Blumira Briefings

Blumira Briefings

Download on the App Store

Blumira Briefings episodes

  • cPanel Vulnerability, Global Phishing, and the Instructure Breach - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:
    - A critical authentication bypass vulnerability, identified as CVE-2026-41940, in cPanel and WHM software is currently being actively exploited by threat actors.
    - Microsoft has unveiled details of a sophisticated global phishing campaign that successfully targeted over 35,000 users across 26 countries in mid-April 2026, with the majority of victims in the United States, particularly within healthcare and finance sectors.
    - Instructure, the U.S.-based educational technology company known for its widely used Canvas learning management system, has confirmed a cybersecurity incident that exposed the personal data of users.

    Have a security topic you want us to cover? Let us know in the comments!


    Sources:
    Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940
    https://securityaffairs.com/191666/breaking-news/hackers-target-governments-and-msps-via-critical-cpanel-flaw-cve-2026-41940.html
    --
    Microsoft warns of global campaign stealing auth tokens from 35K users
    https://securityaffairs.com/191695/security/microsoft-warns-of-global-campaign-stealing-auth-tokens-from-35k-users.html
    --
    Educational tech firm Instructure data breach may have impacted 9,000 schools
    https://securityaffairs.com/191686/cyber-crime/educational-tech-firm-instructure-data-breach-may-have-impacted-9000-schools.html

    16 min
  • CISA KEV Additions, LiteLLM Vulnerability, ShinyHunters, and Copy Fail - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:

    - The U.S. Cybersecurity and Infrastructure Security Agency has added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog, signaling active exploitation
    - A severe SQL injection vulnerability, identified as CVE-2026-42208, in BerriAI's LiteLLM Python package has been actively exploited by threat actors in the wild.
    - The ShinyHunters cybercriminal group has exploited a security incident at Anodot, an artificial intelligence-driven data analytics vendor, to access data from multiple clients, including Vimeo. 
    - copy[dot]fail proof of concept requires only an unprivileged local user account for local privilege escalation to occur

    --
    Have a security topic you want us to cover? Let us know in the comments!
    --

    Sources:

    CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV
    https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html
    --
    LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
    https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html
    --
    ShinyHunters exploit Anodot incident to target Vimeo
    https://securityaffairs.com/191448/security/shinyhunters-exploit-anodot-incident-to-target-vimeo.html

    Chapters:
    0:00 Intro
    0:37 CISA KEV Additions: ConnectWise and Microsoft 
    3:26 LiteLLM SQL Injection Vulnerability 
    9:14 ShinyHunters Anodot Breach 
    11:42 Copy Fail

    16 min
  • SharePoint Zero-Day, Prompt Injection Vulnerabilities, and Chrome Extensions - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:
    - Microsoft has released its April 2026 Patch Tuesday updates, addressing a record 167 security vulnerabilities across its product portfolio.
    - Security researchers have identified prompt injection vulnerabilities in prominent enterprise artificial intelligence (AI) agents, specifically Microsoft Copilot Studio and Salesforce Agentforce.
    - Cybersecurity researchers have uncovered a widespread campaign involving 108 malicious Google Chrome browser extensions that have been actively stealing sensitive data from an estimated 20,000 users.
    --


    Have a security topic you want us to cover? Let us know in the comments!

    --
    Sources:

    -- Microsoft Patch Tuesday for April 2026 fixed actively exploited SharePoint zero-day
    https://securityaffairs.com/190831/security/microsoft-patch-tuesday-for-april-2026-fixed-actively-exploited-sharepoint-zero-day.html
    -- Copilot and Agentforce fall to form-based prompt injection tricks
    https://www.csoonline.com/article/4159079/copilot-and-agentforce-fall-to-form-based-prompt-injection-tricks.html
    -- 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users
    https://www.bitdefender.com/en-us/blog/hotforsecurity/malicious-chrome-extensions-steal-google-telegram-data

    14 min
  • BlueHammer, Forst Blizzard, and a Flowise Workflow Exploit - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:
    - A critical and unpatched vulnerability, named "BlueHammer," has been publicly disclosed for Microsoft Windows operating systems, allowing a local attacker to gain elevated privileges up to a system-level account.
    - A sophisticated espionage campaign, attributed to the Russian state-sponsored hacking group known as APT28 or Forest Blizzard, has been disrupted by U.S. authorities.
    - A critical vulnerability, identified as CVE-2025-59528, in the Flowise low-code platform for building artificial intelligence (AI) workflows is currently being actively exploited by hackers

