
Sign up to save your podcasts
Or


🚨 Welcome to Blumira Briefings! This week, our security experts Jake, Mike, and Michael join Zoe to help break down critical vulnerabilities and trending threats you need to know about. 🚨
What We Cover This Week:
📱 Two critical Cisco vulnerabilities - hard-coded root credentials in Unified CM (CVSS 10.0) and RCE flaws in Identity Services Engine (CVSS 10.0)
🌐 Google's 4th Chrome zero-day of 2025 - type confusion in the V8 JavaScript engine
⚠️ CitrixBleed 2 exploits now in the wild - allowing attackers to steal session tokens with a CVSS 9.3 rating
⚫ Windows' Blue Screen of Death turning black - Microsoft's response to last year's CrowdStrike outage
🤖 AI models providing incorrect login URLs 34% of the time, creating new phishing opportunities 💼 Ingram Micro hit by suspected SafePay ransomware, highlighting supply chain risks
💡 Quick tip of the week: Remind your team that LLMs generate information rather than retrieve it - so it’s important to always verify URLs!
Expert Insights On:
* Building failover communication options in case primary systems are compromised
* How to better validate API security before implementation
* Why organizations should treat AI-generated information with skepticism
* Defensive domain registration strategies to counter AI misdirection
* Preparation steps to mitigate third-party security risks
SOURCES:
Cisco Root Credential Flaw: https://hackread.com/cisco-emergency-fix-critical-root-credential-flaw-unified-cm/
Cisco ISE Vulnerabilities: https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-rce-flaws-in-identity-services-engine/
Chrome Zero-Day: https://www.infosecurity-magazine.com/news/google-patch-chrome-zero-day/
Windows Blue Screen Changes: https://www.securityweek.com/windows-infamous-blue-screen-of-death-will-soon-turn-black/
CitrixBleed 2 Exploits: https://go.theregister.com/feed/www.theregister.com/2025/07/07/citrixbleed_2_exploits/
AI Models URL Issues: https://www.infosecurity-magazine.com/news/ai-models-mislead-users-login-urls/
Ingram Micro Ransomware: https://www.darkreading.com/cyberattacks-data-breaches/ransomware-attack-outage-ingram-micro
RESOURCES:
Burnout Assessment Test for Security Professionals: https://github.com/Patrick-Kelley/CBI-CS
Jake's video on double extension file attacks: https://youtu.be/qXGcNCSLDKw
🔔 Welcome back for this week’s episode and your weekly security download! We're joined by Jake Ouellette, Taylor Jacobson, and Amanda Berlin to break down the week's most important security headlines with context you can actually use. 🔔
What We Cover This Week:
📊 Most changed weekly trends, including recurring process dumps for credential theft and suspicious IAM behavior
🔧 Critical Veeam RCE vulnerability (CVE-2025-23121) with a 9.9 CVSS score - make sure to patch this one immediately!
🌐 NetScaler ADC and Gateway vulnerabilities allowing token theft from internet-facing devices
📲 Cisco Meraki MX and Z device vulnerability can DoS VPN connections
💼 Identity theft report showing 148% surge in impersonation scams, with businesses as primary targets
🤖 First-ever zero-click AI data leak vulnerability in Microsoft 365 Copilot dubbed "EchoLeak"
Document your recovery processes so anyone can perform them if the primary person is unavailable - don't create single points of failure in your incident response team
Plus, Expert Insights On:
NOTE: We'll be on hiatus next week due to the July 4th holiday -- we'll be back on July 11th with more security insights!
📰 SOURCES:
Veeam RCE Vulnerability: https://thehackernews.com/2025/06/veeam-patches-cve-2025-23121-critical.html
Citrix NetScaler Vulnerabilities: https://www.darkreading.com/vulnerabilities-threats/citrix-patches-vulns-netscaler-adc-gateway
Cisco & Atlassian Patches: https://www.securityweek.com/high-severity-vulnerabilities-patched-by-cisco-atlassian/
Identity Impersonation Scams: https://www.infosecurity-magazine.com/news/reported-impersonation-scams-surge/
Zero-Click AI Data Leak: https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/
🔗 LINKS:
Veeam Advisory: https://www.veeam.com/kb4743
Rapid7 Emergent Threat Response: https://www.rapid7.com/blog/post/etr-critical-veeam-backup-replication-cve-2025-23121/
Citrix Security Bulletin CTX693420: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420
OWASP Top 10 for LLM Applications 2025: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
Defensive Security Handbook: https://www.oreilly.com/library/view/defensive-security-handbook/9781098127237/
🔔 Your essential security briefing is here! This week, Matt Warner, Nick Dixon, and Jake Ouellette join Zoe Lindsey to break down critical developments in cybersecurity with practical context for busy IT and security teams. 🔔
What We Cover This Week:
🔐 Trend Micro patches 6 critical vulnerabilities (CVSS 9.8) in Apex Central and PolicyServer products - and how the deserialization method leveraged to exploit them works
🔍 Over 80,000 Microsoft Entra ID accounts targeted using TeamFiltration - how this pen testing tool is being weaponized by attackers
📘 NIST's new Zero Trust Implementation Guide - less conceptual introductions, with better focus on practical implementation
📊Latest World Economic Forum report shows smaller organizations feel they are approaching cybersecurity breaking point - the panel talks how to get strategic when resources and time are tight
💡 Quick tip of the week: Perform a gap assessment to identify high-impact, low-effort security improvements to prioritize first — evolution, not reinvention is the name of the game!
