>
      <itunes:duration>4:08</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-08.html</link>
      <pubDate>Wed, 08 Jul 2026 06:01:44 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260708_060144</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://rastamouse.me/cpl-hook-chains/">Hook Chains (how I built Crystal Kit incorrectly*)</a> <em>(Rasta Mouse)</em></li><li><a href="https://github.com/secdev02/EasyTokens">EasyTokens: Kali365 - EvilTokens Replica</a> <em>(Casey Smith)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-08.mp3" length="1308256" type="audio/mpeg"/>
      <itunes:duration>1:21</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-07.html</link>
      <pubDate>Tue, 07 Jul 2026 06:07:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260707_060746</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>17</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.trendmicro.com/en_us/research/26/f/tonresolver.html">TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry</a> <em>(Trend Micro)</em></li><li><a href="https://sapirxfed.com/2026/07/05/does-anyone-even-use-github-for-federated-authentication/">Does anyone even use GitHub for federated authentication?</a> <em>(Sapir)</em></li><li><a href="https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168">Multiple Local Privilege Escalation Vulnerabilities in Little Orbit GFAC Driver (GFAC_Sys_x64.sys)</a> <em>(FzRsLLaSheR)</em></li><li><a href="https://dl.acm.org/doi/10.1145/3779208.3785387">Identity Crisis in Confidential Computing: Formal Analysis of Attested TLS</a> <em>(Association for Computing Machinery (ACM))</em></li><li><a href="https://practicalsecurityanalytics.com/improved-rpcghosting/">Improved RpcGhosting</a> <em>(Practical Security Analytics)</em></li><li><a href="https://securitylog.sva.de/2026/offsec/escalating-from-on-prem-to-entra-through-mitm-attacks/">Escalating from On-prem to Entra through MITM Attacks</a> <em>(SVA System Vertrieb Alexander GmbH)</em></li><li><a href="https://www.synacktiv.com/en/publications/exploring-cross-domain-cross-forest-rbcd-part-2">Exploring cross-domain &amp; cross-forest RBCD: part 2</a> <em>(Synacktiv)</em></li><li><a href="https://safedep.io/marketfront-dependency-confusion-campaign/">@marketfront: 25 npm Packages Reuse a Known Lure</a> <em>(Safedep)</em></li><li><a href="https://dmpdump.github.io/posts/Backdoor_iKuai_Routers/">Linux Backdoor Targeting iKuai Routers</a> <em>(dmpdump)</em></li><li><a href="https://github.com/iss4cf0ng/NebulaPulsar">NebulaPulsar: NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of the Alien project.</a> <em>(iss4cf0ng)</em></li><li><a href="https://github.com/CodeXTF2/GeoLocation_BOF">GeoLocation_BOF: Cobalt Strike BOF to obtain location data</a> <em>(CodeXTF2)</em></li><li><a href="https://justruss.tech/index.php/2026/06/21/hunting-sleeping-giants-detecting-encrypted-beacon-sleep-obfuscation/">Hunting Sleeping Giants: Detecting Encrypted Beacon Sleep Obfuscation</a> <em>(Russell Allen)</em></li><li><a href="https://github.com/pIat0n/BareMetal-RAM-Dumper">BareMetal-RAM-Dumper: A bare-metal x86 utility to dump physical RAM directly to disk. Built and tested for Cold Boot Attack experiments on frozen memory.</a> <em>(pIat0n)</em></li><li><a href="https://github.com/kernelstub/Nox">Nox: Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning.</a> <em>(kernelstub)</em></li><li><a href="https://github.com/elder-plinius/T3MP3ST">T3MP3ST: autonomous red teaming platform; multi-agent offensive-security meta-harness</a> <em>(elder-plinius)</em></li><li><a href="https://www.zetter-zeroday.com/arrest-of-iranian-hacker-spotlights-irans-movement-into-economic-espionage-and-ip-theft/">Arrest of Iranian Hacker Spotlights Iran’s Movement into Economic Espionage and IP Theft</a> <em>(Kim Zetter)</em></li><li><a href="https://blog.synapticsystems.de/inside-kimsukys-chm-tradecraft-multi-stage-execution-and-selective-payload-delivery/">Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery</a> <em>(Synaptic Systems)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-07.mp3" length="6969931" type="audio/mpeg"/>
      <itunes:duration>7:15</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-06.html</link>
      <pubDate>Mon, 06 Jul 2026 06:07:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260706_060727</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>21</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.greynoise.io/blog/exploitation-citrixbleed-2-cve-2025-5777-before-public-poc">Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public</a> <em>(GreyNoise, Inc.)</em></li><li><a href="https://securelist.com/the-gentlemen-raas/120447/">The Gentlemen RaaS: rapid growth and a new ransomware variant</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://sigreturn.com/blog/rhysida-analysis-decryption/">How I broke Rhysida ransomware encryption</a> <em>(Sigreturn Labs)</em></li><li><a href="https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/">From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks</a> <em>(Arctic Wolf)</em></li><li><a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/">Armored Likho's new weapon: BusySnake Stealer - "tied to a previously unknown APT group that we dubbed Armored Likho (also known as Eagle Werewolf based on circumstantial evidence)."