Mato
ShowsHow it worksAI talentsFree toolsPricing
Book a demo
ShowsHow it worksAI talentsFree toolsPricingSign in
Mato
Mato

The first generation of AI talents. Live AI media for brands, networks and creators.

ElevenLabs GrantsAWS ActivateGoogle for StartupsNVIDIA Inception Program

Product

  • How it works
  • AI talents
  • Documentation
  • The studio
  • Pricing
  • Embed player
  • Mato MCP
  • Mato Voice
  • Voice Studio
  • Changelog

Company

  • About
  • Vision
  • Partners
  • Affiliates
  • Blog
  • CustomersComing soon
  • CareersComing soon
  • Press kit
  • Contact

Resources

  • Investor overview
  • Free podcast tools
  • Free podcast transcription
  • Podcast ROI calculator
  • API docsComing soon
  • SecurityComing soon
  • StatusComing soon

© 2026 Mato. All rights reserved.

English · Multiple languages available

PrivacyTerms

Live Interview

And why does that matter?

This is how a Mato agent talks. Take the other seat: answer a few and feel it follow the thread.

Try it yourself

Podcast charts

Cyber Threat Brief

Published by Carolina Clear Tech, LLC

  • Technology
  • News
  • Tech news

Your daily cybersecurity briefing. Vulnerabilities, ransomware, threat actors, and patches that matter, explained for IT professionals and business leaders protecting small and mid-sized organizations. From Carolina Clear Tech.

Listen on Apple Podcasts, opens in a new tabMake something like it

On the charts

1 chart placement

Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.

  1. Number 194TechnologyAustralia

From the feed

Recent episodes

The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.

  1. 2026-09-20: ShinyHunters breached Clop's leak site using a Grav CMS exploit from Cyber Threat Brief, opens in a new tab

    Sep 20, 20267 min

    Show Notes - 2026-09-20 Stories Covered: - Today: - SolarWinds Access Rights Manager Hard-Coded Key Vulnerability (CVE-2026-28326) (https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html) - ShinyHunters Breaches Clop Ransomware Gang's Leak Site (https://databreaches.net/2026/09/19/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/) - Spirals Ransomware Claims Healthcare and Federal ITAD Targets (https://www.ransomlook.io/group/spirals) - Researchers Chain Vulnerabilities to Compromise OpenAI Staff Accounts (CVE-2026-32882) (https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html) - National Cancer Centre Email Exposure (https://databreaches.net/2026/09/19/national-cancer-centre-e-mail-lapse-allegedly-exposes-patients-details/) - Google Gemini Autonomously Hacked Three Companies in Security Test (https://databreaches.net/2026/09/19/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai/) - SolarWinds Web Help Desk Multiple Vulnerabilities (https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html) - SolarWinds Serv-U 16 Vulnerabilities (https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html) CVEs Referenced: CVE-2026-28299, CVE-2026-28302, CVE-2026-28304, CVE-2026-28317, CVE-2026-28321, CVE-2026-28323, CVE-2026-28326, CVE-2026-32882 Full brief: https://carolinacleartech.com/brief/2026-09-20/

  2. 2026-09-19: Cisco patched a maximum-severity zero-day in Identity Services Engine under active exploitation from Cyber Threat Brief, opens in a new tab

    Sep 19, 202618 min

    Show Notes - 2026-09-19 Stories Covered: - Today: - Cisco ISE Authentication Bypass Zero-Day (CVE-2026-76460) (https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues) - Three Linux Kernel Flaws Exploited in the Wild (https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html) - Orkes Conductor Pre-Auth RCE Exploited (CVE-2026-58138) (https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html) - Ransomware Developer Sentenced to 13 Years in Switzerland (https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/) - Kansas County Hit by Ransomware (https://databreaches.net/2026/09/18/ransomware-attack-on-kansas-county-will-affect-some-services/) - TanStack npm Supply Chain Attack Reached CrowdSec, Mistral, OpenAI (https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html) - Abandoned CDN Domain Re-Registered, Thousands of Sites Still Reference It (https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html) - Foreign Actors Breach Two Colorado Water Utilities (https://databreaches.net/2026/09/18/foreign-actors-breach-colorado-water-systems/) - North Korea Fake Job Interview Campaign Infected 30,000 Devices (https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461) - Plugin4Shell Affects Four AI Coding Agents (https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html) - Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw (https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html) - Windows 11 26H1 Out-of-Band Updates (https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html) - MFA Does Not Stop OAuth Consent Abuse (https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse) - Google Gemini Broke Into Real Company Systems During Security Test (https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html) - AI Agent Incidents Continue (https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html) - AWS AgentCore Harness Credential Exposure (https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/) - Transparent Tribe Deploys Rust Backdoor Using GitHub for C2 (https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html) - FBI: Government Impersonation Scams Cost $1.6B (https://www.theregister.com/cyber-crime/2026/09/18/fbi-fake-cop-and-government-impersonation-scams-cost-victims-16b/5297499) - Four Linux Kernel Local Privilege Escalation Flaws (https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html) - WordPress Click2Shell Flaw (https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html) - SAP Critical Vulnerability (https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/) - Microsoft Edge CVE-2026-88097 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097) CVEs Referenced: CVE-2025-39682, CVE-2025-39964, CVE-2026-20129, CVE-2026-20223, CVE-2026-44756, CVE-2026-45321, CVE-2026-53266, CVE-2026-58138, CVE-2026-62721, CVE-2026-68121, CVE-2026-74469, CVE-2026-76460, CVE-2026-80844, CVE-2026-81000, CVE-2026-85878, CVE-2026-85885, CVE-2026-85889, CVE-2026-85921, CVE-2026-87701, CVE-2026-88097 Full brief: https://carolinacleartech.com/brief/2026-09-19/

  3. 2026-09-18: Cisco disclosed a second actively exploited zero-day this week, CVE-2026-76460 from Cyber Threat Brief, opens in a new tab

