The Defensive Line Podcast
Gogs unpatched remote code execution * Rapid7 [https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/] * BleepingComputer [https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/] * SecurityWeek [https://www.securityweek.com/gogs-zero-day-exposes-servers-to-remote-code-execution/] ShinyHunters: Charter and Carnival * BleepingComputer — Charter [https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/] * BleepingComputer — Carnival [https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/] * The Record [https://therecord.media/cruise-giant-carnival-confirms-data-breach] * Carnival Corporation notice [https://www.carnivalcorp.com/wp-content/uploads/2026/05/Website-Notice-Substitute-Notice-05.27.26.pdf] FBI warning: Silent Ransom Group * FBI IC3 Advisory [https://www.ic3.gov/CSA/2026/260526.pdf] * The Record [https://therecord.media/fbi-warns-hackers-visit-law-firms-to-steal-data] * SecurityWeek [https://www.securityweek.com/fbi-hackers-sending-operatives-in-person-to-insert-usb-drives-and-steal-data/] * CyberScoop [https://cyberscoop.com/fbi-warning-silent-ransom-group-law-firms/] Honourable mentions * Palo Alto GlobalProtect: Rapid7 [https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/], Palo Alto Networks advisory [https://security.paloaltonetworks.com/CVE-2026-0257], CISA KEV [https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-0257] * ChatGPT share links: Push Security [https://pushsecurity.com/blog/llmshare-malvertising-campaign], BleepingComputer [https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/] * GREYVIBE: WithSecure Labs [https://labs.withsecure.com/publications/greyvibe], The Hacker News [https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html] * npm supply chain: Microsoft Security Blog [https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/] This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com [https://thedefensiveline.substack.com?utm_medium=podcast&utm_campaign=CTA_1]
21 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de The Defensive Line Podcast!