</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://lab52.io/blog/gru-military-unit-67606/">GRU: military unit 67606</a> <em>(S2 Grupo)</em></li><li><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023">WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication -</a> <em>(WatchGuard Technologies)</em></li><li><a href="https://infosecwriteups.com/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9-1-10-cvss-8-8-high-e4bf33e67e82">Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High (CVE-2026–10525)</a> <em>(Sai Krishna Kothapalli)</em></li><li><a href="https://github.com/J-jaeyoung/bad-epoll">Bad Epoll: The bug missed by Mythos</a> <em>(Jaeyoung Chung)</em></li><li><a href="https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families">Fake Google and Cloudflare verification pages spread multiple malware families</a> <em>(Malwarebytes)</em></li><li><a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/">PamStealer: macOS Malware Posing as Clipboard Manager App</a> <em>(Jamf)</em></li><li><a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/">FBI Seizes NetNut Proxy Platform, Popa Botnet</a> <em>(Brian Krebs)</em></li><li><a href="https://detect.fyi/the-blind-spot-in-the-watchtower-detections-for-when-someone-attacks-your-sentinel-897709f0dcd9">The Blind Spot in the Watchtower: Detections for When Someone Attacks Your Sentinel</a> <em>(Alex Teixeira)</em></li><li><a href="https://www.praetorian.com/blog/knossos-decoy-environments/">Knossos: Procedurally Generated Decoy Environments</a> <em>(Praetorian)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/building-more-resilient-cni-what-industry-pen-testers-told-us">Building more resilient CNI: what industry penetration testers told us</a> <em>(National Cyber Security Centre (NCSC))</em></li><li><a href="https://bishopfox.com/blog/on-favicons-from-browser-icons-to-attack-surface-intelligence">On Favicons: From Browser Icons to Attack Surface Intelligence</a> <em>(Bishop Fox)</em></li><li><a href="https://github.com/CodeXTF2/OpenUDC2">OpenUDC2: This is an open source implementation of the UDC2 spec used in Cobalt Strike</a> <em>(CodeXTF2)</em></li><li><a href="https://github.com/qmadev/tf-mythic-azure">tf-mythic-azure: Automatically deploying Mythic C2 in Azure using Terraform</a> <em>(qmadev)</em></li><li><a href="https://expel.com/blog/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs/">Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs</a> <em>(Expel)</em></li><li><a href="https://labs.k7computing.com/index.php/boss-scam-dont-trust-every-urgent-message-from-your-boss/">Boss Scam: Don’t Trust Every “Urgent” Message from Your Boss! - "It runs in the background till it finds an active WhatsApp Web session in Chromium-based browsers"</a> <em>(K7 Labs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-06.mp3" length="8789725" type="audio/mpeg"/>
      <itunes:duration>9:09</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-05.html</link>
      <pubDate>Sun, 05 Jul 2026 06:02:26 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260705_060226</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/">Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab</a> <em>(The Citizen Lab)</em></li><li><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/">Accelerating EDR Evasion with LLM-Driven Analysis</a> <em>(SpecterOps)</em></li><li><a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/">ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365</a> <em>(Cisco Talos)</em></li><li><a href="https://github.com/ZakiPedio/GadgetSniper">GadgetSniper: Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler</a> <em>(ZakiPedio)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-05.mp3" length="2209794" type="audio/mpeg"/>
      <itunes:duration>2:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-04.html</link>
      <pubDate>Sat, 04 Jul 2026 06:03:17 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260704_060317</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands">PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems</a> <em>(Socket)</em></li><li><a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat">Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool</a> <em>(Recorded Future)</em></li><li><a href="https://discuss.elastic.co/t/kibana-7-17-15-8-11-1-security-update-esa-2026-53/387449">Kibana 7.17.15, 8.11.1 Security Update (ESA-2026-53) - Improper Output Neutralization for Logs in Kibana can lead to log injection via Log Injection-Tampering-Forging</a> <em>(Elastic)</em></li><li><a href="https://github.com/JVBotelho/skewrun">skewrun: Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.</a> <em>(JVBotelho)</em></li><li><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/dont-pay-the-ransom-warning-to-organisations-to-protect-themselves-from-ransomware-attacks-as-more-than-320-businesses-affected-last-year/">Don’t pay the ransom: Warning to organisations to protect themselves from ransomware attacks as more than 320 businesses affected last year</a> <em>(City of London Police)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-04.mp3" length="2356497" type="audio/mpeg"/>
      <itunes:duration>2:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-03.html</link>
