
Sign up to save your podcasts
Or


Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice!
In this week's edition:Â
- F5 Emergency Patch for BIG-IP APM Zero-Day: Unauthenticated Remote Code Execution Under AttackÂ
- Chinese State-Aligned Hackers Exploit Chrome and Windows Zero-Days in New AttacksÂ
- Sophisticated Infostealer Impersonates LastPass on GitHub, Disables Wide Range of Security Software
--
Have a security topic you want us to cover?
Let us know in the comments!
--
Sources:
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
--Â
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/
--Â
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
https://securityaffairs.com/199577/malware/fake-lastpass-on-github-led-to-an-infostealer-that-killed-145-security-tools.html
Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice!
In this week's edition:
- Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history.
- Critical ConnectWise ScreenConnect Vulnerability Actively Exploited; Organizations Urged to Patch NowÂ
- Cisco Emergency Patches Address Zero-Day Exploit Granting Root Access on Email GatewaysÂ
- China-Linked Actors Use Same Chrome and Windows Zero-Days in Espionage Campaigns
--
Have a security topic you want us to cover?
Let us know in the comments!
--
Sources:
The vulnpocalypse rains iBugs down on Apple with record-setting number of patchesÂ
https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679-Â
Critical ScreenConnect flaw now actively exploited in attacks
https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/
Cisco warns customers of actively exploited zero-day in email gateways
https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html
Welcome to Blumira Briefings, your weekly download of the top headlines for your security practice!
In this week's edition:
- Critical Remote Code Execution Vulnerability in Gitea Actively Exploited, CISA WarnsÂ
- Critical WordPress SAML Plugin Authentication Bypasses Actively Exploited While UnpatchedÂ
- Microsoft Advises Network Controls as Vulnerability Patching Window Rapidly Shrinks
Sources:Â
Hackers now exploit critical Gitea flaw in code injection attacks
https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
--Â
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html
--Â
Microsoft warns patch window is collapsing, urges shift to network-level containment
https://www.csoonline.com/article/4214135/microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment.html
--Â
Welcome to Blumira Briefings, your top headlines and trends for your security practice!
This week:
- Microsoft fixes record number of vulnerabilities in July Patch Tuesday, including actively exploited zero-days.Â
- Microsoft mandates passkeys as default authentication method for Entra ID by September 2026.Â
- Attackers now using artificial intelligence to create custom PowerShell reconnaissance malware.
--
Have a security topic you want us to cover?
Let us know in the comments!
--
Sources:
Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug
https://www.csoonline.com/article/4196940/patch-tuesday-roundup-microsoft-fixes-a-monthly-record-569-holes-sap-patches-a-critical-memory-corruption-bug.html
--Â
Microsoft is forcing an enterprise transition to passkeys
https://www.csoonline.com/article/4197086/microsoft-is-forcing-an-enterprise-transition-to-passkeys-2.html
--Â
Attacker Used AI to Build Custom PowerShell Recon Malware
https://securityaffairs.com/195321/hacking/attacker-used-ai-to-build-custom-powershell-recon-malware.html
Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice!
In this week's edition:Â
- CISA Confirms Microsoft Defender Flaw Actively Exploited in Ransomware Campaigns for System AccessÂ
- Critical SimpleHelp Authentication Bypass Actively Exploited, Puts Managed Service Providers at RiskÂ
- Advanced Phishing Kit Resembles Business Email Compromise Platform, Bypasses Multi-Factor Authentication
--
Have a security topic you want us to cover?
Let us know in the comments!
--
Sources:
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
https://securityaffairs.com/194577/security/cisa-warns-bluehammer-flaw-is-now-exploited-in-ransomware-attacks.html
--Â
U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/194503/security/u-s-cisa-adds-simplehelp-flaw-to-its-known-exploited-vulnerabilities-catalog.html
--Â
This phishing kit looks more like BEC-as-a-service
https://cyberscoop.com/artoken-bec-platform-cisco-talos/
--Â
Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice!
This week:
- Cyber Broker Exposes Access to Over 73,000 Fortinet Firewalls for SaleÂ
- New Mistic Remote Access Trojan Utilized by Ransomware Initial Access Brokers in Active CampaignsÂ
- Supply Chain Attack Infects WordPress Plugins, Stealing Credentials and 2FA Secrets
Sources:
FortiBleed: The Broker Who Turned 73,000 Firewalls Into a Product Catalog
https://securityaffairs.com/194132/cyber-crime/fortibleed-the-broker-who-turned-73000-firewalls-into-a-product-catalog.html
--Â
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/
--Â
ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates
https://securityaffairs.com/194059/hacking/shapedplugin-supply-chain-attack-backdoors-pro-plugin-updates.html
Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice!
