Signal Check

Episode 60: May 31, 2026

5 min · 31. Mai 2026
Episode Episode 60: May 31, 2026 Cover

Beschreibung

This episode covers critical vulnerabilities hitting Gogs self-hosted Git servers, Palo Alto VPN authentication bypass being actively exploited, and a groundbreaking attack where threat actors deployed an AI agent to autonomously handle post-exploitation. We also dig into a new Linux kernel privilege escalation flaw and what it means when your VPN becomes the weakest link. Stories covered: - Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code (The Hacker News) - https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html - Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/ - Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit (The Hacker News) - https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html - New CIFSwitch Linux flaw gives root on multiple distributions (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/ - 13 Indy Trail Races With Views and Vibes That Will Blow You Away (Trail Runner Mag) - https://www.trailrunnermag.com/travel/race-guides/best-indy-trail-races-in-the-us/ - Tyler Andrews Sets Oxygen-Assisted Speed Record on Mount Everest (iRunFar) - https://www.irunfar.com/tyler-andrews-mount-everest-speed-record-2026

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Signal Check-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar.

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

67 Folgen

Episode Episode 70: June 10, 2026 Cover

Episode 70: June 10, 2026

This episode covers a critical Check Point VPN flaw being actively exploited by ransomware groups, a wild new browser-based attack that uses your SSD to spy on your activity, and a must-patch Veeam vulnerability that lets any domain user compromise your backup infrastructure. Adrian also digs into surprising running science that shows walking breaks can actually make you faster. It's threat intel, hardware side-channels, and a dash of endurance strategy before your second cup of coffee. Stories covered: - CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/ - New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing (The Hacker News) - https://thehackernews.com/2026/06/new-frost-attack-lets-websites-track.html - Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code (The Hacker News) - https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html - Walking Breaks Can Make You a Faster and Better Runner. We Can Prove It. (Runner's World) - https://www.runnersworld.com/training/a70690471/walking-break-can-make-you-faster/ - 4 Tactics and 14 Organizations to Support LGBTQ+ Climbers This Pride Month (Climbing Magazine) - https://www.climbing.com/culture-climbing/support-lgbtq-climbers-pride-month/ - COROS Watches Now Talk to AllTrails, Giving Trail Runners One Map for the Backcountry (Marathon Handbook) - https://marathonhandbook.com/coros-watches-now-talk-to-alltrails-giving-trail-runners-one-map-for-the-backcountry/

10. Juni 20265 min
Episode Episode 69: June 09, 2026 Cover

Episode 69: June 09, 2026

This episode covers emergency patches for a critical Check Point VPN zero-day that's been exploited by ransomware groups since early May, plus a Python supply-chain attack that compromised nineteen packages on PyPI. Adrian breaks down why patching isn't enough when attackers have already had weeks inside networks, and how developer trust becomes the vulnerability in these campaigns. Stories covered: - Check Point VPN Flaw Exploited Since Early May (Dark Reading) - https://www.darkreading.com/vulnerabilities-threats/check-point-vpn-flaw-exploited-early-may - Check Point links VPN zero-day attacks to Qilin ransomware gang (BleepingComputer) - https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/ - New Shai-Hulud attack trojanizes 19 science-focused PyPI packages (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-shai-hulud-attack-trojanizes-19-science-focused-pypi-packages/ - UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (The Hacker News) - https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html - ‘I’m a 75-Year-Old Grandmother of Six and Just Ran a 3:57 Marathon. This Is How I Train’ (Runner's World) - https://www.runnersworld.com/training/a71523801/penny-jarvis-runner/ - Surveillance Is Not Safety: A statement on the UK's latest threat to privacy [pdf] (Hacker News) - https://signal.org/blog/pdfs/2026-06-08-uk-surveillance-is-not-safety.pdf

Gestern6 min
Episode Episode 68: June 08, 2026 Cover

Episode 68: June 08, 2026

This episode digs into the worst security breaches of 2026 so far, from compromised critical infrastructure to a hacked FBI surveillance system. Adrian also covers World Cup scammers flooding the web with fake ticket sites and a freshly exploited SolarWinds vulnerability causing server crashes across government and enterprise networks. Stories covered: - Hacked, leaked, and held for ransom: the worst breaches of 2026 so far (TechCrunch) - https://techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/ - FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html - CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/ - Cisco warns of unpatched SD-WAN zero-day exploited in attacks (BleepingComputer) - https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/ - This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/ - Rory Linkletter Trades the Road for His Trail Running Debut (Marathon Handbook) - https://marathonhandbook.com/rory-linkletter-trades-the-road-for-a-mountain/

8. Juni 20266 min
Episode Episode 67: June 07, 2026 Cover

Episode 67: June 07, 2026

This episode digs into Arabic-targeted Android spyware disguised as news apps, a massive npm supply chain attack distributing Rust-based malware to developers, and how hackers reportedly hijacked high-profile Instagram accounts using Meta's own AI support bot. Adrian North walks through the weekend's most critical signals before the world fully wakes up. It's your Sunday morning threat briefing with coffee in hand. Stories covered: - Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps (The Hacker News) - https://thehackernews.com/2026/06/android-spyware-asin-targets-arabic.html - IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks (The Hacker News) - https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html - Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts (Krebs on Security) - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/ - This High School Star Just Ran the 3rd Fastest Prep Mile Ever—and Even Beat the Pros (Runner's World) - https://www.runnersworld.com/news/a71508401/ellery-lincoln-hoka-festival-of-miles/ - What to Do if Your Trail Dog is Obsessed With Wildlife (Trail Runner Mag) - https://www.trailrunnermag.com/people/culture-people/what-to-do-if-your-trail-dog-is-obsessed-with-wildlife/ - Pentagon raised threat of Israeli spying on U.S. to highest level, sources say (Hacker News) - https://www.nbcnews.com/politics/national-security/pentagon-raised-threat-israeli-spying-us-highest-level-sources-say-rcna348565

7. Juni 20266 min
Episode Episode 66: June 06, 2026 Cover

Episode 66: June 06, 2026

This episode covers six critical cybersecurity signals, from World Cup scam operations already in overdrive to the disturbing rise of in-person social engineering attacks where ransomware crews literally walk into offices. Adrian unpacks why the browser has become the new security perimeter and what that means for anyone who thinks their defenses are still holding. Stories covered: - FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins (The Hacker News) - https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html - What 2026 DBIR Confirms: Attacks Are Living in the Browser (BleepingComputer) - https://www.bleepingcomputer.com/news/security/what-2026-dbir-confirms-attacks-are-living-in-the-browser/ - Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person (TechCrunch) - https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/ - Best Running Shoes, Tested and Reviewed (2026): Saucony, Adidas, Hoka (Wired) - https://www.wired.com/gallery/best-running-shoes/ - pg_durable: Microsoft open sources in-database durable execution (Hacker News) - https://github.com/microsoft/pg_durable - The saga of the International Space Station air leak took a worrying turn Friday (Ars Technica) - https://arstechnica.com/space/2026/06/work-on-russias-leaky-space-station-module-causes-astronauts-to-take-shelter/

6. Juni 20266 min