Plus, Expert Insights On:
🔗 LINKS:
Trend Micro Security Bulletins:
NIST Zero Trust Resources:
Active Directory Hardening Guide: https://osintteam.blog/%EF%B8%8Factive-directory-hardening-for-enterprise-security-5832b3f75de0
📰 SOURCES:
Trend Micro Critical Vulnerabilities: https://www.bleepingcomputer.com/news/security/trend-micro-fixes-six-critical-flaws-on-apex-central-endpoint-encryption-policyserver
NIST Zero Trust Implementation Guide: https://www.infosecurity-magazine.com/news/nist-zero-trust-implementation/
Microsoft Entra ID TeamFiltration Attacks: https://thehackernews.com/2025/06/over-80000-microsoft-entra-id-accounts.html
Small Orgs Cybersecurity Breaking Point: https://www.csoonline.com/article/4003892/smaller-organizations-nearing-cybersecurity-breaking-point.html
This week on Blumira Briefings, join our "Oops! All Detection Engineers" episode as Zoe hosts Jake and Justin to break down the most critical security headlines of the week with practical context you can actually use!
🔍 What We Cover This Week:
🌩️ Cisco ISE credential vulnerability affecting cloud deployments on AWS, Azure & Oracle (CVE-2025-20286)
🔐 SAP NetWeaver critical missing authorization bug in RFC framework (CVE-2025-42989)
📊 Our most changed security trends of the week - what's suddenly spiking across our detection data
🪟 Windows WebDAV zero-day exploited against Turkish defense organization (CVE-2025-33053)
🧩 Popular Chrome extensions leaking data through unencrypted HTTP connections
🎭 Updated CISA guidance on Play Ransomware with new attack details
💡 Quick tip of the week: Validate your security controls by testing them regularly - have you tried restoring from your backups recently to confirm they actually work?
Plus, Expert Insights On:
🔑 Why "randomly generated" credentials are just default credentials with extra steps
☁️ How to protect cloud infrastructure from credential vulnerabilities
⏱️ Why the time between vulnerability disclosure and broader exploitation keeps shrinking
🔌 The security risks of browser extensions and VPN services
🛡️ The importance of using phishing-resistant MFA with secure backup options
🔗 LINKS:
CVSS Base Score Metrics: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Pyramid of Pain: https://www.attackiq.com/glossary/pyramid-of-pain/
🤫 SUPER EXTRA BONUS DEFENDER RESOURCE:
🐵 Monkey365 – PS Scanner for M365, Azure, and Entra: https://github.com/silverhack/monkey365
🔔 Welcome to Blumira Briefings! This week, we're joined by Michael Kellar, Chris Furner, and Justin Kikani to break down the week's most important security headlines with expert context you can actually use. 🔔
What We Cover This Week:
🔄 NEW FORMAT! Instead of our usual top trends, we're highlighting the rarest findings in our environments - with insights on what makes these unusual detections worth your attention
🌐 Critical Chrome vulnerabilities with active exploits in the wild - what makes use-after-free and out-of-bounds write bugs so dangerous
🛠️ ConnectWise ScreenConnect and other vulnerabilities added to CISA's Known Exploited Vulnerabilities list
🪟 OneDrive File Picker flaw giving third-party apps broader permissions than users expect
🍪 NordVPN's alarming research on 94 billion stolen cookies for sale on dark web marketplaces
🎭 Deep dive into Scattered Spider's sophisticated help desk social engineering tactics
💡 Quick tip of the week: Consider conducting periodic, scheduled reboots for your organization's devices - this helps clear browser sessions, refresh security policies, and force application updates like Chrome to install critical patches.