    --
    Have a security topic you want us to cover? Let us know in the comments!
    --

    Sources:
    Experts published unpatched Windows zero-day BlueHammer
    https://securityaffairs.com/190400/breaking-news/experts-published-unpatched-windows-zero-day-bluehammer.html
    --
    Russia Hacked Routers to Steal Microsoft Office Tokens
    https://krebsonsecurity.com/2026/04/russia-hacked-routers-to-steal-microsoft-office-tokens/
    --
    Hackers exploit a critical Flowise flaw affecting thousands of AI workflows
    https://www.csoonline.com/article/4155680/hackers-exploit-a-critical-flowise-flaw-affecting-thousands-of-ai-workflows.html


    13 min
  • Axios Compromised, Chrome Zero-Day, and WhatsApp Malware - Blumira Briefings

    Axios Compromised, Chrome Zero-Day, and WhatsApp Malware - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:


    - The npm account for Axios, a JavaScript library with over 100 million weekly downloads, was compromised by threat actors who published malicious versions (1.14.1 and 0.30.4) containing remote access trojan (RAT) malware.
    - Google has released an emergency security update for its Chrome web browser, addressing a high-severity zero-day vulnerability, identified as CVE-2026-5281, which is actively being exploited by malicious actors.
    - Microsoft has issued a warning regarding a new malware campaign that targets WhatsApp users, exploiting social engineering tactics to trick them into executing malicious Visual Basic Script (VBS) files. This campaign, active since late February, aims to establish persistent remote access to infected systems.

    Have a security topic you want us to cover? Let us know in the comments!

    --

    Sources:
    Attackers hijack Axios npm account to spread RAT malware
    https://securityaffairs.com/190221/security/attackers-hijack-axios-npm-account-to-spread-rat-malware.html
    --
    Google fixes actively exploited Chrome zero-day flaw, update now
    https://cyberinsider.com/google-fixes-actively-exploited-chrome-zero-day-flaw-update-now/
    --
    WhatsApp malware campaign uses malicious VBS files to gain persistent access
    https://www.csoonline.com/article/4153092/whatsapp-malware-campaign-uses-malicious-vbs-files-to-gain-persistent-access.html

    18 min
  • FCC Router Ban, Darksword Exploit, and VS Code Malware - Blumira Briefings

    Welcome to Blumira Briefings, your weekly download of the top headlines and trends for your security practice.

    This week's episode:


    - The U.S. Federal Communications Commission, a government agency that regulates interstate and international communications, recently announced a significant new policy. The commission is banning the import of all new foreign-made consumer routers into the United States
    - A version of sophisticated iPhone spyware, known as DarkSword, has been publicly leaked on GitHub, raising urgent concerns among cybersecurity experts about potential widespread compromises of Apple iOS devices.
    - A threat group linked to North Korea, known as Team 8, is actively deploying new malware called StoatWaffle by exploiting features within Microsoft Visual Studio Code. This campaign, part of their ongoing "Contagious Interview" operations, abuses the editor's "tasks.json" auto-run functionality

    --

    Have a security topic you want us to cover? Want to hear more on a story we covered this week? Let us know in the comments!

    --

    Sources:
    US regulator bans imports of new foreign-made routers, citing security concerns
    https://www.reuters.com/sustainability/boards-policy-regulation/fcc-banning-imports-new-chinese-made-routers-citing-security-concerns-2026-03-23
    --
    DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses
    https://cyberscoop.com/darksword-iphone-spyware-leak-ios-18-exploit-threat/
    --
    North Korea-linked threat actors abuse VS Code auto-run to spread StoatWaffle malware
    https://securityaffairs.com/189880/security/north-korea-linked-threat-actors-abuse-vs-code-auto-run-to-spread-stoatwaffle-malware.html

    12 min
  • Clickfix AI Tactics, Aura Exposure, and RondoDox Botnet - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:

    - ClickFix attacks evolve techniques targeting macOS and Windows users with AI-based lures
    - A targeted voice phishing attack has led to unauthorized access to about 900,000 records at identity protection firm Aura
    - RondoDox attacks are becoming more focused and strategic, targeting 174 vulnerabilities up to 15,000 times a day

    Have a security topic you want us to cover? Let us know in the comments!