      <pubDate>Fri, 03 Jul 2026 06:05:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260703_060522</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/">How the ToddyCat APT group gains access to Gmail accounts</a> <em>(Kaspersky Lab)</em></li><li><a href="https://research.jfrog.com/post/rollup-polyfill-masquerading/">Lazarus-Linked npm Malware Masquerades as Rollup Polyfills</a> <em>(JFrog)</em></li><li><a href="https://nsfocusglobal.com/ai-security-incident-case-miasma-worm-attacked-microsoft-github/">AI Security Incident Case: Miasma Worm Attacked Microsoft GitHub</a> <em>(NSFOCUS)</em></li><li><a href="https://webflow.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">JADEPUFFER: Agentic ransomware for automated database extortion</a> <em>(Sysdig)</em></li><li><a href="https://github.com/RedByte1337/CredSpy">CredSpy: Entra ID user enumeration and auth method discovery via the public GetCredentialType API</a> <em>(Keanu Nys)</em></li><li><a href="https://www.esentire.com/blog/fortinet-vulnerability-cve-2026-35616-and-ekz-stealer-attacking-obfuscating-compilers-with-binary-ninja-workflows">Fortinet Vulnerability CVE-2026-35616 and EKZ Stealer, Attacking Obfuscating Compilers with Binary Ninja Workflows</a> <em>(eSentire, Inc.)</em></li><li><a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/">ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365</a> <em>(Cisco Talos)</em></li><li><a href="https://www.extrahop.com/blog/vipertunnel">Anatomy of an Attack: VIPERTUNNEL</a> <em>(ExtraHop)</em></li><li><a href="https://github.com/Chaelsoo/Hollow">Hollow: hollow is a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.</a> <em>(Chaelsoo)</em></li><li><a href="https://github.com/NirvanaOn/SpotifyC2/">SpotifyC2: SpotifyC2 is a cybersecurity research project that demonstrates cloud-based command communication using Spotify playlists for command retrieval and Telegram for output delivery</a> <em>(NirvanaOn)</em></li><li><a href="https://blog.xlab.qianxin.com/rustduck-en/">RustDuck: An In-Depth Analysis of a Two-Stage Botnet</a> <em>(Qianxin XLAB)</em></li><li><a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited">Alleged Member of Criminal Cyber Hacking Group “Scattered Spider” Arrested in Finland and Extradited to the United States</a> <em>(United States Department of Justice)</em></li><li><a href="https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/">A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain</a> <em>(Blackpoint Cyber)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-03.mp3" length="5550124" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-02.html</link>
      <pubDate>Thu, 02 Jul 2026 06:01:37 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260702_060137</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li>The Morris Worm: When a Graduate Student Broke the Internet <em>(Historical Archive)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-02.mp3" length="1026551" type="audio/mpeg"/>
      <itunes:duration>1:04</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - July 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-07-01.html</link>
      <pubDate>Wed, 01 Jul 2026 06:05:24 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260701_060524</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/">Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON</a> <em>(Acronis)</em></li><li><a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/">SOCRadar has attributed FortiBleed to the Lynx / INC ransomware group</a> <em>(SOCRadar® Cyber Intelligence Inc.)</em></li><li><a href="https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/">From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira - The DFIR Report</a> <em>(The DFIR Report)</em></li><li><a href="https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/">Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer</a> <em>(JFrog)</em></li><li><a href="https://www.darknavy.org/blog/the_biometric_authtoken_heist/">The Biometric AuthToken Heist: Cracking PINs and Bypassing CE via a Long-Ignored Attack Surface (Android)</a> <em>(DARKNAVY)</em></li><li><a href="https://github.com/douglasmun/pagecache-lpe-containment-kit">pagecache-lpe-containment-kit: defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation</a> <em>(Douglas Mun)</em></li><li><a href="https://github.com/sgkdev/ipv6_frag_escape">ipv6_frag_escape: Linux LPE - Reliable Jail/Container Escape</a> <em>(sgkdev)</em></li><li><a href="https://practicalsecurityanalytics.com/dumping-lsass-without-touching-disk-improvements-to-shadowdumper/">Dumping LSASS Without Touching Disk: Improvements to ShadowDumper</a> <em>(Practical Security Analytics LLC)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/hypervisor-cheats-part-2-ept-npt-split-views-and-second-stage-fault-evidence/">About Hypervisor Cheats, Part 2: EPT/NPT, Split Views, and Second-Stage Fault Evidence</a> <em>(Kernullist)</em></li><li><a href="https://www.nextron-systems.com/2026/06/26/anatomy-of-a-whql-signed-windows-filtering-platform-wfp-kernel-resident-network-backdoor/">Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor</a> <em>(www.nextron-systems.com)</em></li><li><a href="https://notpayloads.blob.core.windows.net/slides/Azure_PrivEsc_Troopers-2026.pdf">Modern Adventures in Azure 