Plus, Expert Insights On:
- Why auditing third-party app permissions is crucial for cloud security
- Why infostealer attacks are on the rise
- Practical strategies for protecting help desk teams from social engineering
- The rising trend of identity-focused attacks vs. traditional device targeting
- How to implement proper controls for remote workers using home network equipment
🔗 LINKS:
Prowler - Cloud security assessment tool: https://github.com/prowler-cloud/prowler
SilentPush research on Scattered Spider: https://www.silentpush.com/blog/scattered-spider-2025/
Blumira blog on SocGholish: https://www.blumira.com/blog/socgholish-malware-recent-trends-and-effective-detection-strategies
📰 SOURCES:
Chrome Zero-Day Vulnerability: https://www.securityweek.com/google-researchers-find-new-chrome-zero-day/
ConnectWise and CISA KEV Update: https://www.bleepingcomputer.com/news/security/cisa-warns-of-connectwise-screenconnect-bug-exploited-in-attacks/
OneDrive File Picker Vulnerability: https://hackread.com/onedrive-file-picker-apps-full-access-user-drives/
Stolen Cookies Research: https://www.theregister.com/2025/05/29/billions_of_cookies_available
Scattered Spider Analysis: https://thehackernews.com/2025/06/scattered-spider-understanding-help.html
🔔 Welcome back to Blumira Briefings, your essential security download! This week, Matt Warner, Mike Toole, Jake Ouellette, and Zoe Lindsey break down the latest security headlines with context you can actually use. 🔔
What We Cover This Week:
🩹 Cisco patches 10 issues, including 2 high-severity DoS and privilege escalation flaws
🔑 184 million login credentials for major platforms exposed online
🇷🇺 Russia's Fancy Bear stepping up attacks on logistics and IT firms
💻 BadSuccessor: Understanding a Windows Server 2025 vulnerability exploiting permission inheritence
🤖 GitLab Duo prompt injection vulnerability, highlighting potential AI assistant security risks
Plus, Expert Insights On:
📰 SOURCES:
Cisco Patches: https://www.securityweek.com/cisco-patches-high-severity-dos-privilege-escalation-vulnerabilities/
Exposed Login Credentials: https://www.websiteplanet.com/news/infostealer-breach-report/
Fancy Bear Advisory: https://www.darkreading.com/cyberattacks-data-breaches/cisa-russia-fancy-bear-targeting-logistics-it-firms
BadSuccessor Vulnerability: https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory
GitLab Duo Prompt Injection: https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo
🔔 Your essential security download is here! This week on Blumira Briefings, we're joined by Matt Warner, Jake Ouellette, and Mike Toole to break down the latest security headlines with practical insights for busy IT and security teams. 🔔
What We Cover This Week:
📱 Chrome patches 3rd actively-exploited vuln in a week - what this means for browser security
🔐 Microsoft's patch Tuesday fixes 78 flaws, including five 0days and a CVSS 10.0 vulnerability in Azure DevOps Server
🔄 How attackers are abusing dynamic DNS services to create convincing phishing domains and evade detection
🕸️ We look at a novel "Hazy Hawk" attack, exploiting abandoned CNAME records to hijack trusted domains
📊 New "Likely Exploited Vulnerabilities" (LEV) metric proposed by NIST/CISA - will it help your prioritization?
💡 Quick tip of the week: Set a recurring "DNS spring cleaning day" to audit and remove obsolete or unused DNS records to prevent dangling CNAME attacks
Plus, Expert Insights On:
🔗 RESOURCE LINKS:
Certificate Search: https://crt.sh/
DNS Twist Tool: https://dnstwist.it/
📰 SOURCES:
Google Chrome Zero-Day Fixes: https://www.bleepingcomputer.com/news/google/google-fixes-CVE-2024-4947-third-actively-exploited-chrome-zero-day-in-a-week/
Microsoft Patch Tuesday: https://thehackernews.com/2025/05/microsoft-fixes-78-flaws-5-zero-days.html
Likely Exploited Vulnerabilities Metric: https://www.securityweek.com/vulnerability-exploitation-probability-metric-proposed-by-nist-cisa-researchers/
Dynamic DNS Attacks: https://www.darkreading.com/threat-intelligence/dynamic-dns-cyberattack-facilitator
Hazy Hawk DNS Hijacking: https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/
🔔 Welcome to another episode of Blumira Briefings! This week, we welcome special guest Dennis Fisher, InfoSec journalist extraordinaire and Editor-in-Chief of Decipher, joining Zoe Lindsey, Jake Ouellette, and Nick Dixon to break down the week's most important security headlines. 🔔
What We Cover This Week:
📱 Apple's iOS/iPadOS 18.5 update patches 30+ security bugs - learn what's affected and why you need to update now
💻 ASUS DriverHub vulnerability allows attackers to run admin commands through malicious websites
🔧 Cisco IOS XE Wireless Controller critical vulnerability (CVSS 10.0) exploitable via hardcoded JWT tokens
☎️ Fortinet zero-day exploited in FortiVoice attacks - what post-compromise activity looks like
🔍 SPECIAL SEGMENT: Dennis Fisher shares insights on navigating InfoSec journalism, finding reliable sources, and how to cut through vendor spin to find the truth
🛠️ Detection Engineering deep dive: Why maintenance matters, and how to shift from reactive to proactive security operations
💡 Quick tip: Consider the security implications of pre-installed utilities with elevated privileges - sometimes you need to disable bloatware in BIOS, not just uninstall it!
