Signal Check

Episode 114: July 24, 2026


Listen Later

This episode covers a Russian zero-day exploit in Zimbra webmail that let state-backed hackers steal credentials and two-factor codes for months, new vulnerabilities in Microsoft's passkey implementation ahead of Black Hat, and a polished malvertising campaign using fake Claude.ai ads to distribute SectopRAT malware. Adrian breaks down why overlooked infrastructure, sloppy execution on good ideas, and legitimate-looking search ads all remain serious attack surfaces.
Stories covered:
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes (The Hacker News) - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
- Flaws in Passkey Implementation Show Old Attacks Still Work (Dark Reading) - https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
- Fake Claude app promoted by Bing ads pushes SectopRAT malware (BleepingComputer) - https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/
- This 64-Year-Old Mom and Son Made History at the Hardrock 100 (Trail Runner Mag) - https://www.trailrunnermag.com/people/64-year-old-mom-and-son-made-history-at-the-hardrock-100/
- Launch HN: Screenpipe (YC S26) – Record how you work and turn that into agents (Hacker News) - https://news.ycombinator.com/item?id=49024620
- The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required (EFF) - https://www.eff.org/deeplinks/2026/07/fourth-circuit-says-border-agents-can-search-your-phone-hand-no-suspicion-required
...more
View all episodesView all episodes
Download on the App Store

Signal CheckBy Adrian North