<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Daily BlueTeamSec Briefing</title>
    <description>Daily security briefings for blue team professionals</description>
    <language>en-us</language>
    <copyright>© 2025 InfoSec Briefing Bot</copyright>
    <managingEditor>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</managingEditor>
    <webMaster>podcast@briefing.workshop1.net (InfoSec Briefing Bot)</webMaster>
    <category>Technology</category>
    <generator>InfoSec Briefing Generator</generator>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <link>https://briefing.workshop1.net</link>
    <pubDate>Sun, 31 Aug 2025 16:05:46 +0000</pubDate>
    <lastBuildDate>Thu, 18 Jun 2026 06:02:18 +0000</lastBuildDate>
    <itunes:author>InfoSec Briefing Bot</itunes:author>
    <itunes:summary>Daily security briefings for blue team professionals</itunes:summary>
    <itunes:category>Technology</itunes:category>
    <itunes:image href="https://briefing.workshop1.net/assets/podcast-artwork.jpg"/>
    <itunes:owner>
      <itunes:name>InfoSec Briefing Bot</itunes:name>
      <itunes:email>podcast@briefing.workshop1.net</itunes:email>
    </itunes:owner>
    <itunes:explicit>false</itunes:explicit>
    <itunes:language>en-us</itunes:language>
    <item>
      <title>InfoSec Briefing - June 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-18.html</link>
      <pubDate>Thu, 18 Jun 2026 06:02:18 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260618_060218</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://jamestown.org/chinese-grid-operators-maintain-offensive-cyber-programs/">Chinese Grid Operators Maintain Offensive Cyber Programs - Jamestown</a> <em>(The Jamestown Foundation)</em></li><li><a href="https://socket.dev/blog/glasswasm-malware-open-vsx-extensions">GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions</a> <em>(Socket)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/">FishMonger’s arsenal upgraded: SprySOCKS for Windows</a> <em>(ESET)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-18.mp3" length="1943554" type="audio/mpeg"/>
      <itunes:duration>2:01</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-17.html</link>
      <pubDate>Wed, 17 Jun 2026 06:02:22 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260617_060222</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://hunt.io/blog/ababil-of-minab-iranian-hackers-exposed-la-metro-breach-open-directory">Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server</a> <em>(Hunt Intelligence, Inc.)</em></li><li><a href="https://blog.bushidotoken.net/2026/06/ransomware-tool-matrix-project-updates.html">Ransomware Tool Matrix Project Updates: Three Groups To Track</a> <em>(BushidoUK)</em></li><li><a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026">SBOM Adoption State of Play - 2026 | ENISA</a> <em>(European Union Agency for Cybersecurity)</em></li><li><a href="https://github.com/Zypherion-Technologies/HallWatch">HallWatch: Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls &amp; Many more.</a> <em>(Adam Zypherion)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-17.mp3" length="2222333" type="audio/mpeg"/>
      <itunes:duration>2:18</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-16.html</link>
      <pubDate>Tue, 16 Jun 2026 06:06:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260616_060633</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://kmsec.uk/blog/dprk-google-docs/">Hunting North Korea's job adverts on Google Docs</a> <em>(Kieran Miyamoto)</em></li><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat">Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2</a> <em>(Genians)</em></li><li><a href="https://www.ndss-symposium.org/ndss-paper/actively-understanding-the-dynamics-and-risks-of-the-threat-intelligence-ecosystem/">Actively Understanding the Dynamics and Risks of the Threat Intelligence Ecosystem - NDSS Symposium</a> <em>(Internet Society)</em></li><li><a href="https://csrc.nist.gov/pubs/sp/800/126/r4/final">NIST Special Publication (SP) 800-126 Rev. 4, Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.4</a> <em>(National Institute of Standards and Technology (NIST))</em></li><li><a href="https://recyclebin.zip/posts/2026-05-25-secret-scanning-fleet-bagel/">Detecting and removing dangerous secrets on dev workstations before Shai-Hulud does</a> <em>(Guillaume Ross)</em></li><li><a href="https://aws.amazon.com/blogs/security/well-architected-best-practices-for-software-supply-chain-security/">Well-architected best practices for software supply chain security | Amazon Web Services</a> <em>(Amazon Web Services (AWS))</em></li><li><a href="https://mp.weixin.qq.com/s/EM0NQSITmCJ7syHxg5Ig-g">反入侵 Pipeline 2.0 (Agentic) -Anti-intrusion Pipeline 2.0 (Agentic) (Chinese)</a> <em>(奇安信攻防社区)</em></li><li><a href="https://arxiv.org/abs/2605.17380">ADR: An Agentic Detection System for Enterprise Agentic AI Security</a> <em>(Uber Technologies, Inc.)</em></li><li><a href="https://sha0coder.github.io/scales/">Scales — carving an embedded eBPF rootkit</a> <em>(jolmos)</em></li><li><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster supply chain attack hits 1.2 million sites</a> <em>(Sansec)</em></li><li><a href="https://aretiq.ai/research/vul260531-cve-2026-45454-microsoft-sharepoint-server-upload-page-folder-path-traversal/">CVE-2026-45454 — Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution</a> <em>(Aretiq AI)</em></li><li><a href="https://arxiv.org/abs/2604.04805">Unpacking .zip: A First Look at Domain and File Name Confusion</a> <em>(Oregon State University, Georgia Institute of Technology)</em></li><li><a href="https://mp.weixin.qq.com/s/ynnTKDpktqgX-XDpVJOLyw">After applying AI to perform a deep audit of ActiveMQ patches, two new high-risk vulnerabilities were discovered (Chinese)</a> <em>(腾讯安全应急响应中心)</em></li><li><a href="https://www.sygnia.co/blog/operation-highland-velvet-ant/">Velvet Ant’s Operation Highland: How a China-Nexus Actor Infiltrated an Internal Network Undetected</a> <em>(Sygnia)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-16.mp3" length="6100158" type="audio/mpeg"/>
      <itunes:duration>6:21</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-15.html</link>
      <pubDate>Mon, 15 Jun 2026 06:05:57 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260615_060557</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/threathunters-io/tracebit_x33fcon_2026">tracebit_x33fcon_2026: a POC sensor aiming to fingerprint implants in memory using only lowlevel runtime telemetry.</a> <em>(ThreatHunting.io)</em></li><li><a href="https://github.com/0xjbb/ModuleStomped">ModuleStomped: Proof of concept to detect module stomping detection by looking for modified .pdata sections.</a> <em>(0xjbb)</em></li><li><a href="https://blog.helsing.ai/posts/trusting-trust-bootstrapping-nix-from-source/">Trusting trust - building Nix from a manually verified seed</a> <em>(Helsing)</em></li><li><a href="https://github.com/sbousseaden/EDRUnChoker">EDRUnChoker: EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies</a> <em>(sbousseaden)</em></li><li><a href="https://trustedsec.com/blog/hardening-intune-the-implementation-guide">Hardening Intune: The Implementation Guide</a> <em>(TrustedSec, LLC)</em></li><li><a href="https://github.com/e-fin/ADWS-BOF">ADWS-BOF: Beacon Object File for LDAP Queries Through ADWS</a> <em>(Ethan)</em></li><li><a href="https://github.com/ar0x4/tunnel-vision-toolkit">tunnel-vision-toolkit: Offensive security toolkit for Microsoft Global Secure Access (GSA), Microsoft's Zero Trust Network Access (ZTNA) solution.</a> <em>(Arshia Reisi)</em></li><li><a href="https://www.varonis.com/blog/openclaw-phishing">Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets</a> <em>(Varonis)</em></li><li><a href="https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/">Roughly 400 AUR (Arch User Repository) packages compromised</a> <em>(Arch Linux)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit">ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog</a> <em>(Google Cloud)</em></li><li><a href="https://github.com/HexRaysSA/rax">rax: rax is a CPU emulator that does not trust itself.</a> <em>(Hex-Rays SA)</em></li><li><a href="https://github.com/atomiczsec/Noradrenaline">Noradrenaline: Offensive macOS and Linux shared library modules for Poseidon and other agent frameworks. Designed to be small and quick for automation.</a> <em>(atomiczsec)</em></li><li><a href="https://ioctl.fail/preliminary-analysis-of-aur-malware/">Preliminary analysis of AUR malware</a> <em>(Codex)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/covert-kernel-user-communication-channels-on-windows/">Covert Kernel/User Communication Channels on Windows: Rootkits, Game Cheats, and Detection</a> <em>(kernullist)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-15.mp3" length="6095978" type="audio/mpeg"/>
      <itunes:duration>6:20</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-14.html</link>
      <pubDate>Sun, 14 Jun 2026 06:02:16 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260614_060216</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem">Interlock and Rhysida within the Ransomware Ecosystem | IBM</a> <em>(IBM)</em></li><li><a href="https://www.papermtn.co.uk/detecting-misuse-with-the-claude-compliance-api-the-threat-is-in-the-content/">Detecting Misuse with the Claude Compliance API: The Threat Is in the Content</a> <em>(PaperMtn)</em></li><li><a href="https://blog.trailofbits.com/2026/06/12/factoring-short-sleeve-rsa-keys-with-polynomials/">Factoring "short-sleeve" RSA keys with polynomials</a> <em>(Trail of Bits)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-14.mp3" length="1812315" type="audio/mpeg"/>
      <itunes:duration>1:53</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-13.html</link>
      <pubDate>Sat, 13 Jun 2026 06:07:41 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260613_060741</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">BOD 26-04: Prioritizing Security Updates Based on Risk</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/">Behind Khmer Shadow: Targeted espionage against Cambodian government entities</a> <em>(Acronis)</em></li><li><a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation">Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation</a> <em>(Lumen Technologies)</em></li><li><a href="https://binarydefense.com/resources/blog/bluerabbit-a-golang-based-backdoor-with-ransomware-and-destructive-capabilities">BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive…</a> <em>(Binary Defense)</em></li><li><a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/">APT28, an evolution of tradecraft</a> <em>(Sekoia.io)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/">OceanLotus: From external espionage to domestic targeting</a> <em>(ESET)</em></li><li><a href="https://blog.itochuci.co.jp/entry/2026/06/11/110000">ホテル業界を標的とした不審メールの分析（パート1: キャンペーン概要編）- Analysis of suspicious emails targeting the hotel industry (Part 1: Campaign Overview)</a> <em>(ITOCHU Cyber &amp; Intelligence Inc.)</em></li><li><a href="https://blog.itochuci.co.jp/entry/2026/06/11/111500">ホテル業界を標的とした不審メールの分析（パート2: 技術詳細編） - Analysis of Suspicious Emails Targeting the Hotel Industry (Part 2: Technical Details)</a> <em>(ITOCHU Cyber &amp; Intelligence Inc.)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508668&idx=1&sn=1ec03eafb27735e2f5e3b7ea02e77d42&chksm=f9c191b5ceb618a3a101b03fdfd83de445d8e33839d01840374c7e7035d9e245ecba854efb4d&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">APT-C-08（蔓灵花）近期钓鱼网站攻击活动分析 - Analysis of Recent Phishing Website Attacks by APT-C-08 (Manlinghua)</a> <em>(WgpSec)</em></li><li><a href="https://www.nccoe.nist.gov/news-insights/now-available-practical-guidelines-preventing-and-mitigating-ransomware">Now Available: Practical Guidelines for Preventing and Mitigating Ransomware</a> <em>(www.nccoe.nist.gov)</em></li><li><a href="https://trustedsec.com/blog/hardening-intune-the-implementation-guide">Hardening Intune: The Implementation Guide</a> <em>(TrustedSec)</em></li><li><a href="https://bumsrake.de/">BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.</a> <em>(Bumsrakete)</em></li><li><a href="https://deadeclipse666.blogspot.com/2026/06/greatxml-bitlocker-that-seems-to-only.html?m=1">GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan</a> <em>(NightmareEclipse)</em></li><li><a href="https://specterops.io/blog/2026/06/09/user-to-user-authentication-down-the-rabbit-hole-part-1/">User-to-User Authentication: Down the Rabbit Hole - Part 1</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/synacktiv/DCOMIllusionist">DCOMIllusionist: DCOM in memory and fileless lateral movement techniques through .Net deserilization</a> <em>(Synacktiv)</em></li><li><a href="https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-mssql-2025/">Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025</a> <em>(SpecterOps)</em></li><li><a href="https://github.com/S3cur3Th1sSh1t/NimSyscallPacker">NimSyscallPacker: This Packer can be used to pack any C# Assembly, PE-File or Shellcode into a Nim binary. It will encrypt the target payload, build the corresponding Nim source code accordingly</a> <em>(Fabian Mosch)</em></li><li><a href="https://aff-wg.org/2026/06/10/a-long-running-bof-component-contract/">A Long-running BOF Component Contract</a> <em>(Raphael Mudge)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-13.mp3" length="6201304" type="audio/mpeg"/>
      <itunes:duration>6:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-12.html</link>