Privilege Escalation</a> <em>(NetSPI)</em></li><li><a href="https://dfir.ru/2026/06/29/mark-of-the-web-the-rules-changed-the-tools-didnt/">Mark-of-the-Web: the rules changed, the tools didn’t</a> <em>(Maxim Suhanov)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-07-01.mp3" length="4919841" type="audio/mpeg"/>
      <itunes:duration>5:07</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-30.html</link>
      <pubDate>Tue, 30 Jun 2026 06:05:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260630_060516</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.youtube.com/watch?v=-ueCcEdDjOM">Understanding Trends &amp; Patterns In Insider Threat: Analysis Of 1,000+ Cases</a> <em>(Jawed Karim)</em></li><li><a href="https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/">Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment</a> <em>(Seqrite)</em></li><li><a href="https://censys.com/blog/asyncrat-family-threat-overview/">AsyncRAT Family Threat Overview</a> <em>(Censys)</em></li><li><a href="https://www.goblinloot.net/2026/06/adversaries-in-proxmox.html">Proxmox and Adversaries</a> <em>(ZombieLucy)</em></li><li><a href="https://github.blog/changelog/2026-06-18-control-who-and-what-triggers-github-actions-workflows/">Control who and what triggers GitHub Actions workflows - GitHub Changelog</a> <em>(GitHub)</em></li><li><a href="https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf">Inside StegoAd: How a Threat Actor Evolved to Fuel Silent Ad Fraud and Credential Theft at Scale</a> <em>(Orenda Security LLC)</em></li><li><a href="https://www.fortinet.com/blog/threat-research/from-ci-cd-to-cloud-data-how-shai-hulud-persistence-leads-to-redshift-breach">From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach</a> <em>(Fortinet, Inc.)</em></li><li><a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html">CVE-2026-11374: Account takeover vulnerability in ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus</a> <em>(ManageEngine)</em></li><li><a href="https://github.com/licitrasimone/CrystalSliver">CrystalSliver: Crystal Palace Evasion kit for Sliver</a> <em>(Simone Licitra)</em></li><li><a href="https://github.com/28Zaaky/khaos-c2">khaos-c2: KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.</a> <em>(28Zaaky)</em></li><li><a href="https://specterops.io/blog/2026/06/26/time-travel-debugging-with-codex/">Time Travel Debugging with Codex</a> <em>(SpecterOps)</em></li><li><a href="https://blog.zsec.uk/harnessing-harnesses/">Harnessing Harnesses - Climbing the LLM Hills</a> <em>(ZephrSec)</em></li><li><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">Customer &amp; Partner Updates: Remote Code Execution Vulnerability in PTC’s Windchill and FlexPLM Solutions | June 2026 | PTC</a> <em>(PTC)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-30.mp3" length="6060870" type="audio/mpeg"/>
      <itunes:duration>6:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-29.html</link>
      <pubDate>Mon, 29 Jun 2026 06:03:36 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260629_060336</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>8</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ic3.gov/PSA/2026/PSA260626">Internet Crime Complaint Center (IC3) | Russian Intelligence Services Continue to Target Commercial Messaging Applications</a> <em>(Internet Crime Complaint Center (IC3))</em></li><li><a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/">LOTSを活用して進化を続けるKimJongRAT – KimJongRAT continues to evolve by utilizing LOTS</a> <em>(Internet Initiative Japan Inc. (IIJ))</em></li><li><a href="https://github.com/cloudflare/security-audit-skill">security-audit-skill: A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings</a> <em>(Cloudflare)</em></li><li><a href="https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/">a CVE dispute</a> <em>(Daniel Stenberg)</em></li><li><a href="https://github.com/hawktrace/CVE-2026-45504/">CVE-2026-45504: CVE-2026-45504 Microsoft Exchange File Read -  allows an authenticated low-privileged user to read arbitrary local files from the Exchange server by creating an EWS ReferenceAttachment</a> <em>(Hawktrace)</em></li><li><a href="https://github.com/sbousseaden/gluegate">gluegate: Memory API proxy via signed mozglue.dll - Detection research PoC: proxy memory operations (memory mapping, local memory allocation) through Mozilla's signed mozglue.dll</a> <em>(sbousseaden)</em></li><li><a href="https://blog.otterpwn.com/projects/heavener">heavener: This is what happens when you can't afford EDR licenses</a> <em>(Otter)</em></li><li><a href="https://bl4ckarch.github.io/posts/One-Bool.-Six-Shells.-AMSI's-Design-Problem/">One Bool. Six Shells. AMSI’s Design Problem.</a> <em>(Evariste (bl4ckarch))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-29.mp3" length="3796785" type="audio/mpeg"/>
      <itunes:duration>3:57</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-28.html</link>
      <pubDate>Sun, 28 Jun 2026 06:01:40 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260628_060140</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.nationalcrimeagency.gov.uk/who-we-are/publications/788-nca-report-cyber-prevent-reoffending/file">Cyber Prevent: A descriptive evaluation of cohort reoffending</a> <em>(National Crime Agency)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-28.mp3" length="837216" type="audio/mpeg"/>
