This episode covers a critical zero-day exploit in Palo Alto firewalls that went unpatched for nearly a month, malware hiding in PyPI packages using workplace chat tools for cover, and a major breach at Canvas that exposed student data across universities. We also dig into why trust systems in open-source repos keep getting weaponized and close with an ultramarathon story that redefines what the human body can actually endure.
Stories covered:
- PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux (The Hacker News) - https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html
- Palo Alto Networks firewall zero-day exploited for nearly a month (BleepingComputer) - https://www.bleepingcomputer.com/news/security/pan-os-firewall-rce-zero-day-exploited-in-attacks-since-april-9/
- Canvas, used by schools and universities across the U.S., breached by hacker group - FOX13 Memphis (FOX13 Memphis) - https://news.google.com/rss/articles/CBMi9gFBVV95cUxQbWIzLVJFd3BNcWNGam9KQWdJNnJsT0ozeUZ1UVFpTGltY0RNb1FyUTlvUEtydVVxMFJsQmlmMTBrYkRuUzJyRUdtTXRZQ2dzQTlNQlJnOUVpbmYta05NcW9wMkZ6UnV5NXh2WkV3bExPTzN6NE8wZC02X0dKdkJlY3BScmhfTV84eW40TDN1THlNN3BJY1JnRmszTEM5TGlVOFFnS3h2NjJHOUtXMXNsWlYta3RjZXRGcWhLV2hwcFFSakdfaGFSejhaQW1aQWpGN1o5TGYzb21UUlh2RTA3dldxbkRPNHMzZ0hUcnJnQ1NFOGdWQlE?oc=5
- She Ran 250 Miles in an Astonishing 56 Hours—Beating All the Men at Cocodona and Making History (Runner's World) - https://www.runnersworld.com/news/a71240926/rachel-entrekin-wins-cocodona-250/
- A hacker ran me over with a robot lawn mower (The Verge) - https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt
- Dirtyfrag: Universal Linux LPE (Hacker News) - https://www.openwall.com/lists/oss-security/2026/05/07/8