    Sep 18, 202615 min

    Show Notes - 2026-09-18 Stories Covered: - Today: - Cisco ISE Authentication Bypass Zero-Day (CVE-2026-76460, CVSS 10.0) (https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html) - Cisco ISE Additional Critical Flaws (CVE-2026-76423, CVSS 10.0 and 26 more CVEs) (https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html) - Orkes Conductor RCE Under Active Exploitation (CVE-2026-58138, CVSS 9.8) (https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/) - AI-Powered Ransomware Operations Maturing (https://research.checkpoint.com/2026/ai-threat-landscape-digest-july-august-2026/) - Navigate360 Breach -- 8.3M Anonymous Tips Exposed (https://databreaches.net/2026/09/17/navigate360-may-soon-release-a-public-notice-about-its-horrific-breach-but-will-any-individuals-be-notified/) - Cisco ISE Exploitation Indicators (https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html) - HEAVYGRAM Telegram Backdoor (Iran/Handala Hack) (https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html) - Brevo Supply Chain Attack -- 100,000+ Websites Compromised (https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/) - Check Point Security Management RCE (CVE-2026-91843, CVSS 9.8) (https://thehackernews.com/2026/09/critical-check-point-management-server.html) - Gyazo Breach -- 23.6M User Records and 490M Image Metadata Records (https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html) - Microsoft Secure Now -- AI-Era Exposure Management (https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/) - Microsoft Cloud/Azure CVEs (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55946) - Exposed LocalAI Instances Compromised at Scale (https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html) - Docker Sandboxes VM Escape on macOS (CVE-2026-77179, Critical) (https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html) - Port of Los Angeles Blocked 120M Attacks in August (https://databreaches.net/2026/09/17/port-of-la-fended-off-120-million-cyberattacks-in-august/) - BIND 9 -- 14 Security Flaws (ISC) (https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html) - Unbound DNS -- Critical DNSSEC Heap Overflow (CVE-2026-81642, CVSS 9.1) (https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html) - ICS Advisories -- CISA (https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06) CVEs Referenced: CVE-2025-6625, CVE-2026-0899, CVE-2026-13336, CVE-2026-13337, CVE-2026-13348, CVE-2026-15688, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-31431, CVE-2026-55946, CVE-2026-58138, CVE-2026-68791, CVE-2026-69865, CVE-2026-70009, CVE-2026-76163, CVE-2026-76423, CVE-2026-76424, CVE-2026-76460, CVE-2026-76461, CVE-2026-77179, CVE-2026-77692, CVE-2026-81642, CVE-2026-82717, CVE-2026-83946, CVE-2026-86520, CVE-2026-91843 Indicators of Compromise: IPs: 3.2.4.1 Full brief: https://carolinacleartech.com/brief/2026-09-18/

  4. 2026-09-17: Cisco ISE has a CVSS 10 authentication bypass zero-day (CVE-2026-76460) under active exploitation from Cyber Threat Brief, opens in a new tab

    Sep 17, 202614 min

    Show Notes - 2026-09-17 Stories Covered: - Today: - Cisco ISE Authentication Bypass Zero-Day (CVE-2026-76460) (https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/) - Google Pixel Modem Zero-Click Privilege Escalation (CVE-2026-58704) (https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html) - Acronis cPanel Backup Plugin Exploited in the Wild (CVE-2026-87886) (https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html) - Issabel PBX Framework Hard-Coded JWT Key RCE (CVE-2026-89026) (https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html) - Ransomware Trends in Japan H1 2026: The Gentlemen, Qilin, and SMB Targeting (https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/) - Nipigon Hospital Ransomware Attack (https://databreaches.net/2026/09/16/canada-nipigon-hospital-hit-by-ransomware-attack/) - AI Coding Assistant Hijacked, Shai-Hulud Worm Spreads Across ~100 Repositories (https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html) - N0va Phishing Kit Targeting US and EU Organizations (https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html) - BragJack: Browser Extensions Hijacking Agentic AI Assistants (CVE-2026-0628, CVE-2026-55945) (https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html) - WordPress The Events Calendar RCE (CVE-2026-78006, CVE-2026-78159) (https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/) - Three Threat Groups Targeting Russian Enterprises via Exchange and Active Directory (https://thehackernews.com/2026/09/three-threat-groups-target-russian.html) - CISA Ends Weekly Vulnerability Bulletin (https://www.theregister.com/security/2026/09/16/cisa-decides-weekly-vulnerability-bulletin-isnt-necessary-anymore/5296968) - CISA Publishes Cyber Decoy Guidance (https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response) - AMOS Stealer Targeting macOS via Fake Toolkit Pages (https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/) - Scans Targeting Hospitality PBX Applications (https://isc.sans.edu/diary/rss/33344) - Treasury Secretary: No Liability Exemptions for AI Labs (https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/) - Parallels Desktop Local Root Escalation (CVE-2026-90894) (https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html) CVEs Referenced: CVE-2019-0708, CVE-2020-0688, CVE-2021-26855, CVE-2026-0628, CVE-2026-42897, CVE-2026-55945, CVE-2026-58704, CVE-2026-76460, CVE-2026-78006, CVE-2026-78159, CVE-2026-87886, CVE-2026-89026, CVE-2026-90894 Indicators of Compromise: Domains: getmacouscloud[.]com, ferncore13[.]com. IPs: 6.17.3.1, 6.17.4.1, 94.102.49.125 Full brief: https://carolinacleartech.com/brief/2026-09-17/

  5. 2026-09-16: Cisco discloses a critical zero-day in Secure Email Gateway already exploited in the wild with from Cyber Threat Brief, opens in a new tab

