Blumira Briefings

Blumira Briefings

Download on the App Store

Blumira Briefings episodes

  • 🦔 Blumira Briefings Ep. 14: Cisco's Critical Vulnerabilities, Chrome Zero-Day, & CitrixBleed 2 Alert

    🚨 Welcome to Blumira Briefings! This week, our security experts Jake, Mike, and Michael join Zoe to help break down critical vulnerabilities and trending threats you need to know about. 🚨

    What We Cover This Week:

    📱 Two critical Cisco vulnerabilities - hard-coded root credentials in Unified CM (CVSS 10.0) and RCE flaws in Identity Services Engine (CVSS 10.0) 
    🌐 Google's 4th Chrome zero-day of 2025 - type confusion in the V8 JavaScript engine 
    ⚠️ CitrixBleed 2 exploits now in the wild - allowing attackers to steal session tokens with a CVSS 9.3 rating 
    ⚫ Windows' Blue Screen of Death turning black - Microsoft's response to last year's CrowdStrike outage 
    🤖 AI models providing incorrect login URLs 34% of the time, creating new phishing opportunities 💼 Ingram Micro hit by suspected SafePay ransomware, highlighting supply chain risks


    💡 Quick tip of the week: Remind your team that LLMs generate information rather than retrieve it - so it’s important to always verify URLs!

    Expert Insights On:
    * Building failover communication options in case primary systems are compromised
    * How to better validate API security before implementation
    * Why organizations should treat AI-generated information with skepticism
    * Defensive domain registration strategies to counter AI misdirection
    * Preparation steps to mitigate third-party security risks

    SOURCES:
    Cisco Root Credential Flaw: https://hackread.com/cisco-emergency-fix-critical-root-credential-flaw-unified-cm/
    Cisco ISE Vulnerabilities: https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-rce-flaws-in-identity-services-engine/ 
    Chrome Zero-Day: https://www.infosecurity-magazine.com/news/google-patch-chrome-zero-day/
    Windows Blue Screen Changes: https://www.securityweek.com/windows-infamous-blue-screen-of-death-will-soon-turn-black/
    CitrixBleed 2 Exploits: https://go.theregister.com/feed/www.theregister.com/2025/07/07/citrixbleed_2_exploits/
    AI Models URL Issues: https://www.infosecurity-magazine.com/news/ai-models-mislead-users-login-urls/
    Ingram Micro Ransomware: https://www.darkreading.com/cyberattacks-data-breaches/ransomware-attack-outage-ingram-micro

    RESOURCES:
    Burnout Assessment Test for Security Professionals: https://github.com/Patrick-Kelley/CBI-CS
    Jake's video on double extension file attacks: https://youtu.be/qXGcNCSLDKw

    49 min
  • 🦔 Blumira Briefings Ep. 13: Critical Veeam RCE, NetScaler Vulns, & Zero-Click Copilot Data Theft

    🔔 Welcome back for this week’s episode and your weekly security download! We're joined by Jake Ouellette, Taylor Jacobson, and Amanda Berlin to break down the week's most important security headlines with context you can actually use. 🔔


    What We Cover This Week:

    📊 Most changed weekly trends, including recurring process dumps for credential theft and suspicious IAM behavior

    🔧 Critical Veeam RCE vulnerability (CVE-2025-23121) with a 9.9 CVSS score - make sure to patch this one immediately!

    🌐 NetScaler ADC and Gateway vulnerabilities allowing token theft from internet-facing devices

    📲 Cisco Meraki MX and Z device vulnerability can DoS VPN connections 

    💼 Identity theft report showing 148% surge in impersonation scams, with businesses as primary targets 

    🤖 First-ever zero-click AI data leak vulnerability in Microsoft 365 Copilot dubbed "EchoLeak"


    Document your recovery processes so anyone can perform them if the primary person is unavailable - don't create single points of failure in your incident response team


    Plus, Expert Insights On:

    • How to handle emergency patches outside normal change control cycles
    • Why testing backup restoration is more critical than just having backups
    • Practical ways to run tabletop exercises even with limited resources
    • Strategies for businesses to prevent impersonation attacks
    • How organizations can manage AI access to reduce risks


    NOTE: We'll be on hiatus next week due to the July 4th holiday -- we'll be back on July 11th with more security insights!