In this week's edition:
- CISA Directs Agencies to Patch Actively Exploited Cisco and cPanel Vulnerabilities This WeekÂ
- FortiSandbox Vulnerabilities Actively Exploited, Urgent Patching Recommended for Critical FlawsÂ
- Rokarolla Android Trojan Actively Spreads, Stealing Banking and Crypto Credentials, Bypassing Security
--
Have a security topic you want us to cover?
Let us know in the comments!
--
Sources:
U.S. CISA adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/193684/security/u-s-cisa-adds-cisco-catalyst-and-litespeed-cpanel-plugin-flaws-to-its-known-exploited-vulnerabilities-catalog.html
--Â
Active exploitation of FortiSandbox flaws prompt urgent patching calls from security experts
https://www.scworld.com/news/three-critical-fortisandbox-bugs-rated-98-actively-exploited
--Â
New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps
https://securityaffairs.com/193745/cyber-crime/new-rokarolla-android-trojan-targets-217-banking-and-crypto-apps.html
Welcome to Blumira Briefings, your top headlines and trends for your security practice!
In this week's episode:
- FBI Alert: New Kali365 Phishing Kit Bypasses Multi-Factor Authentication for Microsoft 365
- Critical Remote Code Execution Flaw in Microsoft SharePoint Requires Immediate Patching
- Automated Attacks Target Over 30,000 Exposed Databases Globally with Ransom Demands
Have a security topic you want us to cover? Let us know in the comments!
--
Sources:
FBI warns of Kali365 phishing kit targeting Microsoft 365 account
https://cyberinsider.com/fbi-warns-of-kali365-phishing-kit-targeting-microsoft-365-accounts/
--
Microsoft SharePoint Has a New RCE Flaw. If You Havenât Patched Yet, Go Do That.
https://securityaffairs.com/192730/security/microsoft-sharepoint-has-a-new-rce-flaw-if-you-havent-patched-yet-go-do-that.html
--
The Hidden Ransomware Economy Running on Exposed Databases
https://securityaffairs.com/192711/cyber-crime/the-hidden-ransomware-economy-running-on-exposed-databases.html
Welcome to Blumira Briefings, your top headlines and trends for your security practice.
This week's episode:
- Government Contractor Exposes Sensitive CISA and AWS GovCloud Credentials on Public GitHub
- Drupal Issues Critical Security Update Amid Warnings of Rapid Exploit Development Risk
- Shai-Hulud Worm Clones Emerge After Source Code Leak, Intensifying NPM Supply Chain Attacks
Have a security topic you want us to cover? Let us know in the comments!
Sources:
Contractorâs public GitHub account exposed GovCloud and CISA credentials
https://www.csoonline.com/article/4173305/contractors-public-github-account-exposed-govcloud-and-cisa-credentials.html
--
Drupal is rolling out an emergency security update on May 20. You cannot miss it
https://securityaffairs.com/192407/security/drupal-is-rolling-out-an-emergency-security-update-tomorrow-you-cannot-miss-it.html
--
Shai-Hulud worm copycats emerge after source code leak
https://securityaffairs.com/192366/malware/shai-hulud-worm-copycats-emerge-after-source-code-leak.html
Welcome to Blumira Briefings, your top headlines and trends for your security practice.
This week's episode:
- âMini Shai-Huludâ Malware Compromises Hundreds of Open-Source Software Packages in Supply Chain Attack
- Researcher Releases Proof-of-Concept for BitLocker Bypass and Privilege Escalation on Windows SystemsÂ
- Patch Tuesday, Accelerating Attacks, and AI Vulnerability Discovery
Have a security topic you want us to cover? Let us know in the comments!
Sources:
âMini Shai-Huludâ malware compromises hundreds of open-source packages in sprawling supply-chain attack
https://cyberscoop.com/mini-shai-hulud-supply-chain-malware-attack/
Windows BitLocker zero-day gives access to protected drives, PoC released
https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html
Google warns artificial intelligence is accelerating cyberattacks and zero-day exploits
https://securityaffairs.com/191984/ai/google-warns-artificial-intelligence-is-accelerating-cyberattacks-and-zero-day-exploits.html
Patch Tuesday, May 2026 Edition
https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/
From the publisher's feed
Staying on top of security news shouldn't be another full-time job.
Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you mightâŚ
Each week, join a lineup of different Blumira experts (and sometimes special guests!) who will:
â˘â˘Keep it conversational, informative, and under 30 minutes