Cybersecurity Daily: News & Threats
(00:00:00) Three Microsoft Flaws, Drupal RCE & Iran Wiper Escalation | This Week's Threats (00:01:01) Exchange XSS Now Weaponized (00:01:30) Drupal PostgreSQL RCE Flaw (00:02:11) CISA KEV Legacy Flaws (00:02:44) Iran-Linked Wiper Attacks Escalate (00:03:21) ShinyHunters Telus Breach Three Microsoft vulnerabilities are under active exploitation this week, and the story is bigger than the individual CVEs. A critical remote code execution flaw in Microsoft Defender scores 8.1, flanked by two privilege escalation bugs — all three confirmed exploited in the wild. The same week, the Exchange Server cross-site scripting flaw CVE-2026-42897 was added to the CISA Known Exploited Vulnerabilities catalog with a federal remediation deadline. Three Microsoft flaws, one week. The pattern matters. On the web infrastructure front, Drupal issued an emergency patch for CVE-2026-9082, a SQL injection vulnerability in the PostgreSQL layer that requires zero authentication and already has a public proof-of-concept. Every PostgreSQL-backed Drupal installation — government portals, shared hosting, content platforms — is in scope until patched. CISA also added four legacy flaws dating back to 2008–2010 to its KEV catalog, including Internet Explorer RCE and Windows RPC vulnerabilities. Federal agencies have until June 3 to remediate. Vulnerability debt doesn't expire. On the threat actor front, the Iranian-linked Handala group claims a destructive wiper attack against medical device manufacturer Stryker, asserting 50 TB stolen and disruption across 79 countries — consistent with a U.S. intelligence warning of elevated Iranian cyber activity. Separately, ShinyHunters claimed a 1-petabyte breach of Telus Digital with a $65 million extortion demand. This episode covers all six stories with the technical context security professionals need and the accessible framing that keeps everyone else current. This episode includes AI-generated content.
33 Folgen
Kommentare
0Sei die erste Person, die kommentiert
Melde dich jetzt an und werde Teil der Cybersecurity Daily: News & Threats-Community!