The Defensive Line Podcast
Story 1: Vercel Breached via AI Tool OAuth Token Sprawl * Vercel Security Bulletin [https://vercel.com/kb/bulletin/vercel-april-2026-security-incident] * Hudson Rock / InfoStealers [https://www.infostealers.com/blog/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai] * The Register [https://www.theregister.com/2026/04/20/vercel_context_ai_security_incident/] * Push Security [https://pushsecurity.com/blog/unpacking-the-vercel-breach/] * Varonis [https://www.varonis.com/blog/vercel-breach-2026] Story 2: BlackFile Extortion Targets Retail and Hospitality * RH-ISAC / Unit 42 Joint Report [https://rhisac.org/threat-intelligence/extortion-in-the-enterprise-defending-against-blackfile-attacks/] * BleepingComputer [https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/] Story 3: The Gentlemen Ransomware Scales Fast * Check Point Research [https://blog.checkpoint.com/research/the-gentlemen-a-new-ransomware-threat-climbing-the-charts-fast/] * BleepingComputer [https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/] * The Hacker News [https://thehackernews.com/2026/04/systembc-c2-server-reveals-1570-victims.html] Honourable Mentions Bitwarden CLI / TeamPCP Supply Chain * Socket [https://socket.dev/blog/bitwarden-cli-compromised] * BleepingComputer [https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/] * The Hacker News [https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html] China-Nexus Covert Networks Advisory * NCSC Advisory [https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices] * NCSC CEO Keynote — CyberUK 2026 [https://www.ncsc.gov.uk/speech/ncsc-ceo-keynote-speech-cyberuk-2026] Kyber Post-Quantum Ransomware * Rapid7 [https://www.rapid7.com] NCSC Passkeys Endorsement * NCSC [https://www.ncsc.gov.uk] Vulnerability Roundup * CVE-2026-33825 (Microsoft Windows Defender) — actively exploited * CVE-2026-33626 (LMDeploy) — exploited within 12 hours of advisory * Cisco Catalyst SD-WAN Manager — actively exploited 📰 Full written edition: https://thedefensiveline.substack.com/p/the-defensive-line-weekly-18-1926 [https://thedefensiveline.substack.com/p/the-defensive-line-weekly-18-1926] 📬 Subscribe to The Defensive Line on Substack for weekly actionable security intelligence, written for and by blue teamers. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com [https://thedefensiveline.substack.com?utm_medium=podcast&utm_campaign=CTA_1]
22 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de The Defensive Line Podcast!