    Sep 16, 202618 min

    Show Notes - 2026-09-16 Stories Covered: - Today: - Cisco Secure Email Gateway Zero-Day (CVE-2026-76461) (https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/) - WSO2 API Manager JWT Bypass Under Active Exploitation (CVE-2026-5430) (https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-2140/) - Acronis Backup Plugin for cPanel Exploited (CVE-2026-87886) (https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/) - Thai ISP Compromised via Fortinet Vulnerabilities (https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/) - NightEagle APT Targets Russian Companies (https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/) - Healthcare Ransomware Claims (https://databreaches.net/2026/09/15/ransomware-group-claims-attack-on-missouris-cedar-county-memorial-hospital-after-it-outage/) - September Patch Tuesday Emergency Fixes (https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday) - KREMLIN Banking Malware Indicators (https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html) - HEAVYGRAM/CHOSEN BRICK Telegram-Controlled Malware (https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html) - BambooToken MQTT-Based Malware (https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html) - WooCommerce Wholesale Lead Capture Exploitation (CVE-2026-27540) (https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html) - The Events Calendar Critical RCE Flaws (CVE-2026-78159, CVE-2026-78006) (https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html) - ICS/OT Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/) - Apple's Record Patch Release (https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679) - NIST/CISA Token Protection Guidance (https://www.cisa.gov/resources-tools/resources/protecting-tokens-and-assertions-forgery-theft-and-misuse-implementation-recommendations-agencies) - CDM Program Evolution (https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/) CVEs Referenced: CVE-2018-13379, CVE-2020-0688, CVE-2021-22986, CVE-2022-1388, CVE-2022-42475, CVE-2023-27997, CVE-2023-46747, CVE-2024-21762, CVE-2026-27540, CVE-2026-5430, CVE-2026-58113, CVE-2026-73807, CVE-2026-76461, CVE-2026-78006, CVE-2026-78159, CVE-2026-78225, CVE-2026-80465, CVE-2026-81855, CVE-2026-81861, CVE-2026-82567, CVE-2026-87886 Indicators of Compromise: Domains: volmira[.]site, zaviro[.]online., chat5188[.]tk. IPs: 92.241.13.213, 31.59.129.150, 92.241.13.140, 23.137.105.214, 23.180.120.140, 104.194.9.138, 187.75.114.36, 114.10.43.203, 37.114.144.209, 2.0.3.1, 6.17.3.1, 6.17.4.1 Full brief: https://carolinacleartech.com/brief/2026-09-16/

  6. 2026-09-15: Cisco Secure Email Gateway zero-day actively exploited for root command execution from Cyber Threat Brief, opens in a new tab

    Sep 15, 202614 min

    Show Notes - 2026-09-15 Stories Covered: - Today: - Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) (https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/) - GitLab Path Traversal (CVE-2026-85706) (https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk) - Chrome-Windows Zero-Day Chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) (https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html) - Microsoft September Patch Tuesday Zero-Days (CVE-2026-85880, CVE-2026-81963) (https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/) - Cisco Secure Firewall Management Center Exploited by Russia and Cybercriminals (https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/) - MikroTik RouterOS Chain Enables Passwordless SSH and Admin Escalation (https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/) - Large-Scale Fortinet VPN Credential Attacks (https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html) - WordPress Automated Plugin Reviews Block Backdoored Release (https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html) - Microsoft Edge Chromium Updates (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87454) - Windows Secure Kernel Mode Double Free (CVE-2026-85921) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921) - Silent Ransom Group Attacks Greenberg Traurig Law Firm (https://databreaches.net/2026/09/14/silent-ransom-group-hacked-greenberg-traurig-who-notifies-the-126k-affected/) - Monroe School District (Wisconsin) Disrupted by Possible Cyber Incident (https://databreaches.net/2026/09/14/possible-cyber-incident-disrupts-monroe-schools-in-wisconsin/) - Anthropic Claude Models Hacked Real Internet Due to Configuration Failures (https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/) - Check Point Reveals PuzzleMask Plain-Prose Jailbreak Technique (https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/) - DOJ Targets $245M COVID Loan Fraud in Operation No Doze (https://www.justice.gov/opa/pr/dojs-fraud-division-sba-and-sba-oig-target-245m-covid-loan-fraud-enforcement-activity-state) - Data Breaches (https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/) CVEs Referenced: CVE-2026-20079, CVE-2026-20316, CVE-2026-67276, CVE-2026-72898, CVE-2026-76461, CVE-2026-81963, CVE-2026-85046, CVE-2026-85706, CVE-2026-85880, CVE-2026-85921, CVE-2026-86060, CVE-2026-87454, CVE-2026-87491, CVE-2026-87527, CVE-2026-87528, CVE-2026-87632 Full brief: https://carolinacleartech.com/brief/2026-09-15/

  7. 2026-09-14: ConnectWise ScreenConnect faces active worm-like exploitation with CISA adding CVE-2026-84869 to from Cyber Threat Brief, opens in a new tab

    Sep 14, 202610 min

    Show Notes - 2026-09-14 Stories Covered: - Today: - ConnectWise ScreenConnect Vulnerability Exploited in Worm-Like Attacks (CVE-2026-84869) (https://www.securityweek.com/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks/) - Three JFrog Artifactory Flaws Exploited for Backdoor Deployment (https://www.securityweek.com/three-jfrog-artifactory-flaws-exploited-for-backdoor-deployment/) - Passkey-Themed Social Engineering Leads to Microsoft Cloud Account Compromise (https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html) - Malicious Twitch Browser Extension Leaks OAuth Tokens from 31,000 Users (https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html) - Telus Warns Customers of Account Breaches (https://www.securityweek.com/telus-warns-customers-of-account-breaches/) - AT&T Store Worker Sentenced for SIM-Swap Side Hustle (https://databreaches.net/2026/09/13/att-store-worker-gets-16-months-inside-for-sim-swap-side-hustle/) - Anthropic CEO Calls for AI Industry Slowdown (https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/) - Delaware Updates Privacy and Data-Breach Laws (https://databreaches.net/2026/09/13/delaware-consumer-privacy-and-data-breach-law-updates/) - HHS Releases Updated Security Risk Assessment Tool (https://databreaches.net/2026/09/13/hhs-releases-updated-security-risk-assessment-tool-2/) CVEs Referenced: CVE-2026-42016, CVE-2026-42018, CVE-2026-82329, CVE-2026-84869 Full brief: https://carolinacleartech.com/brief/2026-09-14/

  8. 2026-09-13: CISA added five actively exploited flaws to the KEV catalog with patch deadlines through September from Cyber Threat Brief, opens in a new tab