      <itunes:duration>0:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-27.html</link>
      <pubDate>Sat, 27 Jun 2026 06:11:38 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260627_061138</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>29</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/resources-tools/resources/using-sase-modern-tic-30-solution">Using SASE in a Modern TIC 3.0 Solution</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://t.me/SBUkr/17916?embed=1&mode=tme">SBU and FBI exposed Russian special services in systematic attempts to "hack" messengers of officials in Ukraine, Europe and the USA</a> <em>(Служба безпеки України)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/">Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances</a> <em>(ESET)</em></li><li><a href="https://blog.synapticsystems.de/from-winrar-ads-to-reflective-loading-reversing-a-new-uac-0226-giftedcrook-chain/">Tracking UAC-0226 Tooling Evolution: From WinRAR ADS to Reflective GIFTEDCROOK Loading</a> <em>(Robin Dost)</em></li><li><a href="https://rewardsforjustice.net/rewards/unc5792/">UNC5792 – Rewards For Justice</a> <em>(U.S. Department of State)</em></li><li><a href="https://citizenlab.ca/research/russia-breaks-into-human-rights-activists-phone-with-cellebrite/">Russia Breaks Into Human Rights Activist's Phone With Cellebrite - The Citizen Lab</a> <em>(The Citizen Lab)</em></li><li><a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/">CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure</a> <em>(Palo Alto Networks)</em></li><li><a href="https://securelist.com/strikeshark-campaign/120326/">StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon</a> <em>(Kaspersky)</em></li><li><a href="https://mp.weixin.qq.com/s/jXkbq0oWxu4D5yH46TQybg">Analysis of APT-C-36's Recent Activities in Colombia</a> <em>(Intelligence-Group)</em></li><li><a href="https://www.cognyte.com/blog/lazarus-targets-the-financial-sector-with-memory-only-malware-toolset/">Lazarus Targets the Financial Sector with Memory-Only Malware Toolset</a> <em>(Cognyte Software Ltd.)</em></li><li><a href="https://www.sonatype.com/blog/miasma-returns-leo-platform-compromise-in-npm">Miasma Returns: Leo Platform Compromise in npm</a> <em>(Sonatype Security Research Team)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/06/25/photo-zip-campaign-targeting-hospitality-industry-delivers-node-js-implant-persistent-access/">Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access</a> <em>(Microsoft)</em></li><li><a href="https://www.asio.gov.au/resources/speeches-and-statements/director-generals-annual-threat-assessment-2026">Director-General's Annual Threat Assessment 2026 - "We discovered nation state hackers had compromised the network of an Australian critical infrastructure provider."</a> <em>(Australian Security Intelligence Organisation)</em></li><li><a href="https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat">Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker</a> <em>(Broadcom)</em></li><li><a href="https://www.infoblox.com/blog/threat-intelligence/from-san-pedro-to-salinas-how-a-chinese-framework-dcloud-uni-app-powers-a-global-scam-economy/">DCloud Uni-App: One Framework, 236,000+ Scam Sites</a> <em>(Infoblox)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager/">Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager</a> <em>(Google Cloud (Mandiant))</em></li><li><a href="https://whereisk0shl.top/post/From%20context_handle%20to%20type%20confusion/">From context_handle to type confusion - A Type Confusion Vulnerability Pattern in Windows RPC Servers</a> <em>(Whereisk0Shl)</em></li><li><a href="https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action">codfish/semantic-release-action GitHub Action has been compromised</a> <em>(StepSecurity)</em></li><li><a href="https://darkatlas.io/blog/loaderclient-malware-analysis-how-weedhack-uses-ethereum-smart-contracts-for-resilient-c2-infrastructure">LoaderClient Malware Analysis: How WeedHack Uses Ethereum Smart Contracts for Resilient C2 Infrastructure</a> <em>(Buguard)</em></li><li><a href="https://www.threatray.com/blog/kuinaextractor-six-months-of-a-rust-infostealers-evolution">KuinaExtractor: Six Months of a Rust Infostealer's Evolution</a> <em>(Threatray)</em></li><li><a href="https://specterops.io/blog/2026/06/24/disposable-tooling-building-llm-generated-mythic-agents-from-prompt-to-deployment/">Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment</a> <em>(SpecterOps)</em></li><li><a href="https://xmcyber.com/blog/faind-my-xpc-breaks-a-key-trust-boundary/">Trust No One: Automating macOS Privilege Escalation at Scale</a> <em>(XM Cyber)</em></li><li><a href="https://0xmaz.me/posts/LACUNA-Chain-Ghost-Frames-defeats-All-EDR-layers-of-call-stack-based-detection/">LACUNA Chain: Ghost Frames — defeats all EDR layers of call-stack-based detection</a> <em>(Mohamed Alzhrani)</em></li><li><a href="https://whiteknightlabs.com/2026/06/15/harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion-part-3/">Harnessing the Power of Cobalt Strike Profiles for EDR Evasion</a> <em>(White Knight Labs)</em></li><li><a href="https://github.com/x86byte/Obfusk8/releases/tag/v1.5">Release Obfusk8 v1.5</a> <em>(x86byte)</em></li><li><a href="https://security.apple.com/bounty/target-flags/">Target Flags - Apple Security Research - "Target Flags are a new security research capability in Apple operating systems that make it easier to objectively demonstrate your findings"</a> <em>(Apple)</em></li><li><a href="https://detect.fyi/testing-ai-threat-hunting-against-real-world-kql-a-side-by-side-test-4cdda76a5772">Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test</a> <em>(Alex Teixeira)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/">The Latest Addition to Turla’s Intelligence Gathering Apparatus</a> <em>(Google)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-27.mp3" length="13148204" type="audio/mpeg"/>
