The Defensive Line Weekly podcast is the audio edition of the weekly Defensive Line Substack intelligence summary — the week’s most important security stories turned into practical defensive action.
🤖 Voices are AI-generated. Story curation, research and writing are a mix of AI and human.
This week’s edition: The Defensive Line Weekly #36: 23–30 August 2026
Main stories
TerminalFix turns a paste into a persistent intrusion
Microsoft Threat Intelligence: TerminalFix campaign deploys a reverse tunnel through a multistage intrusion
The Hacker News: TerminalFix uses fake Cloudflare verification to deploy a reverse tunnel
The phish worked, but the application boundary held
ReliaQuest: Social-engineering attempt against ReliaQuest — what the company found
Island: NovaCookies phishing service targeting hundreds of organisations
SecurityWeek: ReliaQuest confirms incident and says the impact was limited
When AI systems trust documentation and expose gateways
Data became code: Researchers ran code inside corporate networks through agent-readable documentation
Project site: What Would AI Do?
Ars Technica: Claude, Codex and Hermes installed unowned code inside corporate networks
Wiz: Ninety days of attacks against internet-facing AI infrastructure
Microsoft Security: Securing AI gateways and control points
Honourable mentions
CISA’s tale of two SOCs
CISA: AA26-237A — A Tale of Two SOCs
ServiceNow as a management plane
MDSec: Anatomy of a ServiceNow red-team path
ServiceNow: KB3152242 — AI Platform security update
Signal and WhatsApp account takeover
POLITICO: State-linked actors target EU officials’ messaging accounts
AIVD: Phishing via Signal and WhatsApp
BfV and BSI: Joint warning on messaging-app phishing
Malicious browser extensions
The Hacker News: Malicious Chrome and Edge extensions steal cryptocurrency wallet secrets
The Hacker News: Malicious Firefox extensions impersonate cryptocurrency wallets
Vulnerability roundup
PaperCut NG and MF — zero-day exploitation
PaperCut: Urgent security advisory — 27 August 2026
Versions: PaperCut released emergency patches for versions 25 and 26, followed by additional hardening on 28 August. Consult the advisory for the latest fixed builds and investigation guidance.
CISA KEV additions
CISA: Known Exploited Vulnerabilities catalogue
Six vulnerabilities were added on 27 August, including flaws affecting Citrix NetScaler, Linux and SQL Server.
Citrix NetScaler ADC and Gateway
The Hacker News: Critical NetScaler authentication bypass
Versions: The issue affects customer-managed NetScaler ADC and Gateway deployments, including certain FIPS and NDcPP builds, as well as SecurAccess. Check the current Citrix advisory for the appropriate fixed build for your deployment.
WordPress plugins and themes
The Hacker News: Five critical WordPress plugin and theme flaws
Affected products include WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Update each affected component to the latest fixed release published by its maintainer.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com