Signal Check

Episode 52: May 23, 2026

4 min · 23 mei 2026
aflevering Episode 52: May 23, 2026 artwork

Beschrijving

This episode digs into the week's quiet but persistent threats—Linux rootkits, router zero-days, and AI adversarial probing—before covering major incidents including Grafana Labs' GitHub breach and a zero-day exploit in Trend Micro's own security software. Adrian North wraps up with a sobering reminder that even CISA contractors aren't immune to mistakes, as exposed AWS GovCloud credentials sat publicly on GitHub. Stories covered: - ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories (The Hacker News) - https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html - Grafana Labs Security Breach - Hackers Access GitHub and Download Codebase - CyberSecurityNews (CyberSecurityNews) - https://news.google.com/rss/articles/CBMia0FVX3lxTE00aWtyeFl6WE1sS1N0X0JRYkJXQmxvQ1NpYVlSeWZGempNc2RXdlM2TU5pdkh5SDlOVXVLMGRPMXZzU2VIOUFwUFlSNkR2YVpxcEpZdEcxa3Y4TGgzdlk4cnpra1FCbHh4OWhJ0gFwQVVfeXFMT1owNlYwdDNmV0c5bWVlNlJHbDB6TnlNS28xWUZ1RWpsVHpyQTFxWmZzcG9lV3h3RTBTczM1TWJnaW13Qk10RHpfMi1JME9abzh3QnBRdWlWeVk2cHpVLXJxNHlieWhUZTFUR0swWF9rVw?oc=5 - Trend Micro warns of Apex One zero-day exploited in the wild (BleepingComputer) - https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/ - CISA Admin Leaked AWS GovCloud Keys on Github (Krebs on Security) - https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/ - The Best Editor-Approved Memorial Day Deals on Garmin, Coros, and Shokz: Get Hundreds Off Popular Gear for Runners (Runner's World) - https://www.runnersworld.com/gear/a71292623/memorial-day-running-gear-deals-2026/ - Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses (TechCrunch) - https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/

Reacties

0

Wees de eerste die een reactie plaatst

Meld je nu aan en word lid van de Signal Check community!

Probeer gratis

Probeer 14 dagen gratis

€ 9,99 / maand na proefperiode. · Elk moment opzegbaar.

  • Podcasts die je alleen op Podimo hoort
  • 20 uur luisterboeken / maand
  • Gratis podcasts

Alle afleveringen

79 afleveringen

aflevering Episode 82: June 22, 2026 artwork

Episode 82: June 22, 2026

This episode digs into a CISA deadline for a critical Splunk vulnerability that's already being exploited in the wild, a North Korean supply chain attack that poisoned over 140 npm packages, and how a junior hacker used legitimate tools like Tailscale to maintain persistence after losing his primary command server. Adrian breaks down six stories that show how attackers are leveraging trust, timing, and creative tradecraft to stay ahead. Stories covered: - CISA: Splunk Enterprise flaw actively exploited, patch by Sunday (BleepingComputer) - https://www.bleepingcomputer.com/news/security/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday/ - Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/ - Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5 - I Hated Running in the Heat. This Training Switch Led Me to Love It—and Faster Times (Runner's World) - https://www.runnersworld.com/training/a71631076/benefits-track-workouts-in-heat/ - Catching Up With Jimmy Chin: Training for Everest, Time, and His Next Big Project (Climbing Magazine) - https://www.climbing.com/culture-climbing/catching-up-with-jimmy-chin-training-for-everest-time-and-his-next-big-project/ - A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/

