Weekly CYBER NEWS

Cyber Threat Weekly: Water Plant Hacks, Linux Root Exploits & AI Agent Takeovers

5 min · 10. touko 2026
jakson Cyber Threat Weekly: Water Plant Hacks, Linux Root Exploits & AI Agent Takeovers kansikuva

Kuvaus

This week on the podcast, we break down the cyberattacks targeting critical infrastructure in Poland, a dangerous new Linux “Dirty Frag” privilege escalation exploit, and the latest Ivanti zero-day already being exploited in the wild. We also cover the Quasar Linux RAT targeting developer credentials for software supply chain attacks, the alleged Trellix source code breach, and a new Claude browser extension vulnerability exposing AI agents to takeover. If you want the biggest cybersecurity stories explained clearly and fast, this episode covers what defenders need to know right now.

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Weekly CYBER NEWS-yhteisöön!

Aloita maksutta

14 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

50 jaksot

jakson Cybersecurity Daily: OpenAI Supply Chain Scare, Adobe Zero-Day, Marimo RCE Exploits & APT37 Social Engineering (April 2026) kansikuva

Cybersecurity Daily: OpenAI Supply Chain Scare, Adobe Zero-Day, Marimo RCE Exploits & APT37 Social Engineering (April 2026)

In today’s Cybersecurity Daily, we break down the most critical cyber threats impacting April 2026. OpenAI revokes its macOS signing certificate after the Axios supply chain compromise exposed risks to software-signing pipelines, highlighting how deeply modern attacks can reach into trusted development workflows. We also cover an actively exploited Adobe Acrobat Reader vulnerability (CVE-2026-34621) that enables remote code execution through malicious PDFs, alongside a rapidly exploited Marimo pre-auth RCE flaw where attackers began harvesting secrets within hours of disclosure. On the threat actor side, we analyze North Korea’s APT37 campaign, using Facebook, Messenger, and Telegram to deliver RokRAT malware through a trojanized PDF viewer—showing how social engineering is evolving into long-term trust-based intrusion. Plus, a CPUID supply chain attack distributing malware via CPU-Z and HWMonitor downloads, reinforcing that even official download sources can no longer be fully trusted. The key takeaway: trust is now the primary attack surface—from code signing to social platforms to software distribution.

13. huhti 20265 min