    Sep 13, 202610 min

    Show Notes - 2026-09-13 Stories Covered: - Daily Cybersecurity Brief - September 13, 2026 - Today: - CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog (https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html) - BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) (https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/) - Google Content Removal System Leaked Sex Crime Victim Identities Globally (https://databreaches.net/2026/09/12/not-just-korea-google-leaked-identifying-info-for-sex-crime-victims-across-the-world/) - New York DFS Issues Cybersecurity Risk Assessment Guidance (https://databreaches.net/2026/09/12/nys-dfs-issues-new-cybersecurity-guidance-on-risk-assessments-for-financial-services-entities/) - CVE-2026-42016 - CVE-2026-42018 - CVE-2026-82329 - CVE-2026-84869 - CVE-2026-67277 - CVE-2026-86060 - CVE-2026-85046 - CVE-2026-87491 - CVE-2026-85880 CVEs Referenced: CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-82329, CVE-2026-84869, CVE-2026-85046, CVE-2026-85880, CVE-2026-86060, CVE-2026-87491 Full brief: https://carolinacleartech.com/brief/2026-09-13/

  9. 2026-09-12: Check Point patches four critical VPN flaws including two on CISA's KEV list from Cyber Threat Brief, opens in a new tab

    Sep 12, 202612 min

    Show Notes - 2026-09-12 Stories Covered: - Today: - GitLab CVSS 10 Path Traversal Under Active Exploitation (CVE-2026-85706) (https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html) - Chrome V8 Zero-Day Exploited in the Wild (CVE-2026-87491) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87491) - Check Point VPN Critical Flaws Include Two CISA KEV Entries (CVE-2026-16232, CVE-2026-50751, CVE-2026-85102, CVE-2026-85103) (https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/) - Ukrainian Conti Developer Sentenced to 4 Years (https://www.securityweek.com/ukrainian-conti-ransomware-developer-sentenced-to-4-years-in-us-prison/) - AI-Powered PaperCut Attack Shows Attacker Speed Gains (https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain) - OpenAI Agent Swarm Compromised RubyGems Infrastructure (https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html) - LLM Access Harvesting Operation Uses Autonomous Agent (https://isc.sans.edu/diary/rss/33332) - Endpoint Hardening Gaps Enable Common Intrusions (https://www.huntress.com/blog/endpoint-hardening-best-practices) - CISA Calls for Transparent Breach Communications (https://www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate) - GitLab Multiple Flaws (https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html) - Microsoft Edge and Chromium Updates (https://msrc.microsoft.com/update-guide/) - JFrog Artifactory Under Active Exploitation (https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog) CVEs Referenced: CVE-2026-16232, CVE-2026-19478, CVE-2026-42016, CVE-2026-42018, CVE-2026-50751, CVE-2026-76018, CVE-2026-76019, CVE-2026-76022, CVE-2026-76023, CVE-2026-77490, CVE-2026-84330, CVE-2026-84333, CVE-2026-84869, CVE-2026-85043, CVE-2026-85045, CVE-2026-85052, CVE-2026-85053, CVE-2026-85102, CVE-2026-85103, CVE-2026-85706, CVE-2026-87491, CVE-2026-87719 Full brief: https://carolinacleartech.com/brief/2026-09-12/

  10. 2026-09-11: Cisco firewalls are under attack by state-sponsored groups and Qilin ransomware from Cyber Threat Brief, opens in a new tab

    Sep 11, 202623 min

    Show Notes - 2026-09-11 Stories Covered: - Today: - Cisco FMC Exploited by State-Sponsored Groups and Qilin Ransomware (CVE-2026-20316, CVE-2026-20079) (https://blog.talosintelligence.com/cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy-qilin-ransomware) - PaperCut Attacker Uses AI Agents to Compromise 440+ Instances (CVE-2026-81578, CVE-2026-82078) (https://www.greynoise.io/blog/papercut-attacker-uses-hundreds-of-ai-agents) - Check Point VPN Flaws Enable Unauthenticated RCE (CVE-2026-85102, CVE-2026-85103) (https://supportcontent.checkpoint.com/solutions?id=sk182991) - CISA Adds Four Exploited Vulnerabilities to KEV Catalog (https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Fortinet Flaw Exploited to Deploy PivotC2 RAT (CVE-2025-25249) (https://socradar.io/pivotc2-rat-attacks/) - Conti Ransomware Developer Sentenced to 4 Years (https://cyberscoop.com/conti-ransomware-developer-sentenced/) - Voice Callers Exploit BYOD to Reach Microsoft 365 Corporate Data (https://www.microsoft.com/en-us/security/blog/2026/09/10/voice-callers-exploit-byod-microsoft-365-corporate-data/) - AI-Themed Phishing Campaigns Target ChatGPT, Copilot, DeepSeek, Claude Users (https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/) - Microsoft Promotes AI Invoice Fraud Campaign Using Generative AI (https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/) - JFrog Artifactory Flaws Chained for Admin Takeover (CVE-2026-42018, CVE-2026-42016) (https://www.wiz.io/blog/jfrog-artifactory-vulnerabilities-chained-admin-takeover) - ShieldCrash Bypasses Microsoft Defender Patches (CVE-2026-69414) (https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit) - ShinyHunters Breach McKesson Medical Supplier, Expose 6.4M Records (https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/) - China-Linked UNC3569 Exploited Sogou Input Method for GRAYRABBIT Backdoor (CVE-2021-38003) (https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html) - Trezor and BitBox Targeted in Newsletter Phishing Campaign (https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/) - Citrix NetScaler Authentication Bypass (CVE-2026-19490) (https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/) - AVEVA Pipeline Integrity Monitor ICS Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-253-01) - NextGen Healthcare Mirth Connect Medical Device Flaws (https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01) - Orthanc DICOM Server Heap Overflow (CVE-2026-87020) (https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02) - Google Play Early Access Abused for Deceptive Apps (https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html) - Android Banking Malware Gigabud Uses Work Profiles to Hide (Indonesia) (https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html) CVEs Referenced: CVE-2021-38003, CVE-2025-25249, CVE-2026-19490, CVE-2026-20079, CVE-2026-20316, CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-69414, CVE-2026-78224, CVE-2026-81578, CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824, CVE-2026-82078, CVE-2026-82329, CVE-2026-82578, CVE-2026-82583, CVE-2026-85102, CVE-2026-85103, CVE-2026-86060, CVE-2026-87020 Indicators of Compromise: IPs: 45.142.193.132 Full brief: https://carolinacleartech.com/brief/2026-09-11/