    📰 SOURCES:


    Veeam RCE Vulnerability: https://thehackernews.com/2025/06/veeam-patches-cve-2025-23121-critical.html

    Citrix NetScaler Vulnerabilities: https://www.darkreading.com/vulnerabilities-threats/citrix-patches-vulns-netscaler-adc-gateway

    Cisco & Atlassian Patches: https://www.securityweek.com/high-severity-vulnerabilities-patched-by-cisco-atlassian/

    Identity Impersonation Scams: https://www.infosecurity-magazine.com/news/reported-impersonation-scams-surge/

    Zero-Click AI Data Leak: https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/


    🔗 LINKS:

    Veeam Advisory: https://www.veeam.com/kb4743

    Rapid7 Emergent Threat Response: https://www.rapid7.com/blog/post/etr-critical-veeam-backup-replication-cve-2025-23121/

    Citrix Security Bulletin CTX693420: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420

    OWASP Top 10 for LLM Applications 2025: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/

    Defensive Security Handbook: https://www.oreilly.com/library/view/defensive-security-handbook/9781098127237/

    53 min
  • 🦔 Blumira Briefings Ep. 12: Critical Trend Micro Fix, TeamFiltration Attacks, NIST Zero Trust Guide

    🔔 Your essential security briefing is here! This week, Matt Warner, Nick Dixon, and Jake Ouellette join Zoe Lindsey to break down critical developments in cybersecurity with practical context for busy IT and security teams. 🔔

    What We Cover This Week: 

    🔐 Trend Micro patches 6 critical vulnerabilities (CVSS 9.8) in Apex Central and PolicyServer products - and how the deserialization method leveraged to exploit them works

    🔍 Over 80,000 Microsoft Entra ID accounts targeted using TeamFiltration - how this pen testing tool is being weaponized by attackers 

    📘 NIST's new Zero Trust Implementation Guide - less conceptual introductions, with better focus on practical implementation

    📊Latest World Economic Forum report shows smaller organizations feel they are approaching cybersecurity breaking point - the panel talks how to get strategic when resources and time are tight

    💡 Quick tip of the week: Perform a gap assessment to identify high-impact, low-effort security improvements to prioritize first — evolution, not reinvention is the name of the game!


    Plus, Expert Insights On:

    • Why traditional rate limiting fails against sophisticated password sprays
    • The usefulness of frameworks to start with the right questions
    • Strategies for prioritizing security efforts to avoid burnout


    🔗 LINKS:

    Trend Micro Security Bulletins:

    • Endpoint Encryption PolicyServer: https://success.trendmicro.com/en-US/solution/KA-0019928 
    • Apex Central: https://success.trendmicro.com/en-US/solution/KA-0019926

    NIST Zero Trust Resources:

    • SP 1800-35: Implementing a Zero Trust Architecture (Final): https://csrc.nist.gov/pubs/sp/1800/35/final
    • SP 800-207: Zero Trust Architecture (2020 Conceptual Framework): https://csrc.nist.gov/publications/detail/sp/800-207/final

    Active Directory Hardening Guide: https://osintteam.blog/%EF%B8%8Factive-directory-hardening-for-enterprise-security-5832b3f75de0


    📰 SOURCES:

    Trend Micro Critical Vulnerabilities: https://www.bleepingcomputer.com/news/security/trend-micro-fixes-six-critical-flaws-on-apex-central-endpoint-encryption-policyserver

    NIST Zero Trust Implementation Guide: https://www.infosecurity-magazine.com/news/nist-zero-trust-implementation/

    Microsoft Entra ID TeamFiltration Attacks: https://thehackernews.com/2025/06/over-80000-microsoft-entra-id-accounts.html

    Small Orgs Cybersecurity Breaking Point: https://www.csoonline.com/article/4003892/smaller-organizations-nearing-cybersecurity-breaking-point.html

    55 min
  • 🦔 Blumira Briefings Ep. 11: Cloud ISE Cred Twinsies, Windows 0day Exploited, and Play Ransomware Updates

    This week on Blumira Briefings, join our "Oops! All Detection Engineers" episode as Zoe hosts Jake and Justin to break down the most critical security headlines of the week with practical context you can actually use!

    🔍 What We Cover This Week:

    🌩️ Cisco ISE credential vulnerability affecting cloud deployments on AWS, Azure & Oracle (CVE-2025-20286) 

    🔐 SAP NetWeaver critical missing authorization bug in RFC framework (CVE-2025-42989) 

    📊 Our most changed security trends of the week - what's suddenly spiking across our detection data 

    🪟 Windows WebDAV zero-day exploited against Turkish defense organization (CVE-2025-33053) 

    🧩 Popular Chrome extensions leaking data through unencrypted HTTP connections 

    🎭 Updated CISA guidance on Play Ransomware with new attack details


    💡 Quick tip of the week: Validate your security controls by testing them regularly - have you tried restoring from your backups recently to confirm they actually work?