      <pubDate>Fri, 12 Jun 2026 06:01:46 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260612_060146</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>2</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.deception.pro/blog/xworm-sc-hok-may-2026">[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion</a> <em>(MalBeacon)</em></li><li><a href="https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137">On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface)</a> <em>(Arista Networks)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-12.mp3" length="1368860" type="audio/mpeg"/>
      <itunes:duration>1:25</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-11.html</link>
      <pubDate>Thu, 11 Jun 2026 06:03:17 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260611_060317</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://arxiv.org/abs/2606.07158">Synthetic APTs: the Collapse of TTP-Based Attribution</a> <em>(Alias Robotics)</em></li><li><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/microsoft-defender-now-monitors-rpc-activity/4523368">Microsoft Defender now monitors RPC activity</a> <em>(Microsoft)</em></li><li><a href="https://zer0matt.blogspot.com/2026/05/whoops-i-did-it-again-i-patched-windows.html">Whoops! I did it again. I patched Windows Kernel at Milan0day 2026</a> <em>(Ethical Hacker)</em></li><li><a href="https://github.com/MSNightmare/RoguePlanet">RoguePlanet: RoguePlanet Windows Defender Vulnerability</a> <em>(MSNightmare)</em></li><li><a href="https://magic-box.dev/blog/patch-tuesday/">Benchmarking n-day exploit generation [via AI]</a> <em>(Josh Merrill)</em></li><li><a href="https://bindinghook.com/understanding-modern-chinese-cyber-operations-means-shifting-from-apt-to-composite-responsibility/">Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility</a> <em>(Virtual Routes Community)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-11.mp3" length="2533712" type="audio/mpeg"/>
      <itunes:duration>2:38</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-10.html</link>
      <pubDate>Wed, 10 Jun 2026 06:04:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260610_060445</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/">Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257</a> <em>(Palo Alto Networks)</em></li><li><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/">Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) - Check Point Blog</a> <em>(Check Point Software Technologies Ltd.)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html">Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,</a> <em>(Trend Micro)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal">Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency</a> <em>(Proofpoint)</em></li><li><a href="https://www.numerique.gouv.fr/sinformer/espace-presse/incident-tchap/">Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users</a> <em>(Direction interministérielle du numérique (DINUM))</em></li><li><a href="https://blog.bushidotoken.net/2026/05/uk-cybercrime-journal-british.html">UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season</a> <em>(BushidoToken)</em></li><li><a href="https://github.com/dtrizna/QuasarNix">QuasarNix: Reverse Shell Detection with Machine Learning</a> <em>(Dmitrijs Trizna)</em></li><li><a href="https://helm.sh/blog/security-notice-baltocdn/">Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement | Helm</a> <em>(Cloud Native Computing Foundation)</em></li><li><a href="https://code.visualstudio.com/updates/v1_123#_delayed-extension-autoupdates">Visual Studio Code 1.123: Delayed extension auto-updates</a> <em>(Microsoft)</em></li><li><a href="https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/">Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.</a> <em>(Meta)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-10.mp3" length="5305199" type="audio/mpeg"/>
      <itunes:duration>5:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-09.html</link>
      <pubDate>Tue, 09 Jun 2026 06:04:59 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260609_060459</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>12</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://github.com/princessauroraj/Chinese-Cybercrime-Research">Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.</a> <em>(aurora)</em></li><li><a href="https://github.com/ByteRay-Labs/Query-Hub">Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale</a> <em>(ByteRay-Labs)</em></li><li><a href="https://openai.com/index/building-codex-windows-sandbox/">Building a safe, effective sandbox to enable Codex on Windows</a> <em>(OpenAI)</em></li><li><a href="https://github.com/Division-36/Z-Jail">Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine) for secure, auditable code execution.</a> <em>(Division-36)</em></li><li><a href="https://github.com/Sbharadwaj05/ot-sentinel-rules">ot-sentinel-rules: Open-source ICS/OT detection rules (Wazuh + Sigma) for Modbus, DNP3, IEC 104, MQTT, and OPC-UA — tested against a real OpenPLC + GNS3 digital twin lab.</a> <em>(Subhash Bharadwaj)</em></li><li><a href="https://www.documentcloud.org/documents/28202858-meta-ai-ag-maine/">On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited by unauthorized third parties</a> <em>(Maine Office of the Attorney General)</em></li><li><a href="https://blog.nns.ee/2026/06/03/katana-badusb/">Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee</a> <em>(Rasmus Moorats)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/pcie-dma-cheats/">About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection</a> <em>(kernullist)</em></li><li><a href="https://patchi.fyi/blog/busywork-sleep-replacement/">BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection</a> <em>(m4n0w4r)</em></li><li><a href="https://github.com/SpacePlant/UPnPHostFileRead">UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.</a> <em>(SpacePlant)</em></li><li><a href="https://github.com/TwoSevenOneT/EDRChoker">EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.</a> <em>(Two Seven One Three)</em></li><li><a href="https://github.com/tjnull/cygor">cygor: An modular asset discovery framework written in python to automate the repeating manual work</a> <em>(tjnull)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-09.mp3" length="5464024" type="audio/mpeg"/>
      <itunes:duration>5:41</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-08.html</link>
      <pubDate>Mon, 08 Jun 2026 06:14:28 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260608_061428</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>30</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems">CISA and Partners Urge Hardening Automatic Tank Gauge Systems</a> <em>(Cybersecurity and Infrastructure Security Agency)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/">Ongoing Targeted Campaign Against US Law Firms</a> <em>(Google)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512">New China-Linked Cluster OP-512</a> <em>(ReliaQuest)</em></li><li><a href="https://bluecyber.hashnode.dev/mustang-panda-x-plugx-analysis-of-the-january-2026-sample-a-multi-layer-execution-chain">MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain</a> <em>(BlueCyber)</em></li><li><a href="https://www.lac.co.jp/lacwatch/report/20260604_004759.html">PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver</a> <em>(株式会社ラック)</em></li><li><a href="https://threatreviewjournals.blogspot.com/2026/06/investigation-into-apt-5-and-their.html">Investigation into APT 5 and their inner workings of PLA Troop 61786</a> <em>(The author of the content on the Threat Review Journal blog is not explicitly named.)</em></li><li><a href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/">From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services</a> <em>(Arctic Wolf)</em></li><li><a href="https://www.ox.security/blog/six-stages-deep-and-an-endless-loop-shai-hulud-is-getting-sophisticated/">Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated - OX Security</a> <em>(OX Security)</em></li><li><a href="https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm">Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - StepSecurity</a> <em>(StepSecurity)</em></li><li><a href="https://www.cyderes.com/howler-cell/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat">Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim</a> <em>(Cyderes)</em></li><li><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/">Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns</a> <em>(McAfee)</em></li><li><a href="https://m4lcode.github.io/unmasking-quellostanco-how-a-git-commit-exposed-a-threat-actor-targeting-egyptian-infrastructure">Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)</a> <em>(M4lcode)</em></li><li><a href="https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/">The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy</a> <em>(Include Security)</em></li><li><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts">Security advisory: Brute force attack on Dashlane user accounts</a> <em>(Dashlane)</em></li><li><a href="https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis">Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection &amp; Analysis</a> <em>(Bishop Fox)</em></li><li><a href="https://depthfirst.com/research/21-zero-days-in-ffmpeg">21 Zero-Days in FFmpeg</a> <em>(Depthfirst)</em></li><li><a href="https://beyondmemory.io/blog/json-formatter-data-exposure">Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS</a> <em>(beyondmemory.io)</em></li><li><a href="https://trustedsec.com/blog/the-privileged-roles-nobody-talks-about">The Privileged Roles Nobody Talks About</a> <em>(TrustedSec)</em></li><li><a href="https://blog.nviso.eu/2026/06/04/the-detection-response-chronicles-covert-operations-through-qemu/">The Detection &amp; Response Chronicles: Covert Operations Through QEMU</a> <em>(NVISO)</em></li><li><a href="https://detect.fyi/the-interesting-case-of-wsl-for-payload-staging-bfaa0f69329a">The Interesting Case of WSL for Payload Staging</a> <em>(Daniel Koifman)</em></li><li><a href="https://www.praetorian.com/blog/wasmforge-sliver-webassembly/">Enter the WasmForge: Compiling Sliver into WebAssembly</a> <em>(Praetorian)</em></li><li><a href="https://github.com/kasturixbm5/staged-DLL-Injection-SMB-">staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).</a> <em>(kasturixbm5)</em></li><li><a href="https://matheuzsecurity.github.io/hacking/trendmicro-bmhook-tmhook-reload-bypass/">Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window</a> <em>(Matheuz Security)</em></li><li><a href="https://rastamouse.me/bof-cocktails-in-cobalt-strike/">BOF Cocktails in Cobalt Strike</a> <em>(Rasta Mouse)</em></li><li><a href="https://sansec.io/research/stripe-api-skimmer-infrastructure">Magecart skimmer turns Stripe into a malware command server</a> <em>(Sansec)</em></li><li><a href="https://www.blackhillsinfosec.com/auditing-gitlab-the-ci-cd-kill-chain/">Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...</a> <em>(Black Hills Information Security, Inc.)</em></li><li><a href="https://kernullist.github.io/kernullist-blog/posts/etw-internals-deep-dive/">About ETW Internals: Architecture, Hooking, Tampering, and Detection</a> <em>(kernullist)</em></li><li><a href="https://www.nccgroup.com/research/async-picos-and-custom-beacon-wakeups-in-cobalt-strike/">Async PICOs and Custom Beacon Wakeups in Cobalt Strike</a> <em>(NCC Group)</em></li><li><a href="https://anduinbrian.github.io/posts/blogs/address-translation/">Address Translation</a> <em>(reisen_1943)</em></li><li><a href="https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/">The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer</a> <em>(Positive Technologies)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-08.mp3" length="17802179" type="audio/mpeg"/>
      <itunes:duration>18:32</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-07.html</link>
      <pubDate>Sun, 07 Jun 2026 06:02:20 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260607_060220</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://opensourcemalware.com/blog/miasma-reaches-azure">The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds</a> <em>(OpenSourceMalware)</em></li><li><a href="https://blog.ammaraskar.com/github-token-stealing/">1-Click GitHub Token Stealing via a VSCode Bug</a> <em>(Ammar Askar)</em></li><li><a href="https://blog.thinkst.com/2026/06/introducing-package-proxy-supply-chain-safety-checks-without-client-side-software.html">Enhance your Supply Chain Security with our Package Proxy Tool</a> <em>(Thinkst)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-07.mp3" length="1976991" type="audio/mpeg"/>
      <itunes:duration>2:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-06.html</link>