    --

    Sources:
    ClickFix spreads from Windows to macOS: ClickFix attacks shift tactics with ChatGPT-based lures:
    https://securityaffairs.com/189542/cyber-crime/from-windows-to-macos-clickfix-attacks-shift-tactics-with-chatgpt-based-lures.html
    --
    Identity protection firm Aura suffers breach:
    https://cyberinsider.com/identity-protection-firm-aura-suffers-data-breach-exposing-900000-records
    --
    RondoDox botnet expands arsenal, hits 15,000 daily exploit attempts:
    https://securityaffairs.com/189569/malware/rondodox-botnet-expands-arsenal-targeting-174-flaws-and-hits-15000-daily-exploit-attempts.html

    14 min
  • Salesforce Settings, Rust Crate Risks, and Stryker Attacked - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:
    - Salesforce warns that a threat campaign is exploiting overly permissive Experience Cloud guest configurations to harvest data from public portals.
    - Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors.
    - The Iranian cyberattack on Stryker is the kind of stress test that business continuity and disaster recovery programs often do not plan for.

    --

    Have a security topic you want us to cover? Let us know in the comments!

    --

    Sources:
    Overly permissive ‘guest’ settings put Salesforce customers at risk:
    https://www.csoonline.com/article/4143667/overly-permissive-guest-settings-put-salesforce-customers-at-risk.html
    --
    Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
    https://thehackernews.com/2026/03/five-malicious-rust-crates-and-ai-bot.html
    --
    Why Stryker's Outage Is a Disaster Recovery Wake-Up Call
    https://www.darkreading.com/cybersecurity-operations/stryker-outage-disaster-recovery-wake-up-call

    13 min
  • Iran-Linked Hacking, Microsoft OAuth, and Starkiller Phishing Suite - Blumira Briefings

    Welcome to Blumira Briefings, your top headlines and trends for your security practice.

    This week's episode:

    - Pro-Russia threat actors have formed a loose coalition with Iran-nexus hacking groups in response to the bombing campaign launched by the U.S. and Israel on Iran.
    - Hackers are abusing the legitimate OAuth redirection mechanism to bypass phishing protections in email and browsers to take users to malicious pages.
    - Cybersecurity researchers have disclosed details of a new phishing suite called Starkiller that proxies legitimate login pages to bypass multi-factor authentication (MFA) protections.

    --

    Like the new format? Have a security topic you want us to cover? Let us know in the comments!

    --

    Sources:
    Pro-Russia actors team with Iran-linked hackers in attacks:
    https://www.cybersecuritydive.com/news/pro-russia-actors-support-iran-nexus-hackers/813647/

    Microsoft: Hackers abuse OAuth error flows to spread malware:
    https://www.bleepingcomputer.com/news/security/microsoft-hackers-abuse-oauth-error-flows-to-spread-malware/

    Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
    https://thehackernews.com/2026/03/starkiller-phishing-suite-uses-aitm.html


    16 min
  • NPM Malware, Top IRS Scams 2026, and SonicWall Security Failings - Blumira Briefings

    Welcome to Blumira Briefings, bringing you a weekly download of the top headlines and trends for your security practice.

    *This week's episode:*

    -  Another software supply chain hit: Typosquatted npm packages are harvesting creds and propagating through dev environments.
    - Tax season is open season for threat actors: refund hijacking, credential phishing, and payroll fraud risks are escalating for businesses and their employees.
    - When perimeter security becomes the liability: Marquis claims compromised firewall data paved the way for ransomware.

    Like the new format? Have a security topic you want us to cover? Let us know in the comments!

    *Sources:*
    - Self-spreading npm malware targets developers in new supply chain attack: https://www.helpnetsecurity.com/2026/02/24/npm-worm-sandworm-mode-supply-cain-attack
    - Taxing times: Top IRS scams to look out for in 2026: https://www.welivesecurity.com/en/scams/taxing-times-top-irs-scams-look-out-2026
    - Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led to ransomware attack: https://techcrunch.com/2026/02/24/marquis-sonicwall-lawsuit-ransomware-firewall-breach

    *Chapters:*
    0:00 Intro
    0:31 Self-Spreading NPM Malware
    3:54 IRS Scams 2026 Edition
    10:18 SonicWall Security Failings

    16 min

About Blumira Briefings

From the publisher's feed

Staying on top of security news shouldn't be another full-time job.

Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you might…