🔗 LINKS:
Apple iOS/iPadOS 18.5 Security Update: https://support.apple.com/en-us/122404
ASUS DriverHub Advisory: https://www.bleepingcomputer.com/news/security/asus-driverhub-flaw-let-malicious-sites-run-commands-with-admin-rights/
Cisco IOS XE Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC
Fortinet Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-254
Detection Engineering Maintenance Article: https://medium.com/falconforce/why-is-no-one-talking-about-maintenance-in-detection-engineering-ebb5820564dc
Detection Engineering Maturity Matrix: https://detectionengineering.io/
🔔 Welcome back to Blumira Briefings! Fresh from RSA, we're diving into the week's critical security stories with Mike Toole, Michael Keller, and Jake Ouellette to provide actionable context for IT and security teams. 🔔
What We Cover This Week:
📊 Top trending threats, including suspicious Microsoft 365 activity, Sophos blocked website alerts, and important batch script execution patterns
🔊 "AirBorne" - Wormable AirPlay flaws affecting not just Apple devices but also smart speakers, TVs, and CarPlay systems
🛡️ Two SonicWall vulnerabilities being actively exploited despite patches being available since 2023/2024
🧩 "Bring Your Own Installer" EDR bypass technique used in ransomware attacks against SentinelOne
🪟 Windows RDP session persistence that allows continued access after password changes or account disabling
☁️ Novel privilege escalation technique in Google Cloud Platform using resource tags
💡 Expert Insights On:
- Why attackers consistently use net commands for reconnaissance and how to detect them
- Practical mitigation strategies for AirPlay vulnerabilities, especially for devices that rarely get updates
- The security implications of "wrapper apps" that modify secure messaging platforms
- How to implement stronger cloud access controls to prevent privilege escalation
🔍 QUICK TIP: Check if your organization has RDP directly exposed to the internet - if you do, it's one of the highest risk indicators for a potential breach!
🔗 LINKS:
AirPlay Security Issues: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
SonicWall Vulnerabilities: https://www.securityweek.com/sonicwall-flags-two-vulnerabilities-as-exploited/
EDR Bypass Research: https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone
Windows RDP Issue: https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/
GCP Privilege Escalation: https://www.mitiga.io/blog/tag-your-way-in-new-privilege-escalation-technique-in-gcp
Prowler (Cloud Security Tool): https://prowler.com/
SocGholish Malware Analysis: https://www.blumira.com/blog/socgholish-malware-recent-trends-and-effective-detection-strategies
Subscribe for weekly security insights every Friday at 1pm ET!
#CyberSecurity #VulnerabilityManagement #BlumiraBriefings #AirPlay #AppleSecurity #CloudSecurity #EDR
🔔 It's time for your essential security download with Blumira Briefings! This week, we're joined by Amanda Berlin, Jake Ouellette, and Nick Dixon to break down the week's most important security headlines with context you can actually use. 🔔
What We Cover This Week:
📊 Top trending threats, including a rise in stolen credentials attacks and continuing remote access tool abuse
🌐 Critical Erlang/OTP SSH vulnerability with public exploits now available - what it affects and what it doesn't
📲 Cisco WebEx vulnerability allowing code execution through meeting links
🔐 SSL.com certificate issuance vulnerability though DCV subversion
💰 Ransomware study showing demands increase when attackers find insurance documents - practical steps to protect your organization
🤖 How AI models are generating working exploits within hours of vulnerability disclosures - and what this means for your patching strategy
💡 Quick tip of the week: Shodan searches can help you quickly check if your organization's public-facing systems are exposed
Plus, Expert Insights On:
NOTE: We'll be on hiatus next week due to RSA Conference -- we'll see you in two weeks with more security insights!
From the publisher's feed
Staying on top of security news shouldn't be another full-time job.
Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you might…
Each week, join a lineup of different Blumira experts (and sometimes special guests!) who will:
••Keep it conversational, informative, and under 30 minutes