      <pubDate>Sat, 06 Jun 2026 06:04:33 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260606_060433</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>10</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/">VerdantBamboo: Just Another BRICKSTORM in the Firewall</a> <em>(Volexity)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/software-supply-chain-attacks-check-your-dependencies">Software supply chain attacks: check your dependencies</a> <em>(National Cyber Security Centre)</em></li><li><a href="https://www.ox.security/blog/ironworm-supply-chain-malware-hits-npm/">IronWorm Supply Chain Malware Hits npm - OX Security</a> <em>(OX Security)</em></li><li><a href="https://www.sophos.com/en-us/blog/you-do-surprise-me-exe-an-unexpected-executable-in-hola-browser">You do surprise me.exe: An unexpected executable in Hola Browser</a> <em>(Sophos X-Ops)</em></li><li><a href="https://managedpriv.com/blog/acl-canonical-order-and-security/">The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory</a> <em>(Robin Granberg)</em></li><li><a href="https://github.com/Mr-Un1k0d3r/AzureRedOps">AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID</a> <em>(Mr.Un1k0d3r (TrueCyber Inc.))</em></li><li><a href="https://github.com/zmap/zannotate">zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)</a> <em>(ZMap)</em></li><li><a href="https://www.originhq.com/research/mxc-execution-containers-internals">MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code | Origin</a> <em>(Origin)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel/">FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel</a> <em>(Sekoia.io)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-2-3-gamaredons-gifts-that-keeps-unpacking-gammaload/">FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad</a> <em>(Sekoia.io)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-06.mp3" length="4349745" type="audio/mpeg"/>
      <itunes:duration>4:31</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-05.html</link>
      <pubDate>Fri, 05 Jun 2026 06:05:45 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260605_060545</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>14</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-45247.html">CVE-2026-45247</a> <em>(CISA KEV)</em></li><li><a href="https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/">Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem</a> <em>(Check Point Software Technologies)</em></li><li><a href="https://www.huntress.com/blog/malspam-to-deskcvb-rat-delivery-chain-analysis">Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT | Huntress</a> <em>(Huntress)</em></li><li><a href="https://medium.com/@s12deff/bring-your-own-rwx-region-dll-byorwxdll-0283951d34e9">Bring Your Own RWX Region DLL (BYORWXDLL)</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://tierzerosecurity.co.nz/2026/06/02/nuget-code-execution.html">NuGet Code Execution As A Service</a> <em>(Tier Zero Security)</em></li><li><a href="https://github.com/0xsp-SRD/aether">aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET</a> <em>(0xsp)</em></li><li><a href="https://blog.checkpoint.com/security/the-server-seizure-that-affects-also-irans-cyber-operations/">The Server Seizure That Affects Also Iran's Cyber Operations</a> <em>(Check Point Research)</em></li><li><a href="https://open.substack.com/pub/nattothoughts/p/how-chinas-cyber-operations-and-the-610?r=q9u24">How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad</a> <em>(Natto Team)</em></li><li><a href="https://www.security.com/blog-post/stock-exchange-espionage">Espionage Campaign Targeted Stock Exchange Executive for Five Months</a> <em>(Broadcom)</em></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global">TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US</a> <em>(Proofpoint)</em></li><li><a href="https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse">HazyBeacon and AWS Lambda Function URL Abuse</a> <em>(Qualys)</em></li><li><a href="https://unit42.paloaltonetworks.com/flutterbridge-new-fluttershell-backdoor/">Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor</a> <em>(Palo Alto Networks)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508667&idx=1&sn=3557c4427627029226bda2a9de3a81ca&chksm=f9c191b2ceb618a4b288a4cf57d9813f2b425ed24a11848bee8d34ec2f53ed9bbde180cac3be&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component</a> <em>(上海市浦东新区人民法院)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-05.mp3" length="5645418" type="audio/mpeg"/>
      <itunes:duration>5:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-04.html</link>
      <pubDate>Thu, 04 Jun 2026 06:05:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260604_060523</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.exatrack.com/Tracking_APT28_PixyNetLoader/">Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026</a> <em>(Exatrack)</em></li><li><a href="https://idanmalihi.com/tracking-north-korea-nation-state-apt-infrastructure-kimsuky/">Tracking North Korea Nation-State APT Infrastructure: Kimsuky</a> <em>(Idan Malihi)</em></li><li><a href="https://arcticwolf.com/resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/">From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services</a> <em>(Arctic Wolf)</em></li><li><a href="https://interisle.net/insights/cybercriminaldomaindemand">Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand</a> <em>(Interisle Consulting Group, LLC)</em></li><li><a href="https://cooldowns.dev/">Dependency Cooldowns - Dependency Cooldowns</a> <em>(People Can Fly)</em></li><li><a href="https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb">Codex Discovered a Hidden HTTP/2 Bomb</a> <em>(Calif.io)</em></li><li><a href="https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris/">Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs</a> <em>(SafeBreach)</em></li><li><a href="https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler">Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix | Huntress</a> <em>(Huntress)</em></li><li><a href="https://asec.ahnlab.com/ko/93931/">새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn</a> <em>(AhnLab)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-04.mp3" length="4750150" type="audio/mpeg"/>
      <itunes:duration>4:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-03.html</link>
      <pubDate>Wed, 03 Jun 2026 06:03:48 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260603_060348</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages">Miasma: Supply Chain Attack Targeting RedHat npm Packages</a> <em>(Wiz)</em></li><li><a href="https://socket.dev/blog/mini-shai-hulud-campaign-hits-red-hat-cloud-services-npm-packages">Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages</a> <em>(Socket)</em></li><li><a href="https://www.stepsecurity.io/blog/multiple-redhat-cloud-services-npm-packages-compromised">Multiple redhat-cloud-services npm Packages compromised</a> <em>(StepSecurity)</em></li><li><a href="https://blog.calif.io/p/redsun-exploiting-windows-defenders">RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation</a> <em>(blog.calif.io)</em></li><li><a href="https://docbox.etsi.org/CYBER/EUSR/Open/EN_304-627_V1.0.0_2026-06-01_Routers-Modems-Switches_Final-draft.pdf">Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches</a> <em>(ETSI)</em></li><li><a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/">Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm</a> <em>(Sekoia.io)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-03.mp3" length="2244484" type="audio/mpeg"/>
      <itunes:duration>2:20</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-02.html</link>
      <pubDate>Tue, 02 Jun 2026 06:03:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260602_060323</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign">Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign</a> <em>(LevelBlue)</em></li><li><a href="https://arxiv.org/abs/2602.12388">Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks</a> <em>(Army Cyber Institute)</em></li><li><a href="https://www.veeam.com/kb4853">KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4</a> <em>(Veeam Software)</em></li><li><a href="https://www.safebreach.com/blog/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris/">Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs</a> <em>(SafeBreach Labs)</em></li><li><a href="https://www.cryptika.com/instagram-meta-ai-vulnerability-allegedly-enables-password-reset-for-accounts/">Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched</a> <em>(Cryptika)</em></li><li><a href="https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens">Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens</a> <em>(Aikido Security)</em></li><li><a href="https://safedep.io/oob-moika-tech-dependency-confusion-campaign/">179 npm Packages Target Cloud and Finance via oob.moika.tech</a> <em>(SafeDep)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-02.mp3" length="3283113" type="audio/mpeg"/>
      <itunes:duration>3:25</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - June 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-06-01.html</link>
      <pubDate>Mon, 01 Jun 2026 09:40:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260601_094002</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>29</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/">Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)</a> <em>(Rapid7)</em></li><li><a href="https://security.paloaltonetworks.com/CVE-2026-0257">CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."</a> <em>(Palo Alto Networks)</em></li><li><a href="https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/">Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan</a> <em>(Quick Heal Technologies Limited)</em></li><li><a href="https://www.seqrite.com/blog/operation-dragon-weave-uncovering-a-china-linked-campaign-targeting-czech-republic-and-taiwan-using-azure-cloud-c2/">Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2</a> <em>(Seqrite)</em></li><li><a href="https://www.silentpush.com/blog/drivesurge/">Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites</a> <em>(Silent Push)</em></li><li><a href="https://arxiv.org/abs/2605.29269">HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics</a> <em>(Guangze Zhao, Yongzheng Zhang, Weilin Gai, Hongri Liu, Yuliang Wei, and Bailing Wang)</em></li><li><a href="https://kqlquery.com/posts/defender-xdr-local-account-incident-response/">EDR Incident Response Playbook: Containing Local Account Incidents</a> <em>(Bert-Jan Pals)</em></li><li><a href="https://github.com/git-pkgs/proxy">proxy: A lightweight caching proxy for package registries.</a> <em>(git-pkgs)</em></li><li><a href="https://github.com/falcosecurity/prempti">prempti: Falco-powered policy and visibility layer for AI coding agents</a> <em>(Falco Security)</em></li><li><a href="https://arxiv.org/abs/2605.29963">Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots</a> <em>(Google Research)</em></li><li><a href="https://github.com/nuclear-treestump/pydepgate">pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.</a> <em>(Ikari)</em></li><li><a href="https://github.com/bI8d0/DriverSentinel">DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.</a> <em>(bI8d0)</em></li><li><a href="https://www.privacyguides.org/news/2026/05/29/signal-macos-desktop-app-doesnt-actually-delete-messages-when-it-should/">Signal macOS Desktop App Doesn't Actually Delete Messages When it Should</a> <em>(Privacy Guides)</em></li><li><a href="https://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html">How OLTs may have exposed entire ISP networks</a> <em>(Quarkslab)</em></li><li><a href="https://arxiv.org/abs/2605.25435">Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures</a> <em>(Yuntao Wang, Jianle Ba, Han Liu, Yanghe Pan, Jintao Wei, Zhou Su, Tom H. Luan, and Linkang Du)</em></li><li><a href="https://www.mdsec.co.uk/2026/05/visual-studio-extensions-revisited/">Visual Studio Extensions Revisited</a> <em>(MDSec)</em></li><li><a href="https://www.netcraft.com/blog/eviltokens-and-oauth-abuse">EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA</a> <em>(Netcraft LTD)</em></li><li><a href="https://www.praetorian.com/blog/llm-edr-signature-reduction/">Adversarial Oracles: LLM-Guided EDR Signature Reduction</a> <em>(Praetorian)</em></li><li><a href="https://arxiv.org/abs/2605.27042">Lessons from Penetration Tests on Large-Scale Agent Systems</a> <em>(IBM Research)</em></li><li><a href="https://g3tsyst3m.com/byovd/BYOVD-and-Looting-LSASS-in-the-Modern-EDR-Era/">BYOVD and Looting LSASS in the Modern EDR Era</a> <em>(R.B.C (g3tsyst3m))</em></li><li><a href="https://safedep.io/microsoftsystem64-binary-payload-analysis/">Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace</a> <em>(SafeDep)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/28/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets/">Typosquatted npm packages used to steal cloud and CI/CD secrets</a> <em>(Microsoft Defender Security Research Team)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/">Malicious npm packages abuse dependency confusion to profile developer environments</a> <em>(Microsoft Defender Security Research Team)</em></li><li><a href="https://securelist.com/video-books-pirates-miners-rat/119943/">A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories">Supply Chain Compromises Impact Nx Console and GitHub Repositories</a> <em>(Cybersecurity and Infrastructure Security Agency (CISA))</em></li><li><a href="https://github.com/ProDefense/Hawk">Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services</a> <em>(ProDefense)</em></li><li><a href="https://theoneeyedargus.github.io/">Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign</a> <em>(TheOneEyedArgus)</em></li><li><a href="https://github.com/nvidia/skillspector">SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.</a> <em>(NVIDIA)</em></li><li><a href="https://freiheitsrechte.org/en/ueber-die-gff/presse/pressemitteilungen/one-click-and-youre-spied-on-gff-files-criminal-complaint-alongside-journalist-trung-khoa-le-following-spyware-attack">One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack</a> <em>(Society for Civil Rights (GFF))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-06-01.mp3" length="12431404" type="audio/mpeg"/>