  11. 2026-09-10: Multiple Chinese espionage groups are rapidly exploiting a Chrome/Windows zero-day chain from Cyber Threat Brief, opens in a new tab

    Sep 10, 202619 min

    Show Notes - 2026-09-10 Stories Covered: - Today: - BlueMoon Exploit Chain: Chrome and Windows Zero-Days Under Active Exploitation (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) (https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit) - Cisco Secure Firewall Management Center Under Active Attack (CVE-2026-20079, CVE-2026-20316) (https://blog.talosintelligence.com/fmc-ongoing-exploitation/) - CISA KEV Additions: Four Vulnerabilities with Tight Deadlines (https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog) - Fortinet Flaw Exploited to Deploy PivotC2 RAT (CVE-2025-25249) (https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/) - Qilin Ransomware Affiliate Exploited Cisco FMC (UAT-11988) (https://blog.talosintelligence.com/fmc-ongoing-exploitation/) - Microsoft Defender Zero-Day: ShieldCrash Bypasses September Patches (CVE-2026-69414) (https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/) - Passkey-Themed Social Engineering Leads to Cloud Identity Compromise (https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/) - Infostealer Logs Expose Replayable AI API Keys and Session Tokens (https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html) - LiteLLM Gateways Exposed with Default Admin Key "sk-1234" (CVE-2026-59821) (https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html) - Workflow Identity Hijacking: AI Attack Bypasses Authorization in Enterprise Pipelines (https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data) - ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws (https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/) - Chipmaker Patch Tuesday: Nvidia, AMD, Arm (https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/) - DeepSeek Harness Sandbox Escape (CVE-2026-82533) (https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html) - Alby Hub Bitcoin Wallet Flaw (v1.7.0 - v1.18.5) (https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html) - US Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8M Crypto (https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html) - US Agencies Accuse Chinese AI Firms of Industrial-Scale Model Distillation (https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html) - Anthropic Discloses Fourth AI Hacking Incident (https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html) - EU Cyber Resilience Act Reporting Requirements Begin September 11 (https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements) CVEs Referenced: CVE-2025-25249, CVE-2026-19490, CVE-2026-20079, CVE-2026-20316, CVE-2026-31431, CVE-2026-3869, CVE-2026-43603, CVE-2026-50656, CVE-2026-59821, CVE-2026-69414, CVE-2026-82533, CVE-2026-85046, CVE-2026-85880, CVE-2026-87491 Indicators of Compromise: IPs: 127.0.0.1 Full brief: https://carolinacleartech.com/brief/2026-09-10/

  12. 2026-09-09: Microsoft breaks records with 974 vulnerabilities including two actively exploited zero-days from Cyber Threat Brief, opens in a new tab

    Sep 9, 202620 min

    Show Notes - 2026-09-09 Stories Covered: - Today: - Microsoft Patches Two Actively Exploited Zero-Days Among Record 974 CVEs (https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html) - Chrome 153 Patches Seventh Zero-Day of 2026 (https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html) - N-able N-central Pre-Auth RCE Actively Exploited (https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html) - Adobe Commerce Zero-Day StyleSmuggler Exploited Since September 4 (https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/) - SAP Patches CVSS 10.0 Kernel Flaw OVERPASS (https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html) - 20 Wormable CVEs Create Network Contagion Risk (https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves) - FreeIPA Critical Flaw Chain Enables Admin Credential Creation (https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html) - Multi-Hop Google Redirect Phishing Campaign (https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign) - Microsoft Office Preview Pane Attack Surface (https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/) - Windows Hyper-V Guest-to-Host Escape Flaws (https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/) - Active Directory Rights Management Service (AD RMS) Research (https://www.huntress.com/blog/ad-rms-architecture-and-recon) - Microsoft Defender ShieldBreak Patch Bypass (ShieldCrash) (https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html) - Microsoft September 2026: 974 CVEs (https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html) - Adobe September 2026: 170+ CVEs (https://www.securityweek.com/adobe-patches-over-170-vulnerabilities-including-commerce-zero-day/) CVEs Referenced: CVE-2020-1350, CVE-2026-11645, CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-44756, CVE-2026-48273, CVE-2026-5281, CVE-2026-55007, CVE-2026-58240, CVE-2026-69380, CVE-2026-69414, CVE-2026-69465, CVE-2026-69595, CVE-2026-69676, CVE-2026-69730, CVE-2026-69829, CVE-2026-69845, CVE-2026-72979, CVE-2026-75650, CVE-2026-75746, CVE-2026-76560, CVE-2026-76578, CVE-2026-78510, CVE-2026-80097, CVE-2026-81963, CVE-2026-82004, CVE-2026-85046, CVE-2026-85880, CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, CVE-2026-87491 Full brief: https://carolinacleartech.com/brief/2026-09-09/

  13. 2026-09-08: Google patched a Chrome zero-day already under active exploit from Cyber Threat Brief, opens in a new tab

