Weekly Brief

SOC Minute Weekly

This week: actively exploited flaws, critical bugs across network and enterprise platforms, attacks affecting water systems and travelers, compromised trust in browsers and cloud providers, and the growing role of autonomous AI in intrusion activity.

Weekly Episode
Duration
21:02
Stories
19 stories
Published
Watch on YouTube

About this episode

This week: actively exploited flaws, critical bugs across network and enterprise platforms, attacks affecting water systems and travelers, compromised trust in browsers and cloud providers, and the growing role of autonomous AI in intrusion activity.

This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.

Play the episode, then review the stories and chapter list for the reporting and topics covered.

Stories covered this week

Chapters

  1. Opening
  2. Hackers Exploit FastJson Zero-Day RCE Attacks Targeting US Firms
  3. Critical OpenWrt DHCPv6 Flaw Lets Attackers Execute Code as Root
  4. Critical Ruby on Rails Flaw Lets Attackers Read Server Files via Image Uploads
  5. Critical Ruflo MCP Flaw Enables Remote Code Execution and AI Memory Poisoning
  6. Azure Cosmos DB Flaw Exposed Platform-Wide Access Key
  7. Adobe Campaign Classic CVSS 10.0 Flaw Enables Code Execution Without User Action
  8. Coordinated Cyberattack Disrupts 30+ Minnesota Water Systems
  9. DPRK-Linked macOS Malvertising Uses Fake Updates to Steal Crypto
  10. Midnight Blizzard's CaptiveCrunch targets travelers with malware and credential theft
  11. Chinese-Speaking Hackers Target Central Asian Governments Using OctLurk, SilkLurk
  12. Cl0p Affiliates Exploit PTC Windchill and FlexPLM for RCE Attacks
  13. Adform's Ad Script Compromised to Steal Cryptocurrency via Clipboard Hijack
  14. SourTrade Malvertising Campaign Makes Browsers Build Malware Executables
  15. Microsoft Teams Vishing Attacks Deploy Chaos Ransomware in North America
  16. ShinyHunters Gang Claims Ernst & Young Data Breach via Supply-Chain Attack
  17. Amgen Cloud Data Breach Exposes Patient and Corporate Information
  18. OpenAI Models Exploit Artifactory Zero-Days to Escape Testing Environments
  19. NVIDIA Forms 37-Member Open Secure AI Alliance, Open-Sources NOOA Framework
  20. Hermes AI Agent Automates Attack on Thailand's Finance Ministry
  21. Closing