      <itunes:duration>12:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 31, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-31.html</link>
      <pubDate>Sun, 31 May 2026 06:02:35 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260531_060235</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-0257.html">CVE-2026-0257</a> <em>(CISA KEV)</em></li><li><a href="https://securitylabs.datadoghq.com/articles/introducing-pathfinding-labs/">Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments</a> <em>(Datadog Security Labs)</em></li><li><a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/">Authenticated RCE via Argument Injection in Gogs (NOT FIXED)</a> <em>(Rapid7)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-31.mp3" length="1786819" type="audio/mpeg"/>
      <itunes:duration>1:51</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-30.html</link>
      <pubDate>Sat, 30 May 2026 06:05:28 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260530_060528</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>11</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://labs.withsecure.com/publications/greyvibe">GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations</a> <em>(WithSecure)</em></li><li><a href="https://www.ekathimerini.com/news/1304931/malware-seller-hunted-across-three-continents/">Malware seller hunted  across three continents</a> <em>(Nees Kathimerines Ekdoseis Single-Member S.A.)</em></li><li><a href="https://www.nsa.gov/Cybersecurity/ZIG/">Zero Trust Implementation Guidelines</a> <em>(National Security Agency)</em></li><li><a href="https://www.justice.gov/opa/pr/romanian-national-sentenced-selling-access-networks-oregon-state-government-office-and-other">Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims</a> <em>(U.S. Department of Justice)</em></li><li><a href="https://www.reuters.com/legal/government/law-firm-wiley-rein-hit-with-class-action-over-data-breach-tied-chinese-hackers-2026-05-26/">Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers</a> <em>(Thomson Reuters)</em></li><li><a href="https://www.ncsc.nl/nieuws/gezamenlijke-actie-politie-en-ncsc-legt-groot-botnetwerk-plat">Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network</a> <em>(Nationaal Cyber Security Centrum)</em></li><li><a href="https://kb.cert.org/vuls/id/780781">Casdoor contains multiple authentication bypass and access management vulnerabilities</a> <em>(Carnegie Mellon University)</em></li><li><a href="https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build/">The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents</a> <em>(Adversa AI)</em></li><li><a href="https://hannesweissteiner.com/pdfs/frost.pdf">FROST: Fingerprinting Remotely using OPFS-based SSD Timing</a> <em>(Hannes Weissteiner)</em></li><li><a href="https://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies">Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies</a> <em>(Sonatype)</em></li><li><a href="https://cyb3rops.medium.com/why-i-built-my-own-llm-benchmark-for-thor-finding-triage-c8492e3997dc">Why I Built My Own LLM Benchmark for THOR Finding Triage</a> <em>(Florian Roth)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-30.mp3" length="4883061" type="audio/mpeg"/>
      <itunes:duration>5:05</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 29, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-29.html</link>
      <pubDate>Fri, 29 May 2026 06:02:19 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260529_060219</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://open.substack.com/pub/nattothoughts/p/who-is-salt-typhoon-really-unraveling?r=q9u24">Who is Salt Typhoon Really? Unraveling the Attribution Challenge</a> <em>(open.substack.com)</em></li><li><a href="https://profero.io/blog/war-between-wars/">The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire</a> <em>(Segev-Magen Technologies Ltd. and Segev-Magen Technologies Inc.)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/designing-secure-access-with-ztna">Designing secure access with ZTNA</a> <em>(National Cyber Security Centre (NCSC))</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-29.mp3" length="1857454" type="audio/mpeg"/>
      <itunes:duration>1:56</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 28, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-28.html</link>
      <pubDate>Thu, 28 May 2026 06:08:57 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260528_060857</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-48172.html">CVE-2026-48172</a> <em>(CISA KEV)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/">The Evolution of Chinese-language Phishing Services</a> <em>(Google)</em></li><li><a href="https://www.ic3.gov/CSA/2026/260526.pdf">Silent Ransom Group Impersonating IT Personnel through Social Engineering</a> <em>(Federal Bureau of Investigation (FBI))</em></li><li><a href="https://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/6a155deeaffba9a1bf3c5b63_Ababil_of_Minab_Tech_Report.pdf">Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East</a> <em>(Gambit Security)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508637&idx=1&sn=31399d20fed27c8bfaf8e67aa2017bde&chksm=f9c19194ceb61882b9d5d9db3ce8c317407a7141b5d0356d124a3e1f0138fe7a51454d2c0251&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions</a> <em>(腾讯科技)</em></li><li><a href="https://www.sciencedirect.com/science/article/pii/S0167404826001069">The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization</a> <em>(www.sciencedirect.com)</em></li><li><a href="https://www.whitehouse.gov/wp-content/uploads/2026/05/M-26-14-Ensuring-Effective-and-Efficient-Agency-Logging-and-Network-Visibility-to-Defend-Against-Evolving-Cyber-Threats.pdf">White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats</a> <em>(Office of Management and Budget)</em></li><li><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=GUIDLNVIEW02&refcode=CISG-2026-02">CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state</a> <em>(CERT-In (Indian Computer Emergency Response Team))</em></li><li><a href="https://x41-dsec.de/lab/advisories/x41-2026-002-starlette/">Advisory X41-2026-002: Request Host Header not Validated in Starlette</a> <em>(X41 D-Sec GmbH)</em></li><li><a href="https://guysrd.github.io/epoll-uaf">The epoll UAF -  an epoll uaf race in fs/eventpoll.c</a> <em>(guysrd)</em></li><li><a href="https://www.promptarmor.com/resources/microsoft-copilot-cowork-exfiltrates-files">Microsoft Copilot Cowork Exfiltrates Files</a> <em>(PromptArmor)</em></li><li><a href="https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/">GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip</a> <em>(GitHub Security Lab)</em></li><li><a href="https://cyble.com/blog/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/">JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign - Cyble</a> <em>(Cyble)</em></li><li><a href="https://www.bbc.co.uk/news/articles/c3r2zjpryzro">Top ethical hacker Chompie warns AI tools could put her out of business</a> <em>(BBC)</em></li><li><a href="https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering">Tycoon 2FA AiTM detection for Entra ID and Google</a> <em>(Elastic)</em></li><li><a href="https://github.com/stolevchristian/sylvia">sylvia: iOS Syscall Explorer for IDA 9.X</a> <em>(Christian Stolev)</em></li><li><a href="https://mp.weixin.qq.com/s/ErpOjkTlKhu6QYVahUb_Qw">浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents</a> <em>(mp.weixin.qq.com)</em></li><li><a href="https://www.lexology.com/library/detail.aspx?g=f1e3ec53-5243-4418-8812-960d760c89b7">MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response</a> <em>(Law Business Research Ltd)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-28.mp3" length="8144396" type="audio/mpeg"/>
      <itunes:duration>8:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 27, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-27.html</link>
      <pubDate>Wed, 27 May 2026 06:07:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260527_060723</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/">RemotePE: The Lazarus RAT that lives in memory</a> <em>(Fox-IT)</em></li><li><a href="https://www.yna.co.kr/view/AKR20251120107600004">North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial</a> <em>(Yonhap News Agency)</em></li><li><a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/">Paved With Intent: ROADtools and Nation-State Tactics in the Cloud</a> <em>(Palo Alto Networks)</em></li><li><a href="https://netaskari.substack.com/p/sharp-eyes-how-to-track-a-foreigner">Sharp Eyes: Mass surveillance of foreigners in China - Part 1</a> <em>(NetAskari)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/">Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability</a> <em>(Google)</em></li><li><a href="https://success.trendmicro.com/en-US/solution/KA-0023430">Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities</a> <em>(Trend Micro)</em></li><li><a href="https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer">Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer</a> <em>(Aikido Security)</em></li><li><a href="https://github.com/R3n3r0/CVE-2026-20700">CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.</a> <em>(R3n3r0)</em></li><li><a href="https://github.com/Pennyw0rth/NetExec/pull/1245">Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec</a> <em>(Pennyw0rth)</em></li><li><a href="https://github.com/rootsecdev/relay_bible">relay_bible: Technical Reference to multiple relay techniques</a> <em>(rootsecdev)</em></li><li><a href="https://blog.ghostwolflab.com/redteam/729/">SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format</a> <em>(Ghost Wolf Lab)</em></li><li><a href="https://www.abdulmhsblog.com/posts/useingthewindowssourcecode/">The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]</a> <em>(Abdul Mhanni)</em></li><li><a href="https://github.com/gadievron/honeyslop/">honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports</a> <em>(Gadi Evron, John Cartwright, Daniel Cuthbert, and Michal Kamensky)</em></li><li><a href="https://commsrisk.com/youtube-sms-blaster-ad-displays-scam-messages-that-impersonate-telcos/">YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos</a> <em>(Eric Priezkalns)</em></li><li><a href="https://www.politie.nl/nieuws/2026/mei/22/pl1100---twee-mannen-aangehouden-voor-phishing.html">Twee mannen aangehouden voor phishing - Two men arrested for phishing</a> <em>(Politie)</em></li><li><a href="https://theins.press/en/news/292888">Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council</a> <em>(Roman Dobrokhotov )?kagi_q=who+is+the+founder+or+owner+of+The+Insider+%28theins.press%29)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-27.mp3" length="7362813" type="audio/mpeg"/>
      <itunes:duration>7:40</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 26, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-26.html</link>
      <pubDate>Tue, 26 May 2026 06:12:14 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260526_061214</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>27</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.qurium.org/forensics/the-future-of-residential-proxies/">The Future and Past of Residential Proxies</a> <em>(Qurium Media Foundation)</em></li><li><a href="https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/">Tracking TamperedChef Clusters via Certificate and Code Reuse</a> <em>(Palo Alto Networks)</em></li><li><a href="https://blog.polyswarm.io/kazuar-evolves-from-backdoor-to-resilient-espionage-ecosystem">Kazuar Evolves From Backdoor to Resilient Espionage Ecosystem</a> <em>(PolySwarm)</em></li><li><a href="https://www.fiod.nl/fiod-houdt-twee-verdachten-aan-wegens-overtreding-sanctiewetgeving/">FIOD houdt twee verdachten aan wegens overtreding sanctiewetgeving - An investigation by the FIOD reveals that this new company actually functions as a front for the sanctioned entities.</a> <em>(Fiscale Inlichtingen- en Opsporingsdienst (FIOD))</em></li><li><a href="https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos">Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects</a> <em>(Socket)</em></li><li><a href="https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing">How Attackers Force Microsoft to Send Phishing Emails</a> <em>(Abnormal Security)</em></li><li><a href="https://medium.com/@jehadbudagga/phantom-killer-reverse-engineering-and-weaponizing-a-lenovo-driver-to-terminate-edr-processes-9191cd06374f">Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes</a> <em>(Jehad Abudagga)</em></li><li><a href="https://medium.com/@s12deff/primitive-process-injection-apc-tandem-1dcec8515c86">Primitive Process Injection: APC Tandem</a> <em>(S12)</em></li><li><a href="https://github.com/D7EAD/mkPIVM">mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.</a> <em>(D7EAD)</em></li><li><a href="https://github.com/iss4cf0ng/OpenPetya">OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++</a> <em>(iss4cf0ng)</em></li><li><a href="https://github.com/qriousec/colony_agent/">V8 Wasm Type-Confusion Colony - A multi-agent fuzzing system that hunts WebAssembly type-confusion bugs in V8. Instead of running a single fuzzer loop, it runs a colony of LLM-driven agents</a> <em>(Qriousec)</em></li><li><a href="https://github.com/angr/angr">angr: A powerful and user-friendly binary analysis platform!