      <itunes:duration>13:41</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-26.html</link>
      <pubDate>Fri, 26 Jun 2026 06:01:51 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260626_060151</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://open.substack.com/pub/nattothoughts/p/reconnaissance-scanning-tools-used?r=q9u24">Reconnaissance Scanning Tools Used by Chinese Threat Actors and Those Available in Open Source</a> <em>(Natto Team)</em></li><li><a href="https://github.com/youssefnoob003/SindriKit">SindriKit: A foundational C library for building operationally credible offensive capabilities</a> <em>(youssefnoob003)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-26.mp3" length="1440749" type="audio/mpeg"/>
      <itunes:duration>1:29</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-25.html</link>
      <pubDate>Thu, 25 Jun 2026 06:03:52 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260625_060352</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://socradar.io/wp-content/uploads/2026/06/Dismantling-FortiBleed.pdf">Dismantling Fortibleed: Inside a Russian Fortinet compromise operation</a> <em>(socradar.io)</em></li><li><a href="https://github.com/andreicscs/HoneyWire">HoneyWire: HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.</a> <em>(Andrea Termine)</em></li><li><a href="https://github.com/0xABCD01/CVE-2026-41089">CVE-2026-41089: CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - only a Denial of Service PoC not RCE</a> <em>(0xABCD01)</em></li><li><a href="https://labs.infoguard.ch/posts/ghost-sender/">Ghost-Sender - Universal Email Spoofing against Exchange Online</a> <em>(InfoGuard AG)</em></li><li><a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/">macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox</a> <em>(SentinelOne)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/f/from-langflow-to-monero-inside-cve-2026-33017-cryptominer.html">From Langflow to Monero: Inside CVE-2026-33017 Cryptominer</a> <em>(Trend Micro)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-25.mp3" length="2978003" type="audio/mpeg"/>
      <itunes:duration>3:06</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-24.html</link>
      <pubDate>Wed, 24 Jun 2026 06:05:49 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260624_060549</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure">CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices">Analysis of Reported Credential Compromise of FortiGate Devices</a> <em>(Fortinet, Inc.)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/">From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet</a> <em>(Microsoft)</em></li><li><a href="https://www.jamf.com/blog/klue-incident/">Klue Third-Party Cybersecurity Incident</a> <em>(Jamf)</em></li><li><a href="https://www.bbc.co.uk/news/articles/czx5yp9qy0do">Two men plead guilty over £39m Transport for London cyber attack</a> <em>(BBC)</em></li><li><a href="https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/">From PostCSS Masquerading to Windows RAT</a> <em>(JFrog)</em></li><li><a href="https://spur.us/blog/smart-tv-apps-residential-proxy-sdks">Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs</a> <em>(Spur Intelligence Labs)</em></li><li><a href="https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/">Bypassing Conditional Access policies that have a resource exclusion</a> <em>(Dirk-jan Mollema)</em></li><li><a href="https://aws.amazon.com/blogs/security/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads/">Prevent data exfiltration: AWS egress controls for cloud workloads | Amazon Web Services</a> <em>(Amazon Web Services)</em></li><li><a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/">Securing the Nation Against Advanced Cryptographic Attacks</a> <em>(The White House)</em></li><li><a href="https://squiblydoo.blog/2026/06/22/using-the-cert-graveyard/">Using the Cert Graveyard</a> <em>(Rogue Authority LLC)</em></li><li><a href="https://blog.synapticsystems.de/ghostshell-mb-0009-targeting-ukraines-uav-operations-and-defense-supply-chain/">GhostShell (MB-0009): Targeting Ukraine’s UAV Operations and Defense Supply Chain</a> <em>(Synaptic Systems)</em></li><li><a href="https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/">Security Update: Tanium’s Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium</a> <em>(Tanium)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-24.mp3" length="5551795" type="audio/mpeg"/>
      <itunes:duration>5:46</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-23.html</link>