22 jun 20266 min
aflevering Episode 81: June 21, 2026 artwork

Episode 81: June 21, 2026

On today's Signal Check, Adrian digs into a North Korean supply chain attack that poisoned over 140 npm packages, an unpatchable iPhone exploit targeting Apple's SecureROM, and a scrappy hacker who kept his operation alive using Tailscale and SSH after losing his C2 server. Plus, millions in Brazil received a mysterious unauthorized emergency alert that nobody can quite explain yet. Stories covered: - Microsoft links Mastra AI supply chain attack to North Korean hackers (BleepingComputer) - https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/ - Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html - Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline - The Hacker News (The Hacker News) - https://news.google.com/rss/articles/CBMie0FVX3lxTFBNOXBPUEVoeE5CZl82WmNsVTRUMGY0LVJlMXMxZ3NJYnNuV1Y0MlFRY2pReHl1b2UwWVVENTRBeURnVlFpRmh0eEFzNEJUYkNNZ2IyNlRGOFRsMWJ0aTk1aFhfQURpb2ptVlh2N0hnYktPb2dwNGVMTWNZQQ?oc=5 - Unauthorized alert sent to cell phones across Brazil (Hacker News) - https://www.cnn.com/2026/06/20/americas/brazil-hackers-unauthorized-alert-latam - What 50,000 Runners And 76 Studies Teach Us About Racing The NYC Marathon Smarter (Marathon Handbook) - https://marathonhandbook.com/what-50000-runners-and-76-studies-teach-us-about-racing-the-nyc-marathon-smarter/ - The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf

Gisteren6 min
aflevering Episode 80: June 20, 2026 artwork

Episode 80: June 20, 2026

This episode covers critical security patches for NGINX that can't wait until Monday, a messy OAuth breach at Klue that gave hackers direct access to Salesforce data, and an unpatchable exploit in millions of older iPhones that Apple can't fix with software. Adrian walks through what moved overnight and why it matters before the weekend noise kicks in. Stories covered: - F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution (The Hacker News) - https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html - Klue OAuth breach victim list grows as Icarus hackers claim attack (BleepingComputer) - https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ - Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain (The Hacker News) - https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html - I Faded During My First Two Races. This Simple Workout Helped Me Finish the Next One Strong—and Set a PR. (Runner's World) - https://www.runnersworld.com/training/a71631335/fartlek-training-race-stronger/ - A bold satellite rescue mission came together in record time, but will it work? (Ars Technica) - https://arstechnica.com/space/2026/06/a-bold-satellite-rescue-mission-came-together-in-record-time-but-will-it-work/ - The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf

20 jun 20265 min
aflevering Episode 79: June 19, 2026 artwork

Episode 79: June 19, 2026

This episode digs into a patient cryptocurrency clipper campaign running since February, a French attacker who pivoted to legitimate remote tools when their server died, and why Salesforce integrations are becoming a serious supply chain risk. Adrian pulls signal from the noise before the day gets loud. Stories covered: - Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 (The Hacker News) - https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html - Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html - Salesforce Data Thefts Continue via Klue App Compromise (Dark Reading) - https://www.darkreading.com/cyberattacks-data-breaches/salesforce-data-thefts-klue-app-compromise - Shoulder and back exercises to improve your running mechanics (Canadian Running) - https://runningmagazine.ca/sections/training/shoulder-and-back-exercises-to-improve-your-running-mechanics/ - Launch HN: TesterArmy (YC P26) – Agents that test web and mobile apps (Hacker News) - https://tester.army - ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm (Krebs on Security) - https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/

19 jun 20265 min
aflevering Episode 78: June 18, 2026 artwork

Episode 78: June 18, 2026

On today's Signal Check, Adrian North walks through six morning signals including the UK's controversial ID-based age verification law for social media, a sophisticated Android banking trojan called Rokarolla targeting hundreds of apps, and a French cyberattack that used legitimate IT tools to maintain persistent access. It's a sharp look at what moved overnight before the inbox explodes. Stories covered: - UK to require ID or face scan before you can make social media accounts (BleepingComputer) - https://www.bleepingcomputer.com/news/security/uk-to-require-id-or-face-scan-before-you-can-make-social-media-accounts/ - New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds (The Hacker News) - https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html - Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline (The Hacker News) - https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html - The Performance Booster That Could Help You Push Through Fatigue—If Your Stomach Can Handle It (Runner's World) - https://www.runnersworld.com/nutrition-weight-loss/a71606411/sodium-bicarbonate-runners-performance/ - European Champion Ciara Mageean Says She Will “Fit as Much Living” Into the Years She Has Left (Marathon Handbook) - https://marathonhandbook.com/european-champion-ciara-mageean-says-she-will-fit-as-much-living-into-the-years-she-has-left/ - The Free and Open Web Is Under Attack at the IETF (EFF) - https://www.eff.org/deeplinks/2026/06/free-and-open-web-under-attack-ietf

18 jun 20265 min