</a> <em>(angr)</em></li><li><a href="https://suricata.io/2026/05/19/suricata-8-0-5-and-7-0-16-released/">Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities</a> <em>(Open Information Security Foundation (OISF))</em></li><li><a href="https://fatgid.io/">FatGid - FreeBSD 14.x kernel LPE</a> <em>(Przemyslaw Frasunek .io)</em></li><li><a href="https://tech.nicolonsky.ch/til/authenticationappdevicedetails/">Microsoft Authenticator App Details now exposed in Entra SignInLogs</a> <em>(Nicola Suter)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/20/introducing-rampart-and-clarity-open-source-tools-to-bring-safety-into-agent-development-workflow/">Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow</a> <em>(Microsoft)</em></li><li><a href="https://github.com/santhsecurity/keyhog">keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.</a> <em>(santhsecurity)</em></li><li><a href="https://github.com/KoblerS/np-audit">np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.</a> <em>(KoblerS)</em></li><li><a href="https://code.visualstudio.com/docs/enterprise/extensions">Manage [VSCode] extensions in enterprise environments</a> <em>(Microsoft)</em></li><li><a href="https://github.com/shellkraft/Ledger">Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.</a> <em>(shellkraft)</em></li><li><a href="https://www.preprints.org/frontend/manuscript/77d59744fd591eea279750da52b15011/download_pub">A Systematic Literature Review on Machine Learning for Intrusion Detection Systems</a> <em>(MDPI)</em></li><li><a href="https://warontherocks.com/machine-overmatch-what-salt-typhoon-reveals-about-chinas-data-centric-intelligence-strategy/">Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy</a> <em>(Metamorphic Media)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html">Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware</a> <em>(Trend Micro)</em></li><li><a href="https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/">Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware</a> <em>(Microsoft)</em></li><li><a href="https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows">Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows</a> <em>(Bitdefender)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/e/banana-rat.html">Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud</a> <em>(Trend Micro)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-26.mp3" length="9823338" type="audio/mpeg"/>
      <itunes:duration>10:13</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 25, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-25.html</link>
      <pubDate>Mon, 25 May 2026 06:04:00 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260525_060400</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.europol.europa.eu/media-press/newsroom/news/cybercriminal-vpn-used-ransomware-actors-dismantled-in-global-crackdown">Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation | Europol</a> <em>(Europol)</em></li><li><a href="https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html">VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure</a> <em>(CrowdStrike)</em></li><li><a href="https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms">Introducing Showboat: A new malware family taunts defenses and targets international telecom firms</a> <em>(Lumen Technologies)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/">From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence</a> <em>(Microsoft Defender Security Research Team)</em></li><li><a href="https://github.com/nettitude/CLR-STOMP">CLR-Stomp: .NET CLR-Stomping</a> <em>(Nettitude)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-vpn-exploitation-when-patched-doesnt-mean-protected/">VPN Exploitation When Patched Doesn't Mean Protected</a> <em>(ReliaQuest)</em></li><li><a href="https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html">Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor</a> <em>(PwC)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-25.mp3" length="2754395" type="audio/mpeg"/>
      <itunes:duration>2:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 24, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-24.html</link>
      <pubDate>Sun, 24 May 2026 06:06:09 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260524_060609</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>15</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://dti.domaintools.com/research/threat-intelligence-report-zionsiphon">Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?</a> <em>(DomainTools)</em></li><li><a href="https://www.ox.security/blog/north-korean-npm-infostealer-rat/">North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT</a> <em>(OX Security)</em></li><li><a href="https://socket.dev/blog/coruna-respawned-compromised-art-template-npm-package">Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit</a> <em>(Socket)</em></li><li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585">Windows BitLocker Security Feature Bypass Vulnerability</a> <em>(Microsoft)</em></li><li><a href="https://mysk.blog/2026/05/19/cve-2026-28910/">CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility</a> <em>(Talal Haj Bakry and Tommy Mysk)</em></li><li><a href="https://www.aikido.dev/blog/google-api-keys-deletion">Google API keys keep working after you delete them long enough to be exploited</a> <em>(Aikido)</em></li><li><a href="https://jonny-johnson.medium.com/a-deep-dive-into-codex-windows-sandbox-a2489bf4ae91">A Deep Dive into Codex Windows Sandbox</a> <em>(Jonathan Johnson)</em></li><li><a href="https://github.com/C0oki3s/veilgate">veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes</a> <em>(C0oki3s)</em></li><li><a href="https://www.r-tec.net/r-tec-blog-the-429-microsoft-graph-mystery.html">r-tec Blog | The 429 Microsoft Graph Mystery</a> <em>(r-tec Cyber Security)</em></li><li><a href="https://www.varonis.com/blog/ghosttree-ntfs-trick">GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security</a> <em>(Varonis)</em></li><li><a href="https://www.sprocketsecurity.com/blog/tenant-enumeration-is-dead">Azure Tenant Enumeration is Dead</a> <em>(Sprocket Security)</em></li><li><a href="https://blogs.cisco.com/security/ai-generated-reporting-lessons-learned-from-talos-incident-response">AI-generated reporting: Lessons learned from Cisco Talos Incident Response</a> <em>(Cisco)</em></li><li><a href="https://github.com/qmadev/CrabLoader">CrabLoader: A PoC Cobalt Strike UDRL written in Rust</a> <em>(qmadev)</em></li><li><a href="https://secret.club/2026/05/21/striga.html">Striga: Lifting x86 to LLVM IR with Python</a> <em>(mrexodia)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-24.mp3" length="6411537" type="audio/mpeg"/>
      <itunes:duration>6:40</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 23, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-23.html</link>
      <pubDate>Sat, 23 May 2026 06:05:03 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260523_060503</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>11</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-9082.html">CVE-2026-9082</a> <em>(CISA KEV)</em></li><li><a href="https://censys.com/iran-linked-operators-suspected-in-atg-breaches/">Iran-linked Operators Suspected in ATG Breaches</a> <em>(Censys)</em></li><li><a href="https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/">From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat</a> <em>(Cisco Talos)</em></li><li><a href="https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/">Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure</a> <em>(Quick Heal Technologies Ltd.)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/">Webworm: New burrowing techniques</a> <em>(ESET)</em></li><li><a href="https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/">Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs</a> <em>(Grafana Labs)</em></li><li><a href="https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w">Compromised Nx Console version 18.95.0</a> <em>(Nrwl)</em></li><li><a href="https://www.msuiche.com/posts/from-y2k-to-patch-tuesday-2025-25-years-of-bugs-in-the-windows-2000-source-tree/">From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree</a> <em>(Matt Suiche)</em></li><li><a href="https://securelist.com/exiftool-compromise-mac/119866/">How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/05/20/cve-2026-46333-local-root-privilege-escalation-and-credential-disclosure-in-the-linux-kernel-ptrace-path">CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path</a> <em>(Qualys)</em></li><li><a href="https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205">New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)</a> <em>(Searchlight Cyber)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-23.mp3" length="4784004" type="audio/mpeg"/>
      <itunes:duration>4:58</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 22, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-22.html</link>
      <pubDate>Fri, 22 May 2026 06:03:17 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260522_060317</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>7</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.csis.org/analysis/why-china-now-peer-competitor-united-states-cyberspace">Why China Is Now a Peer Competitor to the United States in Cyberspace</a> <em>(Center for Strategic and International Studies (CSIS))</em></li><li><a href="https://github.com/FalkorDB/falkordb">FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.</a> <em>(FalkorDB)</em></li><li><a href="https://medium.com/@s12deff/remote-process-read-primitive-via-ntcreatethreadex-exit-code-8370c54ed648">Remote Process Read Primitive via NtCreateThreadEx Exit Code</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://github.com/Hamid-K/nginx-rift-private-lab">nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings</a> <em>(Hamid Kashfi)</em></li><li><a href="https://github.com/BishopFox/aimap">laimap: Discover Exposed AI Services</a> <em>(Bishop Fox)</em></li><li><a href="https://github.com/raj3shp/persisthunt">persisthunt: Linux Persistence Detection, Hunting and Arftifact Collection script</a> <em>(raj3shp)</em></li><li><a href="https://x.com/i/status/2056884788179726685">We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.</a> <em>(GitHub)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-22.mp3" length="3323237" type="audio/mpeg"/>
      <itunes:duration>3:27</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 21, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-21.html</link>
      <pubDate>Thu, 21 May 2026 06:04:00 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260521_060400</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/">How Storm-2949 turned a compromised identity into a cloud-wide breach</a> <em>(Microsoft)</em></li><li><a href="https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/">New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here</a> <em>(www.ox.security)</em></li><li><a href="https://socket.dev/blog/antv-packages-compromised">Active Supply Chain Attack Compromises @antv Packages on npm...</a> <em>(socket.dev)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-21.mp3" length="1742515" type="audio/mpeg"/>
      <itunes:duration>1:48</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 20, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-20.html</link>
      <pubDate>Wed, 20 May 2026 06:02:23 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260520_060223</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://edition.cnn.com/2026/05/15/politics/iran-hackers-tank-readers-gas-stations">Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics</a> <em>(CNN)</em></li><li><a href="https://www.gov.pl/web/baza-wiedzy/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-komunikatora-signal">Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger</a> <em>(Kancelaria Prezesa Rady Ministrów)</em></li><li><a href="https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/">SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain</a> <em>(SentinelOne)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-20.mp3" length="1803955" type="audio/mpeg"/>
      <itunes:duration>1:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 19, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-19.html</link>
      <pubDate>Tue, 19 May 2026 06:08:43 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260519_060843</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/">uspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware</a> <em>(Cato Networks)</em></li><li><a href="https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor">Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor</a> <em>(Darktrace)</em></li><li><a href="https://medium.com/@S3N4T0R/static-kitten-apt-adversary-simulation-8f595aa74118">Static Kitten APT Adversary Simulation</a> <em>(S3N4T0R)</em></li><li><a href="https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/%20linux-rxgk-decrypt-mac">DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write</a> <em>(delphoslabs.com)</em></li><li><a href="https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/">Mullvad exit IPs as a fingerprinting vector</a> <em>(tmctmt)</em></li><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-128">An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.</a> <em>(Fortinet)</em></li><li><a href="https://github.com/azqzazq1/LID">LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"</a> <em>(Azizcan Daştan)</em></li><li><a href="https://gurucul.com/blog/hwmonitor-trojanized-to-deliver-multi-stage-stx-rat-via-dll-sideloading/">HWMonitor Trojanized for STX RAT DLL Sideloading</a> <em>(Gurucul)</em></li><li><a href="https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/">Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</a> <em>(Palo Alto Networks)</em></li><li><a href="https://socket.dev/blog/node-ipc-package-compromised">Popular node-ipc npm Package Infected with Credential Steale...</a> <em>(Socket)</em></li><li><a href="https://blog.axelarator.net/we-have-packet-capture-at-home/">We Have Packet Capture at Home</a> <em>(Axelarator)</em></li><li><a href="https://github.com/tsale/awesome-dfir-skills/blob/main/skills/analysis/admiralty-system-tr/SKILL.md">Admiralty System for CTI Claude skill</a> <em>(tsale)</em></li><li><a href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/">Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files</a> <em>(unit42.paloaltonetworks.com)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-19.mp3" length="5222026" type="audio/mpeg"/>