    Plus, Expert Insights On: 

    🔑 Why "randomly generated" credentials are just default credentials with extra steps 

    ☁️ How to protect cloud infrastructure from credential vulnerabilities 

    ⏱️ Why the time between vulnerability disclosure and broader exploitation keeps shrinking 

    🔌 The security risks of browser extensions and VPN services 

    🛡️ The importance of using phishing-resistant MFA with secure backup options


    🔗 LINKS:

    CVSS Base Score Metrics: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

    Pyramid of Pain: https://www.attackiq.com/glossary/pyramid-of-pain/


    🤫 SUPER EXTRA BONUS DEFENDER RESOURCE:


    🐵 Monkey365 – PS Scanner for M365, Azure, and Entra: https://github.com/silverhack/monkey365 

    1 hr 2 min
  • 🦔 Blumira Briefings Ep. 10: Critical Chrome Release, Identity-Based Attacks, Cookie Security Risks

    🔔 Welcome to Blumira Briefings! This week, we're joined by Michael Kellar, Chris Furner, and Justin Kikani to break down the week's most important security headlines with expert context you can actually use. 🔔

    What We Cover This Week:

    🔄 NEW FORMAT! Instead of our usual top trends, we're highlighting the rarest findings in our environments - with insights on what makes these unusual detections worth your attention

    🌐 Critical Chrome vulnerabilities with active exploits in the wild - what makes use-after-free and out-of-bounds write bugs so dangerous
     🛠️ ConnectWise ScreenConnect and other vulnerabilities added to CISA's Known Exploited Vulnerabilities list 
    🪟 OneDrive File Picker flaw giving third-party apps broader permissions than users expect 
    🍪 NordVPN's alarming research on 94 billion stolen cookies for sale on dark web marketplaces 
    🎭 Deep dive into Scattered Spider's sophisticated help desk social engineering tactics

    💡 Quick tip of the week: Consider conducting periodic, scheduled reboots for your organization's devices - this helps clear browser sessions, refresh security policies, and force application updates like Chrome to install critical patches.

    Plus, Expert Insights On:

    - Why auditing third-party app permissions is crucial for cloud security
    - Why infostealer attacks are on the rise
    - Practical strategies for protecting help desk teams from social engineering
    - The rising trend of identity-focused attacks vs. traditional device targeting
    - How to implement proper controls for remote workers using home network equipment

    🔗 LINKS:

    Prowler - Cloud security assessment tool: https://github.com/prowler-cloud/prowler 
    SilentPush research on Scattered Spider: https://www.silentpush.com/blog/scattered-spider-2025/ 
    Blumira blog on SocGholish:  https://www.blumira.com/blog/socgholish-malware-recent-trends-and-effective-detection-strategies

    📰 SOURCES:

    Chrome Zero-Day Vulnerability: https://www.securityweek.com/google-researchers-find-new-chrome-zero-day/
    ConnectWise and CISA KEV Update: https://www.bleepingcomputer.com/news/security/cisa-warns-of-connectwise-screenconnect-bug-exploited-in-attacks/ 
    OneDrive File Picker Vulnerability: https://hackread.com/onedrive-file-picker-apps-full-access-user-drives/ 
    Stolen Cookies Research: https://www.theregister.com/2025/05/29/billions_of_cookies_available 
    Scattered Spider Analysis: https://thehackernews.com/2025/06/scattered-spider-understanding-help.html

    52 min
  • 🦔 Blumira Briefings Ep. 9: Cisco Vulnerabilities, BadSuccessors, Coding Assistant Prompt Injection

    🔔 Welcome back to Blumira Briefings, your essential security download! This week, Matt Warner, Mike Toole, Jake Ouellette, and Zoe Lindsey break down the latest security headlines with context you can actually use. 🔔

    What We Cover This Week:

    🩹 Cisco patches 10 issues, including 2 high-severity DoS and privilege escalation flaws 

    🔑 184 million login credentials for major platforms exposed online

    🇷🇺 Russia's Fancy Bear stepping up attacks on logistics and IT firms

     💻 BadSuccessor: Understanding a Windows Server 2025 vulnerability exploiting permission inheritence 

    🤖 GitLab Duo prompt injection vulnerability, highlighting potential AI assistant security risks

    Plus, Expert Insights On:

    • Focusing on threat actor attribution vs. focusing on remediation
    • Practical strategies for balancing AI assistant functionality with security
    • The importance of monitoring AD permission changes and account creation
    • The risk in using Outlook/email storage for sensitive information

    📰 SOURCES: 

    Cisco Patches: https://www.securityweek.com/cisco-patches-high-severity-dos-privilege-escalation-vulnerabilities/ 

    Exposed Login Credentials: https://www.websiteplanet.com/news/infostealer-breach-report/ 

    Fancy Bear Advisory: https://www.darkreading.com/cyberattacks-data-breaches/cisa-russia-fancy-bear-targeting-logistics-it-firms 

    BadSuccessor Vulnerability: https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory 

    GitLab Duo Prompt Injection: https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo

    54 min
  • 🦔 Blumira Briefings Ep. 8: Chrome Zero-Days, Microsoft’s BIG Patch Tuesday, DNS Attacks & Exploitability Metrics

    🔔 Your essential security download is here! This week on Blumira Briefings, we're joined by Matt Warner, Jake Ouellette, and Mike Toole to break down the latest security headlines with practical insights for busy IT and security teams. 🔔

    What We Cover This Week:

    📱 Chrome patches 3rd actively-exploited vuln in a week - what this means for browser security 

    🔐 Microsoft's patch Tuesday fixes 78 flaws, including five 0days and a CVSS 10.0 vulnerability in Azure DevOps Server

    🔄 How attackers are abusing dynamic DNS services to create convincing phishing domains and evade detection 

    🕸️ We look at a novel "Hazy Hawk" attack, exploiting abandoned CNAME records to hijack trusted domains 

    📊 New "Likely Exploited Vulnerabilities" (LEV) metric proposed by NIST/CISA - will it help your prioritization?

    💡 Quick tip of the week: Set a recurring "DNS spring cleaning day" to audit and remove obsolete or unused DNS records to prevent dangling CNAME attacks

    Plus, Expert Insights On:

    • Can you "just disable JavaScript" in modern web environments?
    • How to properly secure your developer machines against token theft
    • Why a complex password that's "keyboard walked" doesn't count as secure
    • Better approaches to prioritizing vulnerabilities beyond just scores

    🔗 RESOURCE LINKS:

    Certificate Search: https://crt.sh/ 

    DNS Twist Tool: https://dnstwist.it/


    📰 SOURCES:

    Google Chrome Zero-Day Fixes: https://www.bleepingcomputer.com/news/google/google-fixes-CVE-2024-4947-third-actively-exploited-chrome-zero-day-in-a-week/ 

    Microsoft Patch Tuesday: https://thehackernews.com/2025/05/microsoft-fixes-78-flaws-5-zero-days.html 

    Likely Exploited Vulnerabilities Metric: https://www.securityweek.com/vulnerability-exploitation-probability-metric-proposed-by-nist-cisa-researchers/ 

    Dynamic DNS Attacks: https://www.darkreading.com/threat-intelligence/dynamic-dns-cyberattack-facilitator 

    Hazy Hawk DNS Hijacking: https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/

    47 min
  • 🦔 Blumira Briefings Ep. 7: Hardcoded Woes, Detection Maintenance, and Dennis Fisher!

    🔔 Welcome to another episode of Blumira Briefings! This week, we welcome special guest Dennis Fisher, InfoSec journalist extraordinaire and Editor-in-Chief of Decipher, joining Zoe Lindsey, Jake Ouellette, and Nick Dixon to break down the week's most important security headlines. 🔔

    What We Cover This Week:

    📱 Apple's iOS/iPadOS 18.5 update patches 30+ security bugs - learn what's affected and why you need to update now
    💻 ASUS DriverHub vulnerability allows attackers to run admin commands through malicious websites
    🔧 Cisco IOS XE Wireless Controller critical vulnerability (CVSS 10.0) exploitable via hardcoded JWT tokens
    ☎️ Fortinet zero-day exploited in FortiVoice attacks - what post-compromise activity looks like
    🔍 SPECIAL SEGMENT: Dennis Fisher shares insights on navigating InfoSec journalism, finding reliable sources, and how to cut through vendor spin to find the truth
    🛠️ Detection Engineering deep dive: Why maintenance matters, and how to shift from reactive to proactive security operations

    💡 Quick tip: Consider the security implications of pre-installed utilities with elevated privileges - sometimes you need to disable bloatware in BIOS, not just uninstall it!