    Sep 8, 202624 min

    Show Notes - 2026-09-08 Stories Covered: - Today: - Chrome Zero-Day Under Active Exploitation (CVE-2026-85046) (https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html) - Adobe Commerce Zero-Day Deploying Backdoors (CVE-2026-75650) (https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html) - SonicWall SMA Gateways on CISA KEV (CVE-2026-83548, CVE-2026-83549) (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - JFrog Artifactory Authentication Bypass Under Active Exploitation (CVE-2026-82329) (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - N-able N-central Customer Compromise (https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html) - Microsoft 365 Vishing and AitM Token Theft (PREY-0058) (https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html) - ScreenConnect Worm-Like VBScript Chain (https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html) - AI-Assisted Ransomware Intrusion in Under 10 Hours (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - MikroTik RouterOS Zero-Days Exploited (MikroTrick Chain) (https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html) - Telerik UI Padding-Oracle Bug Chained to RCE (https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html) - BigBear 2.0 Phishing-as-a-Service Bypasses MFA at 258 Organizations (https://databreaches.net/2026/09/07/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/) - CrowdStrike Falcon Privilege Escalation on Windows 11 25H2 (FalconFlank) (https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/) - BengalSEO Malware Campaign Delivers MayaBot (https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html) - ClearFake WebDAV Infection Chain Delivers Amatera Stealer (https://blog.talosintelligence.com/clearfake-webdav-infection-chain/) - ClickFix Browser Cryptocurrency Theft via Google Sheets C2 (https://blog.talosintelligence.com/clickfix-moves-into-the-browser/) - North Korean Linux Espionage Toolkit (https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/) - PEEP Post-Compromise Browser Backdoor (https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html) - GitSpawn Vulnerability in AI Coding Agents (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - Avast, Nvidia Zero-Day Exploits Released (https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/) - Thomson Reuters C-Track Breach Affects 11 US States, Canada (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - Baylor Genetics Data Breach Affects 2.8M Patients (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - Dropbox Account Access via Lenovo Email Verification Exploit (https://research.checkpoint.com/2026/7th-september-threat-intelligence-report/) - Liquid Network $320M Bitcoin Theft (https://www.theregister.com/security/2026/09/07/hackers-drain-320m-in-bitcoin-from-liquid-network-claim-theyre-the-good-guys/5294770) - Cloud Misconfiguration Patterns Across AWS, Azure, Google Cloud (https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html) CVEs Referenced: CVE-2019-18935, CVE-2026-13181, CVE-2026-13182, CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-75650, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549, CVE-2026-85046, CVE-2026-86060, CVE-2026-86206, CVE-2026-86207, CVE-2026-86218 Indicators of Compromise: Domains: assignpasskey[.]com, mfaregister[.]com, passkeydeploy[.]com, readthedocs[.]io, github[.]io, 30[.]232, xfjcc[.]fun Full brief: https://carolinacleartech.com/brief/2026-09-08/

  14. 2026-09-07: N-able issued its fourth emergency hotfix in five weeks for a maximum-severity RCE flaw in from Cyber Threat Brief, opens in a new tab

    Sep 7, 202610 min

    Show Notes - 2026-09-07 Stories Covered: - Today: - N-able N-central Unauthenticated RCE (CVE-2026-86218) (https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html) - MikroTik Critical Vulnerability (https://isc.sans.edu/diary/rss/33314) - Four-Year BEC Campaign Nets €35M from French Notaries (https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/) - JetBrains Cadence Cloud Platform Breach (https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/) - $320M Cryptocurrency Heist - Liquid Network (https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/) - JSCeal Malware Campaign via Fake Crypto Sites (https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html) - Two Major US Law Firms Disclose Breaches (https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/) - Roanoke, Virginia Delays Breach Notification Three Months (https://news.risky.biz/risky-bulletin-bec-campaign-steals-eur35-million-from-french-notaries/) - Natural Resources Wales Data Breach (https://databreaches.net/2026/09/06/natural-resources-wales-confirms-data-breach-due-to-human-error/) - US Offers $10M Bounty for Iranian Cyber Official (https://databreaches.net/2026/09/06/us-offers-10-million-for-info-on-iranian-allegedly-behind-cyberattacks-on-critical-infrastructure/) - UK Cybersecurity Bill Excludes Executive Personal Liability (https://www.theregister.com/security/2026/09/07/peers-ask-why-uk-cyber-bill-leaves-execs-off-the-personal-liability-hook/5294586) - CVE-2026-86218 - N-able N-central Static Code Injection (https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html) CVEs Referenced: CVE-2026-18556, CVE-2026-18577, CVE-2026-86218 Full brief: https://carolinacleartech.com/brief/2026-09-07/

  15. 2026-09-06: ShipMonk breach exposes 67,000 Trezor customers via zero-day SQL injection from Cyber Threat Brief, opens in a new tab

    Sep 6, 202612 min

    Show Notes - 2026-09-06 Stories Covered: - Today: - Magento and Adobe Commerce Zero-Day Under Active Exploitation (https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html) - MikroTik Routers Hijacked via Unauthenticated SSH Access (https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html) - FalconFlank Zero-Day Escalates Privileges on CrowdStrike Falcon (https://databreaches.net/2026/09/05/falconflank-zero-day-hits-crowdstrike-falcon-sensor/) - JetBrains Cadence Breached via Unpatched TeamCity Zero-Day (https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html) - Trezor Exposes 67,000 Additional Customers in ShipMonk Breach (https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html) - Elementor Pro WordPress Plugin Exploited Following Patch Release (https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/) - REVSTEALER Modules Disable Windows Update and Defender for Crypto Mining (https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html) - VMware Workstation and Fusion Critical VM Escape Vulnerabilities (https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html) CVEs Referenced: CVE-2026-32475, CVE-2026-59309, CVE-2026-59310, CVE-2026-59346, CVE-2026-59347, CVE-2026-63077, CVE-2026-72898 Full brief: https://carolinacleartech.com/brief/2026-09-06/

  16. 2026-09-05: Google patches its sixth Chrome zero-day of 2026 with a September 18 federal deadline from Cyber Threat Brief, opens in a new tab