      <itunes:duration>5:26</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 18, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-18.html</link>
      <pubDate>Mon, 18 May 2026 07:44:06 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260518_074406</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://medium.com/@S3N4T0R/static-kitten-apt-adversary-simulation-8f595aa74118">Static Kitten APT Adversary Simulation</a> <em>(S3N4T0R)</em></li><li><a href="https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/">uspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware</a> <em>(Cato Networks)</em></li><li><a href="https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor">Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor</a> <em>(Thoma Bravo .com)</em></li><li><a href="https://github.com/tsale/awesome-dfir-skills/blob/main/skills/analysis/admiralty-system-tr/SKILL.md">Admiralty System for CTI Claude skill</a> <em>(**tsale**)</em></li><li><a href="https://delphoslabs.com/blog/36142374-e1fe-80a9-9456-d3c64df81bd5/%20linux-rxgk-decrypt-mac">DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write</a> <em>(Delphos Labs)</em></li><li><a href="https://tmctmt.com/posts/mullvad-exit-ips-as-a-fingerprinting-vector/">Mullvad exit IPs as a fingerprinting vector</a> <em>(Thomas M. C. T.)</em></li><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-128">An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.</a> <em>(Fortinet)</em></li><li><a href="https://github.com/azqzazq1/LID">LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"</a> <em>(Azizcan Daştan)</em></li><li><a href="https://gurucul.com/blog/hwmonitor-trojanized-to-deliver-multi-stage-stx-rat-via-dll-sideloading/">HWMonitor Trojanized for STX RAT DLL Sideloading</a> <em>(Gurucul .com)</em></li><li><a href="https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/">Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools</a> <em>(Palo Alto Networks, Inc.)</em></li><li><a href="https://socket.dev/blog/node-ipc-package-compromised">Popular node-ipc npm Package Infected with Credential Steale...</a> <em>(Socket)</em></li><li><a href="https://unit42.paloaltonetworks.com/gremlin-stealer-evolution/">Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files</a> <em>(Palo Alto Networks)</em></li><li><a href="https://blog.axelarator.net/we-have-packet-capture-at-home/">We Have Packet Capture at Home</a> <em>(axelarator)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-18.mp3" length="6776834" type="audio/mpeg"/>
      <itunes:duration>7:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 17, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-17.html</link>
      <pubDate>Sun, 17 May 2026 06:10:12 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260517_061012</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508584&idx=1&sn=3983faed8f799809ecc23eb552e73548&chksm=f9c19161ceb61877f61517327d054439cdf6a076c935ac98b835b78e125c98346e202e3457dc&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.</a> <em>(Tencent)</em></li><li><a href="https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry">FamousSparrow APT Targets Azerbaijani Oil and Gas Industry</a> <em>(Bitdefender)</em></li><li><a href="https://www.security.com/blog-post/fast16-nuclear-sabotage">Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations</a> <em>(Broadcom)</em></li><li><a href="https://reliaquest.com/blog/threat-spotlight-help-desk-lures-drop-kongtukes-evolved-modelorat/">Help-Desk Lures Drop KongTuke's Evolved ModeloRAT</a> <em>(ReliaQuest .com)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation">Welcome to BlackFile: Inside a Vishing Extortion Operation</a> <em>(Google Cloud)</em></li><li><a href="https://intezer.com/blog/orbit-returns/">OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments</a> <em>(Intezer)</em></li><li><a href="http://ic3.gov/PSA/2026/PSA260515">Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System</a> <em>(Federal Bureau of Investigation (FBI))</em></li><li><a href="https://sastu-insights.com/posts/Triggering-the-Secure-Boot-Certificate-Update-with-Intune-Remediations/">Triggering the Secure Boot Certificate Update with Intune Remediations</a> <em>(Sastu Insights)</em></li><li><a href="https://github.com/v12-security/pocs/tree/main/qemu">QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).</a> <em>(V12 Security)</em></li><li><a href="https://www.akamai.com/blog/security-research/one-fluke-3-pattern-mcp-back-end-vulnerabilities">One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities</a> <em>(Akamai)</em></li><li><a href="https://www.rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass-cisco-catalyst-sd-wan-controller-fixed/">CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)</a> <em>(Rapid7)</em></li><li><a href="https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/">Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities</a> <em>(Cisco Talos)</em></li><li><a href="https://github.com/v12-security/pocs/tree/main/fragnesia">Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit</a> <em>(V12 Security)</em></li><li><a href="https://github.com/kiddo-pwn/ffffirefox">FFFFirefox - A One-Day Wonder Renderer Exploit</a> <em>(kiddo-pwn)</em></li><li><a href="https://deadeclipse666.blogspot.com/2026/05/miniplasma-powerful-lpe.html?m=1">MiniPlasma, a powerful LPE</a> <em>(Nightmare-Eclipse)</em></li><li><a href="https://memn0ps.github.io/doublepulsar-a-user-defined-reflective-loader-in-the-crystal-palace-and-tradecraft-garden-era/">DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era</a> <em>(memN0ps)</em></li><li><a href="https://bigbingus.com/posts/stop-being-weird/">Stop Being Weird — Life After Call Stack Spoofing Under CET</a> <em>(Sizeable-Bingus)</em></li><li><a href="https://newtonpaul.com/blog/evilginx-m365-aitm-panel-research/">Novel Evilginx Frontend - Lowering the barrier for token theft reuse</a> <em>(Paul Newton)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-17.mp3" length="8058715" type="audio/mpeg"/>
      <itunes:duration>8:23</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 16, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-16.html</link>
      <pubDate>Sat, 16 May 2026 06:01:26 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260516_060126</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-42897.html">CVE-2026-42897</a> <em>(CISA KEV)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-16.mp3" length="1076706" type="audio/mpeg"/>
      <itunes:duration>1:07</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 15, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-15.html</link>
      <pubDate>Fri, 15 May 2026 06:02:11 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260515_060211</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-20182.html">CVE-2026-20182</a> <em>(CISA KEV)</em></li><li><a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/">Thus Spoke…The Gentlemen</a> <em>(Check Point Research)</em></li><li><a href="https://github.com/Nightmare-Eclipse/YellowKey">YellowKey: YellowKey Bitlocker Bypass Vulnerability</a> <em>(Nightmare-Eclipse)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-15.mp3" length="2028399" type="audio/mpeg"/>
      <itunes:duration>2:06</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 14, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-14.html</link>
      <pubDate>Thu, 14 May 2026 06:03:14 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260514_060314</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>4</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://harfanglab.io/insidethelab/gamaredon-gammadrop-gammaload/">Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad</a> <em>(HarfangLab)</em></li><li><a href="https://www.stream.security/post/shai-hulud-another-wave-going-open-source">Shai-Hulud: Another Wave and Going Open Source</a> <em>(Stream Security)</em></li><li><a href="https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/">Android Intrusion Logging as a new source of data for consensual forensic analysis - Amnesty International Security Lab</a> <em>(Amnesty International Security Lab)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise/">Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise</a> <em>(Microsoft)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-14.mp3" length="2298819" type="audio/mpeg"/>
      <itunes:duration>2:23</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 13, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-13.html</link>
      <pubDate>Wed, 13 May 2026 06:07:06 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260513_060706</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.security.com/threat-intelligence/iran-seedworm-electronics">Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign</a> <em>(Threat Hunter Team at Broadcom)</em></li><li><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details</a> <em>(Google Threat Intelligence)</em></li><li><a href="https://medium.com/@s12deff/detecting-remote-thread-creation-with-windows-driver-9901fdbaf7b1">Detecting Remote Thread Creation with Windows Driver</a> <em>(S12 - 0x12Dark Development)</em></li><li><a href="https://lists.debian.org/debian-devel-announce/2026/05/msg00001.html">bits from the release team - Aided by the efforts of the Reproducible Builds project,  we've decided it's time to say that Debian must ship reproducible packages</a> <em>(The content posted at the URL is controlled by the **Debian Release Team** . **Paul Gevers** is listed as the sender of the announcement .)</em></li><li><a href="https://0day.click/recipe/2026-05-12-cc-rce/">Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection</a> <em>(0day.click)</em></li><li><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html">AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.</a> <em>(Advanced Micro Devices, Inc.)</em></li><li><a href="https://github.com/sgkdev/rxrpc_privesc">rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions</a> <em>(sgkdev)</em></li><li><a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Mythos finds a curl vulnerability</a> <em>(Daniel Stenberg)</em></li><li><a href="https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment/">Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment</a> <em>(XLab's Cyber Threat Insight and Analysis System (CTIA))</em></li><li><a href="https://husseinmuhaisen.com/blog/reverse-engineering-teampcp-telnyx-file-format-chain/">Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign</a> <em>(Hussein Muhaisen)</em></li><li><a href="https://github.com/maxbrito500/esp32-c5-deauth">esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app</a> <em>(The content posted at the URL is controlled by **maxbrito500**.)</em></li><li><a href="https://github.com/magicsword-io/LOLRMM/pull/141">LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.</a> <em>(The content posted at the URL is controlled by **MHaggis**.)</em></li><li><a href="https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/">How Cloudflare responded to the “Copy Fail” Linux vulnerability</a> <em>(**Cloudflare** controls the content posted at the provided URL .)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-13.mp3" length="6786447" type="audio/mpeg"/>
      <itunes:duration>7:04</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 12, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-12.html</link>
      <pubDate>Tue, 12 May 2026 06:03:47 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260512_060347</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://jonny-johnson.medium.com/etwwatcher-f657b3d60195">EtwWatcher</a> <em>(Jonathan Johnson)</em></li><li><a href="https://github.com/PentHertz/LUKSbox">LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2, TPM 2.0 etc</a> <em>(Sébastien Dudek)</em></li><li><a href="https://techcommunity.microsoft.com/blog/azureinfrastructureblog/cheriot-ibex-closing-the-door-on-memory-safety-vulnerabilities-with-hardware-enf/4517904">CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection</a> <em>(Microsoft)</em></li><li><a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/fine-of-nearly-1m-issued-against-south-staffordshire-plc-and-south-staffordshire-water-plc/">Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach</a> <em>(Information Commissioner's Office (ICO))</em></li><li><a href="https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor">Donuts and Beagles: Fake Claude site spreads backdoor</a> <em>(Sophos X-Ops)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-12.mp3" length="2764844" type="audio/mpeg"/>
      <itunes:duration>2:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 11, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-11.html</link>
