The Defensive Line Podcast
Story 1: Developer Supply Chains Under Sustained Assault * OX Security — TeamPCP / GitHub breach [https://www.ox.security/blog/teampcp-strikes-again-how-a-trojan-vs-code-extension-brought-down-github/] * StepSecurity — Nx Console VS Code extension [https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised] * GitHub Security Blog — Investigating unauthorised access [https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/] * SafeDep — Megalodon mass GitHub repo backdooring [https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows] * StepSecurity — Megalodon CI/CD secrets exfiltration [https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories] * Aikido Security — Laravel-Lang supply chain attack [https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer] * Snyk — Laravel-Lang supply chain advisory [https://snyk.io/blog/laravel-lang-supply-chain-advisory/] * The Hacker News — Packagist supply chain attack [https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html] * Socket — TrapDoor cross-ecosystem campaign [https://socket.dev/blog/trapdoor-crypto-stealer-supply-chain-attack] Story 2: Kali365 — FBI Warns of oh-auth Token Theft Platform * FBI IC3 Public Service Announcement [https://www.ic3.gov/PSA/2026/PSA260521] * Arctic Wolf — Kali365 token and session theft [https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/] * The Record — FBI warns of Kali365 [https://therecord.media/fbi-warns-of-kali365-phishing-attacks] * Microsoft — Protect against consent phishing [https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/protect-against-consent-phishing] * Microsoft — Configure user consent [https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent] * Microsoft — Block device-code flow with Conditional Access [https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows] Story 3: A Zombie Account Hands Over the Water Supply * The Register — Zombie user account let hackers control the city’s water [https://www.theregister.com/security/2026/05/21/zombie-user-account-let-hackers-control-the-citys-water/5243724] Honourable Mentions * Check Point Research — Nimbus Manticore operations during the Iranian conflict [https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/] * Microsoft Security Blog — Fox Tempest malware-signing service [https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/] * Malwarebytes — NYC Health + Hospitals breach [https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach] * Aikido Security — Google API key 23-minute deletion window [https://www.aikido.dev/blog/vs-code-extension-github-breach] * MSRC — Microsoft Defender CVE-2026-41091 [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091] * Dark Reading — Microsoft Exchange OWA zero-day [https://www.darkreading.com/application-security/microsoft-exchange-zero-day-under-attack-no-patch-available] This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com [https://thedefensiveline.substack.com?utm_medium=podcast&utm_campaign=CTA_1]
21 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de The Defensive Line Podcast!