      <pubDate>Tue, 23 Jun 2026 06:26:27 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260623_062627</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>22</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.bushidotoken.net/2026/06/uk-cybercrime-journal-sustained.html">UK Cybercrime Journal: Sustained DragonForce Campaign</a> <em>(BushidoToken)</em></li><li><a href="https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/">Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework</a> <em>(Sekoia.io)</em></li><li><a href="https://www.bridewell.com/insights/blogs/detail/the-booking.com-phishing-campaign-targeting-hotels-and-customers">The Booking.com Phishing Campaign Targeting Hotels and Customers</a> <em>(Bridewell)</em></li><li><a href="https://permiso.io/blog/gcp-servicedata-officially-deprecated-actively-dangerous">Mind the Gap: GCP serviceData in Logs Explorer vs. Exported Logs</a> <em>(Permiso Security)</em></li><li><a href="https://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection">Azure AD Graph Activity Logs: detecting directory enumeration</a> <em>(Elastic)</em></li><li><a href="https://blog.nviso.eu/2026/06/17/reducing-microsoft-sentinel-costs-without-compromising-detection-part-1-the-summary-rules-quest/">Reduce Microsoft Sentinel Costs with Summary Rules</a> <em>(NVISO)</em></li><li><a href="https://www.nextron-systems.com/2026/06/19/oss-artifact-scanning-at-scale/">OSS Artifact Scanning at Scale Without Burning Your Token Budget</a> <em>(Nextron Systems)</em></li><li><a href="https://klue.com/blog/an-update-on-recent-klue-security-incident">An Update on the Recent Klue Security Incident - Klue</a> <em>(Klue)</em></li><li><a href="https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/">A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope</a> <em>(Snyk)</em></li><li><a href="https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind">Inside the FortiBleed Open Directory: A Technical Analysis of What the Attacker Left Behind</a> <em>(CloudSEK)</em></li><li><a href="https://github.com/NirvanaOn/NOW">NOW: NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.</a> <em>(Nirvana)</em></li><li><a href="https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion/">GhostPack Necromancy: Reforging C# Tools with WasmForge</a> <em>(Praetorian)</em></li><li><a href="https://whiteknightlabs.com/2026/06/15/harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion-part-3/">Harnessing the Power of Cobalt Strike Profiles for EDR Evasion – Part 3</a> <em>(White Knight Labs)</em></li><li><a href="https://www.levelblue.com/blogs/spiderlabs-blog/rogueplanet-and-greatxml-detecting-local-privilege-escalation-and-bitlocker-security-boundary-abuse">RoguePlanet and GreatXML: Detecting Local Privilege Escalation and BitLocker Security Boundary Abuse</a> <em>(LevelBlue)</em></li><li><a href="https://unit42.paloaltonetworks.com/large-scale-credential-attacks/">Threat Brief: Mitigating Large-Scale Credential Attacks</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.netskope.com/blog/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat">macOS ClickFix Lures Deploy AppleScript Stealer &amp; Persistent RAT</a> <em>(Netskope)</em></li><li><a href="https://github.com/OALabs/asftriage">asftriage: LLM Agent Session Forensics Tool - A forensic investigation tool for AI agent session logs (Claude Code and Codex CLI).</a> <em>(OA Labs)</em></li><li><a href="https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer">OXLOADER: new loader evading detection to drop infostealer</a> <em>(Elastic)</em></li><li><a href="https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf">Composer &amp; Packagist
Supply Chain Security in 2026</a> <em>(Nils Adermann)</em></li><li><a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/man-jailed-for-role-in-sms-blaster-fraud-operation-following-city-of-london-police-investigation/">Man jailed for role in “SMS Blaster” fraud operation following City of London Police investigation</a> <em>(City of London Police)</em></li><li><a href="https://www.gendigital.com/blog/insights/research/inside-vidar-abe-bypass">Inside Vidar’s ABE Bypass: From Memory Scanning to APC Injections</a> <em>(Gen Digital)</em></li><li><a href="https://blog.talosintelligence.com/scripting-the-disassembler/">Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model</a> <em>(Cisco Talos)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-23.mp3" length="8066238" type="audio/mpeg"/>
      <itunes:duration>8:24</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-22.html</link>
      <pubDate>Mon, 22 Jun 2026 06:07:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260622_060745</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.graphistry.com/blog/fables-and-mythos-conceptions-the-defenders-perspective-with-receipts">Fable 5 Cybersecurity benchemark</a> <em>(Graphistry)</em></li><li><a href="https://safedep.io/astro-config-blockchain-c2-supply-chain/">astro.config.mjs Supply Chain Attack via Blockchain C2</a> <em>(SafeDep)</em></li><li><a href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html">Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies</a> <em>(OALABS)</em></li><li><a href="https://www.recordedfuture.com/blog/klue-security-incident">The Klue Security Incident and Its Impact on Recorded Future</a> <em>(Recorded Future)</em></li><li><a