      <pubDate>Mon, 11 May 2026 06:06:38 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260511_060638</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.beehive.govt.nz/release/nz-announces-sanctions-malicious-russian-cyber-actors-online-platforms">NZ announces sanctions on malicious Russian cyber actors, online platforms</a> <em>(Beehive.govt.nz)</em></li><li><a href="https://www.genians.co.kr/en/blog/threat_intelligence/python">Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign</a> <em>(www.genians.co.kr)</em></li><li><a href="https://detect.fyi/unmanaged-powershell-execution-hunting-beyond-powershell-exe-1356689fb88f">Unmanaged PowerShell Execution: Hunting Beyond powershell.exe</a> <em>(The content posted at the URL is controlled by **Nesrine Cherrabi**.)</em></li><li><a href="https://cloudbrothers.info/en/aadgraphactivitylogs/">Now You See Me: AADGraphActivityLogs</a> <em>(Cloudbrothers)</em></li><li><a href="https://checkmarx.com/blog/ongoing-security-updates/">Update: Ongoing Checkmarx Supply Chain Security Incident</a> <em>(Checkmarx)</em></li><li><a href="https://github.com/sgkdev/page_inject/">page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer</a> <em>(The content posted at the URL is controlled by **sgkdev**.)</em></li><li><a href="https://gmplib.org/">The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."</a> <em>(The Free Software Foundation controls the content posted at https://gmplib.org.)</em></li><li><a href="https://back.engineering/blog/09/05/2026/">Static Devirtualization of Themida</a> <em>(Back Engineering Labs)</em></li><li><a href="https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility">AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT</a> <em>(Dragos)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-11.mp3" length="4993820" type="audio/mpeg"/>
      <itunes:duration>5:12</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 10, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-10.html</link>
      <pubDate>Sun, 10 May 2026 06:09:05 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260510_060905</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>19</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-42208.html">CVE-2026-42208</a> <em>(CISA KEV)</em></li><li><a href="https://www.justice.gov/opa/pr/member-prolific-russian-ransomware-group-sentenced-prison">Member of Prolific Russian Ransomware Group Sentenced to Prison</a> <em>(United States Department of Justice)</em></li><li><a href="https://lab52.io/blog/easterbunny/">EasterBunny: advanced espionage artifacts attributed to APT29</a> <em>(LAB52)</em></li><li><a href="https://r136a1.dev/2026/05/07/where-have-all-the-complex-malware-and-their-analyses-gone/">Where Have All the Complex Windows Malware and Their Analyses Gone?</a> <em>(r136a1.dev)</em></li><li><a href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/">PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</a> <em>(SentinelOne (SentinelLABS))</em></li><li><a href="https://letsencrypt.status.io/">Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root cert</a> <em>(Let's Encrypt)</em></li><li><a href="https://blog.denic.de/analyse-des-dns-ausfalls-vom-5-mai-2026/">Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026</a> <em>(DENIC editorial team)</em></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/">When prompts become shells: RCE vulnerabilities in AI agent frameworks</a> <em>(Microsoft)</em></li><li><a href="https://github.com/p0dalirius/Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus/">Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus</a> <em>(p0dalirius)</em></li><li><a href="https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174">MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)</a> <em>(Progress)</em></li><li><a href="https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo/tree/main">Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo</a> <em>(0xdeadbeefnetwork)</em></li><li><a href="https://github.com/depthsecurity/PositiveIntent">PositiveIntent: Evasive loader for .NET Framework assemblies</a> <em>(The content posted at the URL is controlled by **Mister-Joe**.)</em></li><li><a href="https://specterops.io/blog/2026/05/06/dev-tunnels-the-accidental-c2/">The Accidental C2: Exploring Dev Tunnels for Remote Access</a> <em>(SpecterOps)</em></li><li><a href="https://research.nasbench.dev/research/lolbins/dism-sandbox-provider-hijack">Living of the Land - DISM Sandbox Provider Hijack</a> <em>(NasBench)</em></li><li><a href="https://github.com/azqzazq1/SunnyDayBPF">SunnyDayBPF: SunnyDayBPF: eBPF-based post-syscall user-buffer telemetry deception</a> <em>(Azizcan Daştan)</em></li><li><a href="https://blog.bournemouth2600.org/2026/05/tracking-sorry-extortionist-campaign.html">Tracking the "Sorry" Extortionist Campaign Against cPanel Websites</a> <em>(afx_IDE)</em></li><li><a href="https://eversinc33.com/2026/05/07/llvm-devirtualizer">Writing a Naive LLVM-based Devirtualizer</a> <em>(The content posted at the URL is by **eversinc33**.)</em></li><li><a href="https://www.bluevoyant.com/blog/lorem-ipsum-trojanized-microsoft-teams-installers-multi-stage-loader-backdoor">Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor</a> <em>(BlueVoyant)</em></li><li><a href="https://gsmll.github.io/hypervenom/writeup/">HyperVenom: Using Hyper-V for Ring -1 Control from Usermode | HyperVenom</a> <em>(The content posted at the URL is controlled by **gsmll**.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-10.mp3" length="10309843" type="audio/mpeg"/>
      <itunes:duration>10:44</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 09, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-09.html</link>
      <pubDate>Sat, 09 May 2026 06:01:36 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260509_060136</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>1</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama">Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama</a> <em>(Cyera Research)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-09.mp3" length="950901" type="audio/mpeg"/>
      <itunes:duration>0:59</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 08, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-08.html</link>
      <pubDate>Fri, 08 May 2026 06:05:10 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260508_060510</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-0300.html">CVE-2026-0300</a> <em>(CISA KEV)</em></li><li><a href="https://patchnow.workshop1.net/cve/cve-2026-6973.html">CVE-2026-6973</a> <em>(CISA KEV)</em></li><li><a href="https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US">We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.</a> <em>(Ivanti)</em></li><li><a href="https://margin.re/2026/05/unpacking-russian-iranian-private-sector-cyber-connections/">Unpacking Russian-Iranian Private-Sector Cyber Connections</a> <em>(Margin Research)</em></li><li><a href="https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/">OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI</a> <em>(Kaspersky Global Research and Analysis Team (GReAT))</em></li><li><a href="https://www.rtl-sdr.com/student-arrested-in-taiwan-for-using-sdr-and-handheld-radios-to-halt-four-high-speed-trains-with-tetra-hack/comment-page-221/">Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack</a> <em>(**RTL-SDR.com** is a blog that started as a hobby to share tutorials and curate content related to RTL-SDR dongles . The website itself is not controlled by a large media conglomerate like RTL Group , but rather by the individuals who contribute to and manage the blog .)</em></li><li><a href="https://github.com/V4bel/dirtyfrag">Dirty Frag: Universal Linux LPE</a> <em>(Hyunwoo Kim)</em></li><li><a href="https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker-0">Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea</a> <em>(United States Department of Justice)</em></li><li><a href="https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference">Revealed: Russia’s top secret spy school teaching hacking and election meddling</a> <em>(The Guardian)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-08.mp3" length="4672409" type="audio/mpeg"/>
      <itunes:duration>4:51</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 07, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-07.html</link>
      <pubDate>Thu, 07 May 2026 06:03:53 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260507_060353</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>6</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a> <em>(Rapid7)</em></li><li><a href="https://hunt.io/blog/iranian-nexus-oman-government-intrusion">Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed</a> <em>(Hunt.io)</em></li><li><a href="https://blog.talosintelligence.com/uat-8302/">UAT-8302 and its box full of malware</a> <em>(Cisco Talos)</em></li><li><a href="https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/">A rigged game: ScarCruft compromises gaming platform in a supply-chain attack</a> <em>(ESET Research)</em></li><li><a href="https://security.paloaltonetworks.com/CVE-2026-0300">CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal</a> <em>(Palo Alto Networks)</em></li><li><a href="https://visit.suspect.network/reversing-adventures/inadvertent-injections">Inadvertent Injections</a> <em>(The content posted at the URL is controlled by sud0woodo.)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-07.mp3" length="3255528" type="audio/mpeg"/>
      <itunes:duration>3:23</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 06, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-06.html</link>
      <pubDate>Wed, 06 May 2026 06:02:34 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260506_060234</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>3</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/tr/daemon-tools-backdoor/119654/">Popular DAEMON Tools software compromised</a> <em>(Securelist)</em></li><li><a href="https://blogs.oracle.com/security/accelerating-vulnerability-detection-and-response-at-oracle">Accelerating Vulnerability Detection and Response at Oracle</a> <em>(Oracle)</em></li><li><a href="https://webhosting.today/2026/05/03/the-cpanel-zero-day-was-active-for-64-days-before-anyone-knew/">The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew</a> <em>(webhosting.today)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-06.mp3" length="1687345" type="audio/mpeg"/>
      <itunes:duration>1:45</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 05, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-05.html</link>
      <pubDate>Tue, 05 May 2026 06:07:06 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260505_060706</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>13</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://book.yunzhan365.com/tkgd/ksgs/mobile/index.html?sessionid">《APT高级威胁研究报告》（2026 版）- Advanced Threat Research Report (2026 Edition)</a> <em>(book.yunzhan365.com)</em></li><li><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA%3D%3D&mid=2247508516&idx=1&sn=a869f67294b5777615ad597c3730105e&chksm=f9c1912dceb6183b4f7f359de87814c613d58b671245307a99857eb03847a0860743516e7fae&scene=178&cur_album_id=1955835290309230595&search_click_id=#rd">蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.</a> <em>(mp.weixin.qq.com)</em></li><li><a href="https://github.com/ridgelinecyberdefence/vanguard">vanguard: VanGuard is a self-contained incident response toolkit built in Go that gives DFIR teams a single binary for triage, threat hunting, memory forensics, disk collection, remote operations</a> <em>(ridgelinecyberdefence)</em></li><li><a href="https://github.com/tandrlemandrle/GIDR">GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root</a> <em>(The content posted at the URL is controlled by **tandrlemandrle**.)</em></li><li><a href="https://github.com/magicsword-io/LOLDrivers/pull/221">Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon</a> <em>(magicsword-io)</em></li><li><a href="https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers">38 CVEs in Healthcare Software Used by 100,000 Medical Providers</a> <em>(AISLE)</em></li><li><a href="https://mp.weixin.qq.com/s/eMCDye1A-LfO6gMsTTvNSQ">CVE-2026-31431：我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.</a> <em>(The content posted at the URL is controlled by **Tencent**, the Chinese tech giant that owns WeChat (also known as Weixin). Tencent has close ties with the Chinese Communist Party (CCP), and as of 2023, the government held a small stake in the company. WeChat's external link content management is governed by Tencent's specifications.)</em></li><li><a href="https://www.huntress.com/blog/dmsa-ouroboros-credential-extraction-windows-server-2025">dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 | Huntress</a> <em>(Huntress)</em></li><li><a href="https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/AMSI%20BYPASS/Amsi_Page_Guard_Exceptions">AMSI Page Guard Bypass (Rust PoC)</a> <em>(github.com)</em></li><li><a href="https://ghostbyt3.github.io/blog/nday-research-ai">N-Day Research with AI: Using Ollama and n8n</a> <em>(The content posted at the URL is controlled by **ghostbyt3** .)</em></li><li><a href="https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring/">Recursively fuzzing MS-RPC structures and monitoring using ETW</a> <em>(Incendium)</em></li><li><a href="https://github.com/likaia/nginxpulse">nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板，提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation etc</a> <em>(likaia)</em></li><li><a href="https://zonifer.dev/posts/byovd-kernel-driver-hardware-primitives.html">gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives</a> <em>(Zonifer)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-05.mp3" length="5639149" type="audio/mpeg"/>
