Daily DefSec Brief
by Jerry Bell
A daily podcast covering the important cyber security news that IT and security teams need to know.
2026 Jerry Bell
Sep 11, 2026Episodes (50)

Cyber Security News for September 11 2026 - Daily DefSec Brief
Sep 11, 20265m
1. Two MikroTik flaws exploited, deadline Sunday — CVE-2026-86060, CVE-2026-67277 — Do: Patch RouterOS, close SSH and btest — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. WatchGuard Firebox now in rans

Cyber Security News for September 10 2026 - Daily DefSec Brief
Sep 10, 20265m
1. Cisco firewall manager exploited to root — CVE-2026-20079 (CVSS 10.0), CVE-2026-20316 — Do: Apply the Cisco Secure FMC hotfixes now — Cisco Talos — https://blog.talosintelligence.com/fmc-ongoing-exploitation/ 2. NetSc

Cyber Security News for September 9 2026 - Daily DefSec Brief
Sep 9, 20265m
1. Record 974-CVE Patch Tuesday, two zero-days live — CVE-2026-81963, CVE-2026-85880 (CVSS 7.8) — Do: Install September Windows updates now — SecurityWeek — https://www.securityweek.com/microsoft-patches-record-974-vulne

Cyber Security News for September 8 2026 - Daily DefSec Brief
Sep 8, 20265m
1. A maximum-severity Magento zero-day was exploited for three days before Adobe shipped a fix — CVE-2026-75650 — Do: Apply the APSB26-146 composer patch, then hunt — Adobe — https://helpx.adobe.com/security/products/mag

Cyber Security News for September 4 2026 - Daily DefSec Brief
Sep 4, 20265m
1. Chrome patches a V8 zero-day that attackers are already using — CVE-2026-85046 — The Hacker News — https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html 2. Coder's package registry served Terra

Cyber Security News for September 3 2026 - Daily DefSec Brief
Sep 3, 20264m
1. Kestra workflow engine lets anyone run commands with no credentials at all — CVE-2026-49869 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. GitSpawn lets a repository's own config run comm

Cyber Security News for September 2 2026 - Daily DefSec Brief
Sep 2, 20265m
1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ 2. J

Cyber Security News for September 1 2026 - Daily DefSec Brief
Sep 1, 20264m
1. OpenSearch SQL plugin deserialization flaw gives a read-only user code execution — CVE-2026-83497 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/ 2. BGP hijack pushed a m

Cyber Security News for August 31 2026 - Daily DefSec Brief
Aug 31, 20265m
1. PaperCut ships a second emergency patch after attackers chain two zero-days — CVE-2026-82078, CVE-2026-81578 — SecurityWeek — https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/ 2.

Cyber Security News for August 28 2026 - Daily DefSec Brief
Aug 28, 20265m
1. ownCloud unauthenticated file access flaw added to CISA KEV — CVE-2023-49105 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. ServiceNow patches three CVSS 10.0 flaws in its AI Platform — C

Cyber Security News for August 27 2026 - Daily DefSec Brief
Aug 27, 20265m
1. PaperCut NG/MF under active exploitation, no patch yet — Help Net Security — https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/ 2. GPUThor Rowhammer defeats ECC on NVIDIA workstation GPUs

Cyber Security News for August 26 2026 - Daily DefSec Brief
Aug 26, 20264m
1. CISA adds actively exploited Gitea code-injection flaw to KEV — CVE-2026-60004 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. SonicWall NetExtender Linux client path traversal allows root

Cyber Security News for August 25 2026 - Daily DefSec Brief
Aug 25, 20263m
1. CISA adds actively exploited Oracle HTTP Server / WebLogic proxy plug-in flaw to KEV — CVE-2026-21962 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. Critical Keycloak password-reset flaw

Cyber Security News for August 24 2026 - Daily DefSec Brief
Aug 24, 20264m
1. Passkey phishing kit keeps mailbox access after a password reset — SecurityWeek — https://www.securityweek.com/new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets/ 2. Encrypted-prompt technique

Cyber Security News for August 21 2026 - Daily DefSec Brief
Aug 21, 20264m
1. Max-severity Entra ID flaw exploited before patch — CVE-2026-69836 — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ 2. TrueConf S

Cyber Security News for August 20 2026 - Daily DefSec Brief
Aug 20, 20264m
1. Feds warn of active AI-scripted attacks on internet-exposed Siemens S7 PLCs — CISA — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a 2. Critical Citrix NetScaler auth-bypass patched, exploitation e

Cyber Security News for August 19 2026 - Daily DefSec Brief
Aug 19, 20264m
1. Windows IKE Extension RCE added to CISA KEV, now exploited — CVE-2026-33824 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. macOS Screen Sharing auth bypass added to CISA KEV — CVE-2026-65

Cyber Security News for August 18 2026 - Daily DefSec Brief
Aug 18, 20264m
1. Windows Task Host privesc actively exploited by ransomware gangs — CVE-2025-60710 — BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/ 2. R

Cyber Security News for August 17 2026 - Daily DefSec Brief
Aug 17, 20263m
1. macOS Screen Sharing auth-bypass exploited to root Macs and drop Monero miners — CVE-2026-65400 — SecurityWeek — https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks/ 2. Microsof

Cyber Security News for August 14 2026 - Daily DefSec Brief
Aug 14, 20265m
1. GeoServer zero-day exploited within hours, no patch yet — SecurityWeek https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/ · Cyber Security News https://cybersecuritynews.com/geoserver-0-day-

Cyber Security News for August 13 2026 - Daily DefSec Brief
Aug 13, 20264m
1. VMware vCenter path-traversal RCE now APT-exploited — CVE-2026-59310 — SecurityWeek — https://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/ 2. Fortinet FortiWeb auth bypass (any-p

Cyber Security News for August 12 2026 - Daily DefSec Brief
Aug 12, 20264m
1. Windows WinSock use-after-free zero-day exploited by Lazarus — CVE-2026-68820 — SecurityWeek — https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/ 2. Cisco ASA/FTD VPN flaw expl

Cyber Security News for August 11 2026 - Daily DefSec Brief
Aug 11, 20265m
1. Gunra ransomware exploits Fortinet and Schneider Electric flaws — joint FBI/CISA/South Korea advisory — CVE-2024-55591, CVE-2025-24472, CVE-2024-5559 (verify) — The Hacker News — https://thehackernews.com/2026/08/gunr

Cyber Security News for August 10 2026 - Daily DefSec Brief
Aug 10, 20264m
1. WordPress supply-chain attack poisons BdThemes plugins via remote API feed — Cyber Security News — https://cybersecuritynews.com/wordpress-supply-chain-attack/ 2. Solidity Pro VS Code extensions steal wallets, tokens,

Cyber Security News for August 7 2026 - Daily DefSec Brief
Aug 7, 20265m
1. SOGo webmail XSS exploited in the wild via malicious calendar invites — CVE-2026-8496 — CERT/CC — https://kb.cert.org/vuls/id/487613 2. INTERRUPT INJECTION / TONTOU bypasses Spectre v2 fixes, leaks Linux password hash