Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
Cybersecurity news moves fast. Most of it is noise. This is the signal. The Critical Stack Daily Briefing cuts a day's worth of security news down to what actually matters: real CVEs, real breaches, r... more
FAQs about The Critical Stack:How many episodes does The Critical Stack have?The podcast currently has 10 episodes available.
September 23, 2026A Perfect Ten: Arista VeloCloud Under Attack, ShinyHunters Robs Cl0pA maximum-severity, actively exploited flaw in Arista's VeloCloud Orchestrator tops a brutal day of zero-days, while F5 and VMware vCenter demand same-day patching. Plus: ShinyHunters hijacks rival gang Cl0p's own leak site, SEE-suh retires its weekly vulnerability bulletin, and Microsoft dismantles a phishing platform that burned twelve thousand accounts....more5minPlay
September 23, 2026Nine Hundred Seventy-Four Bugs — And the One That Actually MattersMicrosoft's record Patch Tuesday hits its federal deadline today, but the story underneath it is a c-v-s-s ten point zero authentication bypass in Cisco Secure Firewall Management Center that Sandworm and Qilin affiliates are exploiting right now. Plus: one hundred fifty-three million driver's license scans for sale, Mandiant's negative time-to-exploit, and Palo Alto's five hundred million dollar bet on agentic remediation....more5minPlay
September 21, 2026Perfect Ten: GitLab Under Fire and Ransomware That Runs ItselfA c-v-s-s ten point zero file-read flaw in GitLab went from patch to in-the-wild probing in under a day, and Sysdig documented the first ransomware intrusion planned and executed end to end by an a-i agent. Plus: the CIRCIA final rule lands this month, and Wall Street calls a top on the security trade....more5minPlay
September 20, 2026Cisco's Perfect Ten: Root on the Identity Plane, and a Twelve-Minute a-i AttackA ten-out-of-ten Cisco Identity Services Engine zero-day is under active attack with its federal patch deadline already behind us, Revolut got robbed by a fake government data request, and Amazon's honeypots clocked an autonomous a-i agent running a full attack chain in twelve minutes. Plus: the e-u's incident-reporting clock is now officially running....more5minPlay
September 19, 2026Cisco's Root-by-Email Zero-Day, and a Dark-Web Market for 153 Million Driver's LicensesCisco closes a brutal week with two exploited zero-days, including a Secure Email Gateway flaw where simply receiving a message hands an attacker root. Plus: a dark-web service selling more than one hundred fifty-three million driver's license scans, nist's plan to rebuild the National Vulnerability Database for the AI era, and reports that Palo Alto Networks is circling SentinelOne for up to ten billion dollars....more5minPlay
September 18, 2026A Perfect Ten: Cisco ISE Zero-Day, ShinyHunters' Fifty-Five Million Dollar DemandA maximum-severity Cisco Identity Services Engine zero-day is being exploited in the wild and is already on the k-e-v catalog — patch it today. Plus ShinyHunters' extortion spree lands on healthcare giant McKesson, the e-u's Cyber Resilience Act reporting clock starts ticking, and Kevin Mandia raises a record one hundred eighty-nine point nine million dollars to build a-i red teamers....more5minPlay
September 17, 2026Cisco Email Gateway Zero-Day: The Deadline Is TodayA root-level, unauthenticated flaw in Cisco Secure Email Gateway has been exploited for nearly a year — and the federal patch deadline lands today. Plus: how hardcoded credentials in public JavaScript gave extortionists two months inside Novo Nordisk, the seventy-two-hour reporting clock arriving with SEE-suh's final CIRCIA rule, and Palo Alto's five-hundred-million-dollar bet on agentic security operations....more5minPlay
September 16, 2026974 CVEs and a 153-Million-License Fire SaleMicrosoft ships the largest Patch Tuesday on record — 974 CVEs, two of them already exploited — while a dark-web service peddles searchable access to 153 million driver's licenses. Plus: why a 155x surge in password spraying means your MFA policy probably has a hole in it....more5minPlay
September 15, 2026Sandworm and Qilin Walk Into the Same Firewall: The Cisco FMC 10.0A CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center is being worked by three separate threat clusters at once — including Sandworm and the Qilin ransomware crew. Plus Rhysida dumps Berlin's emergency plans, Anthropic catches Midnight Blizzard using Claude to tune malware evasion, and CrowdStrike goes hunting for rogue AI agents....more5minPlay
September 14, 2026Deadline Day: GitLab's CVSS-10 File Read and Medusa's 500 VictimsA maximum-severity GitLab path traversal is under active exploitation with today's federal patch deadline already here -- and it's only one line in a brutal patch queue. Plus: Medusa ransomware crosses 500 critical-infrastructure victims, Anthropic documents AI-run intrusions finishing in two hours, and a public exploit turns CrowdStrike Falcon's own remediation feature into a privilege escalation....more5minPlay
FAQs about The Critical Stack:How many episodes does The Critical Stack have?The podcast currently has 10 episodes available.