      <itunes:duration>5:52</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 04, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-04.html</link>
      <pubDate>Mon, 04 May 2026 06:10:05 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260504_061005</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>18</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-cpanel-whm-critical-vulnerability">Active exploitation of cPanel/WHM critical vulnerability</a> <em>(ASD's ACSC)</em></li><li><a href="https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html">Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia</a> <em>(Trend Micro (US))</em></li><li><a href="https://github.com/ThatTotallyRealMyth/Impacket-IoCs">Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library</a> <em>(ThatTotallyRealMyth)</em></li><li><a href="https://arxiv.org/abs/2603.28728">Study of Post Quantum status of Widely Used Protocols</a> <em>(Cisco Research (Tushin Mallick, Ashish Kundu, and Ramana Kompella))</em></li><li><a href="https://blog.talosintelligence.com/ai-powered-honeypots-turning-the-tables-on-malicious-ai-agents/">AI-powered honeypots: Turning the tables on malicious AI agents</a> <em>(Talos Intelligence)</em></li><li><a href="https://gp.gov.ua/en/posts/na-lvivshhini-zatrimano-xakersku-grupu-yaka-zlamuvala-igrovi-akaunti-i-otrimala-maize-10-mln-grn-pributku-vid-yix-prodazu-v-rosiyu">A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia</a> <em>(gp.gov.ua)</em></li><li><a href="https://www.trellix.com/statement/">Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "</a> <em>(Trellix)</em></li><li><a href="https://trustedsec.com/blog/arp-around-and-find-out-hijacking-gpo-unc-paths-for-code-execution-and-ntlm-relay">ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…</a> <em>(TrustedSec)</em></li><li><a href="https://github.com/chvancooten/code-needle">code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.</a> <em>(chvancooten)</em></li><li><a href="https://copy.golf/">copy.golf — golf your exploits - copy.fail smaller exploits</a> <em>(**Kabir Acharya** is the individual who controls the content posted at https://copy.golf/.)</em></li><li><a href="https://socket.dev/blog/malicious-ruby-gems-and-go-modules-steal-secrets-poison-ci">Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI</a> <em>(Socket)</em></li><li><a href="https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin/">Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin</a> <em>(Semgrep)</em></li><li><a href="https://github.com/Lightning-AI/pytorch-lightning/issues/21689">Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning</a> <em>(Lightning-AI)</em></li><li><a href="https://ransom-isac.org/blog/dragonbreath-dragon-in-the-kernel/">DragonBreath: Dragon in the Kernel</a> <em>(Ransom-ISAC team)</em></li><li><a href="https://ctrlaltintel.com/research/Qilin/">Watch Guard! Qilin affiliate exploits network appliances for initial access</a> <em>(Ctrl-Alt-Intel)</em></li><li><a href="https://www.varonis.com/blog/bluekit">Meet Bluekit: The AI-Powered All-in-One Phishing Kit</a> <em>(Varonis Threat Labs)</em></li><li><a href="https://gist.github.com/ddamenova/a24f3f012012affd017d6bf712f2dd02">IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect</a> <em>(The content posted at the URL is controlled by **Saar Ron, John Lambert, and Diana Damenova**.)</em></li><li><a href="https://github.com/SharonBrizinov/Holy-Grail-PCAP">Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.</a> <em>(Sharon Brizinov .)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-fallback-2026-05-04.mp3" length="9325549" type="audio/mpeg"/>
      <itunes:duration>9:42</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 03, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-03.html</link>
      <pubDate>Sun, 03 May 2026 06:08:28 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260503_060828</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>16</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://www.bloomberg.com/news/articles/2026-05-01/russian-charged-in-oil-and-gas-facility-hacks-pleads-guilty">Russian Hacker Pleads Guilty in Oil and Gas Facility Attacks</a> <em>(**Bloomberg L.P.** controls the content posted at the provided URL . Bloomberg L.P. is a privately held financial, software, data, and media company co-founded by **Michael Bloomberg** . Michael Bloomberg is the majority owner of Bloomberg L.P. . Bloomberg News is a division of Bloomberg L.P. .)</em></li><li><a href="https://ctrlaltintel.com/research/SEA-CPanel/">South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)</a> <em>(Ctrl-Alt-Intel)</em></li><li><a href="https://www.justice.gov/opa/pr/two-americans-who-attacked-multiple-us-victims-using-alphv-blackcat-ransomware-sentenced">Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison</a> <em>(United States Department of Justice)</em></li><li><a href="https://clickup.com/blog/april-27th-update/">April 27th - What happened with our feature flag configuration | The ClickUp Blog</a> <em>(ClickUp)</em></li><li><a href="https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/">VECT: Ransomware by design, Wiper by accident - Check Point Research</a> <em>(Check Point Research)</em></li><li><a href="https://www.cryptika.com/qilin-ransomware-enumerates-rdp-authentication-history-on-a-compromised-server/">Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server | Cryptika Cybersecurity</a> <em>(Cryptika)</em></li><li><a href="https://medium.com/@rohitashokgowd/seven-queries-to-audit-the-sentinel-detections-your-soc-may-have-missed-8e9c73fc2522">Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.</a> <em>(Rohitashokgowd)</em></li><li><a href="https://github.com/persistent-security/month-of-bypasses">month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only</a> <em>(Persistent Security)</em></li><li><a href="https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era">Blog: Evolving the Android &amp; Chrome VRPs for the AI Era</a> <em>(Google Bug Hunters)</em></li><li><a href="https://github.com/nuclear-treestump/pydep-vector-runner">pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.</a> <em>(The content posted at the URL is controlled by **Ikari**.)</em></li><li><a href="https://www.secwest.net/copyfail-mitigation">How to block CVE-2026-31431 (Copy Fail)</a> <em>(SEC West)</em></li><li><a href="https://github.com/wgnet/wg.copyfail.patch">wg.copyfail.patch: CVE-2026-31431 eBPF fix - Copy.fail</a> <em>(The content posted at the URL is controlled by **wgnet**.)</em></li><li><a href="https://blog.quarkslab.com/auditing-application-permissions-in-microsoft-entra-id-hidden-risks-pitfalls-and-quarkslabs-qazpt-tool.html">Auditing Application Permissions in Microsoft Entra ID: Hidden Risks, Pitfalls, and Quarkslab's QAZPT Tool</a> <em>(Quarkslab)</em></li><li><a href="https://github.com/Meltedd/VisualSploit">VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.</a> <em>(Meltedd)</em></li><li><a href="https://github.com/SilentisVox/DoomSyscalls">DoomSyscalls: Clean Indirect Syscalls with Hook Evasion &amp; Return Address Spoofing.</a> <em>(SilentisVox)</em></li><li><a href="https://github.com/mrphrazer/binary-cartography/tree/main/2026-04-agentic_malware_analysis">Agentic Malware Analysis: From Task Automation to Deep Analysis</a> <em>(github.com)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-03.mp3" length="7169715" type="audio/mpeg"/>
      <itunes:duration>7:28</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 02, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-02.html</link>
      <pubDate>Sat, 02 May 2026 06:07:02 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260502_060702</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://securelist.com/silver-fox-tax-notification-campaign/119575/">Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor</a> <em>(AO Kaspersky Lab)</em></li><li><a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services">Careful adoption of agentic AI services</a> <em>(Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), United States Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), and United Kingdom National Cyber Security Centre (NCSC-UK))</em></li><li><a href="https://anchor.host/wordpress-plugin-hijacked-in-2020-hid-a-dormant-backdoor-for-years/">WordPress Plugin Hijacked in 2020 Hid a Dormant Backdoor for Years</a> <em>(The content posted on the website is controlled by **anadnet** .)</em></li><li><a href="https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce">CVE-2026-42167 Allows Auth Bypass And RCE In ProFTPD - in an extension, not core</a> <em>(ZeroPath)</em></li><li><a href="https://www.sonicwall.com/support/notices/security-advisory-firmware-update-required-gen-6-gen-7-and-gen-8-firewalls/kA1VN000001F03x0AC">Security Advisory: Firmware Update Required — Gen 6, Gen 7, and Gen 8 Firewalls</a> <em>(SonicWall)</em></li><li><a href="https://www.catonetworks.com/blog/cato-ctrl-new-vulnerabilities-in-nvidia-nemo-and-meta-pytorch/">New Vulnerabilities in NVIDIA NeMo and Meta PyTorch Enable Full System Compromise</a> <em>(Cato Networks)</em></li><li><a href="https://atos.net/wp-content/uploads/2026/04/atos-byovd-article.pdf">Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective</a> <em>(atos.net)</em></li><li><a href="https://www.huntress.com/blog/komari-c2-agent-abuse">Komari Red: The Monitoring Tool with a Built-in Reverse Shell</a> <em>(Huntress)</em></li><li><a href="https://www.ncsc.gov.uk/blogs/prepare-for-vulnerability-patch-wave">Preparing for a ‘vulnerability patch wave’</a> <em>(National Cyber Security Centre)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-02.mp3" length="5110431" type="audio/mpeg"/>
      <itunes:duration>5:19</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - May 01, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-05-01.html</link>
      <pubDate>Fri, 01 May 2026 06:04:30 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260501_060430</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>9</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://patchnow.workshop1.net/cve/cve-2026-41940.html">CVE-2026-41940</a> <em>(CISA KEV)</em></li><li><a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026">Security: CVE-2026-41940 - cPanel &amp; WHM / WP2 Security Update 04/28/2026</a> <em>(cPanel)</em></li><li><a href="https://www.justice.gov/usao-sdtx/pr/prolific-chinese-state-sponsored-contract-hacker-extradited-italy">Prolific Chinese state-sponsored contract hacker extradited from Italy</a> <em>(U.S. Attorney's Office, Southern District of Texas)</em></li><li><a href="https://www.ic3.gov/PSA/2026/PSA260430">The Federal Bureau of Investigation is publishing this Public Service Announcement to warn the public of cyber threat actors increasingly using sophisticated, cyber-enabled tactics to steal cargo</a> <em>(Federal Bureau of Investigation)</em></li><li><a href="https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology">Adapting Zero Trust Principles to Operational Technology</a> <em>(CISA)</em></li><li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2033170">2033170 - DigiCert: Misissued code signing certificates</a> <em>(DigiCert)</em></li><li><a href="https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc">SQL injection in Proxy API key verification in LiteLLM</a> <em>(BerriAI)</em></li><li><a href="https://www.sans.org/blog/living-off-the-cloud">Living off the Cloud</a> <em>(SANS Institute)</em></li><li><a href="https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold/">Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold</a> <em>(StarLabs)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-05-01.mp3" length="4854639" type="audio/mpeg"/>
      <itunes:duration>5:03</itunes:duration>
    </item>
    <item>
      <title>InfoSec Briefing - April 30, 2026</title>
      <link>https://briefing.workshop1.net/html/briefing-2026-04-30.html</link>
      <pubDate>Thu, 30 Apr 2026 06:03:58 +0000</pubDate>
      <guid isPermaLink="false">https://briefing.workshop1.net/episode_20260430_060358</guid>
      <description><![CDATA[<p>Today's briefing covers <strong>5</strong> security articles.</p><p><strong>ARTICLES COVERED:</strong></p><ol><li><a href="https://hunt.io/blog/xlabs-v1-ddos-for-hire-operation-exposed">xlabs_v1 DDoS-for-Hire Operation Exposed: How an Operator's Debug Build Unraveled a Commercial Game-Server Botnet</a> <em>(hunt.io)</em></li><li><a href="https://copy.fail/">Copy Fail — 732 Bytes to Root</a> <em>(theori-io)</em></li><li><a href="https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack">TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages</a> <em>(socket.dev)</em></li><li><a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">The Internet Is Falling Down, Falling Down, Falling Down (cPanel &amp; WHM Authentication Bypass CVE-2026-41940)</a> <em>(watchTowr Labs)</em></li><li><a href="https://semgrep.dev/blog/2026/sap-npm-packages-compromised-in-supply-chain-attack-using-obfuscated-bun-runtime-payload/">SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun</a> <em>(semgrep.dev)</em></li></ol>]]></description>
      <enclosure url="https://briefing-workshop1.b-cdn.net/mp3/briefing-conversation-2026-04-30.mp3" length="2492334" type="audio/mpeg"/>
      <itunes:duration>2:35</itunes:duration>
    </item>
  </channel>
</rss>