    Sep 5, 202614 min

    Show Notes - 2026-09-05 Stories Covered: - Today: - Google Chrome 152 Zero-Day Exploited (CVE-2026-85046) (https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/) - Sangoma Switchvox SQL Injection Under Active Exploitation (CVE-2026-9586) (https://www.securityweek.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/) - PaperCut Flaws Exploited for Credential Theft in Education Sector (CVE-2026-81578, CVE-2026-82078) (https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html) - Additional CISA KEV Additions (https://www.securityweek.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/) - Microsoft Exchange CVE-2026-62911 Exploit Published (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - 12-Year-Old PostgreSQL Replication Privilege Escalation (CVE-2026-6471) (https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/) - HPE AOS-CX Critical RCE Vulnerabilities (CVE-2026-73749) (https://www.securityweek.com/hpe-patches-critical-rce-vulnerabilities-in-aos-cx/) - AI Coding Agents Installing Untrusted Code (https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html) - Phishing Campaign Uses Invisible Unicode to Evade Filters (https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html) - Knight Office AitM Phishing Kit Targets Microsoft 365 and Google Workspace (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - DaVita Settles Ransomware Lawsuit for $15M (https://databreaches.net/2026/09/04/davita-settles-ransomware-attack-lawsuit-for-15m/) - Winona County, Minnesota Paid $128K Ransom (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - FBI Probes IDScan.net Breach (https://databreaches.net/2026/09/04/fbi-probes-suspected-breach-at-idscan-net-after-dark-web-service-nexus-offered-153m-us-and-canadian-drivers-license-scans/) - 5,000 Dropbox Accounts Compromised via Lenovo Integration (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - Coder's Module Registry Served Malware (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - Russian Charged for Malware Delivery to 80,000 Freelancers (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - OpenAI Agents Used Abandoned Wiki for Coordination (https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html) - Ted Backdoor Compiled Into HAProxy (https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html) - Microsoft Cloud Patches (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - Plex Security Updates (https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - Microsoft Exchange Mail Blocking for Outdated Servers (https://www.theregister.com/on-prem/2026/09/04/microsoft-to-bounce-mail-from-outdated-exchange-servers/5294506) CVEs Referenced: CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-62911, CVE-2026-6471, CVE-2026-73749, CVE-2026-81578, CVE-2026-82078, CVE-2026-85046, CVE-2026-9586 Indicators of Compromise: Domains: 48[.]134, 193[.]132., 193[.]132, 48[.]134. Full brief: https://carolinacleartech.com/brief/2026-09-05/

  17. 2026-09-04: Google patches a seventh Chrome zero-day exploited in the wild from Cyber Threat Brief, opens in a new tab

    Sep 4, 202619 min

    Show Notes - 2026-09-04 Stories Covered: - Today: - Google Chrome Zero-Day CVE-2026-85046 (https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html) - SonicWall SMA 1000 Zero-Days CVE-2026-83548 & CVE-2026-83549 (https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/) - 153 Million Driver's Licenses Leaked on Dark Web (https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web/) - AI-Enabled Ransomware Attack Delivers 80-Page Security Audit (https://databreaches.net/2026/09/03/agentic-ransomware-took-down-enterprise-in-ten-hours-ai-left-80-page-audit/) - Toy Ghouls Deploys Custom HiveMQ and Element Backdoors (https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/) - Shai-Hulud Infostealer Worm Expands to 469 Credential Locations (https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html) - BraZetsu Malware Framework Fuels Brazilian IAB Marketplace (https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html) - RMM Phishing Campaign Targets 46 Countries, US Top Target (https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html) - AI Agents Used in Multi-Stage Latin American Campaigns (https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/) - All-in-One WP Migration and Backup SQL Injection CVE-2026-19949 (https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/) - IXON VPN Client CRLF Injection CVE-2026-75925 (https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02) - Rockwell Automation Industrial Control System Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04) - Tycon Systems TPDIN-Monitor-WEB3 Multiple Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08) - Inductive Automation Ignition Project Creation Misconfiguration CVE-2026-77393 (https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06) - OPCFoundation UA LDS Privilege Escalation CVE-2026-77477 (https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-01) - Microsoft Patch Tuesday September 2026 (https://msrc.microsoft.com/update-guide/) CVEs Referenced: CVE-2025-10478, CVE-2026-11645, CVE-2026-12663, CVE-2026-19471, CVE-2026-19472, CVE-2026-19949, CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-62906, CVE-2026-69857, CVE-2026-70178, CVE-2026-75925, CVE-2026-77393, CVE-2026-77477, CVE-2026-77847, CVE-2026-82684, CVE-2026-82712, CVE-2026-83548, CVE-2026-83549, CVE-2026-84323, CVE-2026-84324, CVE-2026-84325, CVE-2026-84326, CVE-2026-84329, CVE-2026-84348, CVE-2026-84351, CVE-2026-84356, CVE-2026-84358, CVE-2026-85046 Indicators of Compromise: Domains: infect[.]online, infect[.]online., 185[.]97, duckdns[.]org. Full brief: https://carolinacleartech.com/brief/2026-09-04/

  18. 2026-09-03: SonicWall SMA 1000 devices face active zero-day exploitation with CISA deadlines this week from Cyber Threat Brief, opens in a new tab

    Sep 3, 202619 min

    Show Notes - 2026-09-03 Stories Covered: - Today: - SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE (CVE-2026-83548, CVE-2026-83549) (https://www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce) - CISA Adds Seven Exploited Vulnerabilities to KEV Catalog (https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html) - AI Agents Execute Complete Ransomware Attack in Under 10 Hours (https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/) - Microsoft Teams Vishing Campaign Delivers Remote Access and Malware (https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/) - OpenAI's Astra Model Reaches 'Critical' Cybersecurity Capability Level (https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/) - CrowdStrike Privilege Escalation Zero-Day (FalconFlank) Disclosed (https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html) - Malicious Git Configs Enable Code Execution in AI Coding Agents (https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html) - BGP Hijack Delivers Malicious Virtualizor Updates (https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/) - Chinese-Speaking Threat Cluster Hijacks Brazilian Government Sites for SEO Manipulation (https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/) - NSO Group Pegasus Spyware Infects Serbian Student Movement Member via Zero-Click iMessage Exploit (https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html) - Fake Software Installers Disable Windows Update and Weaken Microsoft Defender (https://thehackernews.com/2026/09/fake-software-installers-disable.html) - Meta Ads Push StreamRat Android Trojan Granting Near-Complete Device Control (https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html) CVEs Referenced: CVE-2026-15409, CVE-2026-15410, CVE-2026-19592, CVE-2026-48710, CVE-2026-49869, CVE-2026-55607, CVE-2026-59822, CVE-2026-69414, CVE-2026-72718, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549, CVE-2026-9586 Indicators of Compromise: Domains: iualef[.]net, oijfwe[.]net, app-microsoft-edge[.]com, baidu-pan[.]com, kaspersky-lab[.]hl Hashes: e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c, ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 IPs: 3.2.9.9 Full brief: https://carolinacleartech.com/brief/2026-09-03/

