Daily DefSec Brief

Daily DefSec Brief

A daily podcast covering the important cyber security news that IT and security teams need to know.

Episodes

July 27, 2026 3 mins
1. Fastjson RCE under active exploitation in the Java ecosystem — Risky Business News — https://news.risky.biz/risky-bulletin-a-json-rce-bug-is-about-to-rock-the-java-world/
2. Ransomware crews mass-exploiting edge VPN/firewall appliances (update) — CVE-2023-4966, CVE-2025-5777, CVE-2026-0257, CVE-2026-3055, CVE-2026-50751, CVE-2026-50752, CVE-2026-8451 — Cyber Security News — https://cybers...
Listen
Watch
Mark as Played
1. Russian espionage group reads Western mailboxes through zero-click Zimbra flaw — CVE-2025-66376 — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
2. Clop exploits critical PTC Windchill/FlexPLM RCE for data-theft extortion — CVE-2026-12569 — BleepingComputer — https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-...
Listen
Watch
Mark as Played
1. Check Point SmartConsole authentication bypass zero-day (active exploitation) — CVE-2026-16232, CVE-2026-50751 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/
2. Chaos ransomware msaRAT hides C2 in Chrome/Edge via WebRTC — No CVE — Cisco Tal...
Listen
Watch
Mark as Played
1. CISA adds DD-WRT UPnP buffer overflow to KEV — CVE-2021-27137 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Kratos AiTM phishing-kit infrastructure taken down — The Hacker News — https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
3. Compromised Outlook mailboxes used to steal MFA-protected M365 sessions — Cyber Security News &m...
Listen
Watch
Mark as Played
1. Palo Alto GlobalProtect auth-bypass now used in Qilin ransomware attacks — CVE-2026-0257 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
2. Windows LegacyHive privilege-escalation zero-day disclosed with PoC, no official fix — (no CVE assigned) — BleepingComputer — https://www.bleepingcomputer.co...
Listen
Watch
Mark as Played
1. ServiceNow AI Platform RCE now under active exploitation — CVE-2026-6875 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
2. WP2Shell — WordPress core flaws exploited within hours — CVE-2026-60137, CVE-2026-63030 — SecurityWeek — https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-...
Listen
Watch
Mark as Played
1. FortiSandbox OS command injection added to CISA KEV, actively exploited — CVE-2026-25089 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. New HTTP/2 flow-control stall DoS — CVE-2019-9511, CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 — CERT/CC VU#885548 — https://kb.cert.org/vuls/id/885548
3. 7-Zip heap overflow in XZ decompression patched — CVE-2...
Listen
Watch
Mark as Played
1. CISA adds actively exploited Oracle E-Business Suite flaw to KEV, feds have until Saturday — CVE-2026-46817 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
2. Zoom patches critical Windows account-takeover flaw — CVE-2026-53412, CVE-2026-53409...
Listen
Watch
Mark as Played
1. CISA adds SharePoint and AD FS zero-days to KEV, deadline Friday — CVE-2026-56164, CVE-2026-56155 (also CVE-2026-32201, CVE-2026-45659, CVE-2026-58644, CVE-2026-55040) — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · CISA advisory https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations · Rapid7 https://www.rapid7.com/blog/post/ve-c...
Listen
Watch
Mark as Played
1. CISA adds 18-year-old Cisco IOS flaw to KEV catalog — CVE-2008-4128 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. Microsoft maps a year of ShinyHunters-style OAuth abuse against Salesforce and SaaS apps — no CVE — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-a...
Listen
Watch
Mark as Played
1. Progress tells ShareFile customers to shut down Storage Zone Controller servers — CVE-2026-2699, CVE-2026-2701 — SecurityWeek — https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/
2. Zimbra patches critical zero-click code execution flaw — CVE not yet disclosed — SecurityWeek — https://www.securityweek.com/zimbra-patches-c...
Listen
Watch
Mark as Played
1. Langflow authorization bypass on KEV, plus the first fully autonomous LLM-driven ransomware campaign — CVE-2026-55255, CVE-2025-3248 — CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog · Dark Reading https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
2. Adobe ColdFusion path traversal added to KEV, actively exploited — CVE...
Listen
Watch
Mark as Played
1. Initial access broker weaponizing CitrixBleed 2 to deploy Dragonforce ransomware — CVE-2025-5777 (referencing CVE-2023-4966, CVE-2026-4368) — Huntress — https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
2. Django SQL injection actively exploited in GeoDjango deployments — CVE-2026-1207 — Cyber Security News — https://cybersecuritynews.com/django-sql-injection-vulner...
Listen
Watch
Mark as Played
Apologies for the dog barking.  She was mad that she had not yet received her morning allotment of cheese.

1. Microsoft patches the RoguePlanet Defender zero-day after a month of public exploit code — CVE-2026-50656 (related: CVE-2026-33825, CVE-2026-41091, CVE-2026-45498) — BleepingComputer https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/ · Secur...
Listen
Watch
Mark as Played
1. CISA adds ColdFusion, Langflow, and two Joomla plugins to KEV — patch by Friday — CVE-2026-48282, CVE-2026-55255, CVE-2026-48908, CVE-2026-56290 — CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog · BleepingComputer: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/ · SecurityWeek: https://www.securityweek.com/cisa-u...
Listen
Watch
Mark as Played
1. BeyondTrust patches critical auth-bypass flaws in Remote Support and Privileged Remote Access — CVE-2026-40138, CVE-2026-40139 — BleepingComputer — https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critical-flaws-in-remote-access-software/
2. Fake Microsoft Teams IT-support calls deliver EtherRAT malware — no CVE (technique; Unit 42 / Palo Alto Networks) — BleepingComput...
Listen
Watch
Mark as Played
1. Attackers phishing Microsoft's device-code login flow — no CVE (flow abuse) — Securelist (Kaspersky) — https://securelist.com/microsoft-device-code-phishing-attack/120350/
2. Unauthenticated PHP-FPM crash via TLS stream wrapper — CVE-2026-12184 — Cyber Security News — https://cybersecuritynews.com/multiple-php-vulnerabilities-dos/
3. ModSecurity WAF input-inspection bypass bugs &mda...
Listen
Watch
Mark as Played

Popular Podcasts

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

    Hey Jonas!

    Hey Jonas! The official Jonas Brothers podcast. Hosted by Kevin, Joe, and Nick Jonas. It’s the Jonas Brothers you know... musicians, actors, and well, yes, brothers. Now, they’re sharing another side of themselves in the playful, intimate, and irreverent way only they can. Spend time with the Jonas Brothers here and stay a little bit longer for deep conversations like never before.

    Betrayal Weekly

    Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.

    Stuff You Should Know

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    Crime Junkie

    Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by Audiochuck Media Company.

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices