The Defensive Line Podcast
The Defensive Line Weekly is a podcast version of our weekly Substack intelligence summary — the security stories that matter most for blue teamers and security leaders, with clear implications and practical defensive actions. AI voices are used, but the content is human curated and written with the support of AI. Topic 1: Helpdesk Impersonation Continues to Succeed * CrowdStrike — Cordial Spider adversary profile [https://www.crowdstrike.com/en-us/adversaries/cordial-spider/] * CrowdStrike — Snarky Spider adversary profile [https://www.crowdstrike.com/en-us/adversaries/snarky-spider/] * Google / Mandiant GTIG — Expansion of ShinyHunters SaaS data theft [https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft] * Unit 42 / RH-ISAC — Extortion in the enterprise: defending against BlackFile attacks [https://rhisac.org/threat-intelligence/extortion-in-the-enterprise-defending-against-blackfile-attacks/] * CyberScoop — CrowdStrike names Cordial Spider and Snarky Spider [https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/] Topic 2: cPanel & WHM and CopyFail cPanel / WHM CVE-2026-41940 * watchTowr Labs — cPanel WHM authentication bypass [https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/] * cPanel vendor advisory — 28 April 2026 [https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026] * Censys — The cPanel situation [https://censys.com/blog/the-cpanel-situation-is/] * Help Net Security — cPanel zero-day exploited [https://www.helpnetsecurity.com/2026/04/30/cpanel-zero-day-vulnerability-cve-2026-41940-exploited/] * Rapid7 — CVE-2026-41940 ETR [https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/] CopyFail CVE-2026-31431 * Wiz Research — CopyFail Linux privilege escalation [https://www.wiz.io/blog/copyfail-cve-2026-31431-linux-privilege-escalation-vulnerability] * Ubuntu security advisory [https://ubuntu.com/security/CVE-2026-31431] * AlmaLinux blog [https://almalinux.org/blog/2026-05-01-cve-2026-31431-copy-fail/] * Red Hat CVE advisory [https://access.redhat.com/security/cve/cve-2026-31431] * Microsoft Security Blog — CopyFail cloud and Kubernetes impact [https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/] * CERT-EU SA 2026-005 [https://cert.europa.eu/publications/security-advisories/2026-005/] Topic 3: Three Supply Chain Attacks in One Week * SentinelOne — Week 18 supply chain roundup [https://blog.sentinelone.com/the-good-the-bad-and-the-ugly-in-cybersecurity-week-18/] * Aikido Security — PyTorch Lightning PyPI compromise [https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud] * Socket — PyTorch Lightning compromised [https://socket.dev/blog/lightning-pypi-package-compromised] * The Hacker News — Poisoned Ruby gems and Go modules [https://thehackernews.com/2026/05/poisoned-ruby-gems-and-go-modules.html] * The Hacker News — PyTorch Lightning supply chain [https://thehackernews.com/2026/04/pylib-poisoned-supply-chain.html] * The Register — SAP npm supply chain [https://www.theregister.com/2026/04/30/supply_chain_attacks_sap_npm/] Honourable Mentions * TRM Labs — North Korea 2026 crypto theft [https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks] * Arctic Wolf — BlueNoroff ClickFix and AI-generated Zoom lures [https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/] * NCSC — AI-driven patch wave warning [https://www.ncsc.gov.uk/] * Fortinet PSIRT FG-IR-26-100 [https://fortiguard.fortinet.com/psirt/FG-IR-26-100] * Fortinet PSIRT FG-IR-26-112 [https://fortiguard.fortinet.com/psirt/FG-IR-26-112] * The Register — Gemini CLI critical RCE [https://www.theregister.com/2026/04/30/gemini_cli_critical_rce/] This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com [https://thedefensiveline.substack.com?utm_medium=podcast&utm_campaign=CTA_1]
21 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de The Defensive Line Podcast!