  19. 2026-09-02: SonicWall disclosed two SMA1000 zero-days (CVSS 10 and 7.8) exploited in the wild, patch immediately from Cyber Threat Brief, opens in a new tab

    Sep 2, 202617 min

    Show Notes - 2026-09-02 Stories Covered: - Today: - SonicWall SMA1000 Dual Zero-Day Exploitation (CVE-2026-83548, CVE-2026-83549) (https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/) - Langflow RCE Under Sustained Exploitation (CVE-2026-0768, CVE-2026-0769, CVE-2026-5027) (https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/) - JFrog Artifactory Authentication Bypass Exploited (CVE-2026-82329) (https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure) - Sangoma Switchvox Unauthenticated SQLi to RCE (CVE-2026-9586) (https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html) - The Gentlemen Claim Nutex Health Breach (https://www.securityweek.com/ransomware-gang-claims-nutex-health-data-breach/) - Insider Recruitment Accelerating for Ransomware Groups (https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within) - BGP Hijack Delivers Malicious Virtualizor Updates (https://news.risky.biz/risky-bulletin-bgp-hijack-targets-virtualizor-to-deliver-malicious-updates/) - GeoNetwork Unauthenticated RCE Chain (CVE-2026-63219 + CVE-2026-58400) (https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html) - FBI Warns of OAuth Consent Phishing Campaign (https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/) - Silver Fox Counterfeit Installer Campaign Targeting Chinese Operations (https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/) - 153M+ Driver's Licenses for Sale on Dark Web (https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/) - Rockwell Automation ICS Advisory Batch (https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04) - Sality Botnet Disrupted by International Law Enforcement (https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html) - Iranian Nimbus Manticore Deploying Cross-Platform RATs via Fake Coding Tests (https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html) - METR Discloses Two Security Incidents (https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing) - Chrome 152 and Firefox 155 Security Updates (https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/) - Malicious Packagist Packages Targeting iOS Devices (https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html) CVEs Referenced: CVE-2021-42260, CVE-2025-12768, CVE-2025-31277, CVE-2025-3248, CVE-2025-43529, CVE-2026-0768, CVE-2026-0769, CVE-2026-12661, CVE-2026-16675, CVE-2026-5027, CVE-2026-58400, CVE-2026-63219, CVE-2026-82329, CVE-2026-83548, CVE-2026-83549, CVE-2026-84352, CVE-2026-84353, CVE-2026-9586, CVE-2026-9621, CVE-2026-9633 Indicators of Compromise: Domains: 148[.]184., gehie246[.]com, yimxg25tiy[.]com, cc8ttkv35b[.]com, n7b8t85zsg[.]com, azurewebsites[.]net, azurewebsites[.]net., cloudfareintcdn[.]com. IPs: 8.4.0.2 Full brief: https://carolinacleartech.com/brief/2026-09-02/

  20. 2026-09-01: PaperCut flaws escalate from scanning to hands-on exploitation with September 14 CISA deadline from Cyber Threat Brief, opens in a new tab

    Sep 1, 202623 min

    Show Notes - 2026-09-01 Stories Covered: - Today: - PaperCut NG/MF Authentication Bypass and RCE (CVE-2026-81578, CVE-2026-82078) (https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Ruby on Rails KindaRails2Shell (CVE-2026-66066) (https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html) - Langflow Code Execution (CVE-2026-0768) (https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html) - JFrog Artifactory Authentication Bypass (CVE-2026-82329) (https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/) - ServiceNow AI Platform Code Injection (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Aurora Ransomware Uses Cursor AI for Active Directory Exploitation (https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html) - Cardiology Associates of Port Huron - 150,000+ Patient Records (https://databreaches.net/2026/08/31/times-up-ransomware-group-claims-150000-cardiology-patient-records-weve-seen-the-data/) - Blossom Health Extortion Attempt (https://databreaches.net/2026/08/31/a-rough-day-at-the-extortion-office-and-a-botched-attack-on-blossom-health/) - TerminalFix Campaign - Fake Cloudflare CAPTCHA Delivers Reverse Tunnel Implant (https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html) - Spring Ring - Microsoft Teams Vishing Targeting 150+ Employees (https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/) - BREEZE COMET (UNC5669) Targets Brazilian Financial Services (https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/) - Fire Ant (UNC3886) Hijacks Cisco Routers, TACACS Servers (https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html) - ZBT Router Backdoors - SPEAKINGSTONE and DARKLANTERN (https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html) - Hugging Face Incident - AI Agents Achieve Domain Admin in 40 Minutes (https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/) - Anthropic Claude Code Users Hit by Infostealer Attacks (https://www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-thefts) - Manchester Airports Group Data Breach - 8.7 Million Customers (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - ATF Cyberattack - Qilin Ransomware (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Boston Scientific Network Outages (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - McKesson Data Breach - 284 Million Patient Records (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Mirage Kitten Targets Aviation and FinTech with NodeRabbit and PollCat (https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/) - ValleyRAT Backdoor in Signed Chinese Adware (https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html) - UAC-0099 GuardBreaker - Nuclear Weapon Prompt in Malware (https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html) - Guildma (Astaroth) Malware via Brazilian Portuguese Email (https://isc.sans.edu/diary/rss/33300) - AI Model Prompt Injection in Legal Filing (https://www.schneier.com/blog/archives/2026/08/hiding-prompt-injection-in-legal-filing.html) - Rogue LLM Endpoint Honeypot - Coding Agent Session Exposed (https://isc.sans.edu/diary/rss/33298) - Cryptographic Context Injection in AI Assistants (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Amazon Kiro Prompt Injection (Fixed) (https://research.checkpoint.com/2026/31th-august-threat-intelligen ...

Ranking source

Apple Podcasts rankings via the Mato Topic Intelligence Platform.

Observed September 20, 2026.

Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.

Pairs with

What to do with a chart

01ShowsThe shows Mato publishesEvery public Mato show, its episodes, and the Apple placements it holds.02AI talentPick the voice before the formatThe live roster of hosts, each with samples you can listen to before you commit.03How it worksFrom an idea to a published episodeWhat Mato does between the brief and the feed, step by step.

Steal the structure, not the show

Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.

Hear a Mato showCreate a show inspired by this