Weekly Brief

SOC Minute Weekly

This episode examines cryptocurrency wallet failures, critical vulnerabilities across hosting, analytics, laboratory, and infrastructure software, evolving phishing and npm supply-chain attacks, a major healthcare breach, and new security failures involving AI agents.

Weekly Episode
Duration
18:02
Stories
16 stories
Published
Watch on YouTube

About this episode

This episode examines cryptocurrency wallet failures, critical vulnerabilities across hosting, analytics, laboratory, and infrastructure software, evolving phishing and npm supply-chain attacks, a major healthcare breach, and new security failures involving AI agents.

This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.

Play the episode, then review the stories and chapter list for the reporting and topics covered.

Stories covered this week

Chapters

  1. Opening
  2. Coldcard Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes
  3. Critical cPanel Flaw Lets Hosting Customers Run SQL as Database Root
  4. Critical Integrity Flaw in Thermo Fisher Genetic Analyzers Could Alter DNA Data
  5. Veeam, Terraform MCP, and Django Patch Critical Vulnerabilities Including CVSS 10.0 Bug
  6. Metabase SQL Injection Zero-Day Exploited in Data-Theft Attacks
  7. Microsoft 365 AitM Phishing Campaign Targets Payroll and Finance Emails
  8. DOUBLECUP ClickFix Service Hides Malware in Browser Cache Images
  9. Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
  10. ChainDrop Malware Infects 1,300+ npm Packages in Supply-Chain Attack
  11. Attackers Use Oracle SQL Injection to Compile Khunt Toolkit for SYSTEM Access
  12. Nearly 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer
  13. Crypto Wallet RNG Flaw Linked to $88M Bitcoin Theft
  14. Unlimited Technology Systems Breach Affects 3.8 Million People
  15. Meta AI Model Hacks Company During Misconfigured Cybersecurity Test
  16. Paperclip AI Flaws Allow Remote Host Command Execution
  17. How Threat Actors Are Weaponizing Cloud-Based AI: A Data-Driven Review
  18. Closing