    🔗 LINKS:
    Apple iOS/iPadOS 18.5 Security Update: https://support.apple.com/en-us/122404
    ASUS DriverHub Advisory: https://www.bleepingcomputer.com/news/security/asus-driverhub-flaw-let-malicious-sites-run-commands-with-admin-rights/
    Cisco IOS XE Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC
    Fortinet Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-254
    Detection Engineering Maintenance Article: https://medium.com/falconforce/why-is-no-one-talking-about-maintenance-in-detection-engineering-ebb5820564dc
    Detection Engineering Maturity Matrix: https://detectionengineering.io/

    56 min
  • 🦔 Blumira Briefings Ep. 6: AirPlay Vulns, SonicWall Warnings, Risk Turduckens

    🔔 Welcome back to Blumira Briefings! Fresh from RSA, we're diving into the week's critical security stories with Mike Toole, Michael Keller, and Jake Ouellette to provide actionable context for IT and security teams. 🔔

    What We Cover This Week:
    📊 Top trending threats, including suspicious Microsoft 365 activity, Sophos blocked website alerts, and important batch script execution patterns
    🔊 "AirBorne" - Wormable AirPlay flaws affecting not just Apple devices but also smart speakers, TVs, and CarPlay systems
    🛡️ Two SonicWall vulnerabilities being actively exploited despite patches being available since 2023/2024
    🧩 "Bring Your Own Installer" EDR bypass technique used in ransomware attacks against SentinelOne
    🪟 Windows RDP session persistence that allows continued access after password changes or account disabling
    ☁️ Novel privilege escalation technique in Google Cloud Platform using resource tags

    💡 Expert Insights On:

    - Why attackers consistently use net commands for reconnaissance and how to detect them
    - Practical mitigation strategies for AirPlay vulnerabilities, especially for devices that rarely get updates
    - The security implications of "wrapper apps" that modify secure messaging platforms
    - How to implement stronger cloud access controls to prevent privilege escalation

    🔍 QUICK TIP: Check if your organization has RDP directly exposed to the internet - if you do, it's one of the highest risk indicators for a potential breach!

    🔗 LINKS:
    AirPlay Security Issues: https://thehackernews.com/2025/05/wormable-airplay-flaws-enable-zero.html
    SonicWall Vulnerabilities: https://www.securityweek.com/sonicwall-flags-two-vulnerabilities-as-exploited/
    EDR Bypass Research: https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone
    Windows RDP Issue: https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/
    GCP Privilege Escalation: https://www.mitiga.io/blog/tag-your-way-in-new-privilege-escalation-technique-in-gcp
    Prowler (Cloud Security Tool): https://prowler.com/
    SocGholish Malware Analysis: https://www.blumira.com/blog/socgholish-malware-recent-trends-and-effective-detection-strategies

    Subscribe for weekly security insights every Friday at 1pm ET!

    #CyberSecurity #VulnerabilityManagement #BlumiraBriefings #AirPlay #AppleSecurity #CloudSecurity #EDR

    42 min
  • 🦔 Blumira Briefings: Fresh Report Drops, Ransom-Tripling Magic Words, AI Accelerating Vulnerability Exploits

    🔔 It's time for your essential security download with Blumira Briefings! This week, we're joined by Amanda Berlin, Jake Ouellette, and Nick Dixon to break down the week's most important security headlines with context you can actually use. 🔔


    What We Cover This Week: 

    📊 Top trending threats, including a rise in stolen credentials attacks and continuing remote access tool abuse 

    🌐 Critical Erlang/OTP SSH vulnerability with public exploits now available - what it affects and what it doesn't 

    📲 Cisco WebEx vulnerability allowing code execution through meeting links 

    🔐 SSL.com certificate issuance vulnerability though DCV subversion

    💰 Ransomware study showing demands increase when attackers find insurance documents - practical steps to protect your organization

    🤖 How AI models are generating working exploits within hours of vulnerability disclosures - and what this means for your patching strategy


    💡 Quick tip of the week: Shodan searches can help you quickly check if your organization's public-facing systems are exposed


    Plus, Expert Insights On:

    • Practical detection strategies for suspicious remote access tools
    • How to strengthen SSH security beyond just patching
    • Why backups fail 85% of the time when actually needed
    • How to balance cyber insurance benefits with potential risks
    • Strategies to accelerate patching as exploit development speeds up


    NOTE: We'll be on hiatus next week due to RSA Conference -- we'll see you in two weeks with more security insights!

    41 min

About Blumira Briefings

From the publisher's feed

Staying on top of security news shouldn't be another full-time job.

Enter Blumira Briefings, our weekly panel series where security experts break down the headlines you might…