href="https://www.dell.com/support/kbdoc/en-uk/000453482/dsa-2026-197-security-update-for-dell-client-platform-bios-for-a-weak-encoding-for-password-vulnerability">DSA-2026-197: Security Update for Dell Client Platform BIOS for a Weak Encoding for Password Vulnerability</a> <em>(Dell Technologies)</em></li><li><a href="https://ps.tc/pages/blog-usbliter8.html">Introducing usbliter8: Apple iPhone A12/A13 SecureROM exploit</a> <em>(Paradigm Shift)</em></li><li><a href="https://blog.calif.io/p/squidbleed-cve-2026-47729">Squidbleed (CVE-2026-47729)</a> <em>(Calif.io)</em></li><li><a href="https://github.com/Print3M/MyTalks/blob/main/2026_06_x33fcon_Bring_Your_Own_Everything_-_The_Final_Approach.pdf">Bring Your Own Everything: Traitorware</a> <em>(Print3M)</em></li><li><a href="https://blog.xlab.qianxin.com/arystinger-botnet-hijacks-legacy-routers-for-global-attacks-en/">More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers</a> <em>(QiAnXin XLab)</em></li><li><a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys">Multiple JetBrains IDE plugins caught stealing AI keys</a> <em>(Aikido)</em></li><li><a href="https://synthient.com/blog/popa-from-sourcing-to-distribution">Popa: From Sourcing to Distribution</a> <em>(Synthient)</em></li><li><a href="https://synthesis.to/presentations/recon26_agentic_deobfuscation.pdf">Deobfuscation in the Age of Agentic Reverse Engineering</a> <em>(Tim Blazytko and Nicolò Altamura)</em></li><li><a href="https://github.com/struppigel/hedgehog-tools/tree/main/ktrace">ktrace: Speakeasy-based Windows kernel-mode driver API tracer</a> <em>(struppigel)</em></li><li><a href="https://github.com/allthingsida/allthingsida/blob/main/presentations/select_from_binary_vibe_re/vibe_re_xsql.pdf">SELECT * FROM binary - Vibe Reversing Across IDA, Ghidra, and Binary Ninja</a> <em>(Elias Bachaalany)</em></li><li><a href="https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker/">From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker</a> <em>(Check Point Research)</em></li><li><a href="https://www.europol.europa.eu/media-press/newsroom/news/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering-pipeline">Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline – Europol analysis links the criminal service to over 15 international cybercrime investigations | Europol</a> <em>(Europol)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-22.mp3" length="6651446" type="audio/mpeg"/>
      <itunes:duration>6:55</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-21.html</link>
      <pubDate>Sun, 21 Jun 2026 06:04:07 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260621_060407</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://book.yunzhan365.com/tkgd/knru/mobile/index.html">APT Organization Research Yearbook (2026 Edition)  - Chinese</a> <em>(绿盟科技、广州大学网络空间安全学院)</em></li><li><a href="https://www.huntress.com/blog/klue-breach-investigation">Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress</a> <em>(Huntress)</em></li><li><a href="https://www.ibm.com/think/x-force/operationalizing-browser-exploits-to-bypass-wdac">Operationalizing browser exploits to bypass Windows Defender Application Control (WDAC)</a> <em>(IBM)</em></li><li><a href="https://github.com/nmht3t/RawHive">RawHive: Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.</a> <em>(nmht3t)</em></li><li><a href="https://github.com/r3xmax/PhantomCtx">PhantomCtx: Activation Context Hijacking Evasion Tool</a> <em>(r3xmax)</em></li><li><a href="https://rwxstoned.github.io/2026-06-18-Slack-links-preview-for-C2/">Using Slack links-preview to smuggle C2 in locked-down environments.</a> <em>(RWXstoned)</em></li><li><a href="https://github.com/RootUp/git-clean-filter">git-clean-filter: This is a proof-of-work for abusing git's clean filter against IDEs &amp; Sublime.</a> <em>(RootUp)</em></li><li><a href="https://www.ic3.gov/PSA/2026/PSA260618">Internet Crime Complaint Center (IC3) | Cyber Criminals Redirecting Users to Fraudulent Websites with Malicious Traffic Distribution Systems</a> <em>(Federal Bureau of Investigation (FBI))</em></li><li><a href="https://www.secm8.com/posts/contentops-detection-pipeline/">Building a Modern Detection Pipeline with ContentOps</a> <em>(Gianni Castaldi)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-21.mp3" length="4257376" type="audio/mpeg"/>
      <itunes:duration>4:26</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-20.html</link>
      <pubDate>Sat, 20 Jun 2026 06:02:31 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260620_060231</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html">International law enforcement initiate hunt on malware group SocGholish</a> <em>(Dutch police (Politie))</em></li><li><a href="https://github.com/0xHossam/UnCanny">UnCanny: Another new coercion primitive with LPE 0day - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution experiments</a> <em>(0xHossam)</em></li><li><a href="https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas">Bluekit Phishing as a Service (PhaaS)</a> <em>(CloudSEK)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/">Killing me gently: Inside Gentlemen’s EDR killer framework</a> <em>(ESET)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-20.mp3" length="2143338" type="audio/mpeg"/>
      <itunes:duration>2:13</itunes:duration